在这里,我还在机器上安装了CA证书链。
1-隐藏SSID (非广播)
2-使用的认证协议是PEAP,这是一个用户名和密码协议。
3-用户名和密码通过SSL加密会话在客户端和身份验证服务器(RADIUS)之间传递。
4-3层CA环境.
根(脱机)、中间(脱机)和2颁发CA证书(联机)
认证服务器(RADIUS)上的实际SSL证书将来自2个发出CA的证书。它允许建立可信的SSL会话以传递用户名和密码。
5-MS-CHAPv2 2支持
我的wpa_suplicant.conf文件:
ctrl_interface=/var/run/wpa_supplicant
ctrl_interface_group=wheel
ap_scan=1 # This is to make sure that we get the hidden SSID
update_config=1
network={
priority=1
mode=0
scan_ssid=1
ssid="FILTERED"
proto=RSN # WPA2/IEEE 802.11i
key_mgmt=WPA-EAP # WPA using EAP authentication
eap=PEAP
group=CCMP TKIP # CCMP AES in Counter mode with CBC-MAC
pairwise=CCMP TKIP # TKIP = Temporal Key Integrity Protocol
#phase1="peaplabel=1"
phase2="auth=MSCHAPV2"
identity="FILTERED" # Identity string for EAP
password="FILTERED"
ca_cert="/etc/cert/CACertChain/CA1CertChain.pem"
}我怎样才能确定什么失败了?
bssid=34:XX:XX:XX:XX:02
ssid=FILTERED
id=0
pairwise_cipher=CCMP
group_cipher=TKIP
key_mgmt=WPA2/IEEE 802.1X/EAP
wpa_state=ASSOCIATED
ip_address=0.0.0.0
Supplicant PAE state=AUTHENTICATING
suppPortStatus=Unauthorized
EAP state=IDLE
> status
bssid=34:XX:XX:XX:XX:02
ssid=pmwproc
id=0
pairwise_cipher=CCMP
group_cipher=TKIP
key_mgmt=WPA2/IEEE 802.1X/EAP
wpa_state=ASSOCIATED
ip_address=0.0.0.0
Supplicant PAE state=CONNECTING
suppPortStatus=Unauthorized
EAP state=IDLE
> status
bssid=34:XX:XX:XX:XX:02
ssid=FILTERED
id=0
pairwise_cipher=CCMP
group_cipher=TKIP
key_mgmt=WPA2/IEEE 802.1X/EAP
wpa_state=ASSOCIATED
ip_address=0.0.0.0
Supplicant PAE state=CONNECTING
suppPortStatus=Unauthorized
EAP state=IDLE
> <2>CTRL-EVENT-EAP-FAILURE EAP authentication failed
<1>Setting authentication timeout: 2 sec 0 usec
<2>Authentication with 34:XX:XX:XX:XX:02 timed out.
<1>Setting scan request: 0 sec 0 usec
<2>CTRL-EVENT-DISCONNECTED - Disconnect event - remove keys发布于 2014-06-27 23:02:34
我知道这并不是“Anwser”,也是有点晚了--但它太大了,需要评论一下。也许会有帮助..。
我的配置没有错,它只是花了很长时间连接,导致超时,设置显式值加快了速度,并及时完成了修改。尝试在eapol_flags和eap中这样做,尝试禁用eap_workaround或fast_reauth。
下面是我如何用我的AP做的:
首先,临时启用广播和连接,然后状态如下所示:
# wpa_cli status
Selected interface 'wlanN'
bssid=XX:XX:XX:XX:XX:XX
ssid=MYHIDDENAP
id=0
mode=station
pairwise_cipher=CCMP
group_cipher=CCMP
key_mgmt=WPA2-PSK
wpa_state=COMPLETED
ip_address=NNN.NNN.NNN.NNN
address=XX:XX:XX:XX:XX:XX在我的示例中,禁用了基于该值的广播和调整了配置:
# /etc/network/interfaces
auto wlanN
iface wlanN inet dhcp
wpa-ssid MYHIDDENAP
wpa-psk af20956209c382340d48ee1a34826c9da80734512e96b7b546d7d1d64f36ee3a
wpa-pairwise CCMP
wpa-group CCMP
wpa-key-mgmt WPA-PSK
# with this values i had to play, see 'man wpa_supplicant.conf'
wpa-ap-scan 1
wpa-scan-ssid 1
wpa-proto RSNhttps://unix.stackexchange.com/questions/103701
复制相似问题