<HTML><HEAD>
<META http-equiv=Content-Type content='text/html; charset=windows-1252'>
<title>Samsung Enterprise Portal mySingle</title>
<style> P, td, li {font-family:Arial, arial; font-size:9pt; margin-top:5px;margin-bottom:5px;} body{font-family:Arial, arial; font-size:9pt;}</style>
</HEAD><BODY><br><p>Hi,</p>
<p> </p>
<p>I would like to request Moderator to unsubscribe my mail ID from the list.</p>
<p> </p>
<p>Thanks & Regards</p>
<p>Pankaj</p>
<p> </p><br><br>------- <b>Original Message</b> -------<br><b>Sender</b> : Jouni Malinen<j@w1.fi><br><b>Date</b> : 2008-10-31 04:04 (GMT+09:00)<br><b>Title</b> : Re: Problems with EAP-TTLS/EAP-TLS - One Step further<br><br>On Thu, Oct 30, 2008 at 03:11:39PM +0100, Carolin Latze wrote:
<br>
<br>> meanwhile I tried several things and didn't succeed but I have an idea
<br>> what's going wrong. It seems that the wpa_supplicant only takes the
<br>> engine for the outer authentication. Is that possible?
<br>
<br>Yes, that is quite possible. I have not tested using OpenSSL engine in
<br>phase 2.
<br>
<br>> Therefore my question: On the wpa_supplicant homepage I saw that
<br>> EAP-TTLS/EAP-TLS has been tested with FreeRADIUS. Is there a place where
<br>> to download the test configurations? That would be very helpful for me!
<br>> I want to try to use EAP-TTLS/EAP-TLS without engine for a first test
<br>> (take out the complexity in order to understand it :)). I tried it with:
<br>
<br>This worked when I lasted tested it, but I've only tested without an
<br>engine and EAP-TLS inside EAP-PEAP or -TTLS has previously been somewhat
<br>of a problem case, so you may need to update FreeRADIUS unless you are
<br>using the latest release.
<br>
<br>> eap=TTLS
<br>>
<br>> phase2="autheap=TLS"
<br>>
<br>> identity="10.1.1.5"
<br>> ca_cert="/home/latze/cert/cacert.pem"
<br>> client_cert2="/home/latze/cert/basisk_cert.pem"
<br>> private_key2="/home/latze/cert/basisk_key.pem"
<br>> private_key2_passwd="PW"
<br>
<br>I would recommend including ca_cert2 here, too, so that wpa_supplicant
<br>will verify server certificate in phase2 should the server be using a
<br>different key in phase 1 and 2 (not really a very likely case, but
<br>anyway, it is good to validate certificates both in phase 1 and 2).
<br>
<br>--
<br>Jouni Malinen PGP id EFC895FA
<br>_______________________________________________
<br>HostAP mailing list
<br>HostAP@lists.shmoo.com
<br>http://lists.shmoo.com/mailman/listinfo/hostap
<br><p> </p><p> </p><!--SP:pankaj.razdan-->
<p><font color="blue"><i>SOC Software
</i></font></p>
<p><FONT face="??" color="blue"><SPAN
style="FONT-SIZE: 10pt"><i>Wireless Solution Lab. </i></SPAN></FONT></p>
<P style="line-height:1; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial; font-family:???,arial;"><FONT face="??" color="blue"><SPAN
style="FONT-SIZE: 10pt"><i>Institute of Central R&D</i></SPAN></FONT><FONT face="??" color=#161685><SPAN
style="FONT-SIZE: 10pt"><i> </i></SPAN></FONT></P><p><img src="file:///C|/Documents%20and%20Settings/Administrator/Desktop/samg.GIF" align="bottom" width="156" height="56" border="0" alt="samg.GIF">
</p>
<p> <font color="blue"> Electro-Mechanics</font></p><!--pankaj.razdan:EP--><p> </p><p> </p></BODY></HTML>