Check the subject and issuer in the EAP-TLS

Lev A. Serebryakov lev at serebryakov.spb.ru
Fri May 12 14:24:49 CEST 2006


Michal Prochazka wrote:

> I'm open for every remark and enhancement of this patch.
   IMHO, it is very breakable script: it compare only strings (issuer 
name, subject, etc), which can be forged easily. IMHO, we need to check 
sha1/md5 signatures of CA certificates, not strings.

-- 
// Lev Serebryakov



More information about the Freeradius-Users mailing list