hostapd.eap_user partial matching of username.
asalinas at sierrawireless.com
Thu Aug 13 13:18:05 EDT 2015
I'm testing hostapd's RADIUS functionality using EAP-TLS. Everything works (clients get authenticated) when I use either * or the full SAN (Subject Alt Name) as username e.g. "laptop1 at example.com"
I'm wondering if it is possible to do partial matching of the SAN, something like *@example.com. So that all machines with a SAN containing the domain "@example.com" would be authenticated without having to list them individually. ( "laptop1 at example.com", "laptop2 at example.com" )
Alternatively, can one use a partial DN as the username? e.g the value of OU=group1 or O=example.
More information about the HostAP