You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

FreeRADIUS与OpenSSL配置EAP-TLS WiFi连接时遇未知CA错误求助

Troubleshooting "eap_tls: ERROR: TLS Alert read:fatal:unknown CA" in FreeRADIUS EAP-TLS Setup

Hey there! No worries about your English at all—let's get this EAP-TLS issue sorted out for you. That "unknown CA" error typically means FreeRADIUS doesn't trust your custom root CA, there's a misconfiguration in certificate paths, or the certificate chain isn't properly set up. Let's walk through the fixes step by step:

1. Verify Certificate Chain & File Permissions

First, make sure your certificates are valid and accessible to FreeRADIUS:

  • Validate the user certificate chain: Run this command to confirm your user certificate was correctly signed by your root CA:
    openssl verify -CAfile /path/to/your/root-ca.crt /path/to/your/user-cert.crt
    
    You should see OK if the chain is valid. If not, re-sign the user certificate with your root CA.
  • Check file ownership & permissions: FreeRADIUS runs as the freerad user, so it needs read access to your certificates. Set the correct permissions:
    chown -R freerad:freerad /etc/freeradius/3.0/certs/
    chmod 600 /etc/freeradius/3.0/certs/*.key  # Keep private keys secure
    chmod 644 /etc/freeradius/3.0/certs/*.crt  # Allow read access to certificates
    

2. Fix EAP Module Configuration

Open /etc/freeradius/3.0/mods-enabled/eap and double-check the tls section—this is where most misconfigurations happen:

  • Ensure you're pointing to your custom root CA, not the default sample certificates:
    tls {
        # Path to your root CA certificate
        ca_file = ${certdir}/root-ca.crt
        # Path to FreeRADIUS server certificate (signed by your root CA)
        cert_file = ${certdir}/server.crt
        # Path to server private key
        key_file = ${certdir}/server.key
        # Remove or comment out any default ca_path settings unless you need them
        # ca_path = ${cadir}
        # If you set a password for your private keys, uncomment and set this:
        # private_key_password = your_key_password
    }
    
    Note: Don't forget to generate a server certificate signed by your root CA—EAP-TLS requires the server to present a trusted certificate to the client too!

3. Confirm Mobile Client Certificate Setup

Your phone's certificate installation needs to be precise:

  • Install your root CA certificate and ensure it's trusted for network authentication:
    • On Android: After importing, go to Settings > Security > Trusted Credentials > User and verify your root CA is listed. Some devices require you to explicitly enable it for "WiFi" or "VPN & app" usage.
    • On iOS: After importing, go to Settings > General > VPN & Device Management and tap your root CA to enable full trust.
  • Import your user certificate as a PKCS#12 (.p12/.pfx) file—this bundle includes both the user certificate and its private key. Make sure you enter the correct password when importing.
  • In your WiFi EAP-TLS settings:
    • Set EAP method to TLS
    • Select your installed root CA as the "CA certificate"
    • Select your imported user certificate as the "User certificate"

4. Debug with Detailed FreeRADIUS Logs

Run FreeRADIUS in debug mode to get more context about the TLS failure:

radiusd -X

Look for lines related to TLS handshake—common clues include:

  • unable to get local issuer certificate: Means FreeRADIUS can't find or trust your root CA.
  • permission denied: Indicates file permissions are incorrect for your certificates/keys.
  • certificate verify failed: Points to a broken certificate chain or expired certificate.

5. Avoid Common Pitfalls

  • Don't mix default and custom certificates: Replace all sample certificates in /etc/freeradius/3.0/certs/ with your own—leftover default files can cause conflicts.
  • Check certificate validity: Ensure none of your certificates are expired. Verify with:
    openssl x509 -enddate -noout -in /path/to/your/certificate.crt
    
  • Use proper certificate fields: When generating certificates, set the Common Name (CN) appropriately (server certificate CN can be your server's hostname/IP; user certificate CN can be the username). For modern clients, adding a Subject Alternative Name (SAN) is also recommended.

If you're still stuck, share the full debug output from radiusd -X and your eap configuration file snippet—I’ll help you dig deeper!

内容的提问来源于stack exchange,提问作者Regastrid

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 19:52:44