EAP-FAST and TLS 1.2 #1756

alandekok opened this Issue Sep 25, 2016 · 0 comments


None yet

1 participant


Issue type

  • Feature request.

Defect/Feature description

EAP-FAST requires disable_tlsv1_2 = yes, because the PRF label used in FAST is forbidden by the RFCs. And, the PRF function in TLS 1.2 is different from the PRF function in earlier versions of TLS.

The solution is to re-implement the TLS 1.2 PRF function in FreeRADIUS, and then make EAP-FAST use it. For example code, see tls_connection_prf() in the hostap repo.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment