Certificate Compatibility

Ben Wiechman wiechman.lists at gmail.com
Wed Mar 30 18:33:51 CEST 2011


If you are getting this error:

WARNING: !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
WARNING: !! EAP session for state 0xf2937007f695654f did not finish!
WARNING: !! Please read http://wiki.freeradius.org/Certificate_Compatibility
WARNING: !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!


Then the SM doesn't like something about the server certificate. So
somewhere along the way your certs are not right. Or I believe if the
time on the AP is not correct you will also encounter this error, but
I don't remember for sure.

Either you don't have the correct CA cert imported on the SM, your
server certificate is not signed by the CA cert you have imported on
the SM, or you are not using the right certs on the server. Something
isn't matching up.

You need three pieces:
CA Cert on server
Server Cert signed by CA cert on server
CA Cert on SM

Somewhere those pieces aren't right.

Ben

On Wed, Mar 30, 2011 at 11:16 AM, Jim Rice <jmrice6640 at yahoo.com> wrote:
> Hi Ben,
>
> I am confused.  If the certificate is incorrect, then what is this?
>
>> [ttls]     (other): SSL negotiation finished successfully
>> SSL Connection Established
>
> But I will review to be sure.
>
>
>
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
>




More information about the Freeradius-Users mailing list