A revision of EAP TLS that uses two phases:

  1. Setup a secure session by creating a tunnel from certificates stored on the server
  2. Authenticate the client’s credentials