-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Manual selection of p12 for eap-profiles without one that specify TLS. #31
Comments
I am happy to provide you with a Usercert from our CA, if you need one for testing. |
If one wants to provide one's own certs it seems easy to grab a sample cap-config TLS profile and fit a P12 file into it. This is what we have started to do at my IdP. We use the app and have our ons distribution service for per-user profiles. |
Sounds good, can you provide some information how you itegrate the p12 content into the TLS profile? regards M. |
It helps if you see the xml structure in an organized way. I usually just hang the file extension to .xml and the open it in a browser. You need to have a section: |
a little bit off topic but do you have a link to a example tls config file, google din´t spit out any usefull. |
You can download a sample config for EAP-TLS (which doesn't have the actual certificate then) and learn about the few extra XML tags to embed one: our specification is openly available at https://github.com/GEANT/CAT/blob/master/devices/xml/eap-metadata.xsd As Tomasz said, when you download the installer, running it through htmltidy or looking at it in an XML browser yields a more readable version. |
Some cat.eduroam.org eap-config profiles are configured for TLS but do not contain a p12.
A feature to enable support for these profiles would require a prompt to get the file location from the user followed by another prompt for any PIN associated with it.
The text was updated successfully, but these errors were encountered: