Let’s Encrypt EAP-PEAP WiFi certificate

Started by GreenMatter, September 08, 2020, 10:15:33 PM

Previous topic - Next topic
I use Freeradius and I set LE certificate to be used for eap peap authentication. Unfortunately it does show up on iOS devices as untrusted (despite that is trusted on webpage).
Maybe it requires full chain certificate?
OPNsense on:
Intel(R) Xeon(R) E-2278G CPU @ 3.40GHz (4 cores)
8 GB RAM
50 GB HDD
and plenty of vlans ;-)


September 09, 2020, 10:13:35 AM #2 Last Edit: September 09, 2020, 01:18:44 PM by Fright
GreenMatter, untrusted or not verified?
its how ios works
https://framebyframewifi.net/2017/01/29/use-lets-encrypt-certificates-with-freeradius/
first comments

I dont trust it, noone should. If you are really concerned set up a PKI, if you are not, you can still use WPA2 without 802.1X



September 09, 2020, 01:29:20 PM #6 Last Edit: September 09, 2020, 01:38:21 PM by Fright
will switch to my own PKI (currently use for inside services. for services available via the Internet i use LE)

Quote from: mimugmail on September 09, 2020, 08:13:47 AM
Why do you want to use LE for such serious service?
I wanted to have/use publicly trusted certificate to do not force guest users to accept self signed certificate...


iOS device shown certificate as untrusted, thanks @Fright for link. Have a closer look at it.
OPNsense on:
Intel(R) Xeon(R) E-2278G CPU @ 3.40GHz (4 cores)
8 GB RAM
50 GB HDD
and plenty of vlans ;-)

One more thing, OSX based computers also show LE certificate as untrusted when is used for Freeradius WiFi validation.


Long story short, it's better to use tailor made, self signed certificate with validity of let's say, 2 years? 😄
OPNsense on:
Intel(R) Xeon(R) E-2278G CPU @ 3.40GHz (4 cores)
8 GB RAM
50 GB HDD
and plenty of vlans ;-)


Quote from: mimugmail on September 09, 2020, 08:28:42 PM
Guests should use WPA Personal or Open plus captive portal
Regardless guests, since users need to accept LE (untrusted) certificate every 2 months, so it is better to use untrusted, self signed certificate with much longer validity...
OPNsense on:
Intel(R) Xeon(R) E-2278G CPU @ 3.40GHz (4 cores)
8 GB RAM
50 GB HDD
and plenty of vlans ;-)