Re: Requesting guidance to understand all moving parts for RadSec + EAP-TLS

Alan DeKok <[email protected]>
Newsgroups gmane.comp.freeradius.user
Message-ID <[email protected]>
On Apr 20, 2025, at 2:17 PM, Yoann Gini <[email protected]> wrote:
> But if I put all of the CA into ca_dir, the Let’s Encrypt issued certificates could also be used to pass client auth?

  Technically, yes.  Practically no.

  The LetsEncrypt certificates generally aren't CAs.  So they can't issue client certs.

  Even if they were CAs, you can run the server in debug mode, and see what it prints out about the TLS certificates.

  You can then add policies to check the TLS-* attributes, to verify that the client certificates are created by a CA you trust.

  Alan DeKok.

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.