>The interesting thing is this that this only occurs on eap-tls
Perhaps they haven't been configured to trust the root CA certficate.
Perhaps they require a minimum of a SHA2 signed root CA certificate and it is only SHA1 signed.
>what message would be sent after a radius accept message as I would expect that to be final message
Hard to say. Could be COA. Could be an additional or secondary challenge. Need to check client log to see what it is saying.