LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking > Linux - Wireless Networking
User Name
Password
Linux - Wireless Networking This forum is for the discussion of wireless networking in Linux.

Notices


Reply
  Search this Thread
Old 07-03-2006, 04:31 PM   #1
shermanramni
LQ Newbie
 
Registered: Feb 2006
Distribution: Fedora Core 6
Posts: 8

Rep: Reputation: 0
What and how for a hotspot?


Gentlemen:

I've been working in a project to build a hotspot under Linux for some weeks now. I've checked FreeRADIUS, OpenSSL and ChilliSpot documentation, and practiced with many Linux distros.
The requirements say that it must be SECURE (i.e. protected against wireless sniffing and no connectivity until the supplicant provides the correct credentials). For example, the supplicant connects to the AP and uses port-based authentication to provide Username/Password, which are verified by a RADIUS-SQL mix (FreeRADIUS + MySQL). If the credentials are valid, then the client is given a IP address and access to the network; else, no connectivity is provided.
Other requirement is that must support Windows XP clients, and nothing must be installed in the clients (except Microsoft patches if needed), not even digital certificates.
Can such an implementation be done? If so, what would I need (software)? Which protocols must I use?

Thanks in advance.

Sherman
 
Old 07-03-2006, 06:32 PM   #2
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
You need 80211i:
Software:
* FreeRadius (+MySQL) + Xsupplicant for the supplicants
* OpenSSL for creating certificates.

Protocols:
* EAP-TLS to authenticate by certificates
or
PEAP-MS-CHAPv2 which established a TLS tunnel to authenticate by passwords.

Ah just seen this
Quote:
must be SECURE
Remove the Windows XP
 
Old 07-03-2006, 09:45 PM   #3
shermanramni
LQ Newbie
 
Registered: Feb 2006
Distribution: Fedora Core 6
Posts: 8

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by nx5000
You need 80211i:
Software:
* FreeRadius (+MySQL) + Xsupplicant for the supplicants
* OpenSSL for creating certificates.

Protocols:
* EAP-TLS to authenticate by certificates
or
PEAP-MS-CHAPv2 which established a TLS tunnel to authenticate by passwords.
So, my solution is FreeRADIUS + MySQL + PEAP-MSCHAPv2. Any FAQs/tutorials/HOWTOs on that?

Quote:
Originally Posted by nx5000
Remove the Windows XP
lol

And the last question: Which Linux distro is the most convenient for this server impementation? I've tried Slackware and I've got used to it, but Ubuntu's package management and simplicity really caught me. Maybe Fedora is an option, too...
 
Old 07-04-2006, 07:42 AM   #4
2Gnu
Senior Member
 
Registered: Jan 2002
Location: Southern California
Distribution: Slackware
Posts: 1,880

Rep: Reputation: 51
Here's a decent writeup on PEAP/CHAP: http://www.microsoft.com/technet/com...uy/cg0702.mspx

The basic FreeRADIUS instructions, some specific to EAP/TLS, should give you the rest of the guidance you need: www.freeradius.org/doc/EAPTLS.pdf

As for distros, I'm a Slack bigot. Once you set up the authentication server, you'll not be doing much in the way of packages. I'm running a RADIUS box and I only add security updates (via Swaret). It you want to create packages for Slack, for easy removal or upgrades (without using the native Slack tools), try Checkinstall: http://asic-linux.com.mx/~izto/checkinstall/
 
Old 07-05-2006, 05:43 PM   #5
shermanramni
LQ Newbie
 
Registered: Feb 2006
Distribution: Fedora Core 6
Posts: 8

Original Poster
Rep: Reputation: 0
Tahnks for all your help.

Well, after struggling a lot, I finally made it. All my tech requirements have been met. Now I'm gonna organize all that and write a FAQ if someone wants to do it too.
Man, it's gonna take loooooooong...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Building a linux Wi-fi hotspot kudos Linux - Wireless Networking 3 08-09-2012 09:29 AM
linux wifi hotspot right for me? henrikwidth Linux - Wireless Networking 4 05-30-2006 02:06 PM
can linux connect to a hotspot? sublyme718 Linux - Wireless Networking 1 11-08-2005 12:07 AM
Pay Wi-Fi HotSpot Linux the best route? blackpenny15 Linux - Wireless Networking 2 06-20-2004 11:19 PM
Linux Hotspot tuxx Linux - Wireless Networking 0 03-04-2004 03:09 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking > Linux - Wireless Networking

All times are GMT -5. The time now is 02:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration