Reply
Thread Tools
Posts: 14 | Thanked: 5 times | Joined on Jun 2010
#1
In my opinion N900 is an advanced device dedicated to multimedia and connectivity. As such, I expect a lot from n900 business connectivity features.

I work in a complex network environment where wifi connectivity is based on WPA-Enterprise (using eap-tls).
Well, I cannot connect to a wifi network that is protected by wpa-enterprise using eap-tls authentication along with a certificate signed by a private CA.
I read a lot of discussions about this matter but I have never found a useful hint.
I have analyzed n900 logs and even captured the network traffic between n900 and the access point.
In the logs I found errors about some certificates not recognized by available ca (maybe the private CA is not recognized?). If I leave the option “Require client authentication” disabled, the phone doesn't even pass the client certificate when it is requested to do that, resulting in a failed authentication error from eap server. If I enable the option “Require client authentication” than the n900 responds with an error to eap server during tls negotiation (warning: bad certificate).
Of course, the user certificate has been installed on n900 and, of course, the same certificate along with others parameters is perfectly working in a linux laptop with wpa_supplicant running.

What can I do?
 
Posts: 999 | Thanked: 1,117 times | Joined on Dec 2009 @ earth?
#2
I have a similar problem with wget.

I'm trying to create a cookie from my rapidshare account so I can download stuff directly with wget.

wget produces a warning about a "bad certificate" and the cookie generation fails. It works quite happily with my linux laptop.

Even the "--no-check-certificate" option does not work.

Maybe it is a problem with the SSL library?

Unless there is something that can be installed?
__________________
I like cake.
 
Posts: 279 | Thanked: 293 times | Joined on Oct 2009 @ Italy
#3
Kick the proprietary nokia network manager in the nuts and use wpa_supplicant. That's what i'll do soon
 

The Following User Says Thank You to admiral0 For This Useful Post:
Posts: 14 | Thanked: 5 times | Joined on Jun 2010
#4
I found wpa_supplicant for n900 in the jeff moe development repository but what about the integration with n900 user interface?
Furthermore, this wpa_supplicant port is not even close to a stable release...
 
Posts: 42 | Thanked: 16 times | Joined on Jan 2010
#5
Originally Posted by johnel View Post
wget produces a warning about a "bad certificate" and the cookie generation fails. It works quite happily with my linux laptop.

Even the "--no-check-certificate" option does not work.
wget is not standard installed, so it is very well possible that the compiled (non-supported) version is not working as intended. Probably it will ignore the no-check-certificate option. Where did you get it from?
 
Posts: 999 | Thanked: 1,117 times | Joined on Dec 2009 @ earth?
#6
Originally Posted by liedekef View Post
wget is not standard installed, so it is very well possible that the compiled (non-supported) version is not working as intended. Probably it will ignore the no-check-certificate option. Where did you get it from?
I think it was a dependancy from cbrReader (comic book reader) or something.

(I also noticed the ssl module for Python is not present either - don't know why)

If I use the web browser to navigate to an SSL page it works fine however if I try it with wget it does not seem to work.
__________________
I like cake.
 
Posts: 42 | Thanked: 16 times | Joined on Jan 2010
#7
I see that http://espejo.freemoe.org/repository.maemo.org/ has a version of wget in the stable repo, maybe try that one? If it already is that version, I would need to install myself to check but if it is the broken version, I most likely won't install it :-)
 

The Following User Says Thank You to liedekef For This Useful Post:
Posts: 999 | Thanked: 1,117 times | Joined on Dec 2009 @ earth?
#8
Originally Posted by liedekef View Post
I see that http://espejo.freemoe.org/repository.maemo.org/ has a version of wget in the stable repo, maybe try that one? If it already is that version, I would need to install myself to check but if it is the broken version, I most likely won't install it :-)
I've just checked the repo; it's the same version 1.10.2 I have installed.

Thanks for your help.
__________________
I like cake.
 
Reply


 
Forum Jump


All times are GMT. The time now is 14:17.