Freeradius-Users
Threads by month
- ----- 2026 -----
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 27049 discussions
RE:please help me :Failed binding to authentication address 192.168.1.102 port 1812
by Duong Manh Truong 22 Nov '11
by Duong Manh Truong 22 Nov '11
22 Nov '11
Be sure that u run just 1 process of FR at one time .
Just type "ps -A | grep radius" to see how many process of FR u are running
Hope that helps
Vào 12:06 Ngày 22 tháng 11 năm 2011, <
freeradius-users-request(a)lists.freeradius.org> đã viết:
> Send Freeradius-Users mailing list submissions to
> freeradius-users(a)lists.freeradius.org
>
> To subscribe or unsubscribe via the World Wide Web, visit
> http://lists.freeradius.org/mailman/listinfo/freeradius-users
> or, via email, send a message with subject or body 'help' to
> freeradius-users-request(a)lists.freeradius.org
>
> You can reach the person managing the list at
> freeradius-users-owner(a)lists.freeradius.org
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Freeradius-Users digest..."
>
>
> Today's Topics:
>
> 1. RE:please help me :Failed binding to authentication address
> 192.168.1.102 port 1812 (Harshavardhan Ch)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Mon, 21 Nov 2011 21:05:51 -0800
> From: Harshavardhan Ch <harshavardhan.ch(a)intelligraphics.com>
> Subject: RE:please help me :Failed binding to authentication address
> 192.168.1.102 port 1812
> To: freeradius-users(a)lists.freeradius.org
> Message-ID:
> <CAGFXDh0FRxe=hgLuX1gtE76rQJMpJ6_n_dwLH2MLz9XWD33MEw(a)mail.gmail.com
> >
> Content-Type: text/plain; charset="iso-8859-1"
>
> Hello sir,
> while activating the free radius server with eap
> authentication via vmware virtual machine i got error like "Failed
> binding to authentication address 192.168.1.102 port 1812"
> and i attched the output file.
>
1
0
I'm a newby to freeradius2 (from cistron), and I have it starting up,
and logging. However, it isn't attempting to load the "users" file.
I do not see any line in the radiusd.conf file which references "users".
I can remove the users file, and freeradius2 doesn't complain about it.
Please, what am I missing?
--
Jim Pazarena work:250 559-7777
Box 550 - 405 2nd Avenue fax: 866 279-3608
Queen Charlotte BC V0T 1S0 mailto:jim@paz.bz
3
3
So I'm moving from an old 1.1.3 (running on rhel5) to 2.1.10 (rhel6). We use EAP-TTLS > PAP which authenticates against openldap and
dynamically assigns vlans based on ldap group properties. I seem to have gotten the authentication working, but the vlan assignment
doesn't appear to be happening. All of our users end up in the default vlan (60). I'm getting a 'No "known good" password' error,
but the bind still seems to be succeeding. Output of radiusd -X is below.
FreeRADIUS Version 2.1.10, for host x86_64-redhat-linux-gnu, built on Mar 25 2011 at 10:54:38
Copyright (C) 1999-2009 The FreeRADIUS server project and contributors.
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE.
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License v2.
Starting - reading configuration files ...
including configuration file /etc/raddb/radiusd.conf
including configuration file /etc/raddb/proxy.conf
including configuration file /etc/raddb/clients.conf
including files in directory /etc/raddb/modules/
including configuration file /etc/raddb/modules/pap
including configuration file /etc/raddb/modules/pap.rpmsave
including configuration file /etc/raddb/modules/inner-eap
including configuration file /etc/raddb/modules/detail.log
including configuration file /etc/raddb/modules/logintime
including configuration file /etc/raddb/modules/exec
including configuration file /etc/raddb/modules/smbpasswd
including configuration file /etc/raddb/modules/detail
including configuration file /etc/raddb/modules/mschap
including configuration file /etc/raddb/modules/otp
including configuration file /etc/raddb/modules/dynamic_clients
including configuration file /etc/raddb/modules/linelog
including configuration file /etc/raddb/modules/preprocess
including configuration file /etc/raddb/modules/policy
including configuration file /etc/raddb/modules/checkval
including configuration file /etc/raddb/modules/pam
including configuration file /etc/raddb/modules/detail.example.com
including configuration file /etc/raddb/modules/ntlm_auth
including configuration file /etc/raddb/modules/files
including configuration file /etc/raddb/modules/echo
including configuration file /etc/raddb/modules/sradutmp
including configuration file /etc/raddb/modules/sqlcounter_expire_on_login
including configuration file /etc/raddb/modules/smsotp
including configuration file /etc/raddb/modules/etc_group
including configuration file /etc/raddb/modules/chap
including configuration file /etc/raddb/modules/attr_rewrite
including configuration file /etc/raddb/modules/mac2ip
including configuration file /etc/raddb/modules/opendirectory
including configuration file /etc/raddb/modules/unix
including configuration file /etc/raddb/modules/wimax
including configuration file /etc/raddb/modules/digest
including configuration file /etc/raddb/modules/ldap
including configuration file /etc/raddb/modules/realm
including configuration file /etc/raddb/modules/expr
including configuration file /etc/raddb/modules/passwd
including configuration file /etc/raddb/modules/perl
including configuration file /etc/raddb/modules/ippool
including configuration file /etc/raddb/modules/mac2vlan
including configuration file /etc/raddb/modules/cui
including configuration file /etc/raddb/modules/radutmp
including configuration file /etc/raddb/modules/sql_log
including configuration file /etc/raddb/modules/attr_filter
including configuration file /etc/raddb/modules/always
including configuration file /etc/raddb/modules/expiration
including configuration file /etc/raddb/modules/counter
including configuration file /etc/raddb/modules/acct_unique
including configuration file /etc/raddb/eap.conf
including configuration file /etc/raddb/policy.conf
including files in directory /etc/raddb/sites-enabled/
including configuration file /etc/raddb/sites-enabled/inner-tunnel
including configuration file /etc/raddb/sites-enabled/control-socket
including configuration file /etc/raddb/sites-enabled/default
main {
user = "radiusd"
group = "radiusd"
allow_core_dumps = no
}
including dictionary file /etc/raddb/dictionary
main {
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/radius"
libdir = "/usr/lib64/freeradius"
radacctdir = "/var/log/radius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 1024
pidfile = "/var/run/radiusd/radiusd.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
}
security {
max_attributes = 200
reject_delay = 1
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = "testsecret"
response_window = 20
max_outstanding = 65536
require_message_authenticator = yes
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
num_answers_to_alive = 3
num_pings_to_alive = 3
revive_interval = 120
status_check_timeout = 4
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client DOMAIN-WLC1 {
ipaddr = 10.5.11.5
require_message_authenticator = no
secret = "testsecret"
nastype = "cisco"
}
client DOMAIN-WLC2 {
ipaddr = 10.5.11.6
require_message_authenticator = no
secret = "testsecret"
nastype = "cisco"
}
client bartleby {
ipaddr = 10.30.2.59
require_message_authenticator = no
secret = "testsecret"
nastype = "other"
}
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = "testsecret"
nastype = "other"
}
radiusd: #### Instantiating modules ####
instantiate {
Module: Linked to module rlm_exec
Module: Instantiating module "exec" from file /etc/raddb/modules/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
}
Module: Linked to module rlm_expr
Module: Instantiating module "expr" from file /etc/raddb/modules/expr
Module: Linked to module rlm_expiration
Module: Instantiating module "expiration" from file /etc/raddb/modules/expiration
expiration {
reply-message = "Password Has Expired "
}
Module: Linked to module rlm_logintime
Module: Instantiating module "logintime" from file /etc/raddb/modules/logintime
logintime {
reply-message = "You are calling outside your allowed timespan "
minimum-timeout = 60
}
}
radiusd: #### Loading Virtual Servers ####
server inner-tunnel { # from file /etc/raddb/sites-enabled/inner-tunnel
modules {
Module: Checking authenticate {...} for more modules to load
Module: Linked to module rlm_pap
Module: Instantiating module "pap" from file /etc/raddb/modules/pap
pap {
encryption_scheme = "auto"
auto_header = no
}
Module: Linked to module rlm_chap
Module: Instantiating module "chap" from file /etc/raddb/modules/chap
Module: Linked to module rlm_mschap
Module: Instantiating module "mschap" from file /etc/raddb/modules/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = no
}
Module: Linked to module rlm_unix
Module: Instantiating module "unix" from file /etc/raddb/modules/unix
unix {
radwtmp = "/var/log/radius/radwtmp"
}
Module: Linked to module rlm_ldap
Module: Instantiating module "ldap" from file /etc/raddb/modules/ldap
ldap {
server = "ldap1.domain.edu"
port = 389
password = ""
identity = ""
net_timeout = 1
timeout = 4
timelimit = 3
tls_mode = no
start_tls = no
tls_require_cert = "allow"
tls {
start_tls = no
require_cert = "allow"
}
basedn = "dc=domain,dc=edu"
filter = "(uid=%u)"
base_filter = "(objectclass=personSR)"
password_attribute = "userPassword"
auto_header = no
access_attr = "uid"
access_attr_used_for_allow = yes
groupname_attribute = "groupSR"
groupmembership_filter = "(&(objectClass=personSR)(uid=%{User-Name}))"
groupmembership_attribute = "groupSR"
dictionary_mapping = "/etc/raddb/ldap.attrmap"
ldap_debug = 0
ldap_connections_number = 5
compare_check_items = no
do_xlat = yes
set_auth_type = yes
}
rlm_ldap: Registering ldap_groupcmp for Ldap-Group
rlm_ldap: Registering ldap_xlat with xlat_name ldap
rlm_ldap: reading ldap<->radius mappings from file /etc/raddb/ldap.attrmap
rlm_ldap: LDAP userPassword mapped to RADIUS User-Password
rlm_ldap: LDAP radiusCheckItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusReplyItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusAuthType mapped to RADIUS Auth-Type
rlm_ldap: LDAP radiusSimultaneousUse mapped to RADIUS Simultaneous-Use
rlm_ldap: LDAP radiusCalledStationId mapped to RADIUS Called-Station-Id
rlm_ldap: LDAP radiusCallingStationId mapped to RADIUS Calling-Station-Id
rlm_ldap: LDAP lmPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP ntPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP sambaLmPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP sambaNtPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP dBCSPwd mapped to RADIUS LM-Password
rlm_ldap: LDAP userPassword mapped to RADIUS Password-With-Header
rlm_ldap: LDAP acctFlags mapped to RADIUS SMB-Account-CTRL-TEXT
rlm_ldap: LDAP radiusExpiration mapped to RADIUS Expiration
rlm_ldap: LDAP radiusNASIpAddress mapped to RADIUS NAS-IP-Address
rlm_ldap: LDAP radiusServiceType mapped to RADIUS Service-Type
rlm_ldap: LDAP radiusFramedProtocol mapped to RADIUS Framed-Protocol
rlm_ldap: LDAP radiusFramedIPAddress mapped to RADIUS Framed-IP-Address
rlm_ldap: LDAP radiusFramedIPNetmask mapped to RADIUS Framed-IP-Netmask
rlm_ldap: LDAP radiusFramedRoute mapped to RADIUS Framed-Route
rlm_ldap: LDAP radiusFramedRouting mapped to RADIUS Framed-Routing
rlm_ldap: LDAP radiusFilterId mapped to RADIUS Filter-Id
rlm_ldap: LDAP radiusFramedMTU mapped to RADIUS Framed-MTU
rlm_ldap: LDAP radiusFramedCompression mapped to RADIUS Framed-Compression
rlm_ldap: LDAP radiusLoginIPHost mapped to RADIUS Login-IP-Host
rlm_ldap: LDAP radiusLoginService mapped to RADIUS Login-Service
rlm_ldap: LDAP radiusLoginTCPPort mapped to RADIUS Login-TCP-Port
rlm_ldap: LDAP radiusCallbackNumber mapped to RADIUS Callback-Number
rlm_ldap: LDAP radiusCallbackId mapped to RADIUS Callback-Id
rlm_ldap: LDAP radiusFramedIPXNetwork mapped to RADIUS Framed-IPX-Network
rlm_ldap: LDAP radiusClass mapped to RADIUS Class
rlm_ldap: LDAP radiusSessionTimeout mapped to RADIUS Session-Timeout
rlm_ldap: LDAP radiusIdleTimeout mapped to RADIUS Idle-Timeout
rlm_ldap: LDAP radiusTerminationAction mapped to RADIUS Termination-Action
rlm_ldap: LDAP radiusLoginLATService mapped to RADIUS Login-LAT-Service
rlm_ldap: LDAP radiusLoginLATNode mapped to RADIUS Login-LAT-Node
rlm_ldap: LDAP radiusLoginLATGroup mapped to RADIUS Login-LAT-Group
rlm_ldap: LDAP radiusFramedAppleTalkLink mapped to RADIUS Framed-AppleTalk-Link
rlm_ldap: LDAP radiusFramedAppleTalkNetwork mapped to RADIUS Framed-AppleTalk-Network
rlm_ldap: LDAP radiusFramedAppleTalkZone mapped to RADIUS Framed-AppleTalk-Zone
rlm_ldap: LDAP radiusPortLimit mapped to RADIUS Port-Limit
rlm_ldap: LDAP radiusLoginLATPort mapped to RADIUS Login-LAT-Port
rlm_ldap: LDAP radiusReplyMessage mapped to RADIUS Reply-Message
conns: 0x7f62718804e0
Module: Linked to module rlm_eap
Module: Instantiating module "eap" from file /etc/raddb/eap.conf
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 4096
}
Module: Linked to sub-module rlm_eap_md5
Module: Instantiating eap-md5
Module: Linked to sub-module rlm_eap_leap
Module: Instantiating eap-leap
Module: Linked to sub-module rlm_eap_gtc
Module: Instantiating eap-gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
Module: Linked to sub-module rlm_eap_tls
Module: Instantiating eap-tls
tls {
rsa_key_exchange = no
dh_key_exchange = yes
rsa_key_length = 512
dh_key_length = 512
verify_depth = 0
CA_path = "/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/etc/raddb/certs/wildcard.pem"
certificate_file = "/etc/raddb/certs/wildcard.pem"
CA_file = "/etc/raddb/certs/wildcardca.pem"
dh_file = "/etc/raddb/certs/dh"
random_file = "/etc/raddb/certs/random"
fragment_size = 1024
include_length = yes
check_crl = no
cipher_list = "DEFAULT"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
}
}
Module: Linked to sub-module rlm_eap_ttls
Module: Instantiating eap-ttls
ttls {
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
}
Module: Linked to sub-module rlm_eap_peap
Module: Instantiating eap-peap
peap {
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
}
Module: Linked to sub-module rlm_eap_mschapv2
Module: Instantiating eap-mschapv2
mschapv2 {
with_ntdomain_hack = no
}
Module: Checking authorize {...} for more modules to load
Module: Linked to module rlm_realm
Module: Instantiating module "suffix" from file /etc/raddb/modules/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
Module: Linked to module rlm_files
Module: Instantiating module "files" from file /etc/raddb/modules/files
files {
usersfile = "/etc/raddb/users"
acctusersfile = "/etc/raddb/acct_users"
preproxy_usersfile = "/etc/raddb/preproxy_users"
compat = "no"
}
Module: Checking session {...} for more modules to load
Module: Linked to module rlm_radutmp
Module: Instantiating module "radutmp" from file /etc/raddb/modules/radutmp
radutmp {
filename = "/var/log/radius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
perm = 384
callerid = yes
}
Module: Checking post-proxy {...} for more modules to load
Module: Checking post-auth {...} for more modules to load
Module: Linked to module rlm_attr_filter
Module: Instantiating module "attr_filter.access_reject" from file /etc/raddb/modules/attr_filter
attr_filter attr_filter.access_reject {
attrsfile = "/etc/raddb/attrs.access_reject"
key = "%{User-Name}"
}
} # modules
} # server
server { # from file /etc/raddb/radiusd.conf
modules {
Module: Checking authenticate {...} for more modules to load
Module: Linked to module rlm_digest
Module: Instantiating module "digest" from file /etc/raddb/modules/digest
Module: Checking authorize {...} for more modules to load
Module: Linked to module rlm_preprocess
Module: Instantiating module "preprocess" from file /etc/raddb/modules/preprocess
preprocess {
huntgroups = "/etc/raddb/huntgroups"
hints = "/etc/raddb/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
Module: Checking preacct {...} for more modules to load
Module: Linked to module rlm_acct_unique
Module: Instantiating module "acct_unique" from file /etc/raddb/modules/acct_unique
acct_unique {
key = "User-Name, Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port"
}
Module: Checking accounting {...} for more modules to load
Module: Linked to module rlm_detail
Module: Instantiating module "detail" from file /etc/raddb/modules/detail
detail {
detailfile = "/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d"
header = "%t"
detailperm = 384
dirperm = 493
locking = no
log_packet_header = no
}
Module: Instantiating module "attr_filter.accounting_response" from file /etc/raddb/modules/attr_filter
attr_filter attr_filter.accounting_response {
attrsfile = "/etc/raddb/attrs.accounting_response"
key = "%{User-Name}"
}
Module: Checking session {...} for more modules to load
Module: Checking post-proxy {...} for more modules to load
Module: Checking post-auth {...} for more modules to load
} # modules
} # server
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *
port = 0
}
listen {
type = "acct"
ipaddr = *
port = 0
}
listen {
type = "control"
listen {
socket = "/var/run/radiusd/radiusd.sock"
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on authentication address * port 1812
Listening on accounting address * port 1813
Listening on command file /var/run/radiusd/radiusd.sock
Listening on authentication address 127.0.0.1 port 18120 as server inner-tunnel
Listening on proxy address * port 1814
Ready to process requests.
rad_recv: Access-Request packet from host 10.5.11.6 port 32768, id=196, length=222
User-Name = "testuser"
Calling-Station-Id = "40-fc-89-f1-a9-c2"
Called-Station-Id = "00-1f-6c-a9-85-d0:its-test"
NAS-Port = 29
Cisco-AVPair = "audit-session-id=0a050b0600013b924eca67ab"
NAS-IP-Address = 10.5.11.6
NAS-Identifier = "DOMAIN-WLC2"
Airespace-Wlan-Id = 3
Service-Type = Framed-User
Framed-MTU = 1300
NAS-Port-Type = Wireless-802.11
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "60"
EAP-Message = 0x020100090174737475
Message-Authenticator = 0xb9df6207236d61485cc6e3ec6f854285
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 1 length 9
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (uid=%u) -> (uid=testuser)
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] attempting LDAP reconnection
[ldap] (re)connect to ldap1.domain.edu:389, authentication 0
[ldap] bind as / to ldap1.domain.edu:389
[ldap] waiting for bind result ...
[ldap] Bind was successful
[ldap] performing search in dc=domain,dc=edu, with filter (uid=testuser)
[ldap] ldap_release_conn: Release Id: 0
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] users: Matched entry DEFAULT at line 244
++[files] returns ok
[ldap] performing user authorization for testuser
[ldap] expand: (uid=%u) -> (uid=testuser)
[ldap] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (uid=testuser)
[ldap] checking if remote access for testuser is allowed by uid
[ldap] looking for check items in directory...
[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP. Are you sure that the user is configured correctly?
[ldap] user testuser authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user. Authentication may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type md5
rlm_eap_md5: Issuing Challenge
++[eap] returns handled
Sending Access-Challenge of id 196 to 10.5.11.6 port 32768
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "360"
EAP-Message = 0x010200160410d42afb9857f9eb60d2a963f11b6f02a6
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x0a0be8430a09ec3409af9106d0fa8ef1
Finished request 0.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 10.5.11.6 port 32768, id=197, length=237
User-Name = "testuser"
Calling-Station-Id = "40-fc-89-f1-a9-c2"
Called-Station-Id = "00-1f-6c-a9-85-d0:its-test"
NAS-Port = 29
Cisco-AVPair = "audit-session-id=0a050b0600013b924eca67ab"
NAS-IP-Address = 10.5.11.6
NAS-Identifier = "DOMAIN-WLC2"
Airespace-Wlan-Id = 3
Service-Type = Framed-User
Framed-MTU = 1300
NAS-Port-Type = Wireless-802.11
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "60"
EAP-Message = 0x020200060315
State = 0x0a0be8430a09ec3409af9106d0fa8ef1
Message-Authenticator = 0xc891b270527a9a333810bd7328d251e7
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 2 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (uid=%u) -> (uid=testuser)
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (uid=testuser)
[ldap] ldap_release_conn: Release Id: 0
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] users: Matched entry DEFAULT at line 244
++[files] returns ok
[ldap] performing user authorization for testuser
[ldap] expand: (uid=%u) -> (uid=testuser)
[ldap] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (uid=testuser)
[ldap] checking if remote access for testuser is allowed by uid
[ldap] looking for check items in directory...
[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP. Are you sure that the user is configured correctly?
[ldap] user testuser authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user. Authentication may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP NAK
[eap] EAP-NAK asked for EAP-Type/ttls
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 197 to 10.5.11.6 port 32768
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "360"
EAP-Message = 0x010300061520
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x0a0be8430b08fd3409af9106d0fa8ef1
Finished request 1.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 10.5.11.6 port 32768, id=198, length=427
User-Name = "testuser"
Calling-Station-Id = "40-fc-89-f1-a9-c2"
Called-Station-Id = "00-1f-6c-a9-85-d0:its-test"
NAS-Port = 29
Cisco-AVPair = "audit-session-id=0a050b0600013b924eca67ab"
NAS-IP-Address = 10.5.11.6
NAS-Identifier = "DOMAIN-WLC2"
Airespace-Wlan-Id = 3
Service-Type = Framed-User
Framed-MTU = 1300
NAS-Port-Type = Wireless-802.11
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "60"
EAP-Message =
0x020300c4150016030100b9010000b503014eca6b5e350b03240373c7268372081bed76da6d538ae12ae8ef5339c5f0f892000048c014c00a00390038c00fc00500
35c012c00800160013c00dc003000ac013c00900330032c00ec004002fc011c007c00cc002000500040015001200090014001100080006000300ff01000044000b00
0403000102000a00340032000100020003000400050006000700080009000a000b000c000d000e000f001000110012001300140015001600170018001900230000
State = 0x0a0be8430b08fd3409af9106d0fa8ef1
Message-Authenticator = 0x5545a479957963890d971798517934fc
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 3 length 196
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] eaptls_verify returned 7
[ttls] Done initial handshake
[ttls] (other): before/accept initialization
[ttls] TLS_accept: before/accept initialization
[ttls] <<< TLS 1.0 Handshake [length 00b9], ClientHello
[ttls] TLS_accept: SSLv3 read client hello A
[ttls] >>> TLS 1.0 Handshake [length 0031], ServerHello
[ttls] TLS_accept: SSLv3 write server hello A
[ttls] >>> TLS 1.0 Handshake [length 08cf], Certificate
[ttls] TLS_accept: SSLv3 write certificate A
[ttls] >>> TLS 1.0 Handshake [length 020d], ServerKeyExchange
[ttls] TLS_accept: SSLv3 write key exchange A
[ttls] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone
[ttls] TLS_accept: SSLv3 write server done A
[ttls] TLS_accept: SSLv3 flush data
[ttls] TLS_accept: Need to read more data: SSLv3 read client certificate A
In SSL Handshake Phase
In SSL Accept mode
[ttls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 198 to 10.5.11.6 port 32768
EAP-Message =
0x0104040015c000000b2516030100310200002d03014eca6b50e31d3f24527611e298d6386147aacde41f93ba9a6c637450b4ca1904000039000005ff0100010016
030108cf0b0008cb0008c80004e9308204e5308203cda003020102020300a0a6300d06092a864886f70d0101050500303c310b300906035504061302555331173015
060355040a130e47656f54727573742c20496e632e311430120603550403130b526170696453534c204341301e170d3131303230383134343634395a170d31323032
31313034343832315a3081e93129302706035504051320547356443351576d4f5375624b2f61636c7a5956362d34494a546d593246666e31
EAP-Message =
0x0b3009060355040613025553311a3018060355040a0c112a2e73696d6f6e732d726f636b2e65647531133011060355040b130a475433373637383036313131302f
060355040b1328536565207777772e726170696473736c2e636f6d2f7265736f75726365732f637073202863293131312f302d060355040b1326446f6d61696e2043
6f6e74726f6c2056616c696461746564202d20526170696453534c285229311a301806035504030c112a2e73696d6f6e732d726f636b2e65647530820122300d0609
2a864886f70d01010105000382010f003082010a0282010100c0f30f8782033a767389b3332db5402bd026f8b4ebcc40370cbd0156aaa160
EAP-Message =
0x7edd569c6f2ccb0082047df379da7f15d3dfed45ee3e54820b214ac4c670e518d1b9a31081dd5fd1ae96d8c4040354f41200e0e2e5594d9f65bb2ed047f87321dd
5ae4a563e9797c87a824189ce91eafe7e0425698d11d9231bb55483ef0c61348f6bd41b9dfcf812d66346f21f4844809c53dfe3cc76414dc9381e628020912e81c44
be4db400c993d2a686ace564337da60fd69882b593c7889cafdae1da4ef9d0d9b2139deac664ede2f57eeeb98f87647e836cfc1fa9ca504bf01b91e52ce0f068ae8e
3b9511ad3eea8fd69f47b77a1289dec7c47ae04664e172fb82c9019b0203010001a38201403082013c301f0603551d230418301680146b69
EAP-Message =
0x3d6a18424add8f026539fd35248678911630300e0603551d0f0101ff0404030205a0301d0603551d250416301406082b0601050507030106082b06010505070302
302d0603551d110426302482112a2e73696d6f6e732d726f636b2e656475820f73696d6f6e732d726f636b2e65647530430603551d1f043c303a3038a036a0348632
687474703a2f2f726170696473736c2d63726c2e67656f74727573742e636f6d2f63726c732f726170696473736c2e63726c301d0603551d0e0416041445e2df8f88
5950a6beaf35ea658dd27a718ac71b300c0603551d130101ff04023000304906082b06010505070101043d303b303906082b060105050730
EAP-Message = 0x02862d687474703a2f2f7261
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x0a0be843080ffd3409af9106d0fa8ef1
Finished request 2.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 10.5.11.6 port 32768, id=199, length=237
User-Name = "testuser"
Calling-Station-Id = "40-fc-89-f1-a9-c2"
Called-Station-Id = "00-1f-6c-a9-85-d0:its-test"
NAS-Port = 29
Cisco-AVPair = "audit-session-id=0a050b0600013b924eca67ab"
NAS-IP-Address = 10.5.11.6
NAS-Identifier = "DOMAIN-WLC2"
Airespace-Wlan-Id = 3
Service-Type = Framed-User
Framed-MTU = 1300
NAS-Port-Type = Wireless-802.11
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "60"
EAP-Message = 0x020400061500
State = 0x0a0be843080ffd3409af9106d0fa8ef1
Message-Authenticator = 0x457578b0e97befc7fd131b6cac5499bf
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 4 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] Received TLS ACK
[ttls] ACK handshake fragment handler
[ttls] eaptls_verify returned 1
[ttls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 199 to 10.5.11.6 port 32768
EAP-Message =
0x0105040015c000000b2570696473736c2d6169612e67656f74727573742e636f6d2f726170696473736c2e637274300d06092a864886f70d010105050003820101
007e914b340ecdb5263a2bce3617cea8ee8a0d20a50d9ecffb9a65c693007c0e81a4366903c1859f80778184d6a8127b007fb89aa19bc0e9ae382e45d360fa5c89fe
94ec1cdf2425bcad7d224112753d5fac3c2cf4dc210f699a65200fddfb396bd478fa24b9f525d8924b6e28b2e6b7c3a4c8f16833c7fa22d4c890a05430117b79b861
17100903c85265c77e5db62c874dcd27a902cb3037d64d16972b6f7201b81c39f8f4b7363f5c2c4fb00acad8995af4fa18dae9762824e7b0
EAP-Message =
0x354a4a1f2ed1d182908078f978067a06d8fdadd06c082ac0f1ce9a9cbfea9fb2062521654c63d0fa16f07dd8d079aa08b80b7c4266b08cc8a1a5f6f684e1af40ce
738d1f870003d9308203d5308202bda00302010202030236d1300d06092a864886f70d01010505003042310b300906035504061302555331163014060355040a130d
47656f547275737420496e632e311b30190603550403131247656f547275737420476c6f62616c204341301e170d3130303231393232343530355a170d3230303231
383232343530355a303c310b300906035504061302555331173015060355040a130e47656f54727573742c20496e632e3114301206035504
EAP-Message =
0x03130b526170696453534c20434130820122300d06092a864886f70d01010105000382010f003082010a0282010100c771f856c71ed9ccb5adf6b497a3fba1e60b
505f50aa3ada0ffc3d292443c61029c1fc554072eebdeadf9fb641f4484bc86efe4f57128b5bfa92dd5ee8adf3f01bb17b4dfbcffdd1e5f8e3dce7f5737fdf0149cf
8c56c1bd37e35bbeb54f8b8bf0da4fc7e3dd554769dff25b7b074f3de5ac21c1c81d7ae8e7f60fa1aaf56fdea8654f10899c03f3897aa55e017233eda9e95a1e79f3
87c8dfc8c5fc37c89a9ad7b876ccb03ee7fde654eadf5f5241785957adf112d67fbcd59f70d3056cfaa37d6758dd26621d31920c79791c8e
EAP-Message =
0xcfca7bc166afa87448fb8e82c29e2c995c7b2d5d9bbc5b579e7c3a7a13adf2a3185b2b590fcd5c3aeb6833c6281d82d1508b0203010001a381d93081d6300e0603
551d0f0101ff040403020106301d0603551d0e041604146b693d6a18424add8f026539fd35248678911630301f0603551d23041830168014c07a98688d89fbab0564
0c117daa7d65b8cacc4e30120603551d130101ff040830060101ff020100303a0603551d1f04333031302fa02da02b8629687474703a2f2f63726c2e67656f747275
73742e636f6d2f63726c732f6774676c6f62616c2e63726c303406082b0601050507010104283026302406082b0601050507300186186874
EAP-Message = 0x74703a2f2f6f6373702e6765
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x0a0be843090efd3409af9106d0fa8ef1
Finished request 3.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 10.5.11.6 port 32768, id=200, length=237
User-Name = "testuser"
Calling-Station-Id = "40-fc-89-f1-a9-c2"
Called-Station-Id = "00-1f-6c-a9-85-d0:its-test"
NAS-Port = 29
Cisco-AVPair = "audit-session-id=0a050b0600013b924eca67ab"
NAS-IP-Address = 10.5.11.6
NAS-Identifier = "DOMAIN-WLC2"
Airespace-Wlan-Id = 3
Service-Type = Framed-User
Framed-MTU = 1300
NAS-Port-Type = Wireless-802.11
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "60"
EAP-Message = 0x020500061500
State = 0x0a0be843090efd3409af9106d0fa8ef1
Message-Authenticator = 0x02c3914c1936f53d85fce7e3eada0cc9
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 5 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] Received TLS ACK
[ttls] ACK handshake fragment handler
[ttls] eaptls_verify returned 1
[ttls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 200 to 10.5.11.6 port 32768
EAP-Message =
0x01060343158000000b256f74727573742e636f6d300d06092a864886f70d01010505000382010100abbcbc0a5d1894e3c1b1c3a84c55d6beb498f1ee3c1ccdcff3
24245c96032758fc36aea22f8ff1feda2b02c333bdc8dd48222b600fa50310fd77f8d0ed96674ffdea47207054dca90c557ee196258ad9b5da574abe8d8e494363a5
6c4e278725eb5b6dfea27f3828e036abad39a5a562c4b75c582caa5d0160a66267a3c0c76223f4e76c46eeb5d3806a2213d22d3f744feaaf8c5fb4389cdbaeceaf84
1ea6f634515979d3e375dcbcd7f373df92ecd220596f9cfb95f89276180a7c0f2ca6cade8a627bd8f3ce5f68bd8f3ec174bb15723a1683a9
EAP-Message =
0x0be64d999cd857eca80151c76f57345eab4a2c42f64f1c8978de264ef56f934c156b27564d00546c7ab7b7160301020d0c0002090080a1810a407ff888a31717a6
3696e01bf55e486bdf12ecc27c18a2ec47a94b32dfafef888372a71f4c927340383f0b72888fb3c7ef26216ca20b117bb94d0032fd7c6a314ce9c4dc15c97998ad86
8699522ed5d57239c545db9579f240839706144cb0f7d946b58f39da09b83337238b4c5111cf38f7ff82a60ed8e41391220773000102008095f57e46374bb6cc0c0f
89651ab67fa9d8d61f26ea082e4118303c4b724f3bcb1c98d57c00008a5d4a8c655db0fc8d2034669d272665f91bc93e11a7986b5547efc0
EAP-Message =
0x7d29707485c55170f9f36c47c7770ae0d241fa70fe6529ab517e617c05eef3440a8e88a246708818ee2378d26edf1721dcddff81394ae203cb4ba62992e2010074
f4c94696fbc5b114ffd0cea27dcff3ac6ee96e3e96f1746894a8f267db9c3ed89d2a257635bc4fe2686e2f5ef5ddd79fb2b205f050a1e8e75f4cfdc2434c529a3bce
9b7f318abd89284f2617570f991e880c76b32f21eea6ac6d0e47775f7c5e3b0c76a7818725676add85d5b75b33f51954194bb6f12dfd77165685c3d5ee43eb09008c
ab916e3c6e121e703cf5918a960b31cc28b94195f5bebb4a7a699f29db31e7b7ad492233b97a25b5e5a991b469c01a5daf394a11b8fac978
EAP-Message =
0xe467f5a8c1d1e1d0476e91dfff20bde527b2a7005cd031bd16fa1ba4bd22215d54ea9f0b8f18edb5485a7b5c6fd05174a0aa796b71c33e22c642ac889df7a16069
58e416030100040e000000
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x0a0be8430e0dfd3409af9106d0fa8ef1
Finished request 4.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 10.5.11.6 port 32768, id=201, length=435
User-Name = "testuser"
Calling-Station-Id = "40-fc-89-f1-a9-c2"
Called-Station-Id = "00-1f-6c-a9-85-d0:its-test"
NAS-Port = 29
Cisco-AVPair = "audit-session-id=0a050b0600013b924eca67ab"
NAS-IP-Address = 10.5.11.6
NAS-Identifier = "DOMAIN-WLC2"
Airespace-Wlan-Id = 3
Service-Type = Framed-User
Framed-MTU = 1300
NAS-Port-Type = Wireless-802.11
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "60"
EAP-Message =
0x020600cc15001603010086100000820080895aa1f1e2c158f2ef399b618bfe153544811fde53aa80013f658eca48b59aae0c782068eac38020068ebad55ba1801f
a110f977f409ccef7bb8dfbc201abed7097dfa5b718b132e3af50b8af59cd671e484a7d14a341430ac95daeb7fcebc8cefde80f80320f1613b59e152ac90cb42adf5
7808e3a8a602294055ad2be51cc714030100010116030100307cfd16b52bc73156f9c5d00eeab53abf45cf8582ad8a4f9cfe6c048e77c7e924b1aaa8142d194fc684
b52b403644ffdd
State = 0x0a0be8430e0dfd3409af9106d0fa8ef1
Message-Authenticator = 0xab5b1b2c976d0b723053afe970c5dafa
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 6 length 204
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] eaptls_verify returned 7
[ttls] Done initial handshake
[ttls] <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange
[ttls] TLS_accept: SSLv3 read client key exchange A
[ttls] <<< TLS 1.0 ChangeCipherSpec [length 0001]
[ttls] <<< TLS 1.0 Handshake [length 0010], Finished
[ttls] TLS_accept: SSLv3 read finished A
[ttls] >>> TLS 1.0 ChangeCipherSpec [length 0001]
[ttls] TLS_accept: SSLv3 write change cipher spec A
[ttls] >>> TLS 1.0 Handshake [length 0010], Finished
[ttls] TLS_accept: SSLv3 write finished A
[ttls] TLS_accept: SSLv3 flush data
[ttls] (other): SSL negotiation finished successfully
SSL Connection Established
[ttls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 201 to 10.5.11.6 port 32768
EAP-Message =
0x0107004515800000003b1403010001011603010030dd1e7ae880ee3dd0b17e648fc5e46b8cc3e846b83743e50f7a82385fe151786e8d335c0a9842aaeda0940734
b4697f80
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x0a0be8430f0cfd3409af9106d0fa8ef1
Finished request 5.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host 10.5.11.6 port 32768, id=202, length=343
User-Name = "testuser"
Calling-Station-Id = "40-fc-89-f1-a9-c2"
Called-Station-Id = "00-1f-6c-a9-85-d0:its-test"
NAS-Port = 29
Cisco-AVPair = "audit-session-id=0a050b0600013b924eca67ab"
NAS-IP-Address = 10.5.11.6
NAS-Identifier = "DOMAIN-WLC2"
Airespace-Wlan-Id = 3
Service-Type = Framed-User
Framed-MTU = 1300
NAS-Port-Type = Wireless-802.11
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "60"
EAP-Message =
0x020700701500170301002023c880010afbaca985b3723f392eaa549658ffcc6d434634bfd3e1e276d3da9317030100407f9236bc7b9e5825a580b427c865635f48
a407f7e9cffade23387c3d5ea350a01de2b68138b21fb39a9cd9acd1b75cdd43010775e3fa1ef8d1658dd40080a571
State = 0x0a0be8430f0cfd3409af9106d0fa8ef1
Message-Authenticator = 0x488b5387ee423eb6c94778c7410c84b7
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 112
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] eaptls_verify returned 7
[ttls] Done initial handshake
[ttls] eaptls_process returned 7
[ttls] Session established. Proceeding to decode tunneled attributes.
[ttls] Got tunneled request
User-Name = "testuser"
User-Password = "testpass"
FreeRADIUS-Proxied-To = 127.0.0.1
[ttls] Sending tunneled request
User-Name = "testuser"
User-Password = "testpass"
FreeRADIUS-Proxied-To = 127.0.0.1
server inner-tunnel {
# Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] No EAP-Message, not doing EAP
++[eap] returns noop
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (uid=%u) -> (uid=testuser)
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (uid=testuser)
[ldap] ldap_release_conn: Release Id: 0
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=faculty)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group faculty not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=staff)(&(objectClass=personSR)(uid=testuser)))
[ldap] object not found
[ldap] ldap_release_conn: Release Id: 0
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in uid=testuser,ou=people,dc=domain,dc=edu, with filter (objectclass=*)
rlm_ldap::groupcmp: Group staff not found or user not a member
[ldap] ldap_release_conn: Release Id: 0
[files] expand: %{Client-IP-Address} -> 10.5.11.6
[ldap] Entering ldap_groupcmp()
[files] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[files] expand: (&(objectClass=personSR)(uid=%{User-Name})) -> (&(objectClass=personSR)(uid=testuser))
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (&(groupSR=student)(&(objectClass=personSR)(uid=testuser)))
rlm_ldap::ldap_groupcmp: User found in group student
[ldap] ldap_release_conn: Release Id: 0
[files] users: Matched entry DEFAULT at line 244
++[files] returns ok
[ldap] performing user authorization for testuser
[ldap] expand: (uid=%u) -> (uid=testuser)
[ldap] expand: dc=domain,dc=edu -> dc=domain,dc=edu
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=domain,dc=edu, with filter (uid=testuser)
[ldap] checking if remote access for testuser is allowed by uid
[ldap] looking for check items in directory...
[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP. Are you sure that the user is configured correctly?
[ldap] Setting Auth-Type = LDAP
[ldap] user testuser authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = LDAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group LDAP {...}
[ldap] login attempt by "testuser" with password "testpass"
[ldap] user DN: uid=testuser,ou=people,dc=domain,dc=edu
[ldap] (re)connect to ldap1.domain.edu:389, authentication 1
[ldap] bind as uid=testuser,ou=people,dc=domain,dc=edu/testpass to ldap1.domain.edu:389
[ldap] waiting for bind result ...
[ldap] Bind was successful
[ldap] user testuser authenticated succesfully
++[ldap] returns ok
WARNING: Empty post-auth section. Using default return values.
# Executing section post-auth from file /etc/raddb/sites-enabled/inner-tunnel
} # server inner-tunnel
[ttls] Got tunneled reply code 2
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "360"
[ttls] Got tunneled Access-Accept
[eap] Freeing handler
++[eap] returns ok
# Executing section post-auth from file /etc/raddb/sites-enabled/default
+- entering group post-auth {...}
++[exec] returns noop
Sending Access-Accept of id 202 to 10.5.11.6 port 32768
MS-MPPE-Recv-Key = 0xef328a0494874f4b9e2c0278014e3f9467c949761073da5cb7b9d6d382699fd9
MS-MPPE-Send-Key = 0xa2796321aa8e0d9014ae3e67c079427a29a82c0851a34ab98d554ea6b41bc8c7
EAP-Message = 0x03070004
Message-Authenticator = 0x00000000000000000000000000000000
User-Name = "testuser"
Finished request 6.
Going to the next request
Waking up in 4.7 seconds.
rad_recv: Accounting-Request packet from host 10.5.11.6 port 32768, id=39, length=263
User-Name = "testuser"
NAS-Port = 29
NAS-IP-Address = 10.5.11.6
Framed-IP-Address = 10.5.14.192
NAS-Identifier = "DOMAIN-WLC2"
Airespace-Wlan-Id = 3
Acct-Session-Id = "4eca67af/40:fc:89:f1:a9:c2/89488"
Cisco-AVPair = "audit-session-id=0a050b0600013b924eca67ab"
Acct-Authentic = RADIUS
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "60"
Acct-Status-Type = Interim-Update
Acct-Input-Octets = 907218
Acct-Output-Octets = 3106458
Acct-Input-Packets = 11383
Acct-Output-Packets = 5326
Acct-Session-Time = 929
Acct-Delay-Time = 0
Calling-Station-Id = "10.5.14.192"
Called-Station-Id = "10.5.11.6"
Cisco-AVPair = "nas-update=true"
# Executing section preacct from file /etc/raddb/sites-enabled/default
+- entering group preacct {...}
++[preprocess] returns ok
[acct_unique] Hashing 'NAS-Port = 29,Client-IP-Address = 10.5.11.6,NAS-IP-Address = 10.5.11.6,Acct-Session-Id =
"4eca67af/40:fc:89:f1:a9:c2/89488",User-Name = "testuser"'
[acct_unique] Acct-Unique-Session-ID = "e441483aa5eda403".
++[acct_unique] returns ok
[suffix] No '@' in User-Name = "testuser", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[files] returns noop
# Executing section accounting from file /etc/raddb/sites-enabled/default
+- entering group accounting {...}
[detail] expand: /var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d ->
/var/log/radius/radacct/10.5.11.6/detail-20111121
[detail] /var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands to /var/log/radius/radacct/10.5.11.6/detail-20111121
[detail] expand: %t -> Mon Nov 21 10:16:32 2011
++[detail] returns ok
++[unix] returns noop
[radutmp] expand: /var/log/radius/radutmp -> /var/log/radius/radutmp
[radutmp] expand: %{User-Name} -> testuser
++[radutmp] returns ok
++[exec] returns noop
[attr_filter.accounting_response] expand: %{User-Name} -> testuser
attr_filter: Matched entry DEFAULT at line 12
++[attr_filter.accounting_response] returns updated
Sending Accounting-Response of id 39 to 10.5.11.6 port 32768
Finished request 7.
Cleaning up request 7 ID 39 with timestamp +6
Going to the next request
Waking up in 4.7 seconds.
Cleaning up request 0 ID 196 with timestamp +6
Cleaning up request 1 ID 197 with timestamp +6
Cleaning up request 2 ID 198 with timestamp +6
Cleaning up request 3 ID 199 with timestamp +6
Cleaning up request 4 ID 200 with timestamp +6
Waking up in 0.1 seconds.
Cleaning up request 5 ID 201 with timestamp +6
Cleaning up request 6 ID 202 with timestamp +6
Ready to process requests.
Brian Gold
System Administrator
Bard College at Simon's Rock
2
2
Hello,
I just stumbled across this which made me worry a bit:
commit f8f58e4bec03d832ad4480b90e7dd531ae0d787d
Author: Alan T. DeKok <aland(a)freeradius.org>
Date: Wed Oct 19 17:20:37 2011 +0200
Only "string" can have "encrypt=2"
diff --git a/src/lib/dict.c b/src/lib/dict.c
index f613664..bdf8065 100644
--- a/src/lib/dict.c
+++ b/src/lib/dict.c
@@ -906,6 +906,13 @@ static int process_attribute(const char* fn, const int line,
fn, line, key);
return -1;
}
+
+ if ((flags.encrypt == FLAG_ENCRYPT_ASCEND_SECRET) &&
+ (type != PW_TYPE_STRING)) {
+ fr_strerror_printf( "dict_init: %s[%d] Only \"string\" types can have the \"encrypt=2\" flag set.",
+ fn, line);
+ return -1;
+ }
} else if (strncmp(key, "array", 8) == 0) {
flags.array = 1;
The reason I'm worrying is dictionary.erx, where I know there are other
types (integer, octets and ipaddress) with "encrypt=2" set. And these
are in fact in use, with encryption, by a number of Juniper JUNOS and
JUNOSe based devices.
And the second issue that made me worry: Why didn't I (and everybody
else) hit that by default in ictionary.erx? Well, it seems that
FLAG_ENCRYPT_ASCEND_SECRET isn't really 2 as the above made me believe.
It is 3. 2 is of course FLAG_ENCRYPT_TUNNEL_PASSWORD.
But if it's a typo, then why repeat it in the commit message as well?
Was this an attempt to disable other encryption types that
FLAG_ENCRYPT_TUNNEL_PASSWORD for other attribute types that strings? Or
what exactly was the above trying to fix?
Anyway: Please don't disable tunnel-password encryption of non-string
attributes. It works, and it *is* in use.
Bjørn (coloured confused)
2
2
PEAP Inner-tunnel can't match a user in the "users" file with some check attributes
by Difan Zhao 21 Nov '11
by Difan Zhao 21 Nov '11
21 Nov '11
Hi gents,
I have an issue that whenever I have check attributes such as NAS-IP-Address or NAS-Port-Type, my PEAP fails... The same config works for MD5... I'm running FreeRADIUS Version 2.1.7.
--- users ---
"phone" User-Name =~ "phone", Cleartext-Password := "mykey", NAS-IP-Address == "10.143.115.14"
Tunnel-Private-Group-Id := "654", Tunnel-Type := "VLAN", Tunnel-Medium-Type := "IEEE-802", Tunnel-Preference := "0"
All other configs are mostly default.
Everything works once I removed NAS-IP-Address == "10.143.115.14". However I do need to check against from which switch/NAS the request is coming from... It seems that those attributes are outside of the "tunnel". How can I copy them in the "tunnel" (does this make sense to you guys)?? My debug output is attached.
Thank you and have a good weekend!
Difan
2
2
so it took me a while, but i finally tracked down a MAC to continue
troubleshooting...at this point windows machines can login with RAIDUS
auth... below is the output from an attempt with a MAC:
[root@ops2 raddb]# radiusd -X
FreeRADIUS Version 2.1.12, for host x86_64-redhat-linux-gnu, built on
Oct 3 2011 at 10:29:04
Copyright (C) 1999-2009 The FreeRADIUS server project and contributors.
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE.
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License v2.
Starting - reading configuration files ...
including configuration file /etc/raddb/radiusd.conf
including configuration file /etc/raddb/proxy.conf
including configuration file /etc/raddb/clients.conf
including files in directory /etc/raddb/modules/
including configuration file /etc/raddb/modules/pap
including configuration file /etc/raddb/modules/preprocess
including configuration file /etc/raddb/modules/perl
including configuration file /etc/raddb/modules/linelog
including configuration file /etc/raddb/modules/sql_log
including configuration file /etc/raddb/modules/cui
including configuration file /etc/raddb/modules/acct_unique
including configuration file /etc/raddb/modules/mac2ip
including configuration file /etc/raddb/modules/detail.example.com
including configuration file /etc/raddb/modules/replicate
including configuration file /etc/raddb/modules/dynamic_clients
including configuration file /etc/raddb/modules/passwd
including configuration file /etc/raddb/modules/wimax
including configuration file /etc/raddb/modules/inner-eap
including configuration file /etc/raddb/modules/logintime
including configuration file /etc/raddb/modules/chap
including configuration file /etc/raddb/modules/digest
including configuration file /etc/raddb/modules/ippool
including configuration file /etc/raddb/modules/mschap
including configuration file /etc/raddb/modules/pam
including configuration file /etc/raddb/modules/redis
including configuration file /etc/raddb/modules/detail.log
including configuration file /etc/raddb/modules/always
including configuration file /etc/raddb/modules/radutmp
including configuration file /etc/raddb/modules/ldap
including configuration file /etc/raddb/modules/ntlm_auth
including configuration file /etc/raddb/modules/ldap.new
including configuration file /etc/raddb/modules/mac2vlan
including configuration file /etc/raddb/modules/etc_group
including configuration file /etc/raddb/modules/sradutmp
including configuration file /etc/raddb/modules/counter
including configuration file /etc/raddb/modules/attr_filter
including configuration file /etc/raddb/modules/soh
including configuration file /etc/raddb/modules/policy
including configuration file /etc/raddb/modules/unix
including configuration file /etc/raddb/modules/opendirectory
including configuration file /etc/raddb/modules/sqlcounter_expire_on_login
including configuration file /etc/raddb/modules/otp
including configuration file /etc/raddb/modules/exec
including configuration file /etc/raddb/modules/realm
including configuration file /etc/raddb/modules/rediswho
including configuration file /etc/raddb/modules/expiration
including configuration file /etc/raddb/modules/checkval
including configuration file /etc/raddb/modules/echo
including configuration file /etc/raddb/modules/detail
including configuration file /etc/raddb/modules/attr_rewrite
including configuration file /etc/raddb/modules/smsotp
including configuration file /etc/raddb/modules/expr
including configuration file /etc/raddb/modules/smbpasswd
including configuration file /etc/raddb/modules/files
including configuration file /etc/raddb/eap.conf
including configuration file /etc/raddb/policy.conf
including files in directory /etc/raddb/sites-enabled/
including configuration file /etc/raddb/sites-enabled/inner-tunnel
including configuration file /etc/raddb/sites-enabled/default
including configuration file /etc/raddb/sites-enabled/control-socket
main {
user = "radiusd"
group = "radiusd"
allow_core_dumps = no
}
including dictionary file /etc/raddb/dictionary
main {
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/radius"
run_dir = "/var/run/radiusd"
libdir = "/usr/lib64/freeradius"
radacctdir = "/var/log/radius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 1024
pidfile = "/var/run/radiusd/radiusd.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
}
security {
max_attributes = 200
reject_delay = 1
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = "i6Lw7uNsG7pZDUGgxirg"
response_window = 20
max_outstanding = 65536
require_message_authenticator = no
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
num_answers_to_alive = 3
num_pings_to_alive = 3
revive_interval = 120
status_check_timeout = 4
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm local.currensee.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = "i6Lw7uNsG7pZDUGgxirg"
nastype = "other"
}
client ops2 {
ipaddr = 192.168.10.247
require_message_authenticator = no
secret = "i6Lw7uNsG7pZDUGgxirg"
nastype = "other"
}
client ap1 {
ipaddr = 192.168.10.31
require_message_authenticator = no
secret = "i6Lw7uNsG7pZDUGgxirg"
shortname = "ap1"
nastype = "cisco"
}
client ap2 {
ipaddr = 192.168.10.30
require_message_authenticator = no
secret = "i6Lw7uNsG7pZDUGgxirg"
shortname = "ap2"
nastype = "cisco"
}
radiusd: #### Instantiating modules ####
instantiate {
Module: Linked to module rlm_exec
Module: Instantiating module "exec" from file /etc/raddb/modules/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
}
Module: Linked to module rlm_expr
Module: Instantiating module "expr" from file /etc/raddb/modules/expr
Module: Linked to module rlm_expiration
Module: Instantiating module "expiration" from file
/etc/raddb/modules/expiration
expiration {
reply-message = "Password Has Expired "
}
Module: Linked to module rlm_logintime
Module: Instantiating module "logintime" from file
/etc/raddb/modules/logintime
logintime {
reply-message = "You are calling outside your allowed timespan "
minimum-timeout = 60
}
}
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/raddb/radiusd.conf
modules {
Module: Creating Auth-Type = LDAP
Module: Creating Post-Auth-Type = REJECT
Module: Checking authenticate {...} for more modules to load
Module: Linked to module rlm_pap
Module: Instantiating module "pap" from file /etc/raddb/modules/pap
pap {
encryption_scheme = "auto"
auto_header = yes
}
Module: Linked to module rlm_chap
Module: Instantiating module "chap" from file /etc/raddb/modules/chap
Module: Linked to module rlm_mschap
Module: Instantiating module "mschap" from file /etc/raddb/modules/mschap
mschap {
use_mppe = yes
require_encryption = yes
require_strong = yes
with_ntdomain_hack = no
allow_retry = yes
}
Module: Linked to module rlm_ldap
Module: Instantiating module "ldap" from file /etc/raddb/modules/ldap
ldap {
server = "ldap.local.currensee.com"
port = 389
password = "VcnxJbFqeAuAFyiu3zvi"
identity = "cn=manager,dc=currensee,dc=com"
net_timeout = 1
timeout = 4
timelimit = 3
tls_mode = no
start_tls = yes
tls_cacertfile = "/etc/ldap/csca.crt"
tls_require_cert = "demand"
tls {
start_tls = no
require_cert = "allow"
}
basedn = "ou=people,dc=currensee,dc=com"
filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
base_filter = "(objectclass=radiusprofile)"
auto_header = no
access_attr = "uid"
access_attr_used_for_allow = yes
groupname_attribute = "cn"
groupmembership_filter =
"(|(&(objectClass=GroupOfNames)(member=%{Ldap-UserDn}))(&(objectClass=GroupOfUniqueNames)(uniquemember=%{Ldap-UserDn})))"
dictionary_mapping = "/etc/raddb/ldap.attrmap"
ldap_debug = 40
ldap_connections_number = 5
compare_check_items = no
do_xlat = yes
set_auth_type = yes
}
rlm_ldap: Registering ldap_groupcmp for Ldap-Group
rlm_ldap: Registering ldap_xlat with xlat_name ldap
rlm_ldap: reading ldap<->radius mappings from file /etc/raddb/ldap.attrmap
rlm_ldap: LDAP radiusCheckItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusReplyItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusAuthType mapped to RADIUS Auth-Type
rlm_ldap: LDAP radiusSimultaneousUse mapped to RADIUS Simultaneous-Use
rlm_ldap: LDAP radiusCalledStationId mapped to RADIUS Called-Station-Id
rlm_ldap: LDAP radiusCallingStationId mapped to RADIUS Calling-Station-Id
rlm_ldap: LDAP lmPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP ntPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP sambaLmPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP sambaNtPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP dBCSPwd mapped to RADIUS LM-Password
rlm_ldap: LDAP acctFlags mapped to RADIUS SMB-Account-CTRL-TEXT
rlm_ldap: LDAP radiusExpiration mapped to RADIUS Expiration
rlm_ldap: LDAP radiusNASIpAddress mapped to RADIUS NAS-IP-Address
rlm_ldap: LDAP userPassword mapped to RADIUS Password-With-Header
rlm_ldap: LDAP radiusServiceType mapped to RADIUS Service-Type
rlm_ldap: LDAP radiusFramedProtocol mapped to RADIUS Framed-Protocol
rlm_ldap: LDAP radiusFramedIPAddress mapped to RADIUS Framed-IP-Address
rlm_ldap: LDAP radiusFramedIPNetmask mapped to RADIUS Framed-IP-Netmask
rlm_ldap: LDAP radiusFramedRoute mapped to RADIUS Framed-Route
rlm_ldap: LDAP radiusFramedRouting mapped to RADIUS Framed-Routing
rlm_ldap: LDAP radiusFilterId mapped to RADIUS Filter-Id
rlm_ldap: LDAP radiusFramedMTU mapped to RADIUS Framed-MTU
rlm_ldap: LDAP radiusFramedCompression mapped to RADIUS Framed-Compression
rlm_ldap: LDAP radiusLoginIPHost mapped to RADIUS Login-IP-Host
rlm_ldap: LDAP radiusLoginService mapped to RADIUS Login-Service
rlm_ldap: LDAP radiusLoginTCPPort mapped to RADIUS Login-TCP-Port
rlm_ldap: LDAP radiusCallbackNumber mapped to RADIUS Callback-Number
rlm_ldap: LDAP radiusCallbackId mapped to RADIUS Callback-Id
rlm_ldap: LDAP radiusFramedIPXNetwork mapped to RADIUS Framed-IPX-Network
rlm_ldap: LDAP radiusClass mapped to RADIUS Class
rlm_ldap: LDAP radiusSessionTimeout mapped to RADIUS Session-Timeout
rlm_ldap: LDAP radiusIdleTimeout mapped to RADIUS Idle-Timeout
rlm_ldap: LDAP radiusTerminationAction mapped to RADIUS Termination-Action
rlm_ldap: LDAP radiusLoginLATService mapped to RADIUS Login-LAT-Service
rlm_ldap: LDAP radiusLoginLATNode mapped to RADIUS Login-LAT-Node
rlm_ldap: LDAP radiusLoginLATGroup mapped to RADIUS Login-LAT-Group
rlm_ldap: LDAP radiusFramedAppleTalkLink mapped to RADIUS
Framed-AppleTalk-Link
rlm_ldap: LDAP radiusFramedAppleTalkNetwork mapped to RADIUS
Framed-AppleTalk-Network
rlm_ldap: LDAP radiusFramedAppleTalkZone mapped to RADIUS
Framed-AppleTalk-Zone
rlm_ldap: LDAP radiusPortLimit mapped to RADIUS Port-Limit
rlm_ldap: LDAP radiusLoginLATPort mapped to RADIUS Login-LAT-Port
rlm_ldap: LDAP radiusReplyMessage mapped to RADIUS Reply-Message
rlm_ldap: LDAP radiusTunnelType mapped to RADIUS Tunnel-Type
rlm_ldap: LDAP radiusTunnelMediumType mapped to RADIUS Tunnel-Medium-Type
rlm_ldap: LDAP radiusTunnelPrivateGroupId mapped to RADIUS
Tunnel-Private-Group-Id
conns: 0x1fa9ddb0
Module: Linked to module rlm_eap
Module: Instantiating module "eap" from file /etc/raddb/eap.conf
eap {
default_eap_type = "peap"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 2048
}
Module: Linked to sub-module rlm_eap_md5
Module: Instantiating eap-md5
Module: Linked to sub-module rlm_eap_leap
Module: Instantiating eap-leap
Module: Linked to sub-module rlm_eap_gtc
Module: Instantiating eap-gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
Module: Linked to sub-module rlm_eap_tls
Module: Instantiating eap-tls
tls {
rsa_key_exchange = no
dh_key_exchange = yes
rsa_key_length = 512
dh_key_length = 512
verify_depth = 0
pem_file_type = yes
private_key_file = "/etc/raddb/certs/radius.key.pem"
certificate_file = "/etc/raddb/certs/radius.crt.pem"
CA_file = "/etc/raddb/certs/cacert.pem"
private_key_password = "i6Lw7uNsG7pZDUGgxirg"
dh_file = "/etc/raddb/certs/dh"
random_file = "/dev/urandom"
fragment_size = 1024
include_length = yes
check_crl = no
cipher_list = "DEFAULT"
make_cert_command = "/etc/raddb/certs/bootstrap"
cache {
enable = no
lifetime = 24
max_entries = 255
}
}
Module: Linked to sub-module rlm_eap_ttls
Module: Instantiating eap-ttls
ttls {
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
}
Module: Linked to sub-module rlm_eap_peap
Module: Instantiating eap-peap
peap {
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
}
Module: Linked to sub-module rlm_eap_mschapv2
Module: Instantiating eap-mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
Module: Checking authorize {...} for more modules to load
Module: Linked to module rlm_preprocess
Module: Instantiating module "preprocess" from file
/etc/raddb/modules/preprocess
preprocess {
huntgroups = "/etc/raddb/huntgroups"
hints = "/etc/raddb/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
Module: Linked to module rlm_realm
Module: Instantiating module "suffix" from file /etc/raddb/modules/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
Module: Linked to module rlm_files
Module: Instantiating module "files" from file /etc/raddb/modules/files
files {
usersfile = "/etc/raddb/users"
acctusersfile = "/etc/raddb/acct_users"
preproxy_usersfile = "/etc/raddb/preproxy_users"
compat = "no"
}
Module: Checking preacct {...} for more modules to load
Module: Linked to module rlm_acct_unique
Module: Instantiating module "acct_unique" from file
/etc/raddb/modules/acct_unique
acct_unique {
key = "User-Name, Acct-Session-Id, NAS-IP-Address,
Client-IP-Address, NAS-Port"
}
Module: Checking accounting {...} for more modules to load
Module: Linked to module rlm_detail
Module: Instantiating module "detail" from file /etc/raddb/modules/detail
detail {
detailfile =
"/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
detailperm = 384
dirperm = 493
locking = no
log_packet_header = no
}
Module: Linked to module rlm_radutmp
Module: Instantiating module "radutmp" from file
/etc/raddb/modules/radutmp
radutmp {
filename = "/var/log/radius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
perm = 384
callerid = yes
}
Module: Linked to module rlm_attr_filter
Module: Instantiating module "attr_filter.accounting_response" from
file /etc/raddb/modules/attr_filter
attr_filter attr_filter.accounting_response {
attrsfile = "/etc/raddb/attrs.accounting_response"
key = "%{User-Name}"
relaxed = no
}
Module: Checking session {...} for more modules to load
Module: Checking post-proxy {...} for more modules to load
Module: Checking post-auth {...} for more modules to load
Module: Instantiating module "attr_filter.access_reject" from file
/etc/raddb/modules/attr_filter
attr_filter attr_filter.access_reject {
attrsfile = "/etc/raddb/attrs.access_reject"
key = "%{User-Name}"
relaxed = no
}
} # modules
} # server
server inner-tunnel { # from file /etc/raddb/sites-enabled/inner-tunnel
modules {
Module: Checking authenticate {...} for more modules to load
Module: Checking authorize {...} for more modules to load
Module: Checking session {...} for more modules to load
Module: Checking post-proxy {...} for more modules to load
Module: Checking post-auth {...} for more modules to load
} # modules
} # server
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *
port = 0
}
listen {
type = "acct"
ipaddr = *
port = 0
}
listen {
type = "control"
listen {
socket = "/var/run/radiusd/radiusd.sock"
}
}
... adding new socket proxy address * port 55962
Listening on authentication address * port 1812
Listening on accounting address * port 1813
Listening on command file /var/run/radiusd/radiusd.sock
Listening on proxy address * port 1814
Ready to process requests.
rad_recv: Access-Request packet from host 192.168.10.31 port 1645,
id=215, length=129
User-Name = "marguin"
Framed-MTU = 1400
Called-Station-Id = "64a0.e72f.69c0"
Calling-Station-Id = "001e.5273.4858"
Service-Type = Login-User
Message-Authenticator = 0x23138394454f3a974d4bda910d58bb2f
EAP-Message = 0x0202000c016d61726775696e
NAS-Port-Type = Wireless-802.11
NAS-Port = 2658
NAS-Port-Id = "2658"
NAS-IP-Address = 192.168.10.31
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 2 length 12
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
[ldap] performing user authorization for marguin
[ldap] expand: %{Stripped-User-Name} ->
[ldap] ... expanding second conditional
[ldap] expand: %{User-Name} -> marguin
[ldap] expand: (uid=%{%{Stripped-User-Name}:-%{User-Name}}) ->
(uid=marguin)
[ldap] expand: ou=people,dc=currensee,dc=com ->
ou=people,dc=currensee,dc=com
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] attempting LDAP reconnection
[ldap] (re)connect to ldap.local.currensee.com:389, authentication 0
[ldap] setting TLS CACert File to /etc/ldap/csca.crt
[ldap] bind as cn=manager,dc=currensee,dc=com/VcnxJbFqeAuAFyiu3zvi to
ldap.local.currensee.com:389
[ldap] waiting for bind result ...
request done: ld 0x1facdf30 msgid 1
[ldap] Bind was successful
[ldap] performing search in ou=people,dc=currensee,dc=com, with
filter (uid=marguin)
request done: ld 0x1facdf30 msgid 2
[ldap] checking if remote access for marguin is allowed by uid
[ldap] looking for check items in directory...
[ldap] userPassword -> Password-With-Header == "{CRYPT}WgRn.wiPxI6Tk"
[ldap] looking for reply items in directory...
[ldap] user marguin authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING: Auth-Type already set. Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 215 to 192.168.10.31 port 1645
EAP-Message = 0x010300061920
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x89f1065d89f21f4f1edcaaacea389153
Finished request 0.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.10.31 port 1645,
id=216, length=299
User-Name = "marguin"
Framed-MTU = 1400
Called-Station-Id = "64a0.e72f.69c0"
Calling-Station-Id = "001e.5273.4858"
Service-Type = Login-User
Message-Authenticator = 0xf6ac040a0d51299187928c5519c1f828
EAP-Message =
0x020300a419800000009a16030100950100009103014eca8a0e0d18c4e50d054bb7ba7bd35d70cca59c3c85503893c89f2c738a923e000056c00ac009c007c008c013c014c011c012c004c005c002c003c00ec00fc00cc00d002f000500040035000a000900030008000600320033003800390016001500140013001200110034003a0018001b001a00170019000101000012000a00080006001700180019000b00020100
NAS-Port-Type = Wireless-802.11
NAS-Port = 2658
NAS-Port-Id = "2658"
State = 0x89f1065d89f21f4f1edcaaacea389153
NAS-IP-Address = 192.168.10.31
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 3 length 164
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
TLS Length 154
[peap] Length Included
[peap] eaptls_verify returned 11
[peap] (other): before/accept initialization
[peap] TLS_accept: before/accept initialization
[peap] <<< TLS 1.0 Handshake [length 0095], ClientHello
[peap] TLS_accept: SSLv3 read client hello A
[peap] >>> TLS 1.0 Handshake [length 002a], ServerHello
[peap] TLS_accept: SSLv3 write server hello A
[peap] >>> TLS 1.0 Handshake [length 06cd], Certificate
[peap] TLS_accept: SSLv3 write certificate A
[peap] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone
[peap] TLS_accept: SSLv3 write server done A
[peap] TLS_accept: SSLv3 flush data
[peap] TLS_accept: Need to read more data: SSLv3 read client
certificate A
In SSL Handshake Phase
In SSL Accept mode
[peap] eaptls_process returned 13
[peap] EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 216 to 192.168.10.31 port 1645
EAP-Message =
0x0104040019c00000070a160301002a0200002603014eca8a0e878b0a7c5cdf1693377ba27c35f0b8e63e093c939626ce43b3a8791d00002f0016030106cd0b0006c90006c60002a6308202a23082020b0203100028300d06092a864886f70d01010405003081b931183016060355040a130f43757272656e7365652c20496e632e31143012060355040b130b456e67696e656572696e673121301f06092a864886f70d0109011612726f6f744063757272656e7365652e636f6d310f300d06035504071306426f73746f6e311630140603550408130d4d617373616368757365747473310b3009060355040613025553312e302c060355040313254c6f
EAP-Message =
0x63616c2043757272656e73656520436572746966696361746520417574686f72697479301e170d3131313032313135313134335a170d3231313032303135313134335a3077310b3009060355040613025553311630140603550408130d4d61737361636875736574747331183016060355040a130f43757272656e7365652c20496e632e31133011060355040b130a4f7065726174696f6e733121301f060355040313186f7073322e6c6f63616c2e63757272656e7365652e636f6d30819f300d06092a864886f70d010101050003818d0030818902818100dbd67230f6e9b1f8d37cd689371e4965f6760ef34369b95ea48e1ef153be887b5dd5ef31
EAP-Message =
0x7a47e5d66048731d7458d9ae1ebe0508aa349d4fa74dd0c077cdca1fb2af2868d309e938cd6222f3c6737116ff656e10bbb175b76e2aa83c35efc2b0655f3bf669cabbad375d98d89c84f9d30b5887ac5225685c5bee55176ce2fe890203010001300d06092a864886f70d01010405000381810023558f75bca5500a1b7ca225f46cd98622ef05c01cc43e000dcae1cd19b8d8fcf7c53d2dff7c6403781839d0dd4a0bffb4eec337967c32665ee5f11720e09760c222e2fc6a029b0d4eb33c45614d21a6fb55cb6f01df47958d97578160057f0d23aa685539931ad0229522218b7d7c31f9fb1b8e94a9b88d6e8bc4f410a9701400041a308204163082
EAP-Message =
0x037fa003020102020900d869d83ec24831ce300d06092a864886f70d01010405003081b931183016060355040a130f43757272656e7365652c20496e632e31143012060355040b130b456e67696e656572696e673121301f06092a864886f70d0109011612726f6f744063757272656e7365652e636f6d310f300d06035504071306426f73746f6e311630140603550408130d4d617373616368757365747473310b3009060355040613025553312e302c060355040313254c6f63616c2043757272656e73656520436572746966696361746520417574686f72697479301e170d3130303432363138323634325a170d3230303432353138323634325a
EAP-Message = 0x3081b931183016060355040a
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x89f1065d88f51f4f1edcaaacea389153
Finished request 1.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.10.31 port 1645,
id=217, length=141
User-Name = "marguin"
Framed-MTU = 1400
Called-Station-Id = "64a0.e72f.69c0"
Calling-Station-Id = "001e.5273.4858"
Service-Type = Login-User
Message-Authenticator = 0x2fef04ad0daf8fc25c5658adb07eb75b
EAP-Message = 0x020400061900
NAS-Port-Type = Wireless-802.11
NAS-Port = 2658
NAS-Port-Id = "2658"
State = 0x89f1065d88f51f4f1edcaaacea389153
NAS-IP-Address = 192.168.10.31
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 4 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1
[peap] eaptls_process returned 13
[peap] EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 217 to 192.168.10.31 port 1645
EAP-Message =
0x0105031a1900130f43757272656e7365652c20496e632e31143012060355040b130b456e67696e656572696e673121301f06092a864886f70d0109011612726f6f744063757272656e7365652e636f6d310f300d06035504071306426f73746f6e311630140603550408130d4d617373616368757365747473310b3009060355040613025553312e302c060355040313254c6f63616c2043757272656e73656520436572746966696361746520417574686f7269747930819f300d06092a864886f70d010101050003818d0030818902818100d6e8fe8f9e3905fcd63f0c9f3b9eded323e8b7a1e47ef23d8d53a29572e41656e189ccd616664ad52ea7
EAP-Message =
0x36ee86a2e1fe0696e1fe24e0345cd5b3167530ef0d6b7a58f9f55774d7a403b9a03e5d9374118a1dbb30fcab8c8bc499ef62b3aac1aec00134b635416c73e2f555b24e08933cefe2fb2a47024ee61ab51490f1cae3070203010001a38201223082011e300c0603551d13040530030101ff301d0603551d0e04160414706ed0933d93523470a6e9bc979d124333df14b03081ee0603551d230481e63081e38014706ed0933d93523470a6e9bc979d124333df14b0a181bfa481bc3081b931183016060355040a130f43757272656e7365652c20496e632e31143012060355040b130b456e67696e656572696e673121301f06092a864886f70d01090116
EAP-Message =
0x12726f6f744063757272656e7365652e636f6d310f300d06035504071306426f73746f6e311630140603550408130d4d617373616368757365747473310b3009060355040613025553312e302c060355040313254c6f63616c2043757272656e73656520436572746966696361746520417574686f72697479820900d869d83ec24831ce300d06092a864886f70d010104050003818100d435d275a02b5e04e17e75b6046bbd1ab3ca33299cee907f2bd9c7603b3da4a23ee97e677e97e442bd855e8c2dffc351e134e03fbec16ad71eb7608c62c29bd2a2aaa2660013bc8d76520a5a9f3b516dcbddf6a773564e57c29e20d0a614a6116a36aef3cdfb
EAP-Message =
0xdc510f1058d291e6310d9b53c8b17e521038a866f3510355ef2916030100040e000000
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x89f1065d8bf41f4f1edcaaacea389153
Finished request 2.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.10.31 port 1645,
id=218, length=343
User-Name = "marguin"
Framed-MTU = 1400
Called-Station-Id = "64a0.e72f.69c0"
Calling-Station-Id = "001e.5273.4858"
Service-Type = Login-User
Message-Authenticator = 0x6486cedcf368658f1ac009c0840251ca
EAP-Message =
0x020500d01980000000c616030100861000008200803dc6943c4914148a900e1702d8ee8987d0bc583cb75e1780b2b5c7765eba71cf74b70d417d0eb2cb3e8d58ebea0d9a1ed7b728c9cd2af2552b257dee8a82e43769183f905ece2a31908875dcd1f28206e95a42eaf7d15bfbd18cf3552921bf9d9e20ccf74668b61e218a80e80aee283d572a3e6eb1d90f6f02747523ff11c48214030100010116030100306760329b805ead4f68860983c061d59dab23f5dc4f3dd285e483cb7ee1813a4f5c68605ba2584cec0221c8617dd20ea6
NAS-Port-Type = Wireless-802.11
NAS-Port = 2658
NAS-Port-Id = "2658"
State = 0x89f1065d8bf41f4f1edcaaacea389153
NAS-IP-Address = 192.168.10.31
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 5 length 208
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
TLS Length 198
[peap] Length Included
[peap] eaptls_verify returned 11
[peap] <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange
[peap] TLS_accept: SSLv3 read client key exchange A
[peap] <<< TLS 1.0 ChangeCipherSpec [length 0001]
[peap] <<< TLS 1.0 Handshake [length 0010], Finished
[peap] TLS_accept: SSLv3 read finished A
[peap] >>> TLS 1.0 ChangeCipherSpec [length 0001]
[peap] TLS_accept: SSLv3 write change cipher spec A
[peap] >>> TLS 1.0 Handshake [length 0010], Finished
[peap] TLS_accept: SSLv3 write finished A
[peap] TLS_accept: SSLv3 flush data
[peap] (other): SSL negotiation finished successfully
SSL Connection Established
[peap] eaptls_process returned 13
[peap] EAPTLS_HANDLED
++[eap] returns handled
Sending Access-Challenge of id 218 to 192.168.10.31 port 1645
EAP-Message =
0x01060041190014030100010116030100304303f9ea6bcd1acd5df76daa0c1644a13fa5bb07a55591fafe48c0450833bd54273446ec5ac97134a35b099238ffd2bd
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x89f1065d8af71f4f1edcaaacea389153
Finished request 3.
Going to the next request
Waking up in 4.9 seconds.
Cleaning up request 0 ID 215 with timestamp +28
Cleaning up request 1 ID 216 with timestamp +28
Cleaning up request 2 ID 217 with timestamp +28
Cleaning up request 3 ID 218 with timestamp +28
WARNING:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
WARNING: !! EAP session for state 0x89f1065d8af71f4f did not finish!
WARNING: !! Please read http://wiki.freeradius.org/Certificate_Compatibility
WARNING:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Ready to process requests.
rad_recv: Access-Request packet from host 192.168.10.31 port 1645,
id=219, length=141
User-Name = "marguin"
Framed-MTU = 1400
Called-Station-Id = "64a0.e72f.69c0"
Calling-Station-Id = "001e.5273.4858"
Service-Type = Login-User
Message-Authenticator = 0x739b73dd50f560d8225a81b34573a4a7
EAP-Message = 0x020600061900
NAS-Port-Type = Wireless-802.11
NAS-Port = 2658
NAS-Port-Id = "2658"
State = 0x89f1065d8af71f4f1edcaaacea389153
NAS-IP-Address = 192.168.10.31
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 6 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake is finished
[peap] eaptls_verify returned 3
[peap] eaptls_process returned 3
[peap] EAPTLS_SUCCESS
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state TUNNEL ESTABLISHED
++[eap] returns handled
Sending Access-Challenge of id 219 to 192.168.10.31 port 1645
EAP-Message =
0x0107002b19001703010020e070168325d6bf65dbf125757cd93e2f39b2be90636f354dad19e3bffc763f18
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x89f1065d8df61f4f1edcaaacea389153
Finished request 4.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.10.31 port 1645,
id=220, length=178
User-Name = "marguin"
Framed-MTU = 1400
Called-Station-Id = "64a0.e72f.69c0"
Calling-Station-Id = "001e.5273.4858"
Service-Type = Login-User
Message-Authenticator = 0x51be84fc57ad005327459d7bf2508b03
EAP-Message =
0x0207002b19001703010020b69cc3f579947cc74451eebc8d55253fcb59470683540101774f0160ac4e20e6
NAS-Port-Type = Wireless-802.11
NAS-Port = 2658
NAS-Port-Id = "2658"
State = 0x89f1065d8df61f4f1edcaaacea389153
NAS-IP-Address = 192.168.10.31
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 43
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state WAITING FOR INNER IDENTITY
[peap] Identity - marguin
[peap] Got inner identity 'marguin'
[peap] Setting default EAP type for tunneled EAP session.
[peap] Got tunneled request
EAP-Message = 0x0207000c016d61726775696e
server {
[peap] Setting User-Name to marguin
Sending tunneled request
EAP-Message = 0x0207000c016d61726775696e
FreeRADIUS-Proxied-To = 127.0.0.1
User-Name = "marguin"
server inner-tunnel {
# Executing section authorize from file
/etc/raddb/sites-enabled/inner-tunnel
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] EAP packet type response id 7 length 12
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
[ldap] performing user authorization for marguin
[ldap] expand: %{Stripped-User-Name} ->
[ldap] ... expanding second conditional
[ldap] expand: %{User-Name} -> marguin
[ldap] expand: (uid=%{%{Stripped-User-Name}:-%{User-Name}}) ->
(uid=marguin)
[ldap] expand: ou=people,dc=currensee,dc=com ->
ou=people,dc=currensee,dc=com
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in ou=people,dc=currensee,dc=com, with
filter (uid=marguin)
request done: ld 0x1facdf30 msgid 3
[ldap] checking if remote access for marguin is allowed by uid
[ldap] looking for check items in directory...
[ldap] userPassword -> Password-With-Header == "{CRYPT}WgRn.wiPxI6Tk"
[ldap] looking for reply items in directory...
[ldap] user marguin authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING: Auth-Type already set. Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
[peap] Got tunneled reply code 11
EAP-Message =
0x010800211a0108001c10162a56370ce0ab80767414d8abfb25486d61726775696e
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x2b2960c02b217a4e71d440973551574b
[peap] Got tunneled reply RADIUS code 11
EAP-Message =
0x010800211a0108001c10162a56370ce0ab80767414d8abfb25486d61726775696e
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x2b2960c02b217a4e71d440973551574b
[peap] Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 220 to 192.168.10.31 port 1645
EAP-Message =
0x0108004b19001703010040ce3d61076b12b99a3e4585a7c13cfa32c9b1fab601dca0271dbf8a13bd4b7ac08db1b5a9fbb630783357a9e7ffefdd5d729c9ce5298341277279a2f890dd2797
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x89f1065d8cf91f4f1edcaaacea389153
Finished request 5.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.10.31 port 1645,
id=221, length=242
User-Name = "marguin"
Framed-MTU = 1400
Called-Station-Id = "64a0.e72f.69c0"
Calling-Station-Id = "001e.5273.4858"
Service-Type = Login-User
Message-Authenticator = 0xa42f6af151fab3cbc3c37097202cc15b
EAP-Message =
0x0208006b1900170301006025cee42a47eed87aa4cbd0d2d1c78f3eecf22b6637712f1201fc1a14b1764025adb9ad700d880c6b51f116500593cd0e72c8e0e7221281cf93e116ea7f7792568d9e717607af5b364e4409959a9db88755383cd6679262c5a5bd10210424a9a0
NAS-Port-Type = Wireless-802.11
NAS-Port = 2658
NAS-Port-Id = "2658"
State = 0x89f1065d8cf91f4f1edcaaacea389153
NAS-IP-Address = 192.168.10.31
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 8 length 107
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state phase2
[peap] EAP type mschapv2
[peap] Got tunneled request
EAP-Message =
0x020800421a0208003d31909dc14eec97e73e0a72148e501ca5130000000000000000fab91e4aa6e4c9a87b9259d1532db0e295ebe2213eda1462006d61726775696e
server {
[peap] Setting User-Name to marguin
Sending tunneled request
EAP-Message =
0x020800421a0208003d31909dc14eec97e73e0a72148e501ca5130000000000000000fab91e4aa6e4c9a87b9259d1532db0e295ebe2213eda1462006d61726775696e
FreeRADIUS-Proxied-To = 127.0.0.1
User-Name = "marguin"
State = 0x2b2960c02b217a4e71d440973551574b
server inner-tunnel {
# Executing section authorize from file
/etc/raddb/sites-enabled/inner-tunnel
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] EAP packet type response id 8 length 66
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
[ldap] performing user authorization for marguin
[ldap] expand: %{Stripped-User-Name} ->
[ldap] ... expanding second conditional
[ldap] expand: %{User-Name} -> marguin
[ldap] expand: (uid=%{%{Stripped-User-Name}:-%{User-Name}}) ->
(uid=marguin)
[ldap] expand: ou=people,dc=currensee,dc=com ->
ou=people,dc=currensee,dc=com
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in ou=people,dc=currensee,dc=com, with
filter (uid=marguin)
request done: ld 0x1facdf30 msgid 4
[ldap] checking if remote access for marguin is allowed by uid
[ldap] looking for check items in directory...
[ldap] userPassword -> Password-With-Header == "{CRYPT}WgRn.wiPxI6Tk"
[ldap] looking for reply items in directory...
[ldap] user marguin authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING: Auth-Type already set. Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/mschapv2
[eap] processing type mschapv2
[mschapv2] # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
[mschapv2] +- entering group MS-CHAP {...}
[mschap] No Cleartext-Password configured. Cannot create LM-Password.
[mschap] No Cleartext-Password configured. Cannot create NT-Password.
[mschap] Creating challenge hash with username: marguin
[mschap] Told to do MS-CHAPv2 for marguin with NT-Password
[mschap] FAILED: No NT/LM-Password. Cannot perform authentication.
[mschap] FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
[eap] Freeing handler
++[eap] returns reject
Failed to authenticate the user.
} # server inner-tunnel
[peap] Got tunneled reply code 3
MS-CHAP-Error = "\010E=691 R=1"
EAP-Message = 0x04080004
Message-Authenticator = 0x00000000000000000000000000000000
[peap] Got tunneled reply RADIUS code 3
MS-CHAP-Error = "\010E=691 R=1"
EAP-Message = 0x04080004
Message-Authenticator = 0x00000000000000000000000000000000
[peap] Tunneled authentication was rejected.
[peap] FAILURE
++[eap] returns handled
Sending Access-Challenge of id 221 to 192.168.10.31 port 1645
EAP-Message =
0x0109002b19001703010020461bb03d763ae49d928d168b37006c190b066e2e5f291152d26e975eb8676af0
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x89f1065d8ff81f4f1edcaaacea389153
Finished request 6.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host 192.168.10.31 port 1645,
id=222, length=178
User-Name = "marguin"
Framed-MTU = 1400
Called-Station-Id = "64a0.e72f.69c0"
Calling-Station-Id = "001e.5273.4858"
Service-Type = Login-User
Message-Authenticator = 0xbe91fe2cf8cdbe0b2ab144028a6c71dd
EAP-Message =
0x0209002b190017030100203c08a31c5ec50023018f8534d0d652cde9744b100ba72bcf3eb8391a726d3dc3
NAS-Port-Type = Wireless-802.11
NAS-Port = 2658
NAS-Port-Id = "2658"
State = 0x89f1065d8ff81f4f1edcaaacea389153
NAS-IP-Address = 192.168.10.31
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "marguin", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 9 length 43
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state send tlv failure
[peap] Received EAP-TLV response.
[peap] The users session was previously rejected: returning reject (again.)
[peap] *** This means you need to read the PREVIOUS messages in the
debug output
[peap] *** to find out the reason why the user was rejected.
[peap] *** Look for "reject" or "fail". Those earlier messages will
tell you.
[peap] *** what went wrong, and how to fix the problem.
[eap] Handler failed in EAP/peap
[eap] Failed in EAP select
++[eap] returns invalid
Failed to authenticate the user.
Using Post-Auth-Type Reject
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group REJECT {...}
[attr_filter.access_reject] expand: %{User-Name} -> marguin
attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 7 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 7
Sending Access-Reject of id 222 to 192.168.10.31 port 1645
EAP-Message = 0x04090004
Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 2.6 seconds.
Cleaning up request 4 ID 219 with timestamp +40
Cleaning up request 5 ID 220 with timestamp +40
Cleaning up request 6 ID 221 with timestamp +40
Waking up in 2.2 seconds.
Cleaning up request 7 ID 222 with timestamp +41
Ready to process requests.
On 11/3/2011 2:40 PM, freeradius-users-request(a)lists.freeradius.org wrote:
> cisco WAP/FreeRadius/OpenLDAP
--
Matthew Arguin
Currensee, Inc.
54 Canal St, 4th Floor
Boston, MA 02114
(617) 986-4758 (Office)
_________________________________________________________________________
This email and any files transmitted with it are confidential and intended solely for the addressee. If you received this email in error, please do not disclose the contents to anyone; kindly notify the sender by return email and delete this email and any attachments from your system.
© 2011 Currensee Inc. is a member of the National Futures Association (NFA) Member ID 0403251 | Over the counter retail foreign currency (Forex) trading may involve significant risk of loss. It is not suitable for all investors and you should make sure you understand the risks involved before trading and seek independent advice if necessary. Performance, strategies and charts shown are not necessarily predictive of any particular result and past performance is no indication of future results. Investor returns may vary from Trade Leader returns based on slippage, fees, broker spreads, volatility or other market conditions.
Currensee Inc | 54 Canal St 4th Floor | Boston, MA 02114 | +1.617.624.3824
2
1
According to
http://wiki.freeradius.org/Build#Building+Debian+packages
a debian package can be compiled from freeradius sources.
On squeeze it fails. Mabe it has to do with libtool?
Is there a known workaround?
libtool: compile: gcc -g -O2 -O2 -Wall -D_GNU_SOURCE -D_REENTRANT -D_POSIX_PTHREAD_SEMANTICS -g -Wshadow -Wpointer-arith -Wcast-qual -Wcast-align -Wwrite-strings -Wstrict-prototypes -Wmissing-prototypes -Wmissing-declarations -Wnested-externs -W -Wredundant-decls -Wundef -I/root/radius/freeradius-server-2.1.12/src -DHOSTINFO=\"arm-unknown-linux-gnueabi\" -DRADIUSD_VERSION=\"2.1.12\" -DOPENSSL_NO_KRB5 -DRADIUSD_MAJOR_VERSION=2 -DRADIUSD_MINOR_VERSION=1.12 -c modules.c -fPIC -DPIC -o .libs/modules.o
modules.c: In function 'fr_dlopenext':
modules.c:216: error: 'lt_dladvise' undeclared (first use in this function)
modules.c:216: error: (Each undeclared identifier is reported only once
modules.c:216: error: for each function it appears in.)
modules.c:216: error: expected ';' before 'advise'
modules.c:218: warning: implicit declaration of function 'lt_dladvise_init'
modules.c:218: warning: nested extern declaration of 'lt_dladvise_init'
modules.c:218: error: 'advise' undeclared (first use in this function)
modules.c:219: warning: implicit declaration of function 'lt_dladvise_ext'
modules.c:219: warning: nested extern declaration of 'lt_dladvise_ext'
modules.c:220: warning: implicit declaration of function 'lt_dladvise_global'
modules.c:220: warning: nested extern declaration of 'lt_dladvise_global'
modules.c:221: warning: implicit declaration of function 'lt_dlopenadvise'
modules.c:221: warning: nested extern declaration of 'lt_dlopenadvise'
modules.c:224: warning: implicit declaration of function 'lt_dladvise_destroy'
modules.c:224: warning: nested extern declaration of 'lt_dladvise_destroy'
modules.c: In function 'setup_modules':
modules.c:1409: warning: nested extern declaration of 'lt_preloaded_symbols'
make[5]: *** [modules.lo] Error 1
make[5]: Leaving directory `/root/radius/freeradius-server-2.1.12/src/main'
make[4]: *** [main] Error 2
make[4]: Leaving directory `/root/radius/freeradius-server-2.1.12/src'
make[3]: *** [all] Error 2
make[3]: Leaving directory `/root/radius/freeradius-server-2.1.12/src'
make[2]: *** [src] Error 2
make[2]: Leaving directory `/root/radius/freeradius-server-2.1.12'
make[1]: *** [all] Error 2
make[1]: Leaving directory `/root/radius/freeradius-server-2.1.12'
make: *** [build-arch-stamp] Error 2
dpkg-buildpackage: error: debian/rules build gave error exit status 2
With best regards,
________________________________
Norbert Wegener
Atos IT Solutions and Services
AIS MS NC PSU SDC
Bruchstraße 5
45883 Gelsenkirchen, Germany
Tel.: +49 (209) 94565716
Fax: +49 (201) 8165581284
mailto:norbert.wegener@atos.net
Atos IT Solutions and Services GmbH; Geschäftsführung: Winfried Holz, Christian Oecking, Rainer-Christian Koppitz; Vorsitzender des Aufsichtsrats: Charles Dehelly; Sitz der Gesellschaft: München, Deutschland; Registergericht: München, HRB 184933.
2
3
Hello.
I am running 2.1.10. Is it possible to log to files and syslog (both)?
Regards
Mika
--
View this message in context: http://freeradius.1045715.n5.nabble.com/Logging-to-destination-files-AND-sy…
Sent from the FreeRadius - User mailing list archive at Nabble.com.
2
1
I've searched for this sort of posting, but found issues unrelated that
responded to my search string, so I decided to post it here.
OK, currently I have Radius authenticating LDAP users via PAP. Works great.
Imagine I want to store x509 certificate data (specifically a client
certificate) in an attribute in LDAP (perhaps as a binary attribute, etc).
I would like FreeRADIUS, should it be passed a client certificate INSTEAD of
a user/pass, to take the DN of the cert and match it to some attribute which
contains said DN and cert-data.
The ultimate goal of all of this is to allow the continued use of LDAP and
store the certificates (to be compared against) in the tree and not on some
filesystem basis.
Note that I want FreeRADIUS to continue supporting PAP user/pass auth, but
only as a secondary fall-back (e.g: customer doesn't have client cert
installed on machine, but has a user and password).
Is this possible? Does this make sense to you? Let me know if I need to
re-explain anything.
Thank you,
subcon
--
View this message in context: http://freeradius.1045715.n5.nabble.com/FreeRADIUS-EAP-TLS-Lookup-Client-Ce…
Sent from the FreeRadius - User mailing list archive at Nabble.com.
4
4
Hi. Yet another MSCHAPv2 thread.
It's related to this one:
http://lists.cistron.nl/pipermail/freeradius-users/2008-July/msg00156.html
(I will post my output if needed, but I believe is almost the same)
Ivan Kalik states "That's because it's doing EAP mschapv2 not plain
mschap. It's normal
to get a couple more Challenge-Requests before process is over." but
neither Windows nor Ubuntu answer that challenge beyond that point.
The thread ends with "Problem solved: ntlm_auth of Samba 3.2.0 seems
not to work with Freeradius 2.0.5. After downgrading Samba to 3.0.29
everything is fine again." which contrasts with the
"
rlm_mschap: adding MS-CHAPv2 MPPE keys
++[mschap] returns ok
MSCHAP Success
"
part. Also, I'd like to know a little more about the ntlm_auth issue
before downgrading (I hate to do that).
Thanks.
3
2