An assessor sees TLS alerts during EAP on a city Enterprise SSID. How should those clues be interpreted under rules of engagement?
Select an answer to reveal the explanation.
Short Explanation
TLS alerts in EAP are yellow flags: maybe the laptop trusts the wrong CA, maybe something is intermediating. Investigate under RoE—do not jump to PMK paste sites or open-SSID conclusions.
Full Explanation
TLS alert messages during EAP often signal certificate trust mismatches, profile errors, or possible interception by an unexpected server certificate. Assessors should investigate carefully within authorization boundaries rather than assuming PMK leakage, open authentication fallback, or WPS as the sole explanation. Correlate with client trust-store settings and known-good AAA certificates before drawing conclusions.