Microsof Client Certificate (OID)

Kwok Sianbin sianbin_kwok at yahoo.com
Sun May 25 06:21:17 CEST 2008


Hi Alan,
 
 certificate generation scripts already executed.
 Is this what you meant.
 # make server.pem
 # make server.csr
 
 Kindly advice how to do it!

Alan DeKok <aland at deployingradius.com> wrote: Kwok Sianbin wrote:
...
> #radtest MarsNet Mars123 localhost 0 testing123
>  User-Name = "MarsNet"
...
> if I change the configuration in radiusd.conf to bind to particular IP
> address (eth0) then about radtest failed to Accept.

  Because you're sending packets to localhost?  Do you know what
different network interfaces are?

...
> ++[eap] returns handled
>         Reply-Message = "Hello, MarsNet"
>         EAP-Message = 0x010200060d20
>         Message-Authenticator = 0x00000000000000000000000000000000
>         State = 0x58961ab6589417883d2fb3d577435665
> Finished request 2.
> Going to the next request
> Waking up in 4.9 seconds.

  This is in the FAQ.  You are using a Microsoft client, and the server
certificate doesn't have the correct OID's.

  Use the certificate generation scripts that come with the server.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


       
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20080524/31c75923/attachment.html>


More information about the Freeradius-Users mailing list