Re: Intermediate-Trust certificate issues

Alan DeKok via Freeradius-Users <[email protected]> Fri, 1 May 2026 15:19:39 -0400
Newsgroups gmane.comp.freeradius.user
Message-ID <[email protected]>
--===============3216533825447979377==
Content-Type: multipart/signed;
	boundary="Apple-Mail=_5BCA355C-AB98-47B9-9160-8E5FD1E4EC33";
	protocol="application/pgp-signature";
	micalg=pgp-sha256


--Apple-Mail=_5BCA355C-AB98-47B9-9160-8E5FD1E4EC33
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

On May 1, 2026, at 2:35=E2=80=AFPM, Hector Rodriguez via =
Freeradius-Users <[email protected]> wrote:
>  I hope everyone is well. Currently I have implemented Free Radius in =
a test environment with EAP-TLS mode enabled.

  Which version?

> My environment currently has a two tier PKI (CA Root and Ca Issuer =
within the Intune Microsoft Cloud PKI environment) . Our Free Radius =
server is configured to have an SSL from the CA server installed within =
my Free Radius Server, which is generated by the CA config. Our Root CA =
and Issuer CA certificates have been imported from Intune, and converted =
from Cer to PEM/CRT file formats, and the EAP config file has been =
edited to point to a bundled (full chain ) Issuer CA cert. The server's =
certificate store has been updated to trust the Microsoft CA and Issuer =
CA for our environment . I have created a configuration profile within =
Intune to grant machines (in my case, just a test machine) to install =
both CA ROOT and Issuer certs to their prespective certificate store.  =
Public certs are owned by the freerad user and currently have the 755 =
permissions

  OK.  There's always some magic fighting with certificates, but that =
sounds reasonable.

>   Another thing to note is that we are currently using a Unifi switch =
and we have set the controller profile to authenticate with Radius. I =
have been going a bit insane trying to figure out why the Free Radius =
server is not trusting my intermediate certificate when I have clearly =
followed the appropriate instructions. No matter what I do the =
intermediate cert is not trusted. Authentication only occurs when I =
set:reject_unknown_intermediate_ca  to No. I have been notciing that =
other users have a similar issue, with PKI's related to Microsoft Cloud =
PKI. Do you thing there will be a fix. Is there anything that I can do =
for this issue ? Although it seems unsafe, do you think it would be Ok, =
to  set reject_unknown_intermediate_ca =3Dno  ?

  IIRC there were issues with intermediate certs at one point.  The fix =
is likely in commit aca3a5955d4e

  i.e. it will be in 3.2.9, which we expect to release shortly.

  Alan DeKok.


--Apple-Mail=_5BCA355C-AB98-47B9-9160-8E5FD1E4EC33
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEIUl02elqcIsf1zM0v3SJ0h7dTTMFAmn0/MsACgkQv3SJ0h7d
TTPjKw/+KX9BFHO/Q5LmdGU7ezijLtpgwWqPdbFnmffhKdLC8aTIUPXnqhg7fAN0
JOGSWdPHRREF9EHrl54ZZtCcOiz4OuWblNdHS8fq6hI2GPiMBQ8p7v6REndXRxyz
t+nBgu12DtAguj1RFFdC1lSMkEbFPQ+fkpuVTdgK9CoSdlEp9l37AwWqQTR7pUoJ
wGCrYlTpP3rAFO3ExZvdw1TrLV2NPtX5LRcv35FUl+by/dTHm44W6YOsvpsLQL1G
OcKoUEPAJv1hz8TTGqehUajcvP44/+7/8T6dvpW04o/Q6pEIrTsAuXpYMwcjG8ND
3YT8jcNVXpiTL/URVc0iCKfj9R0eg6fLbBPltCnERGpnEhLsYacc7ypL949qWBne
k+ueHqwynd32Z76P3XXl9NAPCDzcxc/qYDzsdWblI5ugdGaHLRm3JBoqBidJP23A
7oWezOJPZQB/F0tpCf18BfcoIyHj9Q1uPUDdYlSrue2Fi53ylgY+agohkJiWvuep
zYHtaNj+X7FOA6N+rBSBp6xFYidQTTPEW3X52cHB6iBaYeNAu78o1zHj0yv+MzGG
vwSS+IY+cR0lShQiH12KgBui9Vci/R4HRohbNh5623Ubz70tPo2nAiNZY6C38jBT
tdixwTTgVWeTypkBaljFjwZJXnc8xRa2AuQRqjiyGhA2xPWxOGk=
=JP1J
-----END PGP SIGNATURE-----

--Apple-Mail=_5BCA355C-AB98-47B9-9160-8E5FD1E4EC33--

--===============3216533825447979377==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

--===============3216533825447979377==--