Posted: Tue Jun 24, 2025 2:29 Post subject: GUI not setting WPA3 passphrases
I have two devices that are showing similar behavior.
Linksys MR7500-RM2
Linksys EA8300
Both devices currently have R61843 running.
I have not been able to get any device to connect to 2.4 GHz radio(WLAN1) using WPA3 on the MR7500 for a long time, yet WLAN0 & WLAN2 connect with WPA3 without issue. (I didn't research how many builds this goes back.) I also had no real issue since most of my 2.4Ghz devices do not support WPA3.
On the EA8300 I have not been able to connect to any of the three radios using WPA3 since R59887. Again was not a dire concern since the wireless footprint of the access points do not overlap.
I reset the MR7500 back to factory defaults, while I was doing a manual reconfigure in R61824 I noticed one of my devices was connected to the router using the OEM SSID & Passphrase using WPA3. As I continued to configured the router I changed the SSID & Passphrases. This is when I found the same device could no longer connect to WLAN1 using WPA3. I changed the SSID and/or passphrase several times still could not connect using WPA3. Reset the router to factory defaults and the device immediately connected to WLAN1 using WPA3 again using the default OEM SSID & passphrase.
I changed the SSID but not the passphrase and was able to connect. Changed the passphrase and was no longer able to connect. Changed the WPA3 passphrase on the device back to the OEM default and immediately connected. Changed the WPA3 passphrase for WLAN1 within the GUI multiple times yet the device remained connected using the OEM passphrase. Hmmm? GUI is not changing the WPA3 passphrase.
I started an SSH session. And displayed the NVRAM info.
Using:
nvram get wlan1_wpa_psk ---> I got the WPA2 passphrase set in the GUI.
nvram get wlan1_sae_key ---> I got the OEM passphrase instead.
Note - I changed the passphrase in GUI a few more times, each time the WLAN1_sae_key value did not change, but wlan1_wpa_psk displayed the correct passphrase each time.
When I did the same for WLAN0 the values matched each other, the same was true for WLAN2.
I also found the same conditions for virtual access points on WLAN1. (WLAN1.1, WLAN1.2, etc)
VAP's on WLAN0 & WLAN2 worked as expected.
I used nvram set wlan1_sae_key={pass phrase} to set the passphrase manually and all devices now connect using WPA3 as expected.
Now I turned my attention to the Linksys EA8300.
I could not get any device to connect using WPA3 regardless of the passphrase.
I opened an SSH session and displayed the NVRAM values for each radio.
nvram get wlan0_wpa_psk --> Had the correct passphrase
nvram get wlan0_sae_key --> No Value present / Blank
nvram get wlan1_wpa_psk --> Had the correct passphrase
nvram get wlan1_sae_key --> No Value present / Blank
nvram get wlan2_wpa_psk --> Had the correct passphrase
nvram get wlan2_sae_key --> No Value present / Blank
It did not matter what I did I was not able to change ANY wlan#_sae_key value using the GUI.
Again I set the WPA3 passphrases manually using the CLI and all devices connect using WPA3 as expected.
Once I set the WPA3 pass phrases manually I have not encountered any other issues.
Again I have worked around this issue in multiple builds, but did nothing since it really did not create a major issue for me, which I just choose to turn off WPA3. I just literally stumbled across the condition and decided to follow the rabbit hole.
For what is worth the GUI in R62104 is still not setting the WPA3 SAE Keys for WLAN0 & WLAN1.
I know this is not a gremlin, the only way to install r62104 is using the OEM firmware to flash factory-to-ddwrt.img which dictates you have factory defaults. Then to revert to r61848 you have to use the OEM firmware again. You cannot go directly to r61981 or higher from r61970 or lower without using OEM firmware. Attempting to bridge that divide flashing from dd-wrt just results in a infinite boot loop after flashing.
WHY?
Don't have a clue. This is just the observed behavior I have been presented with.
Try making a VAP and on the VAP use WPA3, this is what I have to do and seems to work without issues.
I have reported this on my mr7350. _________________ Main Router: Dynalink WRX36, PPPoE, Gateway Mode, Network IPV4 - Isolated Vlan's. Unifi AC-Pro x 3 AP's, Router Wi-Fi Disabled. Paid Commercial Wireguard Client's & WG server, DNSMasq, Static Leases with Quad9 SmartDNS, DNSMasq Adblocking thanks to egc script.
No one can build you the bridge on which you, and only you, must cross the river of life!