Failed in SSLv3 read client certificate A

Stefan Paetow Stefan.Paetow at jisc.ac.uk
Mon Jun 6 15:31:45 CEST 2016


> (48) eap_tls: ERROR: TLS_accept: Failed in SSLv3 read client certificate A
> (48) eap_tls: ERROR: SSL says: error:140940E5:SSL
> routines:ssl3_read_bytes:ssl handshake failure
> (48) eap_tls: ERROR: SSL_read failed in a system call (-1), TLS session failed
> (48) eap_tls: ERROR: TLS receive handshake failed during operation

Does the iPad have the CA certificate installed? Does it have the *correct* CA certificate installed? If there are intermediates, is the whole *chain* installed?

See https://www.mail-archive.com/search?l=freeradius-users@lists.freeradius.org&q=subject:%22SSL+error%22&o=newest&f=1

> #2) Is there a way to get more information from radius? It's unclear
> whether Radius (a) received the client certificate but does not
> understand it, or (b) did not receive the client certificate at all

As per the above link, chances are that the iPad didn't understand the cert, didn't like it, or something else is wrong with it, and subsequently said "Thanks but no thanks."

Stefan Paetow
Moonshot Industry & Research Liaison Coordinator

t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp at jabber.dev.ja.net
skype: stefan.paetow.janet

jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under Company No. 5747339, VAT No. GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill, Bristol, BS2 0JA. T 0203 697 5800.




-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 496 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20160606/de351668/attachment.sig>


More information about the Freeradius-Users mailing list