Changes between Version 68 and Version 69 of WikiStart


Ignore:
Timestamp:
Jun 5, 2013, 4:08:19 PM (11 years ago)
Author:
walter
Comment:

pem contains private key strip

Legend:

Unmodified
Added
Removed
Modified
  • WikiStart

    v68 v69  
    11931193}}}
    11941194
    1195 During install of freeradius, certificates are probably auto generated see "/etc/freeradius/certs" folder. These are needed for the eduroam idP part to allow locally authentication of the @wleiden.net realm. However these certificates are made with a common/default credentials but they can also be made again/customized by running the ./bootstrap command and editing the *.cnf (ca, client, server)files to fit your institution/identity. See /usr/share/doc/freeradius/examples/certs/. Bootstrap will probably not run for a second time so move/delete all other files excepts these: bootstrap ca.cnf client.cnf README server.cnf xpextensions
    1196 
    1197 
    1198 TODO Which public certificate files needs to be distributed to the users for their supplicants?
     1195During install of freeradius, certificates are probably auto generated see "/etc/freeradius/certs" folder. These are needed for the eduroam idP part to allow locally authentication of the @wleiden.net realm. However these certificates are made with a common/default credentials but they can also be made again/customized by running the ./bootstrap command and editing the *.cnf (ca, client, server)files to fit your institution/identity. See /usr/share/doc/freeradius/examples/certs/. Bootstrap will probably not run for a second time so move/delete all other files excepts these: bootstrap ca.cnf client.cnf README server.cnf xpextensions.
     1196
     1197For editing/customizing the *.cnf files make sure the "server.cnf" and "client.cnf" have a different "commonname" at the end of their files otherwise database TXTDB 2 error.
     1198
     1199The server.pem file is the one that needs to be distributed/deployed among the eduroam users to correctly setup their supplicants for savely logging in. Also the ca.pem needs to be converted by osx to cer to be used by windows. The pem file we deliver needs to be stripped of bag attributes and PRIVATEKEY? Windows mac use different formats?
    11991200
    12001201Continue setting up isc-dhcp-server. Besides editing the conf file, the service also needs to be removed from its default boot routine because it starts to early before its openvpn interface is online!
     
    14771478https://confluence.terena.org/display/H2eduroam/freeradius-idp
    14781479https://confluence.terena.org/display/H2eduroam/freeradius-sp
    1479 
    1480 = Old HOWTO =
     1480https://support.ssl.com/index.php?/Knowledgebase/Article/View/19
     1481
     1482http://serverfault.com/questions/9708/what-is-a-pem-file-and-how-does-it-differ-from-other-openssl-generated-key-file= Old HOWTO =
    14811483== A. Achtergrond informatie ==
    14821484