This is a bit more complex topic to explain via this post. A short summary.
802.1x with certificate based authentication can result in larger data frames and hence fragmentation. This because the certificate size itself is larger then >1500 bytes. When the IP MTU between the access switch (management IP of the switch) is higher then 1500 bytes the switch will transmit packet larger frames during RADIUS authentication.
I've attached a presentation about this topic. Please check from slide 30.
Which switches are you using? On the Aruba CX and AOS-S switches it easy the configuration fragmentation for EAP-TLS.
For CX switches
aaa authentication port-access dot1x authenticator eap-tls-fragment towards-server <mtu>
For AOS-S switches
aaa port-access authenticator eap-tls-fragment towards-server <mtu>
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125
------------------------------