crypto_mod_exp() is needed for both EAP-FAST and WPS.
The internal TLS implementation can now use both PKCS #1 RSA private key and PKCS #8 encapsulated RSA private key. PKCS #8 encrypted private key is not yet supported.