Reading configuration file 'eapol_test.conf' ctrl_interface='/var/run/wpa_supplicant' eapol_version=1 ap_scan=1 fast_reauth=1 Line: 940 - start of a new network block ssid - hexdump_ascii(len=7): 65 64 75 72 6f 61 6d eduroam key_mgmt: 0x1 eap methods - hexdump(len=16): 00 00 00 00 19 00 00 00 00 00 00 00 00 00 00 00 identity - hexdump_ascii(len=30): 33 30 30 2d 31 34 35 2d 33 35 34 40 77 69 72 65 300-145-354@wire 6c 65 73 73 2e 63 61 6d 2e 61 63 2e 75 6b less.cam.ac.uk anonymous_identity - hexdump_ascii(len=10): 40 63 61 6d 2e 61 63 2e 75 6b @cam.ac.uk password - hexdump_ascii(len=8): 61 34 62 75 6d 69 70 33 a4bumip3 ca_cert - hexdump_ascii(len=61): 2f 75 73 72 2f 73 68 61 72 65 2f 63 61 2d 63 65 /usr/share/ca-ce 72 74 69 66 69 63 61 74 65 73 2f 6d 6f 7a 69 6c rtificates/mozil 6c 61 2f 41 64 64 54 72 75 73 74 5f 45 78 74 65 la/AddTrust_Exte 72 6e 61 6c 5f 52 6f 6f 74 2e 63 72 74 rnal_Root.crt phase1 - hexdump_ascii(len=11): 70 65 61 70 6c 61 62 65 6c 3d 31 peaplabel=1 phase2 - hexdump_ascii(len=16): 61 75 74 68 65 61 70 3d 4d 53 43 48 41 50 56 32 autheap=MSCHAPV2 Priority group 0 id=0 ssid='eduroam' Authentication server 131.111.8.231:1812 RADIUS local address: 193.60.89.41:43693 EAPOL: SUPP_PAE entering state DISCONNECTED EAPOL: KEY_RX entering state NO_KEY_RECEIVE EAPOL: SUPP_BE entering state INITIALIZE EAP: EAP entering state DISABLED EAPOL: External notification - portValid=0 EAPOL: External notification - portEnabled=1 EAPOL: SUPP_PAE entering state CONNECTING EAPOL: SUPP_BE entering state IDLE EAP: EAP entering state INITIALIZE EAP: EAP entering state IDLE Sending fake EAP-Request-Identity EAPOL: Received EAP-Packet frame EAPOL: SUPP_PAE entering state RESTART EAP: EAP entering state INITIALIZE EAP: EAP entering state IDLE EAPOL: SUPP_PAE entering state AUTHENTICATING EAPOL: SUPP_BE entering state REQUEST EAPOL: getSuppRsp EAP: EAP entering state RECEIVED EAP: Received EAP-Request id=0 method=1 vendor=0 vendorMethod=0 EAP: EAP entering state IDENTITY CTRL-EVENT-EAP-STARTED EAP authentication started EAP: Status notification: started (param=) EAP: EAP-Request Identity data - hexdump_ascii(len=0): EAP: using anonymous identity - hexdump_ascii(len=10): 40 63 61 6d 2e 61 63 2e 75 6b @cam.ac.uk EAP: EAP entering state SEND_RESPONSE EAP: EAP entering state IDLE EAPOL: SUPP_BE entering state RESPONSE EAPOL: txSuppRsp WPA: eapol_test_eapol_send(type=0 len=15) TX EAP -> RADIUS - hexdump(len=15): 02 00 00 0f 01 40 63 61 6d 2e 61 63 2e 75 6b Encapsulating EAP message into a RADIUS packet Learned identity from EAP-Response-Identity - hexdump(len=10): 40 63 61 6d 2e 61 63 2e 75 6b Sending RADIUS message to authentication server RADIUS message: code=1 (Access-Request) identifier=0 length=128 Attribute 1 (User-Name) length=12 Value: '@cam.ac.uk' Attribute 4 (NAS-IP-Address) length=6 Value: 127.0.0.1 Attribute 31 (Calling-Station-Id) length=19 Value: '02-00-00-00-00-01' Attribute 12 (Framed-MTU) length=6 Value: 1400 Attribute 61 (NAS-Port-Type) length=6 Value: 19 Attribute 77 (Connect-Info) length=24 Value: 'CONNECT 11Mbps 802.11b' Attribute 79 (EAP-Message) length=17 Value: 02 00 00 0f 01 40 63 61 6d 2e 61 63 2e 75 6b Attribute 80 (Message-Authenticator) length=18 Value: e9 c3 fb 16 e4 02 b3 29 7e e0 d0 c6 2e be bf 3e Next RADIUS client retransmit in 3 seconds EAPOL: SUPP_BE entering state RECEIVE Received 64 bytes from RADIUS server Received RADIUS message RADIUS message: code=11 (Access-Challenge) identifier=0 length=64 Attribute 79 (EAP-Message) length=8 Value: 01 01 00 06 19 20 Attribute 80 (Message-Authenticator) length=18 Value: 18 ce 51 ae 74 8b f1 8b 5d e1 5f ff bb bd fb d9 Attribute 24 (State) length=18 Value: 1c d6 e6 61 1c d7 ff 6c f3 74 51 3f 67 d5 3b 27 STA 02:00:00:00:00:01: Received RADIUS packet matched with a pending request, round trip time 0.00 sec RADIUS packet matching with station decapsulated EAP packet (code=1 id=1 len=6) from RADIUS server: EAP-Request-PEAP (25) EAPOL: Received EAP-Packet frame EAPOL: SUPP_BE entering state REQUEST EAPOL: getSuppRsp EAP: EAP entering state RECEIVED EAP: Received EAP-Request id=1 method=25 vendor=0 vendorMethod=0 EAP: EAP entering state GET_METHOD CTRL-EVENT-EAP-PROPOSED-METHOD vendor=0 method=25 EAP: Status notification: accept proposed method (param=PEAP) EAP: Initialize selected EAP method: vendor 0 method 25 (PEAP) EAP-PEAP: Force new label for key derivation TLS: Phase2 EAP types - hexdump(len=40): 00 00 00 00 04 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 11 00 00 00 TLS: using phase1 config options TLS: Trusted root certificate(s) loaded CTRL-EVENT-EAP-METHOD EAP vendor 0 method 25 (PEAP) selected EAP: EAP entering state METHOD SSL: Received packet(len=6) - Flags 0x20 EAP-PEAP: Start (server ver=0, own ver=1) EAP-PEAP: Using PEAP version 0 SSL: (where=0x10 ret=0x1) SSL: (where=0x1001 ret=0x1) SSL: SSL_connect:before/connect initialization SSL: (where=0x1001 ret=0x1) SSL: SSL_connect:SSLv3 write client hello A SSL: (where=0x1002 ret=0xffffffff) SSL: SSL_connect:error in SSLv3 read server hello A SSL: SSL_connect - want more data SSL: 221 bytes pending from ssl_out SSL: 221 bytes left to be sent out (of total 221 bytes) EAP: method process -> ignore=FALSE methodState=MAY_CONT decision=FAIL eapRespData=0x90dd880 EAP: EAP entering state SEND_RESPONSE EAP: EAP entering state IDLE EAPOL: SUPP_BE entering state RESPONSE EAPOL: txSuppRsp WPA: eapol_test_eapol_send(type=0 len=231) TX EAP -> RADIUS - hexdump(len=231): 02 01 00 e7 19 80 00 00 00 dd 16 03 01 00 d8 01 00 00 d4 03 01 53 8c ce 0c ab bd 07 a3 e5 21 dc f5 bc 5a a8 fd 21 0f 4d 72 d5 82 5c ec d4 89 a3 4f ef dc 05 00 00 00 66 c0 14 c0 0a c0 22 c0 21 00 39 00 38 00 88 00 87 c0 0f c0 05 00 35 00 84 c0 12 c0 08 c0 1c c0 1b 00 16 00 13 c0 0d c0 03 00 0a c0 13 c0 09 c0 1f c0 1e 00 33 00 32 00 9a 00 99 00 45 00 44 c0 0e c0 04 00 2f 00 96 00 41 c0 11 c0 07 c0 0c c0 02 00 05 00 04 00 15 00 12 00 09 00 14 00 11 00 08 00 06 00 03 00 ff 01 00 00 45 00 0b 00 04 03 00 01 02 00 0a 00 34 00 32 00 0e 00 0d 00 19 00 0b 00 0c 00 18 00 09 00 0a 00 16 00 17 00 08 00 06 00 07 00 14 00 15 00 04 00 05 00 12 00 13 00 01 00 02 00 03 00 0f 00 10 00 11 00 0f 00 01 01 Encapsulating EAP message into a RADIUS packet Copied RADIUS State Attribute Sending RADIUS message to authentication server RADIUS message: code=1 (Access-Request) identifier=1 length=362 Attribute 1 (User-Name) length=12 Value: '@cam.ac.uk' Attribute 4 (NAS-IP-Address) length=6 Value: 127.0.0.1 Attribute 31 (Calling-Station-Id) length=19 Value: '02-00-00-00-00-01' Attribute 12 (Framed-MTU) length=6 Value: 1400 Attribute 61 (NAS-Port-Type) length=6 Value: 19 Attribute 77 (Connect-Info) length=24 Value: 'CONNECT 11Mbps 802.11b' Attribute 79 (EAP-Message) length=233 Value: 02 01 00 e7 19 80 00 00 00 dd 16 03 01 00 d8 01 00 00 d4 03 01 53 8c ce 0c ab bd 07 a3 e5 21 dc f5 bc 5a a8 fd 21 0f 4d 72 d5 82 5c ec d4 89 a3 4f ef dc 05 00 00 00 66 c0 14 c0 0a c0 22 c0 21 00 39 00 38 00 88 00 87 c0 0f c0 05 00 35 00 84 c0 12 c0 08 c0 1c c0 1b 00 16 00 13 c0 0d c0 03 00 0a c0 13 c0 09 c0 1f c0 1e 00 33 00 32 00 9a 00 99 00 45 00 44 c0 0e c0 04 00 2f 00 96 00 41 c0 11 c0 07 c0 0c c0 02 00 05 00 04 00 15 00 12 00 09 00 14 00 11 00 08 00 06 00 03 00 ff 01 00 00 45 00 0b 00 04 03 00 01 02 00 0a 00 34 00 32 00 0e 00 0d 00 19 00 0b 00 0c 00 18 00 09 00 0a 00 16 00 17 00 08 00 06 00 07 00 14 00 15 00 04 00 05 00 12 00 13 00 01 00 02 00 03 00 0f 00 10 00 11 00 0f 00 01 01 Attribute 24 (State) length=18 Value: 1c d6 e6 61 1c d7 ff 6c f3 74 51 3f 67 d5 3b 27 Attribute 80 (Message-Authenticator) length=18 Value: 1b fe e7 9b 6f 0e 69 7c 93 5c a9 7c f2 4a b1 44 Next RADIUS client retransmit in 3 seconds EAPOL: SUPP_BE entering state RECEIVE Received 1090 bytes from RADIUS server Received RADIUS message RADIUS message: code=11 (Access-Challenge) identifier=1 length=1090 Attribute 79 (EAP-Message) length=255 Value: 01 02 04 00 19 c0 00 00 0f 58 16 03 01 00 31 02 00 00 2d 03 01 53 8c ce 0c 95 d4 05 3d d6 ed 3f 0a a0 8a e2 56 2a 3b a2 02 a2 ba 01 7e 22 5d 25 32 19 6e 4b 32 00 c0 14 00 00 05 ff 01 00 01 00 16 03 01 0d c4 0b 00 0d c0 00 0d bd 00 04 d8 30 82 04 d4 30 82 03 bc a0 03 02 01 02 02 10 6d 8d 87 77 66 fc 2b 6c 8e d6 22 40 1b d4 a9 7e 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 30 36 31 0b 30 09 06 03 55 04 06 13 02 4e 4c 31 0f 30 0d 06 03 55 04 0a 13 06 54 45 52 45 4e 41 31 16 30 14 06 03 55 04 03 13 0d 54 45 52 45 4e 41 20 53 53 4c 20 43 41 30 1e 17 0d 31 33 30 31 31 38 30 30 30 30 30 30 5a 17 0d 31 36 30 31 31 38 32 33 35 39 35 39 5a 30 81 98 31 0b 30 09 06 03 55 04 06 13 02 47 42 31 10 30 0e 06 03 55 04 08 13 07 45 6e 67 6c 61 6e 64 31 12 30 10 06 03 Attribute 79 (EAP-Message) length=255 Value: 55 04 07 13 09 43 61 6d 62 72 69 64 67 65 31 20 30 1e 06 03 55 04 0a 13 17 55 6e 69 76 65 72 73 69 74 79 20 6f 66 20 43 61 6d 62 72 69 64 67 65 31 1a 30 18 06 03 55 04 0b 13 11 43 6f 6d 70 75 74 69 6e 67 20 53 65 72 76 69 63 65 31 25 30 23 06 03 55 04 03 13 1c 6e 65 74 77 6f 72 6b 2e 74 6f 6b 65 6e 73 2e 63 73 78 2e 63 61 6d 2e 61 63 2e 75 6b 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 e3 5b 2a ec 53 55 d2 88 b2 b2 53 c4 70 43 3a b5 73 de 61 ea 8b 3f 91 15 48 4c 5e 75 56 59 36 69 cc 26 76 93 40 ff c2 9d 27 13 d2 31 e2 1a 79 49 c9 de b2 c3 18 46 7b 80 9e cc d2 38 ee d0 97 24 dd 92 60 81 3e af 29 a3 fc 40 b8 dc 79 b8 fc 75 30 08 cd a9 cb 29 31 f9 d7 a3 9f 41 0f 6c 40 aa 6c 19 37 b7 30 b6 22 4c 4f Attribute 79 (EAP-Message) length=255 Value: d9 19 d0 6e 9c d7 b0 c5 59 ec aa c3 e2 52 1e 6a 5c 65 0b d2 25 87 fc 04 1d 41 ba 16 6e 7e 37 32 da 30 39 db b1 c1 c8 aa d8 73 84 87 72 e5 72 42 14 33 07 22 34 18 7f c0 df e3 b3 7d 1c 30 8e 69 62 4a d2 6d 84 1d fa 17 78 37 b6 b4 34 f2 33 e0 cf 04 58 64 a0 71 d4 a9 ee 91 7e e0 26 3c 8a 72 fe bf a0 9b ea 39 71 7f 79 07 d8 6b 0d b9 e6 7d f0 b3 c7 dc c0 9f f5 d5 94 c4 5a ed a2 ac f3 e7 bf e5 26 2a ca 6e 9c 8e a1 fe 5e 80 fe b3 89 8b c7 1a 91 8d 07 3b 99 02 03 01 00 01 a3 82 01 79 30 82 01 75 30 1f 06 03 55 1d 23 04 18 30 16 80 14 0c bd 93 68 0c f3 de ab a3 49 6b 2b 37 57 47 ea 90 e3 b9 ed 30 1d 06 03 55 1d 0e 04 16 04 14 94 52 5b a1 e3 00 e7 76 03 d7 47 ad 15 90 46 d3 0f c3 19 b3 30 0e 06 03 55 1d 0f 01 01 ff 04 04 03 02 05 a0 30 0c 06 03 55 1d 13 01 01 Attribute 79 (EAP-Message) length=255 Value: ff 04 02 30 00 30 1d 06 03 55 1d 25 04 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b 06 01 05 05 07 03 02 30 22 06 03 55 1d 20 04 1b 30 19 30 0d 06 0b 2b 06 01 04 01 b2 31 01 02 02 1d 30 08 06 06 67 81 0c 01 02 02 30 3a 06 03 55 1d 1f 04 33 30 31 30 2f a0 2d a0 2b 86 29 68 74 74 70 3a 2f 2f 63 72 6c 2e 74 63 73 2e 74 65 72 65 6e 61 2e 6f 72 67 2f 54 45 52 45 4e 41 53 53 4c 43 41 2e 63 72 6c 30 6d 06 08 2b 06 01 05 05 07 01 01 04 61 30 5f 30 35 06 08 2b 06 01 05 05 07 30 02 86 29 68 74 74 70 3a 2f 2f 63 72 74 2e 74 63 73 2e 74 65 72 65 6e 61 2e 6f 72 67 2f 54 45 52 45 4e 41 53 53 4c 43 41 2e 63 72 74 30 26 06 08 2b 06 01 05 05 07 30 01 86 1a 68 74 74 70 3a 2f 2f 6f 63 73 70 2e 74 63 73 2e 74 65 72 65 6e 61 2e 6f 72 67 30 27 06 03 55 1d 11 04 20 30 Attribute 79 (EAP-Message) length=14 Value: 1e 82 1c 6e 65 74 77 6f 72 6b 2e 74 Attribute 80 (Message-Authenticator) length=18 Value: 63 43 56 2d 26 af 7f b3 de 0b e7 71 2e 16 45 85 Attribute 24 (State) length=18 Value: 1c d6 e6 61 1d d4 ff 6c f3 74 51 3f 67 d5 3b 27 STA 02:00:00:00:00:01: Received RADIUS packet matched with a pending request, round trip time 0.00 sec RADIUS packet matching with station decapsulated EAP packet (code=1 id=2 len=1024) from RADIUS server: EAP-Request-PEAP (25) EAPOL: Received EAP-Packet frame EAPOL: SUPP_BE entering state REQUEST EAPOL: getSuppRsp EAP: EAP entering state RECEIVED EAP: Received EAP-Request id=2 method=25 vendor=0 vendorMethod=0 EAP: EAP entering state METHOD SSL: Received packet(len=1024) - Flags 0xc0 SSL: TLS Message Length: 3928 SSL: Need 2914 bytes more input data SSL: Building ACK (type=25 id=2 ver=0) EAP: method process -> ignore=FALSE methodState=MAY_CONT decision=FAIL eapRespData=0x90dc548 EAP: EAP entering state SEND_RESPONSE EAP: EAP entering state IDLE EAPOL: SUPP_BE entering state RESPONSE EAPOL: txSuppRsp WPA: eapol_test_eapol_send(type=0 len=6) TX EAP -> RADIUS - hexdump(len=6): 02 02 00 06 19 00 Encapsulating EAP message into a RADIUS packet Copied RADIUS State Attribute Sending RADIUS message to authentication server RADIUS message: code=1 (Access-Request) identifier=2 length=137 Attribute 1 (User-Name) length=12 Value: '@cam.ac.uk' Attribute 4 (NAS-IP-Address) length=6 Value: 127.0.0.1 Attribute 31 (Calling-Station-Id) length=19 Value: '02-00-00-00-00-01' Attribute 12 (Framed-MTU) length=6 Value: 1400 Attribute 61 (NAS-Port-Type) length=6 Value: 19 Attribute 77 (Connect-Info) length=24 Value: 'CONNECT 11Mbps 802.11b' Attribute 79 (EAP-Message) length=8 Value: 02 02 00 06 19 00 Attribute 24 (State) length=18 Value: 1c d6 e6 61 1d d4 ff 6c f3 74 51 3f 67 d5 3b 27 Attribute 80 (Message-Authenticator) length=18 Value: 7b ab ba b6 61 ca 88 01 10 19 82 a9 6f 6b f4 12 Next RADIUS client retransmit in 3 seconds EAPOL: SUPP_BE entering state RECEIVE Received 1086 bytes from RADIUS server Received RADIUS message RADIUS message: code=11 (Access-Challenge) identifier=2 length=1086 Attribute 79 (EAP-Message) length=255 Value: 01 03 03 fc 19 40 6f 6b 65 6e 73 2e 63 73 78 2e 63 61 6d 2e 61 63 2e 75 6b 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 82 01 01 00 7a b0 c3 21 2f bd bf a9 00 17 46 e9 a9 41 6f de 5c 91 38 7a e5 8a b2 77 e3 b9 75 03 9f cb f6 42 6b e2 4a 81 97 62 0c ac a3 a6 a6 e5 72 89 3a 35 2c af 95 26 2a 6d cf 77 d0 cc 5e 85 c7 55 96 81 73 e0 5b 46 2f 4c 67 e9 a9 74 70 69 26 33 de cc 37 ec 03 99 72 16 bd 8b ce 78 7a d8 5b d3 d8 39 42 ff 20 d2 3e 13 6a 36 f4 19 73 10 3b 23 1a af e5 53 44 5c 21 ed 6c 92 ac a9 ca 85 9a af 39 b6 af 85 14 13 1f 7a 0e a5 a8 e4 f7 1c 00 25 e0 ee 9c 7c 94 98 0f 27 3c 4b ef 9c 55 20 3e 02 9b 3c 54 c7 cd 62 fd fb 16 cc 30 45 aa ea cf c0 46 a3 4b 7c 93 c9 41 23 f8 fa 54 b3 92 08 dd ed a1 1e e2 22 8b 36 77 fc be 63 4e 76 64 b9 7b a1 be b6 Attribute 79 (EAP-Message) length=255 Value: ef 71 a4 a4 7d 61 f2 50 f3 ae 6a 6a c9 fb d0 e4 95 ae 15 e8 f3 f0 0f d1 66 11 c3 2b c3 d0 18 e3 0c a7 bd c2 f3 4a 06 70 74 6b 89 04 97 d7 18 24 00 04 9c 30 82 04 98 30 82 03 80 a0 03 02 01 02 02 10 4b c8 14 03 2f 07 fa 6a a4 f0 da 29 df 61 79 ba 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 30 81 97 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 0b 30 09 06 03 55 04 08 13 02 55 54 31 17 30 15 06 03 55 04 07 13 0e 53 61 6c 74 20 4c 61 6b 65 20 43 69 74 79 31 1e 30 1c 06 03 55 04 0a 13 15 54 68 65 20 55 53 45 52 54 52 55 53 54 20 4e 65 74 77 6f 72 6b 31 21 30 1f 06 03 55 04 0b 13 18 68 74 74 70 3a 2f 2f 77 77 77 2e 75 73 65 72 74 72 75 73 74 2e 63 6f 6d 31 1f 30 1d 06 03 55 04 03 13 16 55 54 4e 2d 55 53 45 52 46 69 72 73 74 2d 48 61 72 64 77 61 72 65 30 1e Attribute 79 (EAP-Message) length=255 Value: 17 0d 30 39 30 35 31 38 30 30 30 30 30 30 5a 17 0d 32 30 30 35 33 30 31 30 34 38 33 38 5a 30 36 31 0b 30 09 06 03 55 04 06 13 02 4e 4c 31 0f 30 0d 06 03 55 04 0a 13 06 54 45 52 45 4e 41 31 16 30 14 06 03 55 04 03 13 0d 54 45 52 45 4e 41 20 53 53 4c 20 43 41 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 c3 e3 48 c4 2f 5c c1 cb a9 99 fd 1b a2 83 5d 8a 3d ad 3a d0 e2 a4 43 1f 4d 0e fe 35 25 30 a5 69 1b c4 e8 e5 c1 8f 54 7e e1 6a a2 9a 5c 5c de 3d fc 02 ce 96 b8 5f 8f 83 5b cc 60 40 90 f8 e4 b6 3a 25 9c 5f 14 51 ec b1 e7 af 9e 50 a1 31 55 c7 02 bd ac 52 8a 7f 35 8e 82 fa 84 ad 15 fe a2 7f 83 10 3a 55 53 94 2c 01 16 74 94 54 63 28 a3 f2 5b 29 3d 94 88 80 20 e2 14 59 21 19 b4 a4 98 e1 60 e6 f2 eb a2 80 Attribute 79 (EAP-Message) length=255 Value: 83 43 e0 ad 68 f3 79 19 8b 68 43 51 3f 8a 9b 41 85 0c 35 8c 5d b5 f1 b6 e5 a7 c3 83 b5 6b 23 6f d4 a5 eb 50 e5 94 f1 4a 5f ee 27 4b 14 12 15 24 4c 0d cf 62 8d b7 00 21 ad 3a 32 0f 58 0b 5f 1e 9b d1 df 9d 8e a9 19 35 50 2f 41 a9 ad 3b c6 e0 45 b2 53 39 7f 21 bf 22 1a 87 5c 34 ae 52 6f 07 7d a2 0b 4e 9f 2b 79 a6 7d 13 dd f5 7f 83 7c 2f 5a 5d 77 78 78 91 a0 14 bf 7d 02 03 01 00 01 a3 82 01 3e 30 82 01 3a 30 1f 06 03 55 1d 23 04 18 30 16 80 14 a1 72 5f 26 1b 28 98 43 95 5d 07 37 d5 85 96 9d 4b d2 c3 45 30 1d 06 03 55 1d 0e 04 16 04 14 0c bd 93 68 0c f3 de ab a3 49 6b 2b 37 57 47 ea 90 e3 b9 ed 30 0e 06 03 55 1d 0f 01 01 ff 04 04 03 02 01 06 30 12 06 03 55 1d 13 01 01 ff 04 08 30 06 01 01 ff 02 01 00 30 18 06 03 55 1d 20 04 11 30 0f 30 0d 06 0b 2b 06 01 Attribute 79 (EAP-Message) length=10 Value: 04 01 b2 31 01 02 02 1d Attribute 80 (Message-Authenticator) length=18 Value: 2b 36 c6 72 8c f8 8e 99 95 49 60 8c 2a e1 f0 a1 Attribute 24 (State) length=18 Value: 1c d6 e6 61 1e d5 ff 6c f3 74 51 3f 67 d5 3b 27 STA 02:00:00:00:00:01: Received RADIUS packet matched with a pending request, round trip time 0.00 sec RADIUS packet matching with station decapsulated EAP packet (code=1 id=3 len=1020) from RADIUS server: EAP-Request-PEAP (25) EAPOL: Received EAP-Packet frame EAPOL: SUPP_BE entering state REQUEST EAPOL: getSuppRsp EAP: EAP entering state RECEIVED EAP: Received EAP-Request id=3 method=25 vendor=0 vendorMethod=0 EAP: EAP entering state METHOD SSL: Received packet(len=1020) - Flags 0x40 SSL: Need 1900 bytes more input data SSL: Building ACK (type=25 id=3 ver=0) EAP: method process -> ignore=FALSE methodState=MAY_CONT decision=FAIL eapRespData=0x90dc590 EAP: EAP entering state SEND_RESPONSE EAP: EAP entering state IDLE EAPOL: SUPP_BE entering state RESPONSE EAPOL: txSuppRsp WPA: eapol_test_eapol_send(type=0 len=6) TX EAP -> RADIUS - hexdump(len=6): 02 03 00 06 19 00 Encapsulating EAP message into a RADIUS packet Copied RADIUS State Attribute Sending RADIUS message to authentication server RADIUS message: code=1 (Access-Request) identifier=3 length=137 Attribute 1 (User-Name) length=12 Value: '@cam.ac.uk' Attribute 4 (NAS-IP-Address) length=6 Value: 127.0.0.1 Attribute 31 (Calling-Station-Id) length=19 Value: '02-00-00-00-00-01' Attribute 12 (Framed-MTU) length=6 Value: 1400 Attribute 61 (NAS-Port-Type) length=6 Value: 19 Attribute 77 (Connect-Info) length=24 Value: 'CONNECT 11Mbps 802.11b' Attribute 79 (EAP-Message) length=8 Value: 02 03 00 06 19 00 Attribute 24 (State) length=18 Value: 1c d6 e6 61 1e d5 ff 6c f3 74 51 3f 67 d5 3b 27 Attribute 80 (Message-Authenticator) length=18 Value: 65 61 68 a7 c0 fe 89 56 dc 43 ce c0 04 94 81 b5 Next RADIUS client retransmit in 3 seconds EAPOL: SUPP_BE entering state RECEIVE Received 1086 bytes from RADIUS server Received RADIUS message RADIUS message: code=11 (Access-Challenge) identifier=3 length=1086 Attribute 79 (EAP-Message) length=255 Value: 01 04 03 fc 19 40 30 44 06 03 55 1d 1f 04 3d 30 3b 30 39 a0 37 a0 35 86 33 68 74 74 70 3a 2f 2f 63 72 6c 2e 75 73 65 72 74 72 75 73 74 2e 63 6f 6d 2f 55 54 4e 2d 55 53 45 52 46 69 72 73 74 2d 48 61 72 64 77 61 72 65 2e 63 72 6c 30 74 06 08 2b 06 01 05 05 07 01 01 04 68 30 66 30 3d 06 08 2b 06 01 05 05 07 30 02 86 31 68 74 74 70 3a 2f 2f 63 72 74 2e 75 73 65 72 74 72 75 73 74 2e 63 6f 6d 2f 55 54 4e 41 64 64 54 72 75 73 74 53 65 72 76 65 72 5f 43 41 2e 63 72 74 30 25 06 08 2b 06 01 05 05 07 30 01 86 19 68 74 74 70 3a 2f 2f 6f 63 73 70 2e 75 73 65 72 74 72 75 73 74 2e 63 6f 6d 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 82 01 01 00 4e 23 ee 48 9c f6 85 8b 71 c4 0a 6e 73 93 72 c0 3a 8e 80 8a d9 b3 ca b2 d4 01 9c 28 cf f2 5c 0e 21 44 93 0b b6 1a 21 Attribute 79 (EAP-Message) length=255 Value: e3 98 01 94 0e 67 49 81 1e be 3d 0d 4e 60 da ef a0 31 4e 95 ef f3 dd 7a 5a 82 20 43 b6 a1 63 43 b3 50 69 43 62 4b 56 62 b0 34 8a b9 13 43 59 93 ec 14 79 88 f3 48 93 e8 9d c9 fa 87 72 0c 6b 56 a0 c3 15 8d 68 a5 87 1f 71 2d e6 5a 6d 3c 69 71 40 04 55 dc a0 43 94 20 45 38 78 d7 bd 8a d8 39 c6 df 09 b7 5a 9a a9 03 b8 28 10 78 cd bf 01 1b 5a 11 3e 38 f4 d8 1b 34 79 cf 33 d2 01 fd ac 98 cd 6d 47 11 90 4c bb b9 5b d8 70 e7 d5 af b6 cc c4 86 e6 75 c0 9e 29 b6 2b 0f 2a a5 69 02 0d e3 e9 a2 b4 5d c0 f3 ce 2c 6a 85 38 76 61 c6 49 82 ab 51 b3 82 a6 b9 41 98 28 98 fb 6b fe 8a 16 ff 31 7e 54 47 a8 3c dc 43 26 a9 9b 05 b7 9e c0 34 43 91 30 d4 32 c3 11 5a e1 00 04 40 30 82 04 3c 30 82 03 24 a0 03 02 01 02 02 10 48 4b ac f1 aa c7 d7 13 43 d1 a2 74 35 49 97 25 30 0d Attribute 79 (EAP-Message) length=255 Value: 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 30 6f 31 0b 30 09 06 03 55 04 06 13 02 53 45 31 14 30 12 06 03 55 04 0a 13 0b 41 64 64 54 72 75 73 74 20 41 42 31 26 30 24 06 03 55 04 0b 13 1d 41 64 64 54 72 75 73 74 20 45 78 74 65 72 6e 61 6c 20 54 54 50 20 4e 65 74 77 6f 72 6b 31 22 30 20 06 03 55 04 03 13 19 41 64 64 54 72 75 73 74 20 45 78 74 65 72 6e 61 6c 20 43 41 20 52 6f 6f 74 30 1e 17 0d 30 35 30 36 30 37 30 38 30 39 31 30 5a 17 0d 32 30 30 35 33 30 31 30 34 38 33 38 5a 30 81 97 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 0b 30 09 06 03 55 04 08 13 02 55 54 31 17 30 15 06 03 55 04 07 13 0e 53 61 6c 74 20 4c 61 6b 65 20 43 69 74 79 31 1e 30 1c 06 03 55 04 0a 13 15 54 68 65 20 55 53 45 52 54 52 55 53 54 20 4e 65 74 77 6f 72 6b 31 21 30 1f 06 03 55 04 0b Attribute 79 (EAP-Message) length=255 Value: 13 18 68 74 74 70 3a 2f 2f 77 77 77 2e 75 73 65 72 74 72 75 73 74 2e 63 6f 6d 31 1f 30 1d 06 03 55 04 03 13 16 55 54 4e 2d 55 53 45 52 46 69 72 73 74 2d 48 61 72 64 77 61 72 65 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 b1 f7 c3 38 3f b4 a8 7f cf 39 82 51 67 d0 6d 9f d2 ff 58 f3 e7 9f 2b ec 0d 89 54 99 b9 38 99 16 f7 e0 21 79 48 c2 bb 61 74 12 96 1d 3c 6a 72 d5 3c 10 67 3a 39 ed 2b 13 cd 66 eb 95 09 33 a4 6c 97 b1 e8 c6 ec c1 75 79 9c 46 5e 8d ab d0 6a fd b9 2a 55 17 10 54 b3 19 f0 9a f6 f1 b1 5d b6 a7 6d fb e0 71 17 6b a2 88 fb 00 df fe 1a 31 77 0c 9a 01 7a b1 32 e3 2b 01 07 38 6e c3 a5 5e 23 bc 45 9b 7b 50 c1 c9 30 8f db e5 2b 7a d3 5b fb 33 40 1e a0 d5 98 17 bc 8b 87 c3 89 d3 5d a0 8e b2 aa Attribute 79 (EAP-Message) length=10 Value: aa f6 8e 69 88 06 c5 fa Attribute 80 (Message-Authenticator) length=18 Value: d9 72 a7 86 02 d6 f8 5d 3d 4b 1d 7d 3e 81 d5 70 Attribute 24 (State) length=18 Value: 1c d6 e6 61 1f d2 ff 6c f3 74 51 3f 67 d5 3b 27 STA 02:00:00:00:00:01: Received RADIUS packet matched with a pending request, round trip time 0.00 sec RADIUS packet matching with station decapsulated EAP packet (code=1 id=4 len=1020) from RADIUS server: EAP-Request-PEAP (25) EAPOL: Received EAP-Packet frame EAPOL: SUPP_BE entering state REQUEST EAPOL: getSuppRsp EAP: EAP entering state RECEIVED EAP: Received EAP-Request id=4 method=25 vendor=0 vendorMethod=0 EAP: EAP entering state METHOD SSL: Received packet(len=1020) - Flags 0x40 SSL: Need 886 bytes more input data SSL: Building ACK (type=25 id=4 ver=0) EAP: method process -> ignore=FALSE methodState=MAY_CONT decision=FAIL eapRespData=0x90dc590 EAP: EAP entering state SEND_RESPONSE EAP: EAP entering state IDLE EAPOL: SUPP_BE entering state RESPONSE EAPOL: txSuppRsp WPA: eapol_test_eapol_send(type=0 len=6) TX EAP -> RADIUS - hexdump(len=6): 02 04 00 06 19 00 Encapsulating EAP message into a RADIUS packet Copied RADIUS State Attribute Sending RADIUS message to authentication server RADIUS message: code=1 (Access-Request) identifier=4 length=137 Attribute 1 (User-Name) length=12 Value: '@cam.ac.uk' Attribute 4 (NAS-IP-Address) length=6 Value: 127.0.0.1 Attribute 31 (Calling-Station-Id) length=19 Value: '02-00-00-00-00-01' Attribute 12 (Framed-MTU) length=6 Value: 1400 Attribute 61 (NAS-Port-Type) length=6 Value: 19 Attribute 77 (Connect-Info) length=24 Value: 'CONNECT 11Mbps 802.11b' Attribute 79 (EAP-Message) length=8 Value: 02 04 00 06 19 00 Attribute 24 (State) length=18 Value: 1c d6 e6 61 1f d2 ff 6c f3 74 51 3f 67 d5 3b 27 Attribute 80 (Message-Authenticator) length=18 Value: 79 18 cd 1e aa 34 31 27 4e 25 71 1c 80 de 10 b9 Next RADIUS client retransmit in 3 seconds EAPOL: SUPP_BE entering state RECEIVE Received 956 bytes from RADIUS server Received RADIUS message RADIUS message: code=11 (Access-Challenge) identifier=4 length=956 Attribute 79 (EAP-Message) length=255 Value: 01 05 03 7c 19 00 89 21 f3 08 9d 69 2e 09 33 9b 29 0d 46 0f 8c cc 49 34 b0 69 51 bd f9 06 cd 68 ad 66 4c bc 3e ac 61 bd 0a 88 0e c8 df 3d ee 7c 04 4c 9d 0a 5e 6b 91 d6 ee c7 ed 28 8d ab 4d 87 89 73 d0 6e a4 d0 1e 16 8b 14 e1 76 44 03 7f 63 ac e4 cd 49 9c c5 92 f4 ab 32 a1 48 5b 02 03 01 00 01 a3 81 aa 30 81 a7 30 1f 06 03 55 1d 23 04 18 30 16 80 14 ad bd 98 7a 34 b4 26 f7 fa c4 26 54 ef 03 bd e0 24 cb 54 1a 30 1d 06 03 55 1d 0e 04 16 04 14 a1 72 5f 26 1b 28 98 43 95 5d 07 37 d5 85 96 9d 4b d2 c3 45 30 0e 06 03 55 1d 0f 01 01 ff 04 04 03 02 01 06 30 0f 06 03 55 1d 13 01 01 ff 04 05 30 03 01 01 ff 30 44 06 03 55 1d 1f 04 3d 30 3b 30 39 a0 37 a0 35 86 33 68 74 74 70 3a 2f 2f 63 72 6c 2e 75 73 65 72 74 72 75 73 74 2e 63 6f 6d 2f 41 64 64 54 72 75 73 74 Attribute 79 (EAP-Message) length=255 Value: 45 78 74 65 72 6e 61 6c 43 41 52 6f 6f 74 2e 63 72 6c 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 82 01 01 00 3c ec 7b e0 ae a3 0e 96 6d 30 d7 85 c6 d2 68 5b 45 5a 82 a6 34 0f b0 c9 92 23 5e 11 6d 08 11 b2 74 09 23 3a 35 25 73 58 5e ca b9 7c 28 fa 47 ec f9 a0 03 58 50 b6 53 ef 8c db 39 e4 67 e9 d8 ca 28 46 d4 a7 e0 f5 38 75 f8 e7 cb 5c bf 1d 11 3c 6a 40 9b 2d 44 56 d3 f7 ff 05 28 32 0c 15 c8 64 45 93 e8 21 24 8f 2d da 7a 84 7b 4f cf cd b2 25 7c 77 10 d3 94 d1 04 91 a8 25 1c 09 22 0f 7d 44 35 11 14 ef af 00 fe 5e ea 5f 8e b0 d9 92 59 ba fc 13 96 a0 18 01 56 ce da f6 28 0b b1 af dd 5c 4f 5c b2 f3 8f 5a 71 cf ed 18 ad 63 88 1d 8e 95 f7 ea 95 e7 1f ad 90 b8 84 08 47 85 7f 22 2f 1a 1d 48 30 d6 4c 08 d8 37 19 67 32 2b eb 5c d0 b2 fc 6e 57 9f 04 35 5e Attribute 79 (EAP-Message) length=255 Value: 90 00 7e 11 c7 de 13 2a cd a4 6d 45 26 c7 88 56 a0 f0 6a f7 d8 e7 fc 27 7e 67 08 d0 bd fa b6 c3 61 02 01 65 b9 b8 2f cf 5a 16 03 01 01 4b 0c 00 01 47 03 00 17 41 04 53 0e 5e 34 8f 5e cc 95 4d bb 8b 33 16 97 fb 00 91 91 4d ba 87 3e a5 1a d5 4b 18 8f cb 9b e1 23 81 de 62 6f ce 49 b4 24 59 59 e0 ac 9d cf 1d bd 02 8a 58 7a 8a 0d 56 24 22 13 21 96 86 c8 aa a8 01 00 b9 ff 9a 55 d6 7a e5 ce 7f 9e 8c 8d 75 d4 0e 63 3e 51 a8 7b c1 46 aa 52 3e 94 43 cd 26 5f 55 eb 43 9d c0 21 03 7c 6c ca c8 ba fc 48 02 7b 83 d0 c7 1a f4 6c e8 f2 2e ae 4f ad b2 4e fe dd b6 e9 a0 4e f1 12 bc 65 71 0d 6a 2b d9 98 c8 9a 59 dd 32 1d 4b 6a 3c 91 a7 0f 5e 14 ba d1 88 a1 56 1e d9 54 ad e0 34 26 4c da 9c c2 48 a1 5f a3 e2 74 9f 05 15 7b d1 d0 71 f0 90 4f df 84 bf 59 f9 85 fc 56 ef 15 Attribute 79 (EAP-Message) length=135 Value: 3a 0a 00 2b e7 7e 84 40 28 93 b3 a8 eb 49 d6 ce fa 3a 5f 88 be a3 be 9f 3a 32 4c 12 05 2e 10 c2 7d 02 fa 99 1c 2f c7 e0 41 f1 8f 97 3f b5 78 9a fa 63 53 31 c4 df 72 dd 9d 37 95 5f d7 40 47 71 01 4d d9 ea 32 54 c9 c3 55 47 88 09 6a cb 7f 53 65 d1 59 f7 be e2 88 39 18 94 62 8f 3e 1a 5c 5f 4c 5b 13 47 c2 a4 5e 74 e9 1d 9a f0 4b b6 47 ac 38 66 a1 be 22 5c b3 40 74 09 6a 1b 16 03 01 00 04 0e 00 00 00 Attribute 80 (Message-Authenticator) length=18 Value: 76 9e 0b 0f 39 80 46 b4 3e 92 7d 3e 3f be 81 a7 Attribute 24 (State) length=18 Value: 1c d6 e6 61 18 d3 ff 6c f3 74 51 3f 67 d5 3b 27 STA 02:00:00:00:00:01: Received RADIUS packet matched with a pending request, round trip time 0.00 sec RADIUS packet matching with station decapsulated EAP packet (code=1 id=5 len=892) from RADIUS server: EAP-Request-PEAP (25) EAPOL: Received EAP-Packet frame EAPOL: SUPP_BE entering state REQUEST EAPOL: getSuppRsp EAP: EAP entering state RECEIVED EAP: Received EAP-Request id=5 method=25 vendor=0 vendorMethod=0 EAP: EAP entering state METHOD SSL: Received packet(len=892) - Flags 0x00 SSL: (where=0x1001 ret=0x1) SSL: SSL_connect:SSLv3 read server hello A TLS: tls_verify_cb - preverify_ok=1 err=0 (ok) ca_cert_verify=1 depth=3 buf='/C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root' CTRL-EVENT-EAP-PEER-CERT depth=3 subject='/C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root' EAP: Status notification: remote certificate verification (param=success) TLS: tls_verify_cb - preverify_ok=1 err=0 (ok) ca_cert_verify=1 depth=2 buf='/C=US/ST=UT/L=Salt Lake City/O=The USERTRUST Network/OU=http://www.usertrust.com/CN=UTN-USERFirst-Hardware' CTRL-EVENT-EAP-PEER-CERT depth=2 subject='/C=US/ST=UT/L=Salt Lake City/O=The USERTRUST Network/OU=http://www.usertrust.com/CN=UTN-USERFirst-Hardware' EAP: Status notification: remote certificate verification (param=success) TLS: tls_verify_cb - preverify_ok=1 err=0 (ok) ca_cert_verify=1 depth=1 buf='/C=NL/O=TERENA/CN=TERENA SSL CA' CTRL-EVENT-EAP-PEER-CERT depth=1 subject='/C=NL/O=TERENA/CN=TERENA SSL CA' EAP: Status notification: remote certificate verification (param=success) TLS: tls_verify_cb - preverify_ok=1 err=0 (ok) ca_cert_verify=1 depth=0 buf='/C=GB/ST=England/L=Cambridge/O=University of Cambridge/OU=Computing Service/CN=network.tokens.csx.cam.ac.uk' CTRL-EVENT-EAP-PEER-CERT depth=0 subject='/C=GB/ST=England/L=Cambridge/O=University of Cambridge/OU=Computing Service/CN=network.tokens.csx.cam.ac.uk' TLS: Server used client certificate CTRL-EVENT-EAP-TLS-CERT-ERROR reason=10 depth=0 subject='/C=GB/ST=England/L=Cambridge/O=University of Cambridge/OU=Computing Service/CN=network.tokens.csx.cam.ac.uk' err='Server used client certificate' EAP: Status notification: remote certificate verification (param=Server used client certificate) SSL: (where=0x4008 ret=0x22e) SSL: SSL3 alert: write (local SSL3 detected an error):fatal:certificate unknown EAP: Status notification: local TLS alert (param=certificate unknown) SSL: (where=0x1002 ret=0xffffffff) SSL: SSL_connect:error in SSLv3 read server certificate B OpenSSL: openssl_handshake - SSL_connect error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed SSL: 7 bytes pending from ssl_out SSL: Failed - tls_out available to report error SSL: 7 bytes left to be sent out (of total 7 bytes) EAP: method process -> ignore=FALSE methodState=MAY_CONT decision=FAIL eapRespData=0x90f4390 EAP: EAP entering state SEND_RESPONSE EAP: EAP entering state IDLE EAPOL: SUPP_BE entering state RESPONSE EAPOL: txSuppRsp WPA: eapol_test_eapol_send(type=0 len=17) TX EAP -> RADIUS - hexdump(len=17): 02 05 00 11 19 80 00 00 00 07 15 03 01 00 02 02 2e Encapsulating EAP message into a RADIUS packet Copied RADIUS State Attribute Sending RADIUS message to authentication server RADIUS message: code=1 (Access-Request) identifier=5 length=148 Attribute 1 (User-Name) length=12 Value: '@cam.ac.uk' Attribute 4 (NAS-IP-Address) length=6 Value: 127.0.0.1 Attribute 31 (Calling-Station-Id) length=19 Value: '02-00-00-00-00-01' Attribute 12 (Framed-MTU) length=6 Value: 1400 Attribute 61 (NAS-Port-Type) length=6 Value: 19 Attribute 77 (Connect-Info) length=24 Value: 'CONNECT 11Mbps 802.11b' Attribute 79 (EAP-Message) length=19 Value: 02 05 00 11 19 80 00 00 00 07 15 03 01 00 02 02 2e Attribute 24 (State) length=18 Value: 1c d6 e6 61 18 d3 ff 6c f3 74 51 3f 67 d5 3b 27 Attribute 80 (Message-Authenticator) length=18 Value: f2 58 bd 12 1e 38 6f 5d 65 87 a0 ac ef 74 ad a9 Next RADIUS client retransmit in 3 seconds EAPOL: SUPP_BE entering state RECEIVE Received 44 bytes from RADIUS server Received RADIUS message RADIUS message: code=3 (Access-Reject) identifier=5 length=44 Attribute 79 (EAP-Message) length=6 Value: 04 05 00 04 Attribute 80 (Message-Authenticator) length=18 Value: f7 27 1a dd 01 87 a9 bc 63 00 26 9a 3b 9e 71 79 STA 02:00:00:00:00:01: Received RADIUS packet matched with a pending request, round trip time 1.00 sec RADIUS packet matching with station decapsulated EAP packet (code=4 id=5 len=4) from RADIUS server: EAP Failure EAPOL: Received EAP-Packet frame EAPOL: SUPP_BE entering state REQUEST EAPOL: getSuppRsp EAP: EAP entering state RECEIVED EAP: Received EAP-Failure EAP: Status notification: completion (param=failure) EAP: EAP entering state FAILURE CTRL-EVENT-EAP-FAILURE EAP authentication failed EAPOL: SUPP_PAE entering state HELD EAPOL: SUPP_BE entering state RECEIVE EAPOL: SUPP_BE entering state FAIL EAPOL: SUPP_BE entering state IDLE eapol_sm_cb: result=0 EAPOL: EAP key not available EAPOL: EAP key not available EAP: deinitialize previously used EAP method (25, PEAP) at EAP deinit ENGINE: engine deinit MPPE keys OK: 0 mismatch: 2 FAILURE