EAP-TLS

An EAP method in which the client and the authentication server each prove their identity with a digital certificate, giving mutual authentication with no password to steal.

EAP-TLS is an authentication method carried by the Extensible Authentication Protocol, defined in RFC 5216 (2008) and updated for TLS 1.3 by RFC 9190. It runs a TLS handshake in which both sides present certificates: the authentication server proves itself to the client, and the client proves itself to the server. It is commonly used with IEEE 802.1X for wired port access and for enterprise Wi-Fi under WPA2 and WPA3.

Because no password is exchanged, there is nothing for an attacker to capture and crack offline, and a client that validates the server’s certificate is designed to refuse a fake network, which counters the evil twin attack. The cost is operational. Every client needs its own certificate, so the organisation has to run a public key infrastructure that issues, renews and revokes them. That burden is commonly the reason organisations choose PEAP instead, where only the server holds a certificate and the user proves identity with a password inside the protected tunnel.

Exam relevance: a scenario is likely to set strong mutual authentication for wireless or wired access against the effort of managing client certificates. Candidates are expected to recognise EAP-TLS as the certificate-on-both-sides option, and PEAP as the server-certificate-plus-password option.