openwrt-pf/package/network/config
Hauke Mehrtens 0cdf956ee1 wifi-scripts: ucode: fix EAP phase2 authentication method
The supplicant config generator emitted the phase2 directive as
phase2="auth=${auth}" for every PEAP/TTLS/FAST configuration. That is
wrong whenever the configured inner method is an EAP method: for
auth='EAP-MSCHAPV2' it produced phase2="auth=EAP-MSCHAPV2", which
wpa_supplicant rejects with:

  TLS: Unsupported Phase2 EAP method 'EAP-MSCHAPV2'

breaking WPA-Enterprise clients that use an EAP inner method.

Mirror the shell config generator (hostapd.sh): strip the "EAP-" prefix
and pick the phase2 prefix from the method type, i.e. "autheap=" for a
tunneled EAP method with TTLS and "auth=" for a non-EAP method or a
full "auth=..." spec provided by the user.

Fixes: https://github.com/openwrt/openwrt/issues/24086
Fixes: c92ded2f6e ("wifi-scripts: fix EAP STA support in supplicant config generation")
Assisted-by: Claude:claude-opus-4-8
Link: https://github.com/openwrt/openwrt/pull/24088
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2026-07-07 01:50:56 +02:00
..
firewall firewall: change synflood_protect option name 2026-01-24 21:33:15 +01:00
firewall4 firewall4: prefer over firewall as dependency 2026-03-10 00:47:21 +01:00
gre
ipip
ltq-adsl-app treewide: remove lantiq dot com URL 2026-01-02 18:07:02 +01:00
ltq-vdsl-vr9-app treewide: remove lantiq dot com URL 2026-01-02 18:07:02 +01:00
ltq-vdsl-vr11-app treewide: remove lantiq dot com URL 2026-01-02 18:07:02 +01:00
netifd netifd: expose udhcpc timeout/retry/tryagain UCI options in dhcp.sh 2026-06-24 11:21:28 +02:00
qos-scripts
qosify qosify: update to Git HEAD (2026-06-22) 2026-07-01 13:15:44 +02:00
soloscli treewide: switch to HTTPS URL 2026-01-02 18:07:02 +01:00
swconfig
vti
vxlan
wifi-scripts wifi-scripts: ucode: fix EAP phase2 authentication method 2026-07-07 01:50:56 +02:00
xfrm