Unfortunately, if you are using an android phone with version 11 patched after 
December 9 2020 you will need to have a public trusted cert installed the 
RADIUS on PF.

Android need to trust the Root CA that provided the cert on the RADIUS side.

Either you provision the Root CA on the android phone and you create a profile 
that would trust the chain of certs or you install a cert from an already 
trusted Root CA installed like Godaddy and deal with you windows laptop by 
pushing the Godaddy into the Root CA trusted store.

Thanks,

Ludovic Zammit
[email protected] <mailto:[email protected]> ::  +1.514.447.4918 (x145) ::  
www.inverse.ca <https://www.inverse.ca/>
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu <http://www.sogo.nu/>) 
and PacketFence (http://packetfence.org <http://packetfence.org/>)







> On Mar 24, 2021, at 9:17 AM, Nathan, Josh <[email protected]> wrote:
> 
> Thank you!  I decided to go the route of issuing the certificate for the 
> RADIUS service.  That seemed to work for the Windows laptop, but it didn't 
> work for my Pixel 3a phone.  The Android app always throws an error when 
> trying to setup the WiFi, so I tried doing it manually.  I downloaded the CA 
> certificate I created within PacketFence (as used for generating the user and 
> RADIUS certificates), and installed that.  And then I also installed the 
> RADIUS certificate.  Neither works.  Any guidance on what it means by 
> "internal error".  Somehow it looks like it's accepting the certificates (not 
> throwing "unknown CA" at least).
> 
> (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: Continuing EAP-TLS
> (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: [eaptls verify] = ok
> (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: Done initial handshake
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS Alert read:fatal:internal 
> error
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS_accept: Failed in error
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: Failed in __FUNCTION__ 
> (SSL_read)
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: error:14094438:SSL 
> routines:ssl3_read_bytes:tlsv1 alert internal error
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: error:140940E5:SSL 
> routines:ssl3_read_bytes:ssl handshake failure
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: System call (I/O) error (-1)
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS receive handshake failed 
> during operation
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: [eaptls process] = fail
> (513) Wed Mar 24 13:41:25 2021: ERROR: Test2: Failed continuing EAP TLS (13) 
> session.  EAP sub-module failed
> (513) Wed Mar 24 13:41:25 2021: Debug: Test2: Sending EAP Failure (code 4) ID 
> 50 length 4
> (513) Wed Mar 24 13:41:25 2021: Debug: Test2: Failed in EAP select
> (513) Wed Mar 24 13:41:25 2021: Debug:     [Test2] = invalid
> (513) Wed Mar 24 13:41:25 2021: Debug:   } # Auth-Type Test2 = invalid
> (513) Wed Mar 24 13:41:25 2021: Debug: Failed to authenticate the user
> (513) Wed Mar 24 13:41:25 2021: Debug: Using Post-Auth-Type Reject
> (513) Wed Mar 24 13:41:25 2021: Debug: # Executing group from file 
> /usr/local/pf/raddb/sites-enabled/packetfence
> 
> But hey, the Windows laptop works now!  So that was great!
> Thank you!
> 
>       
> Joshua Nathan
> IT Supervisor
> Black Forest Academy
> 
> p:    +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056
> a:
> w:    Hammersteiner Straße 50, 79400 Kandern
> bfacademy.de <http://bfacademy.de/>
> 
> 
> 
> 
> On Tue, Mar 23, 2021 at 6:23 PM Ludovic Zammit <[email protected] 
> <mailto:[email protected]>> wrote:
> Hello,
> 
> Your error "TLS Alert write:fatal:unknown CA” means that the windows does not 
> trust the certificate that is install on PF for RADIUS.
> 
> Either make sure to ignore the certificate server identity on the windows for 
> that connection or Issue a certificate for RADIUS from the PKI that you are 
> using.
> 
> <PastedGraphic-2.tiff>
> 
> Uncheck the first one at the top.
> 
> Thanks,
> 
> Ludovic Zammit
> [email protected] <mailto:[email protected]> ::  +1.514.447.4918 (x145) ::  
> www.inverse.ca <https://www.inverse.ca/>
> Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu 
> <http://www.sogo.nu/>) and PacketFence (http://packetfence.org 
> <http://packetfence.org/>)
> 
> 
> 
> 
> 
> 
> 
>> On Mar 23, 2021, at 10:24 AM, Nathan, Josh via PacketFence-users 
>> <[email protected] 
>> <mailto:[email protected]>> wrote:
>> 
>> Hello,
>> 
>> Well, I'm not sure what I missed, but after following the installation guide 
>> for using the built-in PKI provider, I have been unable to get TLS working.
>> 
>> I'm trying to prep a new virtual server for replacing our existing one.  I 
>> have the ZEN version with PF 10.2.0.  The error I'm running into is that the 
>> server is rejecting the certificate during authentication.  The client 
>> device is Windows 10.  I used the registration page and the built-in Windows 
>> provisioner.  The server accepted my credentials on the registration page, 
>> and I did a copy and paste of the password it provided for the certificate 
>> it generated.  After generating the certificate, the server pushed the 
>> configurator, which is what I used for installed the certificate and 
>> configuring the wireless connection.  So I don't know where I could have 
>> gone wrong in regard to this.  The only thing I can think of would be maybe 
>> I was supposed to do something different after generating the CA certificate.
>> 
>> I copied the certificate, went to "System Configuration" in the left-hand 
>> panel.  Then at the bottom of that panel, clicked on "SSL Certificates".  
>> Then selected the "Radius" tab, and clicked edit.  From within there, I was 
>> presented with 3 large text fields, the middle one being "Certification 
>> Authority certificate(s)".  I selected everything within that middle box, 
>> and replaced it with the CA certificate I had copied from what I had 
>> generated.  Was that not right?  Regardless, here's an except from the logs 
>> showing the RADIUS authentication error.
>> 
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Found Auth-Type = Test2
>> (69834) Tue Mar 23 14:52:42 2021: Debug: # Executing group from file 
>> /usr/local/pf/raddb/sites-enabled/packetfence
>> (69834) Tue Mar 23 14:52:42 2021: Debug:   Auth-Type Test2 {
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Expiring EAP session with 
>> state 0x6076e6ab646debf0
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Finished EAP session with 
>> state 0x6076e6ab646debf0
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Previous EAP request found 
>> for state 0x6076e6ab646debf0, released from the list
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Peer sent packet with method 
>> EAP TLS (13)
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Calling submodule eap_tls to 
>> process data
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Continuing EAP-TLS
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Got final TLS record 
>> fragment (257 bytes)
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: [eaptls verify] = ok
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Done initial handshake
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: TLS - Creating attributes 
>> from certificate OIDs
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:   TLS-Client-Cert-Serial 
>> := "06"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:   
>> TLS-Client-Cert-Expiration := "220323134604Z"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:   
>> TLS-Client-Cert-Valid-Since := "210323134604Z"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:   TLS-Client-Cert-Subject 
>> := "/C=DE/ST=BW/L=Kandern/street=Hammersteiner Str. 
>> 50/postalCode=79400/O=Black Forest Academy/CN=josh.nathan"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:   TLS-Client-Cert-Issuer 
>> := "/C=DE/ST=BW/L=Kandern/street=Hammersteiner Str. 
>> 50/postalCode=79400/O=Black Forest Academy/CN=BFA_Root_CA"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:   
>> TLS-Client-Cert-Common-Name := "josh.nathan"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:   
>> TLS-Client-Cert-Subject-Alt-Name-Email := "[email protected] 
>> <mailto:[email protected]>"
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls:   SSL says error 20 : 
>> unable to get local issuer certificate
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: TLS Alert 
>> write:fatal:unknown CA
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: Failed in __FUNCTION__ 
>> (SSL_read): error:14089086:SSL 
>> routines:ssl3_get_client_certificate:certificate verify failed
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: System call (I/O) error 
>> (-1)
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: TLS receive handshake 
>> failed during operation
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: [eaptls process] = fail
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: Test2: Failed continuing EAP TLS 
>> (13) session.  EAP sub-module failed
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Sending EAP Failure (code 4) 
>> ID 27 length 4
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Failed in EAP select
>> (69834) Tue Mar 23 14:52:42 2021: Debug:     [Test2] = invalid
>> (69834) Tue Mar 23 14:52:42 2021: Debug:   } # Auth-Type Test2 = invalid
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Failed to authenticate the user
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Using Post-Auth-Type Reject
>> 
>> Thank you for any help/guidance you can provide!
>> 
>>      
>> Joshua Nathan
>> IT Supervisor
>> Black Forest Academy
>> 
>> p:   +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056
>> a:
>> w:   Hammersteiner Straße 50, 79400 Kandern
>> bfacademy.de <http://bfacademy.de/>
>> 
>> 
>> _______________________________________________
>> PacketFence-users mailing list
>> [email protected] 
>> <mailto:[email protected]>
>> https://lists.sourceforge.net/lists/listinfo/packetfence-users 
>> <https://lists.sourceforge.net/lists/listinfo/packetfence-users>
> 

_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to