diff options
author | David Lam <david@thedavid.net> | 2020-01-16 00:01:35 -0800 |
---|---|---|
committer | Jo-Philipp Wich <jo@mein.io> | 2020-01-16 12:08:18 +0100 |
commit | a5f3648a1c273b45dc9df18785e0b5966ac5b47e (patch) | |
tree | fa7448fc4fbed9c7db6f9794fc686badb712d1e3 /package/kernel | |
parent | 702c70264b388c2b47e171843f297f43c71b86b9 (diff) | |
download | upstream-a5f3648a1c273b45dc9df18785e0b5966ac5b47e.tar.gz upstream-a5f3648a1c273b45dc9df18785e0b5966ac5b47e.tar.bz2 upstream-a5f3648a1c273b45dc9df18785e0b5966ac5b47e.zip |
hostapd: add support for system cert bundle validation
Currently, it is very cumbersome for a user to connect to a WPA-Enterprise
based network securely because the RADIUS server's CA certificate must first be
extracted from the EAPOL handshake using tcpdump or other methods before it can
be pinned using the ca_cert(2) fields. To make this process easier and more
secure (combined with changes in openwrt/openwrt#2654), this commit adds
support for validating against the built-in CA bundle when the ca-bundle
package is installed. Related LuCI changes in openwrt/luci#3513.
Signed-off-by: David Lam <david@thedavid.net>
[bump PKG_RELEASE]
Signed-off-by: Jo-Philipp Wich <jo@mein.io>
Diffstat (limited to 'package/kernel')
0 files changed, 0 insertions, 0 deletions