Re: The EAP Saga begins.

This is a discussion on Re: The EAP Saga begins. within the FreeRADIUS Users forums, part of the Networking and Network Related category; Evan Vittitow wrote: > I think a large part of my problem is the creation of a Certificate > authority. ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-22-2007
Alan DeKok
 
Posts: n/a
Default Re: The EAP Saga begins.

Evan Vittitow wrote:
> I think a large part of my problem is the creation of a Certificate
> authority.


Why? See the various 802.1x howto's (pointed to from freeradius.org &
the wiki) for how to create certificates for the server.

> Its very possible, that said Certificate authority for Radius could
> hypothetically be used layer for IPSec. This being the case, what would
> the best strategy be for implementing a PKI CA. Should I make one Cert
> for every host? One server host and one client Cert for all hosts?
> Different CAs for different Services? How will Mandriva's architecture
> change affect this?


You want one certificate for the RADIUS server. For most RADIUS
situations, this is enough. And that certificate shouldn't be used for
anything else.

Alan DeKok.
--
http://deployingradius.com - The web site of the book
http://deployingradius.com/blog/ - The blog
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 07:03 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0