wpa_supplicant无法连接EAP-PEAP MSCHAPv2 WPA企业网络问题
wpa_supplicant接入PEAP-MSCHAPv2企业WPA网络失败排查
问题背景
我尝试通过wpa_supplicant使用PEAP-MSCHAPv2协议接入WPA企业级网络,后端RADIUS服务器为FreeRADIUS 3.0。目前已确认身份凭证完全正确,尝试多份配置后仍无法完成连接,现附上所有测试过的配置文件及运行输出供问题定位:
请注意输出日志未按配置对应顺序排列,所有哈希值已替换为任意值以符合平台规范
已测试的配置文件
配置1
network={ ssid="lkpop1" scan_ssid=1 key_mgmt=WPA-EAP identity="user1" password="password123!" eap=PEAP phase1="peaplabel=0" phase2="auth=MSCHAPV2" }
配置2
ctrl_interface=DIR=/var/run/wpa_supplicant GROUP=netdev update_config=1 #country=US network={ ssid="lkpop1" scan_ssid=1 key_mgmt=WPA-EAP eap=PEAP identity="user1" password=hash:8119935c5f7fa5f57135620c8073aaca phase1="peaplabel=0" phase2="auth=MSCHAPV2" }
配置3
ctrl_interface=DIR=/var/run/wpa_supplicant GROUP=netdev update_config=1 #country=US network={ ssid="lkpop1" scan_ssid=1 key_mgmt=WPA-EAP eap=PEAP identity="user1" password="password123!" phase1="peaplabel=0" phase2="auth=MSCHAPV2" }
配置4
ctrl_interface=DIR=/var/run/wpa_supplicant GROUP=netdev update_config=1 #country=US network={ ssid="lkpop1" scan_ssid=1 key_mgmt=WPA-EAP eap=PEAP identity="user1" ca_cert="/etc/cert/ca.pem" password="password123!" phase1="peaplabel=0" phase2="auth=MSCHAPV2" }
配置5
network={ ssid="lkpop1" scan_ssid=1 key_mgmt=WPA-EAP eap=PEAP identity="user1" password=hash:8119935c5f7fa5f57135620c8073aaca ca_cert="/etc/cert/ca.pem" phase1="peaplabel=0" phase2="auth=MSCHAPV2" }
运行输出日志
输出1:wl0网卡运行日志
执行命令:wpa_supplicant -i wl0 -Dnl80211 -c wpa_supplicant.conf
Successfully initialized wpa_supplicant rfkill: Cannot open RFKILL control device rfkill: Cannot get wiphy information wl0: SME: Trying to authenticate with 00:11:00:be:02:09 (SSID='lkpop1' freq=2452 MHz) wl0: Trying to associate with 00:11:00:be:02:09 (SSID='lkpop1' freq=2452 MHz) wl0: Associated with 00:11:00:be:02:09 wl0: CTRL-EVENT-SUBNET-STATUS-UPDATE status=0 wl0: CTRL-EVENT-EAP-STARTED EAP authentication started wl0: CTRL-EVENT-EAP-PROPOSED-METHOD vendor=0 method=25 wl0: CTRL-EVENT-EAP-METHOD EAP vendor 0 method 25 (PEAP) selected wl0: CTRL-EVENT-EAP-PEER-CERT depth=1 subject='/C=GB/ST=lk/L=hs/O=pk/emailAddress=ca@lkpop1.localdomain/CN=ak Certificate Authority' hash=6d7acb97ebc3d10f265bc9e0cb79ce2f915eb1d78fc9bb9318ca74a30ce67856 wl0: CTRL-EVENT-EAP-PEER-CERT depth=1 subject='/C=GB/ST=lk/L=hs/O=pk/emailAddress=ca@lkpop1.localdomain/CN=ak Certificate Authority' hash=6d7acb97ebc3d10f265bc9e0cb79ce2f915eb1d78fc9bb9318ca74a30ce67856 wl0: CTRL-EVENT-EAP-PEER-CERT depth=0 subject='/C=GB/ST=lk/O=pk/CN=ak Wi-Fi Radius/emailAddress=wifi-admin@lkpop1.localdomain' hash=6d7acb97ebc3d10f265bc9e0cb79ce2f915eb1d78fc9bb9318ca74a30ce67856 wl0: CTRL-EVENT-EAP-FAILURE EAP authentication failed wl0: CTRL-EVENT-DISCONNECTED bssid=00:11:00:be:02:09 reason=23 wl0: CTRL-EVENT-SSID-TEMP-DISABLED id=0 ssid="lkpop1" auth_failures=1 duration=10 reason=AUTH_FAILED nl80211: Failed to open /proc/sys/net/ipv4/conf/wl0/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter ^Cnl80211: deinit ifname=p2p-dev-wl0 disabled_11b_rates=0 p2p-dev-wl0: CTRL-EVENT-TERMINATING nl80211: Failed to open /proc/sys/net/ipv4/conf/wl0/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter nl80211: Failed to open /proc/sys/net/ipv4/conf/wl0/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter nl80211: deinit ifname=wl0 disabled_11b_rates=0 wl0: CTRL-EVENT-TERMINATING
输出2:wl1网卡运行日志(无明确证书错误)
执行命令:wpa_supplicant -Dnl80211 -i wl1 -c wpa_supplicant.conf
Successfully initialized wpa_supplicant rfkill: Cannot open RFKILL control device rfkill: Cannot get wiphy information nl80211: Could not set interface 'p2p-dev-wl1' UP nl80211: deinit ifname=p2p-dev-wl1 disabled_11b_rates=0 p2p-dev-wl1: Failed to initialize driver interface P2P: Failed to enable P2P Device interface wl1: SME: Trying to authenticate with 00:11:00:be:02:09 (SSID='lkpop1 ' freq=2452 MHz) wl1: Trying to associate with 00:11:00:be:02:09 (SSID='lkpop1 ' freq=2452 MHz) wl1: Associated with 00:11:00:be:02:09 wl1: CTRL-EVENT-SUBNET-STATUS-UPDATE status=0 wl1: CTRL-EVENT-EAP-STARTED EAP authentication started wl1: CTRL-EVENT-EAP-PROPOSED-METHOD vendor=0 method=25 wl1: CTRL-EVENT-EAP-METHOD EAP vendor 0 method 25 (PEAP) selected wl1: CTRL-EVENT-EAP-PEER-CERT depth=1 subject='/C=GB/ST=lk/L=hs/O=pk/emailAddress=ca@pk.localdomain/CN=pk Certificate Authority' hash=9a1a24894acb1f183e9b290583b9ac48ce94ede298f897197b9c94b9db8eb255 wl1: CTRL-EVENT-EAP-PEER-CERT depth=1 subject='/C=GB/ST=lk/L=hs/O=pk/emailAddress=ca@pk.localdomain/CN=pk Certificate Authority' hash=9a1a24894acb1f183e9b290583b9ac48ce94ede298f897197b9c94b9db8eb255 wl1: CTRL-EVENT-EAP-PEER-CERT depth=0 subject='/C=GB/ST=lk/O=pk/CN=pk Wi-Fi Radius/emailAddress=wifi-admin@pk.localdomain' hash=9a1a24894acb1f183e9b290583b9ac48ce94ede298f897197b9c94b9db8eb255 wl1: CTRL-EVENT-EAP-FAILURE EAP authentication failed wl1: CTRL-EVENT-DISCONNECTED bssid=00:11:00:be:02:09 reason=23 wl1: CTRL-EVENT-SSID-TEMP-DISABLED id=0 ssid="lkpop1 " auth_failures=1 duration=10 reason=AUTH_FAILED nl80211: Failed to open /proc/sys/net/ipv4/conf/wl1/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter ^Cnl80211: Failed to open /proc/sys/net/ipv4/conf/wl1/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter nl80211: Failed to open /proc/sys/net/ipv4/conf/wl1/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter nl80211: deinit ifname=wl1 disabled_11b_rates=0 wl1: CTRL-EVENT-TERMINATING
输出3:wl1网卡运行日志(带明确证书错误)
Successfully initialized wpa_supplicant rfkill: Cannot open RFKILL control device rfkill: Cannot get wiphy information nl80211: Could not set interface 'p2p-dev-wl1' UP nl80211: deinit ifname=p2p-dev-wl1 disabled_11b_rates=0 p2p-dev-wl1: Failed to initialize driver interface P2P: Failed to enable P2P Device interface wl1: SME: Trying to authenticate with 00:11:00:be:02:09 (SSID='lkpop1 ' freq=2452 MHz) wl1: Trying to associate with 00:11:00:be:02:09 (SSID='lkpop1 ' freq=2452 MHz) wl1: Associated with 00:11:00:be:02:09 wl1: CTRL-EVENT-SUBNET-STATUS-UPDATE status=0 wl1: CTRL-EVENT-EAP-STARTED EAP authentication started wl1: CTRL-EVENT-EAP-PROPOSED-METHOD vendor=0 method=25 wl1: CTRL-EVENT-EAP-METHOD EAP vendor 0 method 25 (PEAP) selected wl1: CTRL-EVENT-EAP-PEER-CERT depth=1 subject='/C=GB/ST=lk/L=hs/O=pk/emailAddress=ca@pk.localdomain/CN=pk Certificate Authority' hash=9a1a24894acb1f183e9b290583b9ac48ce94ede298f897197b9c94b9db8eb255 wl1: CTRL-EVENT-EAP-PEER-CERT depth=0 subject='/C=GB/ST=lk/O=pk/CN=pk Wi-Fi Radius/emailAddress=wifi-admin@pk.localdomain' hash=9a1a24894acb1f183e9b290583b9ac48ce94ede298f897197b9c94b9db8eb255 TLS: Certificate verification failed, error 7 (certificate signature failure) depth 0 for '/C=GB/ST=lk/O=pk/CN=pk Wi-Fi Radius/emailAddress=wifi-admin@pk.localdomain' wl1: CTRL-EVENT-EAP-TLS-CERT-ERROR reason=0 depth=0 subject='/C=GB/ST=lk/O=pk/CN=pk Wi-Fi Radius/emailAddress=wifi-admin@pk.localdomain' err='certificate signature failure' SSL: SSL3 alert: write (local SSL3 detected an error):fatal:decrypt error OpenSSL: openssl_handshake - SSL_connect error:0407008A:rsa routines:RSA_padding_check_PKCS1_type_1:invalid padding OpenSSL: pending error: error:04067072:rsa routines:rsa_ossl_public_decrypt:padding check failed OpenSSL: pending error: error:0D0C5006:asn1 encoding routines:ASN1_item_verify:EVP lib OpenSSL: pending error: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed wl1: CTRL-EVENT-EAP-FAILURE EAP authentication failed wl1: CTRL-EVENT-DISCONNECTED bssid=00:11:00:be:02:09 reason=23 wl1: CTRL-EVENT-SSID-TEMP-DISABLED id=0 ssid="lkpop1 " auth_failures=1 duration=10 reason=AUTH_FAILED nl80211: Failed to open /proc/sys/net/ipv4/conf/wl1/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter ^Cnl80211: Failed to open /proc/sys/net/ipv4/conf/wl1/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter nl80211: Failed to open /proc/sys/net/ipv4/conf/wl1/drop_unicast_in_l2_multicast: Read-only file system nl80211: Failed to set IPv4 unicast in multicast filter nl80211: deinit ifname=wl1 disabled_11b_rates=0 wl1: CTRL-EVENT-TERMINATING
问题根因定位
- 凭证错误可直接排除:日志显示EAP流程已经走到PEAP隧道建立阶段,在TLS证书校验环节直接失败,和账号密码正确性无关。
- 核心错误来自输出3的日志:
certificate signature failure,即RADIUS服务器下发的证书签名校验不通过,具体是RSA公钥解密时PKCS1填充校验失败,说明本地存放的CA证书和RADIUS服务器实际使用的证书不匹配,要么CA证书文件损坏、要么导错了证书、要么RADIUS侧更换了证书但本地未更新。 - 额外配置错误:输出2、3里连接的SSID是
lkpop1(末尾带空格),和实际目标SSIDlkpop1不一致,虽然能关联到AP,但会导致后续认证匹配异常。 - 日志里的rfkill报错、只读文件系统报错是运行环境权限问题,不影响核心EAP认证流程。
修复步骤
- 修正SSID配置,去掉所有配置里ssid字段末尾的多余空格,确保和AP广播的SSID完全一致。
- 重新从FreeRADIUS服务器导出正确的根CA证书,替换本地
/etc/cert/ca.pem文件,导出后可以用openssl verify命令校验证书完整性,避免文件传输过程中损坏。 - 如果是测试环境
相关产品推荐
相关产品推荐

