Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 20 Oct 2017 07:32:55 +0200
From:      =?utf-8?Q?Peter_Ankerst=C3=A5l?= <peter@pean.org>
To:        Charles Sprickman <spork@bway.net>
Cc:        Stefan Bethke <stb@lassitu.de>, FreeBSD Stable <freebsd-stable@freebsd.org>, Chris Ross <cross+freebsd@distal.com>
Subject:   Re: 802.1X authenticator for FreeBSD
Message-ID:  <82E419D4-4FB4-402A-ACC9-C58D498461BE@pean.org>
In-Reply-To: <3F040A9B-B03F-4FD5-B1DC-70BD8AFCC829@bway.net>
References:  <C34FB467-C2DB-4B59-9DD2-2491E7A136F1@pean.org> <AE175682-AD2B-4DAC-AF4C-3B6F3CDB7449@distal.com> <2D461E1D-895F-4D31-9834-A40DEF02F121@pean.org> <4F45AC20-57F9-4246-836E-4F1C1D01FAC2@lassitu.de> <2B2D49E0-F804-4557-9DB5-A915A8578070@pean.org> <3F040A9B-B03F-4FD5-B1DC-70BD8AFCC829@bway.net>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]


> On 18 Oct 2017, at 21:39, Charles Sprickman <spork@bway.net> wrote:
> 
> 
>> On Oct 18, 2017, at 1:10 PM, Peter Ankerstål <peter@pean.org> wrote:
>> 
>>> 
>>> I’m under the impression that the authenticator function in a wired network is usually part of the switch, and the switch will talk to some authentication server like RADIUS, giving it the port number of the connected device and additional information.
>>> 
>>> If FreeBSD had such a function, I think it would be limited to point-to-point Ethernet links, 802.1x being a link-layer protocol.
>>> 
>> 
>> Yes I know, but this is functional in hostapd for Linux and it would be nice to have it in FreeBSD as well. 
> 
> I’m not seeing this in FreeBSD, but pfsense does claim to support 802.1x for wifi.
> 
> I just happen to be reading about radius (last I used it was for dialup) for wifi auth and the quick overview on the radius side of things is that the AP software sends your auth info as well as MAC and a bunch of other stuff, and the radius server (much like dialup) sends back all sorts of info beyond auth success/fail - session timeout, info on what VLAN the client may be on, firewall policies, etc. Pretty cool stuff.

802.1X (or WPA2 Enterprise) works fine with hostapd for wireless in FreeBSD. Well, the authentication at least. I havent tried assigning clients to specific vlans and so on but according to the documentation it is possible.
[-- Attachment #2 --]
0	*H
010	+0	*H
00ʠk}
׈Q
Y0
	*H
0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
151216010005Z
301216010005Z0u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA0"0
	*H
0
}â}[[_u$Wy5	|̔
vnqY)\aL$dYG|B"QǤĩVD#'F	k9O_]*ςz_kU.u3r	#:C<ogT)K
Xah8v[\KqdlO)3+u7J5";[vfL/"2ϩJ#4ד[U TB,a˖a7H<=qd0`0U0U%0++0U002U+0)0'%#!http://crl.startssl.com/sfsca.crl0f+Z0X0$+0http://ocsp.startssl.com00+0$http://aia.startssl.com/certs/ca.crt0U$l9aIF+('Hmh0U#0N@[i04hCA0?U 80604U 0,0*+http://www.startssl.com/policy0
	*H
[#'#4pnRۡЗN⛭`]K"#H*߷Թψ;UA8Ҟeg{ozmYE60A)wXRK6c^-Al^k[':G=;oLv{$B5;8b,ZP4{o[-໢j	׏m)[땭[4	s.c|ҴvYLJ<|ӯgu0jD2
@hl+:j\ze_ևa@HyMHINxpK?%	㤺RC:=?^&7m´)A2;E~VB1$EvcKj؝(OoپU`"$a;ҡj0$&<$ۊ+/xjzb,7}W*1ܺtDv#8K
%^P>/i?)yRuQg^z`~sP900Ӡ!_,4J:ή30
	*H
0u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA0
170126201430Z
200426201430Z0810Upeter@pean.org10	*H
	peter@pean.org0"0
	*H
0
ܩ߳7+KV~_&&,TGzNG;"Jvx2'>3:7C1j>̊p'VG*J@D:O%a2K@Z(*xz	19{<}2h{7S&XAo&YQ=Q	ߑwFd̠&&/hL_}:Wdj,
>֫B%TK͌֩b2uLLX
'Ş#4̔rFN8Ϡ%AXM&xwP)WQqJ:,0{+ZJjFD>{!hŎǓi8𕭙nEq-Ta	ए&-e&mʓ[̛TF-u+YeQN?6Y|D p5 FpB'MlNw?3(z
N>l4ehs0;00U0U%0++0	U00U
tn#I0U#0$l9aIF+('Hmh0o+c0a0$+0http://ocsp.startssl.com09+0-http://aia.startssl.com/certs/sca.client1.crt08U10/0-+)'http://crl.startssl.com/sca-client1.crl0U0peter@pean.org0#U0http://www.startssl.com/0GU @0>0<+70-0++https://www.startssl.com/policy0
	*H
):rt!}2'PUܐ'asy҈/u#T2-_`Tb5OIIEi%Pn\V[AR+|X$."T8sQ33	&j'KbE#u(j9ʰ
CwYlN;:?'5`:9%e#!3]:#u%1J}p`HezOM6wù(Mi=N `kq,#1N0J00u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA!_,4J:ή30	+0	*H
	1	*H
0	*H
	1
171020053256Z0#	*H
	1	MIbb^(}g0	+7100u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA!_,4J:ή30*H
	10u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA!_,4J:ή30
	*H
&*o}7v_tƼp4eJM?X9zvTB4ei8le.xo`XTwqE@[Lyz.$RO_\r$ߖplGt-?Zk>ݸp7T4ZkݍnU?X7=؞MoMvC	EZ?RNc,ɸ]<]z-Q$uK<{X??gnHҜ["G𚨋</_<l(#Wi¿`֋iۉ4&zv
e]o{M.Kꄛkn4leZ	\yD;r$a,dD@09nQ)N.E$v5RЇqL|0[ըiɟ'f\t\u,vCf!IVOY8vUF{Bs'YAZ^zt]qK{

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?82E419D4-4FB4-402A-ACC9-C58D498461BE>