EAP-TLS: check TLS-Client-Cert with unlang
Alan DeKok
aland at deployingradius.com
Mon Jan 9 19:58:46 UTC 2023
On Jan 9, 2023, at 2:57 PM, Stefan Hartmann <stefanh at hafenthal.de> wrote:
> I updated freeradius on an Devuan machine from 3.0.17 to 3.2.1.
>
> Formerly I checked the client certificate in the virtual server check-eap-tls with the following unlang construct to extract the real User-Name from the certificate:
You'll have to use the v3.2.x branch from github, some unrelated changes broke the mapping between certificate fields and attributes.
We're trying to get 3.2.2 out soon to address this issue, and to add some features.
Alan DeKok.
More information about the Freeradius-Users
mailing list