EAP TLS certificates - Questions

Elias Pereira empbilly at gmail.com
Fri Dec 10 14:17:39 CET 2021


Thanks Anssi and Alan!!!

In my research I found the link below that shows how to set the [alt_names]
option in server.cnf and also in the xpextensions file.

subjectAltName = @alt_names

[alt_names]
DNS.1 = radius.company.net

https://wiki.alpinelinux.org/wiki/FreeRadius_EAP-TLS_configuration

Will this option work?

On Fri, Dec 10, 2021 at 10:01 AM Alan DeKok <aland at deployingradius.com>
wrote:

> On Dec 9, 2021, at 4:37 PM, Anssi Saari <as at sci.fi> wrote:
> > On Android 11 and newer the domain apparently has to match the CN field
> > of the Radius server's certificate. The default for Freeradius is
> > Example Server Certificate.
>
>   So... edit the files in raddb/certs, and create new certificates with
> the correct domain.
>
>   Alan DeKok.
>
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>


-- 
Elias Pereira


More information about the Freeradius-Users mailing list