Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-20 Thread Vincent Guardiola
Hi, I've read documentation and not found responses for my problem. I wonder if I correctly explain my request I would like to use a cllient certificats and mschapV2 in the same authentification in PEAP or TTLS Use client certificats for create TLS tunel and after use mschapv2 for authenticate

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-20 Thread Alan DeKok
Vincent Guardiola wrote: I've read documentation and not found responses for my problem. It is documented. I wonder if I correctly explain my request I would like to use a cllient certificats and mschapV2 in the same authentification in PEAP or TTLS Use client certificats for create

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-20 Thread Vincent Guardiola
Ok, I don't understand why my config doenst work or maybe i've erroe on my client, this my conf : eap.conf eap { default_eap_type = peap timer_expire = 60 ignore_unknown_eap_types = no cisco_accounting_username_bug = no

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-20 Thread Alan DeKok
Vincent Guardiola wrote: Ok, I don't understand why my config doenst work or maybe i've erroe on my client, this my conf : You've butchered the configuration. Why? The default configuration works. Use it. Then, read the default eap.conf, which contains documentation describing how

EAP-TTLS/EAP-PEAP Certificats

2011-12-15 Thread Vincent Guardiola
Hi all, I have just one question about client certificats with EAP-TTLS or EAP-PEAP. I would like use certificats client with authentication MSCHAPv2 it's possible ? It's possible to use client certificats for create TLS tunel and use mschapv2 auth inside ? In my test the authentication is

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-15 Thread Phil Mayers
On 15/12/11 14:29, Vincent Guardiola wrote: Hi all, I have just one question about client certificats with EAP-TTLS or EAP-PEAP. I would like use certificats client with authentication MSCHAPv2 it's possible ? Yes. This is documented in the eap.conf: # You can make PEAP require a client

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-15 Thread Vincent Guardiola
Humm yes, but with this i can use mschapv2 for authenticate or my authentification will be used by client certificat ? 2011/12/15 Phil Mayers p.may...@imperial.ac.uk On 15/12/11 14:29, Vincent Guardiola wrote: Hi all, I have just one question about client certificats with EAP-TTLS or

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-15 Thread Phil Mayers
On 15/12/11 15:12, Vincent Guardiola wrote: Humm yes, but with this i can use mschapv2 for authenticate or my Yes. authentification will be used by client certificat ? No. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-15 Thread Vincent Guardiola
Ok I will try this :), I don't use inner-tunnel file it's required or not ?, I just use file sites-enable/default 2011/12/15 Phil Mayers p.may...@imperial.ac.uk On 15/12/11 15:12, Vincent Guardiola wrote: Humm yes, but with this i can use mschapv2 for authenticate or my Yes.

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-15 Thread Phil Mayers
On 15/12/11 16:14, Vincent Guardiola wrote: Ok I will try this :), I don't use inner-tunnel file it's required or not ?, I just use file sites-enable/default Not sure. Try it. I would always advise using inner-tunnel; it makes a lot of logical sense to have the PEAP inner processed

Re: EAP-TTLS/EAP-PEAP Certificats

2011-12-15 Thread Alan DeKok
Vincent Guardiola wrote: Ok I will try this :), I don't use inner-tunnel file it's required or not ?, I just use file sites-enable/default Please read the documentation and examples that come with the server. It's MUCH nicer than asking questions which are already answered. Alan