<div dir="ltr">What format did you use to get the cert instaled on your NPS server?<div><br></div><div>Did you try to export that cert then try using that on the freeradius server?</div><div><br></div><div>It might not be the "same" cert that you are trying to use on the freeradius server, I have had issues when converting between formats.</div>
</div><div class="gmail_extra"><br><br><div class="gmail_quote">On 27 May 2014 14:13, Ryan De Kock <span dir="ltr"><<a href="mailto:ryandekock1988@gmail.com" target="_blank">ryandekock1988@gmail.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div><div><div>Thanks for all the responses.<br><br></div>I don't mean to doubt you guys, you obviously know more than me, however, If import this certificate into MS and use it with NPS the clients are able to connect and it does work.<br>
<br></div>I could be wrong but I think the issue has something to do with the fact that I have 2 .crt files, the chain and the actual cert. I tried to combine them in different orders into a file but that didn't work either.<br>
<br></div>If it works when in NPS surley it will work in freeradius?<br></div><div class="gmail_extra"><br><br><div class="gmail_quote">On 23 May 2014 17:29, Rui Ribeiro <span dir="ltr"><<a href="mailto:ruyrybeyro@gmail.com" target="_blank">ruyrybeyro@gmail.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Hi Ryan,</div><div><br></div><div>As far as I remember, Windows does not support wildcard certificates. </div>
<div><br></div><div>Regards</div><br><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
Message: 5<br>
Date: Fri, 23 May 2014 16:48:41 +0200<br>
From: Ryan De Kock <<a href="mailto:ryandekock1988@gmail.com" target="_blank">ryandekock1988@gmail.com</a>><br>
To: FreeRadius users mailing list<br>
<<a href="mailto:freeradius-users@lists.freeradius.org" target="_blank">freeradius-users@lists.freeradius.org</a>><br>
Subject: Wild Card GoDaddy cert<br>
Message-ID:<br>
<<a href="mailto:CANek%2BE1Fm%2B_zWfbcyz2Nuax%2BBXp2O7czOteSXoNq09xfi7p6JA@mail.gmail.com" target="_blank">CANek+E1Fm+_zWfbcyz2Nuax+BXp2O7czOteSXoNq09xfi7p6JA@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
Hi,<div><br>
<br>
I have a wildcard cert from <a href="http://godaddy.com" target="_blank">godaddy.com</a>.<br>
<br>
I have tested the cert on Microsoft NPS & IAS and it works fine.<br>
<br></div><div>
I'm sure it will work in freeradius too, however I can't figure it out.<br>
<br>
I have godaddy.crt bundl.e.crt & godaddy.key.<br>
<br>
I have added these to freeradius however it does work.<br>
<br>
This is what windows does when I don't validate certificates<br>
<br>
[eap] Request found, released from the list<br>
[eap] EAP/peap<br>
[eap] processing type peap<br>
[peap] processing EAP-TLS<br>
TLS Length 37<br>
[peap] Length Included<br>
[peap] eaptls_verify returned 11<br>
[peap] <<< TLS 1.0 Alert [length 0002], fatal access_denied<br>
TLS Alert read:fatal:access denied<br></div><div>
[peap] WARNING: No data inside of the tunnel.<br>
[peap] eaptls_process returned 7<br>
[peap] EAPTLS_OK<br>
[peap] Session established. Decoding tunneled attributes.<br>
[peap] Peap state ?<br>
[peap] FAILED processing PEAP: Tunneled data is invalid.<br>
[eap] Handler failed in EAP/peap<br>
[eap] Failed in EAP select<br>
++[eap] returns invalid<br>
Failed to authenticate the user.<br>
} # server Cerebus<br>
<br>
This is a successfull auth on my linux client<br>
<br>
<br>
<br></div><div>
[eap] Request found, released from the list<br>
[eap] EAP/peap<br>
[eap] processing type peap<br>
[peap] processing EAP-TLS<br></div><div>
[peap] eaptls_verify returned 7<br>
[peap] Done initial handshake<br>
[peap] eaptls_process returned 7<br>
[peap] EAPTLS_OK<br>
[peap] Session established. Decoding tunneled attributes.<br>
[peap] Peap state send tlv success<br>
[peap] Received EAP-TLV response.<br>
[peap] Success<br>
[eap] Freeing handler<br>
++[eap] returns ok<br>
<br>
<br>
tls {<br>
<br>
certdir = ${confdir}/certs<br>
cadir = ${confdir}/certs<br>
private_key_file = ${certdir}/godaddy.key<br>
certificate_file = ${certdir}/godaddy.crt<br>
dh_file = ${certdir}/dh<br>
random_file = ${certdir}/random<br>
}<br>
<br>
<br></div><div>
So Im not sure if its got to do with no using the cert chain or what I'm<br>
doing wrong but would appreciate any guidance<br></div>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://lists.freeradius.org/pipermail/freeradius-users/attachments/20140523/f44e9846/attachment-0001.html" target="_blank">http://lists.freeradius.org/pipermail/freeradius-users/attachments/20140523/f44e9846/attachment-0001.html</a>><br>
<br></blockquote></div></div></div>
<br>-<br>
List info/subscribe/unsubscribe? See <a href="http://www.freeradius.org/list/users.html" target="_blank">http://www.freeradius.org/list/users.html</a><br></blockquote></div><br></div>
<br>-<br>
List info/subscribe/unsubscribe? See <a href="http://www.freeradius.org/list/users.html" target="_blank">http://www.freeradius.org/list/users.html</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br>Bertalan Voros<div>
m: 07932858025</div>
</div>