Open SSL and EKU
Hi All,
I have been battling with FreeRadius with LDAP backend and Microsofts built-in supplicant. I found on some directions that the certificate you use have to have a EKU(Enhanced Key Usage) with an ODI of “1.3.6.1.5.5.7.3.1” and a Client side Cert with the same except a ODI of “1.3.6.1.5.5.7.3.2”. First off, is this still the case in Windows 7/xp?
If it is, how do I add that to a certificate with OpenSSL, FYI I am using the ca.cnf/server.cnf under the /etc/raddb/certs directory.
Another question, has anyone got the MS Supplicant to work with Freeradius and a LDAP backend? If so can you point me in the direction of some good walk through?
Thanks
|