[strongSwan] Using RADIUS EAP-TLS auth on the Strongswan Android app

Tobias Brunner tobias at strongswan.org
Mon Jun 26 17:52:41 CEST 2017


Hi Aanand

> Now,
> if I am using a RADIUS server to do EAP-TLS authentication then the
> client has to additionally validate the RADIUS server (using the RADIUS
> server’s certificate). How should I specify the root certificate for
> RADIUS server cert validation?

As mentioned at [1] the RADIUS server's certificate either has to be
issued by the same CA as the IKE server's certificate (if you want to
select a specific CA certificate), or you have to use automatic CA
certificate selection and import the additional CA certificate in the app.

Regards,
Tobias

[1]
https://wiki.strongswan.org/projects/strongswan/wiki/AndroidVPNClient#145-2014-11-06


More information about the Users mailing list