NetworkManager 1.58.1 Fixes a WPA3 Auto-Connect Regression Introduced in the Previous Release
NetworkManager 1.58.1 arrived on August 21, primarily to fix a regression from the previous release that broke automatic reconnection to WPA3 networks.
The WPA3 regression
Profiles configured with key-mgmt=wpa-psk failed to automatically reconnect to SAE-based WPA3 networks. 1.58.1 restores that behavior.
This is a nastier bug than it sounds, because of how WPA3 rolled out. Many access points run a transition mode supporting both WPA2 and WPA3, and many saved profiles were created under WPA2 with wpa-psk and later silently upgraded when the network moved to SAE. Users with those profiles would have seen their laptop simply stop rejoining the network it had been joining for years, with no obvious cause.
If you updated NetworkManager recently and started manually reconnecting to your own wifi, this was why.
# Check what your saved profile actually specifies
nmcli -f 802-11-wireless-security.key-mgmt connection show "Your Network"
# And what the AP is offering
nmcli -f SSID,SECURITY device wifi list
DNS handling
Several DNS fixes landed:
- Unspecified addresses received as DNS nameservers through RDNSS and DHCPv6 are now ignored
- Invalid nameservers are skipped when configuring systemd-resolved
- Port numbers specified in DNS URIs are correctly forwarded to systemd-resolved
The port forwarding fix matters for anyone running DNS on a non-default port, which includes a lot of self-hosted setups. Previously the port could be silently dropped during configuration, so your resolver query went to port 53 on a server that was not listening there, and the failure looked like a DNS outage rather than a configuration bug.
Tighter 802.1X handling
NetworkManager now applies stricter rules to private 802.1X connection profiles. For connections that specify a user through connection.permissions, the ca-path and phase2-ca-path settings are no longer accepted.
The reasoning is that a per-user profile pointing at a directory of CA certificates gives an unprivileged user influence over which certificates are trusted for enterprise authentication. Requiring an explicit certificate rather than a search path closes that.
This will break some existing enterprise wifi profiles. If yours stops connecting after the update, check whether it uses ca-path and switch it to a specific ca-cert.
Other fixes
IPv4 forwarding is now correctly enabled on mobile broadband data interfaces, Bluetooth NAP connections got fixes, and several crashes were resolved.