23
Jun

apel la ajutorul natiunii

   Posted by: cristina_crow   in Uncategorized

Nu pricep/gasesc/nu stiu unde sa caut/nu stiu sa caut pe google…sau in RTFRFC/freeradius.org si nici timp nu prea am de “studiu”…

Am un freeradius cu EAP-TLS (2.0.4), iar in eap.conf fac matching pe CN-ul de la CA si de la certificatele clientilor, asa:

check_cert_issuer =”/CN=VPN-CA”

check_cert_cn = %{peer}

Problema este ca, desi pe Issuer face match ok, eu nu stiu sa-l fac sa matchuiasca ok si CN-ul userilor, therefore, acum “merge” pentru ca i-am comentat linia de check_cert_cn.

Certificatele de la clientii mei au in CN ceva de genul: peer1, peer2…peer 1000. Oamenii de la freeradius zic: “If check_cert_cn is set, the value will be xlat’ed and checked against the CN in the client certificate.  If the values do not match, the certificate verification will fail rejecting the user.” Cum ar trebui sa pun expresia asta, a.i. sa imi matchuiasca toti userii/fiecare  user?

Tags: ,

This entry was posted on Tuesday, June 23rd, 2009 at 3:49 pm and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

6 comments so far

vmp
 1 

Workaround: don’t do that.

De ce vrei sa verifici neaparat subject-ul? Trust everyone.

June 23rd, 2009 at 4:57 pm
 2 

@vmp: I work in security; I trust NOONE :P

June 23rd, 2009 at 4:59 pm
 3 

1) Certificatul tau are doar CN= sau are CN compus (i.e. are si e-mail in CN)?
2) FreeRADIUS are -z (sau -x ? nu mai stiu) care spune tot ce face, inclusiv expandarea %{} in momentul procesarii cererii — foloseste-l cu incredere. O sa te indragostesti de el ca de tcpdump/wireshark ;-)

@Dexter

June 23rd, 2009 at 9:22 pm
 4 

O sa incerc :) Mersi

June 24th, 2009 at 10:49 am
someon
 5 

lol, am inteles 1% din ce-ai zis tu acolo, si ma credeam destept.
I won’t be reading this blog anymore, cacunostintele tale de aiti nu maciuesc cu ale mele.
Good luck, geek girl!

June 24th, 2009 at 6:05 pm
 6 

@someon: unele posturi sunt mai “techie”, dar mnah…:P asta e, lucrez in IT…cik :P

June 24th, 2009 at 6:57 pm

Leave a reply

Name
Mail (will not be published)
URI
Comment