hostapd.eap_user partial matching of username.

Alexis Salinas asalinas at sierrawireless.com
Thu Aug 13 13:18:05 EDT 2015


Hello list,
I'm testing hostapd's RADIUS functionality using EAP-TLS. Everything works (clients get authenticated) when I use either * or the full SAN (Subject Alt Name) as username e.g. "laptop1 at example.com"

I'm wondering if it is possible to do partial matching of the SAN, something like *@example.com. So that all machines with a SAN containing the domain "@example.com" would be authenticated without having to list them individually. (   "laptop1 at example.com",   "laptop2 at example.com" )

Alternatively, can one use a partial DN as the username? e.g the value of OU=group1 or O=example.

Thanks, 
Alexis.


More information about the HostAP mailing list