Certificate Compatibility - Successful Network Entry

Ben Wiechman wiechman.lists at gmail.com
Thu Mar 31 19:00:23 CEST 2011

While testing authentication with a Motorola Canopy AP I noticed that
I was getting a Certificate Compatibility warning. I understand why
this typically happens.

What struck me as odd is that network entry still succeeds.

Just to verify nothing really out of the ordinary was happening I
verified the CA certificate that the server was using and re-imported
this certificate onto the device, but still receive the same
notification and still the same successful network entry.

Does FR only use the State attribute to determine if the previous
session didn't complete? The reason I ask is that the State attribute
sent by FR in the Access-Challenge, and then echoed in the following
Access-Request are the same, but the warning appears to truncate the

Sending Access-Challenge of id 0 to port 1273
       User-Name = "anonymous"
       EAP-Message =
       Message-Authenticator = 0x00000000000000000000000000000000
       State = 0xc2539648c75483204cf5c8028cb0d506
Finished request 9.
Going to the next request
Waking up in 2.9 seconds.
rad_recv: Access-Request packet from host port 1273, id=0, length=99
Cleaning up request 9 ID 0 with timestamp +54
WARNING: !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
WARNING: !! EAP session for state 0xc2539648c7548320 did not finish!
WARNING: !! Please read http://wiki.freeradius.org/Certificate_Compatibility
WARNING: !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
       User-Name = "anonymous"
       State = 0xc2539648c75483204cf5c8028cb0d506
       NAS-IP-Address =
       NAS-Port = 5
       NAS-Port-Type = Wireless-802.11
       Framed-MTU = 1020
       EAP-Message = 0x020700061500
       Message-Authenticator = 0x333490df7d6b149bd645a83de291660e

This appears to be a client side issue, but I would like to confirm
that this is the case. I'm a little confused as to what is really
happening here.

