Re: [PacketFence-users] Captive Portal certificate

2018-01-09 Thread Yiorgos Eleftheriou via PacketFence-users
Dear
i try all these but when i try to authenticate by google i have this ssl
error
https://accounts.google.com/o/oauth2/auth?response_type=
code_uri=https%3A%2F%2Fpacketfence2.msselectronics.
gr%2Foauth2%2Fcallback_id=225737418070-kegnm6l27fg530t4u7d3b4fp9e9e5r
3p.apps.googleusercontent.com==https%3A%2F%
2Fwww.googleapis.com%2Fauth%2Fuserinfo.email

google should use its own certificate but instead of this its uses lets
encrypt cert that i have in my server.

-- 
MSS CY Electronics LTD
Yiorgos Eleftheriou
tel00357 25 310 377
mob 00357 99 08 2154
www.msselectronics.com.cy
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Captive Portal certificate

2017-11-21 Thread Durand fabrice via PacketFence-users

Hello Yohann,

you need to do that:

cat conf/ssl/MyCERT.crt conf/ssl/MyPRIVKEY.key > conf/ssl/server.pem

and restart haproxy

Regards

Fabrice



Le 2017-11-21 à 09:07, LE GALL Yohann a écrit :


Hi Fabrice,

I’m actually trying to fix my bug about certificates. I did the same 
thing as said in previous mails.


My administration’s board ( https://server:1443/admin/ ) is 
certificated but my portal board is not.


How can I do the trick to fix it ?

Regards,

Yohann



*Yohann* *LE GALL*
Administrateur Systèmes et Réseaux junior
http://biocoop.eu/SignatureBiocoop/OWA_trait_biocoop.png




http://biocoop.eu/SignatureBiocoop/OWA_logo_Biocoop.png 
<http://www.biocoop.fr/>
http://biocoop.eu/SignatureBiocoop/OWA_text_logo.png 
<http://www.biocoop.fr/>

www.biocoop.fr <http://www.biocoop.fr>

http://biocoop.eu/SignatureBiocoop/OWA_instagram.png 
<https://www.instagram.com/biocoop_officiel/?hl=fr>http://biocoop.eu/SignatureBiocoop/OWA_Twitter.png 
<http://twitter.com/biocoop/>http://biocoop.eu/SignatureBiocoop/OWA_logo_pinterest.png 
<http://fr.pinterest.com/biocoop/>http://biocoop.eu/SignatureBiocoop/OWA_FACEBOOK.png 
<https://fr-fr.facebook.com/Biocoop>





Adoptez l'éco-attitude: N'imprimez ce document que si nécessaire

*De :*Luís Torres via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]

*Envoyé :* mardi 3 octobre 2017 16:52
*À :* packetfence-users@lists.sourceforge.net
*Cc :* Luís Torres <luistorr...@iol.pt>
*Objet :* Re: [PacketFence-users] Captive Portal certificate

Fabrice,

my bad..., the crt and key was not correctly exported.

Followed this procudure from de .pfx and it worked like you said:

ake the file you exported (e.g. certname.pfx) and copy it to a system 
where you have OpenSSL installed. Note: the *.pfx file is in PKCS#12 
format and includes both the certificate and the private key.


Run the following command to export the private key: openssl pkcs12 
-in certname.pfx -nocerts -out key.pem -nodes
Run the following command to export the certificate: openssl pkcs12 
-in certname.pfx -nokeys -out cert.pem
Run the following command to remove the passphrase from the private 
key: openssl rsa -in key.pem -out server.key


Thanks

Em 2017-10-03 14:54, Fabrice Durand via PacketFence-users escreveu:

You probably did a mistake with the concatenated certificate.

Is there any empty lines in the file ?

Le 2017-10-03 à 09:48, Luís Torres via PacketFence-users a écrit :

Hi Fabrice,

Just did that, restarted the haproxy but the result was :

ERROR pfcmd.pl(50729):
pf::services::manager::haproxy=HASH(0xade6b0)->name died or
has failed to start (pf::services::manager::postStartCleanup)

the service HAproxy wont start

regards

LT

Em 2017-10-03 14:13, Fabrice Durand via PacketFence-users
escreveu:

In fact haproxy terminate the ssl tunnel so you don't have
to change the ssl-certificates.conf file.

This file is just use for the admin interface now and not
the portal anymore.

So just do that: (MyCERT.crt and MyPRIVKEY.key are your
certificate files)

cat conf/ssl/MyCERT.crt conf/ssl/MyPRIVKEY.key >
conf/ssl/server.pem

Regards

Fabrice

Le 2017-10-03 à 05:25, Luís Torres via PacketFence-users a
écrit :

thank you Fabrice,

The ssl-certificates.conf should be like this as well? :

/*SSLCertificateChainFile
%%install_dir%%/conf/ssl/server.pem*/

cheers

Em 2017-10-02 23:49, Durand fabrice via
PacketFence-users escreveu:

Hello Luís,

you need to concatenate the certificates like that:

cat conf/ssl/server.crt conf/ssl/server.key >
conf/ssl/server.pem

and restart haproxy

Regards

Fabrice

Le 2017-10-02 à 10:57, Luís Torres via
PacketFence-users a écrit :

Hi,

to stop the cert error on the captive portal,
its only need to change it on
ssl-certificates.conf to point to the correct
ones?

thanks




--

Check out the vibrant tech community on one of the 
world's most

engaging tech sites, 
Slashdot.org!http://sdm.link/slashdot



___

PacketF

Re: [PacketFence-users] Captive Portal certificate

2017-11-21 Thread LE GALL Yohann via PacketFence-users
Hi Fabrice,

I’m actually trying to fix my bug about certificates. I did the same thing as 
said in previous mails.

My administration’s board ( https://server:1443/admin/ ) is certificated but my 
portal board is not.

How can I do the trick to fix it ?

Regards,
Yohann


Yohann  LE GALL
Administrateur Systèmes et Réseaux junior
[http://biocoop.eu/SignatureBiocoop/OWA_trait_biocoop.png]



[http://biocoop.eu/SignatureBiocoop/OWA_logo_Biocoop.png]<http://www.biocoop.fr/>
[http://biocoop.eu/SignatureBiocoop/OWA_text_logo.png]<http://www.biocoop.fr/>
www.biocoop.fr<http://www.biocoop.fr>

[http://biocoop.eu/SignatureBiocoop/OWA_instagram.png]<https://www.instagram.com/biocoop_officiel/?hl=fr>
  [http://biocoop.eu/SignatureBiocoop/OWA_Twitter.png] 
<http://twitter.com/biocoop/>   
[http://biocoop.eu/SignatureBiocoop/OWA_logo_pinterest.png] 
<http://fr.pinterest.com/biocoop/>   
[http://biocoop.eu/SignatureBiocoop/OWA_FACEBOOK.png] 
<https://fr-fr.facebook.com/Biocoop>


Adoptez l'éco-attitude: N'imprimez ce document que si nécessaire


De : Luís Torres via PacketFence-users 
[mailto:packetfence-users@lists.sourceforge.net]
Envoyé : mardi 3 octobre 2017 16:52
À : packetfence-users@lists.sourceforge.net
Cc : Luís Torres <luistorr...@iol.pt>
Objet : Re: [PacketFence-users] Captive Portal certificate


Fabrice,



my bad..., the crt and key was not correctly exported.

Followed this procudure from de .pfx and it worked like you said:



ake the file you exported (e.g. certname.pfx) and copy it to a system where you 
have OpenSSL installed. Note: the *.pfx file is in PKCS#12 format and includes 
both the certificate and the private key.

Run the following command to export the private key: openssl pkcs12 -in 
certname.pfx -nocerts -out key.pem -nodes
Run the following command to export the certificate: openssl pkcs12 -in 
certname.pfx -nokeys -out cert.pem
Run the following command to remove the passphrase from the private key: 
openssl rsa -in key.pem -out server.key



Thanks





Em 2017-10-03 14:54, Fabrice Durand via PacketFence-users escreveu:

You probably did a mistake with the concatenated certificate.

Is there any empty lines in the file ?

Le 2017-10-03 à 09:48, Luís Torres via PacketFence-users a écrit :

Hi Fabrice,



Just did that, restarted the haproxy but the result was :



ERROR pfcmd.pl(50729): pf::services::manager::haproxy=HASH(0xade6b0)->name died 
or has failed to start (pf::services::manager::postStartCleanup)



the service HAproxy wont start



regards

LT



Em 2017-10-03 14:13, Fabrice Durand via PacketFence-users escreveu:

In fact haproxy terminate the ssl tunnel so you don't have to change the 
ssl-certificates.conf file.

This file is just use for the admin interface now and not the portal anymore.

So just do that: (MyCERT.crt and MyPRIVKEY.key are your certificate files)

cat conf/ssl/MyCERT.crt conf/ssl/MyPRIVKEY.key > conf/ssl/server.pem

Regards

Fabrice



Le 2017-10-03 à 05:25, Luís Torres via PacketFence-users a écrit :

thank you Fabrice,



The ssl-certificates.conf should be like this as well? :



SSLCertificateChainFile %%install_dir%%/conf/ssl/server.pem





cheers



Em 2017-10-02 23:49, Durand fabrice via PacketFence-users escreveu:

Hello Luís,

you need to concatenate the certificates like that:

cat conf/ssl/server.crt conf/ssl/server.key > conf/ssl/server.pem

and restart haproxy



Regards

Fabrice



Le 2017-10-02 à 10:57, Luís Torres via PacketFence-users a écrit :

Hi,



to stop the cert error on the captive portal, its only need to change it on 
ssl-certificates.conf to point to the correct ones?



thanks




--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot



___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users


--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot


___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourceforge.net>

https://lists.sourceforge.net/lists/listinfo/packetfence-users






--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot



___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net<mailto:PacketFence-users@lists.sourcefo

Re: [PacketFence-users] Captive Portal certificate

2017-10-05 Thread Trinklein, Jason R via PacketFence-users
If you don’t wish to overwrite the original cert files, you can modify which 
certs are used as well as the Intermediate cert at: 
/usr/local/pf/conf/httpd.conf.d/ssl-certificates.conf

I found this piece of information to be missing in the documentation and other 
help articles around the web. The file ssl-certificates.conf has moved in more 
recent versions of pf into the httpd.conf.d folder.
--
Jason Trinklein
Wireless Engineering Manager
College of Charleston
81 St. Philip Street | Office 311D | Charleston, SC 29403
trinkle...@cofc.edu<mailto:trinkle...@cofc.edu> | (843) 300–8009

From: Luís Torres via PacketFence-users 
<packetfence-users@lists.sourceforge.net>
Reply-To: "packetfence-users@lists.sourceforge.net" 
<packetfence-users@lists.sourceforge.net>
Date: Tuesday, October 3, 2017 at 11:48 AM
To: "packetfence-users@lists.sourceforge.net" 
<packetfence-users@lists.sourceforge.net>
Cc: Luís Torres <luistorr...@iol.pt>
Subject: Re: [PacketFence-users] Captive Portal certificate

--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Captive Portal certificate

2017-10-03 Thread Luís Torres via PacketFence-users
 

Fabrice, 

my bad..., the crt and key was not correctly exported.


Followed this procudure from de .pfx and it worked like you said:


ake the file you exported (e.g. certname.pfx) and copy it to a system
where you have OpenSSL installed. Note: the *.pfx file is in PKCS#12
format and includes both the certificate and the private key. 

Run the
following command to export the private key: openssl pkcs12 -in
certname.pfx -nocerts -out key.pem -nodes
Run the following command to
export the certificate: openssl pkcs12 -in certname.pfx -nokeys -out
cert.pem
Run the following command to remove the passphrase from the
private key: openssl rsa -in key.pem -out server.key 

Thanks 

Em
2017-10-03 14:54, Fabrice Durand via PacketFence-users escreveu: 

> You
probably did a mistake with the concatenated certificate. 
> 
> Is there
any empty lines in the file ? 
> 
> Le 2017-10-03 à 09:48, Luís Torres
via PacketFence-users a écrit : 
> 
>> Hi Fabrice, 
>> 
>> Just did
that, restarted the haproxy but the result was : 
>> 
>> ERROR
pfcmd.pl(50729): pf::services::manager::haproxy=HASH(0xade6b0)->name
died or has failed to start (pf::services::manager::postStartCleanup)

>> 
>> the service HAproxy wont start 
>> 
>> regards 
>> 
>> LT 
>>

>> Em 2017-10-03 14:13, Fabrice Durand via PacketFence-users escreveu:

>> 
>>> In fact haproxy terminate the ssl tunnel so you don't have to
change the ssl-certificates.conf file. 
>>> 
>>> This file is just use
for the admin interface now and not the portal anymore. 
>>> 
>>> So
just do that: (MyCERT.crt and MyPRIVKEY.key are your certificate files)

>>> 
>>> cat conf/ssl/MyCERT.crt conf/ssl/MyPRIVKEY.key >
conf/ssl/server.pem 
>>> 
>>> Regards 
>>> 
>>> Fabrice 
>>> 
>>> Le
2017-10-03 à 05:25, Luís Torres via PacketFence-users a écrit : 
>>>

 thank you Fabrice, 
 
 The ssl-certificates.conf should be
like this as well? : 
 
 _SSLCERTIFICATECHAINFILE
%%INSTALL_DIR%%/CONF/SSL/SERVER.PEM_ 
 
 cheers 
 
 Em
2017-10-02 23:49, Durand fabrice via PacketFence-users escreveu: 


> Hello Luís, 
> 
> you need to concatenate the
certificates like that: 
> 
> cat conf/ssl/server.crt
conf/ssl/server.key > conf/ssl/server.pem 
> 
> and restart
haproxy 
> 
> Regards 
> 
> Fabrice 
> 
> Le
2017-10-02 à 10:57, Luís Torres via PacketFence-users a écrit : 
>

>> Hi, 
>> 
>> to stop the cert error on the captive
portal, its only need to change it on ssl-certificates.conf to point to
the correct ones? 
>> 
>> thanks 
>> 
>>
--
>>
Check out the vibrant tech community on one of the world's most
>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>>

>> ___
>>
PacketFence-users mailing list
>>
PacketFence-users@lists.sourceforge.net
>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
>

>
--
>
Check out the vibrant tech community on one of the world's most
>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>

> ___
>
PacketFence-users mailing list
>
PacketFence-users@lists.sourceforge.net
>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]



--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]


 ___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net

https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
>>>

>>> -- 
>>> Fabrice Durand
>>> fdur...@inverse.ca :: +1.514.447.4918
(x135) :: www.inverse.ca [3]
>>> Inverse inc. :: Leaders behind SOGo
(http://www.sogo.nu [4]) and PacketFence (http://packetfence.org [5])

>>> 
>>>
--
>>>
Check out the vibrant tech community on one of the world's most
>>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>>> 
>>>
___
>>> PacketFence-users
mailing list
>>> PacketFence-users@lists.sourceforge.net
>>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
>>

>>
--
>>
Check out the vibrant tech community on one of the world's most
>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>> 
>>
___
>> PacketFence-users
mailing list
>> PacketFence-users@lists.sourceforge.net
>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
> 

Re: [PacketFence-users] Captive Portal certificate

2017-10-03 Thread Luís Torres via PacketFence-users
 

did directly from a pfx 

_OPENSSL PKCS12 -IN INFRA.PFX -OUT
SERVER.PEM_ 

no empty lines. 

But using crt and key > pem 

it as
empty lines 

_SSL# CAT INFRA.CRT INFRA.KEY > INFRA.PEM_ 

LT 

Em
2017-10-03 14:54, Fabrice Durand via PacketFence-users escreveu: 

> You
probably did a mistake with the concatenated certificate. 
> 
> Is there
any empty lines in the file ? 
> 
> Le 2017-10-03 à 09:48, Luís Torres
via PacketFence-users a écrit : 
> 
>> Hi Fabrice, 
>> 
>> Just did
that, restarted the haproxy but the result was : 
>> 
>> ERROR
pfcmd.pl(50729): pf::services::manager::haproxy=HASH(0xade6b0)->name
died or has failed to start (pf::services::manager::postStartCleanup)

>> 
>> the service HAproxy wont start 
>> 
>> regards 
>> 
>> LT 
>>

>> Em 2017-10-03 14:13, Fabrice Durand via PacketFence-users escreveu:

>> 
>>> In fact haproxy terminate the ssl tunnel so you don't have to
change the ssl-certificates.conf file. 
>>> 
>>> This file is just use
for the admin interface now and not the portal anymore. 
>>> 
>>> So
just do that: (MyCERT.crt and MyPRIVKEY.key are your certificate files)

>>> 
>>> cat conf/ssl/MyCERT.crt conf/ssl/MyPRIVKEY.key >
conf/ssl/server.pem 
>>> 
>>> Regards 
>>> 
>>> Fabrice 
>>> 
>>> Le
2017-10-03 à 05:25, Luís Torres via PacketFence-users a écrit : 
>>>

 thank you Fabrice, 
 
 The ssl-certificates.conf should be
like this as well? : 
 
 _SSLCERTIFICATECHAINFILE
%%INSTALL_DIR%%/CONF/SSL/SERVER.PEM_ 
 
 cheers 
 
 Em
2017-10-02 23:49, Durand fabrice via PacketFence-users escreveu: 


> Hello Luís, 
> 
> you need to concatenate the
certificates like that: 
> 
> cat conf/ssl/server.crt
conf/ssl/server.key > conf/ssl/server.pem 
> 
> and restart
haproxy 
> 
> Regards 
> 
> Fabrice 
> 
> Le
2017-10-02 à 10:57, Luís Torres via PacketFence-users a écrit : 
>

>> Hi, 
>> 
>> to stop the cert error on the captive
portal, its only need to change it on ssl-certificates.conf to point to
the correct ones? 
>> 
>> thanks 
>> 
>>
--
>>
Check out the vibrant tech community on one of the world's most
>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>>

>> ___
>>
PacketFence-users mailing list
>>
PacketFence-users@lists.sourceforge.net
>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
>

>
--
>
Check out the vibrant tech community on one of the world's most
>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>

> ___
>
PacketFence-users mailing list
>
PacketFence-users@lists.sourceforge.net
>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]



--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]


 ___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net

https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
>>>

>>> -- 
>>> Fabrice Durand
>>> fdur...@inverse.ca :: +1.514.447.4918
(x135) :: www.inverse.ca [3]
>>> Inverse inc. :: Leaders behind SOGo
(http://www.sogo.nu [4]) and PacketFence (http://packetfence.org [5])

>>> 
>>>
--
>>>
Check out the vibrant tech community on one of the world's most
>>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>>> 
>>>
___
>>> PacketFence-users
mailing list
>>> PacketFence-users@lists.sourceforge.net
>>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
>>

>>
--
>>
Check out the vibrant tech community on one of the world's most
>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>> 
>>
___
>> PacketFence-users
mailing list
>> PacketFence-users@lists.sourceforge.net
>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
> 
>
-- 
> Fabrice Durand
> fdur...@inverse.ca :: +1.514.447.4918 (x135) ::
www.inverse.ca [3]
> Inverse inc. :: Leaders behind SOGo
(http://www.sogo.nu [4]) and PacketFence (http://packetfence.org [5]) 
>

>
--
>
Check out the vibrant tech community on one of the world's most
>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
> 
>
___
> PacketFence-users

Re: [PacketFence-users] Captive Portal certificate

2017-10-03 Thread Fabrice Durand via PacketFence-users
You probably did a mistake with the concatenated certificate.

Is there any empty lines in the file ?


Le 2017-10-03 à 09:48, Luís Torres via PacketFence-users a écrit :
>
> Hi Fabrice,
>
>  
>
> Just did that, restarted the haproxy but the result was :
>
>  
>
> ERROR pfcmd.pl(50729):
> pf::services::manager::haproxy=HASH(0xade6b0)->name died or has failed
> to start (pf::services::manager::postStartCleanup)
>
>  
>
> the service HAproxy wont start
>
>  
>
> regards
>
> LT
>
>  
>
> Em 2017-10-03 14:13, Fabrice Durand via PacketFence-users escreveu:
>
>> In fact haproxy terminate the ssl tunnel so you don't have to change
>> the ssl-certificates.conf file.
>>
>> This file is just use for the admin interface now and not the portal
>> anymore.
>>
>> So just do that: (MyCERT.crt and MyPRIVKEY.key are your certificate
>> files)
>>
>> cat conf/ssl/MyCERT.crt conf/ssl/MyPRIVKEY.key > conf/ssl/server.pem
>>
>> Regards
>>
>> Fabrice
>>
>>  
>>
>>
>> Le 2017-10-03 à 05:25, Luís Torres via PacketFence-users a écrit :
>>>
>>> thank you Fabrice,
>>>
>>>  
>>>
>>> The ssl-certificates.conf should be like this as well? :
>>>
>>>  
>>>
>>> */SSLCertificateChainFile %%install_dir%%/conf/ssl/server.pem/*
>>>
>>>  
>>>
>>>  
>>>
>>> cheers
>>>
>>>  
>>>
>>> Em 2017-10-02 23:49, Durand fabrice via PacketFence-users escreveu:
>>>
>>> Hello Luís,
>>>
>>> you need to concatenate the certificates like that:
>>>
>>> cat conf/ssl/server.crt conf/ssl/server.key > conf/ssl/server.pem
>>>
>>> and restart haproxy
>>>
>>>  
>>>
>>> Regards
>>>
>>> Fabrice
>>>
>>>  
>>>
>>>
>>> Le 2017-10-02 à 10:57, Luís Torres via PacketFence-users a écrit :
>>>
>>> Hi,
>>>
>>>  
>>>
>>> to stop the cert error on the captive portal, its only need
>>> to change it on ssl-certificates.conf to point to the
>>> correct ones?
>>>
>>>  
>>>
>>> thanks
>>>
>>>  
>>>
>>>
>>> 
>>> --
>>> Check out the vibrant tech community on one of the world's most
>>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>>
>>>
>>>
>>> ___
>>> PacketFence-users mailing list
>>> PacketFence-users@lists.sourceforge.net
>>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>>>
>>>
>>>
>>> 
>>> --
>>> Check out the vibrant tech community on one of the world's most
>>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>>
>>>
>>> ___
>>> PacketFence-users mailing list
>>> PacketFence-users@lists.sourceforge.net
>>> 
>>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>>>
>>>  
>>>
>>>  
>>>
>>>
>>> --
>>> Check out the vibrant tech community on one of the world's most
>>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>>
>>>
>>> ___
>>> PacketFence-users mailing list
>>> PacketFence-users@lists.sourceforge.net
>>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>>
>> -- 
>> Fabrice Durand
>> fdur...@inverse.ca ::  +1.514.447.4918 (x135) ::  www.inverse.ca
>> Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
>> (http://packetfence.org) 
>>
>> --
>> Check out the vibrant tech community on one of the world's most
>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>
>> ___
>> PacketFence-users mailing list
>> PacketFence-users@lists.sourceforge.net
>> 
>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>  
>
>  
>
>
> --
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>
>
> ___
> PacketFence-users mailing list
> PacketFence-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/packetfence-users

-- 
Fabrice Durand
fdur...@inverse.ca ::  +1.514.447.4918 (x135) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org) 

--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list

Re: [PacketFence-users] Captive Portal certificate

2017-10-03 Thread Luís Torres via PacketFence-users
 

Hi Fabrice, 

Just did that, restarted the haproxy but the result
was : 

ERROR pfcmd.pl(50729):
pf::services::manager::haproxy=HASH(0xade6b0)->name died or has failed
to start (pf::services::manager::postStartCleanup) 

the service HAproxy
wont start 

regards 

LT 

Em 2017-10-03 14:13, Fabrice Durand via
PacketFence-users escreveu: 

> In fact haproxy terminate the ssl tunnel
so you don't have to change the ssl-certificates.conf file. 
> 
> This
file is just use for the admin interface now and not the portal anymore.

> 
> So just do that: (MyCERT.crt and MyPRIVKEY.key are your
certificate files) 
> 
> cat conf/ssl/MyCERT.crt conf/ssl/MyPRIVKEY.key
> conf/ssl/server.pem 
> 
> Regards 
> 
> Fabrice 
> 
> Le 2017-10-03 à
05:25, Luís Torres via PacketFence-users a écrit : 
> 
>> thank you
Fabrice, 
>> 
>> The ssl-certificates.conf should be like this as well?
: 
>> 
>> _SSLCERTIFICATECHAINFILE %%INSTALL_DIR%%/CONF/SSL/SERVER.PEM_

>> 
>> cheers 
>> 
>> Em 2017-10-02 23:49, Durand fabrice via
PacketFence-users escreveu: 
>> 
>>> Hello Luís, 
>>> 
>>> you need to
concatenate the certificates like that: 
>>> 
>>> cat
conf/ssl/server.crt conf/ssl/server.key > conf/ssl/server.pem 
>>> 
>>>
and restart haproxy 
>>> 
>>> Regards 
>>> 
>>> Fabrice 
>>> 
>>> Le
2017-10-02 à 10:57, Luís Torres via PacketFence-users a écrit : 
>>>

 Hi, 
 
 to stop the cert error on the captive portal, its
only need to change it on ssl-certificates.conf to point to the correct
ones? 
 
 thanks 
 

--

Check out the vibrant tech community on one of the world's most

engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]


 ___

PacketFence-users mailing list

PacketFence-users@lists.sourceforge.net

https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
>>>

>>>
--
>>>
Check out the vibrant tech community on one of the world's most
>>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>>> 
>>>
___
>>> PacketFence-users
mailing list
>>> PacketFence-users@lists.sourceforge.net
>>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
>>

>>
--
>>
Check out the vibrant tech community on one of the world's most
>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>> 
>>
___
>> PacketFence-users
mailing list
>> PacketFence-users@lists.sourceforge.net
>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
> 
>
-- 
> Fabrice Durand
> fdur...@inverse.ca :: +1.514.447.4918 (x135) ::
www.inverse.ca [3]
> Inverse inc. :: Leaders behind SOGo
(http://www.sogo.nu [4]) and PacketFence (http://packetfence.org [5]) 
>

>
--
>
Check out the vibrant tech community on one of the world's most
>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
> 
>
___
> PacketFence-users
mailing list
> PacketFence-users@lists.sourceforge.net
>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]




Links:
--
[1] http://sdm.link/slashdot
[2]
https://lists.sourceforge.net/lists/listinfo/packetfence-users
[3]
http://www.inverse.ca
[4] http://www.sogo.nu
[5] http://packetfence.org
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Captive Portal certificate

2017-10-03 Thread Fabrice Durand via PacketFence-users
In fact haproxy terminate the ssl tunnel so you don't have to change the
ssl-certificates.conf file.

This file is just use for the admin interface now and not the portal
anymore.

So just do that: (MyCERT.crt and MyPRIVKEY.key are your certificate files)

cat conf/ssl/MyCERT.crt conf/ssl/MyPRIVKEY.key > conf/ssl/server.pem

Regards

Fabrice



Le 2017-10-03 à 05:25, Luís Torres via PacketFence-users a écrit :
>
> thank you Fabrice,
>
>  
>
> The ssl-certificates.conf should be like this as well? :
>
>  
>
> */SSLCertificateChainFile %%install_dir%%/conf/ssl/server.pem/*
>
>  
>
>  
>
> cheers
>
>  
>
> Em 2017-10-02 23:49, Durand fabrice via PacketFence-users escreveu:
>
>> Hello Luís,
>>
>> you need to concatenate the certificates like that:
>>
>> cat conf/ssl/server.crt conf/ssl/server.key > conf/ssl/server.pem
>>
>> and restart haproxy
>>
>>  
>>
>> Regards
>>
>> Fabrice
>>
>>  
>>
>>
>> Le 2017-10-02 à 10:57, Luís Torres via PacketFence-users a écrit :
>>>
>>> Hi,
>>>
>>>  
>>>
>>> to stop the cert error on the captive portal, its only need to
>>> change it on ssl-certificates.conf to point to the correct ones?
>>>
>>>  
>>>
>>> thanks
>>>
>>>  
>>>
>>>
>>> --
>>> Check out the vibrant tech community on one of the world's most
>>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>>
>>>
>>> ___
>>> PacketFence-users mailing list
>>> PacketFence-users@lists.sourceforge.net
>>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>>
>>
>> --
>> Check out the vibrant tech community on one of the world's most
>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>>
>> ___
>> PacketFence-users mailing list
>> PacketFence-users@lists.sourceforge.net
>> 
>> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>  
>
>  
>
>
> --
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
>
>
> ___
> PacketFence-users mailing list
> PacketFence-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/packetfence-users

-- 
Fabrice Durand
fdur...@inverse.ca ::  +1.514.447.4918 (x135) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org) 

--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Captive Portal certificate

2017-10-03 Thread Luís Torres via PacketFence-users
 

thank you Fabrice, 

The ssl-certificates.conf should be like this
as well? : 

_SSLCERTIFICATECHAINFILE
%%INSTALL_DIR%%/CONF/SSL/SERVER.PEM_ 

cheers 

Em 2017-10-02 23:49,
Durand fabrice via PacketFence-users escreveu: 

> Hello Luís, 
> 
> you
need to concatenate the certificates like that: 
> 
> cat
conf/ssl/server.crt conf/ssl/server.key > conf/ssl/server.pem 
> 
> and
restart haproxy 
> 
> Regards 
> 
> Fabrice 
> 
> Le 2017-10-02 à 10:57,
Luís Torres via PacketFence-users a écrit : 
> 
>> Hi, 
>> 
>> to stop
the cert error on the captive portal, its only need to change it on
ssl-certificates.conf to point to the correct ones? 
>> 
>> thanks 
>>

>>
--
>>
Check out the vibrant tech community on one of the world's most
>>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
>> 
>>
___
>> PacketFence-users
mailing list
>> PacketFence-users@lists.sourceforge.net
>>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]
> 
>
--
>
Check out the vibrant tech community on one of the world's most
>
engaging tech sites, Slashdot.org! http://sdm.link/slashdot [1]
> 
>
___
> PacketFence-users
mailing list
> PacketFence-users@lists.sourceforge.net
>
https://lists.sourceforge.net/lists/listinfo/packetfence-users [2]




Links:
--
[1] http://sdm.link/slashdot
[2]
https://lists.sourceforge.net/lists/listinfo/packetfence-users
--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Captive Portal certificate

2017-10-02 Thread Durand fabrice via PacketFence-users

Hello Luís,

you need to concatenate the certificates like that:

cat conf/ssl/server.crt conf/ssl/server.key > conf/ssl/server.pem

and restart haproxy


Regards

Fabrice



Le 2017-10-02 à 10:57, Luís Torres via PacketFence-users a écrit :


Hi,

to stop the cert error on the captive portal, its only need to change 
it on ssl-certificates.conf to point to the correct ones?


thanks



--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot


___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


--
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users