>My initial question is: "how to configure eap.conf tls section to load a >multi-level certificate hierarchy (CA bundle)" ? >
The same as for a single CA. You have configured that properly. You said that server worked with a single CA but segfaulted when you replaced it with that bundle. I would suspect that there is something wrong with that certificate bundle. You should still follow instructions in doc/bugs to make sure that bundle is the problem. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html