WPA3 is already adopted and is mandatory for devices that pass WiFi Alliance certification since July 2020. WPA2 has not been abolished and is not going anywhere. Both WPA2 and WPA3 support operation in PSK and Enterprise modes, but we recommend examining the Private PSK technology in our article, along with the advantages it offers.

The issues with WPA2-Personal are well known and have mostly been resolved (Priority Management Frames, patches for the KRACK vulnerability, etc.). The main remaining drawback of WPA2 when using PSK is that weak passwords can be easily breached by dictionary attacks. In case of compromise and changing the password, it will be necessary to reconfigure all connected devices (and access points), which can be quite a labor-intensive process (to address the 'weak password' issue, the WiFi Alliance recommends using passwords that are at least 20 characters long).
Another issue that can sometimes not be resolved with WPA2-Personal is assigning different profiles (vlan, QoS, firewall…) to groups of devices connected to the same SSID.
With WPA2-Enterprise, all the above problems can be addressed, but the trade-offs will be:
- The need for a PKI (Public Key Infrastructure) and security certificates;
- Installation challenges may arise;
- Troubleshooting difficulties may occur;
- Not an optimal solution for IoT devices or guest access.
A more radical solution to the issues of WPA2-Personal is to transition to WPA3, whose main enhancement is the use of SAE (Simultaneous Authentication of Equals) and static PSK. WPA3-Personal resolves the 'dictionary attack' issue, but does not provide unique identification during authentication and thus the ability to assign profiles (since a common static password is still used).

It is also necessary to consider that more than 95% of existing clients currently do not support WPA3 and SAE, while WPA2 continues to work successfully on billions of already released devices.
Om een oplossing te bieden voor de eerder beschreven bestaande of potentieel mogelijke problemen, heeft Extreme Networks de technologie Private Pre-Shared Key (PPSK) ontwikkeld. PPSK is compatibel met elke Wi-Fi-client die WPA2-PSK ondersteunt en biedt een beveiligingsniveau dat vergelijkbaar is met dat van WPA2-Enterprise, zonder dat er een 802.1X/EAP-infrastructuur nodig is. Private PSK is in wezen WPA2-PSK, maar elke gebruiker (of groep gebruikers) kan zijn eigen dynamisch gegenereerd wachtwoord hebben. Het beheer van PPSK verschilt niet van het beheer van PSK, aangezien het hele proces geautomatiseerd is. De database met sleutels kan lokaal op toegangspunten of in de cloud worden opgeslagen.

Wachtwoorden kunnen automatisch worden gegenereerd, er is de mogelijkheid om de lengte/sterkte, periode of geldigheid en de bezorgmethode naar de gebruiker (per e-mail of SMS) flexibel in te stellen.


Het maximale aantal clients dat met één PPSK kan verbinden, kan ook worden ingesteld, of zelfs 'MAC-binding' voor verbonden apparaten. Op verzoek van de netwerkbeheerder kan elk wachtwoord eenvoudig worden ingetrokken, en toegang tot het netwerk wordt geweigerd zonder dat alle andere apparaten opnieuw geconfigureerd hoeven te worden. Als de client op het moment van intrekken van het wachtwoord is verbonden, zal het toegangspunt deze automatisch van het netwerk uitschakelen.
Belangrijkste voordelen van PPSK zijn:
- gebruiksgemak bij een hoog beveiligingsniveau;
- het afschermen van woordenboekaanvallen wordt opgelost met lange en sterke wachtwoorden, die ExtremeCloudIQ automatisch kan genereren en verzenden;
- de mogelijkheid om verschillende beveiligingsprofielen aan verschillende apparaten die met hetzelfde SSID zijn verbonden toe te wijzen;
- zeer geschikt voor veilige gasttoegang;
- uitstekend geschikt voor veilige toegang wanneer apparaten geen 802.1X / EAP ondersteunen (handscanner of IoT/VoWiFi-apparaten);
- succesvolle toepassing en verbetering gedurende meer dan 10 jaar.
Vragen die ontstaan of blijven, kunnen altijd aan onze kantoormedewerkers worden gesteld – .
Bron: habr.com
