- Home
- WiFi Glossary
- EAP-TLS
What is EAP-TLS?
Definition
EAP-TLS, the Extensible Authentication Protocol with Transport Layer Security, is the most secure 802.1X authentication method. The client device and the RADIUS server each present an X.509 certificate and validate the other’s, so no password or shared secret is ever sent. It is the default method for passwordless WiFi.
EAP-TLS explained
EAP-TLS is defined in RFC 5216. During the handshake, each side checks that the other’s certificate was issued by a trusted certificate authority and has not expired or been revoked. Neither the device nor the network gains trust until both checks pass, which is why the method is described as mutual authentication.
Removing the password removes the attacks that target it: phishing, credential theft and brute-force guessing. That is why EAP-TLS is recommended for regulated environments working to PCI DSS, HIPAA or ISO 27001, and required for WPA3-Enterprise in its 192-bit mode. Password-based methods such as PEAP-MSCHAPv2 are easier to start with but carry those risks.
The cost is certificate management. EAP-TLS needs a public key infrastructure (PKI) to issue, renew and revoke certificates. On managed fleets, an MDM platform such as Microsoft Intune or Jamf distributes certificates automatically, often through SCEP, and devices then connect with no user interaction. Unmanaged devices need an onboarding step to receive their certificate.
Need more than a definition?
Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.