Interesting EAP-TLS condition, any insights?

Timothy J. Miller tmiller at mitre.org
Fri Dec 23 19:44:45 CET 2005


Alan DeKok wrote:

>   That would appear to be a bug in the AP.  I'd be curious to know how
> many AP's have that bug.  If so, it would be a very, very, serious
> problem.

Which is why it startled me.

>   I'm not sure how to fix that, to be honest.  There's little you can
> do on the RADIUS server to make the AP work.

An abort followed by Access-Reject in rlm_eap_tls might work.

>   My only suggestion is to try another AP.  If that works, mail Cisco,
> and tell them about the bug.

Already in the plan.

-- Tim
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 2859 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20051223/eeb02d10/attachment.bin>


More information about the Freeradius-Users mailing list