Eduroam: Difference between revisions

Add note on certificate location restrictions
Arnecc (talk | contribs)
adapted fix for 26.05 release
Line 17: Line 17:
<syntaxhighlight lang="console">
<syntaxhighlight lang="console">
sudo mkdir -p /etc/ssl/certs/eduroam
sudo mkdir -p /etc/ssl/certs/eduroam
sudo mv private.key cert.pem /etc/ssl/certs/eduroam/
sudo mkdir -p /etc/wpa_supplicant
sudo chmod 600 /etc/ssl/certs/eduroam/private.key
sudo mv cert.pem /etc/ssl/certs/eduroam/
sudo mv private.key /etc/wpa_supplicant/private.key
sudo chmod 644 /etc/ssl/certs/eduroam/cert.pem
sudo chmod 644 /etc/ssl/certs/eduroam/cert.pem
sudo chown root:root /etc/ssl/certs/eduroam/*</syntaxhighlight>
sudo chown root:root /etc/ssl/certs/eduroam/*
sudo chown wpa_supplicant:wpa_supplicant /etc/wpa_supplicant/private.key
sudo chmod 400 /etc/wpa_supplicant/private.key
 
</syntaxhighlight>


Note that some universities just require a certificate some .crt or .pem certificate and authenticate via password, eliminating the need for a .key-file. Stick to your universities instructions for this.
Note that some universities just require a certificate some .crt or .pem certificate and authenticate via password, eliminating the need for a .key-file. Stick to your universities instructions for this.
Line 47: Line 52:
       identity = "likely-youremail@youruniversity.edu";
       identity = "likely-youremail@youruniversity.edu";
       client-cert = "/etc/ssl/certs/eduroam/cert.pem";
       client-cert = "/etc/ssl/certs/eduroam/cert.pem";
       private-key = "/etc/ssl/certs/eduroam/private.key";
       private-key = "/etc/wpa_supplicant/private.key";
       private-key-password = "p@ssw0rd-of-your-.key-file"; ## warning, this should only be done for testing purposes, as it makes the password world-readable. You should replace this with some form of secrets-management using sops-nix or agenix.  
       private-key-password = "p@ssw0rd-of-your-.key-file"; ## warning, this should only be done for testing purposes, as it makes the password world-readable. You should replace this with some form of secrets-management using sops-nix or agenix.  
       ca-cert = "/etc/ssl/certs/certs.pem";
       ca-cert = "/etc/ssl/certs/certs.pem";