Help with advanced FreeRADIUS + MySQL setup using EAP-TLS

Ariel García Reyes <[email protected]>
Newsgroups gmane.comp.freeradius.user
Message-ID <CAB4dDDo=2uuKhb+LDGA+SkAEm=H_9ZvULDHjDvPMdtKKX0eOLA@mail.gmail.com>
Hi everyone,

I'm working on a FreeRADIUS setup connected to MySQL, and I need help
configuring a stricter access validation process.

Currently, *EAP-TLS authentication is working* — if a user has a valid
certificate, they can connect successfully.

However, I want to ensure that *three specific conditions* are met before
granting access:

   1.

   ✅ *The EAP-TLS certificate must be valid.*
   2.

   ✅ *The user must exist in the database and be marked as active.*
   3.

   ✅ *The device requesting access (by MAC address) must be registered and
   associated with that user.*

A user may have multiple devices, but *all three conditions* must be
satisfied to allow access.

Could anyone guide me on how to implement this kind of validation in
FreeRADIUS using MySQL?

Thanks in advance for any help or examples you can share!

--
________________________________________________
Lic. Ariel García Reyes.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.