<HTML>
<font style="font-size: 10pt;"><div style="font-size: 10pt;">I don't have a
lot of idea about freeradius.. but:</div><div> </div><div> </div>
</font><div>[pap] login attempt with password "?;më˝i???á58n??"</div><div>
[pap] Using CRYPT password "1234"</div><div>[pap] Passwords don't match</div>
<div>++[pap] returns reject</div><div>Failed to authenticate the user.</div>
<div><div style="font-size: 10pt;"> WARNING: Unprintable
characters in the password. Double-check the
shared secret on the server and the NAS!</div><div> </div><div>
</div><div>this could be the answer. <br></div></div><font
style="font-size: 10pt;"><div><br> </div></font>
<br><br><br><br><table class="MsoNormalTable" border="0" cellpadding="0">
<tbody><tr><td style="padding: 0.75pt;"><table class="MsoNormalTable"
border="0" cellpadding="0"><tbody><tr><td style="padding: 0.75pt;"><table
class="MsoNormalTable" style="width: 482.25pt;" width="643" border="0"
cellpadding="0"><tbody><tr><td style="padding: 0.75pt; width: 477.45pt;"
width="637"><div class="MsoNormal" style="line-height: 115%;"><b><span
style="font-size: 9pt; color: rgb(31, 73, 125); line-height: 115%;
font-family: 'Arial','sans-serif';" lang="CA">Martín Ruiz</span></b><span
style="font-size: 9pt; color: rgb(31, 73, 125); line-height: 115%;"><o:p>
</o:p></span></div></td><td style="padding: 0cm;" valign="top"><div
class="MsoNormal" style="line-height: 115%;"><b><span style="font-size: 9pt;
color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';"><o:p> </o:p></span></b></div></td></tr><tr><td
style="padding: 0.75pt; width: 477.45pt;" width="637"><div class="MsoNormal"
style="line-height: 115%; margin-right: 297.6pt;"><v:shapetype
id="_x0000_t75" stroked="f" filled="f" path="m@4@5l@4@11@9@11@9@5xe"
o:preferrelative="t" o:spt="75" coordsize="21600,21600"><v:stroke
joinstyle="miter"></v:stroke><v:formulas><v:f eqn="if lineDrawn
pixelLineWidth 0"></v:f><v:f eqn="sum @0 1 0"></v:f><v:f eqn="sum 0 0 @1">
</v:f><v:f eqn="prod @2 1 2"></v:f><v:f eqn="prod @3 21600 pixelWidth"></v:f>
<v:f eqn="prod @3 21600 pixelHeight"></v:f><v:f eqn="sum @0 0 1"></v:f><v:f
eqn="prod @6 1 2"></v:f><v:f eqn="prod @7 21600 pixelWidth"></v:f><v:f
eqn="sum @8 21600 0"></v:f><v:f eqn="prod @7 21600 pixelHeight"></v:f><v:f
eqn="sum @10 21600 0"></v:f></v:formulas><v:path o:connecttype="rect"
gradientshapeok="t" o:extrusionok="f"></v:path><o:lock aspectratio="t"
v:ext="edit"></o:lock></v:shapetype><v:shape id="_x0000_s1026"
style="margin-top: 0.45pt; z-index: -1; visibility: visible; margin-left:
131.15pt; width: 333.1pt; position: absolute; height: 76.8pt;"
alt="correo.jpg" type="#_x0000_t75"><v:imagedata o:title="correo"
src="http://www.ibersystems.es/correo.jpg"></v:imagedata></v:shape><b><span
style="font-size: 9pt; color: rgb(31, 73, 125); line-height: 115%;
font-family: 'Arial','sans-serif';" lang="CA">Ibersystems Solutions,
SL</span></b><span style="font-size: 9pt; color: rgb(31, 73, 125);
line-height: 115%;"></span></div></td><td style="padding: 0cm;" valign="top">
<div class="MsoNormal" style="line-height: 115%;"><b><span style="font-size:
9pt; color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';" lang="CA"><o:p> </o:p></span></b></div></td></tr>
<tr><td style="padding: 0.75pt; width: 477.45pt;" width="637"><div
class="MsoNormal" style="line-height: 115%;"><span style="font-size: 8pt;
color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';" lang="CA">Dpto. Redes Inalámbricas</span><span
style="font-size: 8pt; color: rgb(31, 73, 125); line-height: 115%;"><o:p>
</o:p></span></div></td><td style="padding: 0cm;" valign="top"><div
class="MsoNormal" style="line-height: 115%;"><span style="font-size: 8pt;
color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';" lang="CA"><o:p> </o:p></span></div></td></tr><tr>
<td style="padding: 0.75pt; width: 477.45pt;" width="637"><div
class="MsoNormal" style="line-height: 115%;"><span style="font-size: 8pt;
color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';" lang="CA">Tel. 902 909 858<o:p></o:p></span></div>
<div class="MsoNormal" style="line-height: 115%;"><span style="font-size:
8pt; color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';" lang="CA"> 669 37
95 21</span><span style="font-size: 8pt; color: rgb(31, 73, 125);
line-height: 115%;"><o:p></o:p></span></div></td><td style="padding: 0cm;"
valign="top"><div class="MsoNormal" style="line-height: 115%;"><span
style="font-size: 8pt; color: rgb(31, 73, 125); line-height: 115%;
font-family: 'Arial','sans-serif';" lang="CA"><o:p> </o:p></span></div>
</td></tr><tr><td style="padding: 0.75pt; width: 477.45pt;" width="637"><div
class="MsoNormal" style="line-height: 115%;"><span style="font-size: 8pt;
color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';" lang="CA">Fax 93 758 63 01</span><span
style="font-size: 8pt; color: rgb(31, 73, 125); line-height: 115%;"><o:p>
</o:p></span></div></td><td style="padding: 0cm;" valign="top"><div
class="MsoNormal" style="line-height: 115%;"><span style="font-size: 8pt;
color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';" lang="CA"><o:p> </o:p></span></div></td></tr><tr>
<td style="padding: 0.75pt; width: 477.45pt;" width="637"><div
class="MsoNormal" style="line-height: 115%;"><span style="font-size: 8pt;
color: rgb(31, 73, 125); line-height: 115%; font-family:
'Arial','sans-serif';" lang="CA"><a href="http://www.ibersystems.es/"><span
style="color: blue;">http://www.ibersystems.es</span></a><o:p></o:p></span>
</div><div class="MsoNormal" style="line-height: 115%;"><span
style="font-size: 8pt; color: rgb(31, 73, 125); line-height: 115%;
font-family: 'Arial','sans-serif';" lang="CA"><a
href="mailto:martinruiz@ibersystems.es"><span style="color: blue;">
martinruiz@ibersystems.es</span></a></span><span style="font-size: 8pt;
color: rgb(31, 73, 125); line-height: 115%;"><o:p></o:p></span></div></td>
<td style="padding: 0cm;" valign="top"><div class="MsoNormal"
style="line-height: 115%;"><span style="font-size: 8pt; color: rgb(31, 73,
125); line-height: 115%; font-family: 'Arial','sans-serif';" lang="CA"><o:p>
</o:p></span></div></td></tr></tbody></table></td><td style="padding:
0.75pt 0.75pt 0.75pt 18.7pt;"><br></td></tr></tbody></table></td></tr><tr>
<td style="padding: 0.75pt;"><table class="MsoNormalTable" border="0"
cellpadding="0"><tbody><tr><td style="padding: 0.75pt;" colspan="2"><div
class="MsoNormal" style="line-height: 115%; text-align: justify;"><b><span
style="font-size: 7pt; color: rgb(31, 73, 125); line-height: 115%;
font-family: 'Arial','sans-serif';" lang="CA">Estemensaje puede contener
información confidencial y/o privilegiada. Siusted no es el destinatario o
una persona expresamente autorizada pararecibir este envío no debe
utilizar, copiar, reenviar, distribuir, o engeneral disponer de ninguna
forma de la información incluida. Sihubiera recibido este mensaje por
error, sírvase informar al emisormediante una respuesta inmediata y
bórrelo, por favor. Muchas gracias.<o:p></o:p></span></b></div><div
class="MsoNormal" style="line-height: 115%; text-align: justify;"><span
style="font-size: 10pt; color: green; line-height: 115%; font-family:
Webdings;" lang="CA">P</span><b><span style="font-size: 11pt; color: green;
line-height: 115%; font-family: 'Arial','sans-serif';" lang="CA"> </span></b>
<b><span style="font-size: 7pt; color: green; line-height: 115%;
font-family: 'Arial','sans-serif';" lang="CA">Antes de imprimir este e-mail,
piensa en si es realmente necesario: El Medio Ambiente es responsabilidad de
todos</span></b><span style="font-size: 7pt; color: rgb(31, 73, 125);
line-height: 115%;"><o:p></o:p></span></div></td></tr><tr><td
style="padding: 0.75pt; width: 9.35pt;" width="12"><br></td><td
style="padding: 0.75pt;"><br></td></tr></tbody></table></td></tr></tbody>
</table><br><br>
<br><blockquote style="border-left: 2px solid rgb(0, 0, 0); padding-right:
0px; padding-left: 5px; margin-left: 5px; margin-right: 0px;">
-----Original Message-----<br>
From: Miha Zoubek <miha_zoubek@hotmail.com><br>
To: <freeradius-users@lists.freeradius.org><br>
Date: Thu, 2 Dec 2010 15:04:59 +0000<br>
Subject: Clear text password (radius)<br>
<br>
Hello,<div><br></div><div>I am trying to get radius working for voip. I am
getting this error.</div><div><br></div><div><div>including configuration
file /etc/raddb/modules/ntlm_auth</div><div>including configuration file
/etc/raddb/modules/mac2vlan</div><div>including configuration file
/etc/raddb/modules/dynamic_clients</div><div>including configuration file
/etc/raddb/modules/inner-eap</div><div>including configuration file
/etc/raddb/modules/detail.example.com</div><div>including configuration file
/etc/raddb/modules/expiration</div><div>including configuration file
/etc/raddb/modules/unix</div><div>including configuration file
/etc/raddb/modules/expr</div><div>including configuration file
/etc/raddb/modules/policy</div><div>including configuration file
/etc/raddb/modules/sql_log</div><div>including configuration file
/etc/raddb/modules/cui</div><div>including configuration file
/etc/raddb/modules/realm</div><div>including configuration file
/etc/raddb/modules/radutmp</div><div>including configuration file
/etc/raddb/modules/linelog</div><div>including configuration file
/etc/raddb/modules/detail.log</div><div>including configuration file
/etc/raddb/modules/attr_filter</div><div>including configuration file
/etc/raddb/modules/mschap</div><div>including configuration file
/etc/raddb/modules/attr_rewrite</div><div>including configuration file
/etc/raddb/modules/smbpasswd</div><div>including configuration file
/etc/raddb/modules/opendirectory</div><div>including configuration file
/etc/raddb/modules/sradutmp</div><div>including configuration file
/etc/raddb/modules/logintime</div><div>including configuration file
/etc/raddb/modules/digest</div><div>including configuration file
/etc/raddb/modules/passwd</div><div>including configuration file
/etc/raddb/modules/exec</div><div>including configuration file
/etc/raddb/modules/perl</div><div>including configuration file
/etc/raddb/modules/acct_unique</div><div>including configuration file
/etc/raddb/modules/checkval</div><div>including configuration file
/etc/raddb/modules/otp</div><div>including configuration file
/etc/raddb/modules/preprocess</div><div>including configuration file
/etc/raddb/modules/detail</div><div>including configuration file
/etc/raddb/modules/mac2ip</div><div>including configuration file
/etc/raddb/modules/pap</div><div>including configuration file
/etc/raddb/modules/etc_group</div><div>including configuration file
/etc/raddb/modules/smsotp</div><div>including configuration file
/etc/raddb/modules/chap</div><div>including configuration file
/etc/raddb/modules/echo</div><div>including configuration file
/etc/raddb/modules/wimax</div><div>including configuration file
/etc/raddb/eap.conf</div><div>including configuration file
/etc/raddb/sql.conf</div><div>including configuration file
/etc/raddb/sql/mysql/dialup.conf</div><div>including configuration file
/etc/raddb/policy.conf</div><div>including files in directory
/etc/raddb/sites-enabled/</div><div>including configuration file
/etc/raddb/sites-enabled/inner-tunnel</div><div>including configuration file
/etc/raddb/sites-enabled/control-socket</div><div>including configuration
file /etc/raddb/sites-enabled/default</div><div>main {</div><div>
user = "radiusd"</div><div>
group = "radiusd"</div><div>
allow_core_dumps = no</div><div>}</div><div>including dictionary file
/etc/raddb/dictionary</div><div>main {</div><div>
prefix = "/usr"</div><div>
localstatedir = "/var"</div><div>
logdir = "/var/log/radius"</div><div>
libdir = "/usr/lib64/freeradius"</div><div>
radacctdir = "/var/log/radius/radacct"</div><div>
hostname_lookups = no</div><div>
max_request_time = 30</div><div>
cleanup_delay = 5</div><div>
max_requests = 1024</div><div>&
nbsp; pidfile =
"/var/run/radiusd/radiusd.pid"</div><div>
checkrad = "/usr/sbin/checkrad"</div><div>
debug_level = 0</div><div>
proxy_requests = yes</div><div> log {</div><div>
stripped_names = no</div><div>
auth = no</div><div> auth_badpass =
no</div><div> auth_goodpass = no</div><div>
}</div><div> security {</div><div>
max_attributes = 200</div><div>
reject_delay = 1</div><div>
status_server = yes</div><div> }</div><div>}</div><div>radiusd:
#### Loading Realms and Home Servers ####</div><div> proxy server
{</div><div> retry_delay = 5</div><div>
retry_count = 3</div><div>
default_fallback = no</div><div>
dead_time = 120</div><div>
wake_all_if_all_dead = no</div><div> }</div><div>
home_server localhost {</div><div>
ipaddr = 127.0.0.1</div><div> port =
1812</div><div> type = "auth"</div><div>
secret = "testing123"</div><div>
response_window = 20</div><div>
max_outstanding = 65536</div><div>
require_message_authenticator = yes</div><div>
zombie_period = 40</div><div>
status_check = "status-server"</div><div>
ping_interval = 30</div><div>
check_interval = 30</div><div>
num_answers_to_alive = 3</div><div>
num_pings_to_alive = 3</div><div>
revive_interval = 120</div><div>
status_check_timeout = 4</div><div>
irt = 2</div><div> mrt = 16</div><div>
mrc = 5</div><div>
mrd = 30</div><div> }</div><div> home_server_pool
my_auth_failover {</div><div> type =
fail-over</div><div> home_server =
localhost</div><div> }</div><div> realm example.com {</div><div>
auth_pool = my_auth_failover</div><div>
}</div><div> realm LOCAL {</div><div> }</div><div>radiusd:
#### Loading Clients ####</div><div> client localhost {</div><div>
ipaddr = 127.0.0.1</div><div>
require_message_authenticator = no</div><div>
secret = "testing123"</div><div>
nastype = "other"</div><div> }</div>
<div> client xxx.xxx.xxx.xxx</div><div> {</div><div>
require_message_authenticator = no</div>
<div> secret = "soft1234"</div><div>
shortname = "intraswitch"</div><div>
}</div><div>radiusd: #### Instantiating modules ####</div><div>
instantiate {</div><div> Module: Linked to module rlm_exec</div>
<div> Module: Instantiating module "exec" from file
/etc/raddb/modules/exec</div><div> exec {</div><div>
wait = no</div><div>
input_pairs = "request"</div><div>
shell_escape = yes</div><div> }</div><div> Module:
Linked to module rlm_expr</div><div> Module: Instantiating module
"expr" from file /etc/raddb/modules/expr</div><div> Modu
le: Linked to module rlm_expiration</div><div> Module: Instantiating
module "expiration" from file /etc/raddb/modules/expiration</div><div>
expiration {</div><div>
reply-message = "Password Has Expired "</div><div>
}</div><div> Module: Linked to module rlm_logintime</div>
<div> Module: Instantiating module "logintime" from file
/etc/raddb/modules/logintime</div><div> logintime {</div><div>
reply-message = "You are calling outside
your allowed timespan "</div><div>
minimum-timeout = 60</div><div> }</div><div> }</div>
<div>radiusd: #### Loading Virtual Servers ####</div><div>server
inner-tunnel { # from file /etc/raddb/sites-enabled/inner-tunnel</div><div>
modules {</div><div> Module: Checking authenticate {...} for more
modules to load</div><div> Module: Linked to module rlm_pap</div><div>
Module: Instantiating module "pap" from file
/etc/raddb/modules/pap</div><div> pap {</div><div>
encryption_scheme = "auto"</div><div>
auto_header = no</div><div> }</div><div>
Module: Linked to module rlm_chap</div><div> Module:
Instantiating module "chap" from file /etc/raddb/modules/chap</div><div>
Module: Linked to module rlm_mschap</div><div> Module:
Instantiating module "mschap" from file /etc/raddb/modules/mschap</div><div>
mschap {</div><div> use_mppe =
yes</div><div> require_encryption = no</div>
<div> require_strong = no</div><div>
with_ntdomain_hack = no</div><div>
}</div><div> Module: Linked to module rlm_unix</div><div>
Module: Instantiating module "unix" from file
/etc/raddb/modules/unix</div><div> unix {</div><div>
radwtmp = "/var/log/radius/radwtmp"</div><div>
}</div><div> Module: Linked to module rlm_eap</div><div>
Module: Instantiating module "eap" from file /etc/raddb/eap.conf</div>
<div> eap {</div><div>
default_eap_type = "md5"</div><div>
timer_expire = 60</div><div>
ignore_unknown_eap_types = no</div><div>
cisco_accounting_username_bug = no</div><div>
max_sessions = 4096</div><div> }</div><div>
Module: Linked to sub-module rlm_eap_md5</div><div> Module:
Instantiating eap-md5</div><div> Module: Linked to sub-module
rlm_eap_leap</div><div> Module: Instantiating eap-leap</div><div>
Module: Linked to sub-module rlm_eap_gtc</div><div> Module:
Instantiating eap-gtc</div><div> gtc {</div><div>
challenge = "Password: "</div><div>
auth_type = "PAP"</div><div> }</div><div>
Module: Linked to sub-module rlm_eap_tls</div><div> Module:
Instantiating eap-tls</div><div> tls {</div><div>
rsa_key_exchange = no</div><div>
dh_key_exchange = yes</div><div>
rsa_key_length = 512</div><div>
dh_key_length = 512</div><div>
verify_depth = 0</div><div> CA_path =
"/etc/raddb/certs"</div><div> pem_file_type
= yes</div><div> private_key_file =
"/etc/raddb/certs/server.pem"</div><div>
certificate_file = "/etc/raddb/certs/server.pem"</div><div>
CA_file = "/etc/raddb/certs/ca.pem"</div>
<div> private_key_password = "whatever"</div>
<div> dh_file = "/e
tc/raddb/certs/dh"</div><div> random_file =
"/etc/raddb/certs/random"</div><div>
fragment_size = 1024</div><div>
include_length = yes</div><div>
check_crl = no</div><div> cipher_list
= "DEFAULT"</div><div> cache {</div><div>
enable = no</div><div>
lifetime = 24</div><div> max_entries =
255</div><div> }</div><div> verify
{</div><div> }</div><div> }</div><div>
Module: Linked to sub-module rlm_eap_ttls</div><div> Module:
Instantiating eap-ttls</div><div> ttls {</div><div>
default_eap_type = "md5"</div><div>
copy_request_to_tunnel = no</div><div>
use_tunneled_reply = no</div><div>
virtual_server = "inner-tunnel"</div><div>
include_length = yes</div><div> }</div><div> Module:
Linked to sub-module rlm_eap_peap</div><div> Module: Instantiating
eap-peap</div><div> peap {</div><div>
default_eap_type = "mschapv2"</div><div>
copy_request_to_tunnel = no</div><div>
use_tunneled_reply = no</div><div>
proxy_tunneled_request_as_eap = yes</div><div>
virtual_server = "inner-tunnel"</div><div> }</div>
<div> Module: Linked to sub-module rlm_eap_mschapv2</div><div>
Module: Instantiating eap-mschapv2</div><div> mschapv2
{</div><div> with_ntdomain_hack = no</div>
<div> }</div><div> Module: Checking authorize {...} for
more modules to load</div><div> Module: Linked to module rlm_realm</div>
<div> Module: Instantiating module "suffix" from file
/etc/raddb/modules/realm</div><div> realm suffix {</div><div>
format = "suffix"</div><div>
delimiter = "@"</div><div>
ignore_default = no</div><div>
ignore_null = no</div><div> }</div><div> Module:
Linked to module rlm_files</div><div> Module: Instantiating module
"files" from file /etc/raddb/modules/files</div><div> files
{</div><div> usersfile =
"/etc/raddb/users"</div><div> acctusersfile
= "/etc/raddb/acct_users"</div><div>
preproxy_usersfile = "/etc/raddb/preproxy_users"</div><div>
compat = "no"</div><div> }</div>
<div> Module: Checking session {...} for more modules to load</div><div>
Module: Linked to module rlm_radutmp</div><div> Module:
Instantiating module "radutmp" from file /etc/raddb/modules/radutmp</div>
<div> radutmp {</div><div>
filename = "/var/log/radius/radutmp"</div><div>
username = "%{User-Name}"</div><div>
case_sensitive = yes</div><div>
check_with_nas = yes</div><div> perm =
384</div><div> callerid = yes</div><div>
}</div><div> Module: Checking post-proxy {...} for more
modules to load</div><div> Module: Checking post-auth {...} for more
modules to load</div><div> Module: Linked to module
rlm_attr_filter</div><div> Module: Instantiating module
"attr_filter.access_reject" from file /etc/raddb/modules/attr_filter</div>
<div> attr_filter attr_filter.access_reject {</div><div>
attrsfile = "/etc/raddb/attrs.ac
cess_reject"</div><div> key =
"%{User-Name}"</div><div> }</div><div> } # modules</div><div>
} # server</div><div>server { # from file /etc/raddb/radiusd.conf</div><div>
modules {</div><div> Module: Checking authenticate {...} for more
modules to load</div><div> Module: Linked to module rlm_digest</div>
<div> Module: Instantiating module "digest" from file
/etc/raddb/modules/digest</div><div> Module: Checking authorize {...}
for more modules to load</div><div> Module: Linked to module
rlm_preprocess</div><div> Module: Instantiating module "preprocess"
from file /etc/raddb/modules/preprocess</div><div> preprocess
{</div><div> huntgroups =
"/etc/raddb/huntgroups"</div><div> hints =
"/etc/raddb/hints"</div><div>
with_ascend_hack = no</div><div>
ascend_channels_per_line = 23</div><div>
with_ntdomain_hack = no</div><div>
with_specialix_jetstream_hack = no</div><div>
with_cisco_vsa_hack = no</div><div>
with_alvarion_vsa_hack = no</div><div> }</div><div>
Module: Linked to module rlm_sql</div><div> Module: Instantiating
module "sql" from file /etc/raddb/sql.conf</div><div> sql {</div>
<div> driver = "rlm_sql_mysql"</div><div>
server = "localhost"</div><div>
port = ""</div><div>
login = "root"</div><div> password =
"soft1234"</div><div> radius_db =
"radius"</div><div> read_groups = yes</div>
<div> sqltrace = no</div><div>
sqltracefile = "/var/log/radius/sqltrace.sql"</div><div>
readclients = no</div><div>
deletestalesessions = yes</div><div>
num_sql_socks = 5</div><div>
lifetime = 0</div><div> max_queries =
0</div><div> sql_user_name =
"%{User-Name}"</div><div>
default_user_profile = ""</div><div>
nas_query = "SELECT id, nasname, shortname, type, secret, server FROM
nas"</div><div> authorize_check_query =
"SELECT id, username, attribute, value, op
FROM radcheck WHERE username =
'%{SQL-User-Name}' ORDER BY id"</div><div>
authorize_reply_query = "SELECT id,
username, attribute, value, op FROM
radreply WHERE username =
'%{SQL-User-Name}' ORDER BY id"</div><div>
authorize_group_check_query = "SELECT id,
groupname, attribute, Value, op
FROM radgroupcheck
WHERE groupname = '%{Sql-Group}'
ORDER BY id"</div><div>
authorize_group_reply_query = "SELECT id, groupname, attribute,
value, op
FROM radgroupreply WHERE groupname =
'%{Sql-Group}' ORDER BY id"</div><div>
accounting_onoff_query = "
UPDATE radacct SET
acctstoptime
= '%S', &
nbsp; acctsessiontime = unix_timestamp('%S')
-
unix_timestamp(acctstarttime),
acctterminatecause = '%{Acct-Terminate-Cause}',
acctstopdelay =
%{%{Acct-Delay-Time}:-0} WHERE
acctstoptime IS NULL AND nasipaddress
= '%{NAS-IP-Address}'
AND acctstarttime <= '%S'"</div><div>
accounting_update_query = "
UPDATE radacct SET
framedipaddress = '%{Framed-IP-Address}',
acctsessiontime
= '%{Acct-Session-Time}',
acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}'
<< 32 |
'%{%{Acct-Input-Octets}:-0}',
acctoutputoctets =
'%{%{Acct-Output-Gigawords}:-0}' << 32 |
'%{%{Acct-Output-Octets}:-0}'
WHERE acctsessionid = '%{Acct-Session-Id}'
AND username =
'%{SQL-User-Name}' AND nasipaddress
= '%{NAS-IP-Address}'"</div><div>
accounting_update_query_alt = "
INSERT INTO radacct
(acctsessionid, acctuniqueid, username,
realm,
nasipaddress, nasportid,
nasporttype,
acctstarttime, acctsessiontime,
acctauthentic, connectinfo_start,
acctinputoctets,
acctoutputoctets, calledstationid, callingstationid,
servicetype,
framedprotocol, framedipaddress,
acctstartdelay, xascendsessionsvrkey)
VALUES
('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}',
'%{SQL-User-Name}',
'%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port}',
'%{NAS-Port-Type}',
DATE_SUB('%S',
INTERVAL
(%{%{Acct-Session-Time}:-0} +
%{%{Acct-Delay-Time}:-0}) SECOND),
'%{Acct-Session-Time}',
'%{Acct-Authentic}', '',
'%{%{Acct-Input-Gigawords}:-0}' <<
32 |
'%{%{Acct-Input-Octets}:-0}',
'%{%{Acct-Output-Gigawords}:-0}' << 32 |
'%{%{Acct-Output-Octets}:-0}',
'%
{Called-Station-Id}', '%{Calling-Station-Id}',
'%{Service-Type}', '%{Framed-Protocol}',
'%{Framed-IP-Address}',
'0', '%{X-Ascend-Session-Svr-Key}')"</div>
<div> accounting_start_query = "
INSERT INTO radacct
(acctsessionid, acctuniqueid,
username, realm,
nasipaddress, nasportid,
nasporttype,
acctstarttime, acctstoptime,
acctsessiontime, acctauthentic,
connectinfo_start,
connectinfo_stop, acctinputoctets, acctoutputoctets,
calledstationid,
callingstationid, acctterminatecause,
servicetype, framedprotocol,
framedipaddress,
acctstartdelay, acctstopdelay,
xascendsessionsvrkey) VALUES
('%{Acct-Session-Id}',
'%{Acct-Unique-Session-Id}',
'%{SQL-User-Name}',
'%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port}',
'%{NAS-Port-Type}', '%S', NULL,
'0', '%{Acct-Authentic}',
'%{Connect-Info}', '', '0',
'0', '%{Called-Station-Id}',
'%{Calling-Station-Id}', '',
'%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}',
'%{%{Acct-Delay-Time}:-0}',
'0', '%{X-Ascend-Session-Svr-Key}')"</div><div>
accounting_start_query_alt = "
UPDATE radacct SET
acctstarttime = '%S',
acctstartdelay = '%{%{Acct-Delay-Time}:-0}',
connectinfo_start =
'%{Connect-Info}' WHERE acctsessionid
= '%{Acct-Session-Id}' AND username
= '%{SQL-User-Name}'
AND nasipaddress = '%{NAS-IP-Address}'"</div><div>
accounting_stop_query = "
UPDATE radacct SET
acctstoptime = '%S',
acctsessiontime =
'%{Acct-Session-Time}',
acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}'
<< 32 |
'%{%{Acct-Input-Octets}:-0}',
acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32
|
'%{%{Acct-Output-Octets}:-0}',
acctterminatecause = '%{Acct-Terminate-Cause}',
acctstopdelay =
'%{%{Acct-Delay-Time}:-0}',
connectinfo_stop = '%{Connect-Info}'
WH
ERE acctsessionid = '%{Acct-Session-Id}'
AND username = '%{SQL-User-Name}'
AND nasipaddress =
'%{NAS-IP-Address}'"</div><div>
accounting_stop_query_alt = "
INSERT INTO radacct
(acctsessionid, acctuniqueid, username,
realm, nasipaddress, nasportid,
nasporttype, acctstarttime, acctstoptime,
acctsessiontime, acctauthentic,
connectinfo_start,
connectinfo_stop, acctinputoctets, acctoutputoctets,
calledstationid, callingstationid,
acctterminatecause,
servicetype, framedprotocol, framedipaddress,
acctstartdelay, acctstopdelay)
VALUES
('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}',
'%{SQL-User-Name}',
'%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port}',
'%{NAS-Port-Type}',
DATE_SUB('%S',
INTERVAL (%{%{Acct-Session-Time}:-0} +
%{%{Acct-Delay-Time}:-0}) SECOND),
'%S', '%{Acct-Session-Time}', '%{Acct-Authentic}', '',
'%{Connect-Info}',
'%{%{Acct-Input-Gigawords}:-0}' <<
32 |
'%{%{Acct-Input-Octets}:-0}',
'%{%{Acct-Output-Gigawords}:-0}' << 32 |
'%{%{Acct-Output-Octets}:-0}',
'%{Called-Station-Id}',
'%{Calling-Station-Id}',
'%{Acct-Terminate-Cause}',
'%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}',
'0',
'%{%{Acct-Delay-Time}:-0}')"</div><div>
group_membership_query = "SELECT groupname
FROM radusergroup WHERE username =
'%{SQL-User-Name}' ORDER BY
priority"</div><div>
connect_failure_retry_delay = 60</div><div>
simul_count_query = ""</div><div>
simul_verify_query = "SELECT radacctid, acctsessionid, username,
nasipaddress, nasportid, framedipaddress,
callingstationid, framedprotocol
FROM radacct
WHERE username = '%{SQL-User-Name}'
AND acctstoptime IS NULL"</div><div>
postauth_query = "INSERT INTO radpostauth
(username,
pass, reply, authdate)
&nb
sp; VALUES (
'%{User-Name}',
'%{%{User-Password}:-%{Chap-Password}}',
'%{reply:Packet-Type}', '%S')"</div><div>
safe-characters =
"@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"</div>
<div> }</div><div>rlm_sql (sql): Driver rlm_sql_mysql (module
rlm_sql_mysql) loaded and linked</div><div>rlm_sql (sql): Attempting to
connect to root@localhost:/radius</div><div>rlm_sql (sql): starting 0</div>
<div>rlm_sql (sql): Attempting to connect rlm_sql_mysql #0</div><div>
rlm_sql_mysql: Starting connect to MySQL server for #0</div><div>rlm_sql
(sql): Connected new DB handle, #0</div><div>rlm_sql (sql): starting 1</div>
<div>rlm_sql (sql): Attempting to connect rlm_sql_mysql #1</div><div>
rlm_sql_mysql: Starting connect to MySQL server for #1</div><div>rlm_sql
(sql): Connected new DB handle, #1</div><div>rlm_sql (sql): starting 2</div>
<div>rlm_sql (sql): Attempting to connect rlm_sql_mysql #2</div><div>
rlm_sql_mysql: Starting connect to MySQL server for #2</div><div>rlm_sql
(sql): Connected new DB handle, #2</div><div>rlm_sql (sql): starting 3</div>
<div>rlm_sql (sql): Attempting to connect rlm_sql_mysql #3</div><div>
rlm_sql_mysql: Starting connect to MySQL server for #3</div><div>rlm_sql
(sql): Connected new DB handle, #3</div><div>rlm_sql (sql): starting 4</div>
<div>rlm_sql (sql): Attempting to connect rlm_sql_mysql #4</div><div>
rlm_sql_mysql: Starting connect to MySQL server for #4</div><div>rlm_sql
(sql): Connected new DB handle, #4</div><div> Module: Checking preacct
{...} for more modules to load</div><div> Module: Linked to module
rlm_acct_unique</div><div> Module: Instantiating module "acct_unique"
from file /etc/raddb/modules/acct_unique</div><div> acct_unique
{</div><div> key = "User-Name,
Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port"</div><div>
}</div><div> Module: Checking accounting {...} for more
modules to load</div><div> Module: Linked to module rlm_detail</div>
<div> Module: Instantiating module "detail" from file
/etc/raddb/modules/detail</div><div> detail {</div><div>
detailfile =
"/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d"</div><div>
header = "%t"</div><div>
detailperm = 384</div><div>
dirperm = 493</div><div> locking =
no</div><div> log_packet_header = no</div>
<div> }</div><div> Module: Instantiating module
"attr_filter.accounting_response" from file
/etc/raddb/modules/attr_filter</div><div> attr_filter
attr_filter.accounting_response {</div><div>
attrsfile = "/etc/raddb/attrs.accounting_response"</div><div>
key = "%{User-Name}"</div><div>
}</div><div> Module: Checking session {...} for more
modules to load</div><div> Module: Checking post-proxy {...} for more
modules to load</div><div> Module: Checking post-auth {...} for more
modules to load</div><div> } # modules</div><div>} # server</div><div>
radiusd: #### Opening IP addresses and Ports ####</div><div>listen {</div>
<div> type = "auth"</div><div>
ipaddr = *</div><div>
port = 0</div><div>}</div><div>listen {</div><div>
type = "acct"</div><div> ipaddr
= *</div><div> port = 0</div><div>}</div>
<div>listen {</div><div> type =
"control"</div><div>
;listen {</div><div> socket =
"/var/run/radiusd/radiusd.sock"</div><div> }</div><div>}</div><div>
listen {</div><div> type = "auth"</div><div>
ipaddr = 127.0.0.1</div><div>
port = 18120</div><div>}</div><div>Listening on
authentication address * port 1812</div><div>Listening on accounting address
* port 1813</div><div>Listening on command file
/var/run/radiusd/radiusd.sock</div><div>Listening on authentication address
127.0.0.1 port 18120 as server inner-tunnel</div><div>Listening on proxy
address * port 1814</div><div>Ready to process requests.</div><div>rad_recv:
Access-Request packet from host xxx.xxx.xxx.xxx port 51738,
id=152, length=206</div><div>
Acct-Multi-Session-Id = "1291302052682"</div><div>
Cisco-Attr-130 =
0x683332332d63616c6c696e672d656e74657270726973652d69643d656e74504258</div>
<div> Calling-Station-Id = "81609000"</div>
<div> NAS-Identifier = "intraswitch"</div>
<div> NAS-IP-Address = 212.13.228.58</div>
<div> 3GPP2-Prepaid-acct-Capability =
0x010600000002</div><div>
3GPP2-Session-Termination-Capability = 1</div><div>
h323-conf-id = "h323-conf-id=1291302052682"</div><div>
Vendor-Specific = 0x00000009</div><div>
Event-Timestamp = "Dec 2 2010
16:00:52 CET"</div><div> User-Name =
"081609000"</div><div> User-Password =
"\205;m\353\177\275i\027\231\216\34158n\037\233"</div><div># Executing
section authorize from file /etc/raddb/sites-enabled/default</div><div>+-
entering group authorize {...}</div><div>++[preprocess] returns ok</div><div>
++[chap] returns noop</div><div>++[mschap] returns noop</div><div>++[digest]
returns noop</div><div>[sql] expand: %{User-Name} ->
081609000</div><div>[sql] sql_set_user escaped user --> '081609000'</div>
<div>rlm_sql (sql): Reserving sql socket id: 4</div><div>[sql]
expand: SELECT id, username, attribute, value, op
FROM radcheck WHERE
username = '%{SQL-User-Name}' ORDER BY id
-> SELECT id, username, attribute, value, op
FROM radcheck WHERE username =
'081609000' ORDER BY id</div><div>[sql]
User found in radcheck table</div><div>[sql] expand: SELECT id,
username, attribute, value, op FROM
radreply WHERE username =
'%{SQL-User-Name}' ORDER BY id ->
SELECT id, username, attribute, value, op
FROM radreply WHERE username =
'081609000' ORDER BY id</div><div>[sql]
expand: SELECT groupname FROM
radusergroup WHERE username =
'%{SQL-User-Name}' ORDER BY priority
-> SELECT groupname FROM radusergroup
WHERE username = '081609000'
ORDER BY priority</div><div>[sql] expand:
SELECT id, groupname, attribute, Value,
op FROM radgroupcheck
WHERE groupname = '%{Sql-Group}'
ORDER BY id -> SELECT id, groupname, attribute,
Value, op
FROM radgroupcheck WHERE groupname = 's
tatic' ORDER BY id</div><div>[sql] User
found in group static</div><div>[sql] expand: SELECT id, groupname,
attribute, value, op
FROM radgroupreply WHERE
groupname = '%{Sql-Group}' ORDER BY id
-> SELECT id, groupname, attribute,
value, op FROM radgroupreply
WHERE groupname = 'static'
ORDER BY id</div><div>rlm_sql (sql): Released sql socket id:
4</div><div>++[sql] returns ok</div><div>[suffix] No '@' in User-Name =
"081609000", looking up realm NULL</div><div>[suffix] No such realm
"NULL"</div><div>++[suffix] returns noop</div><div>[eap] No EAP-Message, not
doing EAP</div><div>++[eap] returns noop</div><div>++[unix] returns
notfound</div><div>[sql] expand: %{User-Name} -> 081609000</div>
<div>[sql] sql_set_user escaped user --> '081609000'</div><div>rlm_sql
(sql): Reserving sql socket id: 3</div><div>[sql] expand: SELECT id,
username, attribute, value, op FROM
radcheck WHERE username =
'%{SQL-User-Name}' ORDER BY id ->
SELECT id, username, attribute, value, op
FROM radcheck WHERE username =
'081609000' ORDER BY id</div><div>[sql]
User found in radcheck table</div><div>[sql] expand: SELECT id,
username, attribute, value, op FROM
radreply WHERE username =
'%{SQL-User-Name}' ORDER BY id ->
SELECT id, username, attribute, value, op
FROM radreply WHERE username =
'081609000' ORDER BY id</div><div>[sql]
expand: SELECT groupname FROM
radusergroup WHERE username =
'%{SQL-User-Name}' ORDER BY priority
-> SELECT groupname FROM radusergroup
WHERE username = '081609000'
ORDER BY priority</div><div>[sql] expand:
SELECT id, groupname, attribute, Value,
op FROM radgroupcheck
WHERE groupname = '%{Sql-Group}'
ORDER BY id -> SELECT id, groupname, attribute,
Value, op
FROM radgroupcheck WHERE groupname =
'static' ORDER BY id</div><div>[sql] User
found in group static</div><div>[sql] expand: SELECT id, groupname,
attribute, value, op
FROM radgroupreply WHERE
groupname = '%{Sql-Group}' ORDER BY id
-> SELECT id, groupname, attribute,
value, op FROM radgroupreply
WHERE groupname = 'static'
ORDER BY id</div><div>rlm_sql (sql): Released sql socket id:
3</div><div>++[sql] returns ok</div><div>++[expiration] returns noop</div>
<div>++[logintime] returns noop</div><div>++[pap] returns updated</div><div>
Found Auth-Type = PAP</div><div># Executing group from file
/etc/raddb/sites-enabled/default</div><div>+- entering group PAP {...}</div>
<div>[pap] login attempt with password "?;më˝i???á58n??"</div><div>[pap]
Using CRYPT password "1234"</div><div>[pap] Passwords don't match</div><div>
++[pap] returns re
ject</div><div>Failed to authenticate the user.</div><div>
WARNING: Unprintable characters in the password.
Double-check the shared secret on the server and the NAS!</div>
<div>Using Post-Auth-Type Reject</div><div># Executing group from file
/etc/raddb/sites-enabled/default</div><div>+- entering group REJECT
{...}</div><div>[attr_filter.access_reject] expand:
%{User-Name} -> 081609000</div><div> attr_filter: Matched entry
DEFAULT at line 11</div><div>++[attr_filter.access_reject] returns
updated</div><div>Delaying reject of request 0 for 1 seconds</div><div>Going
to the next request</div><div>Waking up in 0.9 seconds.</div><div>Sending
delayed reject for request 0</div><div>Sending Access-Reject of id 152 to
xxx.xxx.xxx.xxx 8 port 51738</div><div>Waking up in 4.9 seconds.</div><div>
rad_recv: Access-Request packet from
host xxx.xxx.xxx.xxx port 51738, id=152, length=206</div>
<div>Sending duplicate reply to client intraswitch port 51738 - ID: 152</div>
<div>Sending Access-Reject of id 152 to xxx.xxx.xxx.xxx port
51738</div><div>Waking up in 4.9 seconds.</div><div>Cleaning up request 0 ID
152 with timestamp +15</div><div>Ready to process requests.</div></div><div>
<br></div><div><br></div><div>Please help me!</div><div><br></div><div>
Thanks!</div>
</blockquote>
</HTML>