Re: Intermediate-Trust certificate issues
Alan DeKok via Freeradius-Users <[email protected]> Fri, 1 May 2026 15:19:39 -0400
| Newsgroups | gmane.comp.freeradius.user |
|---|---|
| Message-ID | <[email protected]> |
--===============3216533825447979377== Content-Type: multipart/signed; boundary="Apple-Mail=_5BCA355C-AB98-47B9-9160-8E5FD1E4EC33"; protocol="application/pgp-signature"; micalg=pgp-sha256 --Apple-Mail=_5BCA355C-AB98-47B9-9160-8E5FD1E4EC33 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 On May 1, 2026, at 2:35=E2=80=AFPM, Hector Rodriguez via = Freeradius-Users <[email protected]> wrote: > I hope everyone is well. Currently I have implemented Free Radius in = a test environment with EAP-TLS mode enabled. Which version? > My environment currently has a two tier PKI (CA Root and Ca Issuer = within the Intune Microsoft Cloud PKI environment) . Our Free Radius = server is configured to have an SSL from the CA server installed within = my Free Radius Server, which is generated by the CA config. Our Root CA = and Issuer CA certificates have been imported from Intune, and converted = from Cer to PEM/CRT file formats, and the EAP config file has been = edited to point to a bundled (full chain ) Issuer CA cert. The server's = certificate store has been updated to trust the Microsoft CA and Issuer = CA for our environment . I have created a configuration profile within = Intune to grant machines (in my case, just a test machine) to install = both CA ROOT and Issuer certs to their prespective certificate store. = Public certs are owned by the freerad user and currently have the 755 = permissions OK. There's always some magic fighting with certificates, but that = sounds reasonable. > Another thing to note is that we are currently using a Unifi switch = and we have set the controller profile to authenticate with Radius. I = have been going a bit insane trying to figure out why the Free Radius = server is not trusting my intermediate certificate when I have clearly = followed the appropriate instructions. No matter what I do the = intermediate cert is not trusted. Authentication only occurs when I = set:reject_unknown_intermediate_ca to No. I have been notciing that = other users have a similar issue, with PKI's related to Microsoft Cloud = PKI. Do you thing there will be a fix. Is there anything that I can do = for this issue ? Although it seems unsafe, do you think it would be Ok, = to set reject_unknown_intermediate_ca =3Dno ? IIRC there were issues with intermediate certs at one point. The fix = is likely in commit aca3a5955d4e i.e. it will be in 3.2.9, which we expect to release shortly. Alan DeKok. --Apple-Mail=_5BCA355C-AB98-47B9-9160-8E5FD1E4EC33 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEIUl02elqcIsf1zM0v3SJ0h7dTTMFAmn0/MsACgkQv3SJ0h7d TTPjKw/+KX9BFHO/Q5LmdGU7ezijLtpgwWqPdbFnmffhKdLC8aTIUPXnqhg7fAN0 JOGSWdPHRREF9EHrl54ZZtCcOiz4OuWblNdHS8fq6hI2GPiMBQ8p7v6REndXRxyz t+nBgu12DtAguj1RFFdC1lSMkEbFPQ+fkpuVTdgK9CoSdlEp9l37AwWqQTR7pUoJ wGCrYlTpP3rAFO3ExZvdw1TrLV2NPtX5LRcv35FUl+by/dTHm44W6YOsvpsLQL1G OcKoUEPAJv1hz8TTGqehUajcvP44/+7/8T6dvpW04o/Q6pEIrTsAuXpYMwcjG8ND 3YT8jcNVXpiTL/URVc0iCKfj9R0eg6fLbBPltCnERGpnEhLsYacc7ypL949qWBne k+ueHqwynd32Z76P3XXl9NAPCDzcxc/qYDzsdWblI5ugdGaHLRm3JBoqBidJP23A 7oWezOJPZQB/F0tpCf18BfcoIyHj9Q1uPUDdYlSrue2Fi53ylgY+agohkJiWvuep zYHtaNj+X7FOA6N+rBSBp6xFYidQTTPEW3X52cHB6iBaYeNAu78o1zHj0yv+MzGG vwSS+IY+cR0lShQiH12KgBui9Vci/R4HRohbNh5623Ubz70tPo2nAiNZY6C38jBT tdixwTTgVWeTypkBaljFjwZJXnc8xRa2AuQRqjiyGhA2xPWxOGk= =JP1J -----END PGP SIGNATURE----- --Apple-Mail=_5BCA355C-AB98-47B9-9160-8E5FD1E4EC33-- --===============3216533825447979377== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html --===============3216533825447979377==--