Generate a WPA PSK Safely with wpa_passphrase
You will turn an ASCII Wi-Fi passphrase and its SSID into a ready-to-paste network block containing a 256-bit pre-shared key (PSK). This is useful when preparing a wpa_supplicant.conf file, without placing the derived key in a command's arguments. Allow about five minutes. You need the wpasupplicant package and the exact network name.
The route
Jump straight to the step you need, or tick off Done means at the end.
Before you start
This guide uses wpa_passphrase from Ubuntu's wpasupplicant package, version 2:2.10-21ubuntu0.4 on the machine used for these examples. The installed manual page documents two positional arguments: ssid and passphrase. If the passphrase argument is omitted, the program reads it from standard input.
The SSID is the wireless network name, including spaces, capitalisation and punctuation. It is input to the key derivation, so a spelling difference produces a different PSK. The passphrase is not merely converted to hexadecimal: the SSID and passphrase together determine the result.
Checkpoint: derive the network block
Run the command with the SSID as the only argument, then type the passphrase when prompted. Replace
YOUR_SSIDwith the exact network name.wpa_passphrase 'YOUR_SSID'Nothing is echoed while you type. End the input with Enter. For example:
$ wpa_passphrase 'Example Wi-Fi' # reading passphrase from stdin correct horse battery staple network={ ssid="Example Wi-Fi" #psk="correct horse battery staple" psk=a67e4e76154d2f3fbd535340d6a69e4978c805f2c5a8137eb7c3cdd6ecf040f2 }Copy the complete
network={...}block into the configuration file or command that will consume it. The commented#pskline shows the original passphrase for reference, while the uncommentedpskline is the derived hexadecimal key.
Keep the passphrase out of shell history
Prefer the prompt form above. A passphrase supplied as the second argument is visible to the shell history and may be briefly visible to other local users through process inspection. It is also easy to paste it into the wrong terminal or log.
The argument form is supported and can be useful in a controlled, non-interactive context:
wpa_passphrase 'YOUR_SSID' 'YOUR_PASSPHRASE'
Do not put a real secret in a script, shared command transcript or ticket. If automation is unavoidable, arrange for the input to come from a protected secret source and ensure that the source and generated output have access permissions appropriate to the account using them. This command only prints the block; it does not write a configuration file, connect to Wi-Fi or change the system.
Checkpoint: verify before using the key
Check that the output contains the expected SSID and exactly one uncommented
psk=line. The hexadecimal value should be 64 characters long for the generated 256-bit PSK.Repeat the derivation if you are unsure which SSID or passphrase was used, and compare the complete
pskvalue. The same inputs produce the same value. Different capitalisation, an extra space or a changed punctuation mark does not.Remove temporary output containing the passphrase or PSK after checking it. If you saved it in a file only for testing, delete that specific file and check that it is not being backed up or shared.
A safe verification run does not require root:
printf '%s\n' 'YOUR_PASSPHRASE' | wpa_passphrase 'YOUR_SSID'
This pipeline is convenient for a one-off check, but the passphrase can still be exposed through the shell command itself if it is written literally. Use it only with a disposable test value, or provide the input from a protected source. The command's diagnostic line, # reading passphrase from stdin, confirms that the input path was standard input.
Use the result in wpa_supplicant
The generated block is a configuration fragment, not a complete instruction to the wireless service. If you add it to an existing wpa_supplicant.conf, preserve the file's ownership and permissions. A configuration containing a clear-text passphrase in a comment or a derived PSK is sensitive. Do not make it world-readable.
Writing a system configuration or restarting a wireless service normally requires elevated privileges and can interrupt the connection. Confirm the destination before using sudo. Keep a backup of the existing file, then restore that backup if the change prevents the expected network from connecting. The wpa_passphrase command itself does not need sudo.
If the network is not accepted, first check the SSID and passphrase with the network owner. Then check that the block was copied without changing quotes, tabs or the PSK value. A generated PSK is deterministic, so recalculating it with the same inputs is a useful comparison. Do not regenerate keys repeatedly while changing several inputs at once, because that makes the actual error harder to identify.
Common traps
- Wrong network name: hidden spaces and case matter. Copy the SSID from a trusted network listing, then quote it in the command.
- Passphrase shown in output: the commented
#pskline is intentional but sensitive. Treat the entire output as secret material. - Unexpected option error: this interface is positional. The documented form is
wpa_passphrase [ssid] [passphrase]; do not invent option flags for it. - Failed input: when the passphrase argument is omitted, enter it on standard input. An empty or interrupted input does not prove that the network credentials are correct.
Done means
- The SSID in the block exactly matches the intended wireless network.
- The derived
pskis 64 hexadecimal characters and was reproduced from the confirmed inputs. - The passphrase and PSK were not left in shell history, temporary files or logs unnecessarily.
- Any configuration change was made deliberately, with a recoverable backup and awareness that reconnecting may interrupt networking.