forgot to mention that my try to make: heck_cert_cn = %{User-Name} => entered in users db username same as CN is in certificate with password supplied during client-cert generation with OpenSSL (A challenge password []:whatever)
didn't work. As well as placing my real cert data in this filed: check_cert_issuer = "/C=ZZ/ST=Yyyyy/L=yyyyy/O=Xxx" No luck! Also i've mentioned this comments in eap.conf: # If check_cert_issuer is set, the value will # be checked against the DN of the issuer in # the client certificate What is DN? maybe this one should be configured and work properly ? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html