Can a revocation list be configured to reject selected user certificates when using EAP-TLS for authentication?
EAP-TLS authenticates users using digital certificates. If a station with a valid user certificate is lost or stolen then the network is compromised unless there is a means of revoking the certificate at the server. This can be easily done in the RAD-Series RADIUS Server by configuring the user with Authentication-Type=Deny in the default users file. For example, to revoke the certificate for fred@company.com the users file entry would be: fred@company.
EAP-TLS authenticates users using digital certificates. If a station with a valid user certificate is lost or stolen then the network is compromised unless there is a means of revoking the certificate at the server. This can be easily done in the RAD-Series RADIUS Server by configuring the user with Authentication-Type=Deny in the default users file.
Related Questions
- When configured, the supplicant on my computer, must choose the authentication method among EAP-TLS, EAP-TTLS and PEAP. What is involved?
- Can a revocation list be configured to reject selected user certificates when using EAP-TLS for authentication?
- When the user selects an item from a drop list cell, how can I examine the selected entry for validation?