Supported protocols | Admin Panel - RADIUS

Supported Protocols

EAP-TTLS Protocol

Overview

Extensible Authentication Protocol Tunneled Transport Layer Security (EAP-TTLS) is a credential-based authentication protocol that establishes a secure, encrypted tunnel between the client device and the RADIUS server. The user is then authenticated within this tunnel using traditional credentials (username and password). Although EAP-TTLS is supported, we recommend using EAP-TLS wherever possible because it provides stronger, certificate-based authentication.

How does EAP-TTLS work ?

EAP-TTLS uses a two-phase authentication process: an outer TLS tunnel and an inner authentication exchange.

During authentication:

  1. The RADIUS server presents its certificate to the client device.
  2. The client validates the server's certificate and establishes a secure encrypted TLS tunnel.
  3. Within this encrypted tunnel, the client submits its credentials (username and password) using an inner authentication method called the Password Authentication Protocol (PAP).
  4. The RADIUS server validates these credentials against the user's record.
  5. Network access is granted only after the credentials are successfully validated inside the secure tunnel.
Notes
If TOTP is enabled as your MFA, you must append your 6-digit authenticator code with your password separated with a colon (e.g., YourPassword:123456 ). This must be provided in the password field.
Since only the server presents a certificate, client devices do not require individual certificates or private keys, hence EAP-TTLS simplifying deployment and device onboarding. However, user credentials must still be associated with valid user accounts in Zoho One.

Zoho One (RADIUS server) validates the user's credentials against the corresponding device user account and ensures the username submitted through the encrypted tunnel matches an existing, active user in Zoho One. The Wi-Fi connection will fail if the credentials are invalid or the account is inactive.

EAP-TTLS requires:

  1. A RADIUS server configured with a valid server certificate issued by a trusted Certificate Authority (CA).
  2. Valid Zoho One user credentials (username and password) for each user.
  3. Client devices configured to use tunneled authentication with the appropriate inner authentication method.

EAP-TLS Protocol

Overview

Extensible Authentication Protocol Transport Layer Security (EAP-TLS) is a certificate-based authentication protocol that uses digital certificates to authenticate users and devices on wireless networks. Unlike password-based authentication, EAP-TLS uses digital certificates to verify both the client device and the RADIUS server before granting network access.

How does EAP-TLS works?

EAP-TLS is a mutual authentication protocol that uses digital certificates instead of passwords.

During authentication:

  1. The client device presents its certificate to the RADIUS server.
  2. The RADIUS server presents its certificate to the client.
  3. Both certificates are successfully validated.
  4. Network access is granted only after both certificates are successfully validated.
Zoho One validates the client certificate (also known as user certificate) against the uploaded CA certificate and verifies that the email address in the certificate's Subject Alternative Name (SAN) exactly matches the user's email address in Zoho One.

EAP-TLS requires:

  1. A trusted Certificate Authority (CA)
  2. A client certificate and private key for each user's device
  3. A RADIUS server configured to trust the CA certificate
  4. Client devices configured to use certificate-based authentication
Notes
The email address in the certificate's Subject Alternative Name (SAN) must exactly match the user's email address in Zoho One. Authentication fails if they do not match.

Why use EAP-TLS?

EAP-TLS offers several security and operational advantages:
  1. Stronger Security: Certificates are harder to compromise than passwords, making them resistant to common attacks like phishing and credential theft
  2. Better User Experience: No passwords to remember or reset, reducing IT support tickets
  3. Scalability: Ideal for large organizations managing hundreds or thousands of devices
  4. Multi-Device Support: Works seamlessly across Windows, macOS, Linux, iOS, and Android devices

Why use EAP-TLS instead of EAP-TTLS?

Factors
EAP-TLS (Recommended)
EAP-TTLS
Authentication methodCertificate-basedPassword-based
Credential theft riskVery lowModerate
Password managementNoneRequires password reset, expiry policies, etc.
Vulnerability to weak or reused passwordsNot applicablePossible, since authentication is credential-based
Deployment effortHigher (requires client certificate)Lower

While EAP-TTLS provides a reasonable security improvement over plain passwords by encrypting them, it still relies on passwords. Passwords have some well-known weaknesses:
  1. They can be phished -tricked out of a user through fake emails or websites.
  2. They can be guessed, in case they are weak or commonly used.
  3. They can be reused across multiple accounts, so if one gets leaked, then the other systems get affected too.
EAP-TLS avoids all these problems by not relying on passwords. Instead, it used digital certificates that are specific to every device. This makes EAP-TLS much stronger option for keeping your network secure.