EAP-TLS & deny access?

Alan DeKok aland at deployingradius.com
Sun May 25 17:02:16 CEST 2008


uhel at gmx.net wrote:
> how can i deny access to a user (a certificate)? 

  Set Auth-Type := Reject

> Is a CRL (with the CA_path and c_rehash stuff) the only possibility to
> deny access or is it possible to have a *whitelist* (like the CA_path
> and c_rehash stuff but as a whitelist) with certs that are allowed? 

  If you don't want the user to be authenticated, why are you issuing
certificates for them?

  Alan DeKok.



More information about the Freeradius-Users mailing list