Questions for FIPS certification

Michael Kurecka wpi.hostapd
Wed Jul 1 05:24:31 PDT 2009

We are in the process of developing an AP/Client for FIPS certification. The
authentication methods used for EAP are at the most, TLS, TTLS and PEAP
(MSCHAPv2). I've been asked some questions concerning this and was hoping
this forum might be able to better provide them.

1) What TLS, TTLS and PEAP cipher suites are supported?

2) Is client authentication performed during TLS (Part 1 of PEAP) ?

3) Is it possible to disable PEAPv1 and allow only PEAPv2, and if so how
