Home / Companies / Authentik Security / Blog / Post Details
Content Deep Dive

Implementing EAP, EAP-TLS and more (mostly) from scratch

Blog post from Authentik Security

Post Details
Date Published
Author
Jens Langhammer
Word Count
3,936
Company Posts That Month
1
Language
English
Hacker News Points
-
Post removed?
No
Summary

Authentik is an open-source identity provider seeking to replace other platforms like Okta and Keycloak by integrating functionalities into a single platform. The blog post discusses the author's journey of implementing the Extensible Authentication Protocol (EAP) from scratch, highlighting challenges and learning experiences over multiple attempts. The motivation for this endeavor was to integrate EAP with authentik, which has an existing RADIUS server known for its basic, yet insecure, PAP authentication. The author elaborates on the intricacies of RADIUS and EAP protocols, the challenges faced in making them secure, and the quest to implement EAP-TLS, PEAP, and MSCHAPv2 protocols using Go, often addressing protocol nuances and limitations. The narrative includes personal insights into handling protocol parsing, testing with tools like Wireshark, and overcoming hurdles related to data encryption and multi-protocol negotiation. Despite the complexities and initially steep learning curve, the project was driven by a combination of professional curiosity and the aspiration to extend authentik’s functionality, culminating in the development of a standalone library for broader use.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 1,475 175 87 +6%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.