Re: EAP-TLS - Authenticating only certain users

2007-02-17 Thread Alan DeKok
Stephen Bowman wrote: When using EAP-TLS as the only method in freeradius, is there a way to define a list of allowed users, perhaps by the CN on their client certificate? Or the User-Name attribute, which should be the same as the client CN. Alan DeKok. -- http://deployingradius.com

Re: EAP-TLS - Authenticating only certain users

2007-02-17 Thread Stephen Bowman
Ok, so I put a list of usernames in the users file with an Auth-Type := EAP ? Right now, everyone with a valid client certificate is authenticated (nobody is listed in the users file). Once I start enumerating them in the users file, will it have an implicit deny all of everyone who isn't in

Re: EAP-TLS - Authenticating only certain users

2007-02-17 Thread Alan DeKok
Stephen Bowman wrote: Ok, so I put a list of usernames in the users file with an Auth-Type := EAP ? No. Setting Auth-Type is almost always wrong. In this case, it will do nothing. Instead, put the good users into a group (see man rlm_passwd). Then, reject everyone who isn't in that

EAP-TLS - Authenticating only certain users

2007-02-16 Thread Stephen Bowman
When using EAP-TLS as the only method in freeradius, is there a way to define a list of allowed users, perhaps by the CN on their client certificate? I want it so that not *everyone* who has a certificate signed by the CA list can authenticate, but rather a select few (of which I know the CN of