Client Cetificates

abhishek singh abhicc285 at gmail.com
Fri Aug 10 13:08:27 CEST 2007


I am using Free radius to perform EAP-TLS. However when my client
certificates reaches EAP, following error  is generated. Is there any
specific requirement  (in terms of encoding) for  the client side
certificates.

Any help will be appreciated. Thanks in advance.


 rlm_eap: Request found, released from the list
  rlm_eap: EAP/tls
  rlm_eap: processing type tls
  rlm_eap_tls: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0007], Certificate
  rlm_eap_tls: >>> TLS 1.0 Alert [length 0002], fatal handshake_failure
TLS Alert write:fatal:handshake failure
    TLS_accept:error in SSLv3 read client certificate B
rlm_eap: SSL error error:140890C7:SSL
routines:SSL3_GET_CLIENT_CERTIFICATE:peer
did not return a certificate
rlm_eap_tls: SSL_read failed in a system call (-1), TLS session fails.
  eaptls_process returned 13
  rlm_eap: Freeing handler
  modcall[authenticate]: module "eap" returns reject for request 11
modcall: leaving group authenticate (returns reject) for request 11
auth: Failed to validate the user.


--
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20070810/5d89f2ad/attachment.html>


More information about the Freeradius-Users mailing list