Wind XP supplicant Domain//Username

Mark Saner msaner at
Mon Aug 3 21:08:27 CEST 2009

My current setup is Freeraidus 2.0.4 connecting to OpenLDAP with PEAP 
authentication. Currently I have it working with all of our Linux and 
Mac clients and to an extent our Windows clients. I am trying to make 
connecting as simple as possible for the user. I can get the Windows 
clients to work if I uncheck the "Automatically use my Windows logon 
name and password (and domain if any)" option on the XP supplicant under 
the configure button for the MSCHAP authentication method.

I would like to leave that option checked however when I do so the 
rlm_ldap fails because it is looking up DOMAIN\5cUSER. I have searched 
around a found a few leads but most of the deal with authenticating with 
ActiveDirectory and even if I do try their suggestions it doesn't seem 
to work. Output is below any suggestions would be greatly appreciated.

FreeRADIUS Version 2.0.4, for host x86_64-pc-linux-gnu, built on Jul 20 
2009 at 11:25:51
Copyright (C) 1999-2008 The FreeRADIUS server project and contributors.
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License.
Starting - reading configuration files ...
including configuration file /etc/freeradius/radiusd.conf
including configuration file /etc/freeradius/proxy.conf
including configuration file /etc/freeradius/clients.conf
including configuration file /etc/freeradius/snmp.conf
including configuration file /etc/freeradius/eap.conf
including configuration file /etc/freeradius/policy.conf
including files in directory /etc/freeradius/sites-enabled/
including configuration file /etc/freeradius/sites-enabled/inner-tunnel
including configuration file /etc/freeradius/sites-enabled/default
including dictionary file /etc/freeradius/dictionary
main {
    prefix = "/usr"
    localstatedir = "/var"
    logdir = "/var/log/freeradius"
    libdir = "/usr/lib/freeradius"
    radacctdir = "/var/log/freeradius/radacct"
    hostname_lookups = no
    max_request_time = 30
    cleanup_delay = 5
    max_requests = 1024
    allow_core_dumps = no
    pidfile = "/var/run/freeradius/"
    user = "freerad"
    group = "freerad"
    checkrad = "/usr/sbin/checkrad"
    debug_level = 0
    proxy_requests = yes
 security {
    max_attributes = 200
    reject_delay = 1
    status_server = yes
 client localhost {
    ipaddr =
    require_message_authenticator = no
    secret = "ohlieF8A"
    nastype = "other"
 client {
    require_message_authenticator = no
    secret = "ohlieF8A"
    shortname = "private-network-2"
radiusd: #### Loading Realms and Home Servers ####
 proxy server {
    retry_delay = 5
    retry_count = 3
    default_fallback = no
    dead_time = 120
    wake_all_if_all_dead = no
 home_server localhost {
    ipaddr =
    port = 1812
    type = "auth"
    secret = "ohlieF8A"
    response_window = 20
    max_outstanding = 65536
    zombie_period = 40
    status_check = "status-server"
    ping_check = "none"
    ping_interval = 30
    check_interval = 30
    num_answers_to_alive = 3
    num_pings_to_alive = 3
    revive_interval = 120
    status_check_timeout = 4
 home_server_pool my_auth_failover {
    type = fail-over
    home_server = localhost
 realm {
    auth_pool = my_auth_failover
 realm LOCAL {
radiusd: #### Instantiating modules ####
 instantiate {
 Module: Linked to module rlm_exec
 Module: Instantiating exec
  exec {
    wait = yes
    input_pairs = "request"
    shell_escape = yes
 Module: Linked to module rlm_expr
 Module: Instantiating expr
 Module: Linked to module rlm_expiration
 Module: Instantiating expiration
  expiration {
    reply-message = "Password Has Expired  "
 Module: Linked to module rlm_logintime
 Module: Instantiating logintime
  logintime {
    reply-message = "You are calling outside your allowed timespan  "
    minimum-timeout = 60
radiusd: #### Loading Virtual Servers ####
server inner-tunnel {
 modules {
 Module: Checking authenticate {...} for more modules to load
 Module: Linked to module rlm_pap
 Module: Instantiating pap
  pap {
    encryption_scheme = "auto"
    auto_header = no
 Module: Linked to module rlm_chap
 Module: Instantiating chap
 Module: Linked to module rlm_mschap
 Module: Instantiating mschap
  mschap {
    use_mppe = yes
    require_encryption = yes
    require_strong = yes
    with_ntdomain_hack = yes
 Module: Linked to module rlm_unix
 Module: Instantiating unix
  unix {
    radwtmp = "/var/log/freeradius/radwtmp"
 Module: Linked to module rlm_eap
 Module: Instantiating eap
  eap {
    default_eap_type = "peap"
    timer_expire = 60
    ignore_unknown_eap_types = no
    cisco_accounting_username_bug = no
 Module: Linked to sub-module rlm_eap_md5
 Module: Instantiating eap-md5
 Module: Linked to sub-module rlm_eap_leap
 Module: Instantiating eap-leap
 Module: Linked to sub-module rlm_eap_gtc
 Module: Instantiating eap-gtc
   gtc {
    challenge = "Password: "
    auth_type = "PAP"
 Module: Linked to sub-module rlm_eap_tls
 Module: Instantiating eap-tls
   tls {
    rsa_key_exchange = no
    dh_key_exchange = yes
    rsa_key_length = 512
    dh_key_length = 512
    verify_depth = 0
    pem_file_type = yes
    private_key_file = "/etc/freeradius/certs/server.pem"
    certificate_file = "/etc/freeradius/certs/server.pem"
    CA_file = "/etc/freeradius/certs/ca.pem"
    private_key_password = "whatever"
    dh_file = "/etc/freeradius/certs/dh"
    random_file = "/etc/freeradius/certs/random"
    fragment_size = 1024
    include_length = yes
    check_crl = no
    cipher_list = "DEFAULT"
 Module: Linked to sub-module rlm_eap_ttls
 Module: Instantiating eap-ttls
   ttls {
    default_eap_type = "md5"
    copy_request_to_tunnel = no
    use_tunneled_reply = no
    virtual_server = "inner-tunnel"
 Module: Linked to sub-module rlm_eap_peap
 Module: Instantiating eap-peap
   peap {
    default_eap_type = "mschapv2"
    copy_request_to_tunnel = no
    use_tunneled_reply = no
    proxy_tunneled_request_as_eap = yes
    virtual_server = "inner-tunnel"
 Module: Linked to sub-module rlm_eap_mschapv2
 Module: Instantiating eap-mschapv2
   mschapv2 {
    with_ntdomain_hack = no
 Module: Checking authorize {...} for more modules to load
 Module: Linked to module rlm_ldap
 Module: Instantiating ldap
  ldap {
    server = ""
    port = 389
    password = "********"
    identity = "cn=admin,dc=excelhustler,dc=com"
    net_timeout = 1
    timeout = 4
    timelimit = 3
    tls_mode = no
    start_tls = no
    tls_require_cert = "allow"
   tls {
    start_tls = no
    require_cert = "allow"
    basedn = "ou=People,dc=excelhustler,dc=com"
    filter = "(uid=%u)"
    base_filter = "(objectclass=radiusprofile)"
    auto_header = no
    access_attr = "uid"
    access_attr_used_for_allow = yes
    groupname_attribute = "cn"
    groupmembership_filter = 
    dictionary_mapping = "/etc/freeradius/ldap.attrmap"
    ldap_debug = 0
    ldap_connections_number = 5
    compare_check_items = no
    do_xlat = yes
    edir_account_policy_check = no
    set_auth_type = no
rlm_ldap: Registering ldap_groupcmp for Ldap-Group
rlm_ldap: Registering ldap_xlat with xlat_name ldap
rlm_ldap: reading ldap<->radius mappings from file 
rlm_ldap: LDAP radiusCheckItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusReplyItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusAuthType mapped to RADIUS Auth-Type
rlm_ldap: LDAP radiusSimultaneousUse mapped to RADIUS Simultaneous-Use
rlm_ldap: LDAP radiusCalledStationId mapped to RADIUS Called-Station-Id
rlm_ldap: LDAP radiusCallingStationId mapped to RADIUS Calling-Station-Id
rlm_ldap: LDAP lmPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP ntPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP sambaLmPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP sambaNtPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP acctFlags mapped to RADIUS SMB-Account-CTRL-TEXT
rlm_ldap: LDAP radiusExpiration mapped to RADIUS Expiration
rlm_ldap: LDAP radiusNASIpAddress mapped to RADIUS NAS-IP-Address
rlm_ldap: LDAP userPassword mapped to RADIUS User-Password
rlm_ldap: LDAP radiusServiceType mapped to RADIUS Service-Type
rlm_ldap: LDAP radiusFramedProtocol mapped to RADIUS Framed-Protocol
rlm_ldap: LDAP radiusFramedIPAddress mapped to RADIUS Framed-IP-Address
rlm_ldap: LDAP radiusFramedIPNetmask mapped to RADIUS Framed-IP-Netmask
rlm_ldap: LDAP radiusFramedRoute mapped to RADIUS Framed-Route
rlm_ldap: LDAP radiusFramedRouting mapped to RADIUS Framed-Routing
rlm_ldap: LDAP radiusFilterId mapped to RADIUS Filter-Id
rlm_ldap: LDAP radiusFramedMTU mapped to RADIUS Framed-MTU
rlm_ldap: LDAP radiusFramedCompression mapped to RADIUS Framed-Compression
rlm_ldap: LDAP radiusLoginIPHost mapped to RADIUS Login-IP-Host
rlm_ldap: LDAP radiusLoginService mapped to RADIUS Login-Service
rlm_ldap: LDAP radiusLoginTCPPort mapped to RADIUS Login-TCP-Port
rlm_ldap: LDAP radiusCallbackNumber mapped to RADIUS Callback-Number
rlm_ldap: LDAP radiusCallbackId mapped to RADIUS Callback-Id
rlm_ldap: LDAP radiusFramedIPXNetwork mapped to RADIUS Framed-IPX-Network
rlm_ldap: LDAP radiusClass mapped to RADIUS Class
rlm_ldap: LDAP radiusSessionTimeout mapped to RADIUS Session-Timeout
rlm_ldap: LDAP radiusIdleTimeout mapped to RADIUS Idle-Timeout
rlm_ldap: LDAP radiusTerminationAction mapped to RADIUS Termination-Action
rlm_ldap: LDAP radiusLoginLATService mapped to RADIUS Login-LAT-Service
rlm_ldap: LDAP radiusLoginLATNode mapped to RADIUS Login-LAT-Node
rlm_ldap: LDAP radiusLoginLATGroup mapped to RADIUS Login-LAT-Group
rlm_ldap: LDAP radiusFramedAppleTalkLink mapped to RADIUS 
rlm_ldap: LDAP radiusFramedAppleTalkNetwork mapped to RADIUS 
rlm_ldap: LDAP radiusFramedAppleTalkZone mapped to RADIUS 
rlm_ldap: LDAP radiusPortLimit mapped to RADIUS Port-Limit
rlm_ldap: LDAP radiusLoginLATPort mapped to RADIUS Login-LAT-Port
rlm_ldap: LDAP radiusReplyMessage mapped to RADIUS Reply-Message
rlm_ldap: LDAP radiusTunnelType mapped to RADIUS Tunnel-Type
rlm_ldap: LDAP radiusTunnelMediumType mapped to RADIUS Tunnel-Medium-Type
rlm_ldap: LDAP radiusTunnelPrivateGroupId mapped to RADIUS 
conns: 0x1da46c0
 Module: Checking session {...} for more modules to load
 Module: Linked to module rlm_radutmp
 Module: Instantiating radutmp
  radutmp {
    filename = "/var/log/freeradius/radutmp"
    username = "%{User-Name}"
    case_sensitive = yes
    check_with_nas = yes
    perm = 384
    callerid = yes
 Module: Checking post-proxy {...} for more modules to load
 Module: Checking post-auth {...} for more modules to load
 Module: Linked to module rlm_attr_filter
 Module: Instantiating attr_filter.access_reject
  attr_filter attr_filter.access_reject {
    attrsfile = "/etc/freeradius/attrs.access_reject"
    key = "%{User-Name}"
server {
 modules {
 Module: Checking authenticate {...} for more modules to load
 Module: Checking authorize {...} for more modules to load
 Module: Linked to module rlm_preprocess
 Module: Instantiating preprocess
  preprocess {
    huntgroups = "/etc/freeradius/huntgroups"
    hints = "/etc/freeradius/hints"
    with_ascend_hack = no
    ascend_channels_per_line = 23
    with_ntdomain_hack = no
    with_specialix_jetstream_hack = no
    with_cisco_vsa_hack = no
    with_alvarion_vsa_hack = no
 Module: Checking preacct {...} for more modules to load
 Module: Linked to module rlm_acct_unique
 Module: Instantiating acct_unique
  acct_unique {
    key = "User-Name, Acct-Session-Id, NAS-IP-Address, 
Client-IP-Address, NAS-Port"
 Module: Checking accounting {...} for more modules to load
 Module: Linked to module rlm_detail
 Module: Instantiating detail
  detail {
    detailfile = 
    header = "%t"
    detailperm = 384
    dirperm = 493
    locking = no
    log_packet_header = no
 Module: Instantiating attr_filter.accounting_response
  attr_filter attr_filter.accounting_response {
    attrsfile = "/etc/freeradius/attrs.accounting_response"
    key = "%{User-Name}"
 Module: Checking session {...} for more modules to load
 Module: Checking post-proxy {...} for more modules to load
 Module: Checking post-auth {...} for more modules to load
radiusd: #### Opening IP addresses and Ports ####
listen {
    type = "auth"
    ipaddr = *
    port = 0
listen {
    type = "acct"
    ipaddr = *
    port = 0
main {
    snmp = no
    smux_password = ""
    snmp_write_access = no
Listening on authentication address * port 1812
Listening on accounting address * port 1813
Listening on proxy address * port 1814
Ready to process requests.
rad_recv: Access-Request packet from host port 10002, 
id=1, length=156
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    EAP-Message = 0x02010010014c494e55585c7465737431
    Message-Authenticator = 0x30e61dfe7f91ae35e8838442098099d5
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 1 length 16
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: attempting LDAP reconnection
rlm_ldap: (re)connect to, 
authentication 0
rlm_ldap: bind as cn=admin,dc=excelhustler,dc=com/******** to
rlm_ldap: waiting for bind result ...
rlm_ldap: Bind was successful
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: EAP Identity
  rlm_eap: processing type tls
  rlm_eap_tls: Initiate
  rlm_eap_tls: Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 1 to port 10002
    EAP-Message = 0x010200061920
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xbd1a27d0bd183ebed244722aa89641b1
Finished request 0.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 10002, 
id=2, length=238
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0xbd1a27d0bd183ebed244722aa89641b1
    EAP-Message = 
    Message-Authenticator = 0xe1b23065c3ea3a08b748254dd50c36cd
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 2 length 80
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  TLS Length 70
rlm_eap_tls:  Length Included
  eaptls_verify returned 11
    (other): before/accept initialization
    TLS_accept: before/accept initialization
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0041], ClientHello 
    TLS_accept: SSLv3 read client hello A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 004a], ServerHello 
    TLS_accept: SSLv3 write server hello A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 085e], Certificate 
    TLS_accept: SSLv3 write certificate A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 0004], ServerHelloDone 
    TLS_accept: SSLv3 write server done A
    TLS_accept: SSLv3 flush data
    TLS_accept: Need to read more data: SSLv3 read client certificate A
In SSL Handshake Phase
In SSL Accept mode 
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 2 to port 10002
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 0xb04fdd57077b70767f03b4fc
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xbd1a27d0bc193ebed244722aa89641b1
Finished request 1.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 10002, 
id=3, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0xbd1a27d0bc193ebed244722aa89641b1
    EAP-Message = 0x020300061900
    Message-Authenticator = 0x6aa33042e799826ed3a040760ea20615
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 3 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake fragment handler
  eaptls_verify returned 1
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 3 to port 10002
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 0xcc4abf6d8be9f208
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xbd1a27d0bf1e3ebed244722aa89641b1
Finished request 2.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 10002, 
id=4, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0xbd1a27d0bf1e3ebed244722aa89641b1
    EAP-Message = 0x020400061900
    Message-Authenticator = 0xe3f49e1dc1bd9a7cc2ba09d2cad8d052
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 4 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake fragment handler
  eaptls_verify returned 1
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 4 to port 10002
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xbd1a27d0be1f3ebed244722aa89641b1
Finished request 3.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 10002, 
id=5, length=480
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0xbd1a27d0be1f3ebed244722aa89641b1
    EAP-Message = 
    EAP-Message = 
    Message-Authenticator = 0x66d3f60b20559169104856b0f96a6474
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 5 length 253
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  TLS Length 310
rlm_eap_tls:  Length Included
  eaptls_verify returned 11
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0106], ClientKeyExchange 
    TLS_accept: SSLv3 read client key exchange A
  rlm_eap_tls: <<< TLS 1.0 ChangeCipherSpec [length 0001] 
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0010], Finished 
    TLS_accept: SSLv3 read finished A
  rlm_eap_tls: >>> TLS 1.0 ChangeCipherSpec [length 0001] 
    TLS_accept: SSLv3 write change cipher spec A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 0010], Finished 
    TLS_accept: SSLv3 write finished A
    TLS_accept: SSLv3 flush data
    (other): SSL negotiation finished successfully
SSL Connection Established
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 5 to port 10002
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xbd1a27d0b91c3ebed244722aa89641b1
Finished request 4.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 10002, 
id=6, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0xbd1a27d0b91c3ebed244722aa89641b1
    EAP-Message = 0x020600061900
    Message-Authenticator = 0x446d642e8de6477c7ecd709ebc345d1e
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 6 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake is finished
  eaptls_verify returned 3
  eaptls_process returned 3
  rlm_eap_peap: EAPTLS_SUCCESS
++[eap] returns handled
Sending Access-Challenge of id 6 to port 10002
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xbd1a27d0b81d3ebed244722aa89641b1
Finished request 5.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 10002, 
id=7, length=197
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0xbd1a27d0b81d3ebed244722aa89641b1
    EAP-Message = 
    Message-Authenticator = 0x3565f0cea538abec12291a62dbcf5f7b
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 7 length 39
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: Identity - LINUX\test1
  PEAP: Got tunneled EAP-Message
    EAP-Message = 0x02070010014c494e55585c7465737431
  PEAP: Got tunneled identity of LINUX\test1
  PEAP: Setting default EAP type for tunneled EAP session.
  PEAP: Setting User-Name to LINUX\test1
  PEAP: Sending tunneled request
    EAP-Message = 0x02070010014c494e55585c7465737431
    FreeRADIUS-Proxied-To =
    User-Name = "LINUX\\test1"
server inner-tunnel {
+- entering group authorize
++[mschap] returns noop
++[control] returns noop
  rlm_eap: EAP packet type response id 7 length 16
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: EAP Identity
  rlm_eap: processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
  PEAP: Got tunneled reply RADIUS code 11
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xe6b55262e6bd4850d1efd72bdd823e7d
  PEAP: Processing from tunneled session code 0x1de2d40 11
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xe6b55262e6bd4850d1efd72bdd823e7d
  PEAP: Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 7 to port 10002
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xbd1a27d0bb123ebed244722aa89641b1
Finished request 6.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 10002, 
id=8, length=251
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0xbd1a27d0bb123ebed244722aa89641b1
    EAP-Message = 
    Message-Authenticator = 0xe284c38150b6530357b2cc2f73c468d2
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 8 length 93
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: EAP type mschapv2
  PEAP: Got tunneled EAP-Message
    EAP-Message = 
  PEAP: Setting User-Name to LINUX\test1
  PEAP: Sending tunneled request
    EAP-Message = 
    FreeRADIUS-Proxied-To =
    User-Name = "LINUX\\test1"
    State = 0xe6b55262e6bd4850d1efd72bdd823e7d
server inner-tunnel {
+- entering group authorize
++[mschap] returns noop
++[control] returns noop
  rlm_eap: EAP packet type response id 8 length 70
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/mschapv2
  rlm_eap: processing type mschapv2
+- entering group MS-CHAP
  rlm_mschap: No Cleartext-Password configured.  Cannot create LM-Password.
  rlm_mschap: No Cleartext-Password configured.  Cannot create NT-Password.
  rlm_mschap: Told to do MS-CHAPv2 for test1 with NT-Password
  rlm_mschap: FAILED: No NT/LM-Password.  Cannot perform authentication.
  rlm_mschap: FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
  rlm_eap: Freeing handler
++[eap] returns reject
auth: Failed to validate the user.
Login incorrect (rlm_ldap: User not found): [LINUX\\test1/<via Auth-Type 
= EAP>] (from client private-network-2 port 0 via TLS tunnel)
} # server inner-tunnel
  PEAP: Got tunneled reply RADIUS code 3
    MS-CHAP-Error = "\010E=691 R=1"
    EAP-Message = 0x04080004
    Message-Authenticator = 0x00000000000000000000000000000000
  PEAP: Processing from tunneled session code 0x1de1930 3
    MS-CHAP-Error = "\010E=691 R=1"
    EAP-Message = 0x04080004
    Message-Authenticator = 0x00000000000000000000000000000000
  PEAP: Tunneled authentication was rejected.
  rlm_eap_peap: FAILURE
++[eap] returns handled
Sending Access-Challenge of id 8 to port 10002
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0xbd1a27d0ba133ebed244722aa89641b1
Finished request 7.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 10002, 
id=9, length=196
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0xbd1a27d0ba133ebed244722aa89641b1
    EAP-Message = 
    Message-Authenticator = 0x7484b90d3715780775716007fb7dc660
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 9 length 38
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: Received EAP-TLV response.
  rlm_eap_peap:  Had sent TLV failure.  User was rejected earlier in 
this session.
 rlm_eap: Handler failed in EAP/peap
  rlm_eap: Failed in EAP select
++[eap] returns invalid
auth: Failed to validate the user.
Login incorrect: [LINUX\\test1/<via Auth-Type = EAP>] (from client 
private-network-2 port 1 cli 00:13:e8:b9:8c:b9)
  Found Post-Auth-Type Reject
+- entering group REJECT
    expand: %{User-Name} -> LINUX\test1
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 8 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 8
Sending Access-Reject of id 9 to port 10002
    EAP-Message = 0x04090004
    Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 3.9 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=11, length=156
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    EAP-Message = 0x02010010014c494e55585c7465737431
    Message-Authenticator = 0xf00d1284aa5548d655b47a1bac769f35
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 1 length 16
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: EAP Identity
  rlm_eap: processing type tls
  rlm_eap_tls: Initiate
  rlm_eap_tls: Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 11 to port 10003
    EAP-Message = 0x010200061920
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x1000725f10026b765c42d054796fe3e0
Finished request 9.
Going to the next request
Waking up in 3.7 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=12, length=238
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x1000725f10026b765c42d054796fe3e0
    EAP-Message = 
    Message-Authenticator = 0xbd34cc45c69004c920bebfaedde64341
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 2 length 80
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  TLS Length 70
rlm_eap_tls:  Length Included
  eaptls_verify returned 11
    (other): before/accept initialization
    TLS_accept: before/accept initialization
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0041], ClientHello 
    TLS_accept: SSLv3 read client hello A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 004a], ServerHello 
    TLS_accept: SSLv3 write server hello A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 085e], Certificate 
    TLS_accept: SSLv3 write certificate A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 0004], ServerHelloDone 
    TLS_accept: SSLv3 write server done A
    TLS_accept: SSLv3 flush data
    TLS_accept: Need to read more data: SSLv3 read client certificate A
In SSL Handshake Phase
In SSL Accept mode 
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 12 to port 10003
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 0xb04fdd57077b70767f03b4fc
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x1000725f11036b765c42d054796fe3e0
Finished request 10.
Going to the next request
Waking up in 3.7 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=13, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x1000725f11036b765c42d054796fe3e0
    EAP-Message = 0x020300061900
    Message-Authenticator = 0x0ac586525ddee0f50523d80d5f1ccfcb
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 3 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake fragment handler
  eaptls_verify returned 1
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 13 to port 10003
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 0xcc4abf6d8be9f208
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x1000725f12046b765c42d054796fe3e0
Finished request 11.
Going to the next request
Waking up in 3.7 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=14, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x1000725f12046b765c42d054796fe3e0
    EAP-Message = 0x020400061900
    Message-Authenticator = 0xcfdcb541d6e3a4355eb5afaeb87e4c14
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 4 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake fragment handler
  eaptls_verify returned 1
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 14 to port 10003
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x1000725f13056b765c42d054796fe3e0
Finished request 12.
Going to the next request
Waking up in 3.7 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=15, length=480
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x1000725f13056b765c42d054796fe3e0
    EAP-Message = 
    EAP-Message = 
    Message-Authenticator = 0x6fcea68d0057564ded0752c04ef0c0fd
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 5 length 253
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  TLS Length 310
rlm_eap_tls:  Length Included
  eaptls_verify returned 11
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0106], ClientKeyExchange 
    TLS_accept: SSLv3 read client key exchange A
  rlm_eap_tls: <<< TLS 1.0 ChangeCipherSpec [length 0001] 
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0010], Finished 
    TLS_accept: SSLv3 read finished A
  rlm_eap_tls: >>> TLS 1.0 ChangeCipherSpec [length 0001] 
    TLS_accept: SSLv3 write change cipher spec A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 0010], Finished 
    TLS_accept: SSLv3 write finished A
    TLS_accept: SSLv3 flush data
    (other): SSL negotiation finished successfully
SSL Connection Established
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 15 to port 10003
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x1000725f14066b765c42d054796fe3e0
Finished request 13.
Going to the next request
Waking up in 3.7 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=16, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x1000725f14066b765c42d054796fe3e0
    EAP-Message = 0x020600061900
    Message-Authenticator = 0xd1f5823f9c99d02acdfc60567c78f72c
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 6 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake is finished
  eaptls_verify returned 3
  eaptls_process returned 3
  rlm_eap_peap: EAPTLS_SUCCESS
++[eap] returns handled
Sending Access-Challenge of id 16 to port 10003
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x1000725f15076b765c42d054796fe3e0
Finished request 14.
Going to the next request
Waking up in 3.7 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=17, length=197
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x1000725f15076b765c42d054796fe3e0
    EAP-Message = 
    Message-Authenticator = 0xc16e46ee3683ef68ade437712ea6ded6
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 7 length 39
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: Identity - LINUX\test1
  PEAP: Got tunneled EAP-Message
    EAP-Message = 0x02070010014c494e55585c7465737431
  PEAP: Got tunneled identity of LINUX\test1
  PEAP: Setting default EAP type for tunneled EAP session.
  PEAP: Setting User-Name to LINUX\test1
  PEAP: Sending tunneled request
    EAP-Message = 0x02070010014c494e55585c7465737431
    FreeRADIUS-Proxied-To =
    User-Name = "LINUX\\test1"
server inner-tunnel {
+- entering group authorize
++[mschap] returns noop
++[control] returns noop
  rlm_eap: EAP packet type response id 7 length 16
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: EAP Identity
  rlm_eap: processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
  PEAP: Got tunneled reply RADIUS code 11
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x2bad37742ba52dd284335b0b93096851
  PEAP: Processing from tunneled session code 0x1dbdf90 11
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x2bad37742ba52dd284335b0b93096851
  PEAP: Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 17 to port 10003
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x1000725f16086b765c42d054796fe3e0
Finished request 15.
Going to the next request
Waking up in 3.7 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=18, length=251
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x1000725f16086b765c42d054796fe3e0
    EAP-Message = 
    Message-Authenticator = 0xb331a1b177bb51369f9903ea6e5cc76f
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 8 length 93
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: EAP type mschapv2
  PEAP: Got tunneled EAP-Message
    EAP-Message = 
  PEAP: Setting User-Name to LINUX\test1
  PEAP: Sending tunneled request
    EAP-Message = 
    FreeRADIUS-Proxied-To =
    User-Name = "LINUX\\test1"
    State = 0x2bad37742ba52dd284335b0b93096851
server inner-tunnel {
+- entering group authorize
++[mschap] returns noop
++[control] returns noop
  rlm_eap: EAP packet type response id 8 length 70
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/mschapv2
  rlm_eap: processing type mschapv2
+- entering group MS-CHAP
  rlm_mschap: No Cleartext-Password configured.  Cannot create LM-Password.
  rlm_mschap: No Cleartext-Password configured.  Cannot create NT-Password.
  rlm_mschap: Told to do MS-CHAPv2 for test1 with NT-Password
  rlm_mschap: FAILED: No NT/LM-Password.  Cannot perform authentication.
  rlm_mschap: FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
  rlm_eap: Freeing handler
++[eap] returns reject
auth: Failed to validate the user.
Login incorrect (rlm_ldap: User not found): [LINUX\\test1/<via Auth-Type 
= EAP>] (from client private-network-2 port 0 via TLS tunnel)
} # server inner-tunnel
  PEAP: Got tunneled reply RADIUS code 3
    MS-CHAP-Error = "\010E=691 R=1"
    EAP-Message = 0x04080004
    Message-Authenticator = 0x00000000000000000000000000000000
  PEAP: Processing from tunneled session code 0x1dbdff0 3
    MS-CHAP-Error = "\010E=691 R=1"
    EAP-Message = 0x04080004
    Message-Authenticator = 0x00000000000000000000000000000000
  PEAP: Tunneled authentication was rejected.
  rlm_eap_peap: FAILURE
++[eap] returns handled
Sending Access-Challenge of id 18 to port 10003
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x1000725f17096b765c42d054796fe3e0
Finished request 16.
Going to the next request
Waking up in 3.7 seconds.
rad_recv: Access-Request packet from host port 10003, 
id=19, length=196
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x1000725f17096b765c42d054796fe3e0
    EAP-Message = 
    Message-Authenticator = 0xa8ca7a4fcfaa86f696404e95c2f8ee4b
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 9 length 38
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: Received EAP-TLV response.
  rlm_eap_peap:  Had sent TLV failure.  User was rejected earlier in 
this session.
 rlm_eap: Handler failed in EAP/peap
  rlm_eap: Failed in EAP select
++[eap] returns invalid
auth: Failed to validate the user.
Login incorrect: [LINUX\\test1/<via Auth-Type = EAP>] (from client 
private-network-2 port 1 cli 00:13:e8:b9:8c:b9)
  Found Post-Auth-Type Reject
+- entering group REJECT
    expand: %{User-Name} -> LINUX\test1
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 17 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 17
Sending Access-Reject of id 19 to port 10003
    EAP-Message = 0x04090004
    Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 2.7 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=21, length=156
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    EAP-Message = 0x02010010014c494e55585c7465737431
    Message-Authenticator = 0xe812d7788548e10f5519e2b192993b9d
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 1 length 16
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: EAP Identity
  rlm_eap: processing type tls
  rlm_eap_tls: Initiate
  rlm_eap_tls: Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 21 to port 10004
    EAP-Message = 0x010200061920
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x5c9aaff15c98b6268a6c68880037d65f
Finished request 18.
Going to the next request
Waking up in 2.1 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=22, length=238
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x5c9aaff15c98b6268a6c68880037d65f
    EAP-Message = 
    Message-Authenticator = 0xf3a5cd46a4207946dbf86122158d31e8
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 2 length 80
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  TLS Length 70
rlm_eap_tls:  Length Included
  eaptls_verify returned 11
    (other): before/accept initialization
    TLS_accept: before/accept initialization
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0041], ClientHello 
    TLS_accept: SSLv3 read client hello A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 004a], ServerHello 
    TLS_accept: SSLv3 write server hello A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 085e], Certificate 
    TLS_accept: SSLv3 write certificate A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 0004], ServerHelloDone 
    TLS_accept: SSLv3 write server done A
    TLS_accept: SSLv3 flush data
    TLS_accept: Need to read more data: SSLv3 read client certificate A
In SSL Handshake Phase
In SSL Accept mode 
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 22 to port 10004
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 0xb04fdd57077b70767f03b4fc
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x5c9aaff15d99b6268a6c68880037d65f
Finished request 19.
Going to the next request
Waking up in 2.1 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=23, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x5c9aaff15d99b6268a6c68880037d65f
    EAP-Message = 0x020300061900
    Message-Authenticator = 0xdc805aa7b4e1b9c5185c16459e1fa75d
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 3 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake fragment handler
  eaptls_verify returned 1
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 23 to port 10004
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 
    EAP-Message = 0xcc4abf6d8be9f208
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x5c9aaff15e9eb6268a6c68880037d65f
Finished request 20.
Going to the next request
Waking up in 2.1 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=24, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x5c9aaff15e9eb6268a6c68880037d65f
    EAP-Message = 0x020400061900
    Message-Authenticator = 0xfee37471422fafe8fa9e1f462f308402
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 4 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake fragment handler
  eaptls_verify returned 1
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 24 to port 10004
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x5c9aaff15f9fb6268a6c68880037d65f
Finished request 21.
Going to the next request
Waking up in 2.1 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=25, length=480
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x5c9aaff15f9fb6268a6c68880037d65f
    EAP-Message = 
    EAP-Message = 
    Message-Authenticator = 0x2126ff488f3f0520f70089e99213f66a
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 5 length 253
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  TLS Length 310
rlm_eap_tls:  Length Included
  eaptls_verify returned 11
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0106], ClientKeyExchange 
    TLS_accept: SSLv3 read client key exchange A
  rlm_eap_tls: <<< TLS 1.0 ChangeCipherSpec [length 0001] 
  rlm_eap_tls: <<< TLS 1.0 Handshake [length 0010], Finished 
    TLS_accept: SSLv3 read finished A
  rlm_eap_tls: >>> TLS 1.0 ChangeCipherSpec [length 0001] 
    TLS_accept: SSLv3 write change cipher spec A
  rlm_eap_tls: >>> TLS 1.0 Handshake [length 0010], Finished 
    TLS_accept: SSLv3 write finished A
    TLS_accept: SSLv3 flush data
    (other): SSL negotiation finished successfully
SSL Connection Established
  eaptls_process returned 13
  rlm_eap_peap: EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 25 to port 10004
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x5c9aaff1589cb6268a6c68880037d65f
Finished request 22.
Going to the next request
Waking up in 2.1 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=26, length=164
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x5c9aaff1589cb6268a6c68880037d65f
    EAP-Message = 0x020600061900
    Message-Authenticator = 0x59fda3a9e1b134df0b68fb1ad4dc488e
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 6 length 6
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake is finished
  eaptls_verify returned 3
  eaptls_process returned 3
  rlm_eap_peap: EAPTLS_SUCCESS
++[eap] returns handled
Sending Access-Challenge of id 26 to port 10004
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x5c9aaff1599db6268a6c68880037d65f
Finished request 23.
Going to the next request
Waking up in 2.1 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=27, length=197
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x5c9aaff1599db6268a6c68880037d65f
    EAP-Message = 
    Message-Authenticator = 0x3bfc85d5e79119058167b440852935f8
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 7 length 39
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: Identity - LINUX\test1
  PEAP: Got tunneled EAP-Message
    EAP-Message = 0x02070010014c494e55585c7465737431
  PEAP: Got tunneled identity of LINUX\test1
  PEAP: Setting default EAP type for tunneled EAP session.
  PEAP: Setting User-Name to LINUX\test1
  PEAP: Sending tunneled request
    EAP-Message = 0x02070010014c494e55585c7465737431
    FreeRADIUS-Proxied-To =
    User-Name = "LINUX\\test1"
server inner-tunnel {
+- entering group authorize
++[mschap] returns noop
++[control] returns noop
  rlm_eap: EAP packet type response id 7 length 16
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: EAP Identity
  rlm_eap: processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
  PEAP: Got tunneled reply RADIUS code 11
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x8fa5dc688fadc6ebfe94f831548b3cb4
  PEAP: Processing from tunneled session code 0x1dd69f0 11
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x8fa5dc688fadc6ebfe94f831548b3cb4
  PEAP: Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 27 to port 10004
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x5c9aaff15a92b6268a6c68880037d65f
Finished request 24.
Going to the next request
Waking up in 2.1 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=28, length=251
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x5c9aaff15a92b6268a6c68880037d65f
    EAP-Message = 
    Message-Authenticator = 0x28baad3a912c6a18076ffee6d6d4446b
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 8 length 93
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: EAP type mschapv2
  PEAP: Got tunneled EAP-Message
    EAP-Message = 
  PEAP: Setting User-Name to LINUX\test1
  PEAP: Sending tunneled request
    EAP-Message = 
    FreeRADIUS-Proxied-To =
    User-Name = "LINUX\\test1"
    State = 0x8fa5dc688fadc6ebfe94f831548b3cb4
server inner-tunnel {
+- entering group authorize
++[mschap] returns noop
++[control] returns noop
  rlm_eap: EAP packet type response id 8 length 70
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
rlm_ldap: - authorize
rlm_ldap: performing user authorization for LINUX\test1
    expand: (uid=%u) -> (uid=LINUX\5ctest1)
    expand: ou=People,dc=excelhustler,dc=com -> 
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,dc=excelhustler,dc=com, with 
filter (uid=LINUX\5ctest1)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns notfound
++[expiration] returns noop
++[logintime] returns noop
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/mschapv2
  rlm_eap: processing type mschapv2
+- entering group MS-CHAP
  rlm_mschap: No Cleartext-Password configured.  Cannot create LM-Password.
  rlm_mschap: No Cleartext-Password configured.  Cannot create NT-Password.
  rlm_mschap: Told to do MS-CHAPv2 for test1 with NT-Password
  rlm_mschap: FAILED: No NT/LM-Password.  Cannot perform authentication.
  rlm_mschap: FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
  rlm_eap: Freeing handler
++[eap] returns reject
auth: Failed to validate the user.
Login incorrect (rlm_ldap: User not found): [LINUX\\test1/<via Auth-Type 
= EAP>] (from client private-network-2 port 0 via TLS tunnel)
} # server inner-tunnel
  PEAP: Got tunneled reply RADIUS code 3
    MS-CHAP-Error = "\010E=691 R=1"
    EAP-Message = 0x04080004
    Message-Authenticator = 0x00000000000000000000000000000000
  PEAP: Processing from tunneled session code 0x1dd6680 3
    MS-CHAP-Error = "\010E=691 R=1"
    EAP-Message = 0x04080004
    Message-Authenticator = 0x00000000000000000000000000000000
  PEAP: Tunneled authentication was rejected.
  rlm_eap_peap: FAILURE
++[eap] returns handled
Sending Access-Challenge of id 28 to port 10004
    EAP-Message = 
    Message-Authenticator = 0x00000000000000000000000000000000
    State = 0x5c9aaff15b93b6268a6c68880037d65f
Finished request 25.
Going to the next request
Waking up in 2.0 seconds.
rad_recv: Access-Request packet from host port 10004, 
id=29, length=196
    User-Name = "LINUX\\test1"
    Called-Station-Id = "00:23:68:0f:7a:90"
    Calling-Station-Id = "00:13:e8:b9:8c:b9"
    NAS-Port = 1
    NAS-Port-Type = Wireless-802.11
    Framed-MTU = 1400
    NAS-IP-Address =
    NAS-Identifier = "AP-51xx"
    Vendor-388-Attr-2 = 0x657863656c656170
    State = 0x5c9aaff15b93b6268a6c68880037d65f
    EAP-Message = 
    Message-Authenticator = 0x859d6bcd5df76246dc339b04047c507b
+- entering group authorize
++[preprocess] returns ok
++[mschap] returns noop
  rlm_eap: EAP packet type response id 9 length 38
  rlm_eap: Continuing tunnel setup.
++[eap] returns ok
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
+- entering group authenticate
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
  eaptls_verify returned 7
  rlm_eap_tls: Done initial handshake
  eaptls_process returned 7
  rlm_eap_peap: EAPTLS_OK
  rlm_eap_peap: Session established.  Decoding tunneled attributes.
  rlm_eap_peap: Received EAP-TLV response.
  rlm_eap_peap:  Had sent TLV failure.  User was rejected earlier in 
this session.
 rlm_eap: Handler failed in EAP/peap
  rlm_eap: Failed in EAP select
++[eap] returns invalid
auth: Failed to validate the user.
Login incorrect: [LINUX\\test1/<via Auth-Type = EAP>] (from client 
private-network-2 port 1 cli 00:13:e8:b9:8c:b9)
  Found Post-Auth-Type Reject
+- entering group REJECT
    expand: %{User-Name} -> LINUX\test1
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 26 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 26
Sending Access-Reject of id 29 to port 10004
    EAP-Message = 0x04090004
    Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 1.0 seconds.
Cleaning up request 0 ID 1 with timestamp +12
Cleaning up request 1 ID 2 with timestamp +12
Cleaning up request 2 ID 3 with timestamp +12
Cleaning up request 3 ID 4 with timestamp +12
Cleaning up request 4 ID 5 with timestamp +12
Cleaning up request 5 ID 6 with timestamp +12
Cleaning up request 6 ID 7 with timestamp +12
Cleaning up request 7 ID 8 with timestamp +12
Waking up in 1.0 seconds.
Cleaning up request 8 ID 9 with timestamp +12
Waking up in 0.1 seconds.
Cleaning up request 9 ID 11 with timestamp +13
Cleaning up request 10 ID 12 with timestamp +13
Cleaning up request 11 ID 13 with timestamp +13
Cleaning up request 12 ID 14 with timestamp +13
Cleaning up request 13 ID 15 with timestamp +13
Cleaning up request 14 ID 16 with timestamp +13
Cleaning up request 15 ID 17 with timestamp +13
Cleaning up request 16 ID 18 with timestamp +13
Waking up in 1.0 seconds.
Cleaning up request 17 ID 19 with timestamp +13
Waking up in 0.5 seconds.
Cleaning up request 18 ID 21 with timestamp +15
Cleaning up request 19 ID 22 with timestamp +15
Cleaning up request 20 ID 23 with timestamp +15
Cleaning up request 21 ID 24 with timestamp +15
Cleaning up request 22 ID 25 with timestamp +15
Cleaning up request 23 ID 26 with timestamp +15
Cleaning up request 24 ID 27 with timestamp +15
Cleaning up request 25 ID 28 with timestamp +15
Waking up in 1.0 seconds.
Cleaning up request 26 ID 29 with timestamp +15
Ready to process requests.


More information about the Freeradius-Users mailing list