RE: Upgrading to 3.2.10 Breaks EAP-TLS
Hector Rodriguez via Freeradius-Users <[email protected]> Fri, 12 Jun 2026 17:36:19 +0000
| Newsgroups | gmane.comp.freeradius.user |
|---|---|
| Message-ID | <MN2PR01MB5984649E325D3651133601E8F3182@MN2PR01MB5984.prod.exchangelabs.com> |
--===============6128289074461603228==
Content-Language: en-US
Content-Type: multipart/related;
boundary="_004_MN2PR01MB5984649E325D3651133601E8F3182MN2PR01MB5984prod_";
type="multipart/alternative"
--_004_MN2PR01MB5984649E325D3651133601E8F3182MN2PR01MB5984prod_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Community,
It seems that I fixed my issue with EAP-TLS after the new update. In the =
code below you will see : "configurable_client_cert =3D yes" and "EAP-TLS-R=
equire-Client-Cert =3D yes" . If both are enabled and set to yes, it would =
cause conflict. It seems that I had to comment out "configurable_client_cer=
t =3D yes" in order for EAP-TLS to work correctly. Based on the comment, i=
t seems that both "configurable_client_cert =3D yes" and "EAP-TLS-Require-C=
lient-Cert =3D yes" should work together, but it does not. I hope that the =
change I made is the correct one, which makes the server require a client c=
ert.
Within the EAP configs there is a section which states the following:
tls {
# Point to the common TLS configuration
#
tls =3D tls-common
# As part of checking a client certificate, the EAP-TLS
# sets some attributes such as TLS-Client-Cert-Common-Name=
. This
# virtual server has access to these attributes, and can
# be used to accept or reject the request.
#
### virtual_server =3D check-eap-tls
# You can control whether or not EAP-TLS requires a
# client certificate by setting
#
## configurable_client_cert =3D yes
#
# Once that setting has been changed, you can then set
#
## EAP-TLS-Require-Client-Cert =3D yes
#
# in the control items for a request, and the EAP-TLS
# module will not require a client certificate from
## EAP-TLS-Require-Client-Cert =3D yes
#
[https://res.public.onecdn.static.microsoft/assets/bookwithme/misc/Calendar=
Person20px.png]<https://outlook.office.com/bookwithme/user/af4e411e9f384748=
[email protected]?anonymous&ismsaljsauthenabled&ep=3DbwmEmailSi=
gnature>
Book time to meet with me<https://outlook.office.com/bookwithme/user/af4e41=
[email protected]?anonymous&ismsaljsauthenabled&ep=3D=
bwmEmailSignature>
From: Hector Rodriguez <[email protected]>
Sent: Wednesday, June 10, 2026 11:31 AM
To: FreeRadius users mailing list <[email protected]>
Subject: Upgrading to 3.2.10 Breaks EAP-TLS
Community,
After upgrading to the latest and greatest, I have authentication issues ag=
ain with EAP-TLS. TLS handshake has no issues, but my Windows 11 client doe=
s not want to authenticate anymore. Certs were checked, no warning , succes=
sful handshakes.
Should I revert back 3.2.9 ? Everything worked in the last version, but rel=
ease notes stated there were memory leak issues.
[cid:[email protected]]<https://outlook.office.com/bookwithme/=
user/[email protected]?anonymous&ismsaljsauthen=
abled&ep=3DbwmEmailSignature>
Book time to meet with me<https://outlook.office.com/bookwithme/user/af4e41=
[email protected]?anonymous&ismsaljsauthenabled&ep=3D=
bwmEmailSignature>
-- CONFIDENTIALITY NOTICE: This email and any files transmitted with it are=
confidential and are intended solely for the use of the individual or enti=
ty to which they are addressed. This communication may contain material pro=
tected by HIPAA legislation (45 CFR, Parts 160 & 164) or by 42 CFR Part 2. =
If you are not the intended recipient, be advised that you have received th=
is email in error and that any use, dissemination, forwarding, printing or =
copying of this email is strictly prohibited. If you have received this ema=
il in error, please notify the sender by reply email and destroy all copies=
of the original message.=20
--_004_MN2PR01MB5984649E325D3651133601E8F3182MN2PR01MB5984prod_
Content-Type: image/png; name="image001.png"
Content-Description: image001.png
Content-Disposition: inline; filename="image001.png"; size=528;
creation-date="Fri, 12 Jun 2026 17:36:18 GMT";
modification-date="Fri, 12 Jun 2026 17:36:18 GMT"
Content-ID: <[email protected]>
Content-Transfer-Encoding: base64
iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAAAXNSR0IArs4c6QAAAcpJREFUOE9j
ZAABr6aJDHqhuQwMDIxgPrHg19d3DLP91Bk+P3sD08IIN2x1hjPDy7NXiDWL4T8nM0NA33wGWRMP
hg5NJgYGhv8gvYwMFdf/MYAMu3twP9GGISssv/qLYVdzMsP5FYthBv5nmO2pyfDzzVuyDEw/eJ3h
xNyJDEenNSMMJMskJE2Hp9YxHJ2CZOBUM1GGz5/hAUuS+UVnXjOcXDCJygbOm4TqZUpcGDJjJcPz
S1eoYyAvrzDD58/vGRgY/iHSYcX1/wykupBXWpghe89reEbY0RjNcGHFMkQsk2pgwYkXDBz84iiR
16EJzmWghE26C8uv/mZgZGJBM5AZ5HXyDPRo7GMwCCuEG/jj40uGCRYS5LsQpNM6q4TBOLqE4emF
gwxrs8NRI2WynSTD19cvSErQOBQzMhSdecvw8vophqWxngQNBCWTrBMvMMIPpnF7dQQjA6+UCEP2
3tcM//7+Zvjx8QNOQydZizFk7bvNwCepgs9iWIHKyGAYEcPALaQEUQwq3mBplQmi5siUBoa0bRcZ
hBT18Bj4n7QSWlhGmiF19xOcBh6aVEyagSCTQEEUNf8Ag6CcFjyn/Pz8hmF9cQjDg8MHAaiKxp0e
iZJ4AAAAAElFTkSuQmCC
--_004_MN2PR01MB5984649E325D3651133601E8F3182MN2PR01MB5984prod_--
--===============6128289074461603228==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
--===============6128289074461603228==--