Home / Alt manpages / wpa_passphrase(8)

  • wpa_passphrase(8)
  • Admin command
  • linux

Generate a WPA PSK Safely with wpa_passphrase

You will turn an ASCII Wi-Fi passphrase and its SSID into a ready-to-paste network block containing a 256-bit pre-shared key (PSK). This is useful when preparing a wpa_supplicant.conf file, without placing the derived key in a command's arguments. Allow about five minutes. You need the wpasupplicant package and the exact network name.

Before you start

This guide uses wpa_passphrase from Ubuntu's wpasupplicant package, version 2:2.10-21ubuntu0.4 on the machine used for these examples. The installed manual page documents two positional arguments: ssid and passphrase. If the passphrase argument is omitted, the program reads it from standard input.

The SSID is the wireless network name, including spaces, capitalisation and punctuation. It is input to the key derivation, so a spelling difference produces a different PSK. The passphrase is not merely converted to hexadecimal: the SSID and passphrase together determine the result.

Checkpoint: derive the network block

  1. Run the command with the SSID as the only argument, then type the passphrase when prompted. Replace YOUR_SSID with the exact network name.

    wpa_passphrase 'YOUR_SSID'
    

    Nothing is echoed while you type. End the input with Enter. For example:

    $ wpa_passphrase 'Example Wi-Fi'
    # reading passphrase from stdin
    correct horse battery staple
    network={
    	ssid="Example Wi-Fi"
    	#psk="correct horse battery staple"
    	psk=a67e4e76154d2f3fbd535340d6a69e4978c805f2c5a8137eb7c3cdd6ecf040f2
    }
    
  2. Copy the complete network={...} block into the configuration file or command that will consume it. The commented #psk line shows the original passphrase for reference, while the uncommented psk line is the derived hexadecimal key.

Keep the passphrase out of shell history

Prefer the prompt form above. A passphrase supplied as the second argument is visible to the shell history and may be briefly visible to other local users through process inspection. It is also easy to paste it into the wrong terminal or log.

The argument form is supported and can be useful in a controlled, non-interactive context:

wpa_passphrase 'YOUR_SSID' 'YOUR_PASSPHRASE'

Do not put a real secret in a script, shared command transcript or ticket. If automation is unavoidable, arrange for the input to come from a protected secret source and ensure that the source and generated output have access permissions appropriate to the account using them. This command only prints the block; it does not write a configuration file, connect to Wi-Fi or change the system.

Checkpoint: verify before using the key

  1. Check that the output contains the expected SSID and exactly one uncommented psk= line. The hexadecimal value should be 64 characters long for the generated 256-bit PSK.

  2. Repeat the derivation if you are unsure which SSID or passphrase was used, and compare the complete psk value. The same inputs produce the same value. Different capitalisation, an extra space or a changed punctuation mark does not.

  3. Remove temporary output containing the passphrase or PSK after checking it. If you saved it in a file only for testing, delete that specific file and check that it is not being backed up or shared.

A safe verification run does not require root:

printf '%s\n' 'YOUR_PASSPHRASE' | wpa_passphrase 'YOUR_SSID'

This pipeline is convenient for a one-off check, but the passphrase can still be exposed through the shell command itself if it is written literally. Use it only with a disposable test value, or provide the input from a protected source. The command's diagnostic line, # reading passphrase from stdin, confirms that the input path was standard input.

Use the result in wpa_supplicant

The generated block is a configuration fragment, not a complete instruction to the wireless service. If you add it to an existing wpa_supplicant.conf, preserve the file's ownership and permissions. A configuration containing a clear-text passphrase in a comment or a derived PSK is sensitive. Do not make it world-readable.

Writing a system configuration or restarting a wireless service normally requires elevated privileges and can interrupt the connection. Confirm the destination before using sudo. Keep a backup of the existing file, then restore that backup if the change prevents the expected network from connecting. The wpa_passphrase command itself does not need sudo.

If the network is not accepted, first check the SSID and passphrase with the network owner. Then check that the block was copied without changing quotes, tabs or the PSK value. A generated PSK is deterministic, so recalculating it with the same inputs is a useful comparison. Do not regenerate keys repeatedly while changing several inputs at once, because that makes the actual error harder to identify.

Common traps

  • Wrong network name: hidden spaces and case matter. Copy the SSID from a trusted network listing, then quote it in the command.
  • Passphrase shown in output: the commented #psk line is intentional but sensitive. Treat the entire output as secret material.
  • Unexpected option error: this interface is positional. The documented form is wpa_passphrase [ssid] [passphrase]; do not invent option flags for it.
  • Failed input: when the passphrase argument is omitted, enter it on standard input. An empty or interrupted input does not prove that the network credentials are correct.

Done means

  • The SSID in the block exactly matches the intended wireless network.
  • The derived psk is 64 hexadecimal characters and was reproduced from the confirmed inputs.
  • The passphrase and PSK were not left in shell history, temporary files or logs unnecessarily.
  • Any configuration change was made deliberately, with a recoverable backup and awareness that reconnecting may interrupt networking.