[PATCH] eap: disable EAP-TTLS CHAP phase2 on server when CONFIG_FIPS is set

Jouni Malinen j at w1.fi
Mon Feb 9 12:19:30 PST 2026


On Mon, Feb 09, 2026 at 01:50:19PM +0530, Chaitanya Tata wrote:
> Mirror the peer side: reject CHAP in eap_ttls_process_phase2_chap()
> with an error and FAILURE state when building with CONFIG_FIPS, since
> CHAP uses MD5 which is not FIPS-approved.

Thanks, applied.
 
-- 
Jouni Malinen                                            PGP id EFC895FA



More information about the Hostap mailing list