FreeRadius EAP/TLS - Revoke a Certificate

2004-08-23 Thread DonLemmi

Hi everyone,

i'm trying to lay out a wireless LAN with EAP/TLS
Certificate-Authentication. For this pupose i use a Gentoo-Box with
FreeRADIUS Version 0.9.3 and OpenSSL 0.9.7d. The Authentication works
so far. My question now is, if it is possible to lock out a single
given, valid (not expired) certificate? Scenario would be that a
Notebook has been stolen so the User-Certificate on that Notebook
should be maked invalid while the User himself would get a new
Certificate. In this case, a simple Username-based lockout does not
work.
I looked for some docs on FreeRADIUS CLR - maybe a howto or similar, but
did not find any. Does this mean it is not possible?
Thank you in advance for your help.

Best regeards,
Hendrik

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: FreeRadius EAP/TLS - Revoke a Certificate

2004-08-23 Thread Alan DeKok
[EMAIL PROTECTED] wrote:
 I looked for some docs on FreeRADIUS CLR - maybe a howto or similar, but
 did not find any. Does this mean it is not possible?

  See raddb/eap.conf.  Look for crl

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html