CRL List does not appear to work with Freeradius

Matt Harlum mailin at cactuar.net
Sat Mar 24 05:42:20 CET 2007


Hey guys,

I've been using freeradius for a while now, and i want to be able to  
revoke my certs, however when i have revoked them it can't find the  
CRL and as such nobody can log in - even people who have certs that  
are not revoked.

i just get the following message, even thugh my crl.pem is in the  
folder with the other certs,

rlm_eap_tls: <<< TLS 1.0 Handshake [length 0896], Certificate
--> verify error:num=3:unable to get certificate CRL
   rlm_eap_tls: >>> TLS 1.0 Alert [length 0002], fatal unknown_ca
TLS Alert write:fatal:unknown CA
     TLS_accept:error in SSLv3 read client certificate B
rlm_eap: SSL error error:140890B2:SSL  
routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned





More information about the Freeradius-Users mailing list