Re: include_length in mods-available/eap

Alan DeKok via Freeradius-Users <[email protected]> Fri, 27 Feb 2026 09:54:11 -0500
Newsgroups gmane.comp.freeradius.user
Message-ID <[email protected]>
On Feb 27, 2026, at 7:27 AM, Stephen Mellor via Freeradius-Users <[email protected]> wrote:
> I think I've just solved a long-standing problem for our EAP-TLS authentication for wired networks (NAS are Aruba 6200m and 3810m, supplicants are HP Windows 11).

  Nice.

  While Windows 11 is somewhat better than earlier versions for some things, it's still not perfect.

> We'd see occasional problems where a laptop would start the authentication process, and freeradius would send-accept, but the laptop would never get the message. Eventually it would failover to wifi, then recognise that there was an ethernet connection, try ethernet again, same result, and repeat until the user pulled the ethernet cable out of the laptop or dock.
> 
> This was quite a rare occurrence, and not consistently repeatable, so tricky to debug, though with several hundred users it seemed that there was always someone complaining (after the event!). We failed to find any pattern of hardware: although all laptops are recent HP we've a variety of USB docks.

  If you can get me a packet trace of the failing connections (off list) that would help.  I don't need to see inside of the TLS tunnel, just the outer EAP stuff is OK.

  I can take a look to see what's going on, and also share the trace with the Windows team if that's OK with you.

  Windows might be miscounting the TLS data, or maybe FreeRADIUS is.  Either way, a PCAP file would help to understand the root cause of the issue.

> However, eventually I stumbled across this: https://community.cisco.com/t5/network-access-control/eap-tls-w-freeradius-failing-phone-doesn-t-present-client/td-p/1932767
> 
> Sure enough, setting include_length to no does seem to have fixed our problem. It's early days yet so I'm not 100% certain, but there were a couple of laptops failing yesterday which stopped when I made the change, and I've seen none failing today.

  Sounds good.

   Alan DeKok.

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEIUl02elqcIsf1zM0v3SJ0h7dTTMFAmmhsBMACgkQv3SJ0h7d
TTP5JxAAgNsPWlSzaK2wM/ZgsiH7jEPSaMFtfXlLntzjUe2/3FSKpAbWgbVGKj13
riioAV5zyVdC0PDCweWCSlfwKSPEw/nAab4StWYBM+mc8s9dae17QYSnEb2oZzqw
ITbSA8ewuYvohQSAaa/RiMScnXZmhzHd4cWU+Usu1qv1T3ieyjdMgli7azkDBWoq
Ajv7/j57uuiDTQjfzSlaawyM3JGXWFUA7yfLY42aMlvO63W+aAmpJiBVMa64NHVM
8oNcX0tDdmNXklAgJc4f2TbEuUkZ3bCZh0Vi8qZ7iW4gOdzERPI4Z0oj6z5JNKzt
HZSRfGVZZDT4S8UEg1nM9aBsDsXj71K2tg1jElUxXkOh+2EsNMimD4YTs0ghC+y7
iwB95EmDP5xPqpUvy0QCbK5Os+AzPtzF0wPeCuT2x40VHa+SBcW0xhA0nKacgxt/
a/7gNhk9YQZgvtDYg4s460IxP1RnXTiFc1rip9GgV4iRpvZbM90A9b3f22GjBkMK
em4qMoGGdGnaZPMygomjNz17HNE5rN9ILk2h33mcI/XfQAddrN8eOblDOf9bMznC
2B1HPliZ7aed+GtCDmKHpN6blCqv2QO4AbIzlbAlUGvGP68SCwH1EjkiZKlXbJtU
ynS8jj5rWFNterb9YOcW8SZfrdEsSY9Dora39JMUyBEJfydKp8s=
=E+7g
-----END PGP SIGNATURE-----