Re: EAP-TLS authentication allows me to authenticate with invalid certificate.

2010-10-12 Thread Alan DeKok
Terry Simons wrote: > I'm running into an issue where FreeRADIUS allows an invalid certificate (one > not signed by my configured CA) to successfully authenticate to EAP-TLS. Well... the code which prints the error "verify error:num=20:" is in the "verify certificate callback" function. It's r

EAP-TLS authentication allows me to authenticate with invalid certificate.

2010-10-12 Thread Terry Simons
Hi, I'm running into an issue where FreeRADIUS allows an invalid certificate (one not signed by my configured CA) to successfully authenticate to EAP-TLS. There's a message in the log that clearly indicates that the CA wasn't found (--> verify error:num=20:unable to get local issuer certificate