Re: Configuring freeradius for MACsec

2012-02-24 Thread Matija Levec
On 24.2.2012 at 8:38, in message 4f473e78.2070...@deployingradius.com, Alan DeKok al...@deployingradius.com wrote: Matija Levec wrote: What should be configured for radius to also send EAP-Key-Name AVP? Nothing. RFC 4072 says: The EAP-Key-Name AVP (Radius Attribute Type 102

Configuring freeradius for MACsec

2012-02-23 Thread Matija Levec
? Kind regards, Matija Levec - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Configuring freeradius for MACsec

2012-02-23 Thread Matija Levec
, Matija Levec Phil Mayers 02/23/12 6:48 PM On 23/02/12 16:26, Matija Levec wrote: What should be configured for radius to also send EAP-Key-Name AVP? AFAIK that is not implemented yet. I've only skimmed them, but AFAIK most AAA servers and EAP methods don't generate EAP-Key-Name yet. I'm

Re: Freeradius + EAP_TLS + Cisco AP

2010-10-01 Thread Matija Levec
Hi. Valid CA is the one that issued radius server certificate. Just import it to trusted CAs list. Bye, M. Is mandatory for an XP machine to authenticate the server certificate to a valid CA? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius + EAP_TLS + Cisco AP

2010-09-29 Thread Matija Levec
You say you are trying to setup eap-tls and you have client certs - so you probably also want to set client to eap-tls (smart card or other certificate in windows world). Check you installed proper CA certs on both client and server if you are checking them (which I guess you should). 'PEAP or

Radius proxy - kind of

2010-09-24 Thread Matija Levec
Hi everyone! First a little bit of explaining... - auth_server 1 client - fr_proxy -[ - auth_server 2 (client=random NAS, fr_proxy=freeradius, auth_server=two-factor auth server(s)) Currently we have clients authenticating directly to auth_server 1. We would