Hi Stefan,<br><br>Sorry for the confusion, actullay i have checked both secret on both NAS and server sides, it is same.<br>below is debug output, the confusion pasword "Q?²Êà ëê¢p?¤F?+Õa" is very suspecious, it should be '1111' that i configure in database.<br>
maybe i check the wrong conf files for secrect, below is files that i checked. is it correct?<br>NAS:<br> usr/local/etc/radiusclient/<div class="im">servers<br> localhost/localhost testing123<br>
<br> Server:<br>
/usr/local/etc/raddb/clients.conf<br>
secret = testing123</div><br><br>debug output:<br><br>Found Auth-Type = PAP
<br>
# Executing group from file /usr/local/etc/raddb/sites-enabled/default
<br>
+- entering group PAP {...}
<br>
[pap] login attempt with password "Q?²Êà ëê¢p?¤F?+Õa"
<br>
[pap] Using clear text password "1111"
<br>
[pap] Passwords don't match
<br>
<div style="background-color: #ff3333">++[pap] returns reject
</div>Failed to authenticate the user.
<br>
<div style="background-color: yellow"> WARNING: Unprintable characters in the password. Double-check the shared secret on the server and the NAS!
</div><div style="background-color: #ff3333">Using Post-Auth-Type Reject
</div># Executing group from file /usr/local/etc/raddb/sites-enabled/default
<br>
<div style="background-color: #ff3333">+- entering group REJECT {...}
</div><div style="background-color: #ff3333">[attr_filter.access_reject] expand: %{User-Name} -> 1001
</div> attr_filter: Matched entry DEFAULT at line 11
<br>
<div style="background-color: #ff3333">++[attr_filter.access_reject] returns updated
</div><div style="background-color: #ff3333">Delaying reject of request 38 for 1 seconds
</div><br><br>Regards,<br>Charles<br><br><div class="gmail_quote">2011/8/5 Stefan Winter <span dir="ltr"><<a href="mailto:stefan.winter@restena.lu">stefan.winter@restena.lu</a>></span><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
Hello,<br>
<br>
while you marked lots of stuff in yellow, you missed the REALLY helpful<br>
part:<br>
<div class="im"><br>
"WARNING: Unprintable characters in the password. Double-check<br>
the shared secret on the server and the NAS!"<br>
<br>
</div>How about doing exactly that...?<br>
<br>
Stefan Winter<br>
<br>
<br>
Am 05.08.2011 06:14, schrieb fieldpeak:<br>
<div class="im">> Hello Friends,<br>
><br>
> I met a issue regarding password/authentication with FreeRadius, Could<br>
> anybody help for the issue, Thanks!<br>
><br>
> User-Password = "?\210\365@\263\t\306\343\243iT?\311C\t\002"<br>
><br>
> [pap] WARNING! No "known good" password found for the user.<br>
> Authentication may fail because of this.<br>
> ++[pap] returns noop<br>
> ERROR: No authenticate method (Auth-Type) found for the request:<br>
> Rejecting the user<br>
><br>
> The details in below mails.<br>
><br>
> Regards,<br>
> Charles<br>
><br>
> Forwarded conversation<br>
> Subject: *Authentication failure issue*<br>
> ------------------------<br>
><br>
</div>> From: *fieldpeak* <<a href="mailto:fieldpeak@gmail.com">fieldpeak@gmail.com</a> <mailto:<a href="mailto:fieldpeak@gmail.com">fieldpeak@gmail.com</a>>><br>
<div class="im">> Date: 2011/8/4<br>
> To: <a href="mailto:freeradius-users@lists.freeradius.org">freeradius-users@lists.freeradius.org</a><br>
</div>> <mailto:<a href="mailto:freeradius-users@lists.freeradius.org">freeradius-users@lists.freeradius.org</a>><br>
<div class="im">><br>
><br>
> Dear Friends,<br>
><br>
> I'm trying integrate Freeswitch with Freeradius, I met below issue,<br>
> can anyone help, thanks in adance.<br>
><br>
> Freeradius server log:<br>
><br>
> rad_recv: Access-Request packet from host 127.0.0.1 port 52684, id=49,<br>
> length=111<br>
> User-Name = "1001"<br>
> User-Password = "?\210\365@\263\t\306\343\243iT?\311C\t\002"<br>
> Called-Station-Id = "888"<br>
> h323-conf-id = "749d2b5a-16ad-48e4-af58-<br>
> 24011949d1b5"<br>
> Calling-Station-Id = "1001"<br>
> NAS-Port = 0<br>
> NAS-IP-Address = 127.0.0.1<br>
> # Executing section authorize from file<br>
> /usr/local/etc/raddb/sites-enabled/default<br>
> +- entering group authorize {...}<br>
> ++[preprocess] returns ok<br>
> [auth_log] expand:<br>
> /usr/local/var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d<br>
> -> /usr/local/var/log/radius/radacct/<a href="http://127.0.0.1/auth-detail-20110803" target="_blank">127.0.0.1/auth-detail-20110803</a><br>
</div>> <<a href="http://127.0.0.1/auth-detail-20110803" target="_blank">http://127.0.0.1/auth-detail-20110803</a>><br>
<div class="im">> [auth_log]<br>
> /usr/local/var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d<br>
> expands to<br>
> /usr/local/var/log/radius/radacct/<a href="http://127.0.0.1/auth-detail-20110803" target="_blank">127.0.0.1/auth-detail-20110803</a><br>
</div>> <<a href="http://127.0.0.1/auth-detail-20110803" target="_blank">http://127.0.0.1/auth-detail-20110803</a>><br>
<div><div></div><div class="h5">> [auth_log] expand: %t -> Wed Aug 3 12:06:33 2011<br>
> ++[auth_log] returns ok<br>
> ++[chap] returns noop<br>
> ++[mschap] returns noop<br>
> ++[digest] returns noop<br>
> [suffix] No '@' in User-Name = "1001", looking up realm NULL<br>
> [suffix] No such realm "NULL"<br>
> ++[suffix] returns noop<br>
> [eap] No EAP-Message, not doing EAP<br>
> ++[eap] returns noop<br>
> ++[unix] returns notfound<br>
> ++[files] returns noop<br>
> [sql] expand: %{User-Name} -> 1001<br>
> [sql] sql_set_user escaped user --> '1001'<br>
> rlm_sql (sql): Reserving sql socket id: 4<br>
> [sql] expand: SELECT id, username, attribute, value, op<br>
> FROM radcheck WHERE username = '%{SQL-User-Name}'<br>
> ORDER BY id -> SELECT id, username, attribute, value, op<br>
> FROM radcheck WHERE username = '1001' ORDER BY id<br>
> [sql] expand: SELECT groupname FROM radusergroup<br>
> WHERE username = '%{SQL-User-Name}' ORDER BY priority -><br>
> SELECT groupname FROM radusergroup WHERE username<br>
> = '1001' ORDER BY priority<br>
> rlm_sql (sql): Released sql socket id: 4<br>
> [sql] User 1001 not found<br>
> ++[sql] returns notfound<br>
> ++[expiration] returns noop<br>
> ++[logintime] returns noop<br>
> [pap] WARNING! No "known good" password found for the user.<br>
> Authentication may fail because of this.<br>
> ++[pap] returns noop<br>
> ERROR: No authenticate method (Auth-Type) found for the request:<br>
> Rejecting the user<br>
> Failed to authenticate the user.<br>
> WARNING: Unprintable characters in the password. Double-check<br>
> the shared secret on the server and the NAS!<br>
> Using Post-Auth-Type Reject<br>
> # Executing group from file /usr/local/etc/raddb/sites-enabled/default<br>
> +- entering group REJECT {...}<br>
> [attr_filter.access_reject] expand: %{User-Name} -> 1001<br>
> attr_filter: Matched entry DEFAULT at line 11<br>
> ++[attr_filter.access_reject] returns updated<br>
> Delaying reject of request 8 for 1 seconds<br>
> Going to the next request<br>
> Waking up in 0.9 seconds.<br>
> Sending delayed reject for request 8<br>
> Sending Access-Reject of id 49 to 127.0.0.1 port 52684<br>
> Waking up in 4.9 seconds.<br>
> Cleaning up request 8 ID 49 with timestamp +7674<br>
> Ready to process requests.<br>
> WARNING! No "known good" password found for the user<br>
><br>
> Regards,<br>
> Charles<br>
><br>
> ----------<br>
</div></div>> From: *fieldpeak* <<a href="mailto:fieldpeak@gmail.com">fieldpeak@gmail.com</a> <mailto:<a href="mailto:fieldpeak@gmail.com">fieldpeak@gmail.com</a>>><br>
<div class="im">> Date: 2011/8/4<br>
> To: <a href="mailto:freeradius-users@lists.freeradius.org">freeradius-users@lists.freeradius.org</a><br>
</div>> <mailto:<a href="mailto:freeradius-users@lists.freeradius.org">freeradius-users@lists.freeradius.org</a>><br>
<div class="im">><br>
><br>
> Hello Gurus,<br>
><br>
> I've double checked the shared secret on both server and NAS are the<br>
> same, the problem still exist, it trouble me a few days, can anyone<br>
> kindly help?<br>
><br>
> nas:<br>
> /usr/local/etc/radiusclient/servers<br>
> localhost/localhost testing123<br>
><br>
> server:<br>
> /usr/local/etc/raddb/clients.conf<br>
> secret = testing123<br>
><br>
><br>
><br>
</div>> -<br>
> List info/subscribe/unsubscribe? See <a href="http://www.freeradius.org/list/users.html" target="_blank">http://www.freeradius.org/list/users.html</a><br>
<br>
<br>
--<br>
Stefan WINTER<br>
Ingenieur de Recherche<br>
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche<br>
6, rue Richard Coudenhove-Kalergi<br>
L-1359 Luxembourg<br>
<br>
Tel: +352 424409 1<br>
Fax: +352 422473<br>
<br>
<br>
<br>-<br>
List info/subscribe/unsubscribe? See <a href="http://www.freeradius.org/list/users.html" target="_blank">http://www.freeradius.org/list/users.html</a><br></blockquote></div><br>