PEAP

Protected Extensible Authentication Protocol

An EAP method that first builds a server-authenticated TLS tunnel, then runs an inner authentication method — almost always MSCHAPv2 with a username and password — inside it. Only the server needs a certificate, which makes PEAP simpler to deploy than EAP-TLS but leaves it exposed to password theft and evil-twin attacks when clients do not strictly validate the server certificate. Its inner MSCHAPv2 exchange depends on NTLM-style password hashes, tying it to Active Directory-style credential stores.

An unhandled error has occurred. Reload 🗙