Networking, DNS & Wi-Fi

Wi-Fi authentication loops or fails

Use handshake and EAP evidence to separate a personal Wi-Fi credential mismatch from enterprise authentication or driver errors before changing security.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • A visible SSID repeatedly asks for a password or disconnects during authentication.
  • The supplicant reports a four-way handshake or EAP failure before DHCP begins.

Relevant environment

NetworkManager Wi-Fi profiles using wpa_supplicant; iwd backends report different events, and enterprise settings depend on the network administrator.

Recognizable messages (synthetic examples)
wpa_supplicant[810]: wlan0: WPA: 4-Way Handshake failed - pre-shared key may be incorrect

Verify the profile and credential, but also inspect preceding key-installation or radio failures before concluding that the password is wrong.

wpa_supplicant[810]: wlan0: CTRL-EVENT-EAP-FAILURE EAP authentication failed

Read the preceding method and certificate events; this signal does not distinguish an account denial from a TLS validation problem.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • A personal-network handshake can fail with mismatched credentials, incompatible security mode or lower-level key installation/radio trouble; the password hint is not conclusive.
  • An EAP failure can involve identity, method, account policy, certificate validation or the authentication server; earlier EAP/TLS details are needed.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Read current-boot authentication events; journal access may require privileges. Retain preceding TLS, key-installation and association events and redact SSIDs or identities before sharing.

journalctl -b -u NetworkManager -u wpa_supplicant --no-pager -n 250

Interpret the result: EAP failure belongs to enterprise authentication. A four-way handshake password hint also follows some driver failures; ip-config errors after completed authentication belong to address acquisition.

Check 2

Replace PROFILE with the exact saved connection name. Inspect SSID and security methods without --show-secrets; this does not expose the stored password.

nmcli -f 802-11-wireless.ssid,802-11-wireless-security.key-mgmt,802-11-wireless-security.pmf,802-1x.eap connection show "PROFILE"

Interpret the result: Compare the profile with the actual AP policy: WPA-PSK, SAE and WPA-EAP are different methods. A missing 802-1x method is expected for a personal network.

Evidence-guided next steps

Correct the personal-network profile

If a personal network’s verified credentials or security mode differ from the saved profile, edit that specific profile in the desktop connection editor and re-enter the credential through its secure prompt. Compare one connection attempt while keeping driver errors in view.

Precautions: Keep the previous profile settings and use a local console when editing the only link. Do not place a password in command history or weaken the AP to open/WEP to suppress the symptom.

Recovery / rollback: Restore the saved SSID and security mode if the edit targets the wrong network; recover through Ethernet or the prior working profile.

Did this solution help you?

Share this solution#

Repair the documented EAP configuration

If EAP or TLS details identify the enterprise path, compare method, inner authentication, CA certificate and server-name constraint with the administrator’s current profile. Correct an expired client certificate or incorrect system time only when those checks support it.

Precautions: Keep server certificate validation enabled and obtain credentials/certificates through the approved channel. Repeated blind retries can trigger account lockout.

Recovery / rollback: Restore the saved enterprise profile and certificate references if the new configuration fails; use a known working access path to contact the network administrator.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.