SmartBridges sB3210 manual Configure Server for TLS

Page 47

i n t e l l i g e n t

w i r e l e s s

p l a t f o r m

For TLS and PEAP, the server needs root.pem and cert-srv.pem. For TLS, the Windows XP client needs root.der and cert-clt.p12. For PEAP, the Windows XP client needs root.der.

In the event that you want to use TLS authentication with multiple clients, Document 3 provides the needed script. Look for the CA.clt script in Section 6.

3. Configure Server for TLS

There are only a few changes and additions needed for TLS authentication. The clients.conf, users, and radiusd.conf are located at:

/usr/local/radius/etc/raddb

a. clients.conf -- This file contains the basic configuration for the Access Point. Look for the following line then uncomment and modify as appropriate:

#client 192.168.0.0/24 {

client 192.168.1.0/24 {

secret = AP_Shared_Secret shortname = WLAN

}

b. users -- This file contains the basic user information. Look for the following line and then add the user name:

#"John Doe" Auth-Type := Local, User-Password == "hello"

#

jbibe

Note that for TLS, you should not include an Auth-Type or a password. The server is able to determine the correct Auth-Type, and a password is not needed because the client uses a client certificate for authentication.

c. radiusd.conf -- This file contains the server configuration information. Look for the following lines and then change the default_eap_type from md5 to tls:

eap {

default_eap_type = md5

Change md5 to tls.

Move down to the following line, and then uncomment and modify the information, as shown below. Note that I placed the server certificates, dh file and random file in a new directory 1x on our system. Modify the path as needed for your server:

#tls {

tls {

private_key_password = whatever

private_key_file = /usr/local/radius/etc/1x/cert-srv.pem certificate_file = /usr/local/radius/etc/1x/cert-srv.pem CA_file = /usr/local/radius/etc/1x/root.pem

airPoint™ Nexus User Configuration Guide

Page 47 of 55

 

Image 47
Contents Version AirPoint Nexus SB3210Table of Contents Related Publications About This DocumentOverview of User Guide Technical Support Center System Requirements AirPoint Nexus Configuration FeaturesIntroduction Pre-Installation Checklist for airPoint ChecklistsSignature of Engineer Name Date Parameters Units Site a Site BEconomical One radio model sB3210 Rssi Post-Installation Checklist for airPointChecklist Parameters Units Site a Site B User Login and License Agreement AirPoint ConfigurationLicense Agreement Description of Parameters Descriptions Web GUI Administrator Password ChangeNavigation Menu Bar Using the Configuration PagesDescription of Menus Menu Item Menu Sub-items Editable Boxes for Parameter EditingInternal ACL Menu Item Menu Sub-items DescriptionNone WEP OnlyTools Help Wireless Configuration AirPoint Bridge Configuration ParametersEthernet Configurations Wireless Settings Items Descriptions AirPoint Bridge Wireless SettingsRadio Protocol Parameters Radio ProtocolItems Descriptions AirPoint Bridge Performance Settings Default STP Values Setting Default Value Range Purpose Bridge ConfigurationConfiguring Spanning Tree Protocol STP Setting Default Value Range Purpose T e l l i g e n t R e l e s s A t f o r m 11 Bridge Configuration WDS Table WEP only Wireless Equivalent PrivacySecurity T e l l i g e n t R e l e s s A t f o r m Internal ACL with WEP disabled External ACL Radius & Internal ACL WPA-Radius External ACLRadius & Internal ACLWPA radius Traffic Statistics Traffic StatisticsTools System ConfigurationSnmp Security System Configuration DescriptionsSnmp Security Configuration Reset OptionsDelayed Reset NTP Time Server SetupProfile Manager NTP Time SettingsProfile Manager Menu Items Save ProfileProfile Calendar Load Operating ProfilePing Test Result Link TestThroughput Test Result Link Budget Planning10 Link Budget Planning Calculator Link Budget AirPoint Nexus Firmware Upgrade Firmware UpgradeSuccessful upgrade pop-up window Appendix a Configuration of the Radius Server Produce Certificates T e l l i g e n t R e l e s s A t f o r m Configure Server for TLS Install Windows XP Certificates and Setup Client for TLS Test TLS Change Windows XP for Peap Abbreviations Acronyms Appendix B Useful terms and definitionsWPA Snmp Appendix C Snmp Trap Appendix D License