Question about OpenBSD as accesspoint with EAP-TLS

2014-01-12 Thread Aleksandar Lazic

Dear Listmembers.

After reading a lot about 802.1x authentication I hope you can help me 
to clarify some open questions.


1.) When I have more then one Certificate is a radius server mandatory?
2.) I think that the freeradius server is the server I will use, any 
objections for this SW?
3.) Have anybody used this setup and have some hints and tips to avoid 
pitfalls


Thank you for your help.

Best regards
Aleks

Some Links I have read.

http://undeadly.org/cgi?action=articlesid=20130128142215
http://hostap.epitest.fi/wpa_supplicant/
http://wiki.freeradius.org/protocol/EAP#EAP-TLS

http://www.openbsd.org/cgi-bin/man.cgi?query=ifconfigapropos=0sektion=0manpath=OpenBSD+Currentarch=i386format=html


wpaakms akm,akm,...
 Set the comma-separated list of allowed authentication and 
key

 management protocols.

 The supported values are ``psk'' and ``802.1x''.  psk
 authentication (also known as personal mode) uses a 256-bit 
pre-
 shared key.  802.1x authentication (also known as 
enterprise
 mode) is used with an external IEEE 802.1X authentication 
server,
 such as wpa_supplicant.  The default value is ``psk''.  
``psk''
 can only be used if a pre-shared key is configured using 
the

 wpakey option.




Re: Install log from OpenBSD Automatic Installation

2014-01-08 Thread Aleksandar Lazic


Am 08-01-2014 03:06, schrieb Theo de Raadt:

Am 08-01-2014 03:02, schrieb Aleksandar Lazic:

Am 08-01-2014 02:50, schrieb Theo de Raadt:

 Autoinstall does not handle this type of problem either.

Is there a plan to be able to handle such a problem with autoinstall?


Yes... get a CF card which is not broken in this way, or convince a
developer to invent a better workaround (one that works
automatically).  I was quite unhappy when this solution was proposed
initially, since solutions of that sort often lead to no true solution
down the road.


Thanks.



Install log from OpenBSD Automatic Installation

2014-01-07 Thread Aleksandar Lazic

Hi dear list members.

Today I have read the post

http://undeadly.org/cgi?action=articlesid=20140106055302

Call For Testing Of OpenBSD Automatic Installation

on

http://undeadly.org/

Due to the fact that this is my first post to this list I kindly ask 
what the preferred way on this list is to send the install log.


[ ] https://gist.github.com/
[ ] http://pastebin.com/
[ ] in the email
[ ] other way: 

I have of course some questions after the successful installation.

1.) How can I custom the disk layout?

2.) Due to the fact that on my soekris the Compact flash have some 
problems I must change the DMA mode as described here

http://wiki.soekris.info/Installing_OpenBSD#Problems_with_some_CF_cards
Is it possible to add the User Kernel Config (UKC) sequence into 
the boot.conf or any other file?


If this is the wrong list please point me to the right one, thank you.

Best regards
Aleks



Re: Install log from OpenBSD Automatic Installation

2014-01-07 Thread Aleksandar Lazic


Am 08-01-2014 02:50, schrieb Theo de Raadt:



I have of course some questions after the successful installation.

1.) How can I custom the disk layout?


At the moment, you cannot.  I have asked Alexander and Uwe to look at
a clever way of solving this problem, but it will take some time.


Thank you for the answer.


2.) Due to the fact that on my soekris the Compact flash have some
problems I must change the DMA mode as described here

http://wiki.soekris.info/Installing_OpenBSD#Problems_with_some_CF_cards
 Is it possible to add the User Kernel Config (UKC) sequence 
into

the boot.conf or any other file?


Autoinstall does not handle this type of problem either.


Is there a plan to be able to handle such a problem with autoinstall?