{\rtf1\ansi\ansicpg1252\cocoartf1504\cocoasubrtf820 {\fonttbl\f0\fnil\fcharset0 Menlo-Regular;} {\colortbl;\red255\green255\blue255;} {\*\expandedcolortbl;;} \paperw11900\paperh16840\margl1440\margr1440\vieww10800\viewh8400\viewkind0 \deftab720 \pard\pardeftab720\ri-46\partightenfactor0 \f0\fs17 \cf0 FreeRADIUS Version 3.0.12\ Copyright (C) 1999-2016 The FreeRADIUS server project and contributors\ There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A\ PARTICULAR PURPOSE\ You may redistribute copies of FreeRADIUS under the terms of the\ GNU General Public License\ For more information about these matters, see the file named COPYRIGHT\ Starting - reading configuration files ...\ including dictionary file /usr/share/freeradius/dictionary\ including dictionary file /usr/share/freeradius/dictionary.dhcp\ including dictionary file /usr/share/freeradius/dictionary.vqp\ including dictionary file /etc/freeradius/dictionary\ including configuration file /etc/freeradius/radiusd.conf\ including configuration file /etc/freeradius/proxy.conf\ including configuration file /etc/freeradius/clients.conf\ including files in directory /etc/freeradius/mods-enabled/\ including configuration file /etc/freeradius/mods-enabled/expr\ including configuration file /etc/freeradius/mods-enabled/echo\ including configuration file /etc/freeradius/mods-enabled/expiration\ including configuration file /etc/freeradius/mods-enabled/ntlm_auth\ including configuration file /etc/freeradius/mods-enabled/cache_eap\ including configuration file /etc/freeradius/mods-enabled/radutmp\ including configuration file /etc/freeradius/mods-enabled/linelog\ including configuration file /etc/freeradius/mods-enabled/chap\ including configuration file /etc/freeradius/mods-enabled/mschap\ including configuration file /etc/freeradius/mods-enabled/pap\ including configuration file /etc/freeradius/mods-enabled/digest\ including configuration file /etc/freeradius/mods-enabled/always\ including configuration file /etc/freeradius/mods-enabled/preprocess\ including configuration file /etc/freeradius/mods-enabled/passwd\ including configuration file /etc/freeradius/mods-enabled/realm\ including configuration file /etc/freeradius/mods-enabled/sradutmp\ including configuration file /etc/freeradius/mods-enabled/ldap\ including configuration file /etc/freeradius/mods-enabled/eap\ including configuration file /etc/freeradius/mods-enabled/soh\ including configuration file /etc/freeradius/mods-enabled/logintime\ including configuration file /etc/freeradius/mods-enabled/replicate\ including configuration file /etc/freeradius/mods-enabled/date\ including configuration file /etc/freeradius/mods-enabled/unpack\ including configuration file /etc/freeradius/mods-enabled/dynamic_clients\ including configuration file /etc/freeradius/mods-enabled/attr_filter\ including configuration file /etc/freeradius/mods-enabled/exec\ including configuration file /etc/freeradius/mods-enabled/utf8\ including configuration file /etc/freeradius/mods-enabled/detail\ including configuration file /etc/freeradius/mods-enabled/unix\ including configuration file /etc/freeradius/mods-enabled/detail.log\ including configuration file /etc/freeradius/mods-enabled/files\ including files in directory /etc/freeradius/policy.d/\ including configuration file /etc/freeradius/policy.d/abfab-tr\ including configuration file /etc/freeradius/policy.d/operator-name\ including configuration file /etc/freeradius/policy.d/accounting\ including configuration file /etc/freeradius/policy.d/dhcp\ including configuration file /etc/freeradius/policy.d/control\ including configuration file /etc/freeradius/policy.d/eap\ including configuration file /etc/freeradius/policy.d/debug\ including configuration file /etc/freeradius/policy.d/cui\ including configuration file /etc/freeradius/policy.d/filter\ including configuration file /etc/freeradius/policy.d/canonicalization\ including configuration file /etc/freeradius/policy.d/moonshot-targeted-ids\ including files in directory /etc/freeradius/sites-enabled/\ including configuration file /etc/freeradius/sites-enabled/default\ including configuration file /etc/freeradius/sites-enabled/inner-tunnel\ main \{\ \'a0security \{\ \'a0 \'a0 \'a0 \'a0 user = "freerad"\ \'a0 \'a0 \'a0 \'a0 group = "freerad"\ \'a0 \'a0 \'a0 \'a0 allow_core_dumps = no\ \'a0\}\ \'a0 \'a0 \'a0 \'a0 name = "freeradius"\ \'a0 \'a0 \'a0 \'a0 prefix = "/usr"\ \'a0 \'a0 \'a0 \'a0 localstatedir = "/var"\ \'a0 \'a0 \'a0 \'a0 logdir = "/var/log/freeradius"\ \'a0 \'a0 \'a0 \'a0 run_dir = "/var/run/freeradius"\ \}\ main \{\ \'a0 \'a0 \'a0 \'a0 name = "freeradius"\ \'a0 \'a0 \'a0 \'a0 prefix = "/usr"\ \'a0 \'a0 \'a0 \'a0 localstatedir = "/var"\ \'a0 \'a0 \'a0 \'a0 sbindir = "/usr/sbin"\ \'a0 \'a0 \'a0 \'a0 logdir = "/var/log/freeradius"\ \'a0 \'a0 \'a0 \'a0 run_dir = "/var/run/freeradius"\ \'a0 \'a0 \'a0 \'a0 libdir = "/usr/lib/freeradius"\ \'a0 \'a0 \'a0 \'a0 radacctdir = "/var/log/freeradius/radacct"\ \'a0 \'a0 \'a0 \'a0 hostname_lookups = no\ \'a0 \'a0 \'a0 \'a0 max_request_time = 30\ \'a0 \'a0 \'a0 \'a0 cleanup_delay = 5\ \'a0 \'a0 \'a0 \'a0 max_requests = 16384\ \'a0 \'a0 \'a0 \'a0 pidfile = "/var/run/freeradius/freeradius.pid"\ \'a0 \'a0 \'a0 \'a0 checkrad = "/usr/sbin/checkrad"\ \'a0 \'a0 \'a0 \'a0 debug_level = 0\ \'a0 \'a0 \'a0 \'a0 proxy_requests = yes\ \'a0log \{\ \'a0 \'a0 \'a0 \'a0 stripped_names = no\ \'a0 \'a0 \'a0 \'a0 auth = no\ \'a0 \'a0 \'a0 \'a0 auth_badpass = no\ \'a0 \'a0 \'a0 \'a0 auth_goodpass = no\ \'a0 \'a0 \'a0 \'a0 colourise = yes\ \'a0 \'a0 \'a0 \'a0 msg_denied = "You are already logged in - access denied"\ \'a0\}\ \'a0resources \{\ \'a0\}\ \'a0security \{\ \'a0 \'a0 \'a0 \'a0 max_attributes = 200\ \'a0 \'a0 \'a0 \'a0 reject_delay = 1.000000\ \'a0 \'a0 \'a0 \'a0 status_server = yes\ \'a0\}\ \}\ radiusd: #### Loading Realms and Home Servers ####\ \'a0proxy server \{\ \'a0 \'a0 \'a0 \'a0 retry_delay = 5\ \'a0 \'a0 \'a0 \'a0 retry_count = 3\ \'a0 \'a0 \'a0 \'a0 default_fallback = no\ \'a0 \'a0 \'a0 \'a0 dead_time = 120\ \'a0 \'a0 \'a0 \'a0 wake_all_if_all_dead = no\ \'a0\}\ \'a0home_server localhost \{\ \'a0 \'a0 \'a0 \'a0 ipaddr = 127.0.0.1\ \'a0 \'a0 \'a0 \'a0 port = 1812\ \'a0 \'a0 \'a0 \'a0 type = "auth"\ \'a0 \'a0 \'a0 \'a0 secret = <<< secret >>>\ \'a0 \'a0 \'a0 \'a0 response_window = 20.000000\ \'a0 \'a0 \'a0 \'a0 response_timeouts = 1\ \'a0 \'a0 \'a0 \'a0 max_outstanding = 65536\ \'a0 \'a0 \'a0 \'a0 zombie_period = 40\ \'a0 \'a0 \'a0 \'a0 status_check = "status-server"\ \'a0 \'a0 \'a0 \'a0 ping_interval = 30\ \'a0 \'a0 \'a0 \'a0 check_interval = 30\ \'a0 \'a0 \'a0 \'a0 check_timeout = 4\ \'a0 \'a0 \'a0 \'a0 num_answers_to_alive = 3\ \'a0 \'a0 \'a0 \'a0 revive_interval = 120\ \'a0 limit \{\ \'a0 \'a0 \'a0 \'a0 max_connections = 16\ max_requests = 0\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 0\ \'a0 \}\ \'a0 coa \{\ \'a0 \'a0 \'a0 \'a0 irt = 2\ \'a0 \'a0 \'a0 \'a0 mrt = 16\ \'a0 \'a0 \'a0 \'a0 mrc = 5\ \'a0 \'a0 \'a0 \'a0 mrd = 30\ \'a0 \}\ \'a0\}\ \'a0home_server_pool my_auth_failover \{\ \'a0 \'a0 \'a0 \'a0 type = fail-over\ \'a0 \'a0 \'a0 \'a0 home_server = localhost\ \'a0\}\ \'a0realm example.com \{\ \'a0 \'a0 \'a0 \'a0 auth_pool = my_auth_failover\ \'a0\}\ \'a0realm LOCAL \{\ \'a0\}\ radiusd: #### Loading Clients ####\ \'a0client localhost \{\ \'a0 \'a0 \'a0 \'a0 ipaddr = 127.0.0.1\ \'a0 \'a0 \'a0 \'a0 require_message_authenticator = no\ \'a0 \'a0 \'a0 \'a0 secret = <<< secret >>>\ \'a0 \'a0 \'a0 \'a0 nas_type = "other"\ \'a0 \'a0 \'a0 \'a0 proto = "*"\ \'a0 limit \{\ \'a0 \'a0 \'a0 \'a0 max_connections = 16\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 30\ \'a0 \}\ \'a0\}\ \'a0client localhost_ipv6 \{\ \'a0 \'a0 \'a0 \'a0 ipv6addr = ::1\ \'a0 \'a0 \'a0 \'a0 require_message_authenticator = no\ \'a0 \'a0 \'a0 \'a0 secret = <<< secret >>>\ \'a0 limit \{\ \'a0 \'a0 \'a0 \'a0 max_connections = 16\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 30\ \'a0 \}\ \'a0\}\ \'a0client unifi \{\ \'a0 \'a0 \'a0 \'a0 ipaddr = 10.155.20.0/24\ \'a0 \'a0 \'a0 \'a0 require_message_authenticator = no\ \'a0 \'a0 \'a0 \'a0 secret = <<< secret >>>\ \'a0 limit \{\ \'a0 \'a0 \'a0 \'a0 max_connections = 16\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 30\ \'a0 \}\ \'a0\}\ Debugger not attached\ \'a0# Creating Auth-Type = mschap\ \'a0# Creating Auth-Type = digest\ \'a0# Creating Auth-Type = eap\ \'a0# Creating Auth-Type = PAP\ \'a0# Creating Auth-Type = CHAP\ \'a0# Creating Auth-Type = MS-CHAP\ radiusd: #### Instantiating modules ####\ \'a0modules \{\ \'a0 # Loaded module rlm_expr\ \'a0 # Loading module "expr" from file /etc/freeradius/mods-enabled/expr\ \'a0 expr \{\ \'a0 \'a0 \'a0 \'a0 safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /\'e4\'e9\'f6\'fc\'e0\'e2\'e6\'e7\'e8\'e9\'ea\'eb\'ee\'ef\'f4\'9c\'f9\'fb\'fca\'ff\'c4\'c9\'d6\'dc\'df\'c0\'c2\'c6\'c7\'c8\'c9\'ca\'cb\'ce\'cf\'d4\'8c\'d9\'db\'dc\'9f"\ \'a0 \}\ # Loaded module rlm_exec\ \'a0 # Loading module "echo" from file /etc/freeradius/mods-enabled/echo\ \'a0 exec echo \{\ \'a0 \'a0 \'a0 \'a0 wait = yes\ \'a0 \'a0 \'a0 \'a0 program = "/bin/echo %\{User-Name\}"\ \'a0 \'a0 \'a0 \'a0 input_pairs = "request"\ \'a0 \'a0 \'a0 \'a0 output_pairs = "reply"\ \'a0 \'a0 \'a0 \'a0 shell_escape = yes\ \'a0 \}\ \'a0 # Loaded module rlm_expiration\ \'a0 # Loading module "expiration" from file /etc/freeradius/mods-enabled/expiration\ \'a0 # Loading module "ntlm_auth" from file /etc/freeradius/mods-enabled/ntlm_auth\ \'a0 exec ntlm_auth \{\ \'a0 \'a0 \'a0 \'a0 wait = yes\ \'a0 \'a0 \'a0 \'a0 program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN --username=%\{mschap:User-Name\} --password=%\{User-Password\}"\ \'a0 \'a0 \'a0 \'a0 shell_escape = yes\ \'a0 \}\ \'a0 # Loaded module rlm_cache\ \'a0 # Loading module "cache_eap" from file /etc/freeradius/mods-enabled/cache_eap\ \'a0 cache cache_eap \{\ \'a0 \'a0 \'a0 \'a0 driver = "rlm_cache_rbtree"\ \'a0 \'a0 \'a0 \'a0 key = "%\{%\{control:State\}:-%\{%\{reply:State\}:-%\{State\}\}\}"\ \'a0 \'a0 \'a0 \'a0 ttl = 15\ \'a0 \'a0 \'a0 \'a0 max_entries = 0\ \'a0 \'a0 \'a0 \'a0 epoch = 0\ \'a0 \'a0 \'a0 \'a0 add_stats = no\ \'a0 \}\ \'a0 # Loaded module rlm_radutmp\ \'a0 # Loading module "radutmp" from file /etc/freeradius/mods-enabled/radutmp\ \'a0 radutmp \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/radutmp"\ \'a0 \'a0 \'a0 \'a0 username = "%\{User-Name\}"\ \'a0 \'a0 \'a0 \'a0 case_sensitive = yes\ \'a0 \'a0 \'a0 \'a0 check_with_nas = yes\ \'a0 \'a0 \'a0 \'a0 permissions = 384\ \'a0 \'a0 \'a0 \'a0 caller_id = yes\ \'a0 \}\ \'a0 # Loaded module rlm_linelog\ \'a0 # Loading module "linelog" from file /etc/freeradius/mods-enabled/linelog\ \'a0 linelog \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/linelog"\ \'a0 \'a0 \'a0 \'a0 escape_filenames = no\ \'a0 \'a0 \'a0 \'a0 syslog_severity = "info"\ \'a0 \'a0 \'a0 \'a0 permissions = 384\ \'a0 \'a0 \'a0 \'a0 format = "This is a log message for %\{User-Name\}"\ \'a0 \'a0 \'a0 \'a0 reference = "messages.%\{%\{reply:Packet-Type\}:-default\}"\ \'a0 \}\ \'a0 # Loading module "log_accounting" from file /etc/freeradius/mods-enabled/linelog\ \'a0 linelog log_accounting \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/linelog-accounting"\ \'a0 \'a0 \'a0 \'a0 escape_filenames = no\ \'a0 \'a0 \'a0 \'a0 syslog_severity = "info"\ \'a0 \'a0 \'a0 \'a0 permissions = 384\ \'a0 \'a0 \'a0 \'a0 format = ""\ \'a0 \'a0 \'a0 \'a0 reference = "Accounting-Request.%\{%\{Acct-Status-Type\}:-unknown\}"\ \'a0 \}\ \'a0 # Loaded module rlm_chap\ \'a0 # Loading module "chap" from file /etc/freeradius/mods-enabled/chap\ \'a0 # Loaded module rlm_mschap\ \'a0 # Loading module "mschap" from file /etc/freeradius/mods-enabled/mschap\ \'a0 mschap \{\ \'a0 \'a0 \'a0 \'a0 use_mppe = yes\ \'a0 \'a0 \'a0 \'a0 require_encryption = no\ \'a0 \'a0 \'a0 \'a0 require_strong = no\ \'a0 \'a0 \'a0 \'a0 with_ntdomain_hack = yes\ \'a0\'a0 passchange \{\ \'a0\'a0 \}\ \'a0 \'a0 \'a0 \'a0 allow_retry = yes\ \'a0 \}\ # Loaded module rlm_pap\ \'a0 # Loading module "pap" from file /etc/freeradius/mods-enabled/pap\ \'a0 pap \{\ \'a0 \'a0 \'a0 \'a0 normalise = yes\ \'a0 \}\ \'a0 # Loaded module rlm_digest\ \'a0 # Loading module "digest" from file /etc/freeradius/mods-enabled/digest\ \'a0 # Loaded module rlm_always\ \'a0 # Loading module "reject" from file /etc/freeradius/mods-enabled/always\ \'a0 always reject \{\ \'a0 \'a0 \'a0 \'a0 rcode = "reject"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loading module "fail" from file /etc/freeradius/mods-enabled/always\ \'a0 always fail \{\ \'a0 \'a0 \'a0 \'a0 rcode = "fail"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loading module "ok" from file /etc/freeradius/mods-enabled/always\ \'a0 always ok \{\ \'a0 \'a0 \'a0 \'a0 rcode = "ok"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loading module "handled" from file /etc/freeradius/mods-enabled/always\ \'a0 always handled \{\ \'a0 \'a0 \'a0 \'a0 rcode = "handled"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loading module "invalid" from file /etc/freeradius/mods-enabled/always\ \'a0 always invalid \{\ \'a0 \'a0 \'a0 \'a0 rcode = "invalid"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loading module "userlock" from file /etc/freeradius/mods-enabled/always\ \'a0 always userlock \{\ \'a0 \'a0 \'a0 \'a0 rcode = "userlock"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loading module "notfound" from file /etc/freeradius/mods-enabled/always\ \'a0 always notfound \{\ \'a0 \'a0 \'a0 \'a0 rcode = "notfound"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loading module "noop" from file /etc/freeradius/mods-enabled/always\ \'a0 always noop \{\ \'a0 \'a0 \'a0 \'a0 rcode = "noop"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loading module "updated" from file /etc/freeradius/mods-enabled/always\ \'a0 always updated \{\ \'a0 \'a0 \'a0 \'a0 rcode = "updated"\ \'a0 \'a0 \'a0 \'a0 simulcount = 0\ \'a0 \'a0 \'a0 \'a0 mpp = no\ \'a0 \}\ \'a0 # Loaded module rlm_preprocess\ \'a0 # Loading module "preprocess" from file /etc/freeradius/mods-enabled/preprocess\ preprocess \{\ \'a0 \'a0 \'a0 \'a0 huntgroups = "/etc/freeradius/mods-config/preprocess/huntgroups"\ \'a0 \'a0 \'a0 \'a0 hints = "/etc/freeradius/mods-config/preprocess/hints"\ \'a0 \'a0 \'a0 \'a0 with_ascend_hack = no\ \'a0 \'a0 \'a0 \'a0 ascend_channels_per_line = 23\ \'a0 \'a0 \'a0 \'a0 with_ntdomain_hack = no\ \'a0 \'a0 \'a0 \'a0 with_specialix_jetstream_hack = no\ \'a0 \'a0 \'a0 \'a0 with_cisco_vsa_hack = no\ \'a0 \'a0 \'a0 \'a0 with_alvarion_vsa_hack = no\ \'a0 \}\ \'a0 # Loaded module rlm_passwd\ \'a0 # Loading module "etc_passwd" from file /etc/freeradius/mods-enabled/passwd\ \'a0 passwd etc_passwd \{\ \'a0 \'a0 \'a0 \'a0 filename = "/etc/passwd"\ \'a0 \'a0 \'a0 \'a0 format = "*User-Name:Crypt-Password:"\ \'a0 \'a0 \'a0 \'a0 delimiter = ":"\ \'a0 \'a0 \'a0 \'a0 ignore_nislike = no\ \'a0 \'a0 \'a0 \'a0 ignore_empty = yes\ \'a0 \'a0 \'a0 \'a0 allow_multiple_keys = no\ \'a0 \'a0 \'a0 \'a0 hash_size = 100\ \'a0 \}\ \'a0 # Loaded module rlm_realm\ \'a0 # Loading module "IPASS" from file /etc/freeradius/mods-enabled/realm\ \'a0 realm IPASS \{\ \'a0 \'a0 \'a0 \'a0 format = "prefix"\ \'a0 \'a0 \'a0 \'a0 delimiter = "/"\ \'a0 \'a0 \'a0 \'a0 ignore_default = no\ \'a0 \'a0 \'a0 \'a0 ignore_null = no\ \'a0 \}\ \'a0 # Loading module "suffix" from file /etc/freeradius/mods-enabled/realm\ \'a0 realm suffix \{\ \'a0 \'a0 \'a0 \'a0 format = "suffix"\ \'a0 \'a0 \'a0 \'a0 delimiter = "@"\ \'a0 \'a0 \'a0 \'a0 ignore_default = no\ \'a0 \'a0 \'a0 \'a0 ignore_null = no\ \'a0 \}\ \'a0 # Loading module "realmpercent" from file /etc/freeradius/mods-enabled/realm\ \'a0 realm realmpercent \{\ \'a0 \'a0 \'a0 \'a0 format = "suffix"\ \'a0 \'a0 \'a0 \'a0 delimiter = "%"\ \'a0 \'a0 \'a0 \'a0 ignore_default = no\ \'a0 \'a0 \'a0 \'a0 ignore_null = no\ \'a0 \}\ \'a0 # Loading module "ntdomain" from file /etc/freeradius/mods-enabled/realm\ \'a0 realm ntdomain \{\ \'a0 \'a0 \'a0 \'a0 format = "prefix"\ \'a0 \'a0 \'a0 \'a0 delimiter = "\\\\"\ \'a0 \'a0 \'a0 \'a0 ignore_default = no\ \'a0 \'a0 \'a0 \'a0 ignore_null = no\ \'a0 \}\ \'a0 # Loading module "sradutmp" from file /etc/freeradius/mods-enabled/sradutmp\ \'a0 radutmp sradutmp \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/sradutmp"\ \'a0 \'a0 \'a0 \'a0 username = "%\{User-Name\}"\ \'a0 \'a0 \'a0 \'a0 case_sensitive = yes\ \'a0 \'a0 \'a0 \'a0 check_with_nas = yes\ \'a0 \'a0 \'a0 \'a0 permissions = 420\ \'a0 \'a0 \'a0 \'a0 caller_id = no\ \'a0 \}\ \'a0 # Loaded module rlm_ldap\ \'a0 # Loading module "ldap" from file /etc/freeradius/mods-enabled/ldap\ \'a0 ldap \{\ \'a0 \'a0 \'a0 \'a0 server = "localhost"\ \'a0 \'a0 \'a0 \'a0 identity = "cn=admin,dc=jacob-balde,dc=de"\ \'a0 \'a0 \'a0 \'a0 password = <<< secret >>>\ \'a0\'a0 sasl \{\ \'a0\'a0 \}\ \'a0\'a0 user \{\ \'a0 \'a0 \'a0 \'a0 scope = "sub"\ \'a0 \'a0 \'a0 \'a0 access_positive = yes\ sasl \{\ \'a0 \'a0 \}\ \'a0\'a0 \}\ \'a0\'a0 group \{\ \'a0 \'a0 \'a0 \'a0 filter = "(objectClass=posixGroup)"\ \'a0 \'a0 \'a0 \'a0 scope = "sub"\ \'a0 \'a0 \'a0 \'a0 name_attribute = "cn"\ \'a0 \'a0 \'a0 \'a0 membership_attribute = "memberOf"\ \'a0 \'a0 \'a0 \'a0 cacheable_name = no\ \'a0 \'a0 \'a0 \'a0 cacheable_dn = no\ \'a0\'a0 \}\ \'a0\'a0 client \{\ \'a0 \'a0 \'a0 \'a0 filter = "(objectClass=radiusClient)"\ \'a0 \'a0 \'a0 \'a0 scope = "sub"\ \'a0 \'a0 \'a0 \'a0 base_dn = "dc=jacob-balde,dc=de"\ \'a0\'a0 \}\ \'a0\'a0 profile \{\ \'a0\'a0 \}\ \'a0\'a0 options \{\ \'a0 \'a0 \'a0 \'a0 ldap_debug = 40\ \'a0 \'a0 \'a0 \'a0 chase_referrals = yes\ \'a0 \'a0 \'a0 \'a0 rebind = yes\ \'a0 \'a0 \'a0 \'a0 net_timeout = 1\ \'a0 \'a0 \'a0 \'a0 res_timeout = 10\ \'a0 \'a0 \'a0 \'a0 srv_timelimit = 3\ \'a0 \'a0 \'a0 \'a0 idle = 60\ \'a0 \'a0 \'a0 \'a0 probes = 3\ \'a0 \'a0 \'a0 \'a0 interval = 3\ \'a0\'a0 \}\ \'a0\'a0 tls \{\ \'a0 \'a0 \'a0 \'a0 start_tls = no\ \'a0\'a0 \}\ \'a0 \}\ Creating attribute LDAP-Group\ \'a0 # Loaded module rlm_eap\ \'a0 # Loading module "eap" from file /etc/freeradius/mods-enabled/eap\ \'a0 eap \{\ \'a0 \'a0 \'a0 \'a0 default_eap_type = "md5"\ \'a0 \'a0 \'a0 \'a0 timer_expire = 60\ \'a0 \'a0 \'a0 \'a0 ignore_unknown_eap_types = no\ \'a0 \'a0 \'a0 \'a0 cisco_accounting_username_bug = no\ \'a0 \'a0 \'a0 \'a0 max_sessions = 16384\ \'a0 \}\ \'a0 # Loaded module rlm_soh\ \'a0 # Loading module "soh" from file /etc/freeradius/mods-enabled/soh\ \'a0 soh \{\ \'a0 \'a0 \'a0 \'a0 dhcp = yes\ \'a0 \}\ \'a0 # Loaded module rlm_logintime\ \'a0 # Loading module "logintime" from file /etc/freeradius/mods-enabled/logintime\ \'a0 logintime \{\ \'a0 \'a0 \'a0 \'a0 minimum_timeout = 60\ \'a0 \}\ \'a0 # Loaded module rlm_replicate\ \'a0 # Loading module "replicate" from file /etc/freeradius/mods-enabled/replicate\ \'a0 # Loaded module rlm_date\ \'a0 # Loading module "date" from file /etc/freeradius/mods-enabled/date\ \'a0 date \{\ \'a0 \'a0 \'a0 \'a0 format = "%b %e %Y %H:%M:%S %Z"\ \'a0 \}\ \'a0 # Loaded module rlm_unpack\ \'a0 # Loading module "unpack" from file /etc/freeradius/mods-enabled/unpack\ \'a0 # Loaded module rlm_dynamic_clients\ \'a0 # Loading module "dynamic_clients" from file /etc/freeradius/mods-enabled/dynamic_clients\ \'a0 # Loaded module rlm_attr_filter\ \'a0 # Loading module "attr_filter.post-proxy" from file /etc/freeradius/mods-enabled/attr_filter\ attr_filter attr_filter.post-proxy \{\ \'a0 \'a0 \'a0 \'a0 filename = "/etc/freeradius/mods-config/attr_filter/post-proxy"\ \'a0 \'a0 \'a0 \'a0 key = "%\{Realm\}"\ \'a0 \'a0 \'a0 \'a0 relaxed = no\ \'a0 \}\ \'a0 # Loading module "attr_filter.pre-proxy" from file /etc/freeradius/mods-enabled/attr_filter\ \'a0 attr_filter attr_filter.pre-proxy \{\ \'a0 \'a0 \'a0 \'a0 filename = "/etc/freeradius/mods-config/attr_filter/pre-proxy"\ \'a0 \'a0 \'a0 \'a0 key = "%\{Realm\}"\ \'a0 \'a0 \'a0 \'a0 relaxed = no\ \'a0 \}\ \'a0 # Loading module "attr_filter.access_reject" from file /etc/freeradius/mods-enabled/attr_filter\ \'a0 attr_filter attr_filter.access_reject \{\ \'a0 \'a0 \'a0 \'a0 filename = "/etc/freeradius/mods-config/attr_filter/access_reject"\ \'a0 \'a0 \'a0 \'a0 key = "%\{User-Name\}"\ \'a0 \'a0 \'a0 \'a0 relaxed = no\ \'a0 \}\ \'a0 # Loading module "attr_filter.access_challenge" from file /etc/freeradius/mods-enabled/attr_filter\ \'a0 attr_filter attr_filter.access_challenge \{\ \'a0 \'a0 \'a0 \'a0 filename = "/etc/freeradius/mods-config/attr_filter/access_challenge"\ \'a0 \'a0 \'a0 \'a0 key = "%\{User-Name\}"\ \'a0 \'a0 \'a0 \'a0 relaxed = no\ \'a0 \}\ \'a0 # Loading module "attr_filter.accounting_response" from file /etc/freeradius/mods-enabled/attr_filter\ \'a0 attr_filter attr_filter.accounting_response \{\ \'a0 \'a0 \'a0 \'a0 filename = "/etc/freeradius/mods-config/attr_filter/accounting_response"\ \'a0 \'a0 \'a0 \'a0 key = "%\{User-Name\}"\ \'a0 \'a0 \'a0 \'a0 relaxed = no\ \'a0 \}\ \'a0 # Loading module "exec" from file /etc/freeradius/mods-enabled/exec\ \'a0 exec \{\ \'a0 \'a0 \'a0 \'a0 wait = no\ \'a0 \'a0 \'a0 \'a0 input_pairs = "request"\ \'a0 \'a0 \'a0 \'a0 shell_escape = yes\ \'a0 \'a0 \'a0 \'a0 timeout = 10\ \'a0 \}\ \'a0 # Loaded module rlm_utf8\ \'a0 # Loading module "utf8" from file /etc/freeradius/mods-enabled/utf8\ \'a0 # Loaded module rlm_detail\ \'a0 # Loading module "detail" from file /etc/freeradius/mods-enabled/detail\ \'a0 detail \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/radacct/%\{%\{Packet-Src-IP-Address\}:-%\{Packet-Src-IPv6-Address\}\}/detail-%Y%m%d"\ \'a0 \'a0 \'a0 \'a0 header = "%t"\ \'a0 \'a0 \'a0 \'a0 permissions = 384\ \'a0 \'a0 \'a0 \'a0 locking = no\ \'a0 \'a0 \'a0 \'a0 escape_filenames = no\ \'a0 \'a0 \'a0 \'a0 log_packet_header = no\ \'a0 \}\ \'a0 # Loaded module rlm_unix\ \'a0 # Loading module "unix" from file /etc/freeradius/mods-enabled/unix\ \'a0 unix \{\ \'a0 \'a0 \'a0 \'a0 radwtmp = "/var/log/freeradius/radwtmp"\ \'a0 \}\ Creating attribute Unix-Group\ \'a0 # Loading module "auth_log" from file /etc/freeradius/mods-enabled/detail.log\ \'a0 detail auth_log \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/radacct/%\{%\{Packet-Src-IP-Address\}:-%\{Packet-Src-IPv6-Address\}\}/auth-detail-%Y%m%d"\ \'a0 \'a0 \'a0 \'a0 header = "%t"\ \'a0 \'a0 \'a0 \'a0 permissions = 384\ \'a0 \'a0 \'a0 \'a0 locking = no\ \'a0 \'a0 \'a0 \'a0 escape_filenames = no\ \'a0 \'a0 \'a0 \'a0 log_packet_header = no\ \'a0 \}\ \'a0# Loading module "reply_log" from file /etc/freeradius/mods-enabled/detail.log\ \'a0 detail reply_log \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/radacct/%\{%\{Packet-Src-IP-Address\}:-%\{Packet-Src-IPv6-Address\}\}/reply-detail-%Y%m%d"\ \'a0 \'a0 \'a0 \'a0 header = "%t"\ \'a0 \'a0 \'a0 \'a0 permissions = 384\ \'a0 \'a0 \'a0 \'a0 locking = no\ \'a0 \'a0 \'a0 \'a0 escape_filenames = no\ \'a0 \'a0 \'a0 \'a0 log_packet_header = no\ \'a0 \}\ \'a0 # Loading module "pre_proxy_log" from file /etc/freeradius/mods-enabled/detail.log\ \'a0 detail pre_proxy_log \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/radacct/%\{%\{Packet-Src-IP-Address\}:-%\{Packet-Src-IPv6-Address\}\}/pre-proxy-detail-%Y%m%d"\ \'a0 \'a0 \'a0 \'a0 header = "%t"\ \'a0 \'a0 \'a0 \'a0 permissions = 384\ \'a0 \'a0 \'a0 \'a0 locking = no\ \'a0 \'a0 \'a0 \'a0 escape_filenames = no\ \'a0 \'a0 \'a0 \'a0 log_packet_header = no\ \'a0 \}\ \'a0 # Loading module "post_proxy_log" from file /etc/freeradius/mods-enabled/detail.log\ \'a0 detail post_proxy_log \{\ \'a0 \'a0 \'a0 \'a0 filename = "/var/log/freeradius/radacct/%\{%\{Packet-Src-IP-Address\}:-%\{Packet-Src-IPv6-Address\}\}/post-proxy-detail-%Y%m%d"\ \'a0 \'a0 \'a0 \'a0 header = "%t"\ \'a0 \'a0 \'a0 \'a0 permissions = 384\ \'a0 \'a0 \'a0 \'a0 locking = no\ \'a0 \'a0 \'a0 \'a0 escape_filenames = no\ \'a0 \'a0 \'a0 \'a0 log_packet_header = no\ \'a0 \}\ \'a0 # Loaded module rlm_files\ \'a0 # Loading module "files" from file /etc/freeradius/mods-enabled/files\ \'a0 files \{\ \'a0 \'a0 \'a0 \'a0 filename = "/etc/freeradius/mods-config/files/authorize"\ \'a0 \'a0 \'a0 \'a0 acctusersfile = "/etc/freeradius/mods-config/files/accounting"\ \'a0 \'a0 \'a0 \'a0 preproxy_usersfile = "/etc/freeradius/mods-config/files/pre-proxy"\ \'a0 \}\ \'a0 instantiate \{\ \'a0 \}\ \'a0 # Instantiating module "expiration" from file /etc/freeradius/mods-enabled/expiration\ \'a0 # Instantiating module "cache_eap" from file /etc/freeradius/mods-enabled/cache_eap\ rlm_cache (cache_eap): Driver rlm_cache_rbtree (module rlm_cache_rbtree) loaded and linked\ \'a0 # Instantiating module "linelog" from file /etc/freeradius/mods-enabled/linelog\ \'a0 # Instantiating module "log_accounting" from file /etc/freeradius/mods-enabled/linelog\ \'a0 # Instantiating module "mschap" from file /etc/freeradius/mods-enabled/mschap\ rlm_mschap (mschap): using internal authentication\ \'a0 # Instantiating module "pap" from file /etc/freeradius/mods-enabled/pap\ \'a0 # Instantiating module "reject" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "fail" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "ok" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "handled" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "invalid" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "userlock" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "notfound" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "noop" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "updated" from file /etc/freeradius/mods-enabled/always\ \'a0 # Instantiating module "preprocess" from file /etc/freeradius/mods-enabled/preprocess\ reading pairlist file /etc/freeradius/mods-config/preprocess/huntgroups\ reading pairlist file /etc/freeradius/mods-config/preprocess/hints\ \'a0 # Instantiating module "etc_passwd" from file /etc/freeradius/mods-enabled/passwd\ rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no\ \'a0 # Instantiating module "IPASS" from file /etc/freeradius/mods-enabled/realm\ \'a0 # Instantiating module "suffix" from file /etc/freeradius/mods-enabled/realm\ \'a0 # Instantiating module "realmpercent" from file /etc/freeradius/mods-enabled/realm\ \'a0 # Instantiating module "ntdomain" from file /etc/freeradius/mods-enabled/realm\ \'a0 # Instantiating module "ldap" from file /etc/freeradius/mods-enabled/ldap\ rlm_ldap: libldap vendor: OpenLDAP, version: 20442\ accounting \{\ \'a0 \'a0 \'a0 \'a0 reference = "%\{tolower:type.%\{Acct-Status-Type\}\}"\ \'a0\'a0 \}\ \'a0\'a0 post-auth \{\ \'a0 \'a0 \'a0 \'a0 reference = "."\ \'a0\'a0 \}\ rlm_ldap (ldap): Initialising connection pool\ \'a0\'a0 pool \{\ \'a0 \'a0 \'a0 \'a0 start = 5\ \'a0 \'a0 \'a0 \'a0 min = 3\ \'a0 \'a0 \'a0 \'a0 max = 32\ \'a0 \'a0 \'a0 \'a0 spare = 10\ \'a0 \'a0 \'a0 \'a0 uses = 0\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 cleanup_interval = 30\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 60\ \'a0 \'a0 \'a0 \'a0 retry_delay = 30\ \'a0 \'a0 \'a0 \'a0 spread = no\ \'a0\'a0 \}\ rlm_ldap (ldap): Opening additional connection (0), 1 of 32 pending slots used\ rlm_ldap (ldap): Connecting to ldap://localhost:389\ rlm_ldap (ldap): Waiting for bind result...\ rlm_ldap (ldap): Bind successful\ rlm_ldap (ldap): Opening additional connection (1), 1 of 31 pending slots used\ rlm_ldap (ldap): Connecting to ldap://localhost:389\ rlm_ldap (ldap): Waiting for bind result...\ rlm_ldap (ldap): Bind successful\ rlm_ldap (ldap): Opening additional connection (2), 1 of 30 pending slots used\ rlm_ldap (ldap): Connecting to ldap://localhost:389\ rlm_ldap (ldap): Waiting for bind result...\ rlm_ldap (ldap): Bind successful\ rlm_ldap (ldap): Opening additional connection (3), 1 of 29 pending slots used\ rlm_ldap (ldap): Connecting to ldap://localhost:389\ rlm_ldap (ldap): Waiting for bind result...\ rlm_ldap (ldap): Bind successful\ rlm_ldap (ldap): Opening additional connection (4), 1 of 28 pending slots used\ rlm_ldap (ldap): Connecting to ldap://localhost:389\ rlm_ldap (ldap): Waiting for bind result...\ rlm_ldap (ldap): Bind successful\ \'a0 # Instantiating module "eap" from file /etc/freeradius/mods-enabled/eap\ \'a0\'a0 # Linked to sub-module rlm_eap_md5\ \'a0\'a0 # Linked to sub-module rlm_eap_leap\ \'a0\'a0 # Linked to sub-module rlm_eap_gtc\ \'a0\'a0 gtc \{\ \'a0 \'a0 \'a0 \'a0 challenge = "Password: "\ \'a0 \'a0 \'a0 \'a0 auth_type = "PAP"\ \'a0\'a0 \}\ \'a0\'a0 # Linked to sub-module rlm_eap_tls\ \'a0\'a0 tls \{\ \'a0 \'a0 \'a0 \'a0 tls = "tls-common"\ \'a0\'a0 \}\ \'a0\'a0 tls-config tls-common \{\ \'a0 \'a0 \'a0 \'a0 verify_depth = 0\ \'a0 \'a0 \'a0 \'a0 ca_path = "/etc/freeradius/certs"\ \'a0 \'a0 \'a0 \'a0 pem_file_type = yes\ \'a0 \'a0 \'a0 \'a0 private_key_file = "/etc/freeradius/certs/server.pem"\ \'a0 \'a0 \'a0 \'a0 certificate_file = "/etc/freeradius/certs/server.pem"\ \'a0 \'a0 \'a0 \'a0 ca_file = "/etc/freeradius/certs/ca.pem"\ \'a0 \'a0 \'a0 \'a0 private_key_password = <<< secret >>>\ \'a0 \'a0 \'a0 \'a0 dh_file = "/etc/freeradius/certs/dh"\ \'a0 \'a0 \'a0 \'a0 fragment_size = 1024\ \'a0 \'a0 \'a0 \'a0 include_length = yes\ \'a0 \'a0 \'a0 \'a0 auto_chain = yes\ \'a0 \'a0 \'a0 \'a0 check_crl = no\ \'a0 \'a0 \'a0 \'a0 check_all_crl = no\ \'a0 \'a0 \'a0 \'a0 cipher_list = "DEFAULT"\ \'a0 \'a0 \'a0 \'a0 ecdh_curve = "prime256v1"\ cache \{\ \'a0 \'a0 \'a0 \'a0 enable = yes\ \'a0 \'a0 \'a0 \'a0 lifetime = 24\ \'a0 \'a0 \'a0 \'a0 max_entries = 255\ \'a0 \'a0 \}\ \'a0 \'a0 verify \{\ \'a0 \'a0 \'a0 \'a0 skip_if_ocsp_ok = no\ \'a0 \'a0 \}\ \'a0 \'a0 ocsp \{\ \'a0 \'a0 \'a0 \'a0 enable = no\ \'a0 \'a0 \'a0 \'a0 override_cert_url = yes\ \'a0 \'a0 \'a0 \'a0 url = "http://127.0.0.1/ocsp/"\ \'a0 \'a0 \'a0 \'a0 use_nonce = yes\ \'a0 \'a0 \'a0 \'a0 timeout = 0\ \'a0 \'a0 \'a0 \'a0 softfail = no\ \'a0 \'a0 \}\ \'a0\'a0 \}\ \'a0\'a0 # Linked to sub-module rlm_eap_ttls\ \'a0\'a0 ttls \{\ \'a0 \'a0 \'a0 \'a0 tls = "tls-common"\ \'a0 \'a0 \'a0 \'a0 default_eap_type = "md5"\ \'a0 \'a0 \'a0 \'a0 copy_request_to_tunnel = no\ \'a0 \'a0 \'a0 \'a0 use_tunneled_reply = no\ \'a0 \'a0 \'a0 \'a0 virtual_server = "inner-tunnel"\ \'a0 \'a0 \'a0 \'a0 include_length = yes\ \'a0 \'a0 \'a0 \'a0 require_client_cert = no\ \'a0\'a0 \}\ tls: Using cached TLS configuration from previous invocation\ \'a0\'a0 # Linked to sub-module rlm_eap_peap\ \'a0\'a0 peap \{\ \'a0 \'a0 \'a0 \'a0 tls = "tls-common"\ \'a0 \'a0 \'a0 \'a0 default_eap_type = "mschapv2"\ \'a0 \'a0 \'a0 \'a0 copy_request_to_tunnel = no\ \'a0 \'a0 \'a0 \'a0 use_tunneled_reply = no\ \'a0 \'a0 \'a0 \'a0 proxy_tunneled_request_as_eap = yes\ \'a0 \'a0 \'a0 \'a0 virtual_server = "inner-tunnel"\ \'a0 \'a0 \'a0 \'a0 soh = no\ \'a0 \'a0 \'a0 \'a0 require_client_cert = no\ \'a0\'a0 \}\ tls: Using cached TLS configuration from previous invocation\ \'a0\'a0 # Linked to sub-module rlm_eap_mschapv2\ \'a0\'a0 mschapv2 \{\ \'a0 \'a0 \'a0 \'a0 with_ntdomain_hack = no\ \'a0 \'a0 \'a0 \'a0 send_error = no\ \'a0\'a0 \}\ \'a0 # Instantiating module "logintime" from file /etc/freeradius/mods-enabled/logintime\ \'a0 # Instantiating module "attr_filter.post-proxy" from file /etc/freeradius/mods-enabled/attr_filter\ reading pairlist file /etc/freeradius/mods-config/attr_filter/post-proxy\ \'a0 # Instantiating module "attr_filter.pre-proxy" from file /etc/freeradius/mods-enabled/attr_filter\ reading pairlist file /etc/freeradius/mods-config/attr_filter/pre-proxy\ \'a0 # Instantiating module "attr_filter.access_reject" from file /etc/freeradius/mods-enabled/attr_filter\ reading pairlist file /etc/freeradius/mods-config/attr_filter/access_reject\ [/etc/freeradius/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay" \'a0 \'a0 \'a0 found in filter list for realm "DEFAULT".\ [/etc/freeradius/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay-USec"\'a0 found in filter list for realm "DEFAULT".\ \'a0 # Instantiating module "attr_filter.access_challenge" from file /etc/freeradius/mods-enabled/attr_filter\ reading pairlist file /etc/freeradius/mods-config/attr_filter/access_challenge\ \'a0 # Instantiating module "attr_filter.accounting_response" from file /etc/freeradius/mods-enabled/attr_filter\ reading pairlist file /etc/freeradius/mods-config/attr_filter/accounting_response\ \'a0 # Instantiating module "detail" from file /etc/freeradius/mods-enabled/detail\ \'a0 # Instantiating module "auth_log" from file /etc/freeradius/mods-enabled/detail.log\ rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output\ \'a0 # Instantiating module "reply_log" from file /etc/freeradius/mods-enabled/detail.log\ \'a0 # Instantiating module "pre_proxy_log" from file /etc/freeradius/mods-enabled/detail.log\ \'a0 # Instantiating module "post_proxy_log" from file /etc/freeradius/mods-enabled/detail.log\ \'a0 # Instantiating module "files" from file /etc/freeradius/mods-enabled/files\ reading pairlist file /etc/freeradius/mods-config/files/authorize\ reading pairlist file /etc/freeradius/mods-config/files/accounting\ reading pairlist file /etc/freeradius/mods-config/files/pre-proxy\ \'a0\} # modules\ radiusd: #### Loading Virtual Servers ####\ server \{ # from file /etc/freeradius/radiusd.conf\ \} # server\ server default \{ # from file /etc/freeradius/sites-enabled/default\ \'a0# Loading authenticate \{...\}\ \'a0# Loading authorize \{...\}\ Ignoring "sql" (see raddb/mods-available/README.rst)\ \'a0# Loading preacct \{...\}\ \'a0# Loading accounting \{...\}\ \'a0# Loading post-proxy \{...\}\ \'a0# Loading post-auth \{...\}\ \} # server default\ server inner-tunnel \{ # from file /etc/freeradius/sites-enabled/inner-tunnel\ \'a0# Loading authenticate \{...\}\ \'a0# Loading authorize \{...\}\ \'a0# Loading session \{...\}\ \'a0# Loading post-proxy \{...\}\ \'a0# Loading post-auth \{...\}\ \} # server inner-tunnel\ radiusd: #### Opening IP addresses and Ports ####\ listen \{\ \'a0 \'a0 \'a0 \'a0 type = "auth"\ \'a0 \'a0 \'a0 \'a0 ipaddr = *\ \'a0 \'a0 \'a0 \'a0 port = 0\ \'a0\'a0 limit \{\ \'a0 \'a0 \'a0 \'a0 max_connections = 16\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 30\ \'a0\'a0 \}\ \}\ listen \{\ \'a0 \'a0 \'a0 \'a0 type = "acct"\ \'a0 \'a0 \'a0 \'a0 ipaddr = *\ \'a0 \'a0 \'a0 \'a0 port = 0\ \'a0\'a0 limit \{\ \'a0 \'a0 \'a0 \'a0 max_connections = 16\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 30\ \'a0\'a0 \}\ \}\ listen \{\ \'a0 \'a0 \'a0 \'a0 type = "auth"\ \'a0 \'a0 \'a0 \'a0 ipv6addr = ::\ \'a0 \'a0 \'a0 \'a0 port = 0\ \'a0\'a0 limit \{\ \'a0 \'a0 \'a0 \'a0 max_connections = 16\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 30\ \'a0\'a0 \}\ \}\ listen \{\ \'a0 \'a0 \'a0 \'a0 type = "acct"\ \'a0 \'a0 \'a0 \'a0 ipv6addr = ::\ \'a0 \'a0 \'a0 \'a0 port = 0\ \'a0\'a0 limit \{\ \'a0 \'a0 \'a0 \'a0 max_connections = 16\ \'a0 \'a0 \'a0 \'a0 lifetime = 0\ \'a0 \'a0 \'a0 \'a0 idle_timeout = 30\ \'a0\'a0 \}\ \}\ listen \{\ \'a0 \'a0 \'a0 \'a0 type = "auth"\ \'a0 \'a0 \'a0 \'a0 ipaddr = 127.0.0.1\ \'a0 \'a0 \'a0 \'a0 port = 18120\ \}\ Listening on auth address * port 1812 bound to server default\ Listening on acct address * port 1813 bound to server default\ Listening on auth address :: port 1812 bound to server default\ Listening on acct address :: port 1813 bound to server default\ Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel\ Listening on proxy address * port 57287\ Listening on proxy address :: port 54856\ Ready to process requests\ \ \ (0) Received Access-Request Id 0 from 10.155.20.172:40396 to 10.155.20.244:1812 length 165\ (0) \'a0 User-Name = "spircher"\ (0) \'a0 NAS-Identifier = "802aa8c6e2bd"\ (0) \'a0 NAS-Port = 0\ (0) \'a0 Called-Station-Id = "82-2A-A8-C7-E2-BD:jbh-test"\ (0) \'a0 Calling-Station-Id = "78-4F-43-6D-09-48"\ (0) \'a0 Framed-MTU = 1400\ (0) \'a0 NAS-Port-Type = Wireless-802.11\ (0) \'a0 Connect-Info = "CONNECT 0Mbps 802.11b"\ (0) \'a0 EAP-Message = 0x0267000d017370697263686572\ (0) \'a0 Message-Authenticator = 0x737f2de7ea21d8d1a09fee4473c7bf35\ (0) # Executing section authorize from file /etc/freeradius/sites-enabled/default\ (0) \'a0 authorize \{\ (0) \'a0 \'a0 policy filter_username \{\ (0) \'a0 \'a0 \'a0 if (&User-Name) \{\ (0) \'a0 \'a0 \'a0 if (&User-Name)\'a0 -> TRUE\ (0) \'a0 \'a0 \'a0 if (&User-Name)\'a0 \{\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ / /) \{\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ / /)\'a0 -> FALSE\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@[^@]*@/ ) \{\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@[^@]*@/ )\'a0 -> FALSE\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.\\./ ) \{\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.\\./ )\'a0 -> FALSE\ (0) \'a0 \'a0 \'a0 \'a0 if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\\.(.+)$/))\'a0 \{\ (0) \'a0 \'a0 \'a0 \'a0 if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\\.(.+)$/)) \'a0 -> FALSE\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.$/)\'a0 \{\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.$/) \'a0 -> FALSE\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@\\./)\'a0 \{\ (0) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@\\./) \'a0 -> FALSE\ (0) \'a0 \'a0 \'a0 \} # if (&User-Name)\'a0 = notfound\ (0) \'a0 \'a0 \} # policy filter_username = notfound\ (0) \'a0 \'a0 [preprocess] = ok\ (0) \'a0 \'a0 [chap] = noop\ (0) \'a0 \'a0 [mschap] = noop\ (0) \'a0 \'a0 [digest] = noop\ (0) suffix: Checking for suffix after "@"\ (0) suffix: No '@' in User-Name = "spircher", looking up realm NULL\ (0) suffix: No such realm "NULL"\ (0) \'a0 \'a0 [suffix] = noop\ (0) eap: Peer sent EAP Response (code 2) ID 103 length 13\ (0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize\ (0) \'a0 \'a0 [eap] = ok\ (0) \'a0 \} # authorize = ok\ (0) Found Auth-Type = eap\ (0) # Executing group from file /etc/freeradius/sites-enabled/default\ (0) \'a0 authenticate \{\ (0) eap: Peer sent packet with method EAP Identity (1)\ (0) eap: Calling submodule eap_md5 to process data\ (0) eap_md5: Issuing MD5 Challenge\ (0) eap: Sending EAP Request (code 1) ID 104 length 22\ (0) eap: EAP session adding &reply:State = 0xf4d3fdbff4bbf98c\ (0) \'a0 \'a0 [eap] = handled\ (0) \'a0 \} # authenticate = handled\ (0) Using Post-Auth-Type Challenge\ (0) Post-Auth-Type sub-section not found.\'a0 Ignoring.\ (0) # Executing group from file /etc/freeradius/sites-enabled/default\ (0) Sent Access-Challenge Id 0 from 10.155.20.244:1812 to 10.155.20.172:40396 length 0\ (0) \'a0 EAP-Message = 0x01680016041088946b2d842601f33cf01dc8ec023209\ (0) \'a0 Message-Authenticator = 0x00000000000000000000000000000000\ (0) \'a0 State = 0xf4d3fdbff4bbf98c70a9e15ab483361a\ (0) Finished request\ Waking up in 4.9 seconds.\ (1) Received Access-Request Id 1 from 10.155.20.172:40396 to 10.155.20.244:1812 length 178\ (1) \'a0 User-Name = "spircher"\ (1) \'a0 NAS-Identifier = "802aa8c6e2bd"\ (1) \'a0 NAS-Port = 0\ (1) \'a0 Called-Station-Id = "82-2A-A8-C7-E2-BD:jbh-test"\ (1) \'a0 Calling-Station-Id = "78-4F-43-6D-09-48"\ (1) \'a0 Framed-MTU = 1400\ (1) \'a0 NAS-Port-Type = Wireless-802.11\ (1) \'a0 Connect-Info = "CONNECT 0Mbps 802.11b"\ (1) \'a0 EAP-Message = 0x026800080319152b\ (1) \'a0 State = 0xf4d3fdbff4bbf98c70a9e15ab483361a\ (1) \'a0 Message-Authenticator = 0xfee7f8ba3799f594a163a7636f4c9325\ (1) session-state: No cached attributes\ (1) # Executing section authorize from file /etc/freeradius/sites-enabled/default\ (1) \'a0 authorize \{\ (1) \'a0 \'a0 policy filter_username \{\ (1) \'a0 \'a0 \'a0 if (&User-Name) \{\ (1) \'a0 \'a0 \'a0 if (&User-Name)\'a0 -> TRUE\ (1) \'a0 \'a0 \'a0 if (&User-Name)\'a0 \{\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ / /) \{\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ / /)\'a0 -> FALSE\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@[^@]*@/ ) \{\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@[^@]*@/ )\'a0 -> FALSE\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.\\./ ) \{\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.\\./ )\'a0 -> FALSE\ (1) \'a0 \'a0 \'a0 \'a0 if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\\.(.+)$/))\'a0 \{\ (1) \'a0 \'a0 \'a0 \'a0 if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\\.(.+)$/)) \'a0 -> FALSE\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.$/)\'a0 \{\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.$/) \'a0 -> FALSE\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@\\./)\'a0 \{\ (1) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@\\./) \'a0 -> FALSE\ (1) \'a0 \'a0 \'a0 \} # if (&User-Name)\'a0 = notfound\ (1) \'a0 \'a0 \} # policy filter_username = notfound\ (1) \'a0 \'a0 [preprocess] = ok\ (1) \'a0 \'a0 [chap] = noop\ (1) \'a0 \'a0 [mschap] = noop\ (1) \'a0 \'a0 [digest] = noop\ (1) suffix: Checking for suffix after "@"\ (1) suffix: No '@' in User-Name = "spircher", looking up realm NULL\ (1) suffix: No such realm "NULL"\ (1) \'a0 \'a0 [suffix] = noop\ (1) eap: Peer sent EAP Response (code 2) ID 104 length 8\ (1) eap: No EAP Start, assuming it's an on-going EAP conversation\ (1) \'a0 \'a0 [eap] = updated\ (1) \'a0 \'a0 [files] = noop\ rlm_ldap (ldap): Reserved connection (0)\ (1) ldap: EXPAND (uid=%\{%\{Stripped-User-Name\}:-%\{User-Name\}\})\ (1) ldap:\'a0 \'a0 --> (uid=spircher)\ (1) ldap: Performing search in "dc=jacob-balde,dc=de" with filter "(uid=spircher)", scope "sub"\ (1) ldap: Waiting for search result...\ (1) ldap: User object found at DN "cn=spircher,ou=bewohner,dc=jacob-balde,dc=de"\ (1) ldap: Processing user attributes\ (1) ldap: control:Password-With-Header += '\{SSHA\}Kn25t6Jhrvm6WxYV19/+1+lEUyPI3csa'\ rlm_ldap (ldap): Released connection (0)\ rlm_ldap (ldap): Need 5 more connections to reach 10 spares\ rlm_ldap (ldap): Opening additional connection (5), 1 of 27 pending slots used\ rlm_ldap (ldap): Connecting to ldap://localhost:389\ rlm_ldap (ldap): Waiting for bind result...\ rlm_ldap (ldap): Bind successful\ (1) \'a0 \'a0 [ldap] = updated\ (1) \'a0 \'a0 [expiration] = noop\ (1) \'a0 \'a0 [logintime] = noop\ (1) pap: Converted: &control:Password-With-Header -> &control:SSHA1-Password\ (1) pap: Removing &control:Password-With-Header\ (1) pap: Normalizing SSHA1-Password from base64 encoding, 32 bytes -> 24 bytes\ (1) pap: WARNING: Auth-Type already set.\'a0 Not setting to PAP\ (1) \'a0 \'a0 [pap] = noop\ (1) \'a0 \} # authorize = updated\ (1) Found Auth-Type = eap\ (1) # Executing group from file /etc/freeradius/sites-enabled/default\ (1) \'a0 authenticate \{\ (1) eap: Expiring EAP session with state 0xf4d3fdbff4bbf98c\ (1) eap: Finished EAP session with state 0xf4d3fdbff4bbf98c\ (1) eap: Previous EAP request found for state 0xf4d3fdbff4bbf98c, released from the list\ (1) eap: Peer sent packet with method EAP NAK (3)\ (1) eap: Found mutually acceptable type PEAP (25)\ (1) eap: Calling submodule eap_peap to process data\ (1) eap_peap: Initiating new EAP-TLS session\ (1) eap_peap: Flushing SSL sessions (of #0)\ (1) eap_peap: [eaptls start] = request\ (1) eap: Sending EAP Request (code 1) ID 105 length 6\ (1) eap: EAP session adding &reply:State = 0xf4d3fdbff5bae48c\ (1) \'a0 \'a0 [eap] = handled\ (1) \'a0 \} # authenticate = handled\ (1) Using Post-Auth-Type Challenge\ (1) Post-Auth-Type sub-section not found.\'a0 Ignoring.\ (1) # Executing group from file /etc/freeradius/sites-enabled/default\ (1) Sent Access-Challenge Id 1 from 10.155.20.244:1812 to 10.155.20.172:40396 length 0\ (1) \'a0 EAP-Message = 0x016900061920\ (1) \'a0 Message-Authenticator = 0x00000000000000000000000000000000\ (1) \'a0 State = 0xf4d3fdbff5bae48c70a9e15ab483361a\ (1) Finished request\ Waking up in 4.9 seconds.\ (2) Received Access-Request Id 2 from 10.155.20.172:40396 to 10.155.20.244:1812 length 297\ (2) \'a0 User-Name = "spircher"\ (2) \'a0 NAS-Identifier = "802aa8c6e2bd"\ (2) \'a0 NAS-Port = 0\ (2) \'a0 Called-Station-Id = "82-2A-A8-C7-E2-BD:jbh-test"\ (2) \'a0 Calling-Station-Id = "78-4F-43-6D-09-48"\ (2) \'a0 Framed-MTU = 1400\ (2) \'a0 NAS-Port-Type = Wireless-802.11\ (2) \'a0 Connect-Info = "CONNECT 0Mbps 802.11b"\ (2) \'a0 EAP-Message = 0x0269007f19800000007516030100700100006c0301591dbfc314ded933c42104b3573352056128a6615a57164bb94b8552d27b8bcc00002000ffc024c023c00ac009c008c028c027c014c013c012003d003c0035002f000a01000023000a00080006001700180019000b00020100000500050100000000\ (2) \'a0 State = 0xf4d3fdbff5bae48c70a9e15ab483361a\ (2) \'a0 Message-Authenticator = 0x487f097aeddf0a3e5bf0aef47e3b2edd\ (2) session-state: No cached attributes\ (2) # Executing section authorize from file /etc/freeradius/sites-enabled/default\ (2) \'a0 authorize \{\ (2) \'a0 \'a0 policy filter_username \{\ (2) \'a0 \'a0 \'a0 if (&User-Name) \{\ (2) \'a0 \'a0 \'a0 if (&User-Name)\'a0 -> TRUE\ (2) \'a0 \'a0 \'a0 if (&User-Name)\'a0 \{\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ / /) \{\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ / /)\'a0 -> FALSE\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@[^@]*@/ ) \{\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@[^@]*@/ )\'a0 -> FALSE\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.\\./ ) \{\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.\\./ )\'a0 -> FALSE\ (2) \'a0 \'a0 \'a0 \'a0 if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\\.(.+)$/))\'a0 \{\ (2) \'a0 \'a0 \'a0 \'a0 if ((&User-Name =~ /@/) && (&User-Name !~ /@(.+)\\.(.+)$/)) \'a0 -> FALSE\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.$/)\'a0 \{\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /\\.$/) \'a0 -> FALSE\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@\\./)\'a0 \{\ (2) \'a0 \'a0 \'a0 \'a0 if (&User-Name =~ /@\\./) \'a0 -> FALSE\ (2) \'a0 \'a0 \'a0 \} # if (&User-Name)\'a0 = notfound\ (2) \'a0 \'a0 \} # policy filter_username = notfound\ (2) \'a0 \'a0 [preprocess] = ok\ (2) \'a0 \'a0 [chap] = noop\ (2) \'a0 \'a0 [mschap] = noop\ (2) \'a0 \'a0 [digest] = noop\ (2) suffix: Checking for suffix after "@"\ (2) suffix: No '@' in User-Name = "spircher", looking up realm NULL\ (2) suffix: No such realm "NULL"\ (2) \'a0 \'a0 [suffix] = noop\ (2) eap: Peer sent EAP Response (code 2) ID 105 length 127\ (2) eap: Continuing tunnel setup\ (2) \'a0 \'a0 [eap] = ok\ (2) \'a0 \} # authorize = ok\ (2) Found Auth-Type = eap\ (2) # Executing group from file /etc/freeradius/sites-enabled/default\ (2) \'a0 authenticate \{\ (2) eap: Expiring EAP session with state 0xf4d3fdbff5bae48c\ (2) eap: Finished EAP session with state 0xf4d3fdbff5bae48c\ (2) eap: Previous EAP request found for state 0xf4d3fdbff5bae48c, released from the list\ (2) eap: Peer sent packet with method EAP PEAP (25)\ (2) eap: Calling submodule eap_peap to process data\ (2) eap_peap: Continuing EAP-TLS\ (2) eap_peap: Peer indicated complete TLS record size will be 117 bytes\ (2) eap_peap: Got complete TLS record (117 bytes)\ (2) eap_peap: [eaptls verify] = length included\ (2) eap_peap: (other): before/accept initialization\ (2) eap_peap: TLS_accept: before/accept initialization\ (2) eap_peap: <<< recv TLS 1.0 Handshake [length 0070], ClientHello\ (2) eap_peap: TLS_accept: unknown state\ (2) eap_peap: >>> send TLS 1.0 Handshake [length 0059], ServerHello\ (2) eap_peap: TLS_accept: unknown state\ (2) eap_peap: >>> send TLS 1.0 Handshake [length 08d4], Certificate\ (2) eap_peap: TLS_accept: unknown state\ (2) eap_peap: >>> send TLS 1.0 Handshake [length 014b], ServerKeyExchange\ (2) eap_peap: TLS_accept: unknown state\ (2) eap_peap: >>> send TLS 1.0 Handshake [length 0004], ServerHelloDone\ (2) eap_peap: TLS_accept: unknown state\ (2) eap_peap: TLS_accept: unknown state\ (2) eap_peap: TLS_accept: unknown state\ (2) eap_peap: TLS_accept: Need to read more data: unknown state\ (2) eap_peap: TLS_accept: Need to read more data: unknown state\ (2) eap_peap: In SSL Handshake Phase\ (2) eap_peap: In SSL Accept mode\ (2) eap_peap: [eaptls process] = handled\ (2) eap: Sending EAP Request (code 1) ID 106 length 1004\ (2) eap: EAP session adding &reply:State = 0xf4d3fdbff6b9e48c\ (2) \'a0 \'a0 [eap] = handled\ (2) \'a0 \} # authenticate = handled\ (2) Using Post-Auth-Type Challenge\ (2) Post-Auth-Type sub-section not found.\'a0 Ignoring.\ (2) # Executing group from file /etc/freeradius/sites-enabled/default\ (2) Sent Access-Challenge Id 2 from 10.155.20.244:1812 to 10.155.20.172:40396 length 0\ (2) \'a0 EAP-Message = 0x016a03ec19c000000a901603010059020000550301d897975b7a06a66e749f2751fbbaca705f5ed0bbf9918fea6ef054bf7e632b15204d589ad1cae5ee8b56bd79e91a58ee6a0ebf235a644d777e24e526bdd2e6fb24c01400000dff01000100000b00040300010216030108d40b0008d00008cd0003df\ (2) \'a0 Message-Authenticator = 0x00000000000000000000000000000000\ (2) \'a0 State = 0xf4d3fdbff6b9e48c70a9e15ab483361a\ (2) Finished request\ Waking up in 4.9 seconds.\ \ }