No full certificate chain in EAP in 3.2.7

Dave Wang <[email protected]> Mon, 29 Jun 2026 16:56:31 -0700
Newsgroups gmane.comp.freeradius.user
Message-ID <CAKCW7owQn6xdoJBJiCZTsiBED+=E8UZ_82vEka9HUwz=PrHz=A@mail.gmail.com>
Hi there,

Recently I upgraded from freeradius 3.0.26 (with openssl 3.0.20) to
3.2.7/3.2.8, (with openssl 3.5.0), and I noticed that the server does not
send the full certificate chain to the EAP client anymore.

The server certificate has a chained structure like cert->intermediate
CA2->intermediate CA1->root CA, and I am relying on the auto_chain and the
ca_path to construct the chain on the freeradius side.

Now it only sends the server_certificate + intermediate CA2, but previously
it sent all *four* certificates. Is this a known issue?


Regards,
Dave
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html