Proxy PEAP to one Radius Server - EAP-TLS to another Radius Server

Phil Mayers p.mayers at imperial.ac.uk
Thu Aug 13 16:28:09 CEST 2015


On 13/08/15 14:53, Arran Cudbard-Bell wrote:

> Is an Identity-Response definitely required to start PEAP/EAP-TLS
> sessions?  Doesn't seem like there's a good reason for that
> limitation if so.  Even if a RFC required it, there's still no good
> reason to enforce it that I can see?

It's not a requirement I think, and IIRC FreeRADIUS contains code to 
handle this case. But maybe other servers don't; whether this is a 
problem will depend on behaviour of the upstream I guess.


More information about the Freeradius-Users mailing list