Hi artur,
> freeradius NEVER sends the EAPOL Key message. also the sending of an > encapsulated EAP-Success is without any interest. The AP only wants to > see the Access-Accept and that is what freeradius is responsible for. Yes that's true. EAPOL Key messages are sent by AP. But as freeradius is sending Access-Accept in this case so AP is sending EAP-Success message. But the strange thing is why it is sending Access-Accept message without checking client certificate. > why did you set the User-Password? you do not need any user password. > just comment out both lines and try again. > (also why did you explicitly set the Auth-Type? the eap.conf *shouts* > that you should not do that.) I am very new in freeradius. I am not sure here what should I use/set as Auth-Type. Can you please suggest me? Also I will check EAP-TLS without User-Password entry against "Administrator" login by tommorrow. Regards Ankan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html