WPA Arguments
Rogue’s WPA/WPA2/WPA3 behaviour is driven by two options working together:
--authselects the credential model —wpa-personal(a pre-shared passphrase) orwpa-enterprise(802.1X/EAP via freeradius-wpe).--wpaselects the generation —1(legacy WPA),2(WPA2) or3(WPA3).
Rogue combines the two to produce the correct wpa_key_mgmt and Management
Frame Protection (PMF / ieee80211w) settings. Note that hostapd’s wpa=
directive is a bitfield where 2 means RSN and is used by both WPA2 and
WPA3 — WPA3 is expressed through the key-management suite and PMF, so
--wpa 3 is rendered as wpa=2 with WPA3 key management.
Combinations
|
|
Result ( |
PMF ( |
Notes |
|---|---|---|---|---|
|
|
WPA2-Personal ( |
optional (1) |
Passphrase required |
|
|
WPA3-Personal ( |
required (2) |
Passphrase required; |
|
|
WPA2-Enterprise ( |
optional (1) |
EAP via freeradius-wpe |
|
|
WPA3-Enterprise ( |
required (2) |
EAP via freeradius-wpe |
|
|
Legacy WPA ( |
disabled (0) |
Not recommended |
|
n/a |
Enhanced Open ( |
required (2) |
Encrypted, no credentials; |
The PMF column shows the auto default; --pmf overrides it (except WPA3
and OWE, which always require 2). open/wep networks are unaffected by
these options.
owe (Opportunistic Wireless Encryption, a.k.a. “Enhanced Open”) is an open
network with no passphrase, but the association is RSN-encrypted with PMF
required. It shares the WPA/RSN rendering path with wpa-personal — the
passphrase line is simply omitted.
Note
On the 6 GHz band (--freq 6, Wi-Fi 6E) open and WPA2 are forbidden and PMF
is mandatory, so rogue auto-maps the requested auth: open becomes OWE, and
wpa-personal / wpa-enterprise are upgraded to WPA3 (SAE / EAP-SHA256).
wep on 6 GHz is rejected.
Arguments
--wpa {1,2,3}WPA generation: 1 = legacy WPA, 2 = WPA2, 3 = WPA3. Default: 2.
--wpa-passphrase <passphrase>Pre-shared key for
wpa-personal(used by both WPA2-PSK and WPA3-SAE). Required when--auth wpa-personalis selected.--pmf {0,1,2}Management Frame Protection (
ieee80211w): 0 = disabled, 1 = optional, 2 = required. Default is auto (WPA3 → 2, WPA2 → 1, open → 0). WPA3 (--wpa 3) always requires 2 — supplying--pmf 0or--pmf 1with--wpa 3is rejected.--wpa-pairwise {CCMP,TKIP,CCMP TKIP}Pairwise cipher(s) for legacy WPA (WPA v1). Default:
CCMP TKIP.--rsn-pairwise {CCMP,TKIP,CCMP TKIP}Pairwise cipher(s) for RSN (WPA2/WPA3). Default:
CCMP.
Examples
WPA2-Personal:
sudo python3 /opt/rogue/rogue.py -i wlan0 --auth wpa-personal --wpa 2 --wpa-passphrase "SuperSecret" --preset-profile wifi5 --channel-randomiser --country AU
WPA3-Personal (SAE):
sudo python3 /opt/rogue/rogue.py -i wlan0 --auth wpa-personal --wpa 3 --wpa-passphrase "SuperSecret" --preset-profile wifi6 --channel-randomiser --country AU
WPA3-Enterprise:
sudo python3 /opt/rogue/rogue.py -i wlan0 --auth wpa-enterprise --wpa 3 --default-eap peap -E peap --preset-profile wifi6 --channel-randomiser --country AU --server-certificate ./fullchain.pem --ca-certificate ./chain.pem --server-private-key ./privkey.pem
OWE (Enhanced Open):
sudo python3 /opt/rogue/rogue.py -i wlan0 --auth owe --preset-profile wifi6 --channel-randomiser --country AU