On Tue, 15 Mar 2005 13:40:18 -0600, Jon Franklin <[EMAIL PROTECTED]> wrote: > On Tue, 15 Mar 2005 14:00:08 +0100, Michael Riviera > <[EMAIL PROTECTED]> wrote: > > Jon Franklin wrote: > >
On a follow-up to this, I found that the certificate I was using (Thawte Freemail Member) was being validated against a set of root certs in /usr/share/ssl/certs/ca-bundle.crt (I'm using Fedora Core 3, btw). If I remove that file, only the certificates issed by the CA listed in the file specified by CA_file in radiusd.conf are allowed by freeradius. So I'm getting much closer to a solution. I don't want to get rid of all the CA certs in /usr/share/ssl, and only want freeradius to use the root cert I specify in the CA_file line. Can anyone tell me how that's done? Or is it even possible? -- Jon Franklin [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html