Certificate validation time

2010-07-23 Thread _Stefan_H
Hi, I'm using freeradius 2.1.1 and i created my certificates with the makefile and the config-files. Is it possible to rise the time the cerficate is valid, because if i change the entrys default_days and default_crl_days in the ca.cnf to an higher value, nothing happens after I recreat the

Re: Radius Attribute -- Authenticator IP Adress

2010-04-22 Thread _Stefan_H
Alan DeKok-2 wrote: _Stefan_H wrote: Hi, I thought that my Access-Point is able to handle VLAN-Attributes like my Switch but I was wrong. I don't want to tell the whole story. Is there an attribute which returns the authenticator IP-Address? Packet-Src-IP-Address Thanks

Radius Attribute -- Authenticator IP Adress

2010-04-21 Thread _Stefan_H
Hi, I thought that my Access-Point is able to handle VLAN-Attributes like my Switch but I was wrong. I don't want to tell the whole story. Is there an attribute which returns the authenticator IP-Address? For instance: The Access-Point has the IP-Adress 192.168.10.254 and the default rule in

RE: Radius Attribute -- Authenticator IP Adress

2010-04-21 Thread _Stefan_H
I configured 2 SSIDs on my AccessPoint one for normal members and one for administrators each is on a different VLAN. Now to the problem, i have 2 DEFAULT rules in my users-file , for the administrators i use the ldap-group thing that no normal member will be put in the administrator VLAN but

Re: EAP-TLS - OpenLDAP - UID Check

2010-01-27 Thread _Stefan_H
Alan DeKok-2 wrote: EAP-TLS does authentication by checking the certificate, not the user name. If you want the LDAP module to reject users who aren't in LDAP, edit raddb/sites-enabled/default, the authorize section. Change the line saying ldap to: ldap {

EAP-TLS - OpenLDAP - UID Check

2010-01-26 Thread _Stefan_H
Hello, due to a typing error i realized that there is a mistake at my configuration, the eap-tls is working fine but it doesn't matter what name is written in the certificate, ldap is returning not found but the user is always accepted. I looked at the ldap module for an identity check but i

Re: Problem with EAP-TLS, please give me a hint

2009-12-05 Thread _Stefan_H
tnt-5 wrote: client.crt: client.csr ca.key ca.pem index.txt serial openssl ca -batch -keyfile ca.key -cert ca.pem -in client.csr -key $(PASSWORD_SERVER) -out client.crt -extensions xpclient_ext -extfile At a glance, that should be ca password. Ivan Kalik - List

Re: Problem with EAP-TLS, please give me a hint

2009-12-05 Thread _Stefan_H
tnt-5 wrote: I changed it but it's always the same problem: [tls] TLS_accept: SSLv3 write certificate request A [tls] TLS_accept: SSLv3 flush data [tls] TLS_accept: Need to read more data: SSLv3 read client certificate A Problem? What problem? Those are normal openSSL

Re: Problem with EAP-TLS, please give me a hint

2009-12-02 Thread _Stefan_H
Well, can anyone tell me, why nobody is helping me? I would not get on your nerves if there would be a solution to my problem. I was searching for a time and i found this helpful solutions look in the FAQ and look in the eap.conf. Well the FAQ tells about the xptensions and the help in the

Problem with EAP-TLS

2009-11-25 Thread _Stefan_H
I want to configure EAP-TLS on freeradius but it doesn’t work I hope the information below is enough. I am using freeradius 2.1.1. (openSUSE11.1), first I configured PAP using this tutorial( http://en.opensuse.org/RadiusServerHOWTO#Configuring_file_based_authentication

Re: WLAN - Freeradius - OpenLDAP - VLANs

2009-11-09 Thread _Stefan_H
). Best regards! Don't give wrong answers if you're not sure of what you're talking. 2009/11/9 _Stefan_H stefanh...@networld.at First I know my english is not the best, but i hope you will understand it. In the course of a project i have to make an authentification against a freeradius

WLAN - Freeradius - OpenLDAP - VLANs

2009-11-08 Thread _Stefan_H
First I know my english is not the best, but i hope you will understand it. In the course of a project i have to make an authentification against a freeradius server for the WLAN Users. On the Server(OpenSUSE11.1) is a LDAP Directory and i want that the WLAN Users have to authentificate with