Re: Certificate-based client side authentication towards a website with freeradius

2009-07-09 Thread Martin Schneider
Helllo Jay The Internet Draft address what you described in web client/Apache server and mail client and mail server applications. The TLS-EAp extension is leveraging existing user credential and profile in AAA server. In addition, you have flexibility to choose different authentication

Re: Certificate-based client side authentication towards a website with freeradius

2009-07-02 Thread Martin Schneider
Hello Jay If you want to leverage the existing user profiles in the RADIUS server for authentication, authorization, this Internet Draft TLS-EAP Extension http://tools.ietf.org/html/draft-nir-tls-eap-06 might be what you are looking for. Unfortunately, there is no implementation up to date

Certificate-based client side authentication towards a website with freeradius

2009-07-01 Thread Martin Schneider
Hello all, we're trying to setup a freeradius / apache installation that allows us to authenticate and authorize users with *certificates* towards a website. Is there a good tutorial out there somewhere? We did only finde partial information that seems to be quite old unfortunately. Or could

Re: Certificate-based client side authentication towards a website with freeradius

2009-07-01 Thread Martin Schneider
Hi Ivan Why use radius to check certificates when Apache can do it? http://httpd.apache.org/docs/2.0/ssl/ssl_howto.html Thanks for this reply. We need also authorization. So we want to 1.) check if the certificate is signed by a trusted ca 2.) check if the username x in the certificate is

Re: Certificate-based client side authentication towards a website with freeradius

2009-07-01 Thread Martin Schneider
I think I need to clarify my question a little: we're trying to setup a freeradius / apache installation that allows us to authenticate and authorize users with *certificates* towards a website. We want to have *multiple* services, not only just one service. If we would only have one service,

Re: EAP-TNC supported?

2008-08-21 Thread Martin Schneider
Hi 2008/8/20 Alan DeKok [EMAIL PROTECTED]: Martin Schneider wrote: - I read in wikipedia, that the spring 2008 release of FreeRadius has experimental EAP-TNC support. I couldn't find any information on the FreeRadius homepage or wiki, that this information is correct. Has FreeRadius EAP-TNC

Re: EAP-TNC supported?

2008-08-21 Thread Martin Schneider
Hi Ingo and others Does anybody know about a patch or something for FreeRadius that adds more stable EAP-TNC processing? I heard about a patch from FH Hannover (http://tnc.inform.fh-hannover.de/wiki/index.php/Main_Page) but I don't know how good this one works. Did maybe anybody of you guys

EAP-TNC supported?

2008-08-20 Thread Martin Schneider
Hello everybody, I've got two questions: - I read in wikipedia, that the spring 2008 release of FreeRadius has experimental EAP-TNC support. I couldn't find any information on the FreeRadius homepage or wiki, that this information is correct. Has FreeRadius EAP-TNC support? And how experimental