[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freeradius-users
Subject:    Re: EAP-TLS host certificates
From:       Alan DeKok <aland () deployingradius ! com>
Date:       2021-02-10 16:08:32
Message-ID: 633C7D9D-9BC8-438A-B06E-A3FBBCE75702 () deployingradius ! com
[Download RAW message or body]

On Feb 10, 2021, at 10:39 AM, Vieri Di Paola <vieridipaola@gmail.com> wrote:
> I found the time to resume my configuration and found out that
> importing the pem client certificate into the Windows "computer
> account" store does not work as I expect it to (see first post).
> However, importing the p12 certificate works perfectly.

  Ah, yes.  Different formats for different operating systems.

  I guess it would be too much to ask for Windows to either (a) give you an error \
when it can't import the cert, or (b) just convert it automatically.

> I'll have to
> tailor the Makefile as required. BTW why does the Makefile copy
> client.pem to USER_NAME.pem but doesn't do the same for p12 et al.? I
> know it's just there for convenience, but I'm wondering if it's for a
> specific design purpose. Maybe it's because the pem format works fine
> on non-Windoze clients.

  I've added a "cp" for the p12 certs, and updated the certs/README file to note that \
Windows need the p12 format.

  Alan DeKok.


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic