Configure WPA Personal or Enterprise Wi-Fi with wpa_background

WEP still shows up in Wi-Fi menus decades after it was broken, and wpa_background explains exactly why you should never pick it. This guide turns that background into a small, reviewable wpa_supplicant configuration for either a home-style pre-shared key or an enterprise EAP network, then tests it in the foreground so failures stay visible.

The examples use wpa_supplicant 2.10 from Ubuntu package wpasupplicant 2:2.10-21ubuntu0.4. Allow about fifteen minutes, plus time to obtain the correct network credentials or certificates. You need a present and enabled wireless interface, its driver, the wpasupplicant package, and permission to read the configuration and certificate files.

This guide does not change NetworkManager, systemd-networkd or a distribution networking profile. Do not run a second network manager against the same interface. Connecting can interrupt an existing wireless session, so use a maintenance window or a spare interface if the machine is remote.

1. Confirm the installed client and interface

Start with read-only checks. These commands do not need elevated privileges:

$ command -v wpa_supplicant
/usr/sbin/wpa_supplicant
$ wpa_supplicant -v
wpa_supplicant v2.10
$ ip link show wlan0

Replace wlan0 with the real interface name. The daemon exits immediately when the physical device is unavailable or its driver is not loaded. A name that appears in configuration is not enough; the kernel interface must already exist.

Checkpoint: record the interface name and confirm that it is enabled. If it is down, an administrator can inspect or change that state with the host's normal network tooling, but that is outside this guide.

2. Pick the authentication model

Use WPA-Personal when the access point gives you one shared passphrase. In the configuration this is key_mgmt=WPA-PSK and a psk value. Every device shares the same secret, so removing one device usually means changing the network secret for all of them.

Use WPA-Enterprise when the organisation supplies an authentication service, normally through RADIUS and EAP. The configuration uses key_mgmt=WPA-EAP and an EAP method such as TLS, PEAP or TTLS. The exact method, identity format and certificate policy belong to the network administrator. Do not guess them from the SSID.

The background man page describes WPA as the earlier Wi-Fi Protected Access design and WPA2 as the completed IEEE 802.11i generation. WPA2 adds CCMP, based on AES, and was designed to replace TKIP. WEP is explicitly not secure, and the installed client still lists legacy key-management and cipher support for compatibility. Support in the binary is not a recommendation to enable an obsolete network.

3. Write one narrow Personal network block

Create a temporary configuration with an absolute path. The configuration format is plain text. Protect the file because the passphrase is stored in it:

$ umask 077
$ editor /tmp/wpa-test.conf

For a WPA-Personal network, put this block in the file and replace both placeholders:

network={
    ssid="YOUR_SSID"
    key_mgmt=WPA-PSK
    psk="YOUR_WIFI_PASSPHRASE"
}

Keep the SSID and passphrase quoted. Do not add a catch-all network block while diagnosing one connection. The configuration manual says that several network blocks may be selected by security level, block order and signal strength, which can make a test appear to connect to the wrong access point.

Checkpoint: inspect permissions and the block before starting anything:

$ stat -c '%A %n' /tmp/wpa-test.conf
------- ------ /tmp/wpa-test.conf
$ sed -n '1,20p' /tmp/wpa-test.conf

The exact permission text varies with the file's owner and mode. The useful property is that other users cannot read the secret. Never paste the real passphrase into a ticket or shell history.

4. Add an Enterprise block only with supplied details

For an EAP-TLS deployment, a representative block looks like this:

network={
    ssid="CORPORATE_SSID"
    key_mgmt=WPA-EAP
    eap=TLS
    identity="[email protected]"
    ca_cert="/etc/wifi/ca.pem"
    client_cert="/etc/wifi/user.pem"
    private_key="/etc/wifi/user.key"
}

This is a template, not a universal enterprise configuration. EAP-TLS needs the server CA, client certificate and matching private key. PEAP and TTLS use different inner authentication settings. Ask the network team for the exact method and certificate paths, and verify that every path is absolute and readable by the process.

Security boundary: Do not remove ca_cert or accept an unverified server merely to make a login succeed. That can turn an authentication test into credential disclosure to an impostor access point.

5. Test in the foreground

Stop before this step if another service currently manages wlan0. The following command is service-disrupting because it asks the interface to associate with the selected access point. Run it in a terminal you can keep open:

$ sudo wpa_supplicant -c /tmp/wpa-test.conf -i wlan0 -d

-c selects the configuration, -i selects the interface, and -d enables debugging. The process stays in the foreground. A successful WPA exchange ends with encryption keys being configured, after which normal data can be transmitted. A successful association is not the same as having an IP address; DHCP or another higher-level network service must still run.

Look for the SSID you intended and a completed handshake. Debug text differs by driver, so use the exit status and the state reported by the daemon rather than copying one line as a universal success marker. Press Ctrl-C to stop the test and release the interface. No persistent service configuration is changed by this foreground command.

6. Diagnose without hiding the useful error

If the daemon exits immediately, check the three prerequisites first:

  1. Confirm the interface name with ip link.
  2. Confirm the file path and permissions with ls -l /tmp/wpa-test.conf.
  3. Check the first error in the debug output, especially a malformed network block or an unreadable certificate.

If it associates but cannot complete authentication, compare key_mgmt, EAP method, identity, passphrase and certificate requirements with the network administrator's documented policy. A wrong WPA-Personal passphrase and a wrong Enterprise identity are configuration errors, not reasons to enable WEP or broaden the network block.

If you need a background process after the foreground test, the installed manual documents -B for daemonising and gives the form wpa_supplicant -B -c/etc/wpa_supplicant.conf -iwlan0. Use the distribution's service integration where available. Do not launch a second copy over the first one. If you edit a live configuration, the configuration manual documents reloading with SIGHUP or wpa_cli reconfigure; test the foreground path first.

7. Clean up the temporary secret

When testing is complete, stop the foreground process with Ctrl-C. Then remove the temporary file only if you no longer need it:

$ rm -- /tmp/wpa-test.conf

This deletion is irreversible. If the file is needed for a later test, move it into an administrator-controlled directory with restrictive permissions instead of leaving it in a shared temporary location. Reverting the test itself means stopping the foreground process; it does not require changing the access point.

Done means