[RADIATOR] Extracting certificates info for EAP PEAP,TTLS,TLS

Christian Kratzer ck-lists at cksoft.de
Thu Feb 19 03:45:29 CST 2015

Hei Sami,

On Thu, 19 Feb 2015, Sami Keski-Kasari wrote:

> Hello Christian,
> Answer to first question:
> ------------------------
> We have used AuthBy INTERNAL between actual AuthBys to modify request
> message (for example in OTP cases that is very often needed to separate
> first and second factor). In AuthBy INTERNAL you can have for example
> AuthHook.

Thanks. That looks much simpler and fits nicely into the setup.

> Your TLS case could be something like this:
> Answer to second question:
> -------------------------
> There are special characters %x and %X that include user's EAP-Identity.
> %x is The EAP Identity for PEAP and TTLS inner requests.
> %X is the EAP identity, with any trailing @realm stripped off.

Thanks again.  Did not see those options.

> I hope this helps.

Yes it does a lot.  I will proceed with building the setup.

Kiitos ja Terveisin

Christian Kratzer                   CK Software GmbH
Email:   ck at cksoft.de               Wildberger Weg 24/2
Phone:   +49 7032 893 997 - 0       D-71126 Gaeufelden
Fax:     +49 7032 893 997 - 9       HRB 245288, Amtsgericht Stuttgart
Mobile:  +49 171 1947 843           Geschaeftsfuehrer: Christian Kratzer
Web:     http://www.cksoft.de/

More information about the radiator mailing list