FreeRADIUS与OpenSSL配置EAP-TLS WiFi连接时遇未知CA错误求助
Hey there! No worries about your English at all—let's get this EAP-TLS issue sorted out for you. That "unknown CA" error typically means FreeRADIUS doesn't trust your custom root CA, there's a misconfiguration in certificate paths, or the certificate chain isn't properly set up. Let's walk through the fixes step by step:
1. Verify Certificate Chain & File Permissions
First, make sure your certificates are valid and accessible to FreeRADIUS:
- Validate the user certificate chain: Run this command to confirm your user certificate was correctly signed by your root CA:
You should seeopenssl verify -CAfile /path/to/your/root-ca.crt /path/to/your/user-cert.crtOKif the chain is valid. If not, re-sign the user certificate with your root CA. - Check file ownership & permissions: FreeRADIUS runs as the
freeraduser, so it needs read access to your certificates. Set the correct permissions:chown -R freerad:freerad /etc/freeradius/3.0/certs/ chmod 600 /etc/freeradius/3.0/certs/*.key # Keep private keys secure chmod 644 /etc/freeradius/3.0/certs/*.crt # Allow read access to certificates
2. Fix EAP Module Configuration
Open /etc/freeradius/3.0/mods-enabled/eap and double-check the tls section—this is where most misconfigurations happen:
- Ensure you're pointing to your custom root CA, not the default sample certificates:
Note: Don't forget to generate a server certificate signed by your root CA—EAP-TLS requires the server to present a trusted certificate to the client too!tls { # Path to your root CA certificate ca_file = ${certdir}/root-ca.crt # Path to FreeRADIUS server certificate (signed by your root CA) cert_file = ${certdir}/server.crt # Path to server private key key_file = ${certdir}/server.key # Remove or comment out any default ca_path settings unless you need them # ca_path = ${cadir} # If you set a password for your private keys, uncomment and set this: # private_key_password = your_key_password }
3. Confirm Mobile Client Certificate Setup
Your phone's certificate installation needs to be precise:
- Install your root CA certificate and ensure it's trusted for network authentication:
- On Android: After importing, go to Settings > Security > Trusted Credentials > User and verify your root CA is listed. Some devices require you to explicitly enable it for "WiFi" or "VPN & app" usage.
- On iOS: After importing, go to Settings > General > VPN & Device Management and tap your root CA to enable full trust.
- Import your user certificate as a PKCS#12 (.p12/.pfx) file—this bundle includes both the user certificate and its private key. Make sure you enter the correct password when importing.
- In your WiFi EAP-TLS settings:
- Set EAP method to
TLS - Select your installed root CA as the "CA certificate"
- Select your imported user certificate as the "User certificate"
- Set EAP method to
4. Debug with Detailed FreeRADIUS Logs
Run FreeRADIUS in debug mode to get more context about the TLS failure:
radiusd -X
Look for lines related to TLS handshake—common clues include:
unable to get local issuer certificate: Means FreeRADIUS can't find or trust your root CA.permission denied: Indicates file permissions are incorrect for your certificates/keys.certificate verify failed: Points to a broken certificate chain or expired certificate.
5. Avoid Common Pitfalls
- Don't mix default and custom certificates: Replace all sample certificates in
/etc/freeradius/3.0/certs/with your own—leftover default files can cause conflicts. - Check certificate validity: Ensure none of your certificates are expired. Verify with:
openssl x509 -enddate -noout -in /path/to/your/certificate.crt - Use proper certificate fields: When generating certificates, set the Common Name (CN) appropriately (server certificate CN can be your server's hostname/IP; user certificate CN can be the username). For modern clients, adding a Subject Alternative Name (SAN) is also recommended.
If you're still stuck, share the full debug output from radiusd -X and your eap configuration file snippet—I’ll help you dig deeper!
内容的提问来源于stack exchange,提问作者Regastrid

