PMK or PTK instead of PSK in radius response when wpa_psk_radius=2 or wpa_psk_radius=3

Daniel S timeport0 at
Mon Dec 4 13:22:11 PST 2023

I'm new here so please go easy on me if this is a dumb question.

Is there a way(or why you shouldn't/couldn't) to provide the
PMK(perhaps via MS-MPPE-Recv-Key) instead of a cleartext
Tunnel-Password as a radius response?

It would solve the less-than-ideal situation of storing and
transmitting PSKs in cleartext or reversible encryption.

I tried as a test just sending the PMK or PTK back as MS-MPPE-Recv-Key
as in EAP but seems that didn't do the trick.


More information about the Hostap mailing list