Freeradius Let's Encrypt DST Root CA X3
-
Hello Forum,
we use the freeradius3 (0.15.7_32) package on pfsense with EAP and Let's Encrypt. Now we have the problem that whenever we save the config in the WebUI the old Root CA Cert (DST Root CA X3) from Let's Encrypt is also imported into the certs/server_cert.pem. This causes a cert expired error on the clients.
does anyone know the problem? or does anyone have a solution for it?
-
@darkfire Delete the old CA?
-
where and how should I delete the old ca cert? it is not in the cert manager.!
-
@darkfire Is it in the freeradius package CAs somewhere?
-
i have already removed the DST Root CA X3 Cert from the file /usr/local/share/certs/ca-root-nss.crt and the folder /usr/share/certs/trusted/ and run a certctl rehash, but without success. Does the freeradius3 package have its own CA-Cert store? Where should it be?
-
@darkfire Honestly I don't know. I would look through the freeradius3 package and see if you can find it.
-
@darkfire said in Freeradius Let's Encrypt DST Root CA X3:
i have already removed the DST Root CA X3 Cert from the file /usr/local/share/certs/ca-root-nss.crt and the folder /usr/share/certs/trusted/ and run a certctl rehash, but without success.
Humm, your right, it's in there :
...... Certificate: Data: Version: 3 (0x2) Serial Number: 44:af:b0:80:d6:a3:27:ba:89:30:39:86:2e:f8:40:6b Signature Algorithm: sha1WithRSAEncryption Issuer: O = Digital Signature Trust Co., CN = DST Root CA X3 Validity Not Before: Sep 30 21:12:19 2000 GMT Not After : Sep 30 14:01:15 2021 GMT ......
But I'm not using it. That is, I don't use a certificate derived from this one.
( there are more certs in that file that are expired - it's not an issue)@darkfire said in Freeradius Let's Encrypt DST Root CA X3:
Does the freeradius3 package have its own CA-Cert store? Where should it be?
Noop. Nothing there.
I've the FreeRadius package installed years ago, and if I recall well, when installing, I had to create a CA (FreeRADIUS CA) and a certificate (FreeRADIUS Server Certificate).
These are used in my FreeRadius setup right now.No need neither reference to the "Let's Encrypt DST Root CA X3".
-
@gertjan On newer Android versions it is required to have a valid SSL Cert for the Radius service, therefore we use the LE Cert.
Yes, if I manually remove the "DST Root CA X3" from the Freeradius server cert, everything works.
-
-
-