<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Freeradius eap_peap: TLS Alert read:fatal:internal error when using CA cert]]></title><description><![CDATA[<p dir="auto">I wanted to configure my Access point to use radius authentication with WPA Enterprise. I am using PEAP MSCHAPv2 and connected with an android device.</p>
<p dir="auto">The whole setup works just fine if I select "Do Not validate" for the CA Certificate.</p>
<p dir="auto">I get the error "eap_peap: TLS Alert read:fatal:internal error" when using the freeradius generated CA Certificate that I exported from pfsense.<br />
I exported the freeradius-ca.crt and imported it into my phone as a wifi ca certificate. But when I select it when joining the network, it just gives me that error.</p>
<p dir="auto">I thought I export the freeradius CA cert and use that as the verification cert for the wpa enterprise connection. Is this not what I am supposed to do? I don't want to leave the ca cert option in my phone as unverified.</p>
]]></description><link>https://forum.netgate.com/topic/164788/freeradius-eap_peap-tls-alert-read-fatal-internal-error-when-using-ca-cert</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Jul 2026 13:57:15 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/164788.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 30 Jun 2021 21:24:03 GMT</pubDate><ttl>60</ttl></channel></rss>