EAP-TLS

term

networkingsecurity

Wireless and wired authentication using certificates on both sides, rather than a shared password.

It is the strongest common option because there is no passphrase to share, post or take to a former employer, and each device authenticates as itself. The cost is a certificate lifecycle for every endpoint, which is the reason deployments stall. The frequent misconfiguration is worth naming: a client that does not validate the server's certificate will happily authenticate to an impostor, which turns the strongest option into a credential-harvesting opportunity.

Also known as: 802.1x

All glossary entries