An EAP method (RFC 5281) that, like PEAP, establishes a server-authenticated TLS tunnel and then carries an inner authentication exchange. Unlike PEAP it can tunnel a wide range of inner methods, including plain PAP, which lets the RADIUS server validate passwords against stores that only hold non-reversible hashes. The security of the inner credential rests entirely on the client validating the server certificate correctly.