bug WPA2 Enterprise wpa_supplicant fails when server-cert is also client-cert (Radius-RadSec, eduroam) [released]
Current version of wpa_supplicant fails when server certificate is also client certificate as a patch to prevent client certificates to be used did not check if it is actually a server certificate too.
http://patchwork.ozlabs.org/patch/320617/
Fixed in upstream.
Thanks go @Digital Brains for providing an undone version https://together.jolla.com/question/315/wpa2-pskaesothers-wifi-support-needed-workaround/?answer=38843#post-id-38843
UPDATE: For those whom installed the patched version - after 1.0.5.19 you need to reinstall the patched version as the release version gets pulled in again.
UPDATE2: For those whom installed the patched version - after 1.0.7.16 you need to reinstall the patched version as the release version gets pulled in again.
This applies to most/all eduroam servers (WPA2 Enterprise) as Radius cannot do RadSec without having both (client and server cert) http://en.wikipedia.org/wiki/RadSec
Out of pure curiosity, was this bug filed at jolla yet?
ozzi ( 2014-04-15 15:20:44 +0200 )edit@ozzi this here is "bug filed at jolla" - there is no other way than open a question in together.jolla.com and mark it as bug (there is no public bugtracker or anything)
chemist ( 2014-04-15 15:48:06 +0200 )editHoping for Jolla to fix this soon, because it really breaks an important functionality (even if it might not be their fault). I agree with others, that unless you really need it, it will be better to wait for an official patch or Sailfish update.
@Jolla: is there any way you could rollout small urgent, optional or mandatory patches independently of your main update releases?
melg01 ( 2014-04-16 15:46:48 +0200 )editThx for UPDATE2 I don't understand, that the new version is still buggy, it's an easy fix, that shouldn't have happend!
dafeujolla ( 2014-06-10 18:07:24 +0200 )editI will try the current release as soon as I have a new device - I will close this if it is working with our network (some people seem to misunderstand that they did not need this patch if the server-cert is not a client-cert too)
chemist ( 2014-07-21 00:15:32 +0200 )edit