This command test aaa group allows you to do a sanity check on your root AP configuration so you don't spend all day troubleshooting the non-root AP configuration if that isn't the problem.
ROOT#test aaa group rad_eap admin admin new
Trying to authenticate with Servergroup rad_eap
User successfully authenticated
Now at least I know my problem *is* with my non-root AP configuration.
You'll also want to turn on 'debug radius' on the root AP so you can see all the RADIUS messages pertaining to the bridge link authentication attempts.
Keep in mind - 99.9% of the information I put on this site is for me so I can find it easier later! :-)