WAP-Enterprise 802.11x Certificate Revoked but device can still Auth
We have freeRadius running and working with TLS Certificate Auth. When we revoke the certificate the client can still acces the network even after rebooting the freeRadius .
Rebooting the access point resolves this and clients get rejected due to certificate revoked.
We have all cacheing disabled in freeRadius and have been informed that if freeRadius reboots then the AP is doing the cacheing.
How can we resolve this?
Research show the AP is holding on to some sort of PMKSA cache.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Hi @SHA2
Thanks for posting here.
Is the 802.11r (Fast BSS Transition) feature enabled?
If your AP has 802.11r enabled, terminals may skip the full EAP authentication process with the FreeRADIUS server during reassociation and instead use cached PMKSA keys to establish a quick connection.
Protocol Mechanism:
The normal EAP-TLS authentication process includes steps such as Auth, Assoc, RADIUS interaction, and EAPOL key negotiation. However, when 802.11r is enabled, terminals only need to complete Auth and Assoc to quickly connect, bypassing reauthentication with the RADIUS server. As a result, even if the certificate is revoked, the AP may still allow terminal access using cached PMKSA keys.
If 802.11r is not enabled, please let us know.
- Copy Link
- Report Inappropriate Content
Hi @SHA2
Thanks for posting here.
Is the 802.11r (Fast BSS Transition) feature enabled?
If your AP has 802.11r enabled, terminals may skip the full EAP authentication process with the FreeRADIUS server during reassociation and instead use cached PMKSA keys to establish a quick connection.
Protocol Mechanism:
The normal EAP-TLS authentication process includes steps such as Auth, Assoc, RADIUS interaction, and EAPOL key negotiation. However, when 802.11r is enabled, terminals only need to complete Auth and Assoc to quickly connect, bypassing reauthentication with the RADIUS server. As a result, even if the certificate is revoked, the AP may still allow terminal access using cached PMKSA keys.
If 802.11r is not enabled, please let us know.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 143
Replies: 3
Voters 0
No one has voted for it yet.

