Nethserver-freeradius integration module

Any chance on help in installing this module? It gives me the following error:
Loaded plugins: changelog, fastestmirror, nethserver_events
Loading mirror speeds from cached hostfile

Thank you!

yum install https://mirror.de-labrusse.fr/NethDev/nethserver-freeradius/nethserver-freeradius-0.0.7-1.1.g29c2100.ns7.noarch.rpm

You cannot expect support of me for this rpm I just built and kept the sources for other like you

4 Likes

Do you mean freeradius server service runs directly on OPNsense?

@fausp

Hi

Yes, it’s a plug-in, but fully integrated…

Anyone asked about LDAP / AD Integration?

:slight_smile:

@ Andy_Wismer
Hi Andy, looks vy cool! I will test it immediately :grinning:

@fausp

I’m moving in the next ten days, but plan on using Radius for WiFi after moving… :slight_smile:

Maybe you can help me to write a HowTo for Nethserver AD / OPNsense Radius / WPA2 Enterprise Mode?

2 Likes

@fausp

Would be a good idea…

I had that before running, when still using SME Server…
But that wasn’t AD integrated, only MS NT Domain.

At the moment I have too many Home Entertainment stuff which requires WPS2 PSK - and these mostly can’t use WPA2 Enterprise… Bose, Sonos (Not sure?), but there are plenty out there…
So I’m getting another WLan-AP for Radius / WPA2-Enterprise…

:slight_smile:

One thing is sure though: Your NethServer AD needs a correct LE SSL cert… :slight_smile:

I’ve prepped my AD, SSL works sofar well…

Could also be a step in the HowTo…

1 Like

What do you think is better, to get and manage the LE-cert with OPNsense or with Nethserver? Or a mix of both, depending on the needs…?

Get and manage the cert on the device that’s going to use it if possible.

1 Like

Always better and simpler… But not always possible or optimal…

Hence “if possible.” If it isn’t possible (or practical), as is the case with my Mikrotik switches, then you’ll need to come up with a way to get the cert somewhere else, and automatically deploy it to whatever’s going to use it. Lots of ways to do that, and there may not be one “right” answer.

@danb35

This looks interesting, for Microtik Routers (Switches too, eg if using vLans…):

Usually gives more options with the specific hw / sw…

Do you know XCA - X Certificate and Key Management © by Christian Hohnstädt? Could this be the way?

@fausp

Not really, never heard of the App…

One of the main “issues” with WPA2 (Enterprise) is for Windows the nead to use MS-Chapv2. Not the most secure thing - but it does work on most platforms supporting it…

The way for what? What potential problem or need would you be trying to address with this?

The description is here:

Sure, I can see the description on their website. But why would you want to use it?