]> git.ipfire.org Git - thirdparty/freeradius-server.git/commitdiff
Added note on global CA
authorAlan T. DeKok <aland@freeradius.org>
Thu, 4 Feb 2010 07:50:37 +0000 (08:50 +0100)
committerAlan T. DeKok <aland@freeradius.org>
Thu, 4 Feb 2010 07:50:37 +0000 (08:50 +0100)
raddb/eap.conf

index 11c4335ee3ef314d13643d69e41630c51c3b8c9c..faaf8d8580e9ee4dc3d055d1aeda243fa1328e50 100644 (file)
                #
                #  http://www.dslreports.com/forum/remark,9286052~mode=flat
                #
+               #  Note that you should NOT use a globally known CA here!
+               #  e.g. using a Verisign cert as a "known CA" means that
+               #  ANYONE who has a certificate signed by them can
+               #  authenticate via EAP-TLS!  This is likey not what you want.
                tls {
                        #
                        #  These is used to simplify later configurations.