Ah, ok. Thank you!
Joshua Nathan *IT Supervisor* Black Forest Academy p: +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056 a: w: Hammersteiner Straße 50, 79400 Kandern bfacademy.de On Wed, Mar 24, 2021 at 2:34 PM Ludovic Zammit <[email protected]> wrote: > Unfortunately, if you are using an android phone with version 11 patched > after December 9 2020 you will need to have a public trusted cert installed > the RADIUS on PF. > > Android need to trust the Root CA that provided the cert on the RADIUS > side. > > Either you provision the Root CA on the android phone and you create a > profile that would trust the chain of certs or you install a cert from an > already trusted Root CA installed like Godaddy and deal with you windows > laptop by pushing the Godaddy into the Root CA trusted store. > > Thanks, > > > Ludovic Zammit > [email protected] :: +1.514.447.4918 (x145) :: www.inverse.ca > Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence > (http://packetfence.org) > > > > > > > > > On Mar 24, 2021, at 9:17 AM, Nathan, Josh <[email protected]> > wrote: > > Thank you! I decided to go the route of issuing the certificate for the > RADIUS service. That seemed to work for the Windows laptop, but it didn't > work for my Pixel 3a phone. The Android app always throws an error when > trying to setup the WiFi, so I tried doing it manually. I downloaded the > CA certificate I created within PacketFence (as used for generating the > user and RADIUS certificates), and installed that. And then I also > installed the RADIUS certificate. Neither works. Any guidance on what it > means by "internal error". Somehow it looks like it's accepting the > certificates (not throwing "unknown CA" at least). > > (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: Continuing EAP-TLS > (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: [eaptls verify] = ok > (513) Wed Mar 24 13:41:25 2021: Debug: eap_tls: Done initial handshake > (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS Alert > read:fatal:internal error > (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS_accept: Failed in error > (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: Failed in __FUNCTION__ > (SSL_read) > (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: error:14094438:SSL > routines:ssl3_read_bytes:tlsv1 alert internal error > (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: error:140940E5:SSL > routines:ssl3_read_bytes:ssl handshake failure > (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: System call (I/O) error > (-1) > (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: TLS receive handshake > failed during operation > (513) Wed Mar 24 13:41:25 2021: ERROR: eap_tls: [eaptls process] = fail > (513) Wed Mar 24 13:41:25 2021: ERROR: Test2: Failed continuing EAP TLS > (13) session. EAP sub-module failed > (513) Wed Mar 24 13:41:25 2021: Debug: Test2: Sending EAP Failure (code 4) > ID 50 length 4 > (513) Wed Mar 24 13:41:25 2021: Debug: Test2: Failed in EAP select > (513) Wed Mar 24 13:41:25 2021: Debug: [Test2] = invalid > (513) Wed Mar 24 13:41:25 2021: Debug: } # Auth-Type Test2 = invalid > (513) Wed Mar 24 13:41:25 2021: Debug: Failed to authenticate the user > (513) Wed Mar 24 13:41:25 2021: Debug: Using Post-Auth-Type Reject > (513) Wed Mar 24 13:41:25 2021: Debug: # Executing group from file > /usr/local/pf/raddb/sites-enabled/packetfence > > > But hey, the Windows laptop works now! So that was great! > Thank you! > > Joshua Nathan > *IT Supervisor* > Black Forest Academy > > p: +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056 > a: > w: Hammersteiner Straße 50, 79400 Kandern > bfacademy.de > > > > > On Tue, Mar 23, 2021 at 6:23 PM Ludovic Zammit <[email protected]> wrote: > >> Hello, >> >> Your error "TLS Alert write:fatal:unknown CA” means that the windows does >> not trust the certificate that is install on PF for RADIUS. >> >> Either make sure to ignore the certificate server identity on the windows >> for that connection or Issue a certificate for RADIUS from the PKI that you >> are using. >> >> <PastedGraphic-2.tiff> >> >> Uncheck the first one at the top. >> >> Thanks, >> >> >> Ludovic Zammit >> [email protected] :: +1.514.447.4918 (x145) :: www.inverse.ca >> Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence >> (http://packetfence.org) >> >> >> >> >> >> >> >> >> On Mar 23, 2021, at 10:24 AM, Nathan, Josh via PacketFence-users < >> [email protected]> wrote: >> >> Hello, >> >> Well, I'm not sure what I missed, but after following the installation >> guide for using the built-in PKI provider, I have been unable to get TLS >> working. >> >> I'm trying to prep a new virtual server for replacing our existing one. >> I have the ZEN version with PF 10.2.0. The error I'm running into is that >> the server is rejecting the certificate during authentication. The client >> device is Windows 10. I used the registration page and the built-in >> Windows provisioner. The server accepted my credentials on the >> registration page, and I did a copy and paste of the password it provided >> for the certificate it generated. After generating the certificate, the >> server pushed the configurator, which is what I used for installed the >> certificate and configuring the wireless connection. So I don't know where >> I could have gone wrong in regard to this. The only thing I can think of >> would be maybe I was supposed to do something different after generating >> the CA certificate. >> >> I copied the certificate, went to "System Configuration" in the left-hand >> panel. Then at the bottom of that panel, clicked on "SSL Certificates". >> Then selected the "Radius" tab, and clicked edit. From within there, I was >> presented with 3 large text fields, the middle one being "Certification >> Authority certificate(s)". I selected everything within that middle box, >> and replaced it with the CA certificate I had copied from what I had >> generated. Was that not right? Regardless, here's an except from the logs >> showing the RADIUS authentication error. >> >> (69834) Tue Mar 23 14:52:42 2021: Debug: Found Auth-Type = Test2 >> (69834) Tue Mar 23 14:52:42 2021: Debug: # Executing group from file >> /usr/local/pf/raddb/sites-enabled/packetfence >> (69834) Tue Mar 23 14:52:42 2021: Debug: Auth-Type Test2 { >> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Expiring EAP session with >> state 0x6076e6ab646debf0 >> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Finished EAP session with >> state 0x6076e6ab646debf0 >> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Previous EAP request >> found for state 0x6076e6ab646debf0, released from the list >> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Peer sent packet with >> method EAP TLS (13) >> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Calling submodule eap_tls >> to process data >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Continuing EAP-TLS >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Got final TLS record >> fragment (257 bytes) >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: [eaptls verify] = ok >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: Done initial handshake >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: TLS - Creating >> attributes from certificate OIDs >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: >> TLS-Client-Cert-Serial := "06" >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: >> TLS-Client-Cert-Expiration := "220323134604Z" >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: >> TLS-Client-Cert-Valid-Since := "210323134604Z" >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: >> TLS-Client-Cert-Subject := "/C=DE/ST=BW/L=Kandern/street=Hammersteiner Str. >> 50/postalCode=79400/O=Black Forest Academy/CN=josh.nathan" >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: >> TLS-Client-Cert-Issuer := "/C=DE/ST=BW/L=Kandern/street=Hammersteiner Str. >> 50/postalCode=79400/O=Black Forest Academy/CN=BFA_Root_CA" >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: >> TLS-Client-Cert-Common-Name := "josh.nathan" >> (69834) Tue Mar 23 14:52:42 2021: Debug: eap_tls: >> TLS-Client-Cert-Subject-Alt-Name-Email := "[email protected]" >> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: SSL says error 20 : >> unable to get local issuer certificate >> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: TLS Alert >> write:fatal:unknown CA >> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: Failed in __FUNCTION__ >> (SSL_read): error:14089086:SSL >> routines:ssl3_get_client_certificate:certificate verify failed >> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: System call (I/O) error >> (-1) >> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: TLS receive handshake >> failed during operation >> (69834) Tue Mar 23 14:52:42 2021: ERROR: eap_tls: [eaptls process] = fail >> (69834) Tue Mar 23 14:52:42 2021: ERROR: Test2: Failed continuing EAP TLS >> (13) session. EAP sub-module failed >> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Sending EAP Failure (code >> 4) ID 27 length 4 >> (69834) Tue Mar 23 14:52:42 2021: Debug: Test2: Failed in EAP select >> (69834) Tue Mar 23 14:52:42 2021: Debug: [Test2] = invalid >> (69834) Tue Mar 23 14:52:42 2021: Debug: } # Auth-Type Test2 = invalid >> (69834) Tue Mar 23 14:52:42 2021: Debug: Failed to authenticate the user >> (69834) Tue Mar 23 14:52:42 2021: Debug: Using Post-Auth-Type Reject >> >> >> Thank you for any help/guidance you can provide! >> >> Joshua Nathan >> *IT Supervisor* >> Black Forest Academy >> >> p: +49 (0) 7626 9161 631 m: +49 (0) 152 3452 0056 >> a: >> w: Hammersteiner Straße 50, 79400 Kandern >> bfacademy.de >> >> >> _______________________________________________ >> PacketFence-users mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/packetfence-users >> >> >> >
_______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users
