|
Hello, Hello,
I work on a WIFI authentication project, dealing with EAP/TLS on Freeradius. I allready read a lots of docs on the net The certificats are created with xpextensions and installed. I use freeradius. My config files are joined. Client : windows XP pro sp2. Here is the freeradius log when I try to connect : rad_recv: Access-Request packet from host 172.17.5.100:32778, id=168, length=150 User-Name = "mobile" NAS-IP-Address = 172.17.5.100 NAS-Identifier = "172.17.5.100" NAS-Port = 1 NAS-Port-Type = Wireless-802.11 Calling-Station-Id = "000F20957BB7" Called-Station-Id = "000B8641C660" Framed-MTU = 1100 EAP-Message = 0x0201000b016d6f62696c65 Aruba-Essid-Name = "eole" Aruba-Location-Id = "2.1.1" Message-Authenticator = 0x4b5ee61553ec73cc454c403ec873 rlm_pap: WARNING! No "known good" password found for the user. Authentication may fail because of this. Sending Access-Challenge of id 168 to 172.17.5.100 port 32778 Aruba-User-Vlan = 200 Aruba-User-Role = "eole" EAP-Message = 0x010200060d20 Message-Authenticator = 0x0000000000000000000000000000 State = 0xf1d8d2c72aac139bb25089361b94 rad_recv: Access-Request packet from host 172.17.5.100:32778, id=169, length=269 User-Name = "mobile" NAS-IP-Address = 172.17.5.100 NAS-Identifier = "172.17.5.100" NAS-Port = 1 NAS-Port-Type = Wireless-802.11 Calling-Station-Id = "000F20957BB7" Called-Station-Id = "000B8641C660" Framed-MTU = 1100 EAP-Message = 0x020200700d800000006616030100 State = 0xf1d8d2c72aac139bb25089361b94 Aruba-Essid-Name = "eole" Aruba-Location-Id = "2.1.1" Message-Authenticator = 0xd4944b76a67263b3c6431530b335 rlm_pap: WARNING! No "known good" password found for the user. Authentication may fail because of this. Sending Access-Challenge of id 169 to 172.17.5.100 port 32778 Aruba-User-Vlan = 200 Aruba-User-Role = "eole" EAP-Message = 0x0103040a0dc00000041116030100 EAP-Message = 0x2d424541554e4520544c53204341 EAP-Message = 0x6561754063682d626561756e652e EAP-Message = 0x2468002d3c9d510561b12ce489d0 EAP-Message = 0x864886f70d010901161961646d69 Message-Authenticator = 0x0000000000000000000000000000 State = 0x3086036a150a272bec4609fc740f rad_recv: Access-Request packet from host 172.17.5.100:32778, id=170, length=163 User-Name = "mobile" NAS-IP-Address = 172.17.5.100 NAS-Identifier = "172.17.5.100" NAS-Port = 1 NAS-Port-Type = Wireless-802.11 Calling-Station-Id = "000F20957BB7" Called-Station-Id = "000B8641C660" Framed-MTU = 1100 EAP-Message = 0x020300060d00 State = 0x3086036a150a272bec4609fc740f Aruba-Essid-Name = "eole" Aruba-Location-Id = "2.1.1" Message-Authenticator = 0xb21a49657c022a70310f50e9eaae rlm_pap: WARNING! No "known good" password found for the user. Authentication may fail because of this. rlm_eap_tls: No SSL info available. Waiting for more SSL data. Sending Access-Challenge of id 170 to 172.17.5.100 port 32778 Aruba-User-Vlan = 200 Aruba-User-Role = "eole" EAP-Message = 0x0104001b0d80000004114063682d Message-Authenticator = 0x0000000000000000000000000000 State = 0xc8d232500b2a33696b274f085732 rad_recv: Access-Request packet from host 172.17.5.100:32778, id=171, length=1236 User-Name = "mobile" NAS-IP-Address = 172.17.5.100 NAS-Identifier = "172.17.5.100" NAS-Port = 1 NAS-Port-Type = Wireless-802.11 Calling-Station-Id = "000F20957BB7" Called-Station-Id = "000B8641C660" Framed-MTU = 1100 EAP-Message = 0x0204042f0d800000042516030103 EAP-Message = 0x30313036303731345a3081a1310b EAP-Message = 0xb38fa2929f9e97027c7608bca14b EAP-Message = 0xaf1000008200802aaf3007c9a62c EAP-Message = 0x4e7c27d59c78f90d2418a89251f0 State = 0xc8d232500b2a33696b274f085732 Aruba-Essid-Name = "eole" Aruba-Location-Id = "2.1.1" Message-Authenticator = 0xcc6360144fd21b838bf72feda673 rlm_pap: WARNING! No "known good" password found for the user. Authentication may fail because of this. chain-depth=1, error=0 --> User-Name = mobile --> BUF-Name = CH-BEAUNE TLS CA --> subject = /C=FR/ST=Bourgogne/L=Beaune/O=ch-beaune.fr/OU=sinfo.ch TLS CA/emailAddress=admin.reseau@ch-beaune.fr --> issuer = /C=FR/ST=Bourgogne/L=Beaune/O=ch-beaune.fr/OU=sinfo.ch TLS CA/emailAddress=admin.reseau@ch-beaune.fr --> verify return:1 chain-depth=0, error=0 --> User-Name = mobile --> BUF-Name = mobile --> subject = /C=FR/ST=Bourgogne/L=Beaune/O=ch-beaune.fr/OU=sinfo.ch --> issuer = /C=FR/ST=Bourgogne/L=Beaune/O=ch-beaune.fr/OU=sinfo.ch TLS CA/emailAddress=admin.reseau@ch-beaune.fr --> verify return:1 Sending Access-Challenge of id 171 to 172.17.5.100 port 32778 Aruba-User-Vlan = 200 Aruba-User-Role = "eole" EAP-Message = 0x010500350d800000002b14030100 Message-Authenticator = 0x0000000000000000000000000000 State = 0x182de49cc578ef73f4090ae54adb rad_recv: Access-Request packet from host 172.17.5.100:32778, id=172, length=163 User-Name = "mobile" NAS-IP-Address = 172.17.5.100 NAS-Identifier = "172.17.5.100" NAS-Port = 1 NAS-Port-Type = Wireless-802.11 Calling-Station-Id = "000F20957BB7" Called-Station-Id = "000B8641C660" Framed-MTU = 1100 EAP-Message = 0x020500060d00 State = 0x182de49cc578ef73f4090ae54adb Aruba-Essid-Name = "eole" Aruba-Location-Id = "2.1.1" Message-Authenticator = 0xc93dcf66036b55d88e0f8b087237 rlm_pap: WARNING! No "known good" password found for the user. Authentication may fail because of this. rlm_eap_tls: No SSL info available. Waiting for more SSL data. Sending Access-Challenge of id 172 to 172.17.5.100 port 32778 Aruba-User-Vlan = 200 Aruba-User-Role = "eole" EAP-Message = 0x0106000a0d8000000000 Message-Authenticator = 0x0000000000000000000000000000 State = 0x7434fc4a00a7c70dde94fc0ede88 I see no OK, and no 'not OK'. I don't understand why 'rlm_eap_tls: No SSL info available. Waiting for more SSL data.' I don't understand why freeradius sends an access challenge instead of an access ok since the certificates are OK. I have to deploy on next monday. May you help me ? Best regards, --
Ce message, y compris les pièces jointes, est établi à l'attention exclusive de son ou ses destinataires et est confidentiel. Toute utilisation non conforme à sa destination, toute diffusion ou publication, totale ou partielle, est interdite sauf autorisation expresse de l'expéditeur. Si vous n'êtes pas le destinataire de ce message, merci d'avertir l'expéditeur de l'erreur de distribution puis de le détruire. Tout message électronique est susceptible d'altération et son intégrité ne peut être assurée. L'expéditeur décline toute responsabilité dans l'hypothèse où il aurait été modifié ou falsifié. | ||||||