Freeradius-Users
Threads by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
June 2018
- 73 participants
- 85 discussions
All,
I've got authentication working nicely with MSCHAP, but now I'd like to
only allow users that are members of a certain AD group.
I would prefer to have this happen only when requests come from a
specific client (wireless access point). In this case the idea is to
have users only be able to get wireless access when they're in a
specific AD group.
How can I do this in freeradius?
Thanks,
Brian
7
18
Hi,
I've tried to find a way of detail logging the packets sent by
freeradius to the client in the authentication phase but didn't found
a way of doing it. Maybe I've not looked correctly so I'm asking if
it's actually possible?
I was able to log detailed packets sent by the client (Response
packets) but not the ones sent by freeradius to the client (except
accounting and proxied ones).
Thanks for your time.
Jean-François Mousinho
4
6
Hi,
Freeradius Version: 3.0
I had a question about EAP-SIM. We previously got EAP-SIM to work on the
Free-radius version 2. But once we upgraded to 3.0, we saw the
rlm_sim_files has been deprecated and now we need to use rlm_passwd.
I made the following changes the config files:
1. eap - added to the eap{}
sim {
}
2. Changed passwd file under mods-enabled:
passwd passwd {
filename = /usr/local/etc/raddb/simtriplets.dat
format = "*User-Name:User-Password"
hash_size = 100
ignore_nislike = no
allow_multiple_keys = no
}
/usr/local/etc/raddb/simtriplets.dat:
1001010123456789@wlan.mnc001.mcc001.3gppnetwork.org:2
ADE1426F93045258CCD7B9CF739CD51:CA1a6a73:44163dcd3063ee06
1001010123456789(a)wlan.mnc001.mcc001.3gppnetwork.org:
A7DB577E986F41e999981FE01E8E9351:9E0ec181:2B3182377B3d2e05
1001010123456789@wlan.mnc001.mcc001.3gppnetwork.org:92
F13B6BB93641b0914DD3D6DAAFB78C:9Ca5541a:767e395d867fa4b0
1001010123456789@wlan.mnc001.mcc001.3gppnetwork.org:3
D6978EEB53E4c9f94F116A4AFC15EEC:09381b57:68fca592D475ada8
1001010123456789@wlan.mnc001.mcc001.3gppnetwork.org:56
F874F6F0C543c6B1D54CCE3B425E2B:3Ce1debe:4B16c28f5D165ab6
3. Added passwd in authorize section in default file under sites-available:
passwd
eap {
ok = return
}
The radiusd starts up fine with this configuration. But when I run the SIM
test, I see the following error:
*eap_sim: ERROR: EAP-SIM-RAND1 not found*
Is there any documentation on how to setup rlm_passwd for EAP-SIM?
Any help in this regard would be appreciated.
Thanks
Siddharth (Wifi Test, Google inc)
6
242
Hello,I am a freeRADIUS 2.x user and want to start using freeRADIUS 3.x.xI have installed freeRADIUS 3.0.9 and done a lot of reading since I want to avoid being told to "RTFM"I can't seem to get an Access-Accept when I do a radtest for MySQL users. I'm sure I'm missing something (still adjusting to the difference between the two version). Can someone help or point me in the right direction? Below is my debug:(1) Received Access-Request Id 121 from 127.0.0.1:35861 to 127.0.0.1:1812 length 72
(1) User-Name = "me"
(1) User-Password = "pass"
(1) NAS-IP-Address = 127.0.1.1
(1) NAS-Port = 0
(1) Message-Authenticator = 0xd9c706bfd54e51cd4eab51d9e19e4da2
(1) # Executing section authorize from file /usr/local/etc/raddb/sites-enabled/default
(1) authorize {
(1) policy filter_username {
(1) if (!&User-Name) {
(1) if (!&User-Name) -> FALSE
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@.*@/ ) {
(1) if (&User-Name =~ /@.*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # policy filter_username = notfound
(1) [preprocess] = ok
(1) [chap] = noop
(1) suffix: Checking for suffix after "@"
(1) suffix: No '@' in User-Name = "me", looking up realm NULL
(1) suffix: No such realm "NULL"
(1) [suffix] = noop
(1) [files] = noop
(1) sql: EXPAND %{User-Name}
(1) sql: --> me
(1) sql: SQL-User-Name set to 'me'
rlm_sql (sql): Closing connection (3): Hit idle_timeout, was idle for 252 seconds
rlm_sql (sql): Closing connection (4): Hit idle_timeout, was idle for 252 seconds
rlm_sql (sql): Closing connection (0): Hit idle_timeout, was idle for 252 seconds
rlm_sql (sql): Closing connection (5): Hit idle_timeout, was idle for 252 seconds
rlm_sql (sql): Closing connection (1): Hit idle_timeout, was idle for 244 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql (sql): Closing connection (6): Hit idle_timeout, was idle for 244 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql (sql): Closing connection (2): Hit idle_timeout, was idle for 244 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql (sql): 0 of 0 connections in use. You may need to increase "spare"
rlm_sql (sql): Opening additional connection (7), 1 of 32 pending slots used
rlm_sql (sql): Reserved connection (7)
(1) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(1) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'me' ORDER BY id
(1) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'me' ORDER BY id
rlm_sql (sql): Released connection (7)
rlm_sql (sql): 0 of 1 connections in use. Need more spares
rlm_sql (sql): Opening additional connection (8), 1 of 31 pending slots used
(1) [sql] = notfound
(1) [expiration] = noop
(1) [logintime] = noop
(1) } # authorize = ok
(1) ERROR: No Auth-Type found: rejecting the user via Post-Auth-Type = Reject
(1) Failed to authenticate the user
(1) Using Post-Auth-Type Reject
(1) # Executing group from file /usr/local/etc/raddb/sites-enabled/default
(1) Post-Auth-Type REJECT {
(1) sql: EXPAND .query
(1) sql: --> .query
(1) sql: Using query template 'query'
rlm_sql (sql): Reserved connection (7)
(1) sql: EXPAND %{User-Name}
(1) sql: --> me
(1) sql: SQL-User-Name set to 'me'
(1) sql: EXPAND INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( '%{SQL-User-Name}', '%{%{User-Password}:-%{Chap-Password}}', '%{reply:Packet-Type}', '%S')
(1) sql: --> INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( 'me', 'pass', 'Access-Reject', '2015-07-12 23:21:17')
(1) sql: Executing query: INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( 'me', 'pass', 'Access-Reject', '2015-07-12 23:21:17')
(1) sql: SQL query returned: success
(1) sql: 1 record(s) updated
rlm_sql (sql): Released connection (7)
(1) [sql] = ok
(1) attr_filter.access_reject: EXPAND %{User-Name}
(1) attr_filter.access_reject: --> me
(1) attr_filter.access_reject: Matched entry DEFAULT at line 18
(1) [attr_filter.access_reject] = updated
(1) eap: Request didn't contain an EAP-Message, not inserting EAP-Failure
(1) [eap] = noop
(1) policy remove_reply_message_if_eap {
(1) if (&reply:EAP-Message && &reply:Reply-Message) {
(1) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(1) else {
(1) [noop] = noop
(1) } # else = noop
(1) } # policy remove_reply_message_if_eap = noop
(1) } # Post-Auth-Type REJECT = updated
(1) Delaying response for 1.000000 seconds
Waking up in 0.3 seconds.
Waking up in 0.6 seconds.
(1) <delay>: Sending delayed response
(1) <delay>: Sent Access-Reject Id 121 from 127.0.0.1:1812 to 127.0.0.1:35861 length 20
Waking up in 3.9 seconds.
(1) <delay>: Cleaning up request packet ID 121 with timestamp +252
Thanks in advance
6
92
I'm sure you're reading the subject going "ugh not another one". But there is so much documentation out there and all of it slightly different that I don't know which end is up at this point. I would like to use FreeRADIUS to authenticate VPN users and wireless, and I'm working on VPN right now. From what I understand so far, I want to use LDAP to check if the person is in the right group first, and if not reject them. If they are in the right group then authenticate using ntlm_auth. I am also understanding that the place to do this is no longer the users/authorize file and that it should be done in the 'default' file using 'unlang'. Is this correct so far? If so, can someone give me an example of the 'unlang' portion?
6
36
I'm running a CentOS 7 environment and I just did a fresh install of v3.0.9 of FreeRADIUS. I also installed version 1.0.2d of openssl so I'm not subject to heartbleed. When I installed the ldap module, yum downloaded version 3.0.4 and also installed a heartbleed vulnerable version of openssl and broke my install. I know how to patch radiusd.conf for the heartbleed vulnerability but I'd rather not. So I removed the ldap module, re-installed openssl 1.0.2d and recompiled FreeRADIUS. Is there a repo that will provide me with a 3.0.9 version of the ldap module? If not, can I compile and point to my lib directory for openssl 1.0.2d instead? Yum downloads an RPM and I don't know of a way to simply extract that, so I am looking for a way to compile from source for either version 3.0.4 or 3.0.9 if it exists. Don't know where to look for the source(s).
4
7
Hello,I'm using freeRADIUS 3.0.9I use the sql module to do AAAI currently want to use unlang to do the following.Assuming there a user called "bob" who has the password "pass"I want unlung to compare the username and password in such a way thatif username is "bob" and password is not "pass" a Reply-Message such as
"Incorrect password for user "bob" " will be sent. This scenario is for only if the username bob exists.If username "bob" does not exist the a Reply-Message = "User "bob" not found"
Can someone help me with the unlang which will do this?
2
1
How can I further troubleshoot what might be the cause for my query against LDAP to return no results? I have verified the following from debugging and testing:
[ ... SNIP ... ]
# Loaded module rlm_ldap
# Instantiating module "ldap" from file /etc/raddb/mods-enabled/ldap
ldap {
server = "dc01.myDomain.com"
port = 3268
password = <<< secret >>>
identity = "CN=Free RADIUS,CN=Users,DC=myDomain,DC=com"
user {
filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
scope = "sub"
base_dn = "DC=myDomain,DC=com"
access_positive = yes
}
group {
filter = "(objectClass=posixGroup)"
scope = "sub"
base_dn = "DC=myDomain,DC=com"
name_attribute = "cn"
membership_attribute = "memberOf"
membership_filter = "(|(member=%{control:Ldap-UserDn})(memberUid=%{%{Stripped-User-Name}:-%{User-Name}}))"
cacheable_name = no
cacheable_dn = no
}
client {
filter = "(objectClass=frClient)"
scope = "sub"
base_dn = "DC=myDomain,DC=com"
attribute {
identifier = "radiusClientIdentifier"
shortname = "cn"
secret = "radiusClientSecret"
}
}
profile {
filter = "(&)"
}
options {
ldap_debug = 40
chase_referrals = yes
rebind = yes
net_timeout = 1
res_timeout = 20
srv_timelimit = 20
idle = 60
probes = 3
interval = 3
}
tls {
start_tls = no
}
}
rlm_ldap: Falling back to build time libldap version info. Query for LDAP_OPT_API_INFO returned: -1
rlm_ldap: libldap vendor: OpenLDAP version: 20439
accounting {
reference = "%{tolower:type.%{Acct-Status-Type}}"
}
post-auth {
reference = "."
}
rlm_ldap (ldap): Initialising connection pool
pool {
start = 5
min = 4
max = 32
spare = 3
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 1
spread = no
}
rlm_ldap (ldap): Opening additional connection (0)
rlm_ldap (ldap): Connecting to dc01.myDomain.com:3268
rlm_ldap (ldap): Waiting for bind result...
>>rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (1)
rlm_ldap (ldap): Connecting to dc01.myDomain.com:3268
rlm_ldap (ldap): Waiting for bind result...
>>rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (2)
rlm_ldap (ldap): Connecting to dc01.myDomain.com:3268
rlm_ldap (ldap): Waiting for bind result...
>>rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (3)
rlm_ldap (ldap): Connecting to dc01.myDomain.com:3268
rlm_ldap (ldap): Waiting for bind result...
>>rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (4)
rlm_ldap (ldap): Connecting to dc01.myDomain.com:3268
rlm_ldap (ldap): Waiting for bind result...
>>rlm_ldap (ldap): Bind successful
} # modules
[ ... SNIP ... ]
So it appears to be binding to LDAP ok. I am binding on port 3268 to reference the global catalog and search sub-domains.
[ ... SNIP ... ]
Ready to process requests
Received Access-Request Id 32 from 172.18.1.2:1025 to 172.18.2.100:1812 length 66
User-Name = 'spickles'
User-Password = '****'
NAS-IP-Address = 172.18.1.2
NAS-Port = 32
NAS-Port-Type = Virtual
(1) Received Access-Request packet from host 172.18.1.2 port 1025, id=32, length=66
(1) User-Name = 'spickles'
(1) User-Password = '****'
(1) NAS-IP-Address = 172.18.1.2
(1) NAS-Port = 32
(1) NAS-Port-Type = Virtual
(1) # Executing section authorize from file /etc/raddb/sites-enabled/default
(1) authorize {
(1) [preprocess] = ok
(1) rewrite_calling_station_id rewrite_calling_station_id {
(1) if (&Calling-Station-Id =~ /^([0-9a-f]{2})[^0-9a-f]?([0-9a-f]{2})[^0-9a-f]?([0-9a-f]{2})[^0-9a-f]?([0-9a-f]{2})[^0-9a-f]?([0-9a-f]{2})[^0-9a-f]?([0-9a-f]{2})$/i)
(1) ERROR: Failed retrieving values required to evaluate condition
(1) else else {
(1) [noop] = noop
(1) } # else else = noop
(1) } # rewrite_calling_station_id rewrite_calling_station_id = noop
(1) eap : No EAP-Message, not doing EAP
(1) [eap] = noop
(1) [files] = noop
rlm_ldap (ldap): Reserved connection (4)
(1) ldap : EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(1) ldap : --> (uid=spickles)
(1) ldap : EXPAND DC=myDomain,DC=COM
(1) ldap : --> DC=myDomain,DC=COM
(1) ldap : Performing search in 'DC=myDomain,DC=COM' with filter '(uid=spickles)', scope 'sub'
(1) ldap : Waiting for search result...
>> (1) ldap : Search returned no results
rlm_ldap (ldap): Released connection (4)
rlm_ldap (ldap): 0 of 1 connections in use. Need more spares
rlm_ldap (ldap): Opening additional connection (5)
rlm_ldap (ldap): Connecting to rochdc01.myDomain.com:3268
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
>>(1) [ldap] = notfound
(1) } # authorize = ok
(1) ERROR: No Auth-Type found: rejecting the user via Post-Auth-Type = Reject
(1) Failed to authenticate the user
(1) Login incorrect (Failed retrieving values required to evaluate condition): [spickles/****] (from client <<client_short_name>> port 32)
(1) Using Post-Auth-Type Reject
(1) # Executing group from file /etc/raddb/sites-enabled/default
(1) Post-Auth-Type REJECT {
(1) attr_filter.access_reject : EXPAND %{User-Name}
(1) attr_filter.access_reject : --> spickles
(1) attr_filter.access_reject : Matched entry DEFAULT at line 11
(1) [attr_filter.access_reject] = updated
(1) eap : Request didn't contain an EAP-Message, not inserting EAP-Failure
(1) [eap] = noop
(1) remove_reply_message_if_eap remove_reply_message_if_eap {
(1) if (&reply:EAP-Message && &reply:Reply-Message)
(1) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(1) else else {
(1) [noop] = noop
(1) } # else else = noop
(1) } # remove_reply_message_if_eap remove_reply_message_if_eap = noop
(1) } # Post-Auth-Type REJECT = updated
(1) Delaying response for 1 seconds
Waking up in 0.6 seconds.
Waking up in 0.3 seconds.
(1) Sending delayed response
(1) Sending Access-Reject packet to host 172.18.1.2 port 1025, id=32, length=0
Sending Access-Reject Id 32 from 172.18.2.100:1812 to 172.18.1.2:1025
Waking up in 3.9 seconds.
(1) Cleaning up request packet ID 32 with timestamp +189
Ready to process requests
[ ... SNIP ... ]
Not sure why it didn't find my user. My user is in the standard container (i.e. CN=Users) so I would think that sub would search there and find it? Perhaps that is my problem and either my base is incorrect or my scope is not correct? However, this seems to be correct according to the wiki (modules/Rlm_ldap). A final test with 'ldapsearch' yields similar results with no further information:
[ ... SNIP ... ]
[]# ldapsearch -x -b "DC=myDomain,DC=com" -D "CN=Free RADIUS,CN=Users,DC=myDomain,DC=com" -h myDomain.com -w "<<password>>" "(&(CN=VPN-Internal,OU=VPN,OU=Groups,DC=myDomain,DC=com))"
# extended LDIF
#
# LDAPv3
# base <DC=myDomain,DC=com> with scope subtree
# filter: (&(CN=VPN-Internal,OU=VPN,OU=Groups,DC=myDomain,DC=com))
# requesting: ALL
#
# search reference
ref: ldap://DomainDnsZones.myDomain.com/DC=DomainDnsZones,DC=myDomain,
DC=com
# search result
search: 2
>>result: 0 Success
# numResponses: 2
# numReferences: 1
[ ... SNIP ... ]
The only other thing I can think of is that the user that I'm binding to AD with to read information doesn't have the right permissions? But I would also think that the bind wouldn't be successful in the first place for the module if that were the case? I don't know what direction to take this in next to get more information. I would check the logs but since I'm running the server in debug mode the logs would just be duplicates of what I already have, correct?
5
18
Hi
I have just installed freeradius 3.0.9
Didnot modify any files
the only files i touched were
1. users to include my record
2. clients.conf to include my client
started radius server
and tried to authenticate the user
i get the following messages
I checked on the forum and saw various threads dealing with default config deleted etc
I have just installed this radius server and not deleted or over written any config ,
just added a few lines in the 2 files above
i have also given a cat of the sites-enabled/default
Any help would be highly appreciated
Mon Jul 20 07:19:13 2015 : Debug: radiusd: #### Opening IP addresses and Ports ####
Mon Jul 20 07:19:14 2015 : Debug: Listening on auth address 50.50.1.1 port 1900
Mon Jul 20 07:19:14 2015 : Debug: Listening on acct address 50.50.1.1 port 1901
Mon Jul 20 07:19:14 2015 : Debug: Opening new proxy socket 'proxy address 50.50.1.1 port 0'
Mon Jul 20 07:19:14 2015 : Debug: Listening on proxy address 50.50.1.1 port 45887
Mon Jul 20 07:19:14 2015 : Info: Ready to process requests
Mon Jul 20 07:20:57 2015 : Debug: (0) Received Access-Request Id 237 from 50.50.1.2:1812 to 50.50.1.1:1900 length 119
Mon Jul 20 07:20:57 2015 : Debug: (0) User-Name = "00:19:95:20:00:02"
Mon Jul 20 07:20:57 2015 : Debug: (0) User-Password = "xxxx"
Mon Jul 20 07:20:57 2015 : Debug: (0) NAS-Identifier = "S"
Mon Jul 20 07:20:57 2015 : Debug: (0) NAS-Port = 16842817
Mon Jul 20 07:20:57 2015 : Debug: (0) NAS-Port-Type = Async
Mon Jul 20 07:20:57 2015 : Debug: (0) session-state: No State attribute
Mon Jul 20 07:20:57 2015 : Debug: (0) Empty authorize section. Using default return values.
Mon Jul 20 07:20:57 2015 : ERROR: (0) No Auth-Type found: rejecting the user via Post-Auth-Type = Reject
Mon Jul 20 07:20:57 2015 : Debug: (0) Failed to authenticate the user
Mon Jul 20 07:20:57 2015 : Debug: (0) Using Post-Auth-Type Reject
Mon Jul 20 07:20:57 2015 : Debug: (0) Post-Auth-Type sub-section not found. Ignoring.
Mon Jul 20 07:20:57 2015 : Debug: (0) Delaying response for 1.000000 seconds
Mon Jul 20 07:20:57 2015 : Debug: Waking up in 0.3 seconds.
Mon Jul 20 07:20:57 2015 : Debug: Waking up in 0.6 seconds.
Mon Jul 20 07:20:58 2015 : Debug: (0) <delay>: Sending delayed response
Mon Jul 20 07:20:58 2015 : Debug: (0) <delay>: Sent Access-Reject Id 237 from 50.50.1.1:1900 to 50.50.1.2:1812 length 20
Mon Jul 20 07:20:58 2015 : Debug: Waking up in 3.9 seconds.
Mon Jul 20 07:21:02 2015 : Debug: (0) <delay>: Cleaning up request packet ID 237 with timestamp +104
Mon Jul 20 07:21:02 2015 : Info: Ready to process requests
[linux raddb]# cd /usr/local/etc/raddb/
[linux sites-enabled]# pwd
/usr/local/etc/raddb/sites-enabled
[linux sites-enabled]# ls -ltr
total 0
lrwxrwxrwx 1 root root 26 Jul 20 06:25 default -> ../sites-available/default
lrwxrwxrwx 1 root root 31 Jul 20 06:25 inner-tunnel -> ../sites-available/inner-tunnel
[linux sites-enabled]#
[linux sites-enabled]# cat default
######################################################################
#
# As of 2.0.0, FreeRADIUS supports virtual hosts using the
# "server" section, and configuration directives.
#
# Virtual hosts should be put into the "sites-available"
# directory. Soft links should be created in the "sites-enabled"
# directory to these files. This is done in a normal installation.
#
# If you are using 802.1X (EAP) authentication, please see also
# the "inner-tunnel" virtual server. You will likely have to edit
# that, too, for authentication to work.
#
# $Id: e16363f12d3b8ba38a4c056dd09ffa9c2d5e7de1 $
#
######################################################################
#
# Read "man radiusd" before editing this file. See the section
# titled DEBUGGING. It outlines a method where you can quickly
# obtain the configuration you want, without running into
# trouble. See also "man unlang", which documents the format
# of this file.
#
# This configuration is designed to work in the widest possible
# set of circumstances, with the widest possible number of
# authentication methods. This means that in general, you should
# need to make very few changes to this file.
#
# The best way to configure the server for your local system
# is to CAREFULLY edit this file. Most attempts to make large
# edits to this file will BREAK THE SERVER. Any edits should
# be small, and tested by running the server with "radiusd -X".
# Once the edits have been verified to work, save a copy of these
# configuration files somewhere. (e.g. as a "tar" file). Then,
# make more edits, and test, as above.
#
# There are many "commented out" references to modules such
# as ldap, sql, etc. These references serve as place-holders.
# If you need the functionality of that module, then configure
# it in radiusd.conf, and un-comment the references to it in
# this file. In most cases, those small changes will result
# in the server being able to connect to the DB, and to
# authenticate users.
#
######################################################################
server default {
#
# If you want the server to listen on additional addresses, or on
# additional ports, you can use multiple "listen" sections.
#
# Each section make the server listen for only one type of packet,
# therefore authentication and accounting have to be configured in
# different sections.
#
# The server ignore all "listen" section if you are using '-i' and '-p'
# on the command line.
#
listen {
# Type of packets to listen for.
# Allowed values are:
# auth listen for authentication packets
# acct listen for accounting packets
# proxy IP to use for sending proxied packets
# detail Read from the detail file. For examples, see
# raddb/sites-available/copy-acct-to-home-server
# status listen for Status-Server packets. For examples,
# see raddb/sites-available/status
# coa listen for CoA-Request and Disconnect-Request
# packets. For examples, see the file
# raddb/sites-available/coa
#
type = auth
# Note: "type = proxy" lets you control the source IP used for
# proxying packets, with some limitations:
#
# * A proxy listener CANNOT be used in a virtual server section.
# * You should probably set "port = 0".
# * Any "clients" configuration will be ignored.
#
# See also proxy.conf, and the "src_ipaddr" configuration entry
# in the sample "home_server" section. When you specify the
# source IP address for packets sent to a home server, the
# proxy listeners are automatically created.
# ipaddr/ipv4addr/ipv6addr - IP address on which to listen.
# Out of several options the first one will be used.
#
# Allowed values are:
# IPv4 address (e.g. 1.2.3.4, for ipv4addr/ipaddr)
# IPv6 address (e.g. 2001:db8::1, for ipv6addr/ipaddr)
# hostname (radius.example.com,
# A record for ipv4addr,
# AAAA record for ipv6addr,
# A or AAAA record for ipaddr)
# wildcard (*)
#
# ipv4addr = *
# ipv6addr = *
ipaddr = *
# Port on which to listen.
# Allowed values are:
# integer port number (1812)
# 0 means "use /etc/services for the proper port"
port = 0
# Some systems support binding to an interface, in addition
# to the IP address. This feature isn't strictly necessary,
# but for sites with many IP addresses on one interface,
# it's useful to say "listen on all addresses for eth0".
#
# If your system does not support this feature, you will
# get an error if you try to use it.
#
# interface = eth0
# Per-socket lists of clients. This is a very useful feature.
#
# The name here is a reference to a section elsewhere in
# radiusd.conf, or clients.conf. Having the name as
# a reference allows multiple sockets to use the same
# set of clients.
#
# If this configuration is used, then the global list of clients
# is IGNORED for this "listen" section. Take care configuring
# this feature, to ensure you don't accidentally disable a
# client you need.
#
# See clients.conf for the configuration of "per_socket_clients".
#
# clients = per_socket_clients
#
# Connection limiting for sockets with "proto = tcp".
#
# This section is ignored for other kinds of sockets.
#
limit {
#
# Limit the number of simultaneous TCP connections to the socket
#
# The default is 16.
# Setting this to 0 means "no limit"
max_connections = 16
# The per-socket "max_requests" option does not exist.
#
# The lifetime, in seconds, of a TCP connection. After
# this lifetime, the connection will be closed.
#
# Setting this to 0 means "forever".
lifetime = 0
#
# The idle timeout, in seconds, of a TCP connection.
# If no packets have been received over the connection for
# this time, the connection will be closed.
#
# Setting this to 0 means "no timeout".
#
# We STRONGLY RECOMMEND that you set an idle timeout.
#
idle_timeout = 30
}
}
#
# This second "listen" section is for listening on the accounting
# port, too.
#
listen {
ipaddr = *
# ipv6addr = ::
port = 0
type = acct
# interface = eth0
# clients = per_socket_clients
limit {
# The number of packets received can be rate limited via the
# "max_pps" configuration item. When it is set, the server
# tracks the total number of packets received in the previous
# second. If the count is greater than "max_pps", then the
# new packet is silently discarded. This helps the server
# deal with overload situations.
#
# The packets/s counter is tracked in a sliding window. This
# means that the pps calculation is done for the second
# before the current packet was received. NOT for the current
# wall-clock second, and NOT for the previous wall-clock second.
#
# Useful values are 0 (no limit), or 100 to 10000.
# Values lower than 100 will likely cause the server to ignore
# normal traffic. Few systems are capable of handling more than
# 10K packets/s.
#
# It is most useful for accounting systems. Set it to 50%
# more than the normal accounting load, and you can be sure that
# the server will never get overloaded
#
# max_pps = 0
# Only for "proto = tcp". These are ignored for "udp" sockets.
#
# idle_timeout = 0
# lifetime = 0
# max_connections = 0
}
}
# IPv6 versions of the above - read their full config to understand options
listen {
type = auth
ipv6addr = :: # any. ::1 == localhost
port = 0
# interface = eth0
# clients = per_socket_clients
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
ipv6addr = ::
port = 0
type = acct
# interface = eth0
# clients = per_socket_clients
limit {
# max_pps = 0
# idle_timeout = 0
# lifetime = 0
# max_connections = 0
}
}
# Authorization. First preprocess (hints and huntgroups files),
# then realms, and finally look in the "users" file.
#
# Any changes made here should also be made to the "inner-tunnel"
# virtual server.
#
# The order of the realm modules will determine the order that
# we try to find a matching realm.
#
# Make *sure* that 'preprocess' comes before any realm if you
# need to setup hints for the remote radius server
authorize {
#
# Take a User-Name, and perform some checks on it, for spaces and other
# invalid characters. If the User-Name appears invalid, reject the
# request.
#
# See policy.d/filter for the definition of the filter_username policy.
#
filter_username
#
# The preprocess module takes care of sanitizing some bizarre
# attributes in the request, and turning them into attributes
# which are more standard.
#
# It takes care of processing the 'raddb/hints' and the
# 'raddb/huntgroups' files.
preprocess
# If you intend to use CUI and you require that the Operator-Name
# be set for CUI generation and you want to generate CUI also
# for your local clients then uncomment the operator-name
# below and set the operator-name for your clients in clients.conf
# operator-name
#
# If you want to generate CUI for some clients that do not
# send proper CUI requests, then uncomment the
# cui below and set "add_cui = yes" for these clients in clients.conf
# cui
#
# If you want to have a log of authentication requests,
# un-comment the following line.
# auth_log
#
# The chap module will set 'Auth-Type := CHAP' if we are
# handling a CHAP request and Auth-Type has not already been set
chap
#
# If the users are logging in with an MS-CHAP-Challenge
# attribute for authentication, the mschap module will find
# the MS-CHAP-Challenge attribute, and add 'Auth-Type := MS-CHAP'
# to the request, which will cause the server to then use
# the mschap module for authentication.
mschap
#
# If you have a Cisco SIP server authenticating against
# FreeRADIUS, uncomment the following line, and the 'digest'
# line in the 'authenticate' section.
digest
#
# The WiMAX specification says that the Calling-Station-Id
# is 6 octets of the MAC. This definition conflicts with
# RFC 3580, and all common RADIUS practices. Un-commenting
# the "wimax" module here means that it will fix the
# Calling-Station-Id attribute to the normal format as
# specified in RFC 3580 Section 3.21
# wimax
#
# Look for IPASS style 'realm/', and if not found, look for
# '@realm', and decide whether or not to proxy, based on
# that.
# IPASS
#
# If you are using multiple kinds of realms, you probably
# want to set "ignore_null = yes" for all of them.
# Otherwise, when the first style of realm doesn't match,
# the other styles won't be checked.
#
suffix
# ntdomain
#
# This module takes care of EAP-MD5, EAP-TLS, and EAP-LEAP
# authentication.
#
# It also sets the EAP-Type attribute in the request
# attribute list to the EAP type from the packet.
#
# The EAP module returns "ok" if it is not yet ready to
# authenticate the user. The configuration below checks for
# that code, and stops processing the "authorize" section if
# so.
#
# Any LDAP and/or SQL servers will not be queried for the
# initial set of packets that go back and forth to set up
# TTLS or PEAP.
#
eap {
ok = return
}
#
# Pull crypt'd passwords from /etc/passwd or /etc/shadow,
# using the system API's to get the password. If you want
# to read /etc/passwd or /etc/shadow directly, see the
# mods-available/passwd module.
#
# unix
#
# Read the 'users' file. In v3, this is located in
# raddb/mods-config/files/authorize
files
#
# Look in an SQL database. The schema of the database
# is meant to mirror the "users" file.
#
# See "Authorization Queries" in mods-available/sql
-sql
#
# If you are using /etc/smbpasswd, and are also doing
# mschap authentication, the un-comment this line, and
# configure the 'smbpasswd' module.
# smbpasswd
#
# The ldap module reads passwords from the LDAP database.
-ldap
#
# Enforce daily limits on time spent logged in.
# daily
#
expiration
logintime
#
# If no other module has claimed responsibility for
# authentication, then try to use PAP. This allows the
# other modules listed above to add a "known good" password
# to the request, and to do nothing else. The PAP module
# will then see that password, and use it to do PAP
# authentication.
#
# This module should be listed last, so that the other modules
# get a chance to set Auth-Type for themselves.
#
pap
#
# If "status_server = yes", then Status-Server messages are passed
# through the following section, and ONLY the following section.
# This permits you to do DB queries, for example. If the modules
# listed here return "fail", then NO response is sent.
#
# Autz-Type Status-Server {
#
# }
}
# Authentication.
#
#
# This section lists which modules are available for authentication.
# Note that it does NOT mean 'try each module in order'. It means
# that a module from the 'authorize' section adds a configuration
# attribute 'Auth-Type := FOO'. That authentication type is then
# used to pick the appropriate module from the list below.
#
# In general, you SHOULD NOT set the Auth-Type attribute. The server
# will figure it out on its own, and will do the right thing. The
# most common side effect of erroneously setting the Auth-Type
# attribute is that one authentication method will work, but the
# others will not.
#
# The common reasons to set the Auth-Type attribute by hand
# is to either forcibly reject the user (Auth-Type := Reject),
# or to or forcibly accept the user (Auth-Type := Accept).
#
# Note that Auth-Type := Accept will NOT work with EAP.
#
# Please do not put "unlang" configurations into the "authenticate"
# section. Put them in the "post-auth" section instead. That's what
# the post-auth section is for.
#
authenticate {
#
# PAP authentication, when a back-end database listed
# in the 'authorize' section supplies a password. The
# password can be clear-text, or encrypted.
Auth-Type PAP {
pap
}
#
# Most people want CHAP authentication
# A back-end database listed in the 'authorize' section
# MUST supply a CLEAR TEXT password. Encrypted passwords
# won't work.
Auth-Type CHAP {
chap
}
#
# MSCHAP authentication.
Auth-Type MS-CHAP {
mschap
}
#
# If you have a Cisco SIP server authenticating against
# FreeRADIUS, uncomment the following line, and the 'digest'
# line in the 'authorize' section.
digest
#
# Pluggable Authentication Modules.
# pam
# Uncomment it if you want to use ldap for authentication
#
# Note that this means "check plain-text password against
# the ldap database", which means that EAP won't work,
# as it does not supply a plain-text password.
#
# We do NOT recommend using this. LDAP servers are databases.
# They are NOT authentication servers. FreeRADIUS is an
# authentication server, and knows what to do with authentication.
# LDAP servers do not.
#
# Auth-Type LDAP {
# ldap
# }
#
# Allow EAP authentication.
eap
#
# The older configurations sent a number of attributes in
# Access-Challenge packets, which wasn't strictly correct.
# If you want to filter out these attributes, uncomment
# the following lines.
#
# Auth-Type eap {
# eap {
# handled = 1
# }
# if (handled && (Response-Packet-Type == Access-Challenge)) {
# attr_filter.access_challenge.post-auth
# handled # override the "updated" code from attr_filter
# }
# }
}
#
# Pre-accounting. Decide which accounting type to use.
#
preacct {
preprocess
#
# Merge Acct-[Input|Output]-Gigawords and Acct-[Input-Output]-Octets
# into a single 64bit counter Acct-[Input|Output]-Octets64.
#
# acct_counters64
#
# Session start times are *implied* in RADIUS.
# The NAS never sends a "start time". Instead, it sends
# a start packet, *possibly* with an Acct-Delay-Time.
# The server is supposed to conclude that the start time
# was "Acct-Delay-Time" seconds in the past.
#
# The code below creates an explicit start time, which can
# then be used in other modules. It will be *mostly* correct.
# Any errors are due to the 1-second resolution of RADIUS,
# and the possibility that the time on the NAS may be off.
#
# The start time is: NOW - delay - session_length
#
# update request {
# FreeRADIUS-Acct-Session-Start-Time = "%{expr: %l - %{%{Acct-Session-Time}:-0} - %{%{Acct-Delay-Time}:-0}}"
# }
#
# Ensure that we have a semi-unique identifier for every
# request, and many NAS boxes are broken.
acct_unique
#
# Look for IPASS-style 'realm/', and if not found, look for
# '@realm', and decide whether or not to proxy, based on
# that.
#
# Accounting requests are generally proxied to the same
# home server as authentication requests.
# IPASS
suffix
# ntdomain
#
# Read the 'acct_users' file
files
}
#
# Accounting. Log the accounting data.
#
accounting {
# Update accounting packet by adding the CUI attribute
# recorded from the corresponding Access-Accept
# use it only if your NAS boxes do not support CUI themselves
# cui
#
# Create a 'detail'ed log of the packets.
# Note that accounting requests which are proxied
# are also logged in the detail file.
detail
# daily
# Update the wtmp file
#
# If you don't use "radlast", you can delete this line.
unix
#
# For Simultaneous-Use tracking.
#
# Due to packet losses in the network, the data here
# may be incorrect. There is little we can do about it.
# radutmp
# sradutmp
# Return an address to the IP Pool when we see a stop record.
# main_pool
#
# Log traffic to an SQL database.
#
# See "Accounting queries" in mods-available/sql
-sql
#
# If you receive stop packets with zero session length,
# they will NOT be logged in the database. The SQL module
# will print a message (only in debugging mode), and will
# return "noop".
#
# You can ignore these packets by uncommenting the following
# three lines. Otherwise, the server will not respond to the
# accounting request, and the NAS will retransmit.
#
# if (noop) {
# ok
# }
#
# Instead of sending the query to the SQL server,
# write it into a log file.
#
# sql_log
# Cisco VoIP specific bulk accounting
# pgsql-voip
# For Exec-Program and Exec-Program-Wait
exec
# Filter attributes from the accounting response.
attr_filter.accounting_response
#
# See "Autz-Type Status-Server" for how this works.
#
# Acct-Type Status-Server {
#
# }
}
# Session database, used for checking Simultaneous-Use. Either the radutmp
# or rlm_sql module can handle this.
# The rlm_sql module is *much* faster
session {
# radutmp
#
# See "Simultaneous Use Checking Queries" in mods-available/sql
# sql
}
# Post-Authentication
# Once we KNOW that the user has been authenticated, there are
# additional steps we can take.
post-auth {
#
# If you need to have a State attribute, you can
# add it here. e.g. for later CoA-Request with
# State, and Service-Type = Authorize-Only.
#
# if (!&reply:State) {
# update reply {
# State := "0x%{randstr:16h}"
# }
# }
#
# For EAP-TTLS and PEAP, add the cached attributes to the reply.
# The "session-state" attributes are automatically cached when
# an Access-Challenge is sent, and automatically retrieved
# when an Access-Request is received.
#
# The session-state attributes are automatically deleted after
# an Access-Reject or Access-Accept is sent.
#
update {
&reply: += &session-state:
}
# Get an address from the IP Pool.
# main_pool
# Create the CUI value and add the attribute to Access-Accept.
# Uncomment the line below if *returning* the CUI.
# cui
#
# If you want to have a log of authentication replies,
# un-comment the following line, and enable the
# 'detail reply_log' module.
# reply_log
#
# After authenticating the user, do another SQL query.
#
# See "Authentication Logging Queries" in mods-available/sql
-sql
#
# Instead of sending the query to the SQL server,
# write it into a log file.
#
# sql_log
#
# Un-comment the following if you want to modify the user's object
# in LDAP after a successful login.
#
# ldap
# For Exec-Program and Exec-Program-Wait
exec
#
# Calculate the various WiMAX keys. In order for this to work,
# you will need to define the WiMAX NAI, usually via
#
# update request {
# WiMAX-MN-NAI = "%{User-Name}"
# }
#
# If you want various keys to be calculated, you will need to
# update the reply with "template" values. The module will see
# this, and replace the template values with the correct ones
# taken from the cryptographic calculations. e.g.
#
# update reply {
# WiMAX-FA-RK-Key = 0x00
# WiMAX-MSK = "%{EAP-MSK}"
# }
#
# You may want to delete the MS-MPPE-*-Keys from the reply,
# as some WiMAX clients behave badly when those attributes
# are included. See "raddb/modules/wimax", configuration
# entry "delete_mppe_keys" for more information.
#
# wimax
# If there is a client certificate (EAP-TLS, sometimes PEAP
# and TTLS), then some attributes are filled out after the
# certificate verification has been performed. These fields
# MAY be available during the authentication, or they may be
# available only in the "post-auth" section.
#
# The first set of attributes contains information about the
# issuing certificate which is being used. The second
# contains information about the client certificate (if
# available).
#
# update reply {
# Reply-Message += "%{TLS-Cert-Serial}"
# Reply-Message += "%{TLS-Cert-Expiration}"
# Reply-Message += "%{TLS-Cert-Subject}"
# Reply-Message += "%{TLS-Cert-Issuer}"
# Reply-Message += "%{TLS-Cert-Common-Name}"
# Reply-Message += "%{TLS-Cert-Subject-Alt-Name-Email}"
#
# Reply-Message += "%{TLS-Client-Cert-Serial}"
# Reply-Message += "%{TLS-Client-Cert-Expiration}"
# Reply-Message += "%{TLS-Client-Cert-Subject}"
# Reply-Message += "%{TLS-Client-Cert-Issuer}"
# Reply-Message += "%{TLS-Client-Cert-Common-Name}"
# Reply-Message += "%{TLS-Client-Cert-Subject-Alt-Name-Email}"
# }
# Insert class attribute (with unique value) into response,
# aids matching auth and acct records, and protects against duplicate
# Acct-Session-Id. Note: Only works if the NAS has implemented
# RFC 2865 behaviour for the class attribute, AND if the NAS
# supports long Class attributes. Many older or cheap NASes
# only support 16-octet Class attributes.
# insert_acct_class
# MacSEC requires the use of EAP-Key-Name. However, we don't
# want to send it for all EAP sessions. Therefore, the EAP
# modules put required data into the EAP-Session-Id attribute.
# This attribute is never put into a request or reply packet.
#
# Uncomment the next few lines to copy the required data into
# the EAP-Key-Name attribute
# if (&reply:EAP-Session-Id) {
# update reply {
# EAP-Key-Name := &reply:EAP-Session-Id
# }
# }
# Remove reply message if the response contains an EAP-Message
remove_reply_message_if_eap
#
# Access-Reject packets are sent through the REJECT sub-section of the
# post-auth section.
#
# Add the ldap module name (or instance) if you have set
# 'edir_account_policy_check = yes' in the ldap module configuration
#
# The "session-state" attributes are not available here.
#
Post-Auth-Type REJECT {
# log failed authentications in SQL, too.
-sql
attr_filter.access_reject
# Insert EAP-Failure message if the request was
# rejected by policy instead of because of an
# authentication failure
eap
# Remove reply message if the response contains an EAP-Message
remove_reply_message_if_eap
}
}
#
# When the server decides to proxy a request to a home server,
# the proxied request is first passed through the pre-proxy
# stage. This stage can re-write the request, or decide to
# cancel the proxy.
#
# Only a few modules currently have this method.
#
pre-proxy {
# Before proxing the request add an Operator-Name attribute identifying
# if the operator-name is found for this client.
# No need to uncomment this if you have already enabled this in
# the authorize section.
# operator-name
# The client requests the CUI by sending a CUI attribute
# containing one zero byte.
# Uncomment the line below if *requesting* the CUI.
# cui
# Uncomment the following line if you want to change attributes
# as defined in the preproxy_users file.
# files
# Uncomment the following line if you want to filter requests
# sent to remote servers based on the rules defined in the
# 'attrs.pre-proxy' file.
# attr_filter.pre-proxy
# If you want to have a log of packets proxied to a home
# server, un-comment the following line, and the
# 'detail pre_proxy_log' section, above.
# pre_proxy_log
}
#
# When the server receives a reply to a request it proxied
# to a home server, the request may be massaged here, in the
# post-proxy stage.
#
post-proxy {
# If you want to have a log of replies from a home server,
# un-comment the following line, and the 'detail post_proxy_log'
# section, above.
# post_proxy_log
# Uncomment the following line if you want to filter replies from
# remote proxies based on the rules defined in the 'attrs' file.
# attr_filter.post-proxy
#
# If you are proxying LEAP, you MUST configure the EAP
# module, and you MUST list it here, in the post-proxy
# stage.
#
# You MUST also use the 'nostrip' option in the 'realm'
# configuration. Otherwise, the User-Name attribute
# in the proxied request will not match the user name
# hidden inside of the EAP packet, and the end server will
# reject the EAP request.
#
eap
#
# If the server tries to proxy a request and fails, then the
# request is processed through the modules in this section.
#
# The main use of this section is to permit robust proxying
# of accounting packets. The server can be configured to
# proxy accounting packets as part of normal processing.
# Then, if the home server goes down, accounting packets can
# be logged to a local "detail" file, for processing with
# radrelay. When the home server comes back up, radrelay
# will read the detail file, and send the packets to the
# home server.
#
# With this configuration, the server always responds to
# Accounting-Requests from the NAS, but only writes
# accounting packets to disk if the home server is down.
#
# Post-Proxy-Type Fail-Accounting {
# detail
# }
}
}
5
7
I am compiling FreeRADIUS version 3.1.x from source and I get the following error:
[]# cd freeradius-server-3.1.x[]# ./configure --with-openssl-lib-dir=/usr/local/ssl/lib --with-openssl-include-dir=/usr/local/ssl/include[]# make
[ .... SNIP ....]
CC src/lib/version.c
/usr/bin/ld: /usr/local/ssl/lib/libcrypto.a(md4_dgst.o): relocation R_X86_64_PC32 against undefined symbol `memset@@GLIBC_2.2.5' can not be used when making a shared object; recompile with -fPIC
/usr/bin/ld: final link failed: Bad value
collect2: error: ld returned 1 exit status
make: *** [build/lib/local/libfreeradius-radius.la] Error 1
So I recompile openssl:
[]# cd openssl-1.0.2d
[]# ./config -fPIC[]# make[]# make install
Trying make again, different module but same suggestion?
[]# cd freeradius-server-3.1.x[]# make
[ .... SNIP ....]
CC src/modules/rlm_wimax/rlm_wimax.c
/usr/bin/ld: /usr/local/ssl/lib/libcrypto.a(rsaz_exp.o): relocation R_X86_64_32 against `.rodata' can not be used when making a shared object; recompile with -fPIC
/usr/local/ssl/lib/libcrypto.a: could not read symbols: Bad value
collect2: error: ld returned 1 exit status
make: *** [build/lib/local/rlm_wimax.la] Error 1
3
3
Right,
So, this is an authentication on FreeRADIUS 3.0.17 that I've just upgraded to on our 'playpen' network. Previously, it would simply return the User-Name as 'root' (I know, I know...) but now it appears that the server adds the outer User-Name *first*, and then restores the session-state one (which was set by the inner-tunnel as 'root').
This doesn't look right... Alan? Arran?
The /etc/raddb/users file looks like this:
bob Cleartext-Password := <<password>>
Reply-Message := 'Bob has authenticated',
User-Name := 'root'
-- log follows --
FreeRADIUS Version 3.0.17
Copyright (C) 1999-2017 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/raddb/dictionary
including configuration file /etc/raddb/radiusd.conf
including configuration file /etc/raddb/proxy.conf
including configuration file /etc/raddb/clients.conf
including files in directory /etc/raddb/mods-enabled/
including configuration file /etc/raddb/mods-enabled/always
including configuration file /etc/raddb/mods-enabled/attr_filter
including configuration file /etc/raddb/mods-enabled/cache_eap
including configuration file /etc/raddb/mods-enabled/chap
including configuration file /etc/raddb/mods-enabled/date
including configuration file /etc/raddb/mods-enabled/detail
including configuration file /etc/raddb/mods-enabled/detail.log
including configuration file /etc/raddb/mods-enabled/digest
including configuration file /etc/raddb/mods-enabled/dynamic_clients
including configuration file /etc/raddb/mods-enabled/eap
including configuration file /etc/raddb/mods-enabled/echo
including configuration file /etc/raddb/mods-enabled/exec
including configuration file /etc/raddb/mods-enabled/expiration
including configuration file /etc/raddb/mods-enabled/expr
including configuration file /etc/raddb/mods-enabled/files
including configuration file /etc/raddb/mods-enabled/linelog
including configuration file /etc/raddb/mods-enabled/logintime
including configuration file /etc/raddb/mods-enabled/mschap
including configuration file /etc/raddb/mods-enabled/ntlm_auth
including configuration file /etc/raddb/mods-enabled/pap
including configuration file /etc/raddb/mods-enabled/passwd
including configuration file /etc/raddb/mods-enabled/preprocess
including configuration file /etc/raddb/mods-enabled/radutmp
including configuration file /etc/raddb/mods-enabled/realm
including configuration file /etc/raddb/mods-enabled/replicate
including configuration file /etc/raddb/mods-enabled/soh
including configuration file /etc/raddb/mods-enabled/sradutmp
including configuration file /etc/raddb/mods-enabled/unix
including configuration file /etc/raddb/mods-enabled/unpack
including configuration file /etc/raddb/mods-enabled/utf8
including configuration file /etc/raddb/mods-enabled/abfab_psk_sql
including files in directory /etc/raddb/policy.d/
including configuration file /etc/raddb/policy.d/abfab-tr
including configuration file /etc/raddb/policy.d/accounting
including configuration file /etc/raddb/policy.d/canonicalization
including configuration file /etc/raddb/policy.d/control
including configuration file /etc/raddb/policy.d/cui
including configuration file /etc/raddb/policy.d/debug
including configuration file /etc/raddb/policy.d/dhcp
including configuration file /etc/raddb/policy.d/eap
including configuration file /etc/raddb/policy.d/filter
including configuration file /etc/raddb/policy.d/operator-name
including configuration file /etc/raddb/policy.d/moonshot-targeted-ids
including files in directory /etc/raddb/sites-enabled/
including configuration file /etc/raddb/sites-enabled/channel_bindings
including configuration file /etc/raddb/sites-enabled/default
including configuration file /etc/raddb/sites-enabled/inner-tunnel
including configuration file /etc/raddb/sites-enabled/abfab-tls
including configuration file /etc/raddb/sites-enabled/abfab-tr-idp
main {
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/radius"
run_dir = "/var/run/radiusd"
libdir = "/usr/lib64/freeradius"
radacctdir = "/var/log/radius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/var/run/radiusd/radiusd.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
allow_vulnerable_openssl = "yes"
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dynamic = yes
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
realm idp.test.assent {
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debug state unknown (cap_sys_ptrace capability not set)
# Creating Auth-Type = mschap
# Creating Auth-Type = digest
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_always
# Loading module "reject" from file /etc/raddb/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file /etc/raddb/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /etc/raddb/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file /etc/raddb/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file /etc/raddb/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file /etc/raddb/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file /etc/raddb/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file /etc/raddb/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file /etc/raddb/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/etc/raddb/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/etc/raddb/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/etc/raddb/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/etc/raddb/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/etc/raddb/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loaded module rlm_cache
# Loading module "cache_eap" from file /etc/raddb/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_chap
# Loading module "chap" from file /etc/raddb/mods-enabled/chap
# Loaded module rlm_date
# Loading module "date" from file /etc/raddb/mods-enabled/date
date {
format = "%b %e %Y %H:%M:%S %Z"
utc = no
}
# Loaded module rlm_detail
# Loading module "detail" from file /etc/raddb/mods-enabled/detail
detail {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "auth_log" from file /etc/raddb/mods-enabled/detail.log
detail auth_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file /etc/raddb/mods-enabled/detail.log
detail reply_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file /etc/raddb/mods-enabled/detail.log
detail pre_proxy_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file /etc/raddb/mods-enabled/detail.log
detail post_proxy_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_digest
# Loading module "digest" from file /etc/raddb/mods-enabled/digest
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file /etc/raddb/mods-enabled/dynamic_clients
# Loaded module rlm_eap
# Loading module "eap" from file /etc/raddb/mods-enabled/eap
eap {
default_eap_type = "ttls"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_exec
# Loading module "echo" from file /etc/raddb/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loading module "exec" from file /etc/raddb/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_expiration
# Loading module "expiration" from file /etc/raddb/mods-enabled/expiration
# Loaded module rlm_expr
# Loading module "expr" from file /etc/raddb/mods-enabled/expr
expr {
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loaded module rlm_files
# Loading module "files" from file /etc/raddb/mods-enabled/files
files {
filename = "/etc/raddb/mods-config/files/authorize"
acctusersfile = "/etc/raddb/mods-config/files/accounting"
preproxy_usersfile = "/etc/raddb/mods-config/files/pre-proxy"
}
# Loaded module rlm_linelog
# Loading module "linelog" from file /etc/raddb/mods-enabled/linelog
linelog {
filename = "/var/log/radius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file /etc/raddb/mods-enabled/linelog
linelog log_accounting {
filename = "/var/log/radius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_logintime
# Loading module "logintime" from file /etc/raddb/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_mschap
# Loading module "mschap" from file /etc/raddb/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
winbind_retry_with_normalised_username = no
}
# Loading module "ntlm_auth" from file /etc/raddb/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN --username=%{mschap:User-Name} --password=%{User-Password}"
shell_escape = yes
}
# Loaded module rlm_pap
# Loading module "pap" from file /etc/raddb/mods-enabled/pap
pap {
normalise = yes
}
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file /etc/raddb/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loaded module rlm_preprocess
# Loading module "preprocess" from file /etc/raddb/mods-enabled/preprocess
preprocess {
huntgroups = "/etc/raddb/mods-config/preprocess/huntgroups"
hints = "/etc/raddb/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loaded module rlm_radutmp
# Loading module "radutmp" from file /etc/raddb/mods-enabled/radutmp
radutmp {
filename = "/var/log/radius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_realm
# Loading module "IPASS" from file /etc/raddb/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
default_community = "none"
rp_realm = "none"
trust_router = "none"
tr_port = 0
rekey_enabled = no
realm_lifetime = 0
}
# Loading module "suffix" from file /etc/raddb/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
default_community = "apc.test.assent"
rp_realm = "assent-fr-idp.test.assent"
trust_router = "tr.moonshot-playpen.ti.ja.net"
tr_port = 0
rekey_enabled = no
realm_lifetime = 0
}
# Loading module "realmpercent" from file /etc/raddb/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
default_community = "none"
rp_realm = "none"
trust_router = "none"
tr_port = 0
rekey_enabled = no
realm_lifetime = 0
}
# Loading module "ntdomain" from file /etc/raddb/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
default_community = "none"
rp_realm = "none"
trust_router = "none"
tr_port = 0
rekey_enabled = no
realm_lifetime = 0
}
# Loaded module rlm_replicate
# Loading module "replicate" from file /etc/raddb/mods-enabled/replicate
# Loaded module rlm_soh
# Loading module "soh" from file /etc/raddb/mods-enabled/soh
soh {
dhcp = yes
}
# Loading module "sradutmp" from file /etc/raddb/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/radius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_unix
# Loading module "unix" from file /etc/raddb/mods-enabled/unix
unix {
radwtmp = "/var/log/radius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_unpack
# Loading module "unpack" from file /etc/raddb/mods-enabled/unpack
# Loaded module rlm_utf8
# Loading module "utf8" from file /etc/raddb/mods-enabled/utf8
# Loaded module rlm_sql
# Loading module "psksql" from file /etc/raddb/mods-enabled/abfab_psk_sql
sql psksql {
driver = "rlm_sql_sqlite"
server = ""
port = 0
login = ""
password = <<< secret >>>
radius_db = "radius"
read_groups = yes
read_profiles = yes
read_clients = no
delete_stale_sessions = yes
sql_user_name = ""
default_user_profile = ""
client_query = "SELECT id,nasname,shortname,type,secret FROM nas"
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"
accounting {
reference = ".query"
type {
accounting-on {
}
accounting-off {
}
start {
}
interim-update {
}
stop {
}
}
}
post-auth {
reference = ".query"
}
}
rlm_sql (psksql): Driver rlm_sql_sqlite (module rlm_sql_sqlite) loaded and linked
instantiate {
}
# Instantiating module "reject" from file /etc/raddb/mods-enabled/always
# Instantiating module "fail" from file /etc/raddb/mods-enabled/always
# Instantiating module "ok" from file /etc/raddb/mods-enabled/always
# Instantiating module "handled" from file /etc/raddb/mods-enabled/always
# Instantiating module "invalid" from file /etc/raddb/mods-enabled/always
# Instantiating module "userlock" from file /etc/raddb/mods-enabled/always
# Instantiating module "notfound" from file /etc/raddb/mods-enabled/always
# Instantiating module "noop" from file /etc/raddb/mods-enabled/always
# Instantiating module "updated" from file /etc/raddb/mods-enabled/always
# Instantiating module "attr_filter.post-proxy" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/access_reject
[/etc/raddb/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay" found in filter list for realm "DEFAULT".
[/etc/raddb/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay-USec" found in filter list for realm "DEFAULT".
# Instantiating module "attr_filter.access_challenge" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/accounting_response
# Instantiating module "cache_eap" from file /etc/raddb/mods-enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module rlm_cache_rbtree) loaded and linked
# Instantiating module "detail" from file /etc/raddb/mods-enabled/detail
# Instantiating module "auth_log" from file /etc/raddb/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output
# Instantiating module "reply_log" from file /etc/raddb/mods-enabled/detail.log
# Instantiating module "pre_proxy_log" from file /etc/raddb/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file /etc/raddb/mods-enabled/detail.log
# Instantiating module "eap" from file /etc/raddb/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/etc/raddb/certs/server.pem"
certificate_file = "/etc/raddb/certs/server.pem"
ca_file = "/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/etc/raddb/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
cipher_server_preference = no
ecdh_curve = "prime256v1"
tls_max_version = ""
tls_min_version = "1.0"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
# Instantiating module "expiration" from file /etc/raddb/mods-enabled/expiration
# Instantiating module "files" from file /etc/raddb/mods-enabled/files
reading pairlist file /etc/raddb/mods-config/files/authorize
reading pairlist file /etc/raddb/mods-config/files/accounting
reading pairlist file /etc/raddb/mods-config/files/pre-proxy
# Instantiating module "linelog" from file /etc/raddb/mods-enabled/linelog
# Instantiating module "log_accounting" from file /etc/raddb/mods-enabled/linelog
# Instantiating module "logintime" from file /etc/raddb/mods-enabled/logintime
# Instantiating module "mschap" from file /etc/raddb/mods-enabled/mschap
rlm_mschap (mschap): using internal authentication
# Instantiating module "pap" from file /etc/raddb/mods-enabled/pap
# Instantiating module "etc_passwd" from file /etc/raddb/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "preprocess" from file /etc/raddb/mods-enabled/preprocess
reading pairlist file /etc/raddb/mods-config/preprocess/huntgroups
reading pairlist file /etc/raddb/mods-config/preprocess/hints
# Instantiating module "IPASS" from file /etc/raddb/mods-enabled/realm
# Instantiating module "suffix" from file /etc/raddb/mods-enabled/realm
# Instantiating module "realmpercent" from file /etc/raddb/mods-enabled/realm
# Instantiating module "ntdomain" from file /etc/raddb/mods-enabled/realm
# Instantiating module "psksql" from file /etc/raddb/mods-enabled/abfab_psk_sql
rlm_sql_sqlite: libsqlite version: 3.7.17
sqlite {
filename = "/var/lib/trust_router/keys"
busy_timeout = 200
}
rlm_sql (psksql): Attempting to connect to database "radius"
rlm_sql (psksql): Initialising connection pool
pool {
start = 5
min = 5
max = 10
spare = 3
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 1
spread = no
}
rlm_sql (psksql): Opening additional connection (0), 1 of 10 pending slots used
rlm_sql_sqlite: Opening SQLite database "/var/lib/trust_router/keys"
rlm_sql (psksql): Opening additional connection (1), 1 of 9 pending slots used
rlm_sql_sqlite: Opening SQLite database "/var/lib/trust_router/keys"
rlm_sql (psksql): Opening additional connection (2), 1 of 8 pending slots used
rlm_sql_sqlite: Opening SQLite database "/var/lib/trust_router/keys"
rlm_sql (psksql): Opening additional connection (3), 1 of 7 pending slots used
rlm_sql_sqlite: Opening SQLite database "/var/lib/trust_router/keys"
rlm_sql (psksql): Opening additional connection (4), 1 of 6 pending slots used
rlm_sql_sqlite: Opening SQLite database "/var/lib/trust_router/keys"
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/raddb/radiusd.conf
} # server
server channel_bindings { # from file /etc/raddb/sites-enabled/channel_bindings
# Loading authorize {...}
} # server channel_bindings
server default { # from file /etc/raddb/sites-enabled/default
# Loading authenticate {...}
# Loading authorize {...}
Ignoring "sql" (see raddb/mods-available/README.rst)
Ignoring "ldap" (see raddb/mods-available/README.rst)
# Loading preacct {...}
# Loading accounting {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server default
server inner-tunnel { # from file /etc/raddb/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server inner-tunnel
server abfab-idp { # from file /etc/raddb/sites-enabled/abfab-tr-idp
# Loading authenticate {...}
# Loading authorize {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server abfab-idp
thread pool {
start_servers = 5
max_servers = 32
min_spare_servers = 3
max_spare_servers = 10
max_requests_per_server = 0
cleanup_delay = 5
max_queue_size = 65536
auto_limit_acct = no
}
Thread spawned new child 1. Total threads in pool: 1
Thread spawned new child 2. Total threads in pool: 2
Thread spawned new child 3. Total threads in pool: 3
Thread spawned new child 4. Total threads in pool: 4
Thread spawned new child 5. Total threads in pool: 5
Thread pool initialized
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
virtual_server = "abfab-idp"
ipaddr = *
port = 2083
proto = "tcp"
tls {
verify_depth = 0
ca_path = "/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/etc/raddb/certs/server.key"
certificate_file = "/etc/raddb/certs/server.pem"
ca_file = "/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
psk_query = "%{psksql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
dh_file = "/etc/raddb/certs/dh"
fragment_size = 8192
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
require_client_cert = yes
ecdh_curve = "prime256v1"
tls_max_version = ""
tls_min_version = "1.0"
cache {
enable = no
lifetime = 24
name = "abfab-tls"
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = no
use_nonce = yes
timeout = 0
softfail = no
}
}
Thread 4 waiting to be assigned a request
Thread 5 waiting to be assigned a request
Thread 1 waiting to be assigned a request
Thread 2 waiting to be assigned a request
Thread 3 waiting to be assigned a request
clients = "radsec-abfab"
client default {
ipaddr = 0.0.0.0/0
require_message_authenticator = no
proto = "tls"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
}
listen {
type = "auth"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on auth proto tcp address * port 2083 (TLS) bound to server abfab-idp
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Listening on proxy address * port 38341
Listening on proxy address :: port 43559
Ready to process requests
... new connection request on TCP socket
Listening on auth from client (13.94.115.212, 48186) -> (*, 2083, virtual-server=abfab-idp)
Waking up in 0.7 seconds.
(0) Initiating new EAP-TLS session
(0) Setting verify mode to require certificate from client
(0) (other): before/accept initialization
(0) TLS_accept: before/accept initialization
(0) <<< recv TLS 1.2 [length 0060]
(0) TLS_accept: SSLv3 read client hello A
(0) >>> send TLS 1.2 [length 0036]
(0) TLS_accept: SSLv3 write server hello A
(0) >>> send TLS 1.2 [length 0004]
(0) TLS_accept: SSLv3 write server done A
(0) TLS_accept: SSLv3 flush data
(0) TLS_accept: SSLv3 read client certificate A
(0) TLS_accept: Need to read more data: SSLv3 read client key exchange A
(0) TLS_accept: Need to read more data: SSLv3 read client key exchange A
(0) In SSL Handshake Phase
(0) In SSL Accept mode
Waking up in 0.7 seconds.
(0) <<< recv TLS 1.2 [length 0010]
rlm_sql (psksql): Reserved connection (0)
(0) Executing select query: select hex(key) from psk_keys where keyid = 'key-4e72e5'
rlm_sql (psksql): Released connection (0)
(0) EXPAND %{psksql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}
(0) --> 544233A38D055202F75127A33B3EBD5BA9563978C788959361BD61D746EF6DCF82580789031CDDDEF3A27B46C108F678807500B4B9A5578A513E5148A1B1588DF2AD347A90F371468309F1C5C217B41C7B8188FECD1D09A378FA2BA8A858C4A230ECF721AADB4C32721CACBE48F23FD29EE8F3C97DA2BF954CFED68FC89247921570531BD23F2CAAF9E02FFA0344A0C8F2423EBC7CC76BF165843F985EA25198663C5971529BB415E6F70B9BA871B0FD172D36B37ABB4C71D88EF04D2AE6FD00795F53DD4D12D725FA6570BDE2CDAF116FA48BA8622BED439CB1CC7ED59D872F090046F7BEBCE9FDE0256E1AB939BA8401A37D9C5AB53B437CE1635F1EE71D21
(0) TLS_accept: SSLv3 read client key exchange A
(0) TLS_accept: SSLv3 read certificate verify A
(0) <<< recv TLS 1.2 [length 0001]
(0) <<< recv TLS 1.2 [length 0010]
(0) TLS_accept: SSLv3 read finished A
(0) >>> send TLS 1.2 [length 0001]
(0) TLS_accept: SSLv3 write change cipher spec A
(0) >>> send TLS 1.2 [length 0010]
(0) TLS_accept: SSLv3 write finished A
(0) TLS_accept: SSLv3 flush data
(0) (other): SSL negotiation finished successfully
(0) SSL Connection Established
Waking up in 0.7 seconds.
(0) Application data status 7
(0) tls_recv: Access-Request packet from host 13.94.115.212 port 48186, id=222, length=186
Threads: total/active/spare threads = 5/0/5
Waking up in 0.3 seconds.
Thread 5 got semaphore
Thread 5 handling request 0, (1 handled so far)
(0) Retrieved psk identity: key-4e72e5
(0) Received Access-Request Id 222 from 13.94.115.212:48186 to 0.0.0.0:2083 length 186
(0) TLS-PSK-Identity := "key-4e72e5"
(0) User-Name = "@idp.test.assent"
(0) EAP-Message = 0x0200001501406964702e746573742e617373656e74
(0) Message-Authenticator = 0x904db79a53aa1ee03a4a72f2e960f441
(0) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(0) Trust-Router-COI = "apc.test.assent"
(0) GSS-Acceptor-Realm-Name = "assent-test-service.test.assent"
(0) Event-Timestamp = "Apr 23 2018 15:36:17 UTC"
(0) NAS-IP-Address = 127.0.0.1
(0) Proxy-State = 0x30
(0) # Executing section authorize from file /etc/raddb/sites-enabled/abfab-tr-idp
(0) authorize {
(0) policy psk_authorize {
(0) if (&TLS-PSK-Identity) {
(0) if (&TLS-PSK-Identity) -> TRUE
(0) if (&TLS-PSK-Identity) {
(0) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") {
rlm_sql (psksql): Reserved connection (1)
(0) Executing select query: select distinct keyid from authorizations_keys where keyid = 'key-4e72e5' and 'apc.test.assent' like coi and 'assent-test-service.test.assent' like acceptor_realm and 'service.moonshot-playpen.ti.ja.net' like hostname;
rlm_sql (psksql): Released connection (1)
(0) EXPAND %{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}
(0) --> key-4e72e5
(0) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") -> TRUE
(0) ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") { ... } # empty sub-section is ignored
(0) ... skipping else: Preceding "if" was taken
(0) } # if (&TLS-PSK-Identity) = notfound
(0) } # policy psk_authorize = notfound
(0) policy abfab_client_check {
(0) if ("%{client:gss_acceptor_host_name}") {
(0) EXPAND %{client:gss_acceptor_host_name}
(0) -->
(0) if ("%{client:gss_acceptor_host_name}") -> FALSE
(0) if ("%{client:trust_router_coi}") {
(0) EXPAND %{client:trust_router_coi}
(0) --> apc.test.assent
(0) if ("%{client:trust_router_coi}") -> TRUE
(0) if ("%{client:trust_router_coi}") {
(0) update request {
(0) EXPAND %{client:trust_router_coi}
(0) --> apc.test.assent
(0) Trust-Router-COI := apc.test.assent
(0) } # update request = noop
(0) } # if ("%{client:trust_router_coi}") = noop
(0) if ("%{client:gss_acceptor_realm_name}") {
(0) EXPAND %{client:gss_acceptor_realm_name}
(0) --> assent-fr-idp.test.assent
(0) if ("%{client:gss_acceptor_realm_name}") -> TRUE
(0) if ("%{client:gss_acceptor_realm_name}") {
(0) update request {
(0) EXPAND %{client:gss_acceptor_realm_name}
(0) --> assent-fr-idp.test.assent
(0) GSS-Acceptor-Realm-Name := assent-fr-idp.test.assent
(0) } # update request = noop
(0) } # if ("%{client:gss_acceptor_realm_name}") = noop
(0) if ("%{client:gss_acceptor_service_name}") {
(0) EXPAND %{client:gss_acceptor_service_name}
(0) -->
(0) if ("%{client:gss_acceptor_service_name}") -> FALSE
(0) } # policy abfab_client_check = noop
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = noop
(0) } # policy filter_username = noop
(0) [preprocess] = ok
(0) suffix: Checking for suffix after "@"
(0) suffix: Looking up realm "idp.test.assent" for User-Name = "@idp.test.assent"
(0) suffix: No trust router configured, skipping dynamic realm lookup
(0) suffix: Found realm "idp.test.assent"
(0) suffix: Adding Stripped-User-Name = ""
(0) suffix: Adding Realm = "idp.test.assent"
(0) suffix: Authentication realm is LOCAL
(0) [suffix] = ok
(0) eap: Peer sent EAP Response (code 2) ID 0 length 21
(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(0) [eap] = ok
(0) } # authorize = ok
(0) Found Auth-Type = eap
(0) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(0) authenticate {
(0) eap: Peer sent packet with method EAP Identity (1)
(0) eap: Calling submodule eap_ttls to process data
(0) eap_ttls: Initiating new EAP-TLS session
(0) eap_ttls: [eaptls start] = request
(0) eap: Sending EAP Request (code 1) ID 1 length 6
(0) eap: EAP session adding &reply:State = 0x99ee34c099ef2160
(0) [eap] = handled
(0) } # authenticate = handled
(0) Using Post-Auth-Type Challenge
(0) Post-Auth-Type sub-section not found. Ignoring.
(0) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(0) Sent Access-Challenge Id 222 from 0.0.0.0:2083 to 13.94.115.212:48186 length 0
(0) EAP-Message = 0x010100061520
(0) Message-Authenticator = 0x00000000000000000000000000000000
(0) State = 0x99ee34c099ef21606abcbf8df3266bc7
(0) Proxy-State = 0x30
(0) Finished request
Thread 5 waiting to be assigned a request
(0) Application data status 7
(0) tls_recv: Access-Request packet from host 13.94.115.212 port 48186, id=207, length=496
Waking up in 0.2 seconds.
Thread 4 got semaphore
Thread 4 handling request 1, (1 handled so far)
(1) Retrieved psk identity: key-4e72e5
(1) Received Access-Request Id 207 from 13.94.115.212:48186 to 0.0.0.0:2083 length 496
(1) TLS-PSK-Identity := "key-4e72e5"
(1) User-Name = "@idp.test.assent"
(1) EAP-Message = 0x020101371500160301012c0100012803032511bb54ecd0c2c9f87ce917b94c1a2a653ee2f53266fffc75406d78eac6a4b10000aac030c02cc028c024c014c00a00a500a300a1009f006b006a0069006800390038003700360088008700860085c032c02ec02ac026c00fc005009d003d00350084c02fc0
(1) State = 0x99ee34c099ef21606abcbf8df3266bc7
(1) Message-Authenticator = 0x2f4cf0aaa31a35695a73957ae5e0a21f
(1) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(1) Trust-Router-COI = "apc.test.assent"
(1) GSS-Acceptor-Realm-Name = "assent-test-service.test.assent"
(1) Event-Timestamp = "Apr 23 2018 15:36:17 UTC"
(1) NAS-IP-Address = 127.0.0.1
(1) Proxy-State = 0x30
(1) session-state: No cached attributes
(1) # Executing section authorize from file /etc/raddb/sites-enabled/abfab-tr-idp
(1) authorize {
(1) policy psk_authorize {
(1) if (&TLS-PSK-Identity) {
(1) if (&TLS-PSK-Identity) -> TRUE
(1) if (&TLS-PSK-Identity) {
(1) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") {
rlm_sql (psksql): Reserved connection (2)
(1) Executing select query: select distinct keyid from authorizations_keys where keyid = 'key-4e72e5' and 'apc.test.assent' like coi and 'assent-test-service.test.assent' like acceptor_realm and 'service.moonshot-playpen.ti.ja.net' like hostname;
rlm_sql (psksql): Released connection (2)
(1) EXPAND %{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}
(1) --> key-4e72e5
(1) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") -> TRUE
(1) ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") { ... } # empty sub-section is ignored
(1) ... skipping else: Preceding "if" was taken
(1) } # if (&TLS-PSK-Identity) = notfound
(1) } # policy psk_authorize = notfound
(1) policy abfab_client_check {
(1) if ("%{client:gss_acceptor_host_name}") {
(1) EXPAND %{client:gss_acceptor_host_name}
(1) -->
(1) if ("%{client:gss_acceptor_host_name}") -> FALSE
(1) if ("%{client:trust_router_coi}") {
(1) EXPAND %{client:trust_router_coi}
(1) --> apc.test.assent
(1) if ("%{client:trust_router_coi}") -> TRUE
(1) if ("%{client:trust_router_coi}") {
(1) update request {
(1) EXPAND %{client:trust_router_coi}
(1) --> apc.test.assent
(1) Trust-Router-COI := apc.test.assent
(1) } # update request = noop
(1) } # if ("%{client:trust_router_coi}") = noop
(1) if ("%{client:gss_acceptor_realm_name}") {
(1) EXPAND %{client:gss_acceptor_realm_name}
(1) --> assent-fr-idp.test.assent
(1) if ("%{client:gss_acceptor_realm_name}") -> TRUE
(1) if ("%{client:gss_acceptor_realm_name}") {
(1) update request {
(1) EXPAND %{client:gss_acceptor_realm_name}
(1) --> assent-fr-idp.test.assent
(1) GSS-Acceptor-Realm-Name := assent-fr-idp.test.assent
(1) } # update request = noop
(1) } # if ("%{client:gss_acceptor_realm_name}") = noop
(1) if ("%{client:gss_acceptor_service_name}") {
(1) EXPAND %{client:gss_acceptor_service_name}
(1) -->
(1) if ("%{client:gss_acceptor_service_name}") -> FALSE
(1) } # policy abfab_client_check = noop
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # if (&User-Name) = noop
(1) } # policy filter_username = noop
(1) [preprocess] = ok
(1) suffix: Checking for suffix after "@"
(1) suffix: Looking up realm "idp.test.assent" for User-Name = "@idp.test.assent"
(1) suffix: No trust router configured, skipping dynamic realm lookup
(1) suffix: Found realm "idp.test.assent"
(1) suffix: Adding Stripped-User-Name = ""
(1) suffix: Adding Realm = "idp.test.assent"
(1) suffix: Authentication realm is LOCAL
(1) [suffix] = ok
(1) eap: Peer sent EAP Response (code 2) ID 1 length 311
(1) eap: Continuing tunnel setup
(1) [eap] = ok
(1) } # authorize = ok
(1) Found Auth-Type = eap
(1) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(1) authenticate {
(1) eap: Expiring EAP session with state 0x99ee34c099ef2160
(1) eap: Finished EAP session with state 0x99ee34c099ef2160
(1) eap: Previous EAP request found for state 0x99ee34c099ef2160, released from the list
(1) eap: Peer sent packet with method EAP TTLS (21)
(1) eap: Calling submodule eap_ttls to process data
(1) eap_ttls: Authenticate
(1) eap_ttls: Continuing EAP-TLS
(1) eap_ttls: Got final TLS record fragment (305 bytes)
(1) eap_ttls: WARNING: Total received TLS record fragments (305 bytes), does not equal indicated TLS record length (0 bytes)
(1) eap_ttls: [eaptls verify] = ok
(1) eap_ttls: Done initial handshake
(1) eap_ttls: (other): before/accept initialization
(1) eap_ttls: TLS_accept: before/accept initialization
(1) eap_ttls: <<< recv TLS 1.2 [length 012c]
(1) eap_ttls: TLS_accept: SSLv3 read client hello A
(1) eap_ttls: >>> send TLS 1.2 [length 003e]
(1) eap_ttls: TLS_accept: SSLv3 write server hello A
(1) eap_ttls: >>> send TLS 1.2 [length 09f2]
(1) eap_ttls: TLS_accept: SSLv3 write certificate A
(1) eap_ttls: >>> send TLS 1.2 [length 014d]
(1) eap_ttls: TLS_accept: SSLv3 write key exchange A
(1) eap_ttls: >>> send TLS 1.2 [length 0004]
(1) eap_ttls: TLS_accept: SSLv3 write server done A
(1) eap_ttls: TLS_accept: SSLv3 flush data
(1) eap_ttls: TLS_accept: SSLv3 read client certificate A
(1) eap_ttls: TLS_accept: Need to read more data: SSLv3 read client key exchange A
(1) eap_ttls: TLS_accept: Need to read more data: SSLv3 read client key exchange A
(1) eap_ttls: In SSL Handshake Phase
(1) eap_ttls: In SSL Accept mode
(1) eap_ttls: [eaptls process] = handled
(1) eap: Sending EAP Request (code 1) ID 2 length 1004
(1) eap: EAP session adding &reply:State = 0x99ee34c098ec2160
(1) [eap] = handled
(1) } # authenticate = handled
(1) Using Post-Auth-Type Challenge
(1) Post-Auth-Type sub-section not found. Ignoring.
(1) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(1) Sent Access-Challenge Id 207 from 0.0.0.0:2083 to 13.94.115.212:48186 length 0
(1) EAP-Message = 0x010203ec15c000000b95160303003e0200003a030303ad08db91f444207565cdeeb5e9c7c4e268921916965c0dd035e96a1d73e4e100c030000012ff01000100000b000403000102000f00010116030309f20b0009ee0009eb00044e3082044a30820332a003020102020101300d06092a864886f70d01
(1) Message-Authenticator = 0x00000000000000000000000000000000
(1) State = 0x99ee34c098ec21606abcbf8df3266bc7
(1) Proxy-State = 0x30
(1) Finished request
Thread 4 waiting to be assigned a request
(0) Application data status 7
(0) tls_recv: Access-Request packet from host 13.94.115.212 port 48186, id=84, length=189
Waking up in 0.2 seconds.
Thread 3 got semaphore
Thread 3 handling request 2, (1 handled so far)
(2) Retrieved psk identity: key-4e72e5
(2) Received Access-Request Id 84 from 13.94.115.212:48186 to 0.0.0.0:2083 length 189
(2) TLS-PSK-Identity := "key-4e72e5"
(2) User-Name = "@idp.test.assent"
(2) EAP-Message = 0x020200061500
(2) State = 0x99ee34c098ec21606abcbf8df3266bc7
(2) Message-Authenticator = 0x3b0e06a072a1c513cd23499e50dec081
(2) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(2) Trust-Router-COI = "apc.test.assent"
(2) GSS-Acceptor-Realm-Name = "assent-test-service.test.assent"
(2) Event-Timestamp = "Apr 23 2018 15:36:17 UTC"
(2) NAS-IP-Address = 127.0.0.1
(2) Proxy-State = 0x30
(2) session-state: No cached attributes
(2) # Executing section authorize from file /etc/raddb/sites-enabled/abfab-tr-idp
(2) authorize {
(2) policy psk_authorize {
(2) if (&TLS-PSK-Identity) {
(2) if (&TLS-PSK-Identity) -> TRUE
(2) if (&TLS-PSK-Identity) {
(2) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") {
rlm_sql (psksql): Reserved connection (3)
(2) Executing select query: select distinct keyid from authorizations_keys where keyid = 'key-4e72e5' and 'apc.test.assent' like coi and 'assent-test-service.test.assent' like acceptor_realm and 'service.moonshot-playpen.ti.ja.net' like hostname;
rlm_sql (psksql): Released connection (3)
(2) EXPAND %{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}
(2) --> key-4e72e5
(2) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") -> TRUE
(2) ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") { ... } # empty sub-section is ignored
(2) ... skipping else: Preceding "if" was taken
(2) } # if (&TLS-PSK-Identity) = notfound
(2) } # policy psk_authorize = notfound
(2) policy abfab_client_check {
(2) if ("%{client:gss_acceptor_host_name}") {
(2) EXPAND %{client:gss_acceptor_host_name}
(2) -->
(2) if ("%{client:gss_acceptor_host_name}") -> FALSE
(2) if ("%{client:trust_router_coi}") {
(2) EXPAND %{client:trust_router_coi}
(2) --> apc.test.assent
(2) if ("%{client:trust_router_coi}") -> TRUE
(2) if ("%{client:trust_router_coi}") {
(2) update request {
(2) EXPAND %{client:trust_router_coi}
(2) --> apc.test.assent
(2) Trust-Router-COI := apc.test.assent
(2) } # update request = noop
(2) } # if ("%{client:trust_router_coi}") = noop
(2) if ("%{client:gss_acceptor_realm_name}") {
(2) EXPAND %{client:gss_acceptor_realm_name}
(2) --> assent-fr-idp.test.assent
(2) if ("%{client:gss_acceptor_realm_name}") -> TRUE
(2) if ("%{client:gss_acceptor_realm_name}") {
(2) update request {
(2) EXPAND %{client:gss_acceptor_realm_name}
(2) --> assent-fr-idp.test.assent
(2) GSS-Acceptor-Realm-Name := assent-fr-idp.test.assent
(2) } # update request = noop
(2) } # if ("%{client:gss_acceptor_realm_name}") = noop
(2) if ("%{client:gss_acceptor_service_name}") {
(2) EXPAND %{client:gss_acceptor_service_name}
(2) -->
(2) if ("%{client:gss_acceptor_service_name}") -> FALSE
(2) } # policy abfab_client_check = noop
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) } # if (&User-Name) = noop
(2) } # policy filter_username = noop
(2) [preprocess] = ok
(2) suffix: Checking for suffix after "@"
(2) suffix: Looking up realm "idp.test.assent" for User-Name = "@idp.test.assent"
(2) suffix: No trust router configured, skipping dynamic realm lookup
(2) suffix: Found realm "idp.test.assent"
(2) suffix: Adding Stripped-User-Name = ""
(2) suffix: Adding Realm = "idp.test.assent"
(2) suffix: Authentication realm is LOCAL
(2) [suffix] = ok
(2) eap: Peer sent EAP Response (code 2) ID 2 length 6
(2) eap: Continuing tunnel setup
(2) [eap] = ok
(2) } # authorize = ok
(2) Found Auth-Type = eap
(2) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(2) authenticate {
(2) eap: Expiring EAP session with state 0x99ee34c098ec2160
(2) eap: Finished EAP session with state 0x99ee34c098ec2160
(2) eap: Previous EAP request found for state 0x99ee34c098ec2160, released from the list
(2) eap: Peer sent packet with method EAP TTLS (21)
(2) eap: Calling submodule eap_ttls to process data
(2) eap_ttls: Authenticate
(2) eap_ttls: Continuing EAP-TLS
(2) eap_ttls: Peer ACKed our handshake fragment
(2) eap_ttls: [eaptls verify] = request
(2) eap_ttls: [eaptls process] = handled
(2) eap: Sending EAP Request (code 1) ID 3 length 1004
(2) eap: EAP session adding &reply:State = 0x99ee34c09bed2160
(2) [eap] = handled
(2) } # authenticate = handled
(2) Using Post-Auth-Type Challenge
(2) Post-Auth-Type sub-section not found. Ignoring.
(2) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(2) Sent Access-Challenge Id 84 from 0.0.0.0:2083 to 13.94.115.212:48186 length 0
(2) EAP-Message = 0x010303ec15c000000b957bf00fb3723fe2b582405cc3a74e7ab536ae9cc835c2c003636f275ff298982c68049eaa0c6b20bcc571dee510518708b05d49740ead4b0533a3f7d6198257bd78d381cd8ee99c995fa5e0091214ce297ae2a75977b468b039b838054d458a86f65bb0ae89d85b70facb7972d5
(2) Message-Authenticator = 0x00000000000000000000000000000000
(2) State = 0x99ee34c09bed21606abcbf8df3266bc7
(2) Proxy-State = 0x30
(2) Finished request
Thread 3 waiting to be assigned a request
(0) Application data status 7
(0) tls_recv: Access-Request packet from host 13.94.115.212 port 48186, id=66, length=189
Waking up in 0.1 seconds.
Thread 2 got semaphore
Thread 2 handling request 3, (1 handled so far)
(3) Retrieved psk identity: key-4e72e5
(3) Received Access-Request Id 66 from 13.94.115.212:48186 to 0.0.0.0:2083 length 189
(3) TLS-PSK-Identity := "key-4e72e5"
(3) User-Name = "@idp.test.assent"
(3) EAP-Message = 0x020300061500
(3) State = 0x99ee34c09bed21606abcbf8df3266bc7
(3) Message-Authenticator = 0x3e92ccb72595994fbf44f101ea9b9e7f
(3) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(3) Trust-Router-COI = "apc.test.assent"
(3) GSS-Acceptor-Realm-Name = "assent-test-service.test.assent"
(3) Event-Timestamp = "Apr 23 2018 15:36:17 UTC"
(3) NAS-IP-Address = 127.0.0.1
(3) Proxy-State = 0x30
(3) session-state: No cached attributes
(3) # Executing section authorize from file /etc/raddb/sites-enabled/abfab-tr-idp
(3) authorize {
(3) policy psk_authorize {
(3) if (&TLS-PSK-Identity) {
(3) if (&TLS-PSK-Identity) -> TRUE
(3) if (&TLS-PSK-Identity) {
(3) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") {
rlm_sql (psksql): Reserved connection (4)
(3) Executing select query: select distinct keyid from authorizations_keys where keyid = 'key-4e72e5' and 'apc.test.assent' like coi and 'assent-test-service.test.assent' like acceptor_realm and 'service.moonshot-playpen.ti.ja.net' like hostname;
rlm_sql (psksql): Released connection (4)
(3) EXPAND %{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}
(3) --> key-4e72e5
(3) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") -> TRUE
(3) ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") { ... } # empty sub-section is ignored
(3) ... skipping else: Preceding "if" was taken
(3) } # if (&TLS-PSK-Identity) = notfound
(3) } # policy psk_authorize = notfound
(3) policy abfab_client_check {
(3) if ("%{client:gss_acceptor_host_name}") {
(3) EXPAND %{client:gss_acceptor_host_name}
(3) -->
(3) if ("%{client:gss_acceptor_host_name}") -> FALSE
(3) if ("%{client:trust_router_coi}") {
(3) EXPAND %{client:trust_router_coi}
(3) --> apc.test.assent
(3) if ("%{client:trust_router_coi}") -> TRUE
(3) if ("%{client:trust_router_coi}") {
(3) update request {
(3) EXPAND %{client:trust_router_coi}
(3) --> apc.test.assent
(3) Trust-Router-COI := apc.test.assent
(3) } # update request = noop
(3) } # if ("%{client:trust_router_coi}") = noop
(3) if ("%{client:gss_acceptor_realm_name}") {
(3) EXPAND %{client:gss_acceptor_realm_name}
(3) --> assent-fr-idp.test.assent
(3) if ("%{client:gss_acceptor_realm_name}") -> TRUE
(3) if ("%{client:gss_acceptor_realm_name}") {
(3) update request {
(3) EXPAND %{client:gss_acceptor_realm_name}
(3) --> assent-fr-idp.test.assent
(3) GSS-Acceptor-Realm-Name := assent-fr-idp.test.assent
(3) } # update request = noop
(3) } # if ("%{client:gss_acceptor_realm_name}") = noop
(3) if ("%{client:gss_acceptor_service_name}") {
(3) EXPAND %{client:gss_acceptor_service_name}
(3) -->
(3) if ("%{client:gss_acceptor_service_name}") -> FALSE
(3) } # policy abfab_client_check = noop
(3) policy filter_username {
(3) if (&User-Name) {
(3) if (&User-Name) -> TRUE
(3) if (&User-Name) {
(3) if (&User-Name =~ / /) {
(3) if (&User-Name =~ / /) -> FALSE
(3) if (&User-Name =~ /@[^@]*@/ ) {
(3) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(3) if (&User-Name =~ /\.\./ ) {
(3) if (&User-Name =~ /\.\./ ) -> FALSE
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(3) if (&User-Name =~ /\.$/) {
(3) if (&User-Name =~ /\.$/) -> FALSE
(3) if (&User-Name =~ /(a)\./) {
(3) if (&User-Name =~ /(a)\./) -> FALSE
(3) } # if (&User-Name) = noop
(3) } # policy filter_username = noop
(3) [preprocess] = ok
(3) suffix: Checking for suffix after "@"
(3) suffix: Looking up realm "idp.test.assent" for User-Name = "@idp.test.assent"
(3) suffix: No trust router configured, skipping dynamic realm lookup
(3) suffix: Found realm "idp.test.assent"
(3) suffix: Adding Stripped-User-Name = ""
(3) suffix: Adding Realm = "idp.test.assent"
(3) suffix: Authentication realm is LOCAL
(3) [suffix] = ok
(3) eap: Peer sent EAP Response (code 2) ID 3 length 6
(3) eap: Continuing tunnel setup
(3) [eap] = ok
(3) } # authorize = ok
(3) Found Auth-Type = eap
(3) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(3) authenticate {
(3) eap: Expiring EAP session with state 0x99ee34c09bed2160
(3) eap: Finished EAP session with state 0x99ee34c09bed2160
(3) eap: Previous EAP request found for state 0x99ee34c09bed2160, released from the list
(3) eap: Peer sent packet with method EAP TTLS (21)
(3) eap: Calling submodule eap_ttls to process data
(3) eap_ttls: Authenticate
(3) eap_ttls: Continuing EAP-TLS
(3) eap_ttls: Peer ACKed our handshake fragment
(3) eap_ttls: [eaptls verify] = request
(3) eap_ttls: [eaptls process] = handled
(3) eap: Sending EAP Request (code 1) ID 4 length 987
(3) eap: EAP session adding &reply:State = 0x99ee34c09aea2160
(3) [eap] = handled
(3) } # authenticate = handled
(3) Using Post-Auth-Type Challenge
(3) Post-Auth-Type sub-section not found. Ignoring.
(3) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(3) Sent Access-Challenge Id 66 from 0.0.0.0:2083 to 13.94.115.212:48186 length 0
(3) EAP-Message = 0x010403db158000000b95663ceff515d00535b798c82edd71a7591a6517308201020603551d230481fa3081f780149c663ceff515d00535b798c82edd71a7591a6517a181d3a481d03081cd310b30090603550406130247423114301206035504080c0b4f78666f726473686972653110300e0603550407
(3) Message-Authenticator = 0x00000000000000000000000000000000
(3) State = 0x99ee34c09aea21606abcbf8df3266bc7
(3) Proxy-State = 0x30
(3) Finished request
Thread 2 waiting to be assigned a request
(0) Application data status 7
(0) tls_recv: Access-Request packet from host 13.94.115.212 port 48186, id=35, length=315
Thread 1 got semaphore
Thread 1 handling request 4, (1 handled so far)
(4) Retrieved psk identity: key-4e72e5
(4) Received Access-Request Id 35 from 13.94.115.212:48186 to 0.0.0.0:2083 length 315
(4) TLS-PSK-Identity := "key-4e72e5"
(4) User-Name = "@idp.test.assent"
(4) EAP-Message = 0x020400841500160303004610000042410468d99894f17aa98dc8611a7b2dcbe6872feb9ce4d67306a7de57e9896578636dcb96edb9f27f89ac4d37d9998436714567010fefd6c2ae4b28c989a974acf6311403030001011603030028a14d973586558f26407aea94cf8bc17a44b4c3819b349ab450a451
(4) State = 0x99ee34c09aea21606abcbf8df3266bc7
(4) Message-Authenticator = 0x5b48baac1553d9ae88fe0e42b7ddb874
(4) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(4) Trust-Router-COI = "apc.test.assent"
(4) GSS-Acceptor-Realm-Name = "assent-test-service.test.assent"
(4) Event-Timestamp = "Apr 23 2018 15:36:17 UTC"
(4) NAS-IP-Address = 127.0.0.1
(4) Proxy-State = 0x30
(4) session-state: No cached attributes
(4) # Executing section authorize from file /etc/raddb/sites-enabled/abfab-tr-idp
(4) authorize {
(4) policy psk_authorize {
(4) if (&TLS-PSK-Identity) {
(4) if (&TLS-PSK-Identity) -> TRUE
(4) if (&TLS-PSK-Identity) {
(4) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") {
rlm_sql (psksql): Reserved connection (0)
(4) Executing select query: select distinct keyid from authorizations_keys where keyid = 'key-4e72e5' and 'apc.test.assent' like coi and 'assent-test-service.test.assent' like acceptor_realm and 'service.moonshot-playpen.ti.ja.net' like hostname;
rlm_sql (psksql): Released connection (0)
(4) EXPAND %{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}
(4) --> key-4e72e5
(4) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") -> TRUE
(4) ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") { ... } # empty sub-section is ignored
(4) ... skipping else: Preceding "if" was taken
(4) } # if (&TLS-PSK-Identity) = notfound
(4) } # policy psk_authorize = notfound
(4) policy abfab_client_check {
(4) if ("%{client:gss_acceptor_host_name}") {
(4) EXPAND %{client:gss_acceptor_host_name}
(4) -->
(4) if ("%{client:gss_acceptor_host_name}") -> FALSE
(4) if ("%{client:trust_router_coi}") {
(4) EXPAND %{client:trust_router_coi}
(4) --> apc.test.assent
(4) if ("%{client:trust_router_coi}") -> TRUE
(4) if ("%{client:trust_router_coi}") {
(4) update request {
(4) EXPAND %{client:trust_router_coi}
(4) --> apc.test.assent
(4) Trust-Router-COI := apc.test.assent
(4) } # update request = noop
(4) } # if ("%{client:trust_router_coi}") = noop
(4) if ("%{client:gss_acceptor_realm_name}") {
(4) EXPAND %{client:gss_acceptor_realm_name}
(4) --> assent-fr-idp.test.assent
(4) if ("%{client:gss_acceptor_realm_name}") -> TRUE
(4) if ("%{client:gss_acceptor_realm_name}") {
(4) update request {
(4) EXPAND %{client:gss_acceptor_realm_name}
(4) --> assent-fr-idp.test.assent
(4) GSS-Acceptor-Realm-Name := assent-fr-idp.test.assent
(4) } # update request = noop
(4) } # if ("%{client:gss_acceptor_realm_name}") = noop
(4) if ("%{client:gss_acceptor_service_name}") {
(4) EXPAND %{client:gss_acceptor_service_name}
(4) -->
(4) if ("%{client:gss_acceptor_service_name}") -> FALSE
(4) } # policy abfab_client_check = noop
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) } # if (&User-Name) = noop
(4) } # policy filter_username = noop
(4) [preprocess] = ok
(4) suffix: Checking for suffix after "@"
(4) suffix: Looking up realm "idp.test.assent" for User-Name = "@idp.test.assent"
(4) suffix: No trust router configured, skipping dynamic realm lookup
(4) suffix: Found realm "idp.test.assent"
(4) suffix: Adding Stripped-User-Name = ""
(4) suffix: Adding Realm = "idp.test.assent"
(4) suffix: Authentication realm is LOCAL
(4) [suffix] = ok
(4) eap: Peer sent EAP Response (code 2) ID 4 length 132
(4) eap: Continuing tunnel setup
(4) [eap] = ok
(4) } # authorize = ok
(4) Found Auth-Type = eap
(4) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(4) authenticate {
(4) eap: Expiring EAP session with state 0x99ee34c09aea2160
(4) eap: Finished EAP session with state 0x99ee34c09aea2160
(4) eap: Previous EAP request found for state 0x99ee34c09aea2160, released from the list
(4) eap: Peer sent packet with method EAP TTLS (21)
(4) eap: Calling submodule eap_ttls to process data
(4) eap_ttls: Authenticate
(4) eap_ttls: Continuing EAP-TLS
(4) eap_ttls: [eaptls verify] = ok
(4) eap_ttls: Done initial handshake
(4) eap_ttls: <<< recv TLS 1.2 [length 0046]
(4) eap_ttls: TLS_accept: SSLv3 read client key exchange A
(4) eap_ttls: TLS_accept: SSLv3 read certificate verify A
(4) eap_ttls: <<< recv TLS 1.2 [length 0001]
(4) eap_ttls: <<< recv TLS 1.2 [length 0010]
(4) eap_ttls: TLS_accept: SSLv3 read finished A
(4) eap_ttls: >>> send TLS 1.2 [length 0001]
(4) eap_ttls: TLS_accept: SSLv3 write change cipher spec A
(4) eap_ttls: >>> send TLS 1.2 [length 0010]
(4) eap_ttls: TLS_accept: SSLv3 write finished A
(4) eap_ttls: TLS_accept: SSLv3 flush data
(4) eap_ttls: (other): SSL negotiation finished successfully
(4) eap_ttls: SSL Connection Established
(4) eap_ttls: [eaptls process] = handled
(4) eap: Sending EAP Request (code 1) ID 5 length 61
(4) eap: EAP session adding &reply:State = 0x99ee34c09deb2160
(4) [eap] = handled
(4) } # authenticate = handled
(4) Using Post-Auth-Type Challenge
(4) Post-Auth-Type sub-section not found. Ignoring.
(4) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(4) Sent Access-Challenge Id 35 from 0.0.0.0:2083 to 13.94.115.212:48186 length 0
(4) EAP-Message = 0x0105003d158000000033140303000101160303002896caae9b220ab065f33cee302945123fcd3953ed0f957d23becd25f738f9749e76680a61d9f70c11
(4) Message-Authenticator = 0x00000000000000000000000000000000
(4) State = 0x99ee34c09deb21606abcbf8df3266bc7
(4) Proxy-State = 0x30
(4) Finished request
Thread 1 waiting to be assigned a request
(0) Application data status 7
(0) tls_recv: Access-Request packet from host 13.94.115.212 port 48186, id=183, length=250
Thread 5 got semaphore
Thread 5 handling request 5, (2 handled so far)
(5) Retrieved psk identity: key-4e72e5
(5) Received Access-Request Id 183 from 13.94.115.212:48186 to 0.0.0.0:2083 length 250
(5) TLS-PSK-Identity := "key-4e72e5"
(5) User-Name = "@idp.test.assent"
(5) EAP-Message = 0x0205004315001703030038a14d973586558f274576c0dc8704eeb292bb84e8a3c9a809552d1d923c21226ab1bdce7821ccb920d0677a6048fb272d505685d90b557e35
(5) State = 0x99ee34c09deb21606abcbf8df3266bc7
(5) Message-Authenticator = 0x77c3d8c12657209875082fd71b5b3400
(5) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(5) Trust-Router-COI = "apc.test.assent"
(5) GSS-Acceptor-Realm-Name = "assent-test-service.test.assent"
(5) Event-Timestamp = "Apr 23 2018 15:36:17 UTC"
(5) NAS-IP-Address = 127.0.0.1
(5) Proxy-State = 0x30
(5) session-state: No cached attributes
(5) # Executing section authorize from file /etc/raddb/sites-enabled/abfab-tr-idp
(5) authorize {
(5) policy psk_authorize {
(5) if (&TLS-PSK-Identity) {
(5) if (&TLS-PSK-Identity) -> TRUE
(5) if (&TLS-PSK-Identity) {
(5) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") {
rlm_sql (psksql): Reserved connection (1)
(5) Executing select query: select distinct keyid from authorizations_keys where keyid = 'key-4e72e5' and 'apc.test.assent' like coi and 'assent-test-service.test.assent' like acceptor_realm and 'service.moonshot-playpen.ti.ja.net' like hostname;
rlm_sql (psksql): Released connection (1)
(5) EXPAND %{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}
(5) --> key-4e72e5
(5) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") -> TRUE
(5) ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") { ... } # empty sub-section is ignored
(5) ... skipping else: Preceding "if" was taken
(5) } # if (&TLS-PSK-Identity) = notfound
(5) } # policy psk_authorize = notfound
(5) policy abfab_client_check {
(5) if ("%{client:gss_acceptor_host_name}") {
(5) EXPAND %{client:gss_acceptor_host_name}
(5) -->
(5) if ("%{client:gss_acceptor_host_name}") -> FALSE
(5) if ("%{client:trust_router_coi}") {
(5) EXPAND %{client:trust_router_coi}
(5) --> apc.test.assent
(5) if ("%{client:trust_router_coi}") -> TRUE
(5) if ("%{client:trust_router_coi}") {
(5) update request {
(5) EXPAND %{client:trust_router_coi}
(5) --> apc.test.assent
(5) Trust-Router-COI := apc.test.assent
(5) } # update request = noop
(5) } # if ("%{client:trust_router_coi}") = noop
(5) if ("%{client:gss_acceptor_realm_name}") {
(5) EXPAND %{client:gss_acceptor_realm_name}
(5) --> assent-fr-idp.test.assent
(5) if ("%{client:gss_acceptor_realm_name}") -> TRUE
(5) if ("%{client:gss_acceptor_realm_name}") {
(5) update request {
(5) EXPAND %{client:gss_acceptor_realm_name}
(5) --> assent-fr-idp.test.assent
(5) GSS-Acceptor-Realm-Name := assent-fr-idp.test.assent
(5) } # update request = noop
(5) } # if ("%{client:gss_acceptor_realm_name}") = noop
(5) if ("%{client:gss_acceptor_service_name}") {
(5) EXPAND %{client:gss_acceptor_service_name}
(5) -->
(5) if ("%{client:gss_acceptor_service_name}") -> FALSE
(5) } # policy abfab_client_check = noop
(5) policy filter_username {
(5) if (&User-Name) {
(5) if (&User-Name) -> TRUE
(5) if (&User-Name) {
(5) if (&User-Name =~ / /) {
(5) if (&User-Name =~ / /) -> FALSE
(5) if (&User-Name =~ /@[^@]*@/ ) {
(5) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(5) if (&User-Name =~ /\.\./ ) {
(5) if (&User-Name =~ /\.\./ ) -> FALSE
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(5) if (&User-Name =~ /\.$/) {
(5) if (&User-Name =~ /\.$/) -> FALSE
(5) if (&User-Name =~ /(a)\./) {
(5) if (&User-Name =~ /(a)\./) -> FALSE
(5) } # if (&User-Name) = noop
(5) } # policy filter_username = noop
(5) [preprocess] = ok
(5) suffix: Checking for suffix after "@"
(5) suffix: Looking up realm "idp.test.assent" for User-Name = "@idp.test.assent"
(5) suffix: No trust router configured, skipping dynamic realm lookup
(5) suffix: Found realm "idp.test.assent"
(5) suffix: Adding Stripped-User-Name = ""
(5) suffix: Adding Realm = "idp.test.assent"
(5) suffix: Authentication realm is LOCAL
(5) [suffix] = ok
(5) eap: Peer sent EAP Response (code 2) ID 5 length 67
(5) eap: Continuing tunnel setup
(5) [eap] = ok
(5) } # authorize = ok
(5) Found Auth-Type = eap
(5) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(5) authenticate {
(5) eap: Expiring EAP session with state 0x99ee34c09deb2160
(5) eap: Finished EAP session with state 0x99ee34c09deb2160
(5) eap: Previous EAP request found for state 0x99ee34c09deb2160, released from the list
(5) eap: Peer sent packet with method EAP TTLS (21)
(5) eap: Calling submodule eap_ttls to process data
(5) eap_ttls: Authenticate
(5) eap_ttls: Continuing EAP-TLS
(5) eap_ttls: [eaptls verify] = ok
(5) eap_ttls: Done initial handshake
(5) eap_ttls: [eaptls process] = ok
(5) eap_ttls: Session established. Proceeding to decode tunneled attributes
(5) eap_ttls: Got tunneled request
(5) eap_ttls: EAP-Message = 0x0200001801626f62406964702e746573742e617373656e74
(5) eap_ttls: FreeRADIUS-Proxied-To = 127.0.0.1
(5) eap_ttls: Got tunneled identity of bob(a)idp.test.assent
(5) eap_ttls: Setting default EAP type for tunneled EAP session
(5) eap_ttls: Sending tunneled request
(5) Virtual server inner-tunnel received request
(5) EAP-Message = 0x0200001801626f62406964702e746573742e617373656e74
(5) FreeRADIUS-Proxied-To = 127.0.0.1
(5) User-Name = "bob(a)idp.test.assent"
(5) server inner-tunnel {
(5) # Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
(5) authorize {
(5) policy filter_username {
(5) if (&User-Name) {
(5) if (&User-Name) -> TRUE
(5) if (&User-Name) {
(5) if (&User-Name =~ / /) {
(5) if (&User-Name =~ / /) -> FALSE
(5) if (&User-Name =~ /@[^@]*@/ ) {
(5) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(5) if (&User-Name =~ /\.\./ ) {
(5) if (&User-Name =~ /\.\./ ) -> FALSE
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(5) if (&User-Name =~ /\.$/) {
(5) if (&User-Name =~ /\.$/) -> FALSE
(5) if (&User-Name =~ /(a)\./) {
(5) if (&User-Name =~ /(a)\./) -> FALSE
(5) } # if (&User-Name) = notfound
(5) } # policy filter_username = notfound
(5) [chap] = noop
(5) [mschap] = noop
(5) suffix: Checking for suffix after "@"
(5) suffix: Looking up realm "idp.test.assent" for User-Name = "bob(a)idp.test.assent"
(5) suffix: No trust router configured, skipping dynamic realm lookup
(5) suffix: Found realm "idp.test.assent"
(5) suffix: Adding Stripped-User-Name = "bob"
(5) suffix: Adding Realm = "idp.test.assent"
(5) suffix: Authentication realm is LOCAL
(5) [suffix] = ok
(5) update control {
(5) &Proxy-To-Realm := LOCAL
(5) } # update control = noop
(5) eap: Peer sent EAP Response (code 2) ID 0 length 24
(5) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(5) [eap] = ok
(5) } # authorize = ok
(5) Found Auth-Type = eap
(5) # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
(5) authenticate {
(5) eap: Peer sent packet with method EAP Identity (1)
(5) eap: Calling submodule eap_md5 to process data
(5) eap_md5: Issuing MD5 Challenge
(5) eap: Sending EAP Request (code 1) ID 1 length 22
(5) eap: EAP session adding &reply:State = 0x3c80b67c3c81b298
(5) [eap] = handled
(5) } # authenticate = handled
(5) } # server inner-tunnel
(5) Virtual server sending reply
(5) EAP-Message = 0x0101001604108601bd43f14033602f432ae5adb72d86
(5) Message-Authenticator = 0x00000000000000000000000000000000
(5) State = 0x3c80b67c3c81b298e3175f119958de79
(5) eap_ttls: Got tunneled Access-Challenge
(5) eap: Sending EAP Request (code 1) ID 6 length 71
(5) eap: EAP session adding &reply:State = 0x99ee34c09ce82160
(5) [eap] = handled
(5) } # authenticate = handled
(5) Using Post-Auth-Type Challenge
(5) Post-Auth-Type sub-section not found. Ignoring.
(5) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(5) Sent Access-Challenge Id 183 from 0.0.0.0:2083 to 13.94.115.212:48186 length 0
(5) EAP-Message = 0x0106004715800000003d170303003896caae9b220ab0660e76bacafaf2fe033362766fd145e32c0aba49fca7cafcc02dd038b81e3d971f85e056212ab2c47f4bc576ee0c259234
(5) Message-Authenticator = 0x00000000000000000000000000000000
(5) State = 0x99ee34c09ce821606abcbf8df3266bc7
(5) Proxy-State = 0x30
(5) Finished request
Thread 5 waiting to be assigned a request
(0) Application data status 7
(0) tls_recv: Access-Request packet from host 13.94.115.212 port 48186, id=189, length=310
Thread 4 got semaphore
Thread 4 handling request 6, (2 handled so far)
(6) Retrieved psk identity: key-4e72e5
(6) Received Access-Request Id 189 from 13.94.115.212:48186 to 0.0.0.0:2083 length 310
(6) TLS-PSK-Identity := "key-4e72e5"
(6) User-Name = "@idp.test.assent"
(6) EAP-Message = 0x0206007f15001703030074a14d973586558f280dd3a2f38f398bdac90710dafb687dba8df5b7ec1e33e9b47730696aff1bb6286ab4b68994f5bdb187edd27e5e83be6a1add9436d04cc1e9c91c62663cafd68ced457bf1cedf394fb4dbbc3aee0f6015025cdbcd6d4c397e10bef466308cbf87dda67757
(6) State = 0x99ee34c09ce821606abcbf8df3266bc7
(6) Message-Authenticator = 0x98d250a4613b2c499cf8de10d2bb2229
(6) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(6) Trust-Router-COI = "apc.test.assent"
(6) GSS-Acceptor-Realm-Name = "assent-test-service.test.assent"
(6) Event-Timestamp = "Apr 23 2018 15:36:17 UTC"
(6) NAS-IP-Address = 127.0.0.1
(6) Proxy-State = 0x30
(6) session-state: No cached attributes
(6) # Executing section authorize from file /etc/raddb/sites-enabled/abfab-tr-idp
(6) authorize {
(6) policy psk_authorize {
(6) if (&TLS-PSK-Identity) {
(6) if (&TLS-PSK-Identity) -> TRUE
(6) if (&TLS-PSK-Identity) {
(6) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") {
rlm_sql (psksql): Reserved connection (2)
(6) Executing select query: select distinct keyid from authorizations_keys where keyid = 'key-4e72e5' and 'apc.test.assent' like coi and 'assent-test-service.test.assent' like acceptor_realm and 'service.moonshot-playpen.ti.ja.net' like hostname;
rlm_sql (psksql): Released connection (2)
(6) EXPAND %{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}
(6) --> key-4e72e5
(6) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") -> TRUE
(6) ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") { ... } # empty sub-section is ignored
(6) ... skipping else: Preceding "if" was taken
(6) } # if (&TLS-PSK-Identity) = notfound
(6) } # policy psk_authorize = notfound
(6) policy abfab_client_check {
(6) if ("%{client:gss_acceptor_host_name}") {
(6) EXPAND %{client:gss_acceptor_host_name}
(6) -->
(6) if ("%{client:gss_acceptor_host_name}") -> FALSE
(6) if ("%{client:trust_router_coi}") {
(6) EXPAND %{client:trust_router_coi}
(6) --> apc.test.assent
(6) if ("%{client:trust_router_coi}") -> TRUE
(6) if ("%{client:trust_router_coi}") {
(6) update request {
(6) EXPAND %{client:trust_router_coi}
(6) --> apc.test.assent
(6) Trust-Router-COI := apc.test.assent
(6) } # update request = noop
(6) } # if ("%{client:trust_router_coi}") = noop
(6) if ("%{client:gss_acceptor_realm_name}") {
(6) EXPAND %{client:gss_acceptor_realm_name}
(6) --> assent-fr-idp.test.assent
(6) if ("%{client:gss_acceptor_realm_name}") -> TRUE
(6) if ("%{client:gss_acceptor_realm_name}") {
(6) update request {
(6) EXPAND %{client:gss_acceptor_realm_name}
(6) --> assent-fr-idp.test.assent
(6) GSS-Acceptor-Realm-Name := assent-fr-idp.test.assent
(6) } # update request = noop
(6) } # if ("%{client:gss_acceptor_realm_name}") = noop
(6) if ("%{client:gss_acceptor_service_name}") {
(6) EXPAND %{client:gss_acceptor_service_name}
(6) -->
(6) if ("%{client:gss_acceptor_service_name}") -> FALSE
(6) } # policy abfab_client_check = noop
(6) policy filter_username {
(6) if (&User-Name) {
(6) if (&User-Name) -> TRUE
(6) if (&User-Name) {
(6) if (&User-Name =~ / /) {
(6) if (&User-Name =~ / /) -> FALSE
(6) if (&User-Name =~ /@[^@]*@/ ) {
(6) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(6) if (&User-Name =~ /\.\./ ) {
(6) if (&User-Name =~ /\.\./ ) -> FALSE
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(6) if (&User-Name =~ /\.$/) {
(6) if (&User-Name =~ /\.$/) -> FALSE
(6) if (&User-Name =~ /(a)\./) {
(6) if (&User-Name =~ /(a)\./) -> FALSE
(6) } # if (&User-Name) = noop
(6) } # policy filter_username = noop
(6) [preprocess] = ok
(6) suffix: Checking for suffix after "@"
(6) suffix: Looking up realm "idp.test.assent" for User-Name = "@idp.test.assent"
(6) suffix: No trust router configured, skipping dynamic realm lookup
(6) suffix: Found realm "idp.test.assent"
(6) suffix: Adding Stripped-User-Name = ""
(6) suffix: Adding Realm = "idp.test.assent"
(6) suffix: Authentication realm is LOCAL
(6) [suffix] = ok
(6) eap: Peer sent EAP Response (code 2) ID 6 length 127
(6) eap: Continuing tunnel setup
(6) [eap] = ok
(6) } # authorize = ok
(6) Found Auth-Type = eap
(6) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(6) authenticate {
(6) eap: Expiring EAP session with state 0x3c80b67c3c81b298
(6) eap: Finished EAP session with state 0x99ee34c09ce82160
(6) eap: Previous EAP request found for state 0x99ee34c09ce82160, released from the list
(6) eap: Peer sent packet with method EAP TTLS (21)
(6) eap: Calling submodule eap_ttls to process data
(6) eap_ttls: Authenticate
(6) eap_ttls: Continuing EAP-TLS
(6) eap_ttls: [eaptls verify] = ok
(6) eap_ttls: Done initial handshake
(6) eap_ttls: [eaptls process] = ok
(6) eap_ttls: Session established. Proceeding to decode tunneled attributes
(6) eap_ttls: Got tunneled request
(6) eap_ttls: EAP-Channel-Binding-Message = 0x01002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(6) eap_ttls: EAP-Message = 0x020100160410f198c98646992dab6e556338cc256901
(6) eap_ttls: FreeRADIUS-Proxied-To = 127.0.0.1
(6) eap_ttls: Sending tunneled request
(6) eap_ttls: received chbind request
(6) Virtual server channel_bindings received request
(6) FreeRADIUS-Proxied-To = 127.0.0.1
(6) User-Name = "bob(a)idp.test.assent"
(6) GSS-Acceptor-Service-Name = "HTTP"
(6) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(6) server channel_bindings {
(6) # Executing section authorize from file /etc/raddb/sites-enabled/channel_bindings
(6) authorize {
(6) policy abfab_channel_bindings {
(6) if (&GSS-Acceptor-Service-Name && (&outer.request:GSS-Acceptor-Service-Name != &GSS-Acceptor-Service-Name)) {
(6) ERROR: Failed retrieving values required to evaluate condition
(6) if (&GSS-Acceptor-Host-Name && &outer.request:GSS-Acceptor-Host-Name != &GSS-Acceptor-Host-Name ) {
(6) if (&GSS-Acceptor-Host-Name && &outer.request:GSS-Acceptor-Host-Name != &GSS-Acceptor-Host-Name ) -> FALSE
(6) if (&GSS-Acceptor-Realm-Name && &outer.request:GSS-Acceptor-Realm-Name != &GSS-Acceptor-Realm-Name ) {
(6) if (&GSS-Acceptor-Realm-Name && &outer.request:GSS-Acceptor-Realm-Name != &GSS-Acceptor-Realm-Name ) -> FALSE
(6) if (&GSS-Acceptor-Service-Name || &GSS-Acceptor-Realm-Name || &GSS-Acceptor-Host-Name) {
(6) if (&GSS-Acceptor-Service-Name || &GSS-Acceptor-Realm-Name || &GSS-Acceptor-Host-Name) -> TRUE
(6) if (&GSS-Acceptor-Service-Name || &GSS-Acceptor-Realm-Name || &GSS-Acceptor-Host-Name) {
(6) update control {
(6) &Chbind-Response-Code := success
(6) } # update control = noop
(6) update reply {
(6) &GSS-Acceptor-Service-Name = &GSS-Acceptor-Service-Name -> 'HTTP'
(6) &GSS-Acceptor-Host-Name = &GSS-Acceptor-Host-Name -> 'service.moonshot-playpen.ti.ja.net'
(6) No attributes updated
(6) } # update reply = noop
(6) } # if (&GSS-Acceptor-Service-Name || &GSS-Acceptor-Realm-Name || &GSS-Acceptor-Host-Name) = noop
(6) [handled] = handled
(6) } # policy abfab_channel_bindings = handled
(6) } # authorize = handled
(6) } # server channel_bindings
(6) Virtual server sending reply
(6) GSS-Acceptor-Service-Name = "HTTP"
(6) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(6) Sending chbind response: code 2
(6) GSS-Acceptor-Service-Name = "HTTP"
(6) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(6) eap_ttls: sending chbind response
(6) Virtual server inner-tunnel received request
(6) EAP-Channel-Binding-Message = 0x01002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(6) EAP-Message = 0x020100160410f198c98646992dab6e556338cc256901
(6) FreeRADIUS-Proxied-To = 127.0.0.1
(6) User-Name = "bob(a)idp.test.assent"
(6) State = 0x3c80b67c3c81b298e3175f119958de79
(6) server inner-tunnel {
(6) session-state: No cached attributes
(6) # Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
(6) authorize {
(6) policy filter_username {
(6) if (&User-Name) {
(6) if (&User-Name) -> TRUE
(6) if (&User-Name) {
(6) if (&User-Name =~ / /) {
(6) if (&User-Name =~ / /) -> FALSE
(6) if (&User-Name =~ /@[^@]*@/ ) {
(6) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(6) if (&User-Name =~ /\.\./ ) {
(6) if (&User-Name =~ /\.\./ ) -> FALSE
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(6) if (&User-Name =~ /\.$/) {
(6) if (&User-Name =~ /\.$/) -> FALSE
(6) if (&User-Name =~ /(a)\./) {
(6) if (&User-Name =~ /(a)\./) -> FALSE
(6) } # if (&User-Name) = notfound
(6) } # policy filter_username = notfound
(6) [chap] = noop
(6) [mschap] = noop
(6) suffix: Checking for suffix after "@"
(6) suffix: Looking up realm "idp.test.assent" for User-Name = "bob(a)idp.test.assent"
(6) suffix: No trust router configured, skipping dynamic realm lookup
(6) suffix: Found realm "idp.test.assent"
(6) suffix: Adding Stripped-User-Name = "bob"
(6) suffix: Adding Realm = "idp.test.assent"
(6) suffix: Authentication realm is LOCAL
(6) [suffix] = ok
(6) update control {
(6) &Proxy-To-Realm := LOCAL
(6) } # update control = noop
(6) eap: Peer sent EAP Response (code 2) ID 1 length 22
(6) eap: No EAP Start, assuming it's an on-going EAP conversation
(6) [eap] = updated
(6) files: users: Matched entry bob at line 80
(6) [files] = ok
(6) [expiration] = noop
(6) [logintime] = noop
(6) pap: WARNING: Auth-Type already set. Not setting to PAP
(6) [pap] = noop
(6) } # authorize = updated
(6) Found Auth-Type = eap
(6) # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
(6) authenticate {
(6) eap: Expiring EAP session with state 0x3c80b67c3c81b298
(6) eap: Finished EAP session with state 0x3c80b67c3c81b298
(6) eap: Previous EAP request found for state 0x3c80b67c3c81b298, released from the list
(6) eap: Peer sent packet with method EAP MD5 (4)
(6) eap: Calling submodule eap_md5 to process data
(6) eap: Sending EAP Success (code 3) ID 1 length 4
(6) eap: Freeing handler
(6) [eap] = ok
(6) } # authenticate = ok
(6) # Executing section post-auth from file /etc/raddb/sites-enabled/inner-tunnel
(6) post-auth {
(6) policy moonshot_host_tid.post-auth {
(6) if (&outer.request:GSS-Acceptor-Host-Name) {
(6) if (&outer.request:GSS-Acceptor-Host-Name) -> TRUE
(6) if (&outer.request:GSS-Acceptor-Host-Name) {
(6) update control {
(6) EXPAND %{tolower:%{outer.request:GSS-Acceptor-Host-Name}}
(6) --> service.moonshot-playpen.ti.ja.net
(6) Moonshot-MSTID-GSS-Acceptor := service.moonshot-playpen.ti.ja.net
(6) Moonshot-MSTID-Namespace := "a574a04e-b7ff-4850-aa24-a8599c7de1c6"
(6) } # update control = noop
(6) if (!&control:Moonshot-MSTID-TargetedId) {
(6) if (!&control:Moonshot-MSTID-TargetedId) -> TRUE
(6) if (!&control:Moonshot-MSTID-TargetedId) {
(6) policy moonshot_make_targeted_id.post-auth {
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) {
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) -> TRUE
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) {
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) {
(6) Executing: /usr/bin/uuid -v 5 a574a04e-b7ff-4850-aa24-a8599c7de1c6 bob@idp.test.assentt[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zdservice.moonshot-playpen.ti.ja.net:
(6) Program returned code (0) and output '33127397-1bb6-5e95-8859-dfe76acfba67'
(6) EXPAND %{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}
(6) --> 33127397-1bb6-5e95-8859-dfe76acfba67
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) -> TRUE
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) {
(6) update control {
(6) EXPAND %{1}@%{tolower:%{request:Realm}}
(6) --> 33127397-1bb6-5e95-8859-dfe76acfba67(a)idp.test.assent
(6) Moonshot-MSTID-TargetedId := 33127397-1bb6-5e95-8859-dfe76acfba67(a)idp.test.assent
(6) } # update control = noop
(6) if (&control:Moonshot-MSTID-TargetedId =~ /([\%\{\}]+)/) {
(6) EXPAND ([\%\{\}]+)
(6) --> ([\%\{\}]+)
(6) if (&control:Moonshot-MSTID-TargetedId =~ /([\%\{\}]+)/) -> FALSE
(6) } # if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) = noop
(6) ... skipping else: Preceding "if" was taken
(6) } # if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) = noop
(6) ... skipping else: Preceding "if" was taken
(6) } # policy moonshot_make_targeted_id.post-auth = noop
(6) } # if (!&control:Moonshot-MSTID-TargetedId) = noop
(6) if (&control:Moonshot-MSTID-TargetedId) {
(6) if (&control:Moonshot-MSTID-TargetedId) -> TRUE
(6) if (&control:Moonshot-MSTID-TargetedId) {
(6) update outer.session-state {
(6) Moonshot-Host-TargetedId := &control:Moonshot-MSTID-TargetedId -> '33127397-1bb6-5e95-8859-dfe76acfba67(a)idp.test.assent'
(6) } # update outer.session-state = noop
(6) update control {
(6) Moonshot-MSTID-TargetedId !* ANY
(6) } # update control = noop
(6) } # if (&control:Moonshot-MSTID-TargetedId) = noop
(6) } # if (&outer.request:GSS-Acceptor-Host-Name) = noop
(6) } # policy moonshot_host_tid.post-auth = noop
(6) policy moonshot_realm_tid.post-auth {
(6) if (&outer.request:GSS-Acceptor-Realm-Name) {
(6) if (&outer.request:GSS-Acceptor-Realm-Name) -> TRUE
(6) if (&outer.request:GSS-Acceptor-Realm-Name) {
(6) update control {
(6) EXPAND %{tolower:%{outer.request:GSS-Acceptor-Realm-Name}}
(6) --> assent-fr-idp.test.assent
(6) Moonshot-MSTID-GSS-Acceptor := assent-fr-idp.test.assent
(6) Moonshot-MSTID-Namespace := "dea5f26d-a013-4444-977d-d09fc990d2e6"
(6) } # update control = noop
(6) if (!&control:Moonshot-MSTID-TargetedId) {
(6) if (!&control:Moonshot-MSTID-TargetedId) -> TRUE
(6) if (!&control:Moonshot-MSTID-TargetedId) {
(6) policy moonshot_make_targeted_id.post-auth {
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) {
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) -> TRUE
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) {
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) {
(6) Executing: /usr/bin/uuid -v 5 dea5f26d-a013-4444-977d-d09fc990d2e6 bob@idp.test.assentt[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zdassent-fr-idp.test.assent:
(6) Program returned code (0) and output 'abd0d71b-7294-5423-86b1-3fae0bd7b33a'
(6) EXPAND %{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}
(6) --> abd0d71b-7294-5423-86b1-3fae0bd7b33a
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) -> TRUE
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) {
(6) update control {
(6) EXPAND %{1}@%{tolower:%{request:Realm}}
(6) --> abd0d71b-7294-5423-86b1-3fae0bd7b33a(a)idp.test.assent
(6) Moonshot-MSTID-TargetedId := abd0d71b-7294-5423-86b1-3fae0bd7b33a(a)idp.test.assent
(6) } # update control = noop
(6) if (&control:Moonshot-MSTID-TargetedId =~ /([\%\{\}]+)/) {
(6) EXPAND ([\%\{\}]+)
(6) --> ([\%\{\}]+)
(6) if (&control:Moonshot-MSTID-TargetedId =~ /([\%\{\}]+)/) -> FALSE
(6) } # if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) = noop
(6) ... skipping else: Preceding "if" was taken
(6) } # if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) = noop
(6) ... skipping else: Preceding "if" was taken
(6) } # policy moonshot_make_targeted_id.post-auth = noop
(6) } # if (!&control:Moonshot-MSTID-TargetedId) = noop
(6) if (&control:Moonshot-MSTID-TargetedId) {
(6) if (&control:Moonshot-MSTID-TargetedId) -> TRUE
(6) if (&control:Moonshot-MSTID-TargetedId) {
(6) update outer.session-state {
(6) Moonshot-Realm-TargetedId := &control:Moonshot-MSTID-TargetedId -> 'abd0d71b-7294-5423-86b1-3fae0bd7b33a(a)idp.test.assent'
(6) } # update outer.session-state = noop
(6) update control {
(6) Moonshot-MSTID-TargetedId !* ANY
(6) } # update control = noop
(6) } # if (&control:Moonshot-MSTID-TargetedId) = noop
(6) } # if (&outer.request:GSS-Acceptor-Realm-Name) = noop
(6) } # policy moonshot_realm_tid.post-auth = noop
(6) policy moonshot_coi_tid.post-auth {
(6) if (&outer.request:Trust-Router-COI) {
(6) if (&outer.request:Trust-Router-COI) -> TRUE
(6) if (&outer.request:Trust-Router-COI) {
(6) update control {
(6) EXPAND %{tolower:%{outer.request:Trust-Router-COI}}
(6) --> apc.test.assent
(6) Moonshot-MSTID-GSS-Acceptor := apc.test.assent
(6) Moonshot-MSTID-Namespace := "145d7e7e-7d54-43ee-bbcb-3c6ad9428247"
(6) } # update control = noop
(6) if (!&control:Moonshot-MSTID-TargetedId) {
(6) if (!&control:Moonshot-MSTID-TargetedId) -> TRUE
(6) if (!&control:Moonshot-MSTID-TargetedId) {
(6) policy moonshot_make_targeted_id.post-auth {
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) {
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) -> TRUE
(6) if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) {
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) {
(6) Executing: /usr/bin/uuid -v 5 145d7e7e-7d54-43ee-bbcb-3c6ad9428247 bob(a)idp.test.assentt[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zdapc.test.assent:
(6) Program returned code (0) and output 'b40d0def-5b25-52bd-8d13-e6d22fa24648'
(6) EXPAND %{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}
(6) --> b40d0def-5b25-52bd-8d13-e6d22fa24648
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) -> TRUE
(6) if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) {
(6) update control {
(6) EXPAND %{1}@%{tolower:%{request:Realm}}
(6) --> b40d0def-5b25-52bd-8d13-e6d22fa24648(a)idp.test.assent
(6) Moonshot-MSTID-TargetedId := b40d0def-5b25-52bd-8d13-e6d22fa24648(a)idp.test.assent
(6) } # update control = noop
(6) if (&control:Moonshot-MSTID-TargetedId =~ /([\%\{\}]+)/) {
(6) EXPAND ([\%\{\}]+)
(6) --> ([\%\{\}]+)
(6) if (&control:Moonshot-MSTID-TargetedId =~ /([\%\{\}]+)/) -> FALSE
(6) } # if ("%{echo:/usr/bin/uuid -v 5 %{control:Moonshot-MSTID-Namespace} %{tolower:%{User-Name}}t[?.V)Are7gQmFCYK\{!T*JdWqD\{\{Zd%{control:Moonshot-MSTID-GSS-Acceptor}}" =~ /^([^ ]+)([ ]*)$/) = noop
(6) ... skipping else: Preceding "if" was taken
(6) } # if (&control:Moonshot-MSTID-Namespace && &control:Moonshot-MSTID-GSS-Acceptor) = noop
(6) ... skipping else: Preceding "if" was taken
(6) } # policy moonshot_make_targeted_id.post-auth = noop
(6) } # if (!&control:Moonshot-MSTID-TargetedId) = noop
(6) if (&control:Moonshot-MSTID-TargetedId) {
(6) if (&control:Moonshot-MSTID-TargetedId) -> TRUE
(6) if (&control:Moonshot-MSTID-TargetedId) {
(6) update outer.session-state {
(6) Moonshot-TR-COI-TargetedId := &control:Moonshot-MSTID-TargetedId -> 'b40d0def-5b25-52bd-8d13-e6d22fa24648(a)idp.test.assent'
(6) } # update outer.session-state = noop
(6) update control {
(6) Moonshot-MSTID-TargetedId !* ANY
(6) } # update control = noop
(6) } # if (&control:Moonshot-MSTID-TargetedId) = noop
(6) } # if (&outer.request:Trust-Router-COI) = noop
(6) } # policy moonshot_coi_tid.post-auth = noop
(6) if (1) {
(6) if (1) -> TRUE
(6) if (1) {
(6) update reply {
(6) Message-Authenticator !* ANY
(6) EAP-Message !* ANY
(6) Proxy-State !* ANY
(6) MS-MPPE-Encryption-Types !* ANY
(6) MS-MPPE-Encryption-Policy !* ANY
(6) MS-MPPE-Send-Key !* ANY
(6) MS-MPPE-Recv-Key !* ANY
(6) } # update reply = noop
(6) update {
(6) &outer.session-state::EAP-Channel-Binding-Message += &reply:EAP-Channel-Binding-Message[*] -> 0x02002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(6) &outer.session-state::Reply-Message += &reply:Reply-Message[*] -> 'Bob has authenticated'
(6) &outer.session-state::User-Name += &reply:User-Name[*] -> 'root'
(6) } # update = noop
(6) } # if (1) = noop
(6) } # post-auth = noop
(6) } # server inner-tunnel
(6) Virtual server sending reply
(6) EAP-Channel-Binding-Message = 0x02002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(6) Reply-Message = "Bob has authenticated"
(6) User-Name = "root"
(6) eap_ttls: Got tunneled Access-Accept
(6) eap_ttls: Sending tunneled reply attributes
(6) eap_ttls: EAP-Channel-Binding-Message = 0x02002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(6) eap: Sending EAP Request (code 1) ID 7 length 99
(6) eap: EAP session adding &reply:State = 0x99ee34c09fe92160
(6) [eap] = handled
(6) } # authenticate = handled
(6) Using Post-Auth-Type Challenge
(6) Post-Auth-Type sub-section not found. Ignoring.
(6) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(6) session-state: Saving cached attributes
(6) Moonshot-Host-TargetedId := "33127397-1bb6-5e95-8859-dfe76acfba67(a)idp.test.assent"
(6) Moonshot-Realm-TargetedId := "abd0d71b-7294-5423-86b1-3fae0bd7b33a(a)idp.test.assent"
(6) Moonshot-TR-COI-TargetedId := "b40d0def-5b25-52bd-8d13-e6d22fa24648(a)idp.test.assent"
(6) EAP-Channel-Binding-Message += 0x02002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(6) Reply-Message += "Bob has authenticated"
(6) User-Name += "root"
(6) Sent Access-Challenge Id 189 from 0.0.0.0:2083 to 13.94.115.212:48186 length 0
(6) EAP-Message = 0x01070063158000000059170303005496caae9b220ab067aecc7766fafc738318bbd56dcf3f59b7dd26e4a7e77c2fdac72c555890bb6886eb6cf1d317cd9726d06259d3573d6068a5b77b30f78ec840a5c103390937fd16d61ad67c3ef762da375219fc
(6) Message-Authenticator = 0x00000000000000000000000000000000
(6) State = 0x99ee34c09fe921606abcbf8df3266bc7
(6) Proxy-State = 0x30
(6) Finished request
Thread 4 waiting to be assigned a request
(0) Application data status 7
(0) tls_recv: Access-Request packet from host 13.94.115.212 port 48186, id=83, length=189
Thread 3 got semaphore
Thread 3 handling request 7, (2 handled so far)
(7) Retrieved psk identity: key-4e72e5
(7) Received Access-Request Id 83 from 13.94.115.212:48186 to 0.0.0.0:2083 length 189
(7) TLS-PSK-Identity := "key-4e72e5"
(7) User-Name = "@idp.test.assent"
(7) EAP-Message = 0x020700061500
(7) State = 0x99ee34c09fe921606abcbf8df3266bc7
(7) Message-Authenticator = 0x8a936d20e611d1380195029de5055114
(7) GSS-Acceptor-Host-Name = "service.moonshot-playpen.ti.ja.net"
(7) Trust-Router-COI = "apc.test.assent"
(7) GSS-Acceptor-Realm-Name = "assent-test-service.test.assent"
(7) Event-Timestamp = "Apr 23 2018 15:36:17 UTC"
(7) NAS-IP-Address = 127.0.0.1
(7) Proxy-State = 0x30
(7) Restoring &session-state
(7) &session-state:Moonshot-Host-TargetedId := "33127397-1bb6-5e95-8859-dfe76acfba67(a)idp.test.assent"
(7) &session-state:Moonshot-Realm-TargetedId := "abd0d71b-7294-5423-86b1-3fae0bd7b33a(a)idp.test.assent"
(7) &session-state:Moonshot-TR-COI-TargetedId := "b40d0def-5b25-52bd-8d13-e6d22fa24648(a)idp.test.assent"
(7) &session-state:EAP-Channel-Binding-Message += 0x02002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(7) &session-state:Reply-Message += "Bob has authenticated"
(7) &session-state:User-Name += "root"
(7) # Executing section authorize from file /etc/raddb/sites-enabled/abfab-tr-idp
(7) authorize {
(7) policy psk_authorize {
(7) if (&TLS-PSK-Identity) {
(7) if (&TLS-PSK-Identity) -> TRUE
(7) if (&TLS-PSK-Identity) {
(7) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") {
rlm_sql (psksql): Reserved connection (3)
(7) Executing select query: select distinct keyid from authorizations_keys where keyid = 'key-4e72e5' and 'apc.test.assent' like coi and 'assent-test-service.test.assent' like acceptor_realm and 'service.moonshot-playpen.ti.ja.net' like hostname;
rlm_sql (psksql): Released connection (3)
(7) EXPAND %{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}
(7) --> key-4e72e5
(7) if ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") -> TRUE
(7) ("%{psksql:select distinct keyid from authorizations_keys where keyid = '%{tls-psk-identity}' and '%{trust-router-coi}' like coi and '%{gss-acceptor-realm-name}' like acceptor_realm and '%{gss-acceptor-host-name}' like hostname;}") { ... } # empty sub-section is ignored
(7) ... skipping else: Preceding "if" was taken
(7) } # if (&TLS-PSK-Identity) = notfound
(7) } # policy psk_authorize = notfound
(7) policy abfab_client_check {
(7) if ("%{client:gss_acceptor_host_name}") {
(7) EXPAND %{client:gss_acceptor_host_name}
(7) -->
(7) if ("%{client:gss_acceptor_host_name}") -> FALSE
(7) if ("%{client:trust_router_coi}") {
(7) EXPAND %{client:trust_router_coi}
(7) --> apc.test.assent
(7) if ("%{client:trust_router_coi}") -> TRUE
(7) if ("%{client:trust_router_coi}") {
(7) update request {
(7) EXPAND %{client:trust_router_coi}
(7) --> apc.test.assent
(7) Trust-Router-COI := apc.test.assent
(7) } # update request = noop
(7) } # if ("%{client:trust_router_coi}") = noop
(7) if ("%{client:gss_acceptor_realm_name}") {
(7) EXPAND %{client:gss_acceptor_realm_name}
(7) --> assent-fr-idp.test.assent
(7) if ("%{client:gss_acceptor_realm_name}") -> TRUE
(7) if ("%{client:gss_acceptor_realm_name}") {
(7) update request {
(7) EXPAND %{client:gss_acceptor_realm_name}
(7) --> assent-fr-idp.test.assent
(7) GSS-Acceptor-Realm-Name := assent-fr-idp.test.assent
(7) } # update request = noop
(7) } # if ("%{client:gss_acceptor_realm_name}") = noop
(7) if ("%{client:gss_acceptor_service_name}") {
(7) EXPAND %{client:gss_acceptor_service_name}
(7) -->
(7) if ("%{client:gss_acceptor_service_name}") -> FALSE
(7) } # policy abfab_client_check = noop
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = noop
(7) } # policy filter_username = noop
(7) [preprocess] = ok
(7) suffix: Checking for suffix after "@"
(7) suffix: Looking up realm "idp.test.assent" for User-Name = "@idp.test.assent"
(7) suffix: No trust router configured, skipping dynamic realm lookup
(7) suffix: Found realm "idp.test.assent"
(7) suffix: Adding Stripped-User-Name = ""
(7) suffix: Adding Realm = "idp.test.assent"
(7) suffix: Authentication realm is LOCAL
(7) [suffix] = ok
(7) eap: Peer sent EAP Response (code 2) ID 7 length 6
(7) eap: Continuing tunnel setup
(7) [eap] = ok
(7) } # authorize = ok
(7) Found Auth-Type = eap
(7) # Executing group from file /etc/raddb/sites-enabled/abfab-tr-idp
(7) authenticate {
(7) eap: Expiring EAP session with state 0x99ee34c09fe92160
(7) eap: Finished EAP session with state 0x99ee34c09fe92160
(7) eap: Previous EAP request found for state 0x99ee34c09fe92160, released from the list
(7) eap: Peer sent packet with method EAP TTLS (21)
(7) eap: Calling submodule eap_ttls to process data
(7) eap_ttls: Authenticate
(7) eap_ttls: Continuing EAP-TLS
(7) eap_ttls: Peer ACKed our handshake fragment. handshake is finished
(7) eap_ttls: [eaptls verify] = success
(7) eap_ttls: [eaptls process] = success
(7) eap: Sending EAP Success (code 3) ID 7 length 4
(7) eap: Freeing handler
(7) [eap] = ok
(7) } # authenticate = ok
(7) # Executing section post-auth from file /etc/raddb/sites-enabled/abfab-tr-idp
(7) post-auth {
(7) update {
(7) &reply::Moonshot-Host-TargetedId += &session-state:Moonshot-Host-TargetedId[*] -> '33127397-1bb6-5e95-8859-dfe76acfba67(a)idp.test.assent'
(7) &reply::Moonshot-Realm-TargetedId += &session-state:Moonshot-Realm-TargetedId[*] -> 'abd0d71b-7294-5423-86b1-3fae0bd7b33a(a)idp.test.assent'
(7) &reply::Moonshot-TR-COI-TargetedId += &session-state:Moonshot-TR-COI-TargetedId[*] -> 'b40d0def-5b25-52bd-8d13-e6d22fa24648(a)idp.test.assent'
(7) &reply::EAP-Channel-Binding-Message += &session-state:EAP-Channel-Binding-Message[*] -> 0x02002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(7) &reply::Reply-Message += &session-state:Reply-Message[*] -> 'Bob has authenticated'
(7) &reply::User-Name += &session-state:User-Name[*] -> 'root'
(7) } # update = noop
(7) [exec] = noop
(7) policy remove_reply_message_if_eap {
(7) if (&reply:EAP-Message && &reply:Reply-Message) {
(7) if (&reply:EAP-Message && &reply:Reply-Message) -> TRUE
(7) if (&reply:EAP-Message && &reply:Reply-Message) {
(7) update reply {
(7) &Reply-Message !* ANY
(7) } # update reply = noop
(7) } # if (&reply:EAP-Message && &reply:Reply-Message) = noop
(7) ... skipping else: Preceding "if" was taken
(7) } # policy remove_reply_message_if_eap = noop
(7) } # post-auth = noop
(7) Sent Access-Accept Id 83 from 0.0.0.0:2083 to 13.94.115.212:48186 length 0
(7) MS-MPPE-Recv-Key = 0x1ee8bbd31cd79fd4e98d946e946e1f976b7aaebd6e5412b4bab51b2e2d784c9c
(7) MS-MPPE-Send-Key = 0x4de6d0ddcf7a725afc0a7e4b7fb2478b5c59a76ac5689342d33fbcdb4787f2c7
(7) EAP-Message = 0x03070004
(7) Message-Authenticator = 0x00000000000000000000000000000000
(7) User-Name = "@idp.test.assent"
(7) Proxy-State = 0x30
(7) Moonshot-Host-TargetedId += "33127397-1bb6-5e95-8859-dfe76acfba67(a)idp.test.assent"
(7) Moonshot-Realm-TargetedId += "abd0d71b-7294-5423-86b1-3fae0bd7b33a(a)idp.test.assent"
(7) Moonshot-TR-COI-TargetedId += "b40d0def-5b25-52bd-8d13-e6d22fa24648(a)idp.test.assent"
(7) EAP-Channel-Binding-Message += 0x02002a01a40648545450a524736572766963652e6d6f6f6e73686f742d706c617970656e2e74692e6a612e6e6574
(7) User-Name += "root"
(7) Finished request
Thread 3 waiting to be assigned a request
Waking up in 4.2 seconds.
(0) Cleaning up request packet ID 222 with timestamp +5
(1) Cleaning up request packet ID 207 with timestamp +5
(2) Cleaning up request packet ID 84 with timestamp +5
(3) Cleaning up request packet ID 66 with timestamp +5
(4) Cleaning up request packet ID 35 with timestamp +5
Closing TLS socket from client port 48186
(0) >>> send TLS 1.2 [length 0002]
Client has closed connection
(5) Cleaning up request packet ID 183 with timestamp +5
(6) Cleaning up request packet ID 189 with timestamp +5
... shutting down socket auth from client (13.94.115.212, 48186) -> (*, 2083, virtual-server=abfab-idp)
(7) Cleaning up request packet ID 83 with timestamp +5
Waking up in 2.9 seconds.
... cleaning up socket auth from client (13.94.115.212, 48186) -> (*, 2083, virtual-server=abfab-idp)
Ready to process requests
-- log ends --
:-/
Stefan Paetow
Consultant, Trust and Identity
t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp(a)jabber.dev.ja.net
skype: stefan.paetow.janet
jisc.ac.uk
Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under Company No. 5747339, VAT No. GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill, Bristol, BS2 0JA. T 0203 697 5800.
2
14
17 Jul '18
Hi there,
I am working for some days now with FreeRADIUS Version 3.0.13. I knew of RADIUS before and have a technical background but not much experience regarding RADOIS, 802.1X or Authentication in particular (PAP, EAP, CHAP…).
However, my question: I have a working RADIUS-Server, I ensured that as I am able to authenticate a Windows 7 Workstation with 802.1X activated on the switch port it is connected to. When I enter the correct user@domain with the correct password, the switch allows traffic on that port and I can also see an Access-Accept in the RADIUS debug output. My next step is to not use a workstation but an IP camera. I uploaded the “test” certificates and key that were created in /etc/raddp/certs to the IP cam and used the same user I used for the windows 7 authentication. It just wont work like that but I cant figure out why. My debug output is attached.
IMHO everything looks good until:
(2) eap: Peer sent packet with method EAP NAK (3)
(2) eap: Peer NAK'd indicating it is not willing to continue
(2) eap: Sending EAP Failure (code 4) ID 3 length 4
(2) eap: Failed in EAP select
But I have no Idea what that means.
Here is the full debug output:
[root@localhost ~]# radiusd -X
FreeRADIUS Version 3.0.13
Copyright (C) 1999-2017 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/raddb/dictionary
including configuration file /etc/raddb/radiusd.conf
including configuration file /etc/raddb/proxy.conf
including configuration file /etc/raddb/clients.conf
including files in directory /etc/raddb/mods-enabled/
including configuration file /etc/raddb/mods-enabled/always
including configuration file /etc/raddb/mods-enabled/attr_filter
including configuration file /etc/raddb/mods-enabled/cache_eap
including configuration file /etc/raddb/mods-enabled/chap
including configuration file /etc/raddb/mods-enabled/date
including configuration file /etc/raddb/mods-enabled/detail
including configuration file /etc/raddb/mods-enabled/detail.log
including configuration file /etc/raddb/mods-enabled/dhcp
including configuration file /etc/raddb/mods-enabled/digest
including configuration file /etc/raddb/mods-enabled/dynamic_clients
including configuration file /etc/raddb/mods-enabled/eap
including configuration file /etc/raddb/mods-enabled/echo
including configuration file /etc/raddb/mods-enabled/exec
including configuration file /etc/raddb/mods-enabled/expiration
including configuration file /etc/raddb/mods-enabled/expr
including configuration file /etc/raddb/mods-enabled/files
including configuration file /etc/raddb/mods-enabled/linelog
including configuration file /etc/raddb/mods-enabled/logintime
including configuration file /etc/raddb/mods-enabled/mschap
including configuration file /etc/raddb/mods-enabled/ntlm_auth
including configuration file /etc/raddb/mods-enabled/pap
including configuration file /etc/raddb/mods-enabled/passwd
including configuration file /etc/raddb/mods-enabled/preprocess
including configuration file /etc/raddb/mods-enabled/radutmp
including configuration file /etc/raddb/mods-enabled/realm
including configuration file /etc/raddb/mods-enabled/replicate
including configuration file /etc/raddb/mods-enabled/soh
including configuration file /etc/raddb/mods-enabled/sradutmp
including configuration file /etc/raddb/mods-enabled/unix
including configuration file /etc/raddb/mods-enabled/unpack
including configuration file /etc/raddb/mods-enabled/utf8
including configuration file /etc/raddb/mods-enabled/sql
including configuration file /etc/raddb/mods-config/sql/main/mysql/queries.conf
including files in directory /etc/raddb/policy.d/
including configuration file /etc/raddb/policy.d/accounting
including configuration file /etc/raddb/policy.d/canonicalization
including configuration file /etc/raddb/policy.d/control
including configuration file /etc/raddb/policy.d/cui
including configuration file /etc/raddb/policy.d/debug
including configuration file /etc/raddb/policy.d/dhcp
including configuration file /etc/raddb/policy.d/eap
including configuration file /etc/raddb/policy.d/filter
including configuration file /etc/raddb/policy.d/operator-name
including files in directory /etc/raddb/sites-enabled/
including configuration file /etc/raddb/sites-enabled/default
including configuration file /etc/raddb/sites-enabled/inner-tunnel
main {
security {
user = "radiusd"
group = "radiusd"
allow_core_dumps = no
}
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/radius"
run_dir = "/var/run/radiusd"
}
main {
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/radius"
run_dir = "/var/run/radiusd"
libdir = "/usr/lib64/freeradius"
radacctdir = "/var/log/radius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/var/run/radiusd/radiusd.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client testclient {
ipaddr = 10.1.100.103
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client switch {
ipaddr = 10.1.17.213
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client 802test {
ipaddr = 10.1.22.136
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
# Creating Auth-Type = mschap
# Creating Auth-Type = digest
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_always
# Loading module "reject" from file /etc/raddb/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file /etc/raddb/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /etc/raddb/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file /etc/raddb/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file /etc/raddb/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file /etc/raddb/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file /etc/raddb/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file /etc/raddb/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file /etc/raddb/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/etc/raddb/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/etc/raddb/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/etc/raddb/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/etc/raddb/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file /etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/etc/raddb/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loaded module rlm_cache
# Loading module "cache_eap" from file /etc/raddb/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_chap
# Loading module "chap" from file /etc/raddb/mods-enabled/chap
# Loaded module rlm_date
# Loading module "date" from file /etc/raddb/mods-enabled/date
date {
format = "%b %e %Y %H:%M:%S %Z"
}
# Loaded module rlm_detail
# Loading module "detail" from file /etc/raddb/mods-enabled/detail
detail {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "auth_log" from file /etc/raddb/mods-enabled/detail.log
detail auth_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file /etc/raddb/mods-enabled/detail.log
detail reply_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file /etc/raddb/mods-enabled/detail.log
detail pre_proxy_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file /etc/raddb/mods-enabled/detail.log
detail post_proxy_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_dhcp
# Loading module "dhcp" from file /etc/raddb/mods-enabled/dhcp
# Loaded module rlm_digest
# Loading module "digest" from file /etc/raddb/mods-enabled/digest
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file /etc/raddb/mods-enabled/dynamic_clients
# Loaded module rlm_eap
# Loading module "eap" from file /etc/raddb/mods-enabled/eap
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_exec
# Loading module "echo" from file /etc/raddb/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loading module "exec" from file /etc/raddb/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_expiration
# Loading module "expiration" from file /etc/raddb/mods-enabled/expiration
# Loaded module rlm_expr
# Loading module "expr" from file /etc/raddb/mods-enabled/expr
expr {
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loaded module rlm_files
# Loading module "files" from file /etc/raddb/mods-enabled/files
files {
filename = "/etc/raddb/mods-config/files/authorize"
acctusersfile = "/etc/raddb/mods-config/files/accounting"
preproxy_usersfile = "/etc/raddb/mods-config/files/pre-proxy"
}
# Loaded module rlm_linelog
# Loading module "linelog" from file /etc/raddb/mods-enabled/linelog
linelog {
filename = "/var/log/radius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file /etc/raddb/mods-enabled/linelog
linelog log_accounting {
filename = "/var/log/radius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_logintime
# Loading module "logintime" from file /etc/raddb/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_mschap
# Loading module "mschap" from file /etc/raddb/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
winbind_retry_with_normalised_username = no
}
# Loading module "ntlm_auth" from file /etc/raddb/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN --username=%{mschap:User-Name} --password=%{User-Password}"
shell_escape = yes
}
# Loaded module rlm_pap
# Loading module "pap" from file /etc/raddb/mods-enabled/pap
pap {
normalise = yes
}
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file /etc/raddb/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loaded module rlm_preprocess
# Loading module "preprocess" from file /etc/raddb/mods-enabled/preprocess
preprocess {
huntgroups = "/etc/raddb/mods-config/preprocess/huntgroups"
hints = "/etc/raddb/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loaded module rlm_radutmp
# Loading module "radutmp" from file /etc/raddb/mods-enabled/radutmp
radutmp {
filename = "/var/log/radius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_realm
# Loading module "IPASS" from file /etc/raddb/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file /etc/raddb/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file /etc/raddb/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file /etc/raddb/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loaded module rlm_replicate
# Loading module "replicate" from file /etc/raddb/mods-enabled/replicate
# Loaded module rlm_soh
# Loading module "soh" from file /etc/raddb/mods-enabled/soh
soh {
dhcp = yes
}
# Loading module "sradutmp" from file /etc/raddb/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/radius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_unix
# Loading module "unix" from file /etc/raddb/mods-enabled/unix
unix {
radwtmp = "/var/log/radius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_unpack
# Loading module "unpack" from file /etc/raddb/mods-enabled/unpack
# Loaded module rlm_utf8
# Loading module "utf8" from file /etc/raddb/mods-enabled/utf8
# Loaded module rlm_sql
# Loading module "sql" from file /etc/raddb/mods-enabled/sql
sql {
driver = "rlm_sql_mysql"
server = "localhost"
port = 3306
login = "radius"
password = <<< secret >>>
radius_db = "radius"
read_groups = yes
read_profiles = yes
read_clients = yes
delete_stale_sessions = yes
sql_user_name = "%{User-Name}"
default_user_profile = ""
client_query = "SELECT id, nasname, shortname, type, secret, server FROM nas"
authorize_check_query = "SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id"
authorize_reply_query = "SELECT id, username, attribute, value, op FROM radreply WHERE username = '%{SQL-User-Name}' ORDER BY id"
authorize_group_check_query = "SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '%{SQL-Group}' ORDER BY id"
authorize_group_reply_query = "SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '%{SQL-Group}' ORDER BY id"
group_membership_query = "SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority"
simul_count_query = "SELECT COUNT(*) FROM radacct WHERE username = '%{SQL-User-Name}' AND acctstoptime IS NULL"
simul_verify_query = "SELECT radacctid, acctsessionid, username, nasipaddress, nasportid, framedipaddress, callingstationid, framedprotocol FROM radacct WHERE username = '%{SQL-User-Name}' AND acctstoptime IS NULL"
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"
accounting {
reference = "%{tolower:type.%{Acct-Status-Type}.query}"
type {
accounting-on {
query = "UPDATE radacct SET acctstoptime = FROM_UNIXTIME(%{integer:Event-Timestamp}), acctsessiontime = '%{integer:Event-Timestamp}' - UNIX_TIMESTAMP(acctstarttime), acctterminatecause = '%{%{Acct-Terminate-Cause}:-NAS-Reboot}' WHERE acctstoptime IS NULL AND nasipaddress = '%{NAS-IP-Address}' AND acctstarttime <= FROM_UNIXTIME(%{integer:Event-Timestamp})"
}
accounting-off {
query = "UPDATE radacct SET acctstoptime = FROM_UNIXTIME(%{integer:Event-Timestamp}), acctsessiontime = '%{integer:Event-Timestamp}' - UNIX_TIMESTAMP(acctstarttime), acctterminatecause = '%{%{Acct-Terminate-Cause}:-NAS-Reboot}' WHERE acctstoptime IS NULL AND nasipaddress = '%{NAS-IP-Address}' AND acctstarttime <= FROM_UNIXTIME(%{integer:Event-Timestamp})"
}
start {
query = "INSERT INTO radacct (acctsessionid, acctuniqueid, username, realm, nasipaddress, nasportid, nasporttype, acctstarttime, acctupdatetime, acctstoptime, acctsessiontime, acctauthentic, connectinfo_start, connectinfo_stop, acctinputoctets, acctoutputoctets, calledstationid, callingstationid, acctterminatecause, servicetype, framedprotocol, framedipaddress) VALUES ('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm}', '%{NAS-IP-Address}', '%{%{NAS-Port-ID}:-%{NAS-Port}}', '%{NAS-Port-Type}', FROM_UNIXTIME(%{integer:Event-Timestamp}), FROM_UNIXTIME(%{integer:Event-Timestamp}), NULL, '0', '%{Acct-Authentic}', '%{Connect-Info}', '', '0', '0', '%{Called-Station-Id}', '%{Calling-Station-Id}', '', '%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}')"
}
interim-update {
query = "UPDATE radacct SET acctupdatetime = (@acctupdatetime_old:=acctupdatetime), acctupdatetime = FROM_UNIXTIME(%{integer:Event-Timestamp}), acctinterval = %{integer:Event-Timestamp} - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '%{Framed-IP-Address}', acctsessiontime = %{%{Acct-Session-Time}:-NULL}, acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}' WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'"
}
stop {
query = "UPDATE radacct SET acctstoptime = FROM_UNIXTIME(%{integer:Event-Timestamp}), acctsessiontime = %{%{Acct-Session-Time}:-NULL}, acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Input-Octets}:-0}', acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Output-Octets}:-0}', acctterminatecause = '%{Acct-Terminate-Cause}', connectinfo_stop = '%{Connect-Info}' WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'"
}
}
}
post-auth {
reference = ".query"
query = "INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( '%{SQL-User-Name}', '%{%{User-Password}:-%{Chap-Password}}', '%{reply:Packet-Type}', '%S')"
}
}
rlm_sql (sql): Driver rlm_sql_mysql (module rlm_sql_mysql) loaded and linked
Creating attribute SQL-Group
instantiate {
}
# Instantiating module "reject" from file /etc/raddb/mods-enabled/always
# Instantiating module "fail" from file /etc/raddb/mods-enabled/always
# Instantiating module "ok" from file /etc/raddb/mods-enabled/always
# Instantiating module "handled" from file /etc/raddb/mods-enabled/always
# Instantiating module "invalid" from file /etc/raddb/mods-enabled/always
# Instantiating module "userlock" from file /etc/raddb/mods-enabled/always
# Instantiating module "notfound" from file /etc/raddb/mods-enabled/always
# Instantiating module "noop" from file /etc/raddb/mods-enabled/always
# Instantiating module "updated" from file /etc/raddb/mods-enabled/always
# Instantiating module "attr_filter.post-proxy" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/access_reject
[/etc/raddb/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay" found in filter list for realm "DEFAULT".
[/etc/raddb/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay-USec" found in filter list for realm "DEFAULT".
# Instantiating module "attr_filter.access_challenge" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file /etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/accounting_response
# Instantiating module "cache_eap" from file /etc/raddb/mods-enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module rlm_cache_rbtree) loaded and linked
# Instantiating module "detail" from file /etc/raddb/mods-enabled/detail
# Instantiating module "auth_log" from file /etc/raddb/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output
# Instantiating module "reply_log" from file /etc/raddb/mods-enabled/detail.log
# Instantiating module "pre_proxy_log" from file /etc/raddb/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file /etc/raddb/mods-enabled/detail.log
# Instantiating module "eap" from file /etc/raddb/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/etc/raddb/certs/server.pem"
certificate_file = "/etc/raddb/certs/server.pem"
ca_file = "/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/etc/raddb/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
cipher_server_preference = no
ecdh_curve = "prime256v1"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
# Instantiating module "expiration" from file /etc/raddb/mods-enabled/expiration
# Instantiating module "files" from file /etc/raddb/mods-enabled/files
reading pairlist file /etc/raddb/mods-config/files/authorize
reading pairlist file /etc/raddb/mods-config/files/accounting
reading pairlist file /etc/raddb/mods-config/files/pre-proxy
# Instantiating module "linelog" from file /etc/raddb/mods-enabled/linelog
# Instantiating module "log_accounting" from file /etc/raddb/mods-enabled/linelog
# Instantiating module "logintime" from file /etc/raddb/mods-enabled/logintime
# Instantiating module "mschap" from file /etc/raddb/mods-enabled/mschap
rlm_mschap (mschap): using internal authentication
# Instantiating module "pap" from file /etc/raddb/mods-enabled/pap
# Instantiating module "etc_passwd" from file /etc/raddb/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "preprocess" from file /etc/raddb/mods-enabled/preprocess
reading pairlist file /etc/raddb/mods-config/preprocess/huntgroups
reading pairlist file /etc/raddb/mods-config/preprocess/hints
# Instantiating module "IPASS" from file /etc/raddb/mods-enabled/realm
# Instantiating module "suffix" from file /etc/raddb/mods-enabled/realm
# Instantiating module "realmpercent" from file /etc/raddb/mods-enabled/realm
# Instantiating module "ntdomain" from file /etc/raddb/mods-enabled/realm
# Instantiating module "sql" from file /etc/raddb/mods-enabled/sql
rlm_sql_mysql: libmysql version: 10.1.34-MariaDB
mysql {
tls {
}
warnings = "auto"
}
rlm_sql (sql): Attempting to connect to database "radius"
rlm_sql (sql): Initialising connection pool
pool {
start = 5
min = 3
max = 32
spare = 10
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 30
spread = no
}
rlm_sql (sql): Opening additional connection (0), 1 of 32 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, server version 10.1.34-MariaDB, protocol version 10
rlm_sql (sql): Opening additional connection (1), 1 of 31 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, server version 10.1.34-MariaDB, protocol version 10
rlm_sql (sql): Opening additional connection (2), 1 of 30 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, server version 10.1.34-MariaDB, protocol version 10
rlm_sql (sql): Opening additional connection (3), 1 of 29 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, server version 10.1.34-MariaDB, protocol version 10
rlm_sql (sql): Opening additional connection (4), 1 of 28 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, server version 10.1.34-MariaDB, protocol version 10
rlm_sql (sql): Processing generate_sql_clients
rlm_sql (sql) in generate_sql_clients: query is SELECT id, nasname, shortname, type, secret, server FROM nas
rlm_sql (sql): Reserved connection (0)
rlm_sql (sql): Executing select query: SELECT id, nasname, shortname, type, secret, server FROM nas
rlm_sql (sql): Released connection (0)
Need 5 more connections to reach 10 spares
rlm_sql (sql): Opening additional connection (5), 1 of 27 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, server version 10.1.34-MariaDB, protocol version 10
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/raddb/radiusd.conf
} # server
server default { # from file /etc/raddb/sites-enabled/default
# Loading authenticate {...}
# Loading authorize {...}
Ignoring "ldap" (see raddb/mods-available/README.rst)
# Loading preacct {...}
# Loading accounting {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server default
server inner-tunnel { # from file /etc/raddb/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
# Skipping contents of 'if' as it is always 'false' -- /etc/raddb/sites-enabled/inner-tunnel:330
} # server inner-tunnel
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Ready to process requests
(0) Received Access-Request Id 196 from 10.1.17.213:5001 to 10.1.22.139:1812 length 131
(0) User-Name = "test(a)test.de"
(0) EAP-Message = 0x02010011017465737440746573742e6465
(0) Message-Authenticator = 0xcc6b7f6dcf8ad4f75142527dd9c80de9
(0) NAS-IP-Address = 10.1.17.213
(0) NAS-Identifier = "002257bfc602"
(0) NAS-Port = 16842753
(0) NAS-Port-Type = Ethernet
(0) Service-Type = Framed-User
(0) Framed-Protocol = PPP
(0) Calling-Station-Id = "00d0-8916-a51c"
(0) # Executing section authorize from file /etc/raddb/sites-enabled/default
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) [preprocess] = ok
(0) [chap] = noop
(0) [mschap] = noop
(0) [digest] = noop
(0) suffix: Checking for suffix after "@"
(0) suffix: Looking up realm "test.de" for User-Name = "test(a)test.de"
(0) suffix: No such realm "test.de"
(0) [suffix] = noop
(0) eap: Peer sent EAP Response (code 2) ID 1 length 17
(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(0) [eap] = ok
(0) } # authorize = ok
(0) Found Auth-Type = eap
(0) # Executing group from file /etc/raddb/sites-enabled/default
(0) authenticate {
(0) eap: Peer sent packet with method EAP Identity (1)
(0) eap: Calling submodule eap_md5 to process data
(0) eap_md5: Issuing MD5 Challenge
(0) eap: Sending EAP Request (code 1) ID 2 length 22
(0) eap: EAP session adding &reply:State = 0x63be32f863bc36b8
(0) [eap] = handled
(0) } # authenticate = handled
(0) Using Post-Auth-Type Challenge
(0) # Executing group from file /etc/raddb/sites-enabled/default
(0) Challenge { ... } # empty sub-section is ignored
(0) Sent Access-Challenge Id 196 from 10.1.22.139:1812 to 10.1.17.213:5001 length 0
(0) EAP-Message = 0x010200160410ba4998d7891473ac7a4379f547fd8835
(0) Message-Authenticator = 0x00000000000000000000000000000000
(0) State = 0x63be32f863bc36b887ed5f2ce5677eca
(0) Finished request
Waking up in 4.9 seconds.
(1) Received Access-Request Id 197 from 10.1.17.213:5001 to 10.1.22.139:1812 length 138
(1) User-Name = "test(a)test.de"
(1) EAP-Message = 0x02020006030d
(1) Message-Authenticator = 0x97fdf8036af545820ec406c229ad06fe
(1) NAS-IP-Address = 10.1.17.213
(1) NAS-Identifier = "002257bfc602"
(1) NAS-Port = 16842753
(1) NAS-Port-Type = Ethernet
(1) Service-Type = Framed-User
(1) Framed-Protocol = PPP
(1) Calling-Station-Id = "00d0-8916-a51c"
(1) State = 0x63be32f863bc36b887ed5f2ce5677eca
(1) session-state: No cached attributes
(1) # Executing section authorize from file /etc/raddb/sites-enabled/default
(1) authorize {
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # if (&User-Name) = notfound
(1) } # policy filter_username = notfound
(1) [preprocess] = ok
(1) [chap] = noop
(1) [mschap] = noop
(1) [digest] = noop
(1) suffix: Checking for suffix after "@"
(1) suffix: Looking up realm "test.de" for User-Name = "test(a)test.de"
(1) suffix: No such realm "test.de"
(1) [suffix] = noop
(1) eap: Peer sent EAP Response (code 2) ID 2 length 6
(1) eap: No EAP Start, assuming it's an on-going EAP conversation
(1) [eap] = updated
(1) files: users: Matched entry DEFAULT at line 181
(1) [files] = ok
(1) sql: EXPAND %{User-Name}
(1) sql: --> test(a)test.de
(1) sql: SQL-User-Name set to 'test(a)test.de'
rlm_sql (sql): Reserved connection (1)
(1) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(1) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'test(a)test.de' ORDER BY id
(1) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'test(a)test.de' ORDER BY id
(1) sql: User found in radcheck table
(1) sql: Conditional check items matched, merging assignment check items
(1) sql: Cleartext-Password := "test"
(1) sql: EXPAND SELECT id, username, attribute, value, op FROM radreply WHERE username = '%{SQL-User-Name}' ORDER BY id
(1) sql: --> SELECT id, username, attribute, value, op FROM radreply WHERE username = 'test(a)test.de' ORDER BY id
(1) sql: Executing select query: SELECT id, username, attribute, value, op FROM radreply WHERE username = 'test(a)test.de' ORDER BY id
(1) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(1) sql: --> SELECT groupname FROM radusergroup WHERE username = 'test(a)test.de' ORDER BY priority
(1) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'test(a)test.de' ORDER BY priority
(1) sql: User not found in any groups
rlm_sql (sql): Released connection (1)
Need 4 more connections to reach 10 spares
rlm_sql (sql): Opening additional connection (6), 1 of 26 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, server version 10.1.34-MariaDB, protocol version 10
(1) [sql] = ok
(1) [expiration] = noop
(1) [logintime] = noop
(1) pap: WARNING: Auth-Type already set. Not setting to PAP
(1) [pap] = noop
(1) } # authorize = updated
(1) Found Auth-Type = eap
(1) # Executing group from file /etc/raddb/sites-enabled/default
(1) authenticate {
(1) eap: Expiring EAP session with state 0x63be32f863bc36b8
(1) eap: Finished EAP session with state 0x63be32f863bc36b8
(1) eap: Previous EAP request found for state 0x63be32f863bc36b8, released from the list
(1) eap: Peer sent packet with method EAP NAK (3)
(1) eap: Found mutually acceptable type TLS (13)
(1) eap: Calling submodule eap_tls to process data
(1) eap_tls: Initiating new EAP-TLS session
(1) eap_tls: Setting verify mode to require certificate from client
(1) eap_tls: [eaptls start] = request
(1) eap: Sending EAP Request (code 1) ID 3 length 6
(1) eap: EAP session adding &reply:State = 0x63be32f862bd3fb8
(1) [eap] = handled
(1) } # authenticate = handled
(1) Using Post-Auth-Type Challenge
(1) # Executing group from file /etc/raddb/sites-enabled/default
(1) Challenge { ... } # empty sub-section is ignored
(1) Sent Access-Challenge Id 197 from 10.1.22.139:1812 to 10.1.17.213:5001 length 0
(1) Framed-Protocol = PPP
(1) Framed-Compression = Van-Jacobson-TCP-IP
(1) EAP-Message = 0x010300060d20
(1) Message-Authenticator = 0x00000000000000000000000000000000
(1) State = 0x63be32f862bd3fb887ed5f2ce5677eca
(1) Finished request
Waking up in 4.9 seconds.
(2) Received Access-Request Id 198 from 10.1.17.213:5001 to 10.1.22.139:1812 length 138
(2) User-Name = "test(a)test.de"
(2) EAP-Message = 0x020300060300
(2) Message-Authenticator = 0x0b0a97867abe67deb94d4bb3660e2adb
(2) NAS-IP-Address = 10.1.17.213
(2) NAS-Identifier = "002257bfc602"
(2) NAS-Port = 16842753
(2) NAS-Port-Type = Ethernet
(2) Service-Type = Framed-User
(2) Framed-Protocol = PPP
(2) Calling-Station-Id = "00d0-8916-a51c"
(2) State = 0x63be32f862bd3fb887ed5f2ce5677eca
(2) session-state: No cached attributes
(2) # Executing section authorize from file /etc/raddb/sites-enabled/default
(2) authorize {
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) } # if (&User-Name) = notfound
(2) } # policy filter_username = notfound
(2) [preprocess] = ok
(2) [chap] = noop
(2) [mschap] = noop
(2) [digest] = noop
(2) suffix: Checking for suffix after "@"
(2) suffix: Looking up realm "test.de" for User-Name = "test(a)test.de"
(2) suffix: No such realm "test.de"
(2) [suffix] = noop
(2) eap: Peer sent EAP Response (code 2) ID 3 length 6
(2) eap: No EAP Start, assuming it's an on-going EAP conversation
(2) [eap] = updated
(2) files: users: Matched entry DEFAULT at line 181
(2) [files] = ok
(2) sql: EXPAND %{User-Name}
(2) sql: --> test(a)test.de
(2) sql: SQL-User-Name set to 'test(a)test.de'
rlm_sql (sql): Reserved connection (2)
(2) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id
(2) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'test(a)test.de' ORDER BY id
(2) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'test(a)test.de' ORDER BY id
(2) sql: User found in radcheck table
(2) sql: Conditional check items matched, merging assignment check items
(2) sql: Cleartext-Password := "test"
(2) sql: EXPAND SELECT id, username, attribute, value, op FROM radreply WHERE username = '%{SQL-User-Name}' ORDER BY id
(2) sql: --> SELECT id, username, attribute, value, op FROM radreply WHERE username = 'test(a)test.de' ORDER BY id
(2) sql: Executing select query: SELECT id, username, attribute, value, op FROM radreply WHERE username = 'test(a)test.de' ORDER BY id
(2) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority
(2) sql: --> SELECT groupname FROM radusergroup WHERE username = 'test(a)test.de' ORDER BY priority
(2) sql: Executing select query: SELECT groupname FROM radusergroup WHERE username = 'test(a)test.de' ORDER BY priority
(2) sql: User not found in any groups
rlm_sql (sql): Released connection (2)
(2) [sql] = ok
(2) [expiration] = noop
(2) [logintime] = noop
(2) pap: WARNING: Auth-Type already set. Not setting to PAP
(2) [pap] = noop
(2) } # authorize = updated
(2) Found Auth-Type = eap
(2) # Executing group from file /etc/raddb/sites-enabled/default
(2) authenticate {
(2) eap: Expiring EAP session with state 0x63be32f862bd3fb8
(2) eap: Finished EAP session with state 0x63be32f862bd3fb8
(2) eap: Previous EAP request found for state 0x63be32f862bd3fb8, released from the list
(2) eap: Peer sent packet with method EAP NAK (3)
(2) eap: Peer NAK'd indicating it is not willing to continue
(2) eap: Sending EAP Failure (code 4) ID 3 length 4
(2) eap: Failed in EAP select
(2) [eap] = invalid
(2) } # authenticate = invalid
(2) Failed to authenticate the user
(2) Using Post-Auth-Type Reject
(2) # Executing group from file /etc/raddb/sites-enabled/default
(2) Post-Auth-Type REJECT {
(2) sql: EXPAND .query
(2) sql: --> .query
(2) sql: Using query template 'query'
rlm_sql (sql): Reserved connection (3)
(2) sql: EXPAND %{User-Name}
(2) sql: --> test(a)test.de
(2) sql: SQL-User-Name set to 'test(a)test.de'
(2) sql: EXPAND INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( '%{SQL-User-Name}', '%{%{User-Password}:-%{Chap-Password}}', '%{reply:Packet-Type}', '%S')
(2) sql: --> INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( 'test(a)test.de', '', 'Access-Reject', '2018-06-29 15:23:47.268150')
(2) sql: Executing query: INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( 'test(a)test.de', '', 'Access-Reject', '2018-06-29 15:23:47.268150')
(2) sql: SQL query returned: success
(2) sql: 1 record(s) updated
rlm_sql (sql): Released connection (3)
(2) [sql] = ok
(2) attr_filter.access_reject: EXPAND %{User-Name}
(2) attr_filter.access_reject: --> test(a)test.de
(2) attr_filter.access_reject: Matched entry DEFAULT at line 11
(2) [attr_filter.access_reject] = updated
(2) [eap] = noop
(2) policy remove_reply_message_if_eap {
(2) if (&reply:EAP-Message && &reply:Reply-Message) {
(2) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(2) else {
(2) [noop] = noop
(2) } # else = noop
(2) } # policy remove_reply_message_if_eap = noop
(2) } # Post-Auth-Type REJECT = updated
(2) Delaying response for 1.000000 seconds
Waking up in 0.3 seconds.
Waking up in 0.6 seconds.
(2) Sending delayed response
(2) Sent Access-Reject Id 198 from 10.1.22.139:1812 to 10.1.17.213:5001 length 44
(2) EAP-Message = 0x04030004
(2) Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 3.8 seconds.
(0) Cleaning up request packet ID 196 with timestamp +2
(1) Cleaning up request packet ID 197 with timestamp +2
Waking up in 0.1 seconds.
(2) Cleaning up request packet ID 198 with timestamp +2
Ready to process requests
Mit freundlichen Grüßen I With best regards
Niklas Klein
Testengineer
Research & Development
GEUTEBRÜCK GmbH
Telefon +49 2645 137-722
Fax +49 2645 137-999
Mobil
niklas.klein(a)geutebrueck.com<mailto:niklas.klein@geutebrueck.com><mailto:%20name.nachname@geutebrueck.com>
www.geutebrueck.com<https://www.geutebrueck.com/>
[cid:twitter-with-circle_9a242334-fa02-4a91-996d-312ca4ec2004.png] <https://twitter.com/geutebruck/?ref=MF0814> [cid:youtube-with-circle_e5a3a3bd-2aee-463e-a4a7-0b68323eb775.png] <https://www.youtube.com/channel/UCEhjAeu55-1CZO4SRNgqcNQ/> [cid:linkedin-with-circle_ee6ebcac-cd2e-4ce4-807c-435f6a5e43cc.png] <https://www.linkedin.com/company/geutebr-ck-gmbh?trk=company_logo> [cid:xing-with-circle_ff285450-39be-4390-b2cb-8f86d17d327e.png] <https://www.xing.com/companies/geutebr?¼ckgmbh>
GEUTEBRÜCK GmbH ? Im Nassen 7-9 ? 53578 Windhagen
Geschäftsführer: Katharina Geutebrück, Christoph Hoffmann ? UST-Ident-Nr.: DE813443473 ? Handelsregister: HRB 14475 Montabaur
Diese E-Mail enthält vertrauliche und/oder rechtlich geschützte Informationen. Wenn Sie nicht der richtige Adressat sind oder diese E-Mail irrtümlich erhalten haben, informieren Sie bitte sofort den Absender und vernichten Sie diese Mail. Das unerlaubte Kopieren sowie die unbefugte Weitergabe dieser Mail ist nicht gestattet. Weder die Geutebrück GmbH noch der Absender (Niklas Klein) übernehmen die Haftung für Viren; es obliegt Ihrer Verantwortung, die E-Mail und deren Anhänge auf Viren zu prüfen.
________________________________
GEUTEBRÜCK GmbH ? Im Nassen 7-9 ? 53578 Windhagen ? Germany
CEO: Katharina Geutebrück, Christoph Hoffmann ? VAT No: DE813443473 ? Traderegister: HRB 14475 Montabaur
This e-mail contains confidential and/or privileged information. If you are not the intended recipient (or have received this e-mail in error) please notify the sender immediately and destroy this e-mail. Any unauthorised copying, disclosure or distribution of the material in this e-mail is strictly forbidden. Neither the Geutebrück GmbH nor the sender (Niklas Klein) accepts any liability for viruses; it is your responsibility to check the e-mail and their attachments for viruses.
5
9
>
> Hello,
>
> My name is Javier Escalante, I have been asking questions here for a
> couple of days, and I was as well asking in 2015. Revising the answers from
> now and 2015, from Alan Dekok, one of the most active members of this
> group, and I think the one who manages it, I have realized, that it is
> useless to ask, you will always get the same bullshit from him, and he will
> treat you like if you were an idiot, but you won't get a solution. He might
> be very "intelligent", but he and his fellows are wasting time and energy,
> and make us waste it as well (It is clear that they don't know about
> Zen...) by answering in the way they answer. Instead, they and the ones
> who made the wiki, should add the following video sent to me by Uchenna
> Nebedum youtube.com/watch?v=-xws3eo2CAQ (Thanks Uchenna). Here, you will
> find all what you won't get in this group in your whole life, because all
> "these intelligent" people like Alan and fellows, think that we ask because
> we already know. Don't you realize guys that if I knew what I ask, I'd be
> having beers and not wasting my fucking time with you!!!??
>
>
>
> After watching the video, you can configure your RADIUS in less than 30',
> and you can stop wasting your time here. Uchenna also sent me a freeradius
> book, which I can send to all who want it.
>
> My question is; what you guys (Alan and fellows who act like him) are you
> doing here? What is your aim? don't you realize that you waste our time and
> what you are doing is useless?
> If your aim is helping, you are doing it veeeeeery bad. To answer what you
> answer, and how you answer, you better close down this mailing list.
>
> And now, Alan, you can ban me another time.
>
> Have a nice day
>
> Best
>
6
9
Hi:
for many years I just follow the document: create certificate with
xp extensions and use group policy to deploy the CA. I never really
understand what is. now I have several stupid questions:
1. is the "xp" extensions means windows xp or something?
2. is xp extensions only useful if we want client to verify server certificate?
3. if we use certificate like let's encrypt without xp extensions.
what function do we miss? I know it is not very secure to use public
CA, but it seems easier when deal with mobile devices bring by users.
they just want to access wifi with their active directory
username/password.
thanks a lot for help!!
4
6
Hi all, with a subject line this time
FreeRADIUS Version 3.0.15 here.
We have a working freeradius server acting as a proxy for our customers. All customers go through the same clients pool. Clients as intended in /etc/freeradius/clients.
For some new need we need to change the behavior of our server for a certain type of requests - an existing realm must now be processed locally by the server and not as a proxy -. I thought about implementing this through the use of virtual servers. It works well in our testing environment but it’s time to test it in production.
The way I understand virtual servers is that they must be « declared » under the client configuration in the /etc/freeradius/clients file.
The problem I am facing is that in doing so, I implement the change on all incoming authentication requests whereas I would have preferred to do so on a unique user just to be sure it would work in the production environment.
Anyone has an idea?
Thx
Nidhal Taleb
2
2
Good Day all, Please i want sql postauth to store calledstationid in
radpostauth table, I've added the field but i don't know which file to edit
to include the sql.
Please any help would be appreciated.
Thanks.
Uchenna Nebedum
4
4
Hi, All.
I am in trouble with the following problem.
Please help me.
1.What you are trying to do
I need to use PEAP(MS-CHAPv2) with LDAP that has Cleartext-Password
in userPassword attribute.
2.why you are trying to do it
I am trying to use backslash in userPassword like 'Pass\100word'.
3.what you expect the server to do
Access-Accept with password 'Pass\100word'.
Access-Reject with password 'Pass@word'.
4.what the server does instead.
Access-Reject with password 'Pass\100word'.
Access-Accept with password 'Pass@word'.
I assume that the 'value_data_from_str' function converts
'Pass\100word' to 'Pass@word'.
I tried changing single backslash 'Pass\100word' to double backslash
'Pass\\100word' on the LDAP server, and got Access-Accept with
password 'Pass\100word'.
But, we hardly control this problem by changing the userPassword
attribute rules of LDAP server, because other systems which we can not
control use the same LDAP server.
Is there any workaround in freeradius configurations?
etokaoru
The ldapsearch result is as follows:
# ldapsearch -LLL -h 192.168.103.10 -b dc=home -D 'cn=root,dc=home' -w
'password' uid=user001 userPassword
dn: uid=user001,ou=test,dc=home
userPassword:: UGFzc1wxMDB3b3Jk
# echo 'UGFzc1wxMDB3b3Jk' | base64 -d
Pass\100word
The debug log is as follows:
FreeRADIUS Version 3.0.17
Copyright (C) 1999-2017 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/local/radius3017/share/freeradius/dictionary
including dictionary file /usr/local/radius3017/share/freeradius/dictionary.dhcp
including dictionary file /usr/local/radius3017/share/freeradius/dictionary.vqp
including dictionary file /usr/local/radius3017/etc/raddb/dictionary
including configuration file /usr/local/radius3017/etc/raddb/radiusd.conf
including configuration file /usr/local/radius3017/etc/raddb/proxy.conf
including configuration file /usr/local/radius3017/etc/raddb/clients.conf
including files in directory /usr/local/radius3017/etc/raddb/mods-enabled/
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/echo
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/utf8
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/cache_eap
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/ldap
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/digest
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/unix
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/ntlm_auth
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/detail
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/linelog
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/always
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/expr
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/sradutmp
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/passwd
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/exec
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/pap
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/expiration
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/unpack
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/preprocess
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/radutmp
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/replicate
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/mschap
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/dynamic_clients
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/realm
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/files
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/eap
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/soh
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/date
including configuration file /usr/local/radius3017/etc/raddb/mods-enabled/chap
including configuration file
/usr/local/radius3017/etc/raddb/mods-enabled/logintime
including files in directory /usr/local/radius3017/etc/raddb/policy.d/
including configuration file /usr/local/radius3017/etc/raddb/policy.d/debug
including configuration file /usr/local/radius3017/etc/raddb/policy.d/abfab-tr
including configuration file /usr/local/radius3017/etc/raddb/policy.d/dhcp
including configuration file
/usr/local/radius3017/etc/raddb/policy.d/operator-name
including configuration file /usr/local/radius3017/etc/raddb/policy.d/control
including configuration file /usr/local/radius3017/etc/raddb/policy.d/filter
including configuration file
/usr/local/radius3017/etc/raddb/policy.d/canonicalization
including configuration file
/usr/local/radius3017/etc/raddb/policy.d/moonshot-targeted-ids
including configuration file /usr/local/radius3017/etc/raddb/policy.d/cui
including configuration file /usr/local/radius3017/etc/raddb/policy.d/eap
including configuration file /usr/local/radius3017/etc/raddb/policy.d/accounting
including files in directory /usr/local/radius3017/etc/raddb/sites-enabled/
including configuration file
/usr/local/radius3017/etc/raddb/sites-enabled/default
including configuration file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
main {
security {
allow_core_dumps = no
}
name = "radiusd"
prefix = "/usr/local/radius3017"
localstatedir = "/usr/local/radius3017/var"
logdir = "/usr/local/radius3017/var/log/radius"
run_dir = "/usr/local/radius3017/var/run/radiusd"
}
main {
name = "radiusd"
prefix = "/usr/local/radius3017"
localstatedir = "/usr/local/radius3017/var"
sbindir = "/usr/local/radius3017/sbin"
logdir = "/usr/local/radius3017/var/log/radius"
run_dir = "/usr/local/radius3017/var/run/radiusd"
libdir = "/usr/local/radius3017/lib"
radacctdir = "/usr/local/radius3017/var/log/radius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/usr/local/radius3017/var/run/radiusd/radiusd.pid"
checkrad = "/usr/local/radius3017/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = yes
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
allow_vulnerable_openssl = "yes"
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client all-network {
ipaddr = 0.0.0.0/0
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
# Creating Auth-Type = mschap
# Creating Auth-Type = digest
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_exec
# Loading module "echo" from file
/usr/local/radius3017/etc/raddb/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loaded module rlm_utf8
# Loading module "utf8" from file
/usr/local/radius3017/etc/raddb/mods-enabled/utf8
# Loaded module rlm_cache
# Loading module "cache_eap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_ldap
# Loading module "ldap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/ldap
ldap {
server = "192.168.103.10"
identity = "cn=root,dc=home"
password = <<< secret >>>
sasl {
}
user {
scope = "sub"
access_positive = yes
sasl {
}
}
group {
filter = "(objectClass=posixGroup)"
scope = "sub"
name_attribute = "cn"
membership_attribute = "memberOf"
cacheable_name = no
cacheable_dn = no
}
client {
filter = "(objectClass=radiusClient)"
scope = "sub"
base_dn = "dc=home"
}
profile {
}
options {
ldap_debug = 40
chase_referrals = yes
rebind = yes
net_timeout = 1
res_timeout = 10
srv_timelimit = 3
idle = 60
probes = 3
interval = 3
}
tls {
start_tls = no
}
}
Creating attribute LDAP-Group
# Loaded module rlm_digest
# Loading module "digest" from file
/usr/local/radius3017/etc/raddb/mods-enabled/digest
# Loaded module rlm_unix
# Loading module "unix" from file
/usr/local/radius3017/etc/raddb/mods-enabled/unix
unix {
radwtmp = "/usr/local/radius3017/var/log/radius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/usr/local/radius3017/etc/raddb/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/usr/local/radius3017/etc/raddb/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/usr/local/radius3017/etc/raddb/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/usr/local/radius3017/etc/raddb/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/usr/local/radius3017/etc/raddb/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loading module "ntlm_auth" from file
/usr/local/radius3017/etc/raddb/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN
--username=%{mschap:User-Name} --password=%{User-Password}"
shell_escape = yes
}
# Loaded module rlm_detail
# Loading module "detail" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail
detail {
filename = "/usr/local/radius3017/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_linelog
# Loading module "linelog" from file
/usr/local/radius3017/etc/raddb/mods-enabled/linelog
linelog {
filename = "/usr/local/radius3017/var/log/radius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file
/usr/local/radius3017/etc/raddb/mods-enabled/linelog
linelog log_accounting {
filename = "/usr/local/radius3017/var/log/radius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_always
# Loading module "reject" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_expr
# Loading module "expr" from file
/usr/local/radius3017/etc/raddb/mods-enabled/expr
expr {
safe_characters =
"@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_:
/äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loaded module rlm_radutmp
# Loading module "sradutmp" from file
/usr/local/radius3017/etc/raddb/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/usr/local/radius3017/var/log/radius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file
/usr/local/radius3017/etc/raddb/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loading module "exec" from file
/usr/local/radius3017/etc/raddb/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_pap
# Loading module "pap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/pap
pap {
normalise = yes
}
# Loading module "auth_log" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
detail auth_log {
filename = "/usr/local/radius3017/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
detail reply_log {
filename = "/usr/local/radius3017/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
detail pre_proxy_log {
filename = "/usr/local/radius3017/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
detail post_proxy_log {
filename = "/usr/local/radius3017/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_expiration
# Loading module "expiration" from file
/usr/local/radius3017/etc/raddb/mods-enabled/expiration
# Loaded module rlm_unpack
# Loading module "unpack" from file
/usr/local/radius3017/etc/raddb/mods-enabled/unpack
# Loaded module rlm_preprocess
# Loading module "preprocess" from file
/usr/local/radius3017/etc/raddb/mods-enabled/preprocess
preprocess {
huntgroups = "/usr/local/radius3017/etc/raddb/mods-config/preprocess/huntgroups"
hints = "/usr/local/radius3017/etc/raddb/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loading module "radutmp" from file
/usr/local/radius3017/etc/raddb/mods-enabled/radutmp
radutmp {
filename = "/usr/local/radius3017/var/log/radius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_replicate
# Loading module "replicate" from file
/usr/local/radius3017/etc/raddb/mods-enabled/replicate
# Loaded module rlm_mschap
# Loading module "mschap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
winbind_retry_with_normalised_username = no
}
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file
/usr/local/radius3017/etc/raddb/mods-enabled/dynamic_clients
# Loaded module rlm_realm
# Loading module "IPASS" from file
/usr/local/radius3017/etc/raddb/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file
/usr/local/radius3017/etc/raddb/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file
/usr/local/radius3017/etc/raddb/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file
/usr/local/radius3017/etc/raddb/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loaded module rlm_files
# Loading module "files" from file
/usr/local/radius3017/etc/raddb/mods-enabled/files
files {
filename = "/usr/local/radius3017/etc/raddb/mods-config/files/authorize"
acctusersfile = "/usr/local/radius3017/etc/raddb/mods-config/files/accounting"
preproxy_usersfile =
"/usr/local/radius3017/etc/raddb/mods-config/files/pre-proxy"
}
# Loaded module rlm_eap
# Loading module "eap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/eap
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_soh
# Loading module "soh" from file
/usr/local/radius3017/etc/raddb/mods-enabled/soh
soh {
dhcp = yes
}
# Loaded module rlm_date
# Loading module "date" from file
/usr/local/radius3017/etc/raddb/mods-enabled/date
date {
format = "%b %e %Y %H:%M:%S %Z"
utc = no
}
# Loaded module rlm_chap
# Loading module "chap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/chap
# Loaded module rlm_logintime
# Loading module "logintime" from file
/usr/local/radius3017/etc/raddb/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
instantiate {
}
# Instantiating module "cache_eap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module
rlm_cache_rbtree) loaded and linked
# Instantiating module "ldap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/ldap
rlm_ldap: libldap vendor: OpenLDAP, version: 20423
accounting {
reference = "%{tolower:type.%{Acct-Status-Type}}"
}
post-auth {
reference = "."
}
rlm_ldap (ldap): Initialising connection pool
pool {
start = 5
min = 3
max = 32
spare = 10
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 30
spread = no
}
rlm_ldap (ldap): Opening additional connection (0), 1 of 32 pending slots used
rlm_ldap (ldap): Connecting to ldap://192.168.103.10:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (1), 1 of 31 pending slots used
rlm_ldap (ldap): Connecting to ldap://192.168.103.10:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (2), 1 of 30 pending slots used
rlm_ldap (ldap): Connecting to ldap://192.168.103.10:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (3), 1 of 29 pending slots used
rlm_ldap (ldap): Connecting to ldap://192.168.103.10:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (4), 1 of 28 pending slots used
rlm_ldap (ldap): Connecting to ldap://192.168.103.10:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
# Instantiating module "attr_filter.post-proxy" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/attr_filter/access_reject
[/usr/local/radius3017/etc/raddb/mods-config/attr_filter/access_reject]:11
Check item "FreeRADIUS-Response-Delay" found in filter list for realm
"DEFAULT".
[/usr/local/radius3017/etc/raddb/mods-config/attr_filter/access_reject]:11
Check item "FreeRADIUS-Response-Delay-USec" found in filter list for
realm "DEFAULT".
# Instantiating module "attr_filter.access_challenge" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file
/usr/local/radius3017/etc/raddb/mods-enabled/attr_filter
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/attr_filter/accounting_response
# Instantiating module "detail" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail
# Instantiating module "linelog" from file
/usr/local/radius3017/etc/raddb/mods-enabled/linelog
# Instantiating module "log_accounting" from file
/usr/local/radius3017/etc/raddb/mods-enabled/linelog
# Instantiating module "reject" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "fail" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "ok" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "handled" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "invalid" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "userlock" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "notfound" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "noop" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "updated" from file
/usr/local/radius3017/etc/raddb/mods-enabled/always
# Instantiating module "etc_passwd" from file
/usr/local/radius3017/etc/raddb/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "pap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/pap
# Instantiating module "auth_log" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in
detail output
# Instantiating module "reply_log" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
# Instantiating module "pre_proxy_log" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file
/usr/local/radius3017/etc/raddb/mods-enabled/detail.log
# Instantiating module "expiration" from file
/usr/local/radius3017/etc/raddb/mods-enabled/expiration
# Instantiating module "preprocess" from file
/usr/local/radius3017/etc/raddb/mods-enabled/preprocess
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/preprocess/huntgroups
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/preprocess/hints
# Instantiating module "mschap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/mschap
rlm_mschap (mschap): using internal authentication
# Instantiating module "IPASS" from file
/usr/local/radius3017/etc/raddb/mods-enabled/realm
# Instantiating module "suffix" from file
/usr/local/radius3017/etc/raddb/mods-enabled/realm
# Instantiating module "realmpercent" from file
/usr/local/radius3017/etc/raddb/mods-enabled/realm
# Instantiating module "ntdomain" from file
/usr/local/radius3017/etc/raddb/mods-enabled/realm
# Instantiating module "files" from file
/usr/local/radius3017/etc/raddb/mods-enabled/files
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/files/authorize
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/files/accounting
reading pairlist file
/usr/local/radius3017/etc/raddb/mods-config/files/pre-proxy
# Instantiating module "eap" from file
/usr/local/radius3017/etc/raddb/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/usr/local/radius3017/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/usr/local/radius3017/etc/raddb/certs/server.pem"
certificate_file = "/usr/local/radius3017/etc/raddb/certs/server.pem"
ca_file = "/usr/local/radius3017/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/usr/local/radius3017/etc/raddb/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
cipher_server_preference = no
ecdh_curve = "prime256v1"
tls_max_version = ""
tls_min_version = "1.0"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
# Instantiating module "logintime" from file
/usr/local/radius3017/etc/raddb/mods-enabled/logintime
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /usr/local/radius3017/etc/raddb/radiusd.conf
} # server
server default { # from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
# Loading authenticate {...}
# Loading authorize {...}
Ignoring "sql" (see raddb/mods-available/README.rst)
# Loading preacct {...}
# Loading accounting {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server default
server inner-tunnel { # from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
# Skipping contents of 'if' as it is always 'false' --
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel:331
} # server inner-tunnel
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Listening on proxy address * port 42628
Listening on proxy address :: port 45142
Ready to process requests
## Authenticate with password 'Pass\100word'.
(0) Received Access-Request Id 0 from 192.168.103.4:47841 to
192.168.103.2:1812 length 122
(0) User-Name = "user001"
(0) NAS-IP-Address = 127.0.0.1
(0) Calling-Station-Id = "02-00-00-00-00-01"
(0) Framed-MTU = 1400
(0) NAS-Port-Type = Wireless-802.11
(0) Connect-Info = "CONNECT 11Mbps 802.11b"
(0) EAP-Message = 0x0200000c0175736572303031
(0) Message-Authenticator = 0x679feba3c9f1773e472f5380ddc76888
(0) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) [preprocess] = ok
(0) [chap] = noop
(0) [mschap] = noop
(0) [digest] = noop
(0) suffix: Checking for suffix after "@"
(0) suffix: No '@' in User-Name = "user001", looking up realm NULL
(0) suffix: No such realm "NULL"
(0) [suffix] = noop
(0) eap: Peer sent EAP Response (code 2) ID 0 length 12
(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit
the rest of authorize
(0) [eap] = ok
(0) } # authorize = ok
(0) Found Auth-Type = eap
(0) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(0) authenticate {
(0) eap: Peer sent packet with method EAP Identity (1)
(0) eap: Calling submodule eap_md5 to process data
(0) eap_md5: Issuing MD5 Challenge
(0) eap: Sending EAP Request (code 1) ID 1 length 22
(0) eap: EAP session adding &reply:State = 0x186a0e6c186b0ac5
(0) [eap] = handled
(0) } # authenticate = handled
(0) Using Post-Auth-Type Challenge
(0) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(0) Challenge { ... } # empty sub-section is ignored
(0) Sent Access-Challenge Id 0 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(0) EAP-Message = 0x01010016041045887b14d825549ee44bd88d1f95b6b5
(0) Message-Authenticator = 0x00000000000000000000000000000000
(0) State = 0x186a0e6c186b0ac57984571c96feda45
(0) Finished request
Waking up in 4.9 seconds.
(1) Received Access-Request Id 1 from 192.168.103.4:47841 to
192.168.103.2:1812 length 134
(1) User-Name = "user001"
(1) NAS-IP-Address = 127.0.0.1
(1) Calling-Station-Id = "02-00-00-00-00-01"
(1) Framed-MTU = 1400
(1) NAS-Port-Type = Wireless-802.11
(1) Connect-Info = "CONNECT 11Mbps 802.11b"
(1) EAP-Message = 0x020100060319
(1) State = 0x186a0e6c186b0ac57984571c96feda45
(1) Message-Authenticator = 0x7c61e54373c633326aaa4b2189df56cd
(1) session-state: No cached attributes
(1) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(1) authorize {
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # if (&User-Name) = notfound
(1) } # policy filter_username = notfound
(1) [preprocess] = ok
(1) [chap] = noop
(1) [mschap] = noop
(1) [digest] = noop
(1) suffix: Checking for suffix after "@"
(1) suffix: No '@' in User-Name = "user001", looking up realm NULL
(1) suffix: No such realm "NULL"
(1) [suffix] = noop
(1) eap: Peer sent EAP Response (code 2) ID 1 length 6
(1) eap: No EAP Start, assuming it's an on-going EAP conversation
(1) [eap] = updated
(1) [files] = noop
rlm_ldap (ldap): Reserved connection (0)
(1) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(1) ldap: --> (uid=user001)
(1) ldap: Performing search in "dc=home" with filter "(uid=user001)",
scope "sub"
(1) ldap: Waiting for search result...
(1) ldap: User object found at DN "uid=user001,ou=test,dc=home"
(1) ldap: Processing user attributes
(1) ldap: control:Password-With-Header += 'Pass@word'
rlm_ldap (ldap): Released connection (0)
Need 5 more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (5), 1 of 27 pending slots used
rlm_ldap (ldap): Connecting to ldap://192.168.103.10:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
(1) [ldap] = updated
(1) [expiration] = noop
(1) [logintime] = noop
(1) pap: No {...} in Password-With-Header, re-writing to Cleartext-Password
(1) pap: Removing &control:Password-With-Header
(1) pap: WARNING: Auth-Type already set. Not setting to PAP
(1) [pap] = noop
(1) } # authorize = updated
(1) Found Auth-Type = eap
(1) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(1) authenticate {
(1) eap: Expiring EAP session with state 0x186a0e6c186b0ac5
(1) eap: Finished EAP session with state 0x186a0e6c186b0ac5
(1) eap: Previous EAP request found for state 0x186a0e6c186b0ac5,
released from the list
(1) eap: Peer sent packet with method EAP NAK (3)
(1) eap: Found mutually acceptable type PEAP (25)
(1) eap: Calling submodule eap_peap to process data
(1) eap_peap: Initiating new EAP-TLS session
(1) eap_peap: [eaptls start] = request
(1) eap: Sending EAP Request (code 1) ID 2 length 6
(1) eap: EAP session adding &reply:State = 0x186a0e6c196817c5
(1) [eap] = handled
(1) } # authenticate = handled
(1) Using Post-Auth-Type Challenge
(1) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(1) Challenge { ... } # empty sub-section is ignored
(1) Sent Access-Challenge Id 1 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(1) EAP-Message = 0x010200061920
(1) Message-Authenticator = 0x00000000000000000000000000000000
(1) State = 0x186a0e6c196817c57984571c96feda45
(1) Finished request
Waking up in 4.9 seconds.
(2) Received Access-Request Id 2 from 192.168.103.4:47841 to
192.168.103.2:1812 length 293
(2) User-Name = "user001"
(2) NAS-IP-Address = 127.0.0.1
(2) Calling-Station-Id = "02-00-00-00-00-01"
(2) Framed-MTU = 1400
(2) NAS-Port-Type = Wireless-802.11
(2) Connect-Info = "CONNECT 11Mbps 802.11b"
(2) EAP-Message =
0x020200a519800000009b16030100960100009203015b332b6ca88c248054ee38ab8df7b827fb3a34b8a0236ae99fea798591e5038500004cc014c00a0039003800880087c00fc00500350084c013c00900330032009a009900450044c00ec004002f00960041c012c00800160013c00dc003000a0007c0
(2) State = 0x186a0e6c196817c57984571c96feda45
(2) Message-Authenticator = 0x7d8c5566000064c3fac8d37999172605
(2) session-state: No cached attributes
(2) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(2) authorize {
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) } # if (&User-Name) = notfound
(2) } # policy filter_username = notfound
(2) [preprocess] = ok
(2) [chap] = noop
(2) [mschap] = noop
(2) [digest] = noop
(2) suffix: Checking for suffix after "@"
(2) suffix: No '@' in User-Name = "user001", looking up realm NULL
(2) suffix: No such realm "NULL"
(2) [suffix] = noop
(2) eap: Peer sent EAP Response (code 2) ID 2 length 165
(2) eap: Continuing tunnel setup
(2) [eap] = ok
(2) } # authorize = ok
(2) Found Auth-Type = eap
(2) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(2) authenticate {
(2) eap: Expiring EAP session with state 0x186a0e6c196817c5
(2) eap: Finished EAP session with state 0x186a0e6c196817c5
(2) eap: Previous EAP request found for state 0x186a0e6c196817c5,
released from the list
(2) eap: Peer sent packet with method EAP PEAP (25)
(2) eap: Calling submodule eap_peap to process data
(2) eap_peap: Continuing EAP-TLS
(2) eap_peap: Peer indicated complete TLS record size will be 155 bytes
(2) eap_peap: Got complete TLS record (155 bytes)
(2) eap_peap: [eaptls verify] = length included
(2) eap_peap: (other): before/accept initialization
(2) eap_peap: TLS_accept: before/accept initialization
(2) eap_peap: <<< recv TLS 1.0 Handshake [length 0096], ClientHello
(2) eap_peap: TLS_accept: SSLv3 read client hello A
(2) eap_peap: >>> send TLS 1.0 Handshake [length 003e], ServerHello
(2) eap_peap: TLS_accept: SSLv3 write server hello A
(2) eap_peap: >>> send TLS 1.0 Handshake [length 08d3], Certificate
(2) eap_peap: TLS_accept: SSLv3 write certificate A
(2) eap_peap: >>> send TLS 1.0 Handshake [length 014b], ServerKeyExchange
(2) eap_peap: TLS_accept: SSLv3 write key exchange A
(2) eap_peap: >>> send TLS 1.0 Handshake [length 0004], ServerHelloDone
(2) eap_peap: TLS_accept: SSLv3 write server done A
(2) eap_peap: TLS_accept: SSLv3 flush data
(2) eap_peap: TLS_accept: Need to read more data: SSLv3 read client
certificate A
(2) eap_peap: TLS_accept: Need to read more data: SSLv3 read client
certificate A
(2) eap_peap: In SSL Handshake Phase
(2) eap_peap: In SSL Accept mode
(2) eap_peap: [eaptls process] = handled
(2) eap: Sending EAP Request (code 1) ID 3 length 1004
(2) eap: EAP session adding &reply:State = 0x186a0e6c1a6917c5
(2) [eap] = handled
(2) } # authenticate = handled
(2) Using Post-Auth-Type Challenge
(2) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(2) Challenge { ... } # empty sub-section is ignored
(2) Sent Access-Challenge Id 2 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(2) EAP-Message =
0x010303ec19c000000a74160301003e0200003a03015b32acf865a5f239f3eece59da89ebaca7fea51eb6919222d992ba7dc894750100c014000012ff01000100000b000403000102000f00010116030108d30b0008cf0008cc0003de308203da308202c2a003020102020101300d06092a864886f70d01
(2) Message-Authenticator = 0x00000000000000000000000000000000
(2) State = 0x186a0e6c1a6917c57984571c96feda45
(2) Finished request
Waking up in 4.9 seconds.
(3) Received Access-Request Id 3 from 192.168.103.4:47841 to
192.168.103.2:1812 length 134
(3) User-Name = "user001"
(3) NAS-IP-Address = 127.0.0.1
(3) Calling-Station-Id = "02-00-00-00-00-01"
(3) Framed-MTU = 1400
(3) NAS-Port-Type = Wireless-802.11
(3) Connect-Info = "CONNECT 11Mbps 802.11b"
(3) EAP-Message = 0x020300061900
(3) State = 0x186a0e6c1a6917c57984571c96feda45
(3) Message-Authenticator = 0x9fa5df54eaf49871f860b5eb19e5b0c0
(3) session-state: No cached attributes
(3) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(3) authorize {
(3) policy filter_username {
(3) if (&User-Name) {
(3) if (&User-Name) -> TRUE
(3) if (&User-Name) {
(3) if (&User-Name =~ / /) {
(3) if (&User-Name =~ / /) -> FALSE
(3) if (&User-Name =~ /@[^@]*@/ ) {
(3) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(3) if (&User-Name =~ /\.\./ ) {
(3) if (&User-Name =~ /\.\./ ) -> FALSE
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(3) if (&User-Name =~ /\.$/) {
(3) if (&User-Name =~ /\.$/) -> FALSE
(3) if (&User-Name =~ /(a)\./) {
(3) if (&User-Name =~ /(a)\./) -> FALSE
(3) } # if (&User-Name) = notfound
(3) } # policy filter_username = notfound
(3) [preprocess] = ok
(3) [chap] = noop
(3) [mschap] = noop
(3) [digest] = noop
(3) suffix: Checking for suffix after "@"
(3) suffix: No '@' in User-Name = "user001", looking up realm NULL
(3) suffix: No such realm "NULL"
(3) [suffix] = noop
(3) eap: Peer sent EAP Response (code 2) ID 3 length 6
(3) eap: Continuing tunnel setup
(3) [eap] = ok
(3) } # authorize = ok
(3) Found Auth-Type = eap
(3) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(3) authenticate {
(3) eap: Expiring EAP session with state 0x186a0e6c1a6917c5
(3) eap: Finished EAP session with state 0x186a0e6c1a6917c5
(3) eap: Previous EAP request found for state 0x186a0e6c1a6917c5,
released from the list
(3) eap: Peer sent packet with method EAP PEAP (25)
(3) eap: Calling submodule eap_peap to process data
(3) eap_peap: Continuing EAP-TLS
(3) eap_peap: Peer ACKed our handshake fragment
(3) eap_peap: [eaptls verify] = request
(3) eap_peap: [eaptls process] = handled
(3) eap: Sending EAP Request (code 1) ID 4 length 1000
(3) eap: EAP session adding &reply:State = 0x186a0e6c1b6e17c5
(3) [eap] = handled
(3) } # authenticate = handled
(3) Using Post-Auth-Type Challenge
(3) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(3) Challenge { ... } # empty sub-section is ignored
(3) Sent Access-Challenge Id 3 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(3) EAP-Message =
0x010403e81940d3231b0bfa48b450b8c89f0432a23a5ac5d3f6b7f19378f4901279ac237212a82650f14d833aed8e1adce602b8c6de097685d288edf92cdf406d49f25ef4d291c474d5c1a6ffbe64fae1ef6197d30004e8308204e4308203cca003020102020900c762d342c4805c0e300d06092a864886
(3) Message-Authenticator = 0x00000000000000000000000000000000
(3) State = 0x186a0e6c1b6e17c57984571c96feda45
(3) Finished request
Waking up in 4.9 seconds.
(4) Received Access-Request Id 4 from 192.168.103.4:47841 to
192.168.103.2:1812 length 134
(4) User-Name = "user001"
(4) NAS-IP-Address = 127.0.0.1
(4) Calling-Station-Id = "02-00-00-00-00-01"
(4) Framed-MTU = 1400
(4) NAS-Port-Type = Wireless-802.11
(4) Connect-Info = "CONNECT 11Mbps 802.11b"
(4) EAP-Message = 0x020400061900
(4) State = 0x186a0e6c1b6e17c57984571c96feda45
(4) Message-Authenticator = 0x6736403f7baedf92e695977f1d1a2f92
(4) session-state: No cached attributes
(4) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(4) authorize {
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) } # if (&User-Name) = notfound
(4) } # policy filter_username = notfound
(4) [preprocess] = ok
(4) [chap] = noop
(4) [mschap] = noop
(4) [digest] = noop
(4) suffix: Checking for suffix after "@"
(4) suffix: No '@' in User-Name = "user001", looking up realm NULL
(4) suffix: No such realm "NULL"
(4) [suffix] = noop
(4) eap: Peer sent EAP Response (code 2) ID 4 length 6
(4) eap: Continuing tunnel setup
(4) [eap] = ok
(4) } # authorize = ok
(4) Found Auth-Type = eap
(4) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(4) authenticate {
(4) eap: Expiring EAP session with state 0x186a0e6c1b6e17c5
(4) eap: Finished EAP session with state 0x186a0e6c1b6e17c5
(4) eap: Previous EAP request found for state 0x186a0e6c1b6e17c5,
released from the list
(4) eap: Peer sent packet with method EAP PEAP (25)
(4) eap: Calling submodule eap_peap to process data
(4) eap_peap: Continuing EAP-TLS
(4) eap_peap: Peer ACKed our handshake fragment
(4) eap_peap: [eaptls verify] = request
(4) eap_peap: [eaptls process] = handled
(4) eap: Sending EAP Request (code 1) ID 5 length 694
(4) eap: EAP session adding &reply:State = 0x186a0e6c1c6f17c5
(4) [eap] = handled
(4) } # authenticate = handled
(4) Using Post-Auth-Type Challenge
(4) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(4) Challenge { ... } # empty sub-section is ignored
(4) Sent Access-Challenge Id 4 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(4) EAP-Message =
0x010502b61900130101ff040530030101ff30360603551d1f042f302d302ba029a0278625687474703a2f2f7777772e6578616d706c652e6f72672f6578616d706c655f63612e63726c300d06092a864886f70d0101050500038201010092d400531c09e1c44c689f11afbb4bc09bf6857fc4464ea15c59
(4) Message-Authenticator = 0x00000000000000000000000000000000
(4) State = 0x186a0e6c1c6f17c57984571c96feda45
(4) Finished request
Waking up in 4.9 seconds.
(5) Received Access-Request Id 5 from 192.168.103.4:47841 to
192.168.103.2:1812 length 272
(5) User-Name = "user001"
(5) NAS-IP-Address = 127.0.0.1
(5) Calling-Station-Id = "02-00-00-00-00-01"
(5) Framed-MTU = 1400
(5) NAS-Port-Type = Wireless-802.11
(5) Connect-Info = "CONNECT 11Mbps 802.11b"
(5) EAP-Message =
0x0205009019800000008616030100461000004241047e89a09aa9195eee65203d4a9bf38f14b514bab3ba7aae5104f80d3f77b2f4d1524dc06e814cc1b1d28922949f737238c870cdf694b9b42a63156e4e74685d83140301000101160301003027b746221e24aed1f5ba0515fb310d8d6f6bcb1b3e3da8
(5) State = 0x186a0e6c1c6f17c57984571c96feda45
(5) Message-Authenticator = 0x6d56a055ede3b3bfc8800ad39ab8a935
(5) session-state: No cached attributes
(5) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(5) authorize {
(5) policy filter_username {
(5) if (&User-Name) {
(5) if (&User-Name) -> TRUE
(5) if (&User-Name) {
(5) if (&User-Name =~ / /) {
(5) if (&User-Name =~ / /) -> FALSE
(5) if (&User-Name =~ /@[^@]*@/ ) {
(5) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(5) if (&User-Name =~ /\.\./ ) {
(5) if (&User-Name =~ /\.\./ ) -> FALSE
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(5) if (&User-Name =~ /\.$/) {
(5) if (&User-Name =~ /\.$/) -> FALSE
(5) if (&User-Name =~ /(a)\./) {
(5) if (&User-Name =~ /(a)\./) -> FALSE
(5) } # if (&User-Name) = notfound
(5) } # policy filter_username = notfound
(5) [preprocess] = ok
(5) [chap] = noop
(5) [mschap] = noop
(5) [digest] = noop
(5) suffix: Checking for suffix after "@"
(5) suffix: No '@' in User-Name = "user001", looking up realm NULL
(5) suffix: No such realm "NULL"
(5) [suffix] = noop
(5) eap: Peer sent EAP Response (code 2) ID 5 length 144
(5) eap: Continuing tunnel setup
(5) [eap] = ok
(5) } # authorize = ok
(5) Found Auth-Type = eap
(5) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(5) authenticate {
(5) eap: Expiring EAP session with state 0x186a0e6c1c6f17c5
(5) eap: Finished EAP session with state 0x186a0e6c1c6f17c5
(5) eap: Previous EAP request found for state 0x186a0e6c1c6f17c5,
released from the list
(5) eap: Peer sent packet with method EAP PEAP (25)
(5) eap: Calling submodule eap_peap to process data
(5) eap_peap: Continuing EAP-TLS
(5) eap_peap: Peer indicated complete TLS record size will be 134 bytes
(5) eap_peap: Got complete TLS record (134 bytes)
(5) eap_peap: [eaptls verify] = length included
(5) eap_peap: <<< recv TLS 1.0 Handshake [length 0046], ClientKeyExchange
(5) eap_peap: TLS_accept: SSLv3 read client key exchange A
(5) eap_peap: <<< recv TLS 1.0 ChangeCipherSpec [length 0001]
(5) eap_peap: <<< recv TLS 1.0 Handshake [length 0010], Finished
(5) eap_peap: TLS_accept: SSLv3 read finished A
(5) eap_peap: >>> send TLS 1.0 ChangeCipherSpec [length 0001]
(5) eap_peap: TLS_accept: SSLv3 write change cipher spec A
(5) eap_peap: >>> send TLS 1.0 Handshake [length 0010], Finished
(5) eap_peap: TLS_accept: SSLv3 write finished A
(5) eap_peap: TLS_accept: SSLv3 flush data
(5) eap_peap: (other): SSL negotiation finished successfully
(5) eap_peap: SSL Connection Established
(5) eap_peap: [eaptls process] = handled
(5) eap: Sending EAP Request (code 1) ID 6 length 65
(5) eap: EAP session adding &reply:State = 0x186a0e6c1d6c17c5
(5) [eap] = handled
(5) } # authenticate = handled
(5) Using Post-Auth-Type Challenge
(5) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(5) Challenge { ... } # empty sub-section is ignored
(5) Sent Access-Challenge Id 5 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(5) EAP-Message =
0x0106004119001403010001011603010030b75756ba563254cec0a03c450c676171d90fa3f50211a2f912759605e739ce90d5ec9f2d794ed3f7db091b481261820c
(5) Message-Authenticator = 0x00000000000000000000000000000000
(5) State = 0x186a0e6c1d6c17c57984571c96feda45
(5) Finished request
Waking up in 4.9 seconds.
(6) Received Access-Request Id 6 from 192.168.103.4:47841 to
192.168.103.2:1812 length 134
(6) User-Name = "user001"
(6) NAS-IP-Address = 127.0.0.1
(6) Calling-Station-Id = "02-00-00-00-00-01"
(6) Framed-MTU = 1400
(6) NAS-Port-Type = Wireless-802.11
(6) Connect-Info = "CONNECT 11Mbps 802.11b"
(6) EAP-Message = 0x020600061900
(6) State = 0x186a0e6c1d6c17c57984571c96feda45
(6) Message-Authenticator = 0xbb380f836baa8c893f1e7216c5e7f068
(6) session-state: No cached attributes
(6) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(6) authorize {
(6) policy filter_username {
(6) if (&User-Name) {
(6) if (&User-Name) -> TRUE
(6) if (&User-Name) {
(6) if (&User-Name =~ / /) {
(6) if (&User-Name =~ / /) -> FALSE
(6) if (&User-Name =~ /@[^@]*@/ ) {
(6) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(6) if (&User-Name =~ /\.\./ ) {
(6) if (&User-Name =~ /\.\./ ) -> FALSE
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(6) if (&User-Name =~ /\.$/) {
(6) if (&User-Name =~ /\.$/) -> FALSE
(6) if (&User-Name =~ /(a)\./) {
(6) if (&User-Name =~ /(a)\./) -> FALSE
(6) } # if (&User-Name) = notfound
(6) } # policy filter_username = notfound
(6) [preprocess] = ok
(6) [chap] = noop
(6) [mschap] = noop
(6) [digest] = noop
(6) suffix: Checking for suffix after "@"
(6) suffix: No '@' in User-Name = "user001", looking up realm NULL
(6) suffix: No such realm "NULL"
(6) [suffix] = noop
(6) eap: Peer sent EAP Response (code 2) ID 6 length 6
(6) eap: Continuing tunnel setup
(6) [eap] = ok
(6) } # authorize = ok
(6) Found Auth-Type = eap
(6) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(6) authenticate {
(6) eap: Expiring EAP session with state 0x186a0e6c1d6c17c5
(6) eap: Finished EAP session with state 0x186a0e6c1d6c17c5
(6) eap: Previous EAP request found for state 0x186a0e6c1d6c17c5,
released from the list
(6) eap: Peer sent packet with method EAP PEAP (25)
(6) eap: Calling submodule eap_peap to process data
(6) eap_peap: Continuing EAP-TLS
(6) eap_peap: Peer ACKed our handshake fragment. handshake is finished
(6) eap_peap: [eaptls verify] = success
(6) eap_peap: [eaptls process] = success
(6) eap_peap: Session established. Decoding tunneled attributes
(6) eap_peap: PEAP state TUNNEL ESTABLISHED
(6) eap: Sending EAP Request (code 1) ID 7 length 43
(6) eap: EAP session adding &reply:State = 0x186a0e6c1e6d17c5
(6) [eap] = handled
(6) } # authenticate = handled
(6) Using Post-Auth-Type Challenge
(6) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(6) Challenge { ... } # empty sub-section is ignored
(6) Sent Access-Challenge Id 6 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(6) EAP-Message =
0x0107002b19001703010020bd2d0af72124240767092f71860daa342d5ef6b0050425e5f8f127bf43b2405f
(6) Message-Authenticator = 0x00000000000000000000000000000000
(6) State = 0x186a0e6c1e6d17c57984571c96feda45
(6) Finished request
Waking up in 4.9 seconds.
(7) Received Access-Request Id 7 from 192.168.103.4:47841 to
192.168.103.2:1812 length 208
(7) User-Name = "user001"
(7) NAS-IP-Address = 127.0.0.1
(7) Calling-Station-Id = "02-00-00-00-00-01"
(7) Framed-MTU = 1400
(7) NAS-Port-Type = Wireless-802.11
(7) Connect-Info = "CONNECT 11Mbps 802.11b"
(7) EAP-Message =
0x02070050190017030100202b5937f4b944b27f59ca2e4cacf6b1f450f7e2e0baa25f318004586c3cff33a31703010020f91fb26e67e589842c4890663b5061fe23583fec56db5edf9b17d56634cfd978
(7) State = 0x186a0e6c1e6d17c57984571c96feda45
(7) Message-Authenticator = 0xcb5902be23698745e6d3cd0a9387206c
(7) session-state: No cached attributes
(7) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(7) authorize {
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = notfound
(7) } # policy filter_username = notfound
(7) [preprocess] = ok
(7) [chap] = noop
(7) [mschap] = noop
(7) [digest] = noop
(7) suffix: Checking for suffix after "@"
(7) suffix: No '@' in User-Name = "user001", looking up realm NULL
(7) suffix: No such realm "NULL"
(7) [suffix] = noop
(7) eap: Peer sent EAP Response (code 2) ID 7 length 80
(7) eap: Continuing tunnel setup
(7) [eap] = ok
(7) } # authorize = ok
(7) Found Auth-Type = eap
(7) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(7) authenticate {
(7) eap: Expiring EAP session with state 0x186a0e6c1e6d17c5
(7) eap: Finished EAP session with state 0x186a0e6c1e6d17c5
(7) eap: Previous EAP request found for state 0x186a0e6c1e6d17c5,
released from the list
(7) eap: Peer sent packet with method EAP PEAP (25)
(7) eap: Calling submodule eap_peap to process data
(7) eap_peap: Continuing EAP-TLS
(7) eap_peap: [eaptls verify] = ok
(7) eap_peap: Done initial handshake
(7) eap_peap: [eaptls process] = ok
(7) eap_peap: Session established. Decoding tunneled attributes
(7) eap_peap: PEAP state WAITING FOR INNER IDENTITY
(7) eap_peap: Identity - user001
(7) eap_peap: Got inner identity 'user001'
(7) eap_peap: Setting default EAP type for tunneled EAP session
(7) eap_peap: Got tunneled request
(7) eap_peap: EAP-Message = 0x0207000c0175736572303031
(7) eap_peap: Setting User-Name to user001
(7) eap_peap: Sending tunneled request to inner-tunnel
(7) eap_peap: EAP-Message = 0x0207000c0175736572303031
(7) eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(7) eap_peap: User-Name = "user001"
(7) Virtual server inner-tunnel received request
(7) EAP-Message = 0x0207000c0175736572303031
(7) FreeRADIUS-Proxied-To = 127.0.0.1
(7) User-Name = "user001"
(7) WARNING: Outer and inner identities are the same. User privacy is
compromised.
(7) server inner-tunnel {
(7) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(7) authorize {
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = notfound
(7) } # policy filter_username = notfound
(7) [chap] = noop
(7) [mschap] = noop
(7) suffix: Checking for suffix after "@"
(7) suffix: No '@' in User-Name = "user001", looking up realm NULL
(7) suffix: No such realm "NULL"
(7) [suffix] = noop
(7) update control {
(7) &Proxy-To-Realm := LOCAL
(7) } # update control = noop
(7) eap: Peer sent EAP Response (code 2) ID 7 length 12
(7) eap: EAP-Identity reply, returning 'ok' so we can short-circuit
the rest of authorize
(7) [eap] = ok
(7) } # authorize = ok
(7) Found Auth-Type = eap
(7) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(7) authenticate {
(7) eap: Peer sent packet with method EAP Identity (1)
(7) eap: Calling submodule eap_mschapv2 to process data
(7) eap_mschapv2: Issuing Challenge
(7) eap: Sending EAP Request (code 1) ID 8 length 43
(7) eap: EAP session adding &reply:State = 0xb2ca8b3bb2c2917f
(7) [eap] = handled
(7) } # authenticate = handled
(7) } # server inner-tunnel
(7) Virtual server sending reply
(7) EAP-Message =
0x0108002b1a010800261034213726edcf30d2e2417530feca1f17667265657261646975732d332e302e3137
(7) Message-Authenticator = 0x00000000000000000000000000000000
(7) State = 0xb2ca8b3bb2c2917f09d0e8253bfea91e
(7) eap_peap: Got tunneled reply code 11
(7) eap_peap: EAP-Message =
0x0108002b1a010800261034213726edcf30d2e2417530feca1f17667265657261646975732d332e302e3137
(7) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(7) eap_peap: State = 0xb2ca8b3bb2c2917f09d0e8253bfea91e
(7) eap_peap: Got tunneled reply RADIUS code 11
(7) eap_peap: EAP-Message =
0x0108002b1a010800261034213726edcf30d2e2417530feca1f17667265657261646975732d332e302e3137
(7) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(7) eap_peap: State = 0xb2ca8b3bb2c2917f09d0e8253bfea91e
(7) eap_peap: Got tunneled Access-Challenge
(7) eap: Sending EAP Request (code 1) ID 8 length 75
(7) eap: EAP session adding &reply:State = 0x186a0e6c1f6217c5
(7) [eap] = handled
(7) } # authenticate = handled
(7) Using Post-Auth-Type Challenge
(7) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(7) Challenge { ... } # empty sub-section is ignored
(7) Sent Access-Challenge Id 7 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(7) EAP-Message =
0x0108004b190017030100400f36c3251958eae8435610e577612e8e9d6a9080cb3ec9b052234156e0cb6bb615eddb0736adc396fe12817dea26a98327e6bd21b523543ec72fad7d674c001e
(7) Message-Authenticator = 0x00000000000000000000000000000000
(7) State = 0x186a0e6c1f6217c57984571c96feda45
(7) Finished request
Waking up in 4.9 seconds.
(8) Received Access-Request Id 8 from 192.168.103.4:47841 to
192.168.103.2:1812 length 272
(8) User-Name = "user001"
(8) NAS-IP-Address = 127.0.0.1
(8) Calling-Station-Id = "02-00-00-00-00-01"
(8) Framed-MTU = 1400
(8) NAS-Port-Type = Wireless-802.11
(8) Connect-Info = "CONNECT 11Mbps 802.11b"
(8) EAP-Message =
0x020800901900170301002086d6d2186da193675b361b94410068b8ae6d915ef3834164f48178e4cce07f08170301006081654fe5086f906d2902662352a8b6c2094b73311fcfedab254e01b11f7b4138e07c7d87dc9185b07b2502ee99edd843285961c629bfa88f5e994c1db85ee10a0c1e48801aee88
(8) State = 0x186a0e6c1f6217c57984571c96feda45
(8) Message-Authenticator = 0x4923fa28964bfa7aef8bc28213d8cd32
(8) session-state: No cached attributes
(8) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(8) authorize {
(8) policy filter_username {
(8) if (&User-Name) {
(8) if (&User-Name) -> TRUE
(8) if (&User-Name) {
(8) if (&User-Name =~ / /) {
(8) if (&User-Name =~ / /) -> FALSE
(8) if (&User-Name =~ /@[^@]*@/ ) {
(8) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(8) if (&User-Name =~ /\.\./ ) {
(8) if (&User-Name =~ /\.\./ ) -> FALSE
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(8) if (&User-Name =~ /\.$/) {
(8) if (&User-Name =~ /\.$/) -> FALSE
(8) if (&User-Name =~ /(a)\./) {
(8) if (&User-Name =~ /(a)\./) -> FALSE
(8) } # if (&User-Name) = notfound
(8) } # policy filter_username = notfound
(8) [preprocess] = ok
(8) [chap] = noop
(8) [mschap] = noop
(8) [digest] = noop
(8) suffix: Checking for suffix after "@"
(8) suffix: No '@' in User-Name = "user001", looking up realm NULL
(8) suffix: No such realm "NULL"
(8) [suffix] = noop
(8) eap: Peer sent EAP Response (code 2) ID 8 length 144
(8) eap: Continuing tunnel setup
(8) [eap] = ok
(8) } # authorize = ok
(8) Found Auth-Type = eap
(8) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(8) authenticate {
(8) eap: Expiring EAP session with state 0xb2ca8b3bb2c2917f
(8) eap: Finished EAP session with state 0x186a0e6c1f6217c5
(8) eap: Previous EAP request found for state 0x186a0e6c1f6217c5,
released from the list
(8) eap: Peer sent packet with method EAP PEAP (25)
(8) eap: Calling submodule eap_peap to process data
(8) eap_peap: Continuing EAP-TLS
(8) eap_peap: [eaptls verify] = ok
(8) eap_peap: Done initial handshake
(8) eap_peap: [eaptls process] = ok
(8) eap_peap: Session established. Decoding tunneled attributes
(8) eap_peap: PEAP state phase2
(8) eap_peap: EAP method MSCHAPv2 (26)
(8) eap_peap: Got tunneled request
(8) eap_peap: EAP-Message =
0x020800421a0208003d31d60a5331dba1431cc70e41aed8d01f390000000000000000e029925ac2cca206fe67df52363bad347e0884f74abd901e0075736572303031
(8) eap_peap: Setting User-Name to user001
(8) eap_peap: Sending tunneled request to inner-tunnel
(8) eap_peap: EAP-Message =
0x020800421a0208003d31d60a5331dba1431cc70e41aed8d01f390000000000000000e029925ac2cca206fe67df52363bad347e0884f74abd901e0075736572303031
(8) eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(8) eap_peap: User-Name = "user001"
(8) eap_peap: State = 0xb2ca8b3bb2c2917f09d0e8253bfea91e
(8) Virtual server inner-tunnel received request
(8) EAP-Message =
0x020800421a0208003d31d60a5331dba1431cc70e41aed8d01f390000000000000000e029925ac2cca206fe67df52363bad347e0884f74abd901e0075736572303031
(8) FreeRADIUS-Proxied-To = 127.0.0.1
(8) User-Name = "user001"
(8) State = 0xb2ca8b3bb2c2917f09d0e8253bfea91e
(8) WARNING: Outer and inner identities are the same. User privacy is
compromised.
(8) server inner-tunnel {
(8) session-state: No cached attributes
(8) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(8) authorize {
(8) policy filter_username {
(8) if (&User-Name) {
(8) if (&User-Name) -> TRUE
(8) if (&User-Name) {
(8) if (&User-Name =~ / /) {
(8) if (&User-Name =~ / /) -> FALSE
(8) if (&User-Name =~ /@[^@]*@/ ) {
(8) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(8) if (&User-Name =~ /\.\./ ) {
(8) if (&User-Name =~ /\.\./ ) -> FALSE
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(8) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(8) if (&User-Name =~ /\.$/) {
(8) if (&User-Name =~ /\.$/) -> FALSE
(8) if (&User-Name =~ /(a)\./) {
(8) if (&User-Name =~ /(a)\./) -> FALSE
(8) } # if (&User-Name) = notfound
(8) } # policy filter_username = notfound
(8) [chap] = noop
(8) [mschap] = noop
(8) suffix: Checking for suffix after "@"
(8) suffix: No '@' in User-Name = "user001", looking up realm NULL
(8) suffix: No such realm "NULL"
(8) [suffix] = noop
(8) update control {
(8) &Proxy-To-Realm := LOCAL
(8) } # update control = noop
(8) eap: Peer sent EAP Response (code 2) ID 8 length 66
(8) eap: No EAP Start, assuming it's an on-going EAP conversation
(8) [eap] = updated
(8) [files] = noop
rlm_ldap (ldap): Reserved connection (1)
(8) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(8) ldap: --> (uid=user001)
(8) ldap: Performing search in "dc=home" with filter "(uid=user001)",
scope "sub"
(8) ldap: Waiting for search result...
(8) ldap: User object found at DN "uid=user001,ou=test,dc=home"
(8) ldap: Processing user attributes
(8) ldap: control:Password-With-Header += 'Pass@word'
rlm_ldap (ldap): Released connection (1)
(8) [ldap] = updated
(8) [expiration] = noop
(8) [logintime] = noop
(8) pap: No {...} in Password-With-Header, re-writing to Cleartext-Password
(8) pap: Removing &control:Password-With-Header
(8) pap: WARNING: Auth-Type already set. Not setting to PAP
(8) [pap] = noop
(8) } # authorize = updated
(8) Found Auth-Type = eap
(8) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(8) authenticate {
(8) eap: Expiring EAP session with state 0xb2ca8b3bb2c2917f
(8) eap: Finished EAP session with state 0xb2ca8b3bb2c2917f
(8) eap: Previous EAP request found for state 0xb2ca8b3bb2c2917f,
released from the list
(8) eap: Peer sent packet with method EAP MSCHAPv2 (26)
(8) eap: Calling submodule eap_mschapv2 to process data
(8) eap_mschapv2: # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(8) eap_mschapv2: authenticate {
(8) mschap: Found Cleartext-Password, hashing to create NT-Password
(8) mschap: Found Cleartext-Password, hashing to create LM-Password
(8) mschap: Creating challenge hash with username: user001
(8) mschap: Client is using MS-CHAPv2
(8) mschap: ERROR: MS-CHAP2-Response is incorrect
(8) [mschap] = reject
(8) } # authenticate = reject
(8) eap: Sending EAP Failure (code 4) ID 8 length 4
(8) eap: Freeing handler
(8) [eap] = reject
(8) } # authenticate = reject
(8) Failed to authenticate the user
(8) Using Post-Auth-Type Reject
(8) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(8) Post-Auth-Type REJECT {
(8) attr_filter.access_reject: EXPAND %{User-Name}
(8) attr_filter.access_reject: --> user001
(8) attr_filter.access_reject: Matched entry DEFAULT at line 11
(8) [attr_filter.access_reject] = updated
(8) update outer.session-state {
(8) &Module-Failure-Message := &request:Module-Failure-Message
-> 'mschap: MS-CHAP2-Response is incorrect'
(8) } # update outer.session-state = noop
(8) } # Post-Auth-Type REJECT = updated
(8) Login incorrect (mschap: MS-CHAP2-Response is incorrect):
[user001] (from client all-network port 0 via TLS tunnel)
(8) } # server inner-tunnel
(8) Virtual server sending reply
(8) MS-CHAP-Error = "\010E=691 R=1
C=9b892032077589b54b87dfec62977166 V=3 M=Authentication rejected"
(8) EAP-Message = 0x04080004
(8) Message-Authenticator = 0x00000000000000000000000000000000
(8) eap_peap: Got tunneled reply code 3
(8) eap_peap: MS-CHAP-Error = "\010E=691 R=1
C=9b892032077589b54b87dfec62977166 V=3 M=Authentication rejected"
(8) eap_peap: EAP-Message = 0x04080004
(8) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(8) eap_peap: Got tunneled reply RADIUS code 3
(8) eap_peap: MS-CHAP-Error = "\010E=691 R=1
C=9b892032077589b54b87dfec62977166 V=3 M=Authentication rejected"
(8) eap_peap: EAP-Message = 0x04080004
(8) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(8) eap_peap: Tunneled authentication was rejected
(8) eap_peap: FAILURE
(8) eap: Sending EAP Request (code 1) ID 9 length 43
(8) eap: EAP session adding &reply:State = 0x186a0e6c106317c5
(8) [eap] = handled
(8) } # authenticate = handled
(8) Using Post-Auth-Type Challenge
(8) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(8) Challenge { ... } # empty sub-section is ignored
(8) session-state: Saving cached attributes
(8) Module-Failure-Message := "mschap: MS-CHAP2-Response is incorrect"
(8) Sent Access-Challenge Id 8 from 192.168.103.2:1812 to
192.168.103.4:47841 length 0
(8) EAP-Message =
0x0109002b1900170301002067e9cac1bf37a0e7b2e58e299d31891a1fcb8301978bc19a82b16cc32f8fc935
(8) Message-Authenticator = 0x00000000000000000000000000000000
(8) State = 0x186a0e6c106317c57984571c96feda45
(8) Finished request
Waking up in 4.9 seconds.
(9) Received Access-Request Id 9 from 192.168.103.4:47841 to
192.168.103.2:1812 length 208
(9) User-Name = "user001"
(9) NAS-IP-Address = 127.0.0.1
(9) Calling-Station-Id = "02-00-00-00-00-01"
(9) Framed-MTU = 1400
(9) NAS-Port-Type = Wireless-802.11
(9) Connect-Info = "CONNECT 11Mbps 802.11b"
(9) EAP-Message =
0x0209005019001703010020016ad7d5770bd72e9fc473c174260de58a5a1b24aee7f28f076622ce50fd944f1703010020621743e011311bfbbab226da72788784635a0d351a80db3c30713903bebbb8d2
(9) State = 0x186a0e6c106317c57984571c96feda45
(9) Message-Authenticator = 0x6f729f136b21246a5789b189823cacaf
(9) Restoring &session-state
(9) &session-state:Module-Failure-Message := "mschap:
MS-CHAP2-Response is incorrect"
(9) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(9) authorize {
(9) policy filter_username {
(9) if (&User-Name) {
(9) if (&User-Name) -> TRUE
(9) if (&User-Name) {
(9) if (&User-Name =~ / /) {
(9) if (&User-Name =~ / /) -> FALSE
(9) if (&User-Name =~ /@[^@]*@/ ) {
(9) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(9) if (&User-Name =~ /\.\./ ) {
(9) if (&User-Name =~ /\.\./ ) -> FALSE
(9) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(9) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(9) if (&User-Name =~ /\.$/) {
(9) if (&User-Name =~ /\.$/) -> FALSE
(9) if (&User-Name =~ /(a)\./) {
(9) if (&User-Name =~ /(a)\./) -> FALSE
(9) } # if (&User-Name) = notfound
(9) } # policy filter_username = notfound
(9) [preprocess] = ok
(9) [chap] = noop
(9) [mschap] = noop
(9) [digest] = noop
(9) suffix: Checking for suffix after "@"
(9) suffix: No '@' in User-Name = "user001", looking up realm NULL
(9) suffix: No such realm "NULL"
(9) [suffix] = noop
(9) eap: Peer sent EAP Response (code 2) ID 9 length 80
(9) eap: Continuing tunnel setup
(9) [eap] = ok
(9) } # authorize = ok
(9) Found Auth-Type = eap
(9) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(9) authenticate {
(9) eap: Expiring EAP session with state 0x186a0e6c106317c5
(9) eap: Finished EAP session with state 0x186a0e6c106317c5
(9) eap: Previous EAP request found for state 0x186a0e6c106317c5,
released from the list
(9) eap: Peer sent packet with method EAP PEAP (25)
(9) eap: Calling submodule eap_peap to process data
(9) eap_peap: Continuing EAP-TLS
(9) eap_peap: [eaptls verify] = ok
(9) eap_peap: Done initial handshake
(9) eap_peap: [eaptls process] = ok
(9) eap_peap: Session established. Decoding tunneled attributes
(9) eap_peap: PEAP state send tlv failure
(9) eap_peap: Received EAP-TLV response
(9) eap_peap: ERROR: The users session was previously rejected:
returning reject (again.)
(9) eap_peap: This means you need to read the PREVIOUS messages in
the debug output
(9) eap_peap: to find out the reason why the user was rejected
(9) eap_peap: Look for "reject" or "fail". Those earlier messages
will tell you
(9) eap_peap: what went wrong, and how to fix the problem
(9) eap: ERROR: Failed continuing EAP PEAP (25) session. EAP sub-module failed
(9) eap: Sending EAP Failure (code 4) ID 9 length 4
(9) eap: Failed in EAP select
(9) [eap] = invalid
(9) } # authenticate = invalid
(9) Failed to authenticate the user
(9) Using Post-Auth-Type Reject
(9) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(9) Post-Auth-Type REJECT {
(9) attr_filter.access_reject: EXPAND %{User-Name}
(9) attr_filter.access_reject: --> user001
(9) attr_filter.access_reject: Matched entry DEFAULT at line 11
(9) [attr_filter.access_reject] = updated
(9) [eap] = noop
(9) policy remove_reply_message_if_eap {
(9) if (&reply:EAP-Message && &reply:Reply-Message) {
(9) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(9) else {
(9) [noop] = noop
(9) } # else = noop
(9) } # policy remove_reply_message_if_eap = noop
(9) } # Post-Auth-Type REJECT = updated
(9) Login incorrect (eap_peap: The users session was previously
rejected: returning reject (again.)): [user001] (from client
all-network port 0 cli 02-00-00-00-00-01)
(9) Delaying response for 1.000000 seconds
Waking up in 0.3 seconds.
Waking up in 0.6 seconds.
(9) Sending delayed response
(9) Sent Access-Reject Id 9 from 192.168.103.2:1812 to
192.168.103.4:47841 length 44
(9) EAP-Message = 0x04090004
(9) Message-Authenticator = 0x00000000000000000000000000000000
## Authenticate with password 'Pass@word'.
Waking up in 3.9 seconds.
(10) Received Access-Request Id 0 from 192.168.103.4:55548 to
192.168.103.2:1812 length 122
(10) User-Name = "user001"
(10) NAS-IP-Address = 127.0.0.1
(10) Calling-Station-Id = "02-00-00-00-00-01"
(10) Framed-MTU = 1400
(10) NAS-Port-Type = Wireless-802.11
(10) Connect-Info = "CONNECT 11Mbps 802.11b"
(10) EAP-Message = 0x0200000c0175736572303031
(10) Message-Authenticator = 0x50cc7b8af5949c955f1f3d60576990b7
(10) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(10) authorize {
(10) policy filter_username {
(10) if (&User-Name) {
(10) if (&User-Name) -> TRUE
(10) if (&User-Name) {
(10) if (&User-Name =~ / /) {
(10) if (&User-Name =~ / /) -> FALSE
(10) if (&User-Name =~ /@[^@]*@/ ) {
(10) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(10) if (&User-Name =~ /\.\./ ) {
(10) if (&User-Name =~ /\.\./ ) -> FALSE
(10) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(10) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(10) if (&User-Name =~ /\.$/) {
(10) if (&User-Name =~ /\.$/) -> FALSE
(10) if (&User-Name =~ /(a)\./) {
(10) if (&User-Name =~ /(a)\./) -> FALSE
(10) } # if (&User-Name) = notfound
(10) } # policy filter_username = notfound
(10) [preprocess] = ok
(10) [chap] = noop
(10) [mschap] = noop
(10) [digest] = noop
(10) suffix: Checking for suffix after "@"
(10) suffix: No '@' in User-Name = "user001", looking up realm NULL
(10) suffix: No such realm "NULL"
(10) [suffix] = noop
(10) eap: Peer sent EAP Response (code 2) ID 0 length 12
(10) eap: EAP-Identity reply, returning 'ok' so we can short-circuit
the rest of authorize
(10) [eap] = ok
(10) } # authorize = ok
(10) Found Auth-Type = eap
(10) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(10) authenticate {
(10) eap: Peer sent packet with method EAP Identity (1)
(10) eap: Calling submodule eap_md5 to process data
(10) eap_md5: Issuing MD5 Challenge
(10) eap: Sending EAP Request (code 1) ID 1 length 22
(10) eap: EAP session adding &reply:State = 0xb09e5f13b09f5bda
(10) [eap] = handled
(10) } # authenticate = handled
(10) Using Post-Auth-Type Challenge
(10) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(10) Challenge { ... } # empty sub-section is ignored
(10) Sent Access-Challenge Id 0 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(10) EAP-Message = 0x010100160410d6321c67873ca6a2fd3f51f8be2c417b
(10) Message-Authenticator = 0x00000000000000000000000000000000
(10) State = 0xb09e5f13b09f5bdad63a05ea128e9a97
(10) Finished request
Waking up in 0.2 seconds.
(11) Received Access-Request Id 1 from 192.168.103.4:55548 to
192.168.103.2:1812 length 134
(11) User-Name = "user001"
(11) NAS-IP-Address = 127.0.0.1
(11) Calling-Station-Id = "02-00-00-00-00-01"
(11) Framed-MTU = 1400
(11) NAS-Port-Type = Wireless-802.11
(11) Connect-Info = "CONNECT 11Mbps 802.11b"
(11) EAP-Message = 0x020100060319
(11) State = 0xb09e5f13b09f5bdad63a05ea128e9a97
(11) Message-Authenticator = 0xb182df041321aa5880caf743ab8893e5
(11) session-state: No cached attributes
(11) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(11) authorize {
(11) policy filter_username {
(11) if (&User-Name) {
(11) if (&User-Name) -> TRUE
(11) if (&User-Name) {
(11) if (&User-Name =~ / /) {
(11) if (&User-Name =~ / /) -> FALSE
(11) if (&User-Name =~ /@[^@]*@/ ) {
(11) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(11) if (&User-Name =~ /\.\./ ) {
(11) if (&User-Name =~ /\.\./ ) -> FALSE
(11) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(11) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(11) if (&User-Name =~ /\.$/) {
(11) if (&User-Name =~ /\.$/) -> FALSE
(11) if (&User-Name =~ /(a)\./) {
(11) if (&User-Name =~ /(a)\./) -> FALSE
(11) } # if (&User-Name) = notfound
(11) } # policy filter_username = notfound
(11) [preprocess] = ok
(11) [chap] = noop
(11) [mschap] = noop
(11) [digest] = noop
(11) suffix: Checking for suffix after "@"
(11) suffix: No '@' in User-Name = "user001", looking up realm NULL
(11) suffix: No such realm "NULL"
(11) [suffix] = noop
(11) eap: Peer sent EAP Response (code 2) ID 1 length 6
(11) eap: No EAP Start, assuming it's an on-going EAP conversation
(11) [eap] = updated
(11) [files] = noop
rlm_ldap (ldap): Reserved connection (2)
(11) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(11) ldap: --> (uid=user001)
(11) ldap: Performing search in "dc=home" with filter "(uid=user001)",
scope "sub"
(11) ldap: Waiting for search result...
(11) ldap: User object found at DN "uid=user001,ou=test,dc=home"
(11) ldap: Processing user attributes
(11) ldap: control:Password-With-Header += 'Pass@word'
rlm_ldap (ldap): Released connection (2)
Need 4 more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (6), 1 of 26 pending slots used
rlm_ldap (ldap): Connecting to ldap://192.168.103.10:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
(11) [ldap] = updated
(11) [expiration] = noop
(11) [logintime] = noop
(11) pap: No {...} in Password-With-Header, re-writing to Cleartext-Password
(11) pap: Removing &control:Password-With-Header
(11) pap: WARNING: Auth-Type already set. Not setting to PAP
(11) [pap] = noop
(11) } # authorize = updated
(11) Found Auth-Type = eap
(11) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(11) authenticate {
(11) eap: Expiring EAP session with state 0xb09e5f13b09f5bda
(11) eap: Finished EAP session with state 0xb09e5f13b09f5bda
(11) eap: Previous EAP request found for state 0xb09e5f13b09f5bda,
released from the list
(11) eap: Peer sent packet with method EAP NAK (3)
(11) eap: Found mutually acceptable type PEAP (25)
(11) eap: Calling submodule eap_peap to process data
(11) eap_peap: Initiating new EAP-TLS session
(11) eap_peap: [eaptls start] = request
(11) eap: Sending EAP Request (code 1) ID 2 length 6
(11) eap: EAP session adding &reply:State = 0xb09e5f13b19c46da
(11) [eap] = handled
(11) } # authenticate = handled
(11) Using Post-Auth-Type Challenge
(11) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(11) Challenge { ... } # empty sub-section is ignored
(11) Sent Access-Challenge Id 1 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(11) EAP-Message = 0x010200061920
(11) Message-Authenticator = 0x00000000000000000000000000000000
(11) State = 0xb09e5f13b19c46dad63a05ea128e9a97
(11) Finished request
Waking up in 0.2 seconds.
(12) Received Access-Request Id 2 from 192.168.103.4:55548 to
192.168.103.2:1812 length 293
(12) User-Name = "user001"
(12) NAS-IP-Address = 127.0.0.1
(12) Calling-Station-Id = "02-00-00-00-00-01"
(12) Framed-MTU = 1400
(12) NAS-Port-Type = Wireless-802.11
(12) Connect-Info = "CONNECT 11Mbps 802.11b"
(12) EAP-Message =
0x020200a519800000009b16030100960100009203015b332b712476e6c7a625df7a5644d95a0f230a8d77233c34e18dccd5c1e2efa300004cc014c00a0039003800880087c00fc00500350084c013c00900330032009a009900450044c00ec004002f00960041c012c00800160013c00dc003000a0007c0
(12) State = 0xb09e5f13b19c46dad63a05ea128e9a97
(12) Message-Authenticator = 0x1d9a03ee094efc6d647b67bb550eee13
(12) session-state: No cached attributes
(12) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(12) authorize {
(12) policy filter_username {
(12) if (&User-Name) {
(12) if (&User-Name) -> TRUE
(12) if (&User-Name) {
(12) if (&User-Name =~ / /) {
(12) if (&User-Name =~ / /) -> FALSE
(12) if (&User-Name =~ /@[^@]*@/ ) {
(12) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(12) if (&User-Name =~ /\.\./ ) {
(12) if (&User-Name =~ /\.\./ ) -> FALSE
(12) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(12) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(12) if (&User-Name =~ /\.$/) {
(12) if (&User-Name =~ /\.$/) -> FALSE
(12) if (&User-Name =~ /(a)\./) {
(12) if (&User-Name =~ /(a)\./) -> FALSE
(12) } # if (&User-Name) = notfound
(12) } # policy filter_username = notfound
(12) [preprocess] = ok
(12) [chap] = noop
(12) [mschap] = noop
(12) [digest] = noop
(12) suffix: Checking for suffix after "@"
(12) suffix: No '@' in User-Name = "user001", looking up realm NULL
(12) suffix: No such realm "NULL"
(12) [suffix] = noop
(12) eap: Peer sent EAP Response (code 2) ID 2 length 165
(12) eap: Continuing tunnel setup
(12) [eap] = ok
(12) } # authorize = ok
(12) Found Auth-Type = eap
(12) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(12) authenticate {
(12) eap: Expiring EAP session with state 0xb09e5f13b19c46da
(12) eap: Finished EAP session with state 0xb09e5f13b19c46da
(12) eap: Previous EAP request found for state 0xb09e5f13b19c46da,
released from the list
(12) eap: Peer sent packet with method EAP PEAP (25)
(12) eap: Calling submodule eap_peap to process data
(12) eap_peap: Continuing EAP-TLS
(12) eap_peap: Peer indicated complete TLS record size will be 155 bytes
(12) eap_peap: Got complete TLS record (155 bytes)
(12) eap_peap: [eaptls verify] = length included
(12) eap_peap: (other): before/accept initialization
(12) eap_peap: TLS_accept: before/accept initialization
(12) eap_peap: <<< recv TLS 1.0 Handshake [length 0096], ClientHello
(12) eap_peap: TLS_accept: SSLv3 read client hello A
(12) eap_peap: >>> send TLS 1.0 Handshake [length 003e], ServerHello
(12) eap_peap: TLS_accept: SSLv3 write server hello A
(12) eap_peap: >>> send TLS 1.0 Handshake [length 08d3], Certificate
(12) eap_peap: TLS_accept: SSLv3 write certificate A
(12) eap_peap: >>> send TLS 1.0 Handshake [length 014b], ServerKeyExchange
(12) eap_peap: TLS_accept: SSLv3 write key exchange A
(12) eap_peap: >>> send TLS 1.0 Handshake [length 0004], ServerHelloDone
(12) eap_peap: TLS_accept: SSLv3 write server done A
(12) eap_peap: TLS_accept: SSLv3 flush data
(12) eap_peap: TLS_accept: Need to read more data: SSLv3 read client
certificate A
(12) eap_peap: TLS_accept: Need to read more data: SSLv3 read client
certificate A
(12) eap_peap: In SSL Handshake Phase
(12) eap_peap: In SSL Accept mode
(12) eap_peap: [eaptls process] = handled
(12) eap: Sending EAP Request (code 1) ID 3 length 1004
(12) eap: EAP session adding &reply:State = 0xb09e5f13b29d46da
(12) [eap] = handled
(12) } # authenticate = handled
(12) Using Post-Auth-Type Challenge
(12) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(12) Challenge { ... } # empty sub-section is ignored
(12) Sent Access-Challenge Id 2 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(12) EAP-Message =
0x010303ec19c000000a74160301003e0200003a03015b32acfc674cdf49e08c7da28c0d7d914ed6b90c98b12e8b612e916f445f2a4e00c014000012ff01000100000b000403000102000f00010116030108d30b0008cf0008cc0003de308203da308202c2a003020102020101300d06092a864886f70d01
(12) Message-Authenticator = 0x00000000000000000000000000000000
(12) State = 0xb09e5f13b29d46dad63a05ea128e9a97
(12) Finished request
Waking up in 0.2 seconds.
(13) Received Access-Request Id 3 from 192.168.103.4:55548 to
192.168.103.2:1812 length 134
(13) User-Name = "user001"
(13) NAS-IP-Address = 127.0.0.1
(13) Calling-Station-Id = "02-00-00-00-00-01"
(13) Framed-MTU = 1400
(13) NAS-Port-Type = Wireless-802.11
(13) Connect-Info = "CONNECT 11Mbps 802.11b"
(13) EAP-Message = 0x020300061900
(13) State = 0xb09e5f13b29d46dad63a05ea128e9a97
(13) Message-Authenticator = 0x6c7d31b819157bc05029cd376da843cc
(13) session-state: No cached attributes
(13) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(13) authorize {
(13) policy filter_username {
(13) if (&User-Name) {
(13) if (&User-Name) -> TRUE
(13) if (&User-Name) {
(13) if (&User-Name =~ / /) {
(13) if (&User-Name =~ / /) -> FALSE
(13) if (&User-Name =~ /@[^@]*@/ ) {
(13) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(13) if (&User-Name =~ /\.\./ ) {
(13) if (&User-Name =~ /\.\./ ) -> FALSE
(13) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(13) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(13) if (&User-Name =~ /\.$/) {
(13) if (&User-Name =~ /\.$/) -> FALSE
(13) if (&User-Name =~ /(a)\./) {
(13) if (&User-Name =~ /(a)\./) -> FALSE
(13) } # if (&User-Name) = notfound
(13) } # policy filter_username = notfound
(13) [preprocess] = ok
(13) [chap] = noop
(13) [mschap] = noop
(13) [digest] = noop
(13) suffix: Checking for suffix after "@"
(13) suffix: No '@' in User-Name = "user001", looking up realm NULL
(13) suffix: No such realm "NULL"
(13) [suffix] = noop
(13) eap: Peer sent EAP Response (code 2) ID 3 length 6
(13) eap: Continuing tunnel setup
(13) [eap] = ok
(13) } # authorize = ok
(13) Found Auth-Type = eap
(13) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(13) authenticate {
(13) eap: Expiring EAP session with state 0xb09e5f13b29d46da
(13) eap: Finished EAP session with state 0xb09e5f13b29d46da
(13) eap: Previous EAP request found for state 0xb09e5f13b29d46da,
released from the list
(13) eap: Peer sent packet with method EAP PEAP (25)
(13) eap: Calling submodule eap_peap to process data
(13) eap_peap: Continuing EAP-TLS
(13) eap_peap: Peer ACKed our handshake fragment
(13) eap_peap: [eaptls verify] = request
(13) eap_peap: [eaptls process] = handled
(13) eap: Sending EAP Request (code 1) ID 4 length 1000
(13) eap: EAP session adding &reply:State = 0xb09e5f13b39a46da
(13) [eap] = handled
(13) } # authenticate = handled
(13) Using Post-Auth-Type Challenge
(13) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(13) Challenge { ... } # empty sub-section is ignored
(13) Sent Access-Challenge Id 3 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(13) EAP-Message =
0x010403e81940d3231b0bfa48b450b8c89f0432a23a5ac5d3f6b7f19378f4901279ac237212a82650f14d833aed8e1adce602b8c6de097685d288edf92cdf406d49f25ef4d291c474d5c1a6ffbe64fae1ef6197d30004e8308204e4308203cca003020102020900c762d342c4805c0e300d06092a864886
(13) Message-Authenticator = 0x00000000000000000000000000000000
(13) State = 0xb09e5f13b39a46dad63a05ea128e9a97
(13) Finished request
Waking up in 0.2 seconds.
(14) Received Access-Request Id 4 from 192.168.103.4:55548 to
192.168.103.2:1812 length 134
(14) User-Name = "user001"
(14) NAS-IP-Address = 127.0.0.1
(14) Calling-Station-Id = "02-00-00-00-00-01"
(14) Framed-MTU = 1400
(14) NAS-Port-Type = Wireless-802.11
(14) Connect-Info = "CONNECT 11Mbps 802.11b"
(14) EAP-Message = 0x020400061900
(14) State = 0xb09e5f13b39a46dad63a05ea128e9a97
(14) Message-Authenticator = 0x5c1a6df3961ae0c425c59baf84cd046e
(14) session-state: No cached attributes
(14) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(14) authorize {
(14) policy filter_username {
(14) if (&User-Name) {
(14) if (&User-Name) -> TRUE
(14) if (&User-Name) {
(14) if (&User-Name =~ / /) {
(14) if (&User-Name =~ / /) -> FALSE
(14) if (&User-Name =~ /@[^@]*@/ ) {
(14) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(14) if (&User-Name =~ /\.\./ ) {
(14) if (&User-Name =~ /\.\./ ) -> FALSE
(14) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(14) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(14) if (&User-Name =~ /\.$/) {
(14) if (&User-Name =~ /\.$/) -> FALSE
(14) if (&User-Name =~ /(a)\./) {
(14) if (&User-Name =~ /(a)\./) -> FALSE
(14) } # if (&User-Name) = notfound
(14) } # policy filter_username = notfound
(14) [preprocess] = ok
(14) [chap] = noop
(14) [mschap] = noop
(14) [digest] = noop
(14) suffix: Checking for suffix after "@"
(14) suffix: No '@' in User-Name = "user001", looking up realm NULL
(14) suffix: No such realm "NULL"
(14) [suffix] = noop
(14) eap: Peer sent EAP Response (code 2) ID 4 length 6
(14) eap: Continuing tunnel setup
(14) [eap] = ok
(14) } # authorize = ok
(14) Found Auth-Type = eap
(14) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(14) authenticate {
(14) eap: Expiring EAP session with state 0xb09e5f13b39a46da
(14) eap: Finished EAP session with state 0xb09e5f13b39a46da
(14) eap: Previous EAP request found for state 0xb09e5f13b39a46da,
released from the list
(14) eap: Peer sent packet with method EAP PEAP (25)
(14) eap: Calling submodule eap_peap to process data
(14) eap_peap: Continuing EAP-TLS
(14) eap_peap: Peer ACKed our handshake fragment
(14) eap_peap: [eaptls verify] = request
(14) eap_peap: [eaptls process] = handled
(14) eap: Sending EAP Request (code 1) ID 5 length 694
(14) eap: EAP session adding &reply:State = 0xb09e5f13b49b46da
(14) [eap] = handled
(14) } # authenticate = handled
(14) Using Post-Auth-Type Challenge
(14) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(14) Challenge { ... } # empty sub-section is ignored
(14) Sent Access-Challenge Id 4 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(14) EAP-Message =
0x010502b61900130101ff040530030101ff30360603551d1f042f302d302ba029a0278625687474703a2f2f7777772e6578616d706c652e6f72672f6578616d706c655f63612e63726c300d06092a864886f70d0101050500038201010092d400531c09e1c44c689f11afbb4bc09bf6857fc4464ea15c59
(14) Message-Authenticator = 0x00000000000000000000000000000000
(14) State = 0xb09e5f13b49b46dad63a05ea128e9a97
(14) Finished request
Waking up in 0.2 seconds.
(15) Received Access-Request Id 5 from 192.168.103.4:55548 to
192.168.103.2:1812 length 272
(15) User-Name = "user001"
(15) NAS-IP-Address = 127.0.0.1
(15) Calling-Station-Id = "02-00-00-00-00-01"
(15) Framed-MTU = 1400
(15) NAS-Port-Type = Wireless-802.11
(15) Connect-Info = "CONNECT 11Mbps 802.11b"
(15) EAP-Message =
0x020500901980000000861603010046100000424104f00bdd46adeb6927a8f17dd7135e98f3488b717e5addab9989b7b6d583a161d8ce6df2d8e2340631443ca987572ebd98c3831eb6b1ed2d73ec362c3276aeeb2e1403010001011603010030c055f4c3cc048b2a43f9b28f9463eae395a66084de092b
(15) State = 0xb09e5f13b49b46dad63a05ea128e9a97
(15) Message-Authenticator = 0x9342a7c9c6451a195361aa6f8d0dc94b
(15) session-state: No cached attributes
(15) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(15) authorize {
(15) policy filter_username {
(15) if (&User-Name) {
(15) if (&User-Name) -> TRUE
(15) if (&User-Name) {
(15) if (&User-Name =~ / /) {
(15) if (&User-Name =~ / /) -> FALSE
(15) if (&User-Name =~ /@[^@]*@/ ) {
(15) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(15) if (&User-Name =~ /\.\./ ) {
(15) if (&User-Name =~ /\.\./ ) -> FALSE
(15) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(15) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(15) if (&User-Name =~ /\.$/) {
(15) if (&User-Name =~ /\.$/) -> FALSE
(15) if (&User-Name =~ /(a)\./) {
(15) if (&User-Name =~ /(a)\./) -> FALSE
(15) } # if (&User-Name) = notfound
(15) } # policy filter_username = notfound
(15) [preprocess] = ok
(15) [chap] = noop
(15) [mschap] = noop
(15) [digest] = noop
(15) suffix: Checking for suffix after "@"
(15) suffix: No '@' in User-Name = "user001", looking up realm NULL
(15) suffix: No such realm "NULL"
(15) [suffix] = noop
(15) eap: Peer sent EAP Response (code 2) ID 5 length 144
(15) eap: Continuing tunnel setup
(15) [eap] = ok
(15) } # authorize = ok
(15) Found Auth-Type = eap
(15) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(15) authenticate {
(15) eap: Expiring EAP session with state 0xb09e5f13b49b46da
(15) eap: Finished EAP session with state 0xb09e5f13b49b46da
(15) eap: Previous EAP request found for state 0xb09e5f13b49b46da,
released from the list
(15) eap: Peer sent packet with method EAP PEAP (25)
(15) eap: Calling submodule eap_peap to process data
(15) eap_peap: Continuing EAP-TLS
(15) eap_peap: Peer indicated complete TLS record size will be 134 bytes
(15) eap_peap: Got complete TLS record (134 bytes)
(15) eap_peap: [eaptls verify] = length included
(15) eap_peap: <<< recv TLS 1.0 Handshake [length 0046], ClientKeyExchange
(15) eap_peap: TLS_accept: SSLv3 read client key exchange A
(15) eap_peap: <<< recv TLS 1.0 ChangeCipherSpec [length 0001]
(15) eap_peap: <<< recv TLS 1.0 Handshake [length 0010], Finished
(15) eap_peap: TLS_accept: SSLv3 read finished A
(15) eap_peap: >>> send TLS 1.0 ChangeCipherSpec [length 0001]
(15) eap_peap: TLS_accept: SSLv3 write change cipher spec A
(15) eap_peap: >>> send TLS 1.0 Handshake [length 0010], Finished
(15) eap_peap: TLS_accept: SSLv3 write finished A
(15) eap_peap: TLS_accept: SSLv3 flush data
(15) eap_peap: (other): SSL negotiation finished successfully
(15) eap_peap: SSL Connection Established
(15) eap_peap: [eaptls process] = handled
(15) eap: Sending EAP Request (code 1) ID 6 length 65
(15) eap: EAP session adding &reply:State = 0xb09e5f13b59846da
(15) [eap] = handled
(15) } # authenticate = handled
(15) Using Post-Auth-Type Challenge
(15) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(15) Challenge { ... } # empty sub-section is ignored
(15) Sent Access-Challenge Id 5 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(15) EAP-Message =
0x01060041190014030100010116030100300fc7f80d490e6e1cb2842fe3260f0d2f39da6fb63644ce1be35dfe89d182049d8f336cc7c1b3225f34930db337c14be6
(15) Message-Authenticator = 0x00000000000000000000000000000000
(15) State = 0xb09e5f13b59846dad63a05ea128e9a97
(15) Finished request
Waking up in 0.2 seconds.
(16) Received Access-Request Id 6 from 192.168.103.4:55548 to
192.168.103.2:1812 length 134
(16) User-Name = "user001"
(16) NAS-IP-Address = 127.0.0.1
(16) Calling-Station-Id = "02-00-00-00-00-01"
(16) Framed-MTU = 1400
(16) NAS-Port-Type = Wireless-802.11
(16) Connect-Info = "CONNECT 11Mbps 802.11b"
(16) EAP-Message = 0x020600061900
(16) State = 0xb09e5f13b59846dad63a05ea128e9a97
(16) Message-Authenticator = 0xece74a0c54385df66f5f86aca47aeaf1
(16) session-state: No cached attributes
(16) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(16) authorize {
(16) policy filter_username {
(16) if (&User-Name) {
(16) if (&User-Name) -> TRUE
(16) if (&User-Name) {
(16) if (&User-Name =~ / /) {
(16) if (&User-Name =~ / /) -> FALSE
(16) if (&User-Name =~ /@[^@]*@/ ) {
(16) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(16) if (&User-Name =~ /\.\./ ) {
(16) if (&User-Name =~ /\.\./ ) -> FALSE
(16) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(16) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(16) if (&User-Name =~ /\.$/) {
(16) if (&User-Name =~ /\.$/) -> FALSE
(16) if (&User-Name =~ /(a)\./) {
(16) if (&User-Name =~ /(a)\./) -> FALSE
(16) } # if (&User-Name) = notfound
(16) } # policy filter_username = notfound
(16) [preprocess] = ok
(16) [chap] = noop
(16) [mschap] = noop
(16) [digest] = noop
(16) suffix: Checking for suffix after "@"
(16) suffix: No '@' in User-Name = "user001", looking up realm NULL
(16) suffix: No such realm "NULL"
(16) [suffix] = noop
(16) eap: Peer sent EAP Response (code 2) ID 6 length 6
(16) eap: Continuing tunnel setup
(16) [eap] = ok
(16) } # authorize = ok
(16) Found Auth-Type = eap
(16) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(16) authenticate {
(16) eap: Expiring EAP session with state 0xb09e5f13b59846da
(16) eap: Finished EAP session with state 0xb09e5f13b59846da
(16) eap: Previous EAP request found for state 0xb09e5f13b59846da,
released from the list
(16) eap: Peer sent packet with method EAP PEAP (25)
(16) eap: Calling submodule eap_peap to process data
(16) eap_peap: Continuing EAP-TLS
(16) eap_peap: Peer ACKed our handshake fragment. handshake is finished
(16) eap_peap: [eaptls verify] = success
(16) eap_peap: [eaptls process] = success
(16) eap_peap: Session established. Decoding tunneled attributes
(16) eap_peap: PEAP state TUNNEL ESTABLISHED
(16) eap: Sending EAP Request (code 1) ID 7 length 43
(16) eap: EAP session adding &reply:State = 0xb09e5f13b69946da
(16) [eap] = handled
(16) } # authenticate = handled
(16) Using Post-Auth-Type Challenge
(16) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(16) Challenge { ... } # empty sub-section is ignored
(16) Sent Access-Challenge Id 6 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(16) EAP-Message =
0x0107002b19001703010020d963fef29252de942d53a7854ea09fef83bcd1e956f973ecd66a02cae0d3224e
(16) Message-Authenticator = 0x00000000000000000000000000000000
(16) State = 0xb09e5f13b69946dad63a05ea128e9a97
(16) Finished request
Waking up in 0.2 seconds.
(17) Received Access-Request Id 7 from 192.168.103.4:55548 to
192.168.103.2:1812 length 208
(17) User-Name = "user001"
(17) NAS-IP-Address = 127.0.0.1
(17) Calling-Station-Id = "02-00-00-00-00-01"
(17) Framed-MTU = 1400
(17) NAS-Port-Type = Wireless-802.11
(17) Connect-Info = "CONNECT 11Mbps 802.11b"
(17) EAP-Message =
0x0207005019001703010020462bb66ea4ac9026c0c35a6b9e4f6a1458adf64862409256953d11d325aa52c51703010020c2f065c0021137ff119b7b8573bad0aec7f8e9c6981c77e19b6510f286c716ce
(17) State = 0xb09e5f13b69946dad63a05ea128e9a97
(17) Message-Authenticator = 0x1832f64b129b49b2aaef585c6e003614
(17) session-state: No cached attributes
(17) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(17) authorize {
(17) policy filter_username {
(17) if (&User-Name) {
(17) if (&User-Name) -> TRUE
(17) if (&User-Name) {
(17) if (&User-Name =~ / /) {
(17) if (&User-Name =~ / /) -> FALSE
(17) if (&User-Name =~ /@[^@]*@/ ) {
(17) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(17) if (&User-Name =~ /\.\./ ) {
(17) if (&User-Name =~ /\.\./ ) -> FALSE
(17) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(17) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(17) if (&User-Name =~ /\.$/) {
(17) if (&User-Name =~ /\.$/) -> FALSE
(17) if (&User-Name =~ /(a)\./) {
(17) if (&User-Name =~ /(a)\./) -> FALSE
(17) } # if (&User-Name) = notfound
(17) } # policy filter_username = notfound
(17) [preprocess] = ok
(17) [chap] = noop
(17) [mschap] = noop
(17) [digest] = noop
(17) suffix: Checking for suffix after "@"
(17) suffix: No '@' in User-Name = "user001", looking up realm NULL
(17) suffix: No such realm "NULL"
(17) [suffix] = noop
(17) eap: Peer sent EAP Response (code 2) ID 7 length 80
(17) eap: Continuing tunnel setup
(17) [eap] = ok
(17) } # authorize = ok
(17) Found Auth-Type = eap
(17) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(17) authenticate {
(17) eap: Expiring EAP session with state 0xb09e5f13b69946da
(17) eap: Finished EAP session with state 0xb09e5f13b69946da
(17) eap: Previous EAP request found for state 0xb09e5f13b69946da,
released from the list
(17) eap: Peer sent packet with method EAP PEAP (25)
(17) eap: Calling submodule eap_peap to process data
(17) eap_peap: Continuing EAP-TLS
(17) eap_peap: [eaptls verify] = ok
(17) eap_peap: Done initial handshake
(17) eap_peap: [eaptls process] = ok
(17) eap_peap: Session established. Decoding tunneled attributes
(17) eap_peap: PEAP state WAITING FOR INNER IDENTITY
(17) eap_peap: Identity - user001
(17) eap_peap: Got inner identity 'user001'
(17) eap_peap: Setting default EAP type for tunneled EAP session
(17) eap_peap: Got tunneled request
(17) eap_peap: EAP-Message = 0x0207000c0175736572303031
(17) eap_peap: Setting User-Name to user001
(17) eap_peap: Sending tunneled request to inner-tunnel
(17) eap_peap: EAP-Message = 0x0207000c0175736572303031
(17) eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(17) eap_peap: User-Name = "user001"
(17) Virtual server inner-tunnel received request
(17) EAP-Message = 0x0207000c0175736572303031
(17) FreeRADIUS-Proxied-To = 127.0.0.1
(17) User-Name = "user001"
(17) WARNING: Outer and inner identities are the same. User privacy
is compromised.
(17) server inner-tunnel {
(17) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(17) authorize {
(17) policy filter_username {
(17) if (&User-Name) {
(17) if (&User-Name) -> TRUE
(17) if (&User-Name) {
(17) if (&User-Name =~ / /) {
(17) if (&User-Name =~ / /) -> FALSE
(17) if (&User-Name =~ /@[^@]*@/ ) {
(17) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(17) if (&User-Name =~ /\.\./ ) {
(17) if (&User-Name =~ /\.\./ ) -> FALSE
(17) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(17) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(17) if (&User-Name =~ /\.$/) {
(17) if (&User-Name =~ /\.$/) -> FALSE
(17) if (&User-Name =~ /(a)\./) {
(17) if (&User-Name =~ /(a)\./) -> FALSE
(17) } # if (&User-Name) = notfound
(17) } # policy filter_username = notfound
(17) [chap] = noop
(17) [mschap] = noop
(17) suffix: Checking for suffix after "@"
(17) suffix: No '@' in User-Name = "user001", looking up realm NULL
(17) suffix: No such realm "NULL"
(17) [suffix] = noop
(17) update control {
(17) &Proxy-To-Realm := LOCAL
(17) } # update control = noop
(17) eap: Peer sent EAP Response (code 2) ID 7 length 12
(17) eap: EAP-Identity reply, returning 'ok' so we can short-circuit
the rest of authorize
(17) [eap] = ok
(17) } # authorize = ok
(17) Found Auth-Type = eap
(17) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(17) authenticate {
(17) eap: Peer sent packet with method EAP Identity (1)
(17) eap: Calling submodule eap_mschapv2 to process data
(17) eap_mschapv2: Issuing Challenge
(17) eap: Sending EAP Request (code 1) ID 8 length 43
(17) eap: EAP session adding &reply:State = 0xa0858e68a08d9427
(17) [eap] = handled
(17) } # authenticate = handled
(17) } # server inner-tunnel
(17) Virtual server sending reply
(17) EAP-Message =
0x0108002b1a0108002610285ffc4dd3c42977290efb22ee95fb19667265657261646975732d332e302e3137
(17) Message-Authenticator = 0x00000000000000000000000000000000
(17) State = 0xa0858e68a08d9427d9ffae98230c67f7
(17) eap_peap: Got tunneled reply code 11
(17) eap_peap: EAP-Message =
0x0108002b1a0108002610285ffc4dd3c42977290efb22ee95fb19667265657261646975732d332e302e3137
(17) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(17) eap_peap: State = 0xa0858e68a08d9427d9ffae98230c67f7
(17) eap_peap: Got tunneled reply RADIUS code 11
(17) eap_peap: EAP-Message =
0x0108002b1a0108002610285ffc4dd3c42977290efb22ee95fb19667265657261646975732d332e302e3137
(17) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(17) eap_peap: State = 0xa0858e68a08d9427d9ffae98230c67f7
(17) eap_peap: Got tunneled Access-Challenge
(17) eap: Sending EAP Request (code 1) ID 8 length 75
(17) eap: EAP session adding &reply:State = 0xb09e5f13b79646da
(17) [eap] = handled
(17) } # authenticate = handled
(17) Using Post-Auth-Type Challenge
(17) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(17) Challenge { ... } # empty sub-section is ignored
(17) Sent Access-Challenge Id 7 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(17) EAP-Message =
0x0108004b190017030100404b7b38e297a483e4bc6fbe4d5269ff1df96d038bb38ba7e88b5c0c76e58b492e70bd4b8a04f24fa8c0f4a449143e5f85e2c7d6ed884e9f54aee157e2c0aca9a4
(17) Message-Authenticator = 0x00000000000000000000000000000000
(17) State = 0xb09e5f13b79646dad63a05ea128e9a97
(17) Finished request
Waking up in 0.2 seconds.
(18) Received Access-Request Id 8 from 192.168.103.4:55548 to
192.168.103.2:1812 length 272
(18) User-Name = "user001"
(18) NAS-IP-Address = 127.0.0.1
(18) Calling-Station-Id = "02-00-00-00-00-01"
(18) Framed-MTU = 1400
(18) NAS-Port-Type = Wireless-802.11
(18) Connect-Info = "CONNECT 11Mbps 802.11b"
(18) EAP-Message =
0x020800901900170301002019aa35606f604db1818d001c7edff14e7bb9c0444c9ec8971010de14cdf58c2c17030100603322beb1b11abae87865f328154b21857d5e3dc7ae65e18e8a535931986862b557ad8ec588b069a3a5808b06c7d6c119f6ffedbc43fbe839c0437fd8c6c1d7e09ceb139ac141ab
(18) State = 0xb09e5f13b79646dad63a05ea128e9a97
(18) Message-Authenticator = 0xda76de704f613eaad6b01a2e3a65a0fc
(18) session-state: No cached attributes
(18) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(18) authorize {
(18) policy filter_username {
(18) if (&User-Name) {
(18) if (&User-Name) -> TRUE
(18) if (&User-Name) {
(18) if (&User-Name =~ / /) {
(18) if (&User-Name =~ / /) -> FALSE
(18) if (&User-Name =~ /@[^@]*@/ ) {
(18) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(18) if (&User-Name =~ /\.\./ ) {
(18) if (&User-Name =~ /\.\./ ) -> FALSE
(18) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(18) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(18) if (&User-Name =~ /\.$/) {
(18) if (&User-Name =~ /\.$/) -> FALSE
(18) if (&User-Name =~ /(a)\./) {
(18) if (&User-Name =~ /(a)\./) -> FALSE
(18) } # if (&User-Name) = notfound
(18) } # policy filter_username = notfound
(18) [preprocess] = ok
(18) [chap] = noop
(18) [mschap] = noop
(18) [digest] = noop
(18) suffix: Checking for suffix after "@"
(18) suffix: No '@' in User-Name = "user001", looking up realm NULL
(18) suffix: No such realm "NULL"
(18) [suffix] = noop
(18) eap: Peer sent EAP Response (code 2) ID 8 length 144
(18) eap: Continuing tunnel setup
(18) [eap] = ok
(18) } # authorize = ok
(18) Found Auth-Type = eap
(18) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(18) authenticate {
(18) eap: Expiring EAP session with state 0xa0858e68a08d9427
(18) eap: Finished EAP session with state 0xb09e5f13b79646da
(18) eap: Previous EAP request found for state 0xb09e5f13b79646da,
released from the list
(18) eap: Peer sent packet with method EAP PEAP (25)
(18) eap: Calling submodule eap_peap to process data
(18) eap_peap: Continuing EAP-TLS
(18) eap_peap: [eaptls verify] = ok
(18) eap_peap: Done initial handshake
(18) eap_peap: [eaptls process] = ok
(18) eap_peap: Session established. Decoding tunneled attributes
(18) eap_peap: PEAP state phase2
(18) eap_peap: EAP method MSCHAPv2 (26)
(18) eap_peap: Got tunneled request
(18) eap_peap: EAP-Message =
0x020800421a0208003d319ab058f06ae820a4864bb6c4c7d9e96100000000000000008a61710780a8f4e5efe100e37b236203a29f8d469c5e1db70075736572303031
(18) eap_peap: Setting User-Name to user001
(18) eap_peap: Sending tunneled request to inner-tunnel
(18) eap_peap: EAP-Message =
0x020800421a0208003d319ab058f06ae820a4864bb6c4c7d9e96100000000000000008a61710780a8f4e5efe100e37b236203a29f8d469c5e1db70075736572303031
(18) eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(18) eap_peap: User-Name = "user001"
(18) eap_peap: State = 0xa0858e68a08d9427d9ffae98230c67f7
(18) Virtual server inner-tunnel received request
(18) EAP-Message =
0x020800421a0208003d319ab058f06ae820a4864bb6c4c7d9e96100000000000000008a61710780a8f4e5efe100e37b236203a29f8d469c5e1db70075736572303031
(18) FreeRADIUS-Proxied-To = 127.0.0.1
(18) User-Name = "user001"
(18) State = 0xa0858e68a08d9427d9ffae98230c67f7
(18) WARNING: Outer and inner identities are the same. User privacy
is compromised.
(18) server inner-tunnel {
(18) session-state: No cached attributes
(18) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(18) authorize {
(18) policy filter_username {
(18) if (&User-Name) {
(18) if (&User-Name) -> TRUE
(18) if (&User-Name) {
(18) if (&User-Name =~ / /) {
(18) if (&User-Name =~ / /) -> FALSE
(18) if (&User-Name =~ /@[^@]*@/ ) {
(18) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(18) if (&User-Name =~ /\.\./ ) {
(18) if (&User-Name =~ /\.\./ ) -> FALSE
(18) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(18) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(18) if (&User-Name =~ /\.$/) {
(18) if (&User-Name =~ /\.$/) -> FALSE
(18) if (&User-Name =~ /(a)\./) {
(18) if (&User-Name =~ /(a)\./) -> FALSE
(18) } # if (&User-Name) = notfound
(18) } # policy filter_username = notfound
(18) [chap] = noop
(18) [mschap] = noop
(18) suffix: Checking for suffix after "@"
(18) suffix: No '@' in User-Name = "user001", looking up realm NULL
(18) suffix: No such realm "NULL"
(18) [suffix] = noop
(18) update control {
(18) &Proxy-To-Realm := LOCAL
(18) } # update control = noop
(18) eap: Peer sent EAP Response (code 2) ID 8 length 66
(18) eap: No EAP Start, assuming it's an on-going EAP conversation
(18) [eap] = updated
(18) [files] = noop
rlm_ldap (ldap): Reserved connection (3)
(18) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(18) ldap: --> (uid=user001)
(18) ldap: Performing search in "dc=home" with filter "(uid=user001)",
scope "sub"
(18) ldap: Waiting for search result...
(18) ldap: User object found at DN "uid=user001,ou=test,dc=home"
(18) ldap: Processing user attributes
(18) ldap: control:Password-With-Header += 'Pass@word'
rlm_ldap (ldap): Released connection (3)
(18) [ldap] = updated
(18) [expiration] = noop
(18) [logintime] = noop
(18) pap: No {...} in Password-With-Header, re-writing to Cleartext-Password
(18) pap: Removing &control:Password-With-Header
(18) pap: WARNING: Auth-Type already set. Not setting to PAP
(18) [pap] = noop
(18) } # authorize = updated
(18) Found Auth-Type = eap
(18) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(18) authenticate {
(18) eap: Expiring EAP session with state 0xa0858e68a08d9427
(18) eap: Finished EAP session with state 0xa0858e68a08d9427
(18) eap: Previous EAP request found for state 0xa0858e68a08d9427,
released from the list
(18) eap: Peer sent packet with method EAP MSCHAPv2 (26)
(18) eap: Calling submodule eap_mschapv2 to process data
(18) eap_mschapv2: # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(18) eap_mschapv2: authenticate {
(18) mschap: Found Cleartext-Password, hashing to create NT-Password
(18) mschap: Found Cleartext-Password, hashing to create LM-Password
(18) mschap: Creating challenge hash with username: user001
(18) mschap: Client is using MS-CHAPv2
(18) mschap: Adding MS-CHAPv2 MPPE keys
(18) [mschap] = ok
(18) } # authenticate = ok
(18) MSCHAP Success
(18) eap: Sending EAP Request (code 1) ID 9 length 51
(18) eap: EAP session adding &reply:State = 0xa0858e68a18c9427
(18) [eap] = handled
(18) } # authenticate = handled
(18) } # server inner-tunnel
(18) Virtual server sending reply
(18) EAP-Message =
0x010900331a0308002e533d33434145453538354230413246414543394246443837354545373032414641323238304443363134
(18) Message-Authenticator = 0x00000000000000000000000000000000
(18) State = 0xa0858e68a18c9427d9ffae98230c67f7
(18) eap_peap: Got tunneled reply code 11
(18) eap_peap: EAP-Message =
0x010900331a0308002e533d33434145453538354230413246414543394246443837354545373032414641323238304443363134
(18) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(18) eap_peap: State = 0xa0858e68a18c9427d9ffae98230c67f7
(18) eap_peap: Got tunneled reply RADIUS code 11
(18) eap_peap: EAP-Message =
0x010900331a0308002e533d33434145453538354230413246414543394246443837354545373032414641323238304443363134
(18) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(18) eap_peap: State = 0xa0858e68a18c9427d9ffae98230c67f7
(18) eap_peap: Got tunneled Access-Challenge
(18) eap: Sending EAP Request (code 1) ID 9 length 91
(18) eap: EAP session adding &reply:State = 0xb09e5f13b89746da
(18) [eap] = handled
(18) } # authenticate = handled
(18) Using Post-Auth-Type Challenge
(18) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(18) Challenge { ... } # empty sub-section is ignored
(18) Sent Access-Challenge Id 8 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(18) EAP-Message =
0x0109005b19001703010050b34770cb4cd71ef70c512c1d463aee83dbdbb1b4d41a82135aa8c006e78b637121160c4b4fcbc236c1ddc806e662b70dcc53870d082877ca2b6c88a6fce035c702d36c458a406ae6003757e65de44b10
(18) Message-Authenticator = 0x00000000000000000000000000000000
(18) State = 0xb09e5f13b89746dad63a05ea128e9a97
(18) Finished request
Waking up in 0.2 seconds.
(19) Received Access-Request Id 9 from 192.168.103.4:55548 to
192.168.103.2:1812 length 208
(19) User-Name = "user001"
(19) NAS-IP-Address = 127.0.0.1
(19) Calling-Station-Id = "02-00-00-00-00-01"
(19) Framed-MTU = 1400
(19) NAS-Port-Type = Wireless-802.11
(19) Connect-Info = "CONNECT 11Mbps 802.11b"
(19) EAP-Message =
0x0209005019001703010020a6ff938ffe471ed81f6cc80b903bfc6fbabc3d27dc685c3e572482516192d7ad170301002069f5245f02b8d05114f260200ec1bd58a86e3c1ba522742fcf10e04d36758845
(19) State = 0xb09e5f13b89746dad63a05ea128e9a97
(19) Message-Authenticator = 0x2942ab285c01a1f988c5b91a8571cf8b
(19) session-state: No cached attributes
(19) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(19) authorize {
(19) policy filter_username {
(19) if (&User-Name) {
(19) if (&User-Name) -> TRUE
(19) if (&User-Name) {
(19) if (&User-Name =~ / /) {
(19) if (&User-Name =~ / /) -> FALSE
(19) if (&User-Name =~ /@[^@]*@/ ) {
(19) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(19) if (&User-Name =~ /\.\./ ) {
(19) if (&User-Name =~ /\.\./ ) -> FALSE
(19) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(19) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(19) if (&User-Name =~ /\.$/) {
(19) if (&User-Name =~ /\.$/) -> FALSE
(19) if (&User-Name =~ /(a)\./) {
(19) if (&User-Name =~ /(a)\./) -> FALSE
(19) } # if (&User-Name) = notfound
(19) } # policy filter_username = notfound
(19) [preprocess] = ok
(19) [chap] = noop
(19) [mschap] = noop
(19) [digest] = noop
(19) suffix: Checking for suffix after "@"
(19) suffix: No '@' in User-Name = "user001", looking up realm NULL
(19) suffix: No such realm "NULL"
(19) [suffix] = noop
(19) eap: Peer sent EAP Response (code 2) ID 9 length 80
(19) eap: Continuing tunnel setup
(19) [eap] = ok
(19) } # authorize = ok
(19) Found Auth-Type = eap
(19) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(19) authenticate {
(19) eap: Expiring EAP session with state 0xa0858e68a18c9427
(19) eap: Finished EAP session with state 0xb09e5f13b89746da
(19) eap: Previous EAP request found for state 0xb09e5f13b89746da,
released from the list
(19) eap: Peer sent packet with method EAP PEAP (25)
(19) eap: Calling submodule eap_peap to process data
(19) eap_peap: Continuing EAP-TLS
(19) eap_peap: [eaptls verify] = ok
(19) eap_peap: Done initial handshake
(19) eap_peap: [eaptls process] = ok
(19) eap_peap: Session established. Decoding tunneled attributes
(19) eap_peap: PEAP state phase2
(19) eap_peap: EAP method MSCHAPv2 (26)
(19) eap_peap: Got tunneled request
(19) eap_peap: EAP-Message = 0x020900061a03
(19) eap_peap: Setting User-Name to user001
(19) eap_peap: Sending tunneled request to inner-tunnel
(19) eap_peap: EAP-Message = 0x020900061a03
(19) eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(19) eap_peap: User-Name = "user001"
(19) eap_peap: State = 0xa0858e68a18c9427d9ffae98230c67f7
(19) Virtual server inner-tunnel received request
(19) EAP-Message = 0x020900061a03
(19) FreeRADIUS-Proxied-To = 127.0.0.1
(19) User-Name = "user001"
(19) State = 0xa0858e68a18c9427d9ffae98230c67f7
(19) WARNING: Outer and inner identities are the same. User privacy
is compromised.
(19) server inner-tunnel {
(19) session-state: No cached attributes
(19) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(19) authorize {
(19) policy filter_username {
(19) if (&User-Name) {
(19) if (&User-Name) -> TRUE
(19) if (&User-Name) {
(19) if (&User-Name =~ / /) {
(19) if (&User-Name =~ / /) -> FALSE
(19) if (&User-Name =~ /@[^@]*@/ ) {
(19) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(19) if (&User-Name =~ /\.\./ ) {
(19) if (&User-Name =~ /\.\./ ) -> FALSE
(19) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(19) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(19) if (&User-Name =~ /\.$/) {
(19) if (&User-Name =~ /\.$/) -> FALSE
(19) if (&User-Name =~ /(a)\./) {
(19) if (&User-Name =~ /(a)\./) -> FALSE
(19) } # if (&User-Name) = notfound
(19) } # policy filter_username = notfound
(19) [chap] = noop
(19) [mschap] = noop
(19) suffix: Checking for suffix after "@"
(19) suffix: No '@' in User-Name = "user001", looking up realm NULL
(19) suffix: No such realm "NULL"
(19) [suffix] = noop
(19) update control {
(19) &Proxy-To-Realm := LOCAL
(19) } # update control = noop
(19) eap: Peer sent EAP Response (code 2) ID 9 length 6
(19) eap: No EAP Start, assuming it's an on-going EAP conversation
(19) [eap] = updated
(19) [files] = noop
rlm_ldap (ldap): Reserved connection (4)
(19) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(19) ldap: --> (uid=user001)
(19) ldap: Performing search in "dc=home" with filter "(uid=user001)",
scope "sub"
(19) ldap: Waiting for search result...
(19) ldap: User object found at DN "uid=user001,ou=test,dc=home"
(19) ldap: Processing user attributes
(19) ldap: control:Password-With-Header += 'Pass@word'
rlm_ldap (ldap): Released connection (4)
(19) [ldap] = updated
(19) [expiration] = noop
(19) [logintime] = noop
(19) pap: No {...} in Password-With-Header, re-writing to Cleartext-Password
(19) pap: Removing &control:Password-With-Header
(19) pap: WARNING: Auth-Type already set. Not setting to PAP
(19) [pap] = noop
(19) } # authorize = updated
(19) Found Auth-Type = eap
(19) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(19) authenticate {
(19) eap: Expiring EAP session with state 0xa0858e68a18c9427
(19) eap: Finished EAP session with state 0xa0858e68a18c9427
(19) eap: Previous EAP request found for state 0xa0858e68a18c9427,
released from the list
(19) eap: Peer sent packet with method EAP MSCHAPv2 (26)
(19) eap: Calling submodule eap_mschapv2 to process data
(19) eap: Sending EAP Success (code 3) ID 9 length 4
(19) eap: Freeing handler
(19) [eap] = ok
(19) } # authenticate = ok
(19) # Executing section post-auth from file
/usr/local/radius3017/etc/raddb/sites-enabled/inner-tunnel
(19) post-auth {
(19) if (0) {
(19) if (0) -> FALSE
(19) } # post-auth = noop
(19) Login OK: [user001] (from client all-network port 0 via TLS tunnel)
(19) } # server inner-tunnel
(19) Virtual server sending reply
(19) MS-MPPE-Encryption-Policy = Encryption-Allowed
(19) MS-MPPE-Encryption-Types = RC4-40or128-bit-Allowed
(19) MS-MPPE-Send-Key = 0x5898c7bc66b836e31c303e2b268f2f02
(19) MS-MPPE-Recv-Key = 0x788fc53da9e19e5d3283e333dcc57f7d
(19) EAP-Message = 0x03090004
(19) Message-Authenticator = 0x00000000000000000000000000000000
(19) User-Name = "user001"
(19) eap_peap: Got tunneled reply code 2
(19) eap_peap: MS-MPPE-Encryption-Policy = Encryption-Allowed
(19) eap_peap: MS-MPPE-Encryption-Types = RC4-40or128-bit-Allowed
(19) eap_peap: MS-MPPE-Send-Key = 0x5898c7bc66b836e31c303e2b268f2f02
(19) eap_peap: MS-MPPE-Recv-Key = 0x788fc53da9e19e5d3283e333dcc57f7d
(19) eap_peap: EAP-Message = 0x03090004
(19) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(19) eap_peap: User-Name = "user001"
(19) eap_peap: Got tunneled reply RADIUS code 2
(19) eap_peap: MS-MPPE-Encryption-Policy = Encryption-Allowed
(19) eap_peap: MS-MPPE-Encryption-Types = RC4-40or128-bit-Allowed
(19) eap_peap: MS-MPPE-Send-Key = 0x5898c7bc66b836e31c303e2b268f2f02
(19) eap_peap: MS-MPPE-Recv-Key = 0x788fc53da9e19e5d3283e333dcc57f7d
(19) eap_peap: EAP-Message = 0x03090004
(19) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(19) eap_peap: User-Name = "user001"
(19) eap_peap: Tunneled authentication was successful
(19) eap_peap: SUCCESS
(19) eap: Sending EAP Request (code 1) ID 10 length 43
(19) eap: EAP session adding &reply:State = 0xb09e5f13b99446da
(19) [eap] = handled
(19) } # authenticate = handled
(19) Using Post-Auth-Type Challenge
(19) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(19) Challenge { ... } # empty sub-section is ignored
(19) Sent Access-Challenge Id 9 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(19) EAP-Message =
0x010a002b1900170301002043bac2d89d42a9599889993ea1f1182c435771acf065d903822369bfef8b1131
(19) Message-Authenticator = 0x00000000000000000000000000000000
(19) State = 0xb09e5f13b99446dad63a05ea128e9a97
(19) Finished request
Waking up in 0.2 seconds.
(20) Received Access-Request Id 10 from 192.168.103.4:55548 to
192.168.103.2:1812 length 208
(20) User-Name = "user001"
(20) NAS-IP-Address = 127.0.0.1
(20) Calling-Station-Id = "02-00-00-00-00-01"
(20) Framed-MTU = 1400
(20) NAS-Port-Type = Wireless-802.11
(20) Connect-Info = "CONNECT 11Mbps 802.11b"
(20) EAP-Message =
0x020a005019001703010020fb506d031f3051e5306cd75d5c079ddad27fb1d82cdfb4c3368f5bbdcbd3e7031703010020f9514d556fbbf16c9b489b7b710b0c3d43930e86e0d4952319dedd8a986c56f0
(20) State = 0xb09e5f13b99446dad63a05ea128e9a97
(20) Message-Authenticator = 0xdd99c1d4930b6fa651e9357141d4a3e6
(20) session-state: No cached attributes
(20) # Executing section authorize from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(20) authorize {
(20) policy filter_username {
(20) if (&User-Name) {
(20) if (&User-Name) -> TRUE
(20) if (&User-Name) {
(20) if (&User-Name =~ / /) {
(20) if (&User-Name =~ / /) -> FALSE
(20) if (&User-Name =~ /@[^@]*@/ ) {
(20) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(20) if (&User-Name =~ /\.\./ ) {
(20) if (&User-Name =~ /\.\./ ) -> FALSE
(20) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(20) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(20) if (&User-Name =~ /\.$/) {
(20) if (&User-Name =~ /\.$/) -> FALSE
(20) if (&User-Name =~ /(a)\./) {
(20) if (&User-Name =~ /(a)\./) -> FALSE
(20) } # if (&User-Name) = notfound
(20) } # policy filter_username = notfound
(20) [preprocess] = ok
(20) [chap] = noop
(20) [mschap] = noop
(20) [digest] = noop
(20) suffix: Checking for suffix after "@"
(20) suffix: No '@' in User-Name = "user001", looking up realm NULL
(20) suffix: No such realm "NULL"
(20) [suffix] = noop
(20) eap: Peer sent EAP Response (code 2) ID 10 length 80
(20) eap: Continuing tunnel setup
(20) [eap] = ok
(20) } # authorize = ok
(20) Found Auth-Type = eap
(20) # Executing group from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(20) authenticate {
(20) eap: Expiring EAP session with state 0xb09e5f13b99446da
(20) eap: Finished EAP session with state 0xb09e5f13b99446da
(20) eap: Previous EAP request found for state 0xb09e5f13b99446da,
released from the list
(20) eap: Peer sent packet with method EAP PEAP (25)
(20) eap: Calling submodule eap_peap to process data
(20) eap_peap: Continuing EAP-TLS
(20) eap_peap: [eaptls verify] = ok
(20) eap_peap: Done initial handshake
(20) eap_peap: [eaptls process] = ok
(20) eap_peap: Session established. Decoding tunneled attributes
(20) eap_peap: PEAP state send tlv success
(20) eap_peap: Received EAP-TLV response
(20) eap_peap: Success
(20) eap: Sending EAP Success (code 3) ID 10 length 4
(20) eap: Freeing handler
(20) [eap] = ok
(20) } # authenticate = ok
(20) # Executing section post-auth from file
/usr/local/radius3017/etc/raddb/sites-enabled/default
(20) post-auth {
(20) update {
(20) No attributes updated
(20) } # update = noop
(20) [exec] = noop
(20) policy remove_reply_message_if_eap {
(20) if (&reply:EAP-Message && &reply:Reply-Message) {
(20) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(20) else {
(20) [noop] = noop
(20) } # else = noop
(20) } # policy remove_reply_message_if_eap = noop
(20) } # post-auth = noop
(20) Login OK: [user001] (from client all-network port 0 cli 02-00-00-00-00-01)
(20) Sent Access-Accept Id 10 from 192.168.103.2:1812 to
192.168.103.4:55548 length 0
(20) MS-MPPE-Recv-Key =
0xe1bde851c347ee67f1313da2032e61baf145aed58cb1ed25743c4cf05dd0c1ec
(20) MS-MPPE-Send-Key =
0x4b3fc3fc0e8634006434001a8d3e76ab79798d5c0eabe253e7bbb972899bef90
(20) EAP-Message = 0x030a0004
(20) Message-Authenticator = 0x00000000000000000000000000000000
(20) User-Name = "user001"
(20) Finished request
Waking up in 0.2 seconds.
(0) Cleaning up request packet ID 0 with timestamp +7
(1) Cleaning up request packet ID 1 with timestamp +7
(2) Cleaning up request packet ID 2 with timestamp +7
(3) Cleaning up request packet ID 3 with timestamp +7
(4) Cleaning up request packet ID 4 with timestamp +7
(5) Cleaning up request packet ID 5 with timestamp +7
(6) Cleaning up request packet ID 6 with timestamp +7
(7) Cleaning up request packet ID 7 with timestamp +7
(8) Cleaning up request packet ID 8 with timestamp +7
(9) Cleaning up request packet ID 9 with timestamp +7
Waking up in 4.6 seconds.
2
4
Hi all,
FreeRADIUS Version 3.0.15 here.
We have a working freeradius server acting as a proxy for our customers. All customers go through the same clients pool. Clients as intended in /etc/freeradius/clients.
For some new need we need to change the behavior of our server for a certain type of requests - an existing realm must now be processed locally by the server and not as a proxy -. I thought about implementing this through the use of virtual servers. It works well in our testing environment but it’s time to test it in production.
The way I understand virtual servers is that they must be « declared » under the client configuration in the /etc/freeradius/clients file.
The problem I am facing is that in doing so, I implement the change on all incoming authentication requests whereas I would have preferred to do so on a unique user just to be sure it would work in the production environment.
Anyone has an idea?
Thx
1
0
Freeradius PROXY: EAP-PEAP - TLS with NT-Password and Cleartext-Password
by Andrei Antonelli 29 Jun '18
by Andrei Antonelli 29 Jun '18
29 Jun '18
Hi, could someone help me with the example of my configuration below?
I have
*Client* <---> * Wireless Controller*: MYWLAN(802.1x EAP) <--->
*Freeradius.*
AAA Server setting in Controller with IP: 192.168.100.3 (my internal
freeradius)
Freeradius *Version 3.0.16 with Mysql*
*Two Freeradius servers: one HCRPP(internal) and CR(External)*
radcheck attribute is *NT-Password* (HCRPP) , and the user stored in the
database is without suffix.
*radcheck attribute is Cleartext-Password to (CR)*
*Freeradius HCRRP use EAP 802.1x and CR - PAP cleartext*
*What I need is when a user authenticates without suffix or with suffix
(@hcrpp.com <http://hcrpp.com>), use EAP-PEAP or TLS to authenticates in my
local freeradius and if the suffix was @cr.net <http://cr.net> proxy
to 126.100.20.3 with cleartext password.*
When i'm logging with username and password *without suffix*, *it's works*,
but when i'm logging with *suffix *like testuser(a)hcrpp.com or testuser@
cr.net i get this error message:
suffix: Checking for suffix after "@"
(22) suffix: Looking up realm "hcrpp.com" for User-Name = "testuser@
hcrpp.com"
(22) suffix: Found realm "hcrpp.com"
(22) suffix: Adding Realm = "hcrpp.com"
(22) suffix: Proxying request from user testuser(a)hcrpp.com to realm
hcrpp.com
(22) suffix: Preparing to proxy authentication request to realm "hcrpp.com"
(22) [suffix] = updated
(22) update control {
(22) &Proxy-To-Realm := "LOCAL"
(22) } # update control = noop
(22) eap: Peer sent EAP Response (code 2) ID 6 length 81
(22) eap: No EAP Start, assuming it's an on-going EAP conversation
(22) [eap] = updated
(22) sql: EXPAND %{User-Name}
(22) sql: --> testuser(a)hcrpp.com
(22) sql: SQL-User-Name set to 'testuser(a)hcrpp.com'
rlm_sql (sql): Reserved connection (19)
(22) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck
WHERE username = '%{SQL-User-Name}' ORDER BY id
(22) sql: --> SELECT id, username, attribute, value, op FROM radcheck
WHERE username = 'testuser(a)hcrpp.com' ORDER BY id
(22) sql: Executing select query: SELECT id, username, attribute, value, op
FROM radcheck WHERE username = 'testuser(a)hcrpp.com' ORDER BY id
(22) sql: EXPAND SELECT groupname FROM radusergroup WHERE username =
'%{SQL-User-Name}' ORDER BY priority
(22) sql: --> SELECT groupname FROM radusergroup WHERE username = '
testuser(a)hcrpp.com' ORDER BY priority
(22) sql: Executing select query: SELECT groupname FROM radusergroup WHERE
username = 'testuser(a)hcrpp.com' ORDER BY priority
(22) sql: User not found in any groups
rlm_sql (sql): Released connection (19)
(22) [sql] = notfound
(22) [pap] = noop
(22) } # authorize = updated
(22) Found Auth-Type = eap
(22) # Executing group from file
/usr/local/etc/raddb/sites-enabled/inner-tunnel
(22) authenticate {
(22) eap: Expiring EAP session with state 0xa05ae720a05cfdb8
(22) eap: Finished EAP session with state 0xa05ae720a05cfdb8
(22) eap: Previous EAP request found for state 0xa05ae720a05cfdb8, released
from the list
(22) eap: Peer sent packet with method EAP MSCHAPv2 (26)
(22) eap: Calling submodule eap_mschapv2 to process data
(22) eap_mschapv2: # Executing group from file
/usr/local/etc/raddb/sites-enabled/inner-tunnel
(22) eap_mschapv2: Auth-Type MS-CHAP {
*(22) mschap: WARNING: No Cleartext-Password configured. Cannot create
NT-Password*
*(22) mschap: WARNING: No Cleartext-Password configured. Cannot create
LM-Password*
(22) mschap: Creating challenge hash with username: dbarcelini(a)cirp.usp.br
(22) mschap: Client is using MS-CHAPv2
*(22) mschap: ERROR: FAILED: No NT/LM-Password. Cannot perform
authentication*
*(22) mschap: ERROR: MS-CHAP2-Response is incorrect*
*My config below*
*proxy.conf*
home_server HCRPP {
type = auth+acct
ipaddr = 192.168.100.3
port = 1821
secret = XXXX
require_message_authenticator = yes
response_window = 20
zombie_period = 40
status_check = status-server
check_interval = 30
num_answers_to_alive = 3
max_outstanding = 65536
}
home_server CR {
type = auth+acct
ipaddr = 126.100.20.3
port = 1812
secret = XXXX
}
home_server_pool HCRPPOOL {
type = fail-over
home_server = HCRPP
}
home_server_pool CRPOOL {
type = fail-over
home_server = CR
}
realm hcrpp.com {
auth_pool = HCRPPOOL
strip
}
realm cr.net {
auth_pool = CRPOOL
nostrip
}
------------------------------------------
*mods-enabled/eap*
eap {
default_eap_type = peap
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = ${max_requests}
md5 {
}
* ...*
ttls {
tls = tls-common
copy_request_to_tunnel = yes
use_tunneled_reply = yes
virtual_server = "inner-tunnel"
peap {
tls = tls-common
default_eap_type = mschapv2
copy_request_to_tunnel = yes
use_tunneled_reply = yes
proxy_tunneled_request_as_eap = no
virtual_server = "inner-tunnel"
*sites-enabled/default*
authorize {
preprocess
sql
eap {
ok = return
updated = return
}
suffix
*sites-enabled/inner-tunnel*
authorize {
suffix
update control {
&Proxy-To-Realm := "LOCAL"
}
eap {
ok = return
}
sql
Thanks
2
5
Hello,
I use FreeRADIUS 3.0.17 and i try to fix an issue when i try to store
the reply in Mysql.
I use with '%{pairs:&reply:[*]}' in my sql request but the debug tell me
that there is "Insufficient space to store pair string".
(18) Thu Jun 28 09:43:05 2018: ERROR: sql: Insufficient space to store
pair string, needed 2101 bytes have 2048 bytes
Can you tell me where in the code i can raise this value ?
Regards
Fabrice
--
Fabrice Durand
fdurand(a)inverse.ca :: +1.514.447.4918 (x135) :: www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence (http://packetfence.org)
3
3
28 Jun '18
Hello Dear,
I use freeradius 3 and daloradius to manage the user on SQL.
When I create manually the username and do a Password-Type in
Cleartext-Password, The Acces request match the good password.
When I create the users from Daloradius Batch User form, the Paswword-Type
is in User-Password, and no option to change it, then the Acces Request
doesn't match a good password.
It show PAP warning below :
.........................
..........................
(3) [sql] = ok
(3) [expiration] = noop
(3) [logintime] = noop
(3) pap: WARNING:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
(3) pap: WARNING: !!! Ignoring control:User-Password. Update your
!!!
(3) pap: WARNING: !!! configuration so that the "known good" clear text !!!
(3) pap: WARNING: !!! password is in Cleartext-Password and NOT in
!!!
(3) pap: WARNING: !!! User-Password.
!!!
(3) pap: WARNING:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
(3) pap: WARNING: No "known good" password found for the user. Not setting
Auth-Type
(3) pap: WARNING: Authentication will fail unless a "known good" password is
available
(3) [pap] = noop
(3) } # authorize = ok
(3) ERROR: No Auth-Type found: rejecting the user via Post-Auth-Type =
Reject
(3) Failed to authenticate the user
(3) Using Post-Auth-Type Reject
............................
..........................
Is this an issue on my freeradius seting ?
Can I change the password type in Cleartext-Password somewhere ?
How can I do to solve thie issues ?
jmlz
2
2
Hi,
we are using the post-proxy for putting the user in the their vlan.
Everything is working fine, if the realm looks like this
itmc
Tunnel-Private-Group-ID :=5,
Fall-Through = Yes
#
But we want to use
itmc.tu-dortmund.de as realm and
itmc.tu-dortmund.de
Tunnel-Private-Group-ID :=5,
Fall-Through = Yes
#
doesn't work.
Regards
Hans Bornemann
Abteilung Datanet
Technische Universität Dortmund
ITMC
Otto-Hahn-Str. 12
44227 Dortmund
Tel.: +49 231-755 2132
hans.bornemann(a)tu-dortmund.de
www.itmc.tu-dortmund.de
Wichtiger Hinweis: Die Information in dieser E-Mail ist vertraulich. Sie ist ausschließlich für den Adressaten bestimmt. Sollten Sie nicht der für diese E-Mail bestimmte Adressat sein, unterrichten Sie bitte den Absender und vernichten Sie diese Mail. Vielen Dank.
Unbeschadet der Korrespondenz per E-Mail, sind unsere Erklärungen ausschließlich final rechtsverbindlich, wenn sie in herkömmlicher Schriftform (mit eigenhändiger Unterschrift) oder durch Übermittlung eines solchen Schriftstücks per Telefax erfolgen.
Important note: The information included in this e-mail is confidential. It is solely intended for the recipient. If you are not the intended recipient of this e-mail please contact the sender and delete this message. Thank you. Without prejudice of e-mail correspondence, our statements are only legally binding when they are made in the conventional written form (with personal signature) or when such documents are sent by fax.
2
1
Hi,
I figured out why the server failed to respond..
I need to set "require-message-authenticator = no" for that particular
client IP address in the client.conf under /etc/freeradius on the server
side.
However, there are still heaps of other issues after this one was shot down.
Now it seems the password for the user cannot be passed to the radius
server correctly when ssh was executed.
After checking the /var/log/auth.log on the client machine, it has
following items (in bold face) which worries me:
Jun 25 16:23:15 dev-ldap-server sshd[25675]: pam_radius_auth: Got user name
micfox
Jun 25 16:23:15 dev-ldap-server sshd[25675]: pam_radius_auth: ignore
last_pass, force_prompt set
Jun 25 16:23:15 dev-ldap-server sshd[25672]: Postponed keyboard-interactive
for invalid user micfox from 127.0.0.1 port 37892 ssh2 [preauth]
Jun 25 16:23:19 dev-ldap-server sshd[25675]: pam_radius_auth: Sending
RADIUS request code 1
Jun 25 16:23:19 dev-ldap-server sshd[25675]: pam_radius_auth: DEBUG:
get_ipaddr(10.10.150.134) returned 0.
Jun 25 16:23:20 dev-ldap-server sshd[25675]: pam_radius_auth: Got RADIUS
response code 3
Jun 25 16:23:20 dev-ldap-server sshd[25675]: pam_radius_auth:
authentication failed
Jun 25 16:23:20 dev-ldap-server sshd[25675]: pam_radius_auth: Got user name
micfox
Jun 25 16:23:20 dev-ldap-server sshd[25675]: pam_radius_auth: ignore
last_pass, force_prompt set
*Jun 25 16:23:20 dev-ldap-server sshd[25675]: pam_radius_auth: Got password
#010#012#015INCOR*
Jun 25 16:23:20 dev-ldap-server sshd[25675]: pam_radius_auth: Sending
RADIUS request code 1
Jun 25 16:23:20 dev-ldap-server sshd[25675]: pam_radius_auth: DEBUG:
get_ipaddr(10.10.150.134) returned 0.
Jun 25 16:23:21 dev-ldap-server sshd[25675]: pam_radius_auth: Got RADIUS
response code 3
Jun 25 16:23:21 dev-ldap-server sshd[25675]: pam_radius_auth:
authentication failed
*"#010#012#015INCOR" *is definitely not the password the user "micfox" has
*.*
I run the freeradius in debug mode on the server side. As expected, the
authentication failed due to the incorrect password.
Ready to process requests.
rad_recv: Access-Request packet from host 10.10.150.136 port 52388, id=151,
length=91
User-Name = "micfox"
* User-Password = "\010\n\r\177INCOR"*
NAS-IP-Address = 10.10.150.136
NAS-Identifier = "sshd"
NAS-Port = 26140
NAS-Port-Type = Virtual
Service-Type = Authenticate-Only
Calling-Station-Id = "10.10.150.136"
# Executing section authorize from file /etc/freeradius/sites-enabled/
default
+group authorize {
++[preprocess] = ok
++[chap] = noop
++[mschap] = noop
++[digest] = noop
[suffix] No '@' in User-Name = "micfox", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] = noop
[eap] No EAP-Message, not doing EAP
++[eap] = noop
[sql] expand: %{User-Name} -> micfox
[sql] sql_set_user escaped user --> 'micfox'
rlm_sql (sql): Reserving sql socket id: 14
[sql] expand: SELECT id, username, attribute, value, op FROM
radcheck WHERE username = '%{SQL-User-Name}' ORDER BY
id -> SELECT id, username, attribute, value, op FROM
radcheck WHERE username = 'micfox' ORDER BY id
[sql] User found in radcheck table
[sql] expand: SELECT id, username, attribute, value, op FROM
radreply WHERE username = '%{SQL-User-Name}' ORDER BY
id -> SELECT id, username, attribute, value, op FROM
radreply WHERE username = 'micfox' ORDER BY id
[sql] expand: SELECT groupname FROM radusergroup
WHERE username = '%{SQL-User-Name}' ORDER BY priority -> SELECT
groupname FROM radusergroup WHERE username =
'micfox' ORDER BY priority
[sql] expand: SELECT id, groupname, attribute, Value,
op FROM radgroupcheck WHERE groupname =
'%{Sql-Group}' ORDER BY id -> SELECT id, groupname,
attribute, Value, op FROM radgroupcheck WHERE
groupname = 'test' ORDER BY id
[sql] User found in group test
[sql] expand: SELECT id, groupname, attribute, value,
op FROM radgroupreply WHERE groupname =
'%{Sql-Group}' ORDER BY id -> SELECT id, groupname,
attribute, value, op FROM radgroupreply WHERE
groupname = 'test' ORDER BY id
rlm_sql (sql): Released sql socket id: 14
++[sql] = ok
++[expiration] = noop
++[logintime] = noop
++[pap] = updated
+} # group authorize = updated
Found Auth-Type = PAP
# Executing group from file /etc/freeradius/sites-enabled/default
+group PAP {
*[pap] login attempt with password "? INCOR"*[pap] Using clear text
password "micfox001"
[pap] Passwords don't match
++[pap] = reject
+} # group PAP = reject
Failed to authenticate the user.
WARNING: Unprintable characters in the password. Double-check the shared
secret on the server and the NAS!
Using Post-Auth-Type Reject
# Executing group from file /etc/freeradius/sites-enabled/default
+group REJECT {
[sql] expand: %{User-Name} -> micfox
[sql] sql_set_user escaped user --> 'micfox'
[sql] expand: %{User-Password} -> =5C010=5Cn=5Cr=5C177INCOR
[sql] expand: INSERT INTO radpostauth
(username, pass, reply, authdate) VALUES
( '%{User-Name}',
'%{%{User-Password}:-%{Chap-Password}}',
'%{reply:Packet-Type}', '%S') -> INSERT INTO radpostauth
(username, pass, reply, authdate) VALUES
( 'micfox',
'=5C010=5Cn=5Cr=5C177INCOR', 'Access-Reject',
'2018-06-25 16:45:25')
rlm_sql (sql) in sql_postauth: query is INSERT INTO
radpostauth (username, pass, reply,
authdate) VALUES (
'micfox', '=5C010=5Cn=5Cr=5C177INCOR',
'Access-Reject', '2018-06-25 16:45:25')
rlm_sql (sql): Reserving sql socket id: 13
rlm_sql (sql): Released sql socket id: 13
++[sql] = ok
[eap] Request didn't contain an EAP-Message, not inserting EAP-Failure
++[eap] = noop
[attr_filter.access_reject] expand: %{User-Name} -> micfox
attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] = updated
+} # group REJECT = updated
Delaying reject of request 8 for 1 seconds
*=============*
I then check the code in pam_radius_auth.c for the shared library
paM_radius_auth.so. I wonder where the password was actually retrieved from
the conversation function of PAM session. That is the first question I
would like to ask.
However, it is not the end of the problems. I now edited the code in
pam_radius_auth.c to offer a hard-coded correct password for the user
,micfox (i.e., the correct password is "micfox001"). Then the user
authentication passes in both client and server side for this connection.
However, the user still cannot open the ssh session. On the client side,
the /var/user/auth.log shows the following error:
======================
Jun 25 16:45:29 dev-ldap-server sshd[26137]: pam_radius_auth: Got user name
micfox
Jun 25 16:45:29 dev-ldap-server sshd[26137]: pam_radius_auth: Sending
RADIUS request code 1
Jun 25 16:45:29 dev-ldap-server sshd[26137]: pam_radius_auth: DEBUG:
get_ipaddr(10.10.150.134) returned 0.
Jun 25 16:45:30 dev-ldap-server sshd[26137]: pam_radius_auth: Got RADIUS
response code 3
Jun 25 16:45:30 dev-ldap-server sshd[26137]: pam_radius_auth:
authentication failed
Jun 25 16:45:30 dev-ldap-server sshd[26137]: pam_radius_auth: Got user name
micfox
Jun 25 16:45:30 dev-ldap-server sshd[26137]: pam_radius_auth: ignore
last_pass, force_prompt set
Jun 25 16:45:30 dev-ldap-server sshd[26137]: pam_radius_auth: Got password
micfox001
Jun 25 16:45:30 dev-ldap-server sshd[26137]: pam_radius_auth: Sending
RADIUS request code 1
Jun 25 16:45:30 dev-ldap-server sshd[26137]: pam_radius_auth: DEBUG:
get_ipaddr(10.10.150.134) returned 0.
Jun 25 16:45:31 dev-ldap-server sshd[26137]: pam_radius_auth: Got RADIUS
response code 2
Jun 25 16:45:31 dev-ldap-server sshd[26137]: pam_radius_auth:
authentication succeeded
J*un 25 16:45:31 dev-ldap-server sshd[26137]: Failed password for invalid
user micfox from 10.10.150.136 port 33330 ssh2*
Jun 25 17:09:01 dev-ldap-server CRON[26274]: pam_unix(cron:session):
session opened for user root by (uid=0)
Jun 25 17:09:03 dev-ldap-server CRON[26274]: pam_unix(cron:session):
session closed for user root
================
I am totally lost for that bold-face message. even though the user
authentication passes, why is the "Failed password for invalid user" still
shows up???
Can ssh actually use pam_radius_auth.so for user authentication?? Please
advise how to fix it as I really do not have any clue now...
On Mon, Jun 25, 2018 at 2:56 PM, Hailun Tan <dearambermini(a)gmail.com> wrote:
> I am trying to perform the user authentication via freeradius server on
> the ssh conection.
>
> I have setup the free radius server according to the wiki pages:
>
> https://wiki.freeradius.org/guide/Getting-Started
>
>
> In addition, I managed to install the dolaradius to manage the free
> radius. I have run the radtest for the servers.
>
> The configurations for the radius server is:
> free radius server IP: 10.10.150.134
> free radius server port: 1812
> master secret: NOJA
> user name: micfox
> user password: micfox001
>
>
> On the client machine (client IP: 10.10.150.136), I run the following
> command:
>
> *dev-ldap-server: radtest micfox micfox001 10.10.150.134:1812
> <http://10.10.150.134:1812> 1812 NOJA*
> Sending Access-Request of id 5 to 10.10.150.134 port 1812
> User-Name = "micfox"
> User-Password = "micfox001"
> NAS-IP-Address = 10.10.150.136
> NAS-Port = 1812
> Message-Authenticator = 0x00000000000000000000000000000000
> rad_recv: Access-Accept packet from host 10.10.150.134 port 1812, id=5,
> length=38
> Service-Type = Framed-User
> Framed-Protocol = PPP
> Framed-Compression = Van-Jacobson-TCP-IP
>
> So it should prove the free radius server is up and running.
>
>
> However, I have configured to use the pam-freeradius-auth.so to hookup
> with the PAM modules on the client machine to authenticate the ssh user. it
> does not work. I have updated the /etc/pam.d/sshd as follows:
> ===========
>
>
> *auth sufficient pam_radius_auth.so debug skip_passwd*# PAM configuration
> for the Secure Shell service
>
> # Standard Un*x authentication.
> @include common-auth
>
> # Disallow non-root logins when /etc/nologin exists.
> account required pam_nologin.so
>
> # Uncomment and edit /etc/security/access.conf if you need to set complex
> # access limits that are hard to express in sshd_config.
> # account required pam_access.so
>
> # Standard Un*x authorization.
> @include common-account
>
> # SELinux needs to be the first session rule. This ensures that any
> # lingering context has been cleared. Without this it is possible that a
> # module could execute code in the wrong domain.
> session [success=ok ignore=ignore module_unknown=ignore
> default=bad] pam_selinux.so close
>
> # Set the loginuid process attribute.
> session required pam_loginuid.so
>
> # Create a new session keyring.
> session optional pam_keyinit.so force revoke
>
> # Standard Un*x session setup and teardown.
> @include common-session
>
> # Print the message of the day upon successful login.
> # This includes a dynamically generated part from /run/motd.dynamic
> # and a static (admin-editable) part from /etc/motd.
> session optional pam_motd.so motd=/run/motd.dynamic
> session optional pam_motd.so noupdate
>
> # Print the status of the user's mailbox upon successful login.
> session optional pam_mail.so standard noenv # [1]
>
> # Set up user limits from /etc/security/limits.conf.
> session required pam_limits.so
>
> # Read environment variables from /etc/environment and
> # /etc/security/pam_env.conf.
> session required pam_env.so # [1]
> # In Debian 4.0 (etch), locale-related environment variables were moved to
> # /etc/default/locale, so read that as well.
> session required pam_env.so user_readenv=1
> envfile=/etc/default/locale
>
> # SELinux needs to intervene at login time to ensure that the process
> starts
> # in the proper default security context. Only sessions which are intended
> # to run in the user's context should be run after this.
> session [success=ok ignore=ignore module_unknown=ignore
> default=bad] pam_selinux.so open
>
> # Standard Un*x password updating.
> @include common-password
>
>
> But now when I run the ssh micfox(a)10.10.150.136 (freeradius client's iP).
> the /var/log/auth.log has the following error messages:
>
>
> Jun 25 12:05:51 dev-ldap-server sshd[6441]: pam_radius_auth: Got user name
> micfox
> Jun 25 12:05:51 dev-ldap-server sshd[6441]: pam_radius_auth: ignore
> last_pass, force_prompt set
> Jun 25 12:05:51 dev-ldap-server sshd[6441]: pam_radius_auth: Sending
> RADIUS request code 1
> Jun 25 12:05:51 dev-ldap-server sshd[6441]: pam_radius_auth: DEBUG:
> get_ipaddr(10.10.150.134) is available. (1812)
> Jun 25 12:05:51 dev-ldap-server sshd[6441]: pam_radius_auth: DEBUG:
> talk_radius(0x86960a0a) is available (1812,port).
> Jun 25 12:05:51 dev-ldap-server sshd[6441]: pam_radius_auth: DEBUG:
> waiting for response from radius server 10.10.150.134 with port 1812
> (master secret: NOJA).
> *Jun 25 12:05:54 dev-ldap-server sshd[6441]: pam_radius_auth: RADIUS
> server 10.10.150.134 failed to respond*
> Jun 25 12:05:54 dev-ldap-server sshd[6441]: pam_radius_auth: All RADIUS
> servers failed to respond.
> Jun 25 12:05:54 dev-ldap-server sshd[6441]: pam_radius_auth:
> authentication failed
> Jun 25 12:05:54 dev-ldap-server sshd[6438]: Postponed keyboard-interactive
> for invalid user micfox from 127.0.0.1 port 37362 ssh2 [preauth]
>
>
>
> The RADIUS server always failed to respond..
>
> I have configured the /etc/pam_radius_auth.conf as follows:
>
>
>
> # pam_radius_auth configuration file. Copy to: /etc/raddb/server
> #
> # For proper security, this file SHOULD have permissions 0600,
> # that is readable by root, and NO ONE else. If anyone other than
> # root can read this file, then they can spoof responses from the server!
> #
> # There are 3 fields per line in this file. There may be multiple
> # lines. Blank lines or lines beginning with '#' are treated as
> # comments, and are ignored. The fields are:
> #
> # server[:port] secret [timeout]
> #
> # the port name or number is optional. The default port name is
> # "radius", and is looked up from /etc/services The timeout field is
> # optional. The default timeout is 3 seconds.
> #
> # If multiple RADIUS server lines exist, they are tried in order. The
> # first server to return success or failure causes the module to return
> # success or failure. Only if a server fails to response is it skipped,
> # and the next server in turn is used.
> #
> # The timeout field controls how many seconds the module waits before
> # deciding that the server has failed to respond.
> #
> # server[:port] shared_secret timeout (s)
> *10.10.150.134:1831 <http://10.10.150.134:1831> NOJA 3*
> #other-server other-secret 3
>
> #
> # having localhost in your radius configuration is a Good Thing.
> #
> # See the INSTALL file for pam.conf hints.
>
>
> I believed I should have setup everything correctly?? why is the
> radius-pam-auth.so not working with the error message,
>
> * RADIUS server 10.10.150.134 failed to respond??*
> I have prolonged the timeout parameter from 3 seconds to 60 seconds but it
> did not work.
>
> If the radius server is not correctly set, it should not even pass the
> radtest before. But why there is no response from the radius server for
> freeradius-pam-auth.so if the server does work?? what could go wrong from
> the configurations on the pam-radius module?
>
> Please advise
>
3
6
27 Jun '18
Hi guys
I am running freeradius ver 2.2.6.7 on CentOS 6.0. I have
configured freeradius with sql_counter module and all is working fine:
users are disconnected when they reached the time or traffic
assigned.
Now my goal is to implement CoA on freeradius in order to
update the Time (Session-Timeout) and Traffic (Mikrotik-Xmit-Limit)
attribute, every time the NAS server (Mikrotik) sends the interim update
packet, : how can I achieve that?
I add this inside the accounting
section of the file /ETC/SITE-AVAILABLE/DEFAULT
#COA
update coa {
User-Name = "%{User-Name}"
Acct-Session-Id = "%{Acct-Session-Id}"
NAS-IP-Address = "%{NAS-IP-Address}"
Framed-IP-Address =
"%{Framed-IP-Address}"
Session-Timeout = "%{Session-Timeout}"
}
update control {
Send-CoA-Request =
Yes
}
and this inside
CLIENTS.CONF:
client 0.0.0.0/0 {
secret =
xxxxxxx
require_message_authenticator = no
nastype =
other
}
#COA
home_server
piazzalaterale-coa {
type = coa
#
# Note
that a home server of type
"coa" MUST be a real NAS,
# with an ipaddr
or ipv6addr. It CANNOT point
to a virtual
# server.
#
ipaddr =
192.168.0.201
port = 3799
# This
secret SHOULD NOT be the same as the
shared
# secret in a "client"
section.
secret = xxxxxx
# CoA
specific parameters. See
raddb/proxy.conf for details.
coa {
irt = 2
mrt = 16
mrc = 5
mrd =
30
}
}
but when the CoA packet is sent to the
NAS the Session-Timeout attribute is set to 0 instead of to the residual
credit time of the user.
I need that because if two people log-in
simultaneosly with the same username, they should share the credit
time/traffic instead, without CoA, they will both have the same
credit
Sorry for my English....I hope to have been clear
Best regards
Con MyOpen hai Giga, SMS e i minuti che vuoi da 3€ al mese, per sempre. Cambi gratis quando e come vuoi e in più hai 10€ di credito omaggio!
SCOPRI DI PIU’ http://tisca.li/MailHPMobile
2
1
Hello,
I'm using freeradius 3.0.12 with rlm_ldap authentication.
I configured it as suggested in README:
authorize {
...
ldap
if ((ok || updated) && User-Password) {
update control {
Auth-Type := ldap
}
}
...
}
authenticate {
...
Auth-Type ldap {
ldap
}
...
}
I wonder what is the best practice for user permissions.
1. in users file :
DEFAULT Auth-Type := ldap, LDAP-Group == "reseau"
cisco-avpair :="shell:priv-lvl=15"
DEFAULT Auth-Type := Reject
OR
2. in post-auth section
if (LDAP-Group == "reseau") {
update reply {
cisco-avpair :="shell:priv-lvl=15"
}
}
else {
reject
}
Could someone give me an explanation of the best way to go ?
Best regards,
Sam
3
4