Re: MAC address restriction with EAP-TLS

2009-01-27 Thread tnt
>> > >> >So how would I do the same thing for a certificate instead of a username? >> >> Ther will be a username in EAP-TLS request too. > >From everything that I have been able to read, the user name in a EAP-TLS >request should come from the CN value of the certificate. Does this >sound correct?

Re: MAC address restriction with EAP-TLS

2009-01-27 Thread John T. Guthrie III
Ivan Kalik wrote: > >> >We are currently using EAP-TLS authentication with FreeRADIUS at the place > >> >where I work right now. Management would like to be able to restrict the > >> >use > >> >of a given certificate for this authentication to specific MAC addresses. > >> > In > >> >other words

Re: MAC address restriction with EAP-TLS

2009-01-26 Thread tnt
>> >We are currently using EAP-TLS authentication with FreeRADIUS at the place >> >where I work right now. Management would like to be able to restrict the >> >use >> >of a given certificate for this authentication to specific MAC addresses. >> >In >> >other words, for each certificate, the des

Re: MAC address restriction with EAP-TLS

2009-01-25 Thread John T. Guthrie III
Ivan Kalik wrote: > >We are currently using EAP-TLS authentication with FreeRADIUS at the place > >where I work right now. Management would like to be able to restrict the use > >of a given certificate for this authentication to specific MAC addresses. In > >other words, for each certificate, th

Re: MAC address restriction with EAP-TLS

2009-01-23 Thread tnt
>We are currently using EAP-TLS authentication with FreeRADIUS at the place >where I work right now. Management would like to be able to restrict the use >of a given certificate for this authentication to specific MAC addresses. In >other words, for each certificate, the desire is to tie that cer

MAC address restriction with EAP-TLS

2009-01-23 Thread John T. Guthrie III
Hello all, We are currently using EAP-TLS authentication with FreeRADIUS at the place where I work right now. Management would like to be able to restrict the use of a given certificate for this authentication to specific MAC addresses. In other words, for each certificate, the desire is to tie