[SOLVED] Client Mode - 802.1X - Eduroam - Certificates

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Goto page Previous  1, 2, 3, 4, 5  Next
Author Message
iclassique
DD-WRT Novice


Joined: 23 Apr 2012
Posts: 7

PostPosted: Tue Apr 24, 2012 22:11    Post subject: Reply with quote
habeIchVergessen wrote:
i think you have to configure eap-peap.
should work without modification of wpa_supplicant.conf

wireless -> security

security mode radius/802.1x
select peap

enter your data

apply settings

Hi buddy
i have attached the setting below
pls help me Very Happy
Sponsor
habeIchVergessen
DD-WRT User


Joined: 04 May 2010
Posts: 431

PostPosted: Wed Apr 25, 2012 6:09    Post subject: Reply with quote
the bridge is working (wireless client connected at ath0).
the ca cert is more than the name. open the file and copy all enclosed by the PEM headers.

joke1981 uses a second router behind the bridge (page 3).

you can try to connect a wired client that should get the network config via dhcp.

why did you configure vaps?
JarodRussell
DD-WRT Novice


Joined: 03 Feb 2010
Posts: 15

PostPosted: Wed Apr 25, 2012 9:34    Post subject: Reply with quote
I found this thread quite interesting but I was wondering what you are all doing there to establish the connection. I was running a LaFonera 2100 as a Wireless eduroam-Client with DD-WRT and since two days now a TP-Link TL-WR842ND in the same way (DD-WRT v24-sp2 (04/22/12) std - build 19081). I never edited the supplicant or anything else. I did everything in the Web-Interface of DD-WRT, so maybe I can help you a bit with my settings in the Wireless-Tab:

Basic-Settings:
Mode: Client
Network Mode: Mixed
Channel Width: 20MHz (Full)
SSID: eduroam

No changes in advanced settings needed, I just put the ACK Timing to 0 because I am quite far away from the AP.

Wireless-Security (now it gets interesting Wink):

Security-Mode: 802.1x
XSuplicant-Type: Students use Peap here, employees such as assistants use TTLS
User: your account@youruniversity.de
Anonymous Identity: anonymous
Password: your password
Phase2: auth=MSChapV2 (students) / auth=PAP (employees)
Public Server Certificate: -------BEGIN CERTIFICATE------- till --------------END CERTIFICATE---------------

And that was all...I get an automatic connection to the eduroam APs and quite quick a WAN IP. In the Setup->Basic Setup Tab of the router you need to configure WAN Connection Type to "Automatic DHCP"
habeIchVergessen
DD-WRT User


Joined: 04 May 2010
Posts: 431

PostPosted: Wed Apr 25, 2012 9:57    Post subject: Reply with quote
dd-wrt uses odd web key encryption if tls is selected.
modifications of wpa_supplicant.conf switch to wpa/wpa2 encryption.
JarodRussell
DD-WRT Novice


Joined: 03 Feb 2010
Posts: 15

PostPosted: Wed Apr 25, 2012 12:09    Post subject: Reply with quote
For me, everything works well. I just wanted to point out, that it does not seem to be necessary to meddle around in the conf-files. It just works with the web-interface without any problems.
lawsu
DD-WRT Novice


Joined: 07 Nov 2007
Posts: 7

PostPosted: Wed May 22, 2013 3:00    Post subject: Reply with quote
Can I know what should I put under public server cert?
I am required to have gd-class2-root.cer from https://certs.godaddy.com/anonymous/repository.pki

Thank you in advance.


JarodRussell wrote:
I found this thread quite interesting but I was wondering what you are all doing there to establish the connection. I was running a LaFonera 2100 as a Wireless eduroam-Client with DD-WRT and since two days now a TP-Link TL-WR842ND in the same way (DD-WRT v24-sp2 (04/22/12) std - build 19081). I never edited the supplicant or anything else. I did everything in the Web-Interface of DD-WRT, so maybe I can help you a bit with my settings in the Wireless-Tab:

Basic-Settings:
Mode: Client
Network Mode: Mixed
Channel Width: 20MHz (Full)
SSID: eduroam

No changes in advanced settings needed, I just put the ACK Timing to 0 because I am quite far away from the AP.

Wireless-Security (now it gets interesting Wink):

Security-Mode: 802.1x
XSuplicant-Type: Students use Peap here, employees such as assistants use TTLS
User: your account@youruniversity.de
Anonymous Identity: anonymous
Password: your password
Phase2: auth=MSChapV2 (students) / auth=PAP (employees)
Public Server Certificate: -------BEGIN CERTIFICATE------- till --------------END CERTIFICATE---------------

And that was all...I get an automatic connection to the eduroam APs and quite quick a WAN IP. In the Setup->Basic Setup Tab of the router you need to configure WAN Connection Type to "Automatic DHCP"
habeIchVergessen
DD-WRT User


Joined: 04 May 2010
Posts: 431

PostPosted: Wed May 22, 2013 8:10    Post subject: Reply with quote
you have to enter the ca cert here. it's not mandatory.
derfan
DD-WRT Novice


Joined: 28 May 2014
Posts: 4

PostPosted: Fri May 30, 2014 8:11    Post subject: Reply with quote
Hi all,

I am trying to connect a wrt54gl v1.1 with the latest available firmware v24 presp2 build 14896 from 2010 to eduroam via the dd-wrt webinterface.

Unfortunately in the webinterface in client mode I can only choose between wpa psk and wep. There is no wpa enterprise, radius or 802.1x.

Could it be that the firmware version is too old? Could this functionality be integrated into the wrt54gl v1.1 firmware?

Thank you,
Benjamin
habeIchVergessen
DD-WRT User


Joined: 04 May 2010
Posts: 431

PostPosted: Fri May 30, 2014 8:57    Post subject: Reply with quote
wireless security mode 802.11x is only avalible when you select client bridge mode.
also look for required binaries wpa_supplicant, hostapd and relayd.
derfan
DD-WRT Novice


Joined: 28 May 2014
Posts: 4

PostPosted: Fri May 30, 2014 9:22    Post subject: Reply with quote
thank you. is there a reason that this is only available in bridge mode? Is this in all versions of ddwrt?
derfan
DD-WRT Novice


Joined: 28 May 2014
Posts: 4

PostPosted: Fri May 30, 2014 21:30    Post subject: Reply with quote
i just tried this with a tp link router with a recent ddwrt from last month. this one supports 802.11x in client mode. it would be great to get an upgrade for the wrt54gl then..
habeIchVergessen
DD-WRT User


Joined: 04 May 2010
Posts: 431

PostPosted: Sat May 31, 2014 19:48    Post subject: Reply with quote
your router has 4mb flash only. i guess it's to small for 802.11x
derfan
DD-WRT Novice


Joined: 28 May 2014
Posts: 4

PostPosted: Mon Jun 02, 2014 8:18    Post subject: Reply with quote
on the other hand as you said it seems to work in bridge mode..
spyder8
DD-WRT Novice


Joined: 13 Aug 2014
Posts: 7

PostPosted: Wed Aug 13, 2014 0:14    Post subject: Reply with quote
Still have issues...

When I try to kill wpa_supplicant to start it in debug mode, it says that it is already started. In fact, I see that the process id of wpa_supplicant is constantly changing. Does anyone have an idea why this is happening? How can I stop wpa_supplicant from restarting itself?

It would really be great to see the output of wpa_supplicant to understand what is going wrong!
habeIchVergessen
DD-WRT User


Joined: 04 May 2010
Posts: 431

PostPosted: Wed Aug 13, 2014 12:02    Post subject: Reply with quote
try following:

killall wpa_supplicant && wpa_supplicant <your options>

maybe wpa_supplicant was compiled without debug.
Goto page Previous  1, 2, 3, 4, 5  Next Display posts from previous:    Page 4 of 5
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum