RE: Upgrading to 3.2.10 Breaks EAP-TLS

Hector Rodriguez via Freeradius-Users <[email protected]> Fri, 12 Jun 2026 17:36:19 +0000
Newsgroups gmane.comp.freeradius.user
Message-ID <MN2PR01MB5984649E325D3651133601E8F3182@MN2PR01MB5984.prod.exchangelabs.com>
--===============6128289074461603228==
Content-Language: en-US
Content-Type: multipart/related;
	boundary="_004_MN2PR01MB5984649E325D3651133601E8F3182MN2PR01MB5984prod_";
	type="multipart/alternative"

--_004_MN2PR01MB5984649E325D3651133601E8F3182MN2PR01MB5984prod_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable



Community,
  It seems that I fixed my issue with EAP-TLS after the new update. In the =
code below you will see : "configurable_client_cert =3D yes" and "EAP-TLS-R=
equire-Client-Cert =3D yes" . If both are enabled and set to yes, it would =
cause conflict. It seems that I had to comment out "configurable_client_cer=
t =3D yes"  in order for EAP-TLS to work correctly. Based on the comment, i=
t seems that both "configurable_client_cert =3D yes" and "EAP-TLS-Require-C=
lient-Cert =3D yes" should work together, but it does not. I hope that the =
change I made is the correct one, which makes the server require a client c=
ert.

Within the EAP configs there is a section which states the following:
tls {
                #  Point to the common TLS configuration
                #
                tls =3D tls-common
                #  As part of checking a client certificate, the EAP-TLS
                #  sets some attributes such as TLS-Client-Cert-Common-Name=
. This
                #  virtual server has access to these attributes, and can
                #  be used to accept or reject the request.
                #
###             virtual_server =3D check-eap-tls
                #  You can control whether or not EAP-TLS requires a
                #  client certificate by setting
                #
##                      configurable_client_cert =3D yes
                #
                #  Once that setting has been changed, you can then set
                #
##                      EAP-TLS-Require-Client-Cert =3D yes
                #
                #  in the control items for a request, and the EAP-TLS
                #  module will not require a client certificate from
##                      EAP-TLS-Require-Client-Cert =3D yes
                #
[https://res.public.onecdn.static.microsoft/assets/bookwithme/misc/Calendar=
Person20px.png]<https://outlook.office.com/bookwithme/user/af4e411e9f384748=
[email protected]?anonymous&ismsaljsauthenabled&ep=3DbwmEmailSi=
gnature>
Book time to meet with me<https://outlook.office.com/bookwithme/user/af4e41=
[email protected]?anonymous&ismsaljsauthenabled&ep=3D=
bwmEmailSignature>

From: Hector Rodriguez <[email protected]>
Sent: Wednesday, June 10, 2026 11:31 AM
To: FreeRadius users mailing list <[email protected]>
Subject: Upgrading to 3.2.10 Breaks EAP-TLS

Community,

After upgrading to the latest and greatest, I have authentication issues ag=
ain with EAP-TLS. TLS handshake has no issues, but my Windows 11 client doe=
s not want to authenticate anymore. Certs were checked, no warning , succes=
sful handshakes.

Should I revert back 3.2.9 ? Everything worked in the last version, but rel=
ease notes stated there were memory leak issues.





[cid:[email protected]]<https://outlook.office.com/bookwithme/=
user/[email protected]?anonymous&ismsaljsauthen=
abled&ep=3DbwmEmailSignature>
Book time to meet with me<https://outlook.office.com/bookwithme/user/af4e41=
[email protected]?anonymous&ismsaljsauthenabled&ep=3D=
bwmEmailSignature>

-- CONFIDENTIALITY NOTICE: This email and any files transmitted with it are=
 confidential and are intended solely for the use of the individual or enti=
ty to which they are addressed. This communication may contain material pro=
tected by HIPAA legislation (45 CFR, Parts 160 & 164) or by 42 CFR Part 2. =
If you are not the intended recipient, be advised that you have received th=
is email in error and that any use, dissemination, forwarding, printing or =
copying of this email is strictly prohibited. If you have received this ema=
il in error, please notify the sender by reply email and destroy all copies=
 of the original message.=20

--_004_MN2PR01MB5984649E325D3651133601E8F3182MN2PR01MB5984prod_
Content-Type: image/png; name="image001.png"
Content-Description: image001.png
Content-Disposition: inline; filename="image001.png"; size=528;
	creation-date="Fri, 12 Jun 2026 17:36:18 GMT";
	modification-date="Fri, 12 Jun 2026 17:36:18 GMT"
Content-ID: <[email protected]>
Content-Transfer-Encoding: base64

iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAAAXNSR0IArs4c6QAAAcpJREFUOE9j
ZAABr6aJDHqhuQwMDIxgPrHg19d3DLP91Bk+P3sD08IIN2x1hjPDy7NXiDWL4T8nM0NA33wGWRMP
hg5NJgYGhv8gvYwMFdf/MYAMu3twP9GGISssv/qLYVdzMsP5FYthBv5nmO2pyfDzzVuyDEw/eJ3h
xNyJDEenNSMMJMskJE2Hp9YxHJ2CZOBUM1GGz5/hAUuS+UVnXjOcXDCJygbOm4TqZUpcGDJjJcPz
S1eoYyAvrzDD58/vGRgY/iHSYcX1/wykupBXWpghe89reEbY0RjNcGHFMkQsk2pgwYkXDBz84iiR
16EJzmWghE26C8uv/mZgZGJBM5AZ5HXyDPRo7GMwCCuEG/jj40uGCRYS5LsQpNM6q4TBOLqE4emF
gwxrs8NRI2WynSTD19cvSErQOBQzMhSdecvw8vophqWxngQNBCWTrBMvMMIPpnF7dQQjA6+UCEP2
3tcM//7+Zvjx8QNOQydZizFk7bvNwCepgs9iWIHKyGAYEcPALaQEUQwq3mBplQmi5siUBoa0bRcZ
hBT18Bj4n7QSWlhGmiF19xOcBh6aVEyagSCTQEEUNf8Ag6CcFjyn/Pz8hmF9cQjDg8MHAaiKxp0e
iZJ4AAAAAElFTkSuQmCC

--_004_MN2PR01MB5984649E325D3651133601E8F3182MN2PR01MB5984prod_--

--===============6128289074461603228==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

--===============6128289074461603228==--