New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

EAP-FAST and TLS 1.2 #1756

alandekok opened this Issue Sep 25, 2016 · 0 comments


None yet
1 participant

alandekok commented Sep 25, 2016

Issue type

  • Feature request.

Defect/Feature description

EAP-FAST requires disable_tlsv1_2 = yes, because the PRF label used in FAST is forbidden by the RFCs. And, the PRF function in TLS 1.2 is different from the PRF function in earlier versions of TLS.

The solution is to re-implement the TLS 1.2 PRF function in FreeRADIUS, and then make EAP-FAST use it. For example code, see tls_connection_prf() in the hostap repo.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment