LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-21-2007, 09:11 PM   #1
lindope
LQ Newbie
 
Registered: Aug 2007
Location: Washington State
Distribution: openSUSE 10.3 & 11.0
Posts: 9

Rep: Reputation: 0
wpa_supplicant and multiple certificates


I am attempting to connect to my university's network which uses:
128-bit rotating dynamic WEP keys and EAP-TTLS/PAP and server-only certificates.
I am using wpa_supplicant.

The university provides two certificates which I understand are chosen randomly.

I have seen talk here about the ca_cert2="/blah" setting and am I correct that is only for setting the certificate for the phase2 (i.e. PAP) level?

How do I designate two certificates otherwise?

Konqueror and KCertPart indicate the two certificates provided by the U are DEM, PEM, or Netscape encoded X.509 type. They have .cer extensions. I tried concatenating them into one using the openssl 'cat' command and designating both.pem as the output but here is what I get from wpa_supplicant with ca_cert="/etc/cert/both.pem" and -d set:

Code:
CTRL-EVENT-EAP-STARTED EAP authentication started
CTRL-EVENT-EAP-METHOD EAP vendor 0 method 21 (TTLS) selected
OpenSSL: tls_connection_ca_cert - Failed to load root certificates error:00000000:lib(0):func(0):reason(0)
OpenSSL: tls_load_ca_der - Failed load CA in DER format error:0B07C065:x509 certificate routines:X509_STORE_add_cert:cert already in hash table
OpenSSL: tls_connection_handshake - Failed to read possible Application Data error:00000000:lib(0):func(0):reason(0)
CTRL-EVENT-EAP-SUCCESS EAP authentication completed successfully
CTRL-EVENT-CONNECTED - Connection to 00:14:f2:da:1f:d0 completed (reauth) [id=0 id_str=]
While it does authenticate, I am unsure why the fail to load error, is this not a problem? Or,is it allowing me to authenticate because I've also imported the certificates to my system using Kleopatra? (note: cert already in hash table) Or, is it really reading them and I just don't see it because I only set -d and not -dd ?

I would like to know if there is a way to call either/both certificates, perhaps
ca_cert="/etc/cert/cert1.cer, /etc/cert/cert2.cer"

also, what is the ca_path="/etc/cert/" command used for?

Sorry for a lot of questions, but I have searched for days on some documentation on multiple certificates and have come up empty handed...lindope
 
Old 12-30-2007, 11:22 AM   #2
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
Found this from a quick google search. http://64.233.167.104/linux?q=cache:...lnk&cd=1&gl=us
Also this may help as well. http://hostap.epitest.fi/wpa_supplic...configure.html

Let us know if any helps.
Brian
 
Old 12-30-2007, 02:36 PM   #3
lindope
LQ Newbie
 
Registered: Aug 2007
Location: Washington State
Distribution: openSUSE 10.3 & 11.0
Posts: 9

Original Poster
Rep: Reputation: 0
I appreciate the effort Brian, but there is nothing there regarding multiple certificates. I have considered looking into xsupplicant to see if it handles certificates differently but was hoping wpa_supplicant would do handle it.

I have googled extensively to no avail regarding multiple certificates. I probably should leave well enough alone. I've got the connection working, and once I shut off debug I don't see the read errors. I just thought there might be a better way to implement the dual certificates, but I guess not to many are using that. thanks again.

The larger concerns I have now is automating two different configurations, one for home, one for school. I still haven't figured out the xinetd.d in this SuSE. If someone has a script for choosing ifconfig settings it would help as I'm still too newb to be proficient at scripts.

Also/or, (probably fodder for a new thread) how to get wpa_gui to run as non-root.

lindope
 
Old 12-30-2007, 03:13 PM   #4
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
Never seen anything quite like that so I would contact the wpa_supplicant team and ask them for a possible configuration setup. If you figure it out post back.

Brian
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSL Certificates SBN Linux - Security 1 09-30-2006 03:29 AM
how do i install certificates ? jik Linux - Newbie 1 08-19-2004 04:57 AM
OpenSSL Certificates time112852 Linux - Security 1 05-01-2004 04:27 PM
certificates for linux udayan Linux - Newbie 1 07-30-2002 07:11 AM
Multiple SSL Certificates Per IP Address dkochan Linux - General 1 03-05-2002 01:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration