From: Tobias Brunner Date: Thu, 6 Nov 2014 15:33:01 +0000 (+0100) Subject: Merge branch 'android-eap-tls' X-Git-Tag: 5.2.2dr1~41 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=2d19ff462acbb0c26a238d4bae205f3db25148ba;p=thirdparty%2Fstrongswan.git Merge branch 'android-eap-tls' This adds support for EAP-TLS authentication on Android. EAP-only authentication is currently not allowed because the AAA identity is not configurable, so to prevent anyone with a valid certificate from impersonating the AAA server and thus the gateway, we authenticate the gateway (like we do with other authentication methods). Also, it's currently not possible to select a specific CA certificate to authenticate the AAA server certificate, so it either must be issued by the same CA as that of the gateway or automatic CA certificate selection must be used. --- 2d19ff462acbb0c26a238d4bae205f3db25148ba