(RADIATOR) Sending server certificate chain

Jan Tomasek jan at tomasek.cz
Mon Feb 18 09:29:58 CST 2008


Hi,

I've RADIUS server with chained certificate:

Subject:C=CZ,O=CESNET,CN=publikace.cesnet.cz
Issuer: C=BE,O=Cybertrust,OU=Educational CA,CN=Cybertrust Educational CA

Subject:C=BE,O=Cybertrust,OU=Educational CA,CN=Cybertrust Educational CA
Issuer: C=US,O=GTE Corporation,OU=GTE CyberTrust Solutions, Inc., CN=GTE 
CyberTrust Global Root

GTE CyberTrust Global Root is commonly installed in clients but 
Cybertrust Educational CA is not. To get Radiator correctly working with 
OpenSSL based clients like wpa_supplicant I need way how to instruct 
Radiator to send certificate of intermediate CA "Cybertrust Educational CA".

Apache does that by SSLCertificateChainFile directive, but Radiator 
seams to be missing something like this.

FreeRadius is able to get and send intermediate CA certificate when it 
is in same file as server certificate. But Radiator seams to ignore it.

Is there some way how to achieve sending intermediate CA to the client? 
And if not, is it possible to be added?


Thanks
-- 
-----------------------
Jan Tomasek aka Semik
http://www.tomasek.cz/

--
Archive at http://www.open.com.au/archives/radiator/
Announcements on radiator-announce at open.com.au
To unsubscribe, email 'majordomo at open.com.au' with
'unsubscribe radiator' in the body of the message.


More information about the radiator mailing list