Hey

On 3/15/04 5:02 AM, "Pavol Zibrita" <[EMAIL PROTECTED]> wrote:

> 
> Hi!
> 
>> Okay, I know that PEAP is supported with XP/OSX. What are the options in
>> radiusd.conf I need to configure for PEAP? I have the users file with
>> entries like: kevan   Auth-Type := EAP, User-Password == "mypassword". Do
> I
>> still need to install certificates on the client? What are the options on
>> the Cisco 1231 that I need to make sure this works correctly?
> 
> Remove the Auth-Type := EAP

Should the users file contain only kevan or "kevan   Auth-Type := Local,
User-Password == "mypassword"?

> You don't need certificate on client, but don't check the checkbox for
> validating the certificate on the client.
> Or the root.der certificate can be installed for verification.

Okay, I'll give that a try because this is what log I get now:

Info: rlm_eap_tls:  Received EAP-TLS First Fragment of the message
Error: --> verify error:num=3:unable to get certificate CRL
Error: TLS Alert write:fatal:unknown CA
Error:     TLS_accept:error in SSLv3 read client certificate B
Error: rlm_eap_tls: SSL_read failed in a system call (-1), TLS session
fails.

> radius.conf - enable and configure module eap. tls within eap, peap and also
> the mschapv2 (all are in the config after
> installing the radius. change the default_eap_type to peap in eap section.
> eap should be in authorization and accounting sections. I think..
> 
> It should work. I dont' know what cisco ios needs, i have working with
> not-ios ciscos yet (aironert 350).
> 
> P.Z.
> 
> 
> - 
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to