Devinder Singh devinbhullar at gmail.com
Tue Aug 4 11:05:04 CEST 2009

Hi Ivan

These are the changes made to Makefile

client.csr client.key: client.cnf
        openssl req -new  -out client.csr -keyout client.key -config

client.crt: client.csr ca.pem ca.key index.txt serial
        openssl ca -batch -keyfile ca.key -cert ca.pem -in client.csr
-key $(PASSWORD_CA) -out client.crt -extensions xpclient_ext -extfile
xpextensions -config ./client.cnf

client.p12: client.crt
        openssl pkcs12 -export -in client.crt -inkey client.key -out
client.p12  -passin pass:$(PASSWORD_CLIENT) -passout

client.pem: client.p12
        openssl pkcs12 -in client.p12 -out client.pem -passin
pass:$(PASSWORD_CLIENT) -passout pass:$(PASSWORD_CLIENT)
        cp client.pem $(USER_NAME).pem

.PHONY: server.vrfy
client.vrfy: ca.pem client.pem
        c_rehash .
        openssl verify -CApath . client.pem

Ok iam about to re do the certiicates do i need to delete any files
from /certs directory?

2009/8/4 Devinder Singh <devinbhullar at gmail.com>:
> Ok
> 2009/8/4 Ivan Kalik <tnt at kalik.net>:
>>> Ok once i have made the changes shoud i repeat the steps in the
>>> /etc/raddb/README to generate the certs , server and client once again?
>> Yes, make certificates again.
>> Ivan Kalik
>> Kalik Informatika ISP
> --
> Devinder


More information about the Freeradius-Users mailing list