Getting TLS-related information about a PEAP connection from wpa_supplicant

Arsen Arsenović arsen at aarsen.me
Sun Nov 26 01:52:54 PST 2023


Morning,

I'm trying to debug a connection failure from some systems onto our
PEAP-connected network.

I've identified that the cause of the issue is that OpenSSL 3, present
some of the systems that fail to connect, has a higher default SECLEVEL
and/or minimum protocol version than previous versions.

I have reason to suspect that our PEAP infrastructure uses severely
outdated TLS, and so that OpenSSL is acting correctly, and would like to
confirm this suspicion and submit an analysis and request to upgrade to
our network administrators.

Can I fetch information about the PEAP TLS session (TLS version, ciphers
in use, ...) from wpa_supplicant?

TIA, have a lovely day!
-- 
Arsen Arsenović
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 251 bytes
Desc: not available
URL: <http://lists.infradead.org/pipermail/hostap/attachments/20231126/3ac29bec/attachment.sig>


More information about the Hostap mailing list