<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WPA Wireless Authentication with eDirectory and&#160;FreeRADIUS</title>
	<atom:link href="http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/</link>
	<description>developer by day, developer by night</description>
	<lastBuildDate>Sat, 17 Jul 2010 19:16:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: FreeRaduis and OES2 SP2 - Linux - NOVELL FORUMS</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-13253</link>
		<dc:creator>FreeRaduis and OES2 SP2 - Linux - NOVELL FORUMS</dc:creator>
		<pubDate>Mon, 14 Jun 2010 16:14:37 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-13253</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Stavert</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-13186</link>
		<dc:creator>Matt Stavert</dc:creator>
		<pubDate>Wed, 09 Jun 2010 22:14:19 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-13186</guid>
		<description>How do I make the certificates longer than one year?  Any guidence would be fantastic, please email, staverts@shaw.ca</description>
		<content:encoded><![CDATA[<p>How do I make the certificates longer than one year?  Any guidence would be fantastic, please email, <a href="mailto:staverts@shaw.ca">staverts@shaw.ca</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Hallahan</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-12694</link>
		<dc:creator>Jim Hallahan</dc:creator>
		<pubDate>Mon, 01 Feb 2010 16:26:04 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-12694</guid>
		<description>Having trouble getting this solution working. Works fine with LDAP auth. and NTRadTest. I seem to be having trouble with the certificates on the XP workstation. Anybody have any tips regarding what certificates I need to import to the workstation, type/format etc.. jim.hallahan@gmail.com.

Jim Hallahan</description>
		<content:encoded><![CDATA[<p>Having trouble getting this solution working. Works fine with LDAP auth. and NTRadTest. I seem to be having trouble with the certificates on the XP workstation. Anybody have any tips regarding what certificates I need to import to the workstation, type/format etc.. <a href="mailto:jim.hallahan@gmail.com">jim.hallahan@gmail.com</a>.</p>
<p>Jim Hallahan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Hallahan</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-12492</link>
		<dc:creator>Jim Hallahan</dc:creator>
		<pubDate>Thu, 28 Jan 2010 09:46:52 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-12492</guid>
		<description>Great article. Haven&#039;t tried the connection on the XP yet. I am also a littel confused as the certificate format for the windows xp client. Is it supposed to be servercert.pem or should it be something like servercert.cer ? The documentation says export yast ca to servercert.pem, later on the documentation refers to importing cert.cer on the windows xp machine. I get an authentication accept using  ntradping. Will be trying it on an XP tomorrow.

Thanks for the effort
Jim Hallahan</description>
		<content:encoded><![CDATA[<p>Great article. Haven&#8217;t tried the connection on the XP yet. I am also a littel confused as the certificate format for the windows xp client. Is it supposed to be servercert.pem or should it be something like servercert.cer ? The documentation says export yast ca to servercert.pem, later on the documentation refers to importing cert.cer on the windows xp machine. I get an authentication accept using  ntradping. Will be trying it on an XP tomorrow.</p>
<p>Thanks for the effort<br />
Jim Hallahan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick Bousquet</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-11740</link>
		<dc:creator>Rick Bousquet</dc:creator>
		<pubDate>Wed, 11 Nov 2009 17:21:08 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-11740</guid>
		<description>For anyone who runs into this. The default cert created by Sles is one year. Before undertaking this create a new server cert and than export it. Make it longer than a year. Dave you some pain one day when people get expired cert errors.</description>
		<content:encoded><![CDATA[<p>For anyone who runs into this. The default cert created by Sles is one year. Before undertaking this create a new server cert and than export it. Make it longer than a year. Dave you some pain one day when people get expired cert errors.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Corrigan</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-7844</link>
		<dc:creator>Patrick Corrigan</dc:creator>
		<pubDate>Fri, 26 Jun 2009 22:38:32 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-7844</guid>
		<description>Please ignore my last message. I should have read forward! Thanks.</description>
		<content:encoded><![CDATA[<p>Please ignore my last message. I should have read forward! Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Corrigan</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-7843</link>
		<dc:creator>Patrick Corrigan</dc:creator>
		<pubDate>Fri, 26 Jun 2009 22:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-7843</guid>
		<description>Thanks for a great, comprehensive article. I have one question: The CA accessible through YAST is the YAST_Default_CA.

Don&#039;t I need the eDirectory Organizational CA?

Thanks.</description>
		<content:encoded><![CDATA[<p>Thanks for a great, comprehensive article. I have one question: The CA accessible through YAST is the YAST_Default_CA.</p>
<p>Don&#8217;t I need the eDirectory Organizational CA?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Isted</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-7770</link>
		<dc:creator>Richard Isted</dc:creator>
		<pubDate>Mon, 22 Jun 2009 12:36:45 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-7770</guid>
		<description>Chris,

Just wanted to say a massive thank you for creating this arlicle.  This has been driving me round the bend for a while and your guide got me 95% there.

Two things caught me out.

1.  Problem with the certificates:  I had an issue as I was connecting to ldap on 127.0.0.1 and it kept giving me a tls error.  I eventually realised this was because the server name in the certificate was set to radius-server but that was not associated to 127.0.0.1.  I made a hosts entry for the server IP 192.168.1.10 and set this to radius-server, then set the ldap server (in radius.conf) to connect to as 192.168.1.10 instead of 127.0.0.1.

2.  When trying to authenticate I kept getting (rlm_ldap: Error reading Universal Password.Return Code = -1659), amongst other errors.  Basically I think it means that the radiusAdmin user was not able to read the universal password for my account.

Basically it would seem that you do need to enable Forgotten Password feature then allow admin to retreive the passwords, the guide says to turn it off.  To do this in iManager go to the Password Policies option.  Go to the forgotten password tab and just click enable then apply.  After that click on the Universal Passwords tab then Configuration Options then under the Universal Password Retrieval section tick the Allow admin to retrieve passwords, I also unticked Allow user to retrieve passwords.  I was not able specifically specify any objects or users but it seems to work just fine.

I think that was everything I did (hopefully)

Thanks again!


Rich.</description>
		<content:encoded><![CDATA[<p>Chris,</p>
<p>Just wanted to say a massive thank you for creating this arlicle.  This has been driving me round the bend for a while and your guide got me 95% there.</p>
<p>Two things caught me out.</p>
<p>1.  Problem with the certificates:  I had an issue as I was connecting to ldap on 127.0.0.1 and it kept giving me a tls error.  I eventually realised this was because the server name in the certificate was set to radius-server but that was not associated to 127.0.0.1.  I made a hosts entry for the server IP 192.168.1.10 and set this to radius-server, then set the ldap server (in radius.conf) to connect to as 192.168.1.10 instead of 127.0.0.1.</p>
<p>2.  When trying to authenticate I kept getting (rlm_ldap: Error reading Universal Password.Return Code = -1659), amongst other errors.  Basically I think it means that the radiusAdmin user was not able to read the universal password for my account.</p>
<p>Basically it would seem that you do need to enable Forgotten Password feature then allow admin to retreive the passwords, the guide says to turn it off.  To do this in iManager go to the Password Policies option.  Go to the forgotten password tab and just click enable then apply.  After that click on the Universal Passwords tab then Configuration Options then under the Universal Password Retrieval section tick the Allow admin to retrieve passwords, I also unticked Allow user to retrieve passwords.  I was not able specifically specify any objects or users but it seems to work just fine.</p>
<p>I think that was everything I did (hopefully)</p>
<p>Thanks again!</p>
<p>Rich.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arni Snorri Eggertsson</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-7563</link>
		<dc:creator>Arni Snorri Eggertsson</dc:creator>
		<pubDate>Fri, 12 Jun 2009 13:00:12 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-7563</guid>
		<description>Has anyone managed to do  &quot;single sign on&quot; with a novell client and this?</description>
		<content:encoded><![CDATA[<p>Has anyone managed to do  &#8220;single sign on&#8221; with a novell client and this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chrismoos</title>
		<link>http://chrismoos.com/2009/02/05/wpa-wireless-authentication-with-edirectory-and-freeradius-2/comment-page-1/#comment-4485</link>
		<dc:creator>chrismoos</dc:creator>
		<pubDate>Sat, 04 Apr 2009 23:02:23 +0000</pubDate>
		<guid isPermaLink="false">http://chrismoos.com/?p=176#comment-4485</guid>
		<description>I originally wrote this article years ago -- I can&#039;t believe there are people who still find it useful. That&#039;s great though!</description>
		<content:encoded><![CDATA[<p>I originally wrote this article years ago &#8212; I can&#8217;t believe there are people who still find it useful. That&#8217;s great though!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
