TRUSTED CERTIFICATE

Alyssa Ross <[email protected]> Fri, 04 Oct 2024 16:52:11 +0200
Newsgroups dev.linux.lists.ell
Message-ID <[email protected]>
Hello,

I encountered a problem when attempting to connect to a WPA2 Enterprise
network with iwd, that I think is caused by ell not understanding some
certificates.

I'm pretty confident that it should be valid to point EAP-TTLS-CACert to
the /etc/ssl/certs/ca-bundle.crt that comes with my distro.  I believe
this has worked with NetworkManager/wpa_supplicant for me in the past.
It doesn't work with iwd/ell, because
l_pem_load_certificate_list_from_data will error if any of the entries
in the provided PEM data don't have the "CERTIFICATE" label, but some of
the entries in my ca-bundle.crt have the "TRUSTED CERTIFICATE" label.

I think ell should therefore either support trusted certificates (or at
least give up if it finds any), so that users don't need to manually
configure a certificate for networks with certificates signed by a CA in
the system's bundle.
signature.asc (application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEH9wgcxqlHM/ARR3h+dvtSFmyccAFAmcAARsACgkQ+dvtSFmy
ccBEqw//YdnQshRB39NF5deXJos47gH9SWQ5RMeRArXaq0OT26bwrVPCk2FPgSMu
hTF3gshfFlOj9OyvOrfG7Oc82vEfryC9IolOxafHjebwv4LdFGqxuWPA+3J7PZfO
Ar2LQlurTLKcoNZLokXG4QO7or2di7tT1Gmio0WLJ3QIINFX48lEjtzSfxAxtd0W
PmADJTApIHRSjL21dj57yMNfVKzCchHcecomzP1iNp2MnfNlpdx5skxCbBjeytX4
S71Av2f7ubWLUtPUWpk9IlIABtZSUWo4pfYMnj5XxE8+FfMcrQSpl6OgjklABBAv
ctlKqyVZgBSu8UnnzrwS0dxh9om574xhH3AXYgJh86Plmv6FH8f8E7cZGRGwbIE2
m9oG5flew2Zt9ZxzIL8cFcD17TjEh1JLx5Rs0McX6dh598e+ufS4K7jQDSFpCXvB
U8LvVBiucNQ8bhCCk7dPsREUzk645uaBRUNyhfO079/sGbIHF+OUZptzNjKxENqo
FhR+ptnUtXGgB0SXAqwVkdyLIHd0j1fEmGpsg16rXN0iKSsC/UFzGIvLDVoyRUr7
oMm3he/rNhXVtRCdgndGy6/D69cKB7IO3tzGQgHvtbrQIzGwmpaZjSwSh1WC87vQ
lNj16awW0sTqQ6XUwkXNhOU4hy9s9A2ENN8/XdjAKOrwa+Qk6DI=
=nK7L
-----END PGP SIGNATURE-----