[RADIATOR] EAP-TLS response encoding question

Markus Moeller huaraz at moeller.plus.com
Thu Jan 16 18:23:42 UTC 2020


Hi,

   I am using Radiator to authenticate wireless clients using EAP-TLS with a 
client cert. It works for most clients, but not all. I can see that Radiator 
is sending the server certificates chain and the client response i.e. 
Access-Request shown below creates a Reject

Code:       Access-Request       EAP-Message = 
<2><17><0><17><13><128><0><0><0><7><21><3><1><0><2><1><0>

Code:       Access-Reject

For a successful client I get the below after the server certificate chain 
was send i.e. the client sends the cert:

Code:       Access-Request       EAP-Message = 
<2><9><4><252><13><192><0><0><21>]<22><3><1><19><7><11><0><19><3><0><19><0><0><7><20>0<130><7><16>0<130><5><248><160><3><2><1><2><2><12><5><149><221><255><157>PZS)<<236><227>0<13><6><9>*<134>H<134><247><13><1><1><11><5><0>0`1<11>0<9><6><3>U<4><6><19><2>DE1<25>0<23><6><3>U<4><10><19><16>Company 
Services 
AG1<12>0<10><6><3>U<4><11><19><3>PKI1(0&<6><3>U<4><3><19><31>Company 
Services Device TEST CA 
130<30><23><13>200111014612Z<23><13>200711014612Z0<129><138>1<19>0<17><6><10><9><146>&<137><147><242>,d<1><25><22><3>com1<18>0<16><6><10><9><146>&<137><147><242>,d<1><25><22><2>company1<25>0<23><6><3>U<4><10><12><16>D


How can I interpret the response EAP-Message = 
<2><17><0><17><13><128><0><0><0><7><21><3><1><0><2><1><0> ?   I think <2> 
means it is a Request and <13> means EAP TLS,

Thank you
Markus 




More information about the radiator mailing list