definitively, I have a problem with eap-tls

Phil Mayers p.mayers at imperial.ac.uk
Thu Jul 24 14:09:33 CEST 2008


Sergio wrote:
> Sorry, I'll do the things right jeje

I haven't been reading all your emails, but what I have read is very 
confusing. So I'm sorry if I misunderstand.

The error message seems very very clear.

FreeRadius cannot verify the client certificate.

This means you have not given it the correct CA certificate.

You keep talking about "c_rehash" - to the best of my knowledge, 
FreeRadius doesn't make use of a "certificate directory" with the 
openssl-style xxxxxxxx.0 -> real.pem symlinks. Forget about that.

Can you please provide:

  * a copy of your eap.conf
  * a copy of the files from the "eap { tls {} }" section:
    * certificate_file
    * CA_file
  * a copy of the client cert:
    * user at example.com.pem



More information about the Freeradius-Users mailing list