On Tue, 15 Mar 2005 13:40:18 -0600, Jon Franklin <[EMAIL PROTECTED]> wrote:
> On Tue, 15 Mar 2005 14:00:08 +0100, Michael Riviera
> <[EMAIL PROTECTED]> wrote:
> > Jon Franklin wrote:
> >

On a follow-up to this, I found that the certificate I was using
(Thawte Freemail Member) was being validated against a set of root
certs in /usr/share/ssl/certs/ca-bundle.crt (I'm using Fedora Core 3,
btw).

If I remove that file, only the certificates issed by the CA listed in
the file specified by CA_file in radiusd.conf are allowed by
freeradius.

So I'm getting much closer to a solution.  I don't want to get rid of
all the CA certs in /usr/share/ssl, and only want freeradius to use
the root cert I specify in the CA_file line.

Can anyone tell me how that's done?  Or is it even possible?

-- 
Jon Franklin
[EMAIL PROTECTED]

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to