Re: Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-27 Thread Alan DeKok
Sergio wrote: I'm agree, a good begining would be comment out all modules you're not using. The instances of the modules are in sites-enabled/default and sites-enabled/inner-tunnel (for peap and ttls). For debugging... no. The default configuration file WORKS in the widest possible set of

Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-27 Thread Reveal MAP
I'm agree, a good begining would be comment out all modules you're not using. The instances of the modules are in sites-enabled/default and sites-enabled/inner-tunnel (for peap and ttls). - --- Donb't worry, it will be done soon (as soon as the week starts again ). i really want to figure it

Re: Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-27 Thread Alan DeKok
Reveal MAP wrote: Yes, Alan, we already now that thedefault config do works! my mind: freeradius (in our case, sergio and me) is correctly configured. But, we encounterd a problem showing no error message. so to make the log slimmer, why not deactivate some non mandatory module in our

Re: Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-27 Thread Alan DeKok
Reveal MAP wrote: now we know what not to do at all. we are still wondering what we have to do. Use a client that isn't broken. Sorry. Try SecureW2. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Re : Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-26 Thread Phil Mayers
see the logf there: http://tinypaste.com/5b99b Your problem is nothing to do with certificates. The PEAP tunnel gets setup correctly, the MS-CHAP client-server auth succeeds, but the final server-client (mutual) auth appears to fail. This could be for a number of reasons, but it's a

Re: Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-26 Thread Anders Holm
[snip] rlm_pap: WARNING! No known good password found for the user. Authentication may fail because of this.//Normal, i am not willing to do PAP but mschapv2 me If you¹re not using a module, disable it. All it¹ll do is add latency, delays and unnecessary log

Re: Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Sergio
: FreeRadius users mailing list freeradius-users@lists.freeradius.org Envoyé le : Jeudi, 24 Juillet 2008, 19h54mn 32s Objet : Re: cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls) Sergio wrote: But the debug I posted shows that radius doesn't recognize the issuer of client cert

Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Reveal MAP
d'origine De : Sergio [EMAIL PROTECTED] À : FreeRadius users mailing list freeradius-users@lists.freeradius.org Envoyé le : Vendredi, 25 Juillet 2008, 13h20mn 54s Objet : Re: Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls) Reveal MAP escribió: HOW TO FIX THE PROBLEM

Re: Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Sergio
open! - Message d'origine De : Sergio [EMAIL PROTECTED] À : FreeRadius users mailing list freeradius-users@lists.freeradius.org Envoyé le : Vendredi, 25 Juillet 2008, 13h20mn 54s Objet : Re: Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls) Reveal MAP

Re : Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Reveal MAP
installing ca.der and putting user pass into client machine, the authentication doesn't work? -- no, it doesn't! you only need ca.der but, if you have an active directory like LDAP, check if your comunication with AD server also have tls authentication. Into ldap module you can

Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread nf-vale
Are you using vista supplicant? By reading the last lines of your radius debug file it seems so... See earlier posts with subject: PEAP or TTLS and Microsoft Vista. Sex, 2008-07-25 às 17:10 +, Reveal MAP escreveu: installing ca.der and putting user pass into client machine, the

Re: Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Sergio
nf-vale escribió: Are you using vista supplicant? By reading the last lines of your radius debug file it seems so... See earlier posts with subject: PEAP or TTLS and Microsoft Vista. Sex, 2008-07-25 às 17:10 +, Reveal MAP escreveu: installing ca.der and putting user pass into