Hello, as far as I have understood, the "check_cert_cn" switch in raddb/eap.conf forces the certificate's Common Name to be in the raddb/users file. Otherwise there the request will be rejected.
Now I've commented out the whole raddb/users file but the radius doesn't reject any request. I am running a WLAN with EAP-TLS authentication and need to "switch off" single certificates. --Manuel Schmitz -- Lassen Sie Ihren Gedanken freien Lauf... z.B. per FreeSMS GMX bietet bis zu 100 FreeSMS/Monat: http://www.gmx.net/de/go/mail - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

