lawik
This is some ongoing work I’m doing for [ REDACTED ] (one of my favorite clients, makes me seem very cool and mysterious). I am reporting the progress and procedure here to gives some findable context for others who want to do this stuff and also some context for the PR.
Wired 802.1x using EAP-TLS with device certificates is a pretty decent bump in network security and control, or so I hear.
I’ve confirmed the Linux setup for wired 802.1x using this helpful note and a freeradius server along with a Unifi managed switch. So we have a Raspbian OS install doing the right song and dance.
Currently we are hacking apart VintageNetWiFi and VintageNetEthernet to reproduce the config and setup.
We got the thing working but hit a fairly unexpected snag. No wired driver for wpa_supplicant.
So Add wired driver to WPA Supplicant by tomielee · Pull Request #234 · nerves-project/nerves_system_rpi4 · GitHub should address the immediate need we have and we’re currently building that system to see if it works out. It passes then smell check at least.
@fhunleth is this handled in each system separately or should this go somewhere in nerves_system_br?
Trending in Discussions
Other Trending Topics
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ai
- #ecto-query
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #metaprogramming
- #hex











Showing Posts 4 to 1- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
lawik
BOOM!
Quick note. It works:
Skip ca_cert to avoid CA verification unless you are doing more CA-related stuff and it matters to you. If it matters, add your signer cert to your CA list. Should not be hard.
On the freeradius side (what I tested against). I only really had to replace the ca cert in freeradius with the signer cert and then also add the signer cert to my system CA list so that it was in the root of trust or whatever that’s called.
Will post updates require on the system as well as the forked vintage_net stuff that will later need to be integrated. I did this on nerves_system_rpi3 but it should work on any.
lawik
Using those forks of VintageNet I’ve had no real issue doing PEAP-MSCHAPv2 over ethernet.
Not my goal.
I want EAP-TLS using NervesKey.
Last run gave some promising results:
The wrinkle is that OpenSSL doesn’t seem to have engine support compiled in (curious how Erlang does that differently) so I need to add something to Buildroot:
in nerves_defconfig is my theory.
The log was wildly misleading. The big read error seems irrelevant and is probably due to negotiations breaking down somehow. The real stuff is about failing to load and missing engine support by SSL and TLS higher up.
lawik
@fhunleth the separate supplicant library we discussed is taking shape here: GitHub - underjord/vintage_net_supplicant: Vintage Net Supplicant · GitHub
We are not 100% certain about the dividing line between Supplicant and WiFi libraries. Currently we brought a lot of WiFi-stuff over to the Supplicant library, because that worked and it all seemed relevant to the supplicant’s work. But much of it is pointless for the Supplicant under Ethernet. I think that’s fine but let us know what you think.
Plenty of tidying up before you get PRs for WiFi, Ethernet and we consider the Supplicant library ready to move over into the nerves-networking org but it is on it’s way.
lawik
It worked!