eap-fast: using eap-fast-mschapv2 in anonymous tunnel

Alan DeKok aland at deployingradius.com
Sat Sep 23 15:06:21 CEST 2017


On Sep 23, 2017, at 7:40 AM, Isaac Boukris <iboukris at gmail.com> wrote:
> That stopped the crash. However eap-fast still fails for no obvious
> reason and sometimes the server exits on assertion fail - see attached
> log.

  I've pushed the patch, thanks.

  The reason EAP-FAST fails is odd... I suspect it's because the code was re-written a while ago and not properly tested.

  I've pushed one more fix which lets it go further.  It now complains about 

(1)    eap_fast - ERROR: PAC missing type TLV, sending alert to client

  And the client complains about:

SSL: SSL3 alert: read (remote end reported an error):fatal:bad certificate


  Which is weird.  Probably again due to the re-write.

  As for the assertion, that's odd.  I don't see anything like that on my system.  And the hope is that time is always increasing.

  Alan DeKok.




More information about the Freeradius-Users mailing list