Re: EAP-TLS with different CA per user?

2008-06-09 Thread Frank Sweetser
Alan DeKok wrote: Frank Sweetser wrote: The usernames currently don't have a domain portion. Would it be possible for me to set a default domain for a given username? (The list is small, so would be manageable for me.) And if so, could you give me at least a rough example of how I would set t

Re: EAP-TLS with different CA per user?

2008-06-08 Thread Frank Sweetser
Alan DeKok wrote: > Frank Sweetser wrote: >> The usernames currently don't have a domain portion. Would it be possible >> for >> me to set a default domain for a given username? (The list is small, so >> would >> be manageable for me.) And if so, could you give me at least a rough example >> o

Re: EAP-TLS with different CA per user?

2008-06-07 Thread Alan DeKok
Frank Sweetser wrote: > The usernames currently don't have a domain portion. Would it be possible for > me to set a default domain for a given username? (The list is small, so would > be manageable for me.) And if so, could you give me at least a rough example > of how I would set this up? Yo

Re: EAP-TLS with different CA per user?

2008-06-07 Thread Frank Sweetser
SecureW2 (List) wrote: > Frank, > > It is not really a configuration issue, but more an Identity Management > issue. > > It is not common to have a CA per user, but a CA per domain. And per domain > you have users. In general, I certainly agree. The catch is that I'm attempting to handle certs

Re: EAP-TLS with different CA per user?

2008-06-07 Thread Matt Causey
In our company, we do have certificates signed by multiple Certificate Authorities...but there is a hierarchy. So, some users come in from Domain A (root CA) some come in from Domain B (intermediate CA). So then it's easyjust maintain the CA_path containing the root and any necessary interme

RE: EAP-TLS with different CA per user?

2008-06-07 Thread SecureW2 (List)
Frank, It is not really a configuration issue, but more an Identity Management issue. It is not common to have a CA per user, but a CA per domain. And per domain you have users. So: User X from domain A has CA 1. User Y from domain B has CA 2. If this is what you are trying to achieve you can