Ah, ok.

Thank you!

Joshua Nathan
*IT Supervisor*
Black Forest Academy

p: +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056
a:
w: Hammersteiner Straße 50, 79400 Kandern
bfacademy.de




On Wed, Mar 24, 2021 at 2:34 PM Ludovic Zammit <[email protected]> wrote:

> Unfortunately, if you are using an android phone with version 11 patched
> after December 9 2020 you will need to have a public trusted cert installed
> the RADIUS on PF.
>
> Android need to trust the Root CA that provided the cert on the RADIUS
> side.
>
> Either you provision the Root CA on the android phone and you create a
> profile that would trust the chain of certs or you install a cert from an
> already trusted Root CA installed like Godaddy and deal with you windows
> laptop by pushing the Godaddy into the Root CA trusted store.
>
> Thanks,
>
>
> Ludovic Zammit
> [email protected] ::  +1.514.447.4918 (x145) ::  www.inverse.ca
> Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
> (http://packetfence.org)
>
>
>
>
>
>
>
>
> On Mar 24, 2021, at 9:17 AM, Nathan, Josh <[email protected]>
> wrote:
>
> Thank you!  I decided to go the route of issuing the certificate for the
> RADIUS service.  That seemed to work for the Windows laptop, but it didn't
> work for my Pixel 3a phone.  The Android app always throws an error when
> trying to setup the WiFi, so I tried doing it manually.  I downloaded the
> CA certificate I created within PacketFence (as used for generating the
> user and RADIUS certificates), and installed that.  And then I also
> installed the RADIUS certificate.  Neither works.  Any guidance on what it
> means by "internal error".  Somehow it looks like it's accepting the
> certificates (not throwing "unknown CA" at least).
>
> (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: Continuing EAP-TLS
> (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: [eaptls verify] = ok
> (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: Done initial handshake
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS Alert
> read:fatal:internal error
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS_accept: Failed in error
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: Failed in __FUNCTION__
> (SSL_read)
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: error:14094438:SSL
> routines:ssl3_read_bytes:tlsv1 alert internal error
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: error:140940E5:SSL
> routines:ssl3_read_bytes:ssl handshake failure
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: System call (I/O) error
> (-1)
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS receive handshake
> failed during operation
> (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: [eaptls process] = fail
> (513) Wed Mar 24 13:41:25 2021: ERROR: Test2: Failed continuing EAP TLS
> (13) session.  EAP sub-module failed
> (513) Wed Mar 24 13:41:25 2021: Debug: Test2: Sending EAP Failure (code 4)
> ID 50 length 4
> (513) Wed Mar 24 13:41:25 2021: Debug: Test2: Failed in EAP select
> (513) Wed Mar 24 13:41:25 2021: Debug:     [Test2] = invalid
> (513) Wed Mar 24 13:41:25 2021: Debug:   } # Auth-Type Test2 = invalid
> (513) Wed Mar 24 13:41:25 2021: Debug: Failed to authenticate the user
> (513) Wed Mar 24 13:41:25 2021: Debug: Using Post-Auth-Type Reject
> (513) Wed Mar 24 13:41:25 2021: Debug: # Executing group from file
> /usr/local/pf/raddb/sites-enabled/packetfence
>
>
> But hey, the Windows laptop works now!  So that was great!
> Thank you!
>
> Joshua Nathan
> *IT Supervisor*
> Black Forest Academy
>
> p: +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056
> a:
> w: Hammersteiner Straße 50, 79400 Kandern
> bfacademy.de
>
>
>
>
> On Tue, Mar 23, 2021 at 6:23 PM Ludovic Zammit <[email protected]> wrote:
>
>> Hello,
>>
>> Your error "TLS Alert write:fatal:unknown CA” means that the windows does
>> not trust the certificate that is install on PF for RADIUS.
>>
>> Either make sure to ignore the certificate server identity on the windows
>> for that connection or Issue a certificate for RADIUS from the PKI that you
>> are using.
>>
>> <PastedGraphic-2.tiff>
>>
>> Uncheck the first one at the top.
>>
>> Thanks,
>>
>>
>> Ludovic Zammit
>> [email protected] ::  +1.514.447.4918 (x145) ::  www.inverse.ca
>> Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
>> (http://packetfence.org)
>>
>>
>>
>>
>>
>>
>>
>>
>> On Mar 23, 2021, at 10:24 AM, Nathan, Josh via PacketFence-users <
>> [email protected]> wrote:
>>
>> Hello,
>>
>> Well, I'm not sure what I missed, but after following the installation
>> guide for using the built-in PKI provider, I have been unable to get TLS
>> working.
>>
>> I'm trying to prep a new virtual server for replacing our existing one.
>> I have the ZEN version with PF 10.2.0.  The error I'm running into is that
>> the server is rejecting the certificate during authentication.  The client
>> device is Windows 10.  I used the registration page and the built-in
>> Windows provisioner.  The server accepted my credentials on the
>> registration page, and I did a copy and paste of the password it provided
>> for the certificate it generated.  After generating the certificate, the
>> server pushed the configurator, which is what I used for installed the
>> certificate and configuring the wireless connection.  So I don't know where
>> I could have gone wrong in regard to this.  The only thing I can think of
>> would be maybe I was supposed to do something different after generating
>> the CA certificate.
>>
>> I copied the certificate, went to "System Configuration" in the left-hand
>> panel.  Then at the bottom of that panel, clicked on "SSL Certificates".
>> Then selected the "Radius" tab, and clicked edit.  From within there, I was
>> presented with 3 large text fields, the middle one being "Certification
>> Authority certificate(s)".  I selected everything within that middle box,
>> and replaced it with the CA certificate I had copied from what I had
>> generated.  Was that not right?  Regardless, here's an except from the logs
>> showing the RADIUS authentication error.
>>
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Found Auth-Type = Test2
>> (69834) Tue Mar 23 14:52:42 2021: Debug: # Executing group from file
>> /usr/local/pf/raddb/sites-enabled/packetfence
>> (69834) Tue Mar 23 14:52:42 2021: Debug:   Auth-Type Test2 {
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Expiring EAP session with
>> state 0x6076e6ab646debf0
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Finished EAP session with
>> state 0x6076e6ab646debf0
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Previous EAP request
>> found for state 0x6076e6ab646debf0, released from the list
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Peer sent packet with
>> method EAP TLS (13)
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Calling submodule eap_tls
>> to process data
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Continuing EAP-TLS
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Got final TLS record
>> fragment (257 bytes)
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: [eaptls verify] = ok
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Done initial handshake
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: TLS - Creating
>> attributes from certificate OIDs
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:
>> TLS-Client-Cert-Serial := "06"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:
>> TLS-Client-Cert-Expiration := "220323134604Z"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:
>> TLS-Client-Cert-Valid-Since := "210323134604Z"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:
>> TLS-Client-Cert-Subject := "/C=DE/ST=BW/L=Kandern/street=Hammersteiner Str.
>> 50/postalCode=79400/O=Black Forest Academy/CN=josh.nathan"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:
>> TLS-Client-Cert-Issuer := "/C=DE/ST=BW/L=Kandern/street=Hammersteiner Str.
>> 50/postalCode=79400/O=Black Forest Academy/CN=BFA_Root_CA"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:
>> TLS-Client-Cert-Common-Name := "josh.nathan"
>> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls:
>> TLS-Client-Cert-Subject-Alt-Name-Email := "[email protected]"
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls:   SSL says error 20 :
>> unable to get local issuer certificate
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: TLS Alert
>> write:fatal:unknown CA
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: Failed in __FUNCTION__
>> (SSL_read): error:14089086:SSL
>> routines:ssl3_get_client_certificate:certificate verify failed
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: System call (I/O) error
>> (-1)
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: TLS receive handshake
>> failed during operation
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: [eaptls process] = fail
>> (69834) Tue Mar 23 14:52:42 2021: ERROR: Test2: Failed continuing EAP TLS
>> (13) session.  EAP sub-module failed
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Sending EAP Failure (code
>> 4) ID 27 length 4
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Failed in EAP select
>> (69834) Tue Mar 23 14:52:42 2021: Debug:     [Test2] = invalid
>> (69834) Tue Mar 23 14:52:42 2021: Debug:   } # Auth-Type Test2 = invalid
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Failed to authenticate the user
>> (69834) Tue Mar 23 14:52:42 2021: Debug: Using Post-Auth-Type Reject
>>
>>
>> Thank you for any help/guidance you can provide!
>>
>> Joshua Nathan
>> *IT Supervisor*
>> Black Forest Academy
>>
>> p: +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056
>> a:
>> w: Hammersteiner Straße 50, 79400 Kandern
>> bfacademy.de
>>
>>
>> _______________________________________________
>> PacketFence-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>>
>>
>>
>
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to