How are encryption keys derived between NAS and Supplicant for 802.1x when using EAP as authentication method?

I’m wondering how key negotiation works for WPA2 Enterprise where a clear text protocol like EAP is used to authenticate the user. All the info I was able to find suggests that EAP is an inherently insecure authentication met… Continue reading How are encryption keys derived between NAS and Supplicant for 802.1x when using EAP as authentication method?

Is it possible for an 802.1x network (PEAP/MSCHAPv2) to have no certificate?

Is it possible for an 802.1x network (PEAP/MSCHAPv2) to have no certificate (CA, user, or otherwise)?

If so, what are the security implications?

The reason I ask is: I’m regularly connecting to a particular organization’s … Continue reading Is it possible for an 802.1x network (PEAP/MSCHAPv2) to have no certificate?

WPA2-PSK / EAP-PEAP MSCHAPv2: Do user-name or passphrase or SSID have any official restrictions?

I am testing a new WLAN client mode of a device. So that the device can handle preferably every possible case, I have to know which characters and lengths are generally allowed in the SSID, user-name and passphrase.

So are t… Continue reading WPA2-PSK / EAP-PEAP MSCHAPv2: Do user-name or passphrase or SSID have any official restrictions?

Problem with configuring PEAP to only accept users with client certificate. (freeradius)

I’m currently trying to configure PEAP.

I had no problems configuring it without the use of client certificates.
But I want to only accept people who have a valid cert. However,
the clients can still connect without any pr… Continue reading Problem with configuring PEAP to only accept users with client certificate. (freeradius)

Problem with configuring PEAP to only accept users with client certificate. (freeradius)

I’m currently trying to configure PEAP.

I had no problems configuring it without the use of client certificates.
But I want to only accept people who have a valid cert. However,
the clients can still connect without any pr… Continue reading Problem with configuring PEAP to only accept users with client certificate. (freeradius)