Setting VLAN based on Certificate Issuer

Edgar Fuß ef at math.uni-bonn.de
Mon Nov 17 18:27:54 CET 2008


I thought this was a FAQ but apparently it isn't.

I have an 1.1.7 FreeRADIUS server up and running with EAP/TLS.
Now, I would like to put clients into different VLANs based on who signed
their certificate.
Is there a way to set the Tunnel-Private-Group-Id attribute based on the
certificate issuer? Is the Rlm_eap module able to export any information
on the certificate chain?

Switching to 2.1.1 wouldn't be a problem for me I suppose.

Thanks for any help.




More information about the Freeradius-Users mailing list