Freeradius-Users
Threads by month
- ----- 2026 -----
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 27049 discussions
Hi
I'm using freeradius with ldap users and mschap + peap. But i have one
problem. When a user gets his login prompt, no access to the network is
allowed because they first get access when they login and freeradius can
perform an ldap check with the username.
But when a new user wants to login or the user uses an different computer,
the user dosen't exist on this machine -> so they can't login -> no network
connection ->can't load profile -> no local user.
So i have tested a little bit with guest vlan ... but this didn't solve my
problem. What can i do to solve this issue?
I think it will be possible if alle users get access to an restricted vlan
before they login with their user credentials. Then the profile can be
loaded from server and then the user can validate. But how can i do this,
that every user get access before login?
I'll hope you understand my problem und you can give me some futher hints
what i can do to solve this.
best regards
--
View this message in context: http://freeradius.1045715.n5.nabble.com/Grant-access-for-all-users-before-l…
Sent from the FreeRadius - User mailing list archive at Nabble.com.
2
4
sltd wrote:
>
> No authenticate method (Auth-Type) configuration found for the request:
> Rejecting the user
> Failed to authenticate the user.
>
What authentication do you want to use!? the user file? you should enable
your prefered authentification!!!!!
--
View this message in context: http://freeradius.1045715.n5.nabble.com/Problem-with-authenticate-method-Au…
Sent from the FreeRadius - User mailing list archive at Nabble.com.
1
0
Hello ... my name is Jorge
I raised a question I am making the draft validation of users by MAC address and my question is not that high given file directions Mac, I installed before 1.2.1910 Freeradius a virtual machine VirtualBox-3.2.8 Win-64453-OS "Ubuntu 9.10" in the / raddb belonging to freeradius files are "users" and "clients.conf" which amended. your help will be very important ........
1
1
TLS authentication works, but does not check usernames against 'users' file.
by Andrew Bovill 30 Nov '10
by Andrew Bovill 30 Nov '10
30 Nov '10
Hi,
I'm trying to get WPA Enterprise EAP/TLS working with my wireless
router. It appears that the TLS portion of the authentication works
(valid certificates give me a working connection) but it does NOT appear
to actually be checking the username/password combination that is also
sent along the line.
I have followed the WPA_HOWTO as best I could (my clients are OS X and
Android and Gentoo, not Windows XP) but I can't figure out how to 'fail'
an auth attempt with an invalid user/pass combination.
Here is the debug output:
Thanks for any advice. I didn't want to start reconfiguring with a
shotgun :)
freeradius -X
FreeRADIUS Version 2.1.10, for host i486-pc-linux-gnu, built on Nov 17
2010 at 04:06:04
Copyright (C) 1999-2009 The FreeRADIUS server project and contributors.
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE.
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License v2.
Starting - reading configuration files ...
including configuration file /etc/freeradius/radiusd.conf
including configuration file /etc/freeradius/proxy.conf
including configuration file /etc/freeradius/clients.conf
including files in directory /etc/freeradius/modules/
including configuration file /etc/freeradius/modules/passwd
including configuration file /etc/freeradius/modules/inner-eap
including configuration file /etc/freeradius/modules/pam
including configuration file /etc/freeradius/modules/checkval
including configuration file /etc/freeradius/modules/detail
including configuration file /etc/freeradius/modules/mschap
including configuration file /etc/freeradius/modules/chap
including configuration file /etc/freeradius/modules/realm
including configuration file /etc/freeradius/modules/echo
including configuration file
/etc/freeradius/modules/sqlcounter_expire_on_login
including configuration file /etc/freeradius/modules/perl
including configuration file /etc/freeradius/modules/krb5
including configuration file /etc/freeradius/modules/opendirectory
including configuration file /etc/freeradius/modules/counter
including configuration file /etc/freeradius/modules/smbpasswd
including configuration file /etc/freeradius/modules/attr_filter
including configuration file /etc/freeradius/modules/smsotp
including configuration file /etc/freeradius/modules/ntlm_auth
including configuration file /etc/freeradius/modules/detail.example.com
including configuration file /etc/freeradius/modules/cui
including configuration file /etc/freeradius/modules/logintime
including configuration file /etc/freeradius/modules/policy
including configuration file /etc/freeradius/modules/expiration
including configuration file /etc/freeradius/modules/always
including configuration file /etc/freeradius/modules/exec
including configuration file /etc/freeradius/modules/linelog
including configuration file /etc/freeradius/modules/detail.log
including configuration file /etc/freeradius/modules/files
including configuration file /etc/freeradius/modules/mac2vlan
including configuration file /etc/freeradius/modules/ldap
including configuration file /etc/freeradius/modules/sql_log
including configuration file /etc/freeradius/modules/attr_rewrite
including configuration file /etc/freeradius/modules/expr
including configuration file /etc/freeradius/modules/mac2ip
including configuration file /etc/freeradius/modules/ippool
including configuration file /etc/freeradius/modules/dynamic_clients
including configuration file /etc/freeradius/modules/otp
including configuration file /etc/freeradius/modules/sradutmp
including configuration file /etc/freeradius/modules/wimax
including configuration file /etc/freeradius/modules/acct_unique
including configuration file /etc/freeradius/modules/preprocess
including configuration file /etc/freeradius/modules/etc_group
including configuration file /etc/freeradius/modules/digest
including configuration file /etc/freeradius/modules/unix
including configuration file /etc/freeradius/modules/radutmp
including configuration file /etc/freeradius/modules/pap
including configuration file /etc/freeradius/eap.conf
including configuration file /etc/freeradius/policy.conf
including files in directory /etc/freeradius/sites-enabled/
including configuration file /etc/freeradius/sites-enabled/inner-tunnel
including configuration file /etc/freeradius/sites-enabled/default
main {
user = "freerad"
group = "freerad"
allow_core_dumps = no
}
including dictionary file /etc/freeradius/dictionary
main {
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/freeradius"
libdir = "/usr/lib/freeradius"
radacctdir = "/var/log/freeradius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 1024
pidfile = "/var/run/freeradius/freeradius.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
}
security {
max_attributes = 200
reject_delay = 1
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = "testing123"
response_window = 20
max_outstanding = 65536
require_message_authenticator = yes
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
num_answers_to_alive = 3
num_pings_to_alive = 3
revive_interval = 120
status_check_timeout = 4
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = "testing123"
nastype = "other"
}
client 3com4400_1 {
ipaddr = 192.168.183.5
netmask = 32
require_message_authenticator = no
secret = "testing123"
nastype = "other"
}
client wrt54gl_testbed {
ipaddr = 192.168.183.110
netmask = 32
require_message_authenticator = no
secret = "testing123"
nastype = "other"
}
radiusd: #### Instantiating modules ####
instantiate {
Module: Linked to module rlm_exec
Module: Instantiating module "exec" from file /etc/freeradius/modules/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
}
Module: Linked to module rlm_expr
Module: Instantiating module "expr" from file /etc/freeradius/modules/expr
Module: Linked to module rlm_expiration
Module: Instantiating module "expiration" from file
/etc/freeradius/modules/expiration
expiration {
reply-message = "Password Has Expired "
}
Module: Linked to module rlm_logintime
Module: Instantiating module "logintime" from file
/etc/freeradius/modules/logintime
logintime {
reply-message = "You are calling outside your allowed timespan "
minimum-timeout = 60
}
}
radiusd: #### Loading Virtual Servers ####
server inner-tunnel { # from file /etc/freeradius/sites-enabled/inner-tunnel
modules {
Module: Checking authenticate {...} for more modules to load
Module: Linked to module rlm_pap
Module: Instantiating module "pap" from file /etc/freeradius/modules/pap
pap {
encryption_scheme = "auto"
auto_header = no
}
Module: Linked to module rlm_chap
Module: Instantiating module "chap" from file /etc/freeradius/modules/chap
Module: Linked to module rlm_mschap
Module: Instantiating module "mschap" from file
/etc/freeradius/modules/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = no
}
Module: Linked to module rlm_unix
Module: Instantiating module "unix" from file /etc/freeradius/modules/unix
unix {
radwtmp = "/var/log/freeradius/radwtmp"
}
Module: Linked to module rlm_eap
Module: Instantiating module "eap" from file /etc/freeradius/eap.conf
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 4096
}
Module: Linked to sub-module rlm_eap_md5
Module: Instantiating eap-md5
Module: Linked to sub-module rlm_eap_leap
Module: Instantiating eap-leap
Module: Linked to sub-module rlm_eap_gtc
Module: Instantiating eap-gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
Module: Linked to sub-module rlm_eap_tls
Module: Instantiating eap-tls
tls {
rsa_key_exchange = no
dh_key_exchange = yes
rsa_key_length = 512
dh_key_length = 512
verify_depth = 0
CA_path = "/etc/freeradius/certs"
pem_file_type = yes
private_key_file = "/etc/freeradius/certs/server.key"
certificate_file = "/etc/freeradius/certs/server.pem"
CA_file = "/etc/freeradius/certs/ca.pem"
private_key_password = "whatever"
dh_file = "/etc/freeradius/certs/dh"
random_file = "/dev/urandom"
fragment_size = 1024
include_length = yes
check_crl = no
cipher_list = "DEFAULT"
make_cert_command = "/etc/freeradius/certs/bootstrap"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
}
}
Module: Linked to sub-module rlm_eap_ttls
Module: Instantiating eap-ttls
ttls {
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
}
Module: Linked to sub-module rlm_eap_peap
Module: Instantiating eap-peap
peap {
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
}
Module: Linked to sub-module rlm_eap_mschapv2
Module: Instantiating eap-mschapv2
mschapv2 {
with_ntdomain_hack = no
}
Module: Checking authorize {...} for more modules to load
Module: Linked to module rlm_realm
Module: Instantiating module "suffix" from file
/etc/freeradius/modules/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
Module: Linked to module rlm_files
Module: Instantiating module "files" from file
/etc/freeradius/modules/files
files {
usersfile = "/etc/freeradius/users"
acctusersfile = "/etc/freeradius/acct_users"
preproxy_usersfile = "/etc/freeradius/preproxy_users"
compat = "no"
}
Module: Checking session {...} for more modules to load
Module: Linked to module rlm_radutmp
Module: Instantiating module "radutmp" from file
/etc/freeradius/modules/radutmp
radutmp {
filename = "/var/log/freeradius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
perm = 384
callerid = yes
}
Module: Checking post-proxy {...} for more modules to load
Module: Checking post-auth {...} for more modules to load
Module: Linked to module rlm_attr_filter
Module: Instantiating module "attr_filter.access_reject" from file
/etc/freeradius/modules/attr_filter
attr_filter attr_filter.access_reject {
attrsfile = "/etc/freeradius/attrs.access_reject"
key = "%{User-Name}"
}
} # modules
} # server
server { # from file /etc/freeradius/radiusd.conf
modules {
Module: Checking authenticate {...} for more modules to load
Module: Linked to module rlm_digest
Module: Instantiating module "digest" from file
/etc/freeradius/modules/digest
Module: Checking authorize {...} for more modules to load
Module: Linked to module rlm_preprocess
Module: Instantiating module "preprocess" from file
/etc/freeradius/modules/preprocess
preprocess {
huntgroups = "/etc/freeradius/huntgroups"
hints = "/etc/freeradius/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
Module: Checking preacct {...} for more modules to load
Module: Linked to module rlm_acct_unique
Module: Instantiating module "acct_unique" from file
/etc/freeradius/modules/acct_unique
acct_unique {
key = "User-Name, Acct-Session-Id, NAS-IP-Address,
Client-IP-Address, NAS-Port"
}
Module: Checking accounting {...} for more modules to load
Module: Linked to module rlm_detail
Module: Instantiating module "detail" from file
/etc/freeradius/modules/detail
detail {
detailfile =
"/var/log/freeradius/radacct/%{Client-IP-Address}/detail-%Y%m%d"
header = "%t"
detailperm = 384
dirperm = 493
locking = no
log_packet_header = no
}
Module: Instantiating module "attr_filter.accounting_response" from
file /etc/freeradius/modules/attr_filter
attr_filter attr_filter.accounting_response {
attrsfile = "/etc/freeradius/attrs.accounting_response"
key = "%{User-Name}"
}
Module: Checking session {...} for more modules to load
Module: Checking post-proxy {...} for more modules to load
Module: Checking post-auth {...} for more modules to load
} # modules
} # server
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *
port = 0
}
listen {
type = "acct"
ipaddr = *
port = 0
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on authentication address * port 1812
Listening on accounting address * port 1813
Listening on authentication address 127.0.0.1 port 18120 as server
inner-tunnel
Listening on proxy address * port 1814
Ready to process requests.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=70, length=154
User-Name = "invaliduser1"
NAS-Identifier = "openwrt"
NAS-Port = 1
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-17-F2-E7-39-C0"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02d4000a01706f6f7079
Message-Authenticator = 0x96155aae1c1a13904212926041844222
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser1", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 212 length 10
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user.
Authentication may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type md5
rlm_eap_md5: Issuing Challenge
++[eap] returns handled
Sending Access-Challenge of id 70 to 192.168.183.110 port 55425
EAP-Message = 0x01d5001604104b7e073f1d295b16bd346d251f67ed9b
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x1925f89c19f0fce511765369958e0fff
Finished request 0.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=71, length=168
User-Name = "invaliduser1"
NAS-Identifier = "openwrt"
NAS-Port = 1
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-17-F2-E7-39-C0"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02d50006030d
State = 0x1925f89c19f0fce511765369958e0fff
Message-Authenticator = 0xfb81366232f27755b84f3d53880e6793
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser1", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 213 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user.
Authentication may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP NAK
[eap] EAP-NAK asked for EAP-Type/tls
[eap] processing type tls
[tls] Requiring client certificate
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 71 to 192.168.183.110 port 55425
EAP-Message = 0x01d600060d20
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x1925f89c18f3f5e511765369958e0fff
Finished request 1.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=72, length=274
User-Name = "invaliduser1"
NAS-Identifier = "openwrt"
NAS-Port = 1
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-17-F2-E7-39-C0"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x02d600700d800000006616030100610100005d03014cf47dccabafcd6559461322e0d11b2781c65dca5f1d237073c77169593a5ace000036002f000500040035000a000900030008000600320033003800390016001500140013001200110034003a0018001b001a0017001900010100
State = 0x1925f89c18f3f5e511765369958e0fff
Message-Authenticator = 0x7d9b552c05313f4f8e4e66559782ed1e
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser1", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 214 length 112
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
TLS Length 102
[tls] Length Included
[tls] eaptls_verify returned 11
[tls] (other): before/accept initialization
[tls] TLS_accept: before/accept initialization
[tls] <<< TLS 1.0 Handshake [length 0061], ClientHello
[tls] TLS_accept: SSLv3 read client hello A
[tls] >>> TLS 1.0 Handshake [length 002a], ServerHello
[tls] TLS_accept: SSLv3 write server hello A
[tls] >>> TLS 1.0 Handshake [length 0861], Certificate
[tls] TLS_accept: SSLv3 write certificate A
[tls] >>> TLS 1.0 Handshake [length 00a7], CertificateRequest
[tls] TLS_accept: SSLv3 write certificate request A
[tls] TLS_accept: SSLv3 flush data
[tls] TLS_accept: Need to read more data: SSLv3 read client
certificate A
In SSL Handshake Phase
In SSL Accept mode
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 72 to 192.168.183.110 port 55425
EAP-Message =
0x01d704000dc000000941160301002a0200002603014cf47dcd98edd353ce39b099785a7e97da101613c63adf77d9643d0092c71e6500002f0016030108610b00085d00085a0003a6308203a23082028aa003020102020101300d06092a864886f70d0101040500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f726974
EAP-Message =
0x79301e170d3130313132363037323333305a170d3131313132363037323333305a307b310b30090603550406130255533111300f0603550408130856697267696e696131123010060355040a13094565626c652e6e6574312530230603550403131c4565626c652e6e657420536572766572204365727469666963617465311e301c06092a864886f70d010901160f61646d696e406565626c652e6e657430820122300d06092a864886f70d01010105000382010f003082010a0282010100ab4afd83acd6fea4fce7bb07d045a43436798b06b2f2be86ab6f19386c5e7d536585255834652f9a40160c6d19947c5fd02148f127b1d6d58558e055a952
EAP-Message =
0xaaaaaeb915a8475944790f539aa2084dfcd4de24636182bf350426db1a04320019b47a8d32229c4f4d4f0039bf7c4840673502f1eaefe170447fc3a508944ea8cd2197867ddb4e8f3cf5cba3da5d10f4714f40f4b28e1f48805023bb26cd940e96a68a4dc2a73243321c0af06b9b5356162641a5099fc439255340c3c02df4433f88969ce4e6035d40db3a0b4f74d31ac421e2faeec27c6fc6385d91755c1c4ed458ff850d37d7e06e9f95e87a59a5d63b25e44d3e608f6802ee9ef42619251a13ef0203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d0101040500038201010048267d769b012e4e35
EAP-Message =
0xee42366711bc376d503f76bd2da75c7a4040a07878b5bc5a1ad52e5e3e803b526cefeb61c58bb3db5041f4383377c39b5a72b0d35a0edde4fc3469abdaf0acb14920cc11ca1bf93e95089a627a1b99de8124c51a2dc7524e473e9333eda0aa213b11ecf188fcacbc20c2840beb0906e283d8e9025bbb2eb83ac816b2dcefe20edadddc2d5dfc171882bb8dde3f07a008fb4caa66e98a1c9ae3b452dee84971cfe892cfeab83846a60d9be8dfc0866ab93473c83541dd2d182076da789ec03128445292be43d0150e299e33030f45e4344a32ba4f6ed33a10e1e10f4a472649b92b2da7233986ed251adc2ea59764ef2187070e23a8743c0004ae308204
EAP-Message = 0xaa30820392a0030201020209
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x1925f89c1bf2f5e511765369958e0fff
Finished request 2.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=73, length=168
User-Name = "invaliduser1"
NAS-Identifier = "openwrt"
NAS-Port = 1
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-17-F2-E7-39-C0"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02d700060d00
State = 0x1925f89c1bf2f5e511765369958e0fff
Message-Authenticator = 0xe6897b99aab4241541cb41bf88f8a8c6
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser1", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 215 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake fragment handler
[tls] eaptls_verify returned 1
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 73 to 192.168.183.110 port 55425
EAP-Message =
0x01d804000dc0000009410097852e5140914149300d06092a864886f70d0101050500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037323333305a170d3230313132333037323333305a308194310b30090603550406130255533111300f0603550408130856697267696e696131
EAP-Message =
0x1430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f7269747930820122300d06092a864886f70d01010105000382010f003082010a02820101009a8f48c1dab2627525533672059ac65f037f7e96dca2744211718eda8e799239ada3486e9872eb0b811e888df90de8d5fc0837f5a146191528f1d1ff35adbad8a9b8928080363eb64a6ab03942480f48534902136d8c94b34e01d7e331ad215c11b35bb6990bafc17f
EAP-Message =
0xd261890769bb00533729a6fcc0b5d4d18e08bf54b1d66127996136d9577f12a4513304da016917577afdf64b02cf91d0a39b3c451dce5a920c810b4d23bd34931bb03d156f8d7fe834536b9ae11bd62195b59177db765d9982b232369e5bd89b10f4a0031ba2dbff86f672ac101a155d11ae07b904a4f74ffbb86f2524bc227167e41ca889fa9c56735a5665cfa5de0ad81b7ddaa0785d0203010001a381fc3081f9301d0603551d0e04160414a1454d2d4a35b362e6397fe81e7964fa6d2e9a9a3081c90603551d230481c13081be8014a1454d2d4a35b362e6397fe81e7964fa6d2e9a9aa1819aa48197308194310b30090603550406130255533111
EAP-Message =
0x300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f7269747982090097852e5140914149300c0603551d13040530030101ff300d06092a864886f70d010105050003820101004a090448190a316f43d373decd0d9e53a75d10c17c49043984a6c492f8bf96d303796e7c4e4539c5c3d49ebbe972a9ca204067bbf9886462119bb1ce627ffb6fe9beb21a56dc152facef50
EAP-Message = 0x40cfcbdd5a55e31c0c9eb904
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x1925f89c1afdf5e511765369958e0fff
Finished request 3.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=74, length=168
User-Name = "invaliduser1"
NAS-Identifier = "openwrt"
NAS-Port = 1
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-17-F2-E7-39-C0"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02d800060d00
State = 0x1925f89c1afdf5e511765369958e0fff
Message-Authenticator = 0x13f202928ab1d3156068c6d2ecc9fcb9
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser1", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 216 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake fragment handler
[tls] eaptls_verify returned 1
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 74 to 192.168.183.110 port 55425
EAP-Message =
0x01d9015f0d8000000941914f2148c7338774e1eb3f21449d3bbf86fe03d78f34a07df485fbff7dc3b305fadf41bfcbc41ec076c5c542b8f858008b3b3be00f858d2737331cf567c738692d8723ac6307cac62801513bf055cd6a9c726953195fbd7dbcf9e0a44289e5f1eee447c9ce87570f77a7e8574bc1fff0a2dbf4f85b545d5b6fa0b4c96b5f8db94b42686f9fdc9b7daebd59d83ddbf5dd64e1ac041d4653a4a5175ce9079c27b4a60d4115166c619f3d16030100a70d00009f0301024000990097308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c65
EAP-Message =
0x31123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f726974790e000000
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x1925f89c1dfcf5e511765369958e0fff
Finished request 4.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=75, length=1568
User-Name = "invaliduser1"
NAS-Identifier = "openwrt"
NAS-Port = 1
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-17-F2-E7-39-C0"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x02d905740dc000000aa816030108520b00084e00084b000397308203933082027ba003020102020102300d06092a864886f70d0101040500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037333533385a170d3131313132363037333533385a306c310b30090603550406130255
EAP-Message =
0x533111300f0603550408130856697267696e696131123010060355040a13094565626c652e6e6574311730150603550403140e616e6479406565626c652e6e6574311d301b06092a864886f70d010901160e616e6479406565626c652e6e657430820122300d06092a864886f70d01010105000382010f003082010a0282010100b4023777541709e539867d3033954f764c3a207c352dba4ee043642002ed4df123cb5edbe0d7a35cf9c21c88cd4ea537f3f297d9be68cb7bcbc49fdbc6ed94745d1aa057fcf259ad7898a6eb1b123b277e55da4d877972f169d29b922bfedd8dab070dbe905d1437ef1c84e9c7be7fd9736882d153993e36aa498819
EAP-Message =
0x68e526722d720427a9b2cccece64fcae119806c9ae5a925f68c09d0df5fcd9ebc6e20040cb97dac3f44a32ade71f6cfc40f90ac4b64f2585d45fd6901b13b2ae12347460853c30dab72c88c4f0becccd393433e47037ecb61544cb38155bb8ce9f75a9e5a024b5e03139cacb74d47d4af87aa3b9781903b8b6976260c39fc83df288482f0203010001a317301530130603551d25040c300a06082b06010505070302300d06092a864886f70d0101040500038201010049c7d67a933fd63a42cf33f6adb61bdc203bc30007ed3dfa9da446a6c3e78bced49ae68d7fd3611a431e888a9144d196bf30f46ae1be3d673006bbb6e50d3191f6756b38506838
EAP-Message =
0xad445350dfa97ac88297b8f36979dea39a92c4add1e5f6050eb5af41f3c8702b682365719456074d7623c2a0bca5be7c86c65ad538d4e8c615dde70df4967e6ea2acc5e2e76dde0ca0f13c4a34eddc93615cc7eba93b75ea9c23a85f74f1240ee999c08416d080a36246deec5b552046232ad3470f042bbe1774bb386c84aaa3ddcd4dc38acd816de90983e5a44231e77ae4d641ea14d6e822bbf969852387230eef0e02b3f84916b2bd0ba4aa159a4cb7aeb542b8cf3bd8dd0004ae308204aa30820392a00302010202090097852e5140914149300d06092a864886f70d0101050500308194310b30090603550406130255533111300f060355040813
EAP-Message =
0x0856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037323333305a170d3230313132333037323333305a308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f6164
EAP-Message =
0x6d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f7269747930820122300d06092a864886f70d01010105000382010f003082010a02820101009a8f48c1dab2627525533672059ac65f037f7e96dca2744211718eda8e799239ada3486e9872eb0b811e88
State = 0x1925f89c1dfcf5e511765369958e0fff
Message-Authenticator = 0xfcf4cb45ff5347d477c93f6722c86b03
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser1", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 217 length 253
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
TLS Length 2728
[tls] Received EAP-TLS First Fragment of the message
[tls] eaptls_verify returned 9
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 75 to 192.168.183.110 port 55425
EAP-Message = 0x01da00060d00
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x1925f89c1cfff5e511765369958e0fff
Finished request 5.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=76, length=1520
User-Name = "invaliduser1"
NAS-Identifier = "openwrt"
NAS-Port = 1
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-17-F2-E7-39-C0"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x02da05440d008df90de8d5fc0837f5a146191528f1d1ff35adbad8a9b8928080363eb64a6ab03942480f48534902136d8c94b34e01d7e331ad215c11b35bb6990bafc17fd261890769bb00533729a6fcc0b5d4d18e08bf54b1d66127996136d9577f12a4513304da016917577afdf64b02cf91d0a39b3c451dce5a920c810b4d23bd34931bb03d156f8d7fe834536b9ae11bd62195b59177db765d9982b232369e5bd89b10f4a0031ba2dbff86f672ac101a155d11ae07b904a4f74ffbb86f2524bc227167e41ca889fa9c56735a5665cfa5de0ad81b7ddaa0785d0203010001a381fc3081f9301d0603551d0e04160414a1454d2d4a35b362e6397fe8
EAP-Message =
0x1e7964fa6d2e9a9a3081c90603551d230481c13081be8014a1454d2d4a35b362e6397fe81e7964fa6d2e9a9aa1819aa48197308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f7269747982090097852e5140914149300c0603551d13040530030101ff300d06092a864886f70d010105050003820101004a090448190a31
EAP-Message =
0x6f43d373decd0d9e53a75d10c17c49043984a6c492f8bf96d303796e7c4e4539c5c3d49ebbe972a9ca204067bbf9886462119bb1ce627ffb6fe9beb21a56dc152facef5040cfcbdd5a55e31c0c9eb904914f2148c7338774e1eb3f21449d3bbf86fe03d78f34a07df485fbff7dc3b305fadf41bfcbc41ec076c5c542b8f858008b3b3be00f858d2737331cf567c738692d8723ac6307cac62801513bf055cd6a9c726953195fbd7dbcf9e0a44289e5f1eee447c9ce87570f77a7e8574bc1fff0a2dbf4f85b545d5b6fa0b4c96b5f8db94b42686f9fdc9b7daebd59d83ddbf5dd64e1ac041d4653a4a5175ce9079c27b4a60d4115166c619f3d16030101
EAP-Message =
0x061000010201006cd3d5d42d02607bad6cccbd821c47acc842e535db3091bd9cd1cc369c7e0399623ccdcf02b6920f15b853cd89adf40f5f89b1702349e6b4c943b5b52ab983384011ca214a2be1672a68ae91f347060b74fe93db442fe65b09718d6a6b34c87b3b2b5de157bebcecb313bdaf56a437e1eef95a2ece695c37eb54914dc08e08dee09449a011ccfb7124872bc841651511c86fbdffc7f58f5a9b8ad2fae518b0c72c41460ddc486e9dddde73478a990836218d14253d864260ef3902315fca7a5acd21eea5171b6ab224e9b2191cc61958ccb4527d83161f1c369e5164ea82f3339c5165155cc64489ad348571165ce25f2fe83dd92ea6
EAP-Message =
0x5f5e14f428dc80c3f16616030101060f00010201002e81b25e6082ccd1e0f71b7954b92d248e76fbd5734e683991e4409fd0a4e3ec0d13f13fafe41a35824c883c23a2ced28e19ac8659cc7297ef9e6f4a0c5a32dd1eb8c0e832ed929ac41a5f67c1aeeaa95aae9af57b230ba7753ca57783081910e59830c3ad1982499fcde5884bab2b451d026679a613a728d2128123fb76d0fb78944d099d81e86b81a16137633e15ed533401586c3fe773c93fcf2472ac73e41ecbb4c0393638891db14325d52ebe991e29bc976650924f34ffb45e25543d53c869a3cea0638f6fc188ee34a1ff07acb77226722bbfdffa6f04c56614797a8a4cce2abc53b764de
EAP-Message =
0x58cc7ef38ce7145532fde4d99063e60183e6a9e9405a92311403010001011603010030bc0ee785b2ff17529ace39c5a6c66ba168cfc082558510afdbcc3f5114014bbc66545699903692ff3b004ae50fc841b3
State = 0x1925f89c1cfff5e511765369958e0fff
Message-Authenticator = 0x1b3aea67ccedae9d41055d48e08deeca
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser1", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 218 length 253
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] eaptls_verify returned 7
[tls] Done initial handshake
[tls] <<< TLS 1.0 Handshake [length 0852], Certificate
[tls] chain-depth=1,
[tls] error=0
[tls] --> User-Name = invaliduser1
[tls] --> BUF-Name = Example.net Certificate Authority
[tls] --> subject =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> issuer =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> verify return:1
[tls] chain-depth=0,
[tls] error=0
[tls] --> User-Name = invaliduser1
[tls] --> BUF-Name = andy(a)example.net
[tls] --> subject =
/C=US/ST=Virginia/O=Example.net/CN=andy@example.net/emailAddress=andy@example.net
[tls] --> issuer =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> verify return:1
[tls] TLS_accept: SSLv3 read client certificate A
[tls] <<< TLS 1.0 Handshake [length 0106], ClientKeyExchange
[tls] TLS_accept: SSLv3 read client key exchange A
[tls] <<< TLS 1.0 Handshake [length 0106], CertificateVerify
[tls] TLS_accept: SSLv3 read certificate verify A
[tls] <<< TLS 1.0 ChangeCipherSpec [length 0001]
[tls] <<< TLS 1.0 Handshake [length 0010], Finished
[tls] TLS_accept: SSLv3 read finished A
[tls] >>> TLS 1.0 ChangeCipherSpec [length 0001]
[tls] TLS_accept: SSLv3 write change cipher spec A
[tls] >>> TLS 1.0 Handshake [length 0010], Finished
[tls] TLS_accept: SSLv3 write finished A
[tls] TLS_accept: SSLv3 flush data
[tls] (other): SSL negotiation finished successfully
SSL Connection Established
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 76 to 192.168.183.110 port 55425
EAP-Message =
0x01db00450d800000003b1403010001011603010030327d72375b8df7a3e6ed4e0575b76d753a34c65a21ed33bcb3036e2b37006404c7356e779df933c9af852f525a6877d1
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x1925f89c1ffef5e511765369958e0fff
Finished request 6.
Going to the next request
Waking up in 4.7 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=77, length=168
User-Name = "invaliduser1"
NAS-Identifier = "openwrt"
NAS-Port = 1
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-17-F2-E7-39-C0"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02db00060d00
State = 0x1925f89c1ffef5e511765369958e0fff
Message-Authenticator = 0x532e5b192c2b3f42d94eca4f8f1b6322
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser1", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 219 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake is finished
[tls] eaptls_verify returned 3
[tls] eaptls_process returned 3
[tls] Adding user data to cached session
[eap] Freeing handler
++[eap] returns ok
# Executing section post-auth from file
/etc/freeradius/sites-enabled/default
+- entering group post-auth {...}
++[exec] returns noop
Sending Access-Accept of id 77 to 192.168.183.110 port 55425
MS-MPPE-Recv-Key =
0xad6a9918758ca549457e3cb1635cebde2c308c218cd1ba3bb1fcb0e6222964f9
MS-MPPE-Send-Key =
0x2d9a175670e6428ae1c84bd869cac06f47b47703c29addc0f8fbbe4081ffe5e7
EAP-Message = 0x03db0004
Message-Authenticator = 0x00000000000000000000000000000000
User-Name = "invaliduser1"
Finished request 7.
Going to the next request
Waking up in 4.7 seconds.
Cleaning up request 0 ID 70 with timestamp +46
Cleaning up request 1 ID 71 with timestamp +46
Cleaning up request 2 ID 72 with timestamp +46
Cleaning up request 3 ID 73 with timestamp +46
Cleaning up request 4 ID 74 with timestamp +46
Cleaning up request 5 ID 75 with timestamp +46
Cleaning up request 6 ID 76 with timestamp +46
Cleaning up request 7 ID 77 with timestamp +46
Ready to process requests.
^[[Brad_recv: Access-Request packet from host 192.168.183.110 port
55425, id=78, length=156
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x0265000b01626f6f676572
Message-Authenticator = 0xcbeda4a2bb48dac1e14a1e77420b9ad3
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 101 length 11
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user.
Authentication may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type md5
rlm_eap_md5: Issuing Challenge
++[eap] returns handled
Sending Access-Challenge of id 78 to 192.168.183.110 port 55425
EAP-Message = 0x016600160410fab91c864c3e522df93d00b39b6c51bf
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9106cfd89160cb8160f4a77ced516b61
Finished request 8.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=79, length=169
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02660006030d
State = 0x9106cfd89160cb8160f4a77ced516b61
Message-Authenticator = 0xcc79781441efd250c146b39492c1e6e8
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 102 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user.
Authentication may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP NAK
[eap] EAP-NAK asked for EAP-Type/tls
[eap] processing type tls
[tls] Requiring client certificate
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 79 to 192.168.183.110 port 55425
EAP-Message = 0x016700060d20
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9106cfd89061c28160f4a77ced516b61
Finished request 9.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=80, length=278
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x026700730d0016030100680100006403014cf481b4d6922495a82e8d872689752cd335368ce1d573362881aef4ad676af700003600390038003500880087008400160013000a00330032002f0045004400410007000500040015001200090014001100080006000300ff020100000400230000
State = 0x9106cfd89061c28160f4a77ced516b61
Message-Authenticator = 0x3fb0727493ed1edbe0bae2c6c3dd0501
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 103 length 115
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] eaptls_verify returned 7
[tls] Done initial handshake
[tls] (other): before/accept initialization
[tls] TLS_accept: before/accept initialization
[tls] <<< TLS 1.0 Handshake [length 0068], ClientHello
[tls] TLS_accept: SSLv3 read client hello A
[tls] >>> TLS 1.0 Handshake [length 002a], ServerHello
[tls] TLS_accept: SSLv3 write server hello A
[tls] >>> TLS 1.0 Handshake [length 0861], Certificate
[tls] TLS_accept: SSLv3 write certificate A
[tls] >>> TLS 1.0 Handshake [length 020d], ServerKeyExchange
[tls] TLS_accept: SSLv3 write key exchange A
[tls] >>> TLS 1.0 Handshake [length 00a9], CertificateRequest
[tls] TLS_accept: SSLv3 write certificate request A
[tls] TLS_accept: SSLv3 flush data
[tls] TLS_accept: Need to read more data: SSLv3 read client
certificate A
In SSL Handshake Phase
In SSL Accept mode
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 80 to 192.168.183.110 port 55425
EAP-Message =
0x016804000dc000000b55160301002a0200002603014cf481afc3b222e7c1332f8cc59549c4b063a8bf9077bbd1cde56575eafe36cb0000390116030108610b00085d00085a0003a6308203a23082028aa003020102020101300d06092a864886f70d0101040500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f726974
EAP-Message =
0x79301e170d3130313132363037323333305a170d3131313132363037323333305a307b310b30090603550406130255533111300f0603550408130856697267696e696131123010060355040a13094565626c652e6e6574312530230603550403131c4565626c652e6e657420536572766572204365727469666963617465311e301c06092a864886f70d010901160f61646d696e406565626c652e6e657430820122300d06092a864886f70d01010105000382010f003082010a0282010100ab4afd83acd6fea4fce7bb07d045a43436798b06b2f2be86ab6f19386c5e7d536585255834652f9a40160c6d19947c5fd02148f127b1d6d58558e055a952
EAP-Message =
0xaaaaaeb915a8475944790f539aa2084dfcd4de24636182bf350426db1a04320019b47a8d32229c4f4d4f0039bf7c4840673502f1eaefe170447fc3a508944ea8cd2197867ddb4e8f3cf5cba3da5d10f4714f40f4b28e1f48805023bb26cd940e96a68a4dc2a73243321c0af06b9b5356162641a5099fc439255340c3c02df4433f88969ce4e6035d40db3a0b4f74d31ac421e2faeec27c6fc6385d91755c1c4ed458ff850d37d7e06e9f95e87a59a5d63b25e44d3e608f6802ee9ef42619251a13ef0203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d0101040500038201010048267d769b012e4e35
EAP-Message =
0xee42366711bc376d503f76bd2da75c7a4040a07878b5bc5a1ad52e5e3e803b526cefeb61c58bb3db5041f4383377c39b5a72b0d35a0edde4fc3469abdaf0acb14920cc11ca1bf93e95089a627a1b99de8124c51a2dc7524e473e9333eda0aa213b11ecf188fcacbc20c2840beb0906e283d8e9025bbb2eb83ac816b2dcefe20edadddc2d5dfc171882bb8dde3f07a008fb4caa66e98a1c9ae3b452dee84971cfe892cfeab83846a60d9be8dfc0866ab93473c83541dd2d182076da789ec03128445292be43d0150e299e33030f45e4344a32ba4f6ed33a10e1e10f4a472649b92b2da7233986ed251adc2ea59764ef2187070e23a8743c0004ae308204
EAP-Message = 0xaa30820392a0030201020209
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9106cfd8936ec28160f4a77ced516b61
Finished request 10.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=81, length=169
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x026800060d00
State = 0x9106cfd8936ec28160f4a77ced516b61
Message-Authenticator = 0x9a957e238e6c0098c09f429bab8a5cfb
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 104 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake fragment handler
[tls] eaptls_verify returned 1
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 81 to 192.168.183.110 port 55425
EAP-Message =
0x016904000dc000000b550097852e5140914149300d06092a864886f70d0101050500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037323333305a170d3230313132333037323333305a308194310b30090603550406130255533111300f0603550408130856697267696e696131
EAP-Message =
0x1430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f7269747930820122300d06092a864886f70d01010105000382010f003082010a02820101009a8f48c1dab2627525533672059ac65f037f7e96dca2744211718eda8e799239ada3486e9872eb0b811e888df90de8d5fc0837f5a146191528f1d1ff35adbad8a9b8928080363eb64a6ab03942480f48534902136d8c94b34e01d7e331ad215c11b35bb6990bafc17f
EAP-Message =
0xd261890769bb00533729a6fcc0b5d4d18e08bf54b1d66127996136d9577f12a4513304da016917577afdf64b02cf91d0a39b3c451dce5a920c810b4d23bd34931bb03d156f8d7fe834536b9ae11bd62195b59177db765d9982b232369e5bd89b10f4a0031ba2dbff86f672ac101a155d11ae07b904a4f74ffbb86f2524bc227167e41ca889fa9c56735a5665cfa5de0ad81b7ddaa0785d0203010001a381fc3081f9301d0603551d0e04160414a1454d2d4a35b362e6397fe81e7964fa6d2e9a9a3081c90603551d230481c13081be8014a1454d2d4a35b362e6397fe81e7964fa6d2e9a9aa1819aa48197308194310b30090603550406130255533111
EAP-Message =
0x300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f7269747982090097852e5140914149300c0603551d13040530030101ff300d06092a864886f70d010105050003820101004a090448190a316f43d373decd0d9e53a75d10c17c49043984a6c492f8bf96d303796e7c4e4539c5c3d49ebbe972a9ca204067bbf9886462119bb1ce627ffb6fe9beb21a56dc152facef50
EAP-Message = 0x40cfcbdd5a55e31c0c9eb904
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9106cfd8926fc28160f4a77ced516b61
Finished request 11.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=82, length=169
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x026900060d00
State = 0x9106cfd8926fc28160f4a77ced516b61
Message-Authenticator = 0x6a6a344f5929ac78f2ed252a2870d7b2
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 105 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake fragment handler
[tls] eaptls_verify returned 1
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 82 to 192.168.183.110 port 55425
EAP-Message =
0x016a03730d8000000b55914f2148c7338774e1eb3f21449d3bbf86fe03d78f34a07df485fbff7dc3b305fadf41bfcbc41ec076c5c542b8f858008b3b3be00f858d2737331cf567c738692d8723ac6307cac62801513bf055cd6a9c726953195fbd7dbcf9e0a44289e5f1eee447c9ce87570f77a7e8574bc1fff0a2dbf4f85b545d5b6fa0b4c96b5f8db94b42686f9fdc9b7daebd59d83ddbf5dd64e1ac041d4653a4a5175ce9079c27b4a60d4115166c619f3d160301020d0c0002090080ff1dbabee46297bf06de02f05ad815fdf518ce607e3dd1ff5c528dd383fd71430fc86fe3a57b4e2d8e6b2d017f89ff90d03477d409b591bde4502eee1aeb02
EAP-Message =
0x38c518226df76f43435eba774de8611277591c7cbc23913412d8067e5cd7ea38c53f314e3198473832c4f1737a0edb3a09d44f512c4b4131f3e1b5d6d91732691b0001020080a3f58451d5337dde0a183e126d86ee23158947536f4a7a89c279e5fec04915f6052292b9d57c8a0dbe8b3c8feee54217f6c8265da333535fe2b471651c33303cb12abcc1bb925f7d51e35780ba5bc9db2c9f25127abcdd1ad7b239e6fb5542c7bb1b5db0e28695d5e2ac3c84e65f0bd6095edb79a88f8ec2ab64957f34e65ad201007ac7cd7798bb5f7a7bdb90a0db030464d2d7f6e40e085790f1e405b6f627d55f7c70c5ae25951a718f1190462a4b7cbf822a7e7fea
EAP-Message =
0x0b918e8224b19c2782deda073f2a26af8e7c00c3f5d257f939f91cb7abd572e0e5eb97bdd82d29549d4b29051865d7f26d92984d226ded73e4838e542a00e3090841845ac4c50411726153c9cc7c90036d815c24b1118b1983dea8226823d9f9cb4ea15eaea198924265f56d32d612a2d819719c7fa6bd07f1c6a8f4624a9e1f6a51ba426e662726c0bc2bc881ac5290d6fdab5763b7cfd4de06955364ec5cb15a454fe78e8b6b4e24d06f18f8e31b0755ca9aeabb2fcb12eb6f9931b4b8284f0adeb8cfec4cfd979b6f2516030100a90d0000a105030401024000990097308194310b30090603550406130255533111300f0603550408130856697267
EAP-Message =
0x696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f726974790e000000
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9106cfd8956cc28160f4a77ced516b61
Finished request 12.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=83, length=1483
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x026a051e0dc000000a2816030108520b00084e00084b000397308203933082027ba003020102020102300d06092a864886f70d0101040500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037333533385a170d3131313132363037333533385a306c310b30090603550406130255
EAP-Message =
0x533111300f0603550408130856697267696e696131123010060355040a13094565626c652e6e6574311730150603550403140e616e6479406565626c652e6e6574311d301b06092a864886f70d010901160e616e6479406565626c652e6e657430820122300d06092a864886f70d01010105000382010f003082010a0282010100b4023777541709e539867d3033954f764c3a207c352dba4ee043642002ed4df123cb5edbe0d7a35cf9c21c88cd4ea537f3f297d9be68cb7bcbc49fdbc6ed94745d1aa057fcf259ad7898a6eb1b123b277e55da4d877972f169d29b922bfedd8dab070dbe905d1437ef1c84e9c7be7fd9736882d153993e36aa498819
EAP-Message =
0x68e526722d720427a9b2cccece64fcae119806c9ae5a925f68c09d0df5fcd9ebc6e20040cb97dac3f44a32ade71f6cfc40f90ac4b64f2585d45fd6901b13b2ae12347460853c30dab72c88c4f0becccd393433e47037ecb61544cb38155bb8ce9f75a9e5a024b5e03139cacb74d47d4af87aa3b9781903b8b6976260c39fc83df288482f0203010001a317301530130603551d25040c300a06082b06010505070302300d06092a864886f70d0101040500038201010049c7d67a933fd63a42cf33f6adb61bdc203bc30007ed3dfa9da446a6c3e78bced49ae68d7fd3611a431e888a9144d196bf30f46ae1be3d673006bbb6e50d3191f6756b38506838
EAP-Message =
0xad445350dfa97ac88297b8f36979dea39a92c4add1e5f6050eb5af41f3c8702b682365719456074d7623c2a0bca5be7c86c65ad538d4e8c615dde70df4967e6ea2acc5e2e76dde0ca0f13c4a34eddc93615cc7eba93b75ea9c23a85f74f1240ee999c08416d080a36246deec5b552046232ad3470f042bbe1774bb386c84aaa3ddcd4dc38acd816de90983e5a44231e77ae4d641ea14d6e822bbf969852387230eef0e02b3f84916b2bd0ba4aa159a4cb7aeb542b8cf3bd8dd0004ae308204aa30820392a00302010202090097852e5140914149300d06092a864886f70d0101050500308194310b30090603550406130255533111300f060355040813
EAP-Message =
0x0856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037323333305a170d3230313132333037323333305a308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f6164
EAP-Message =
0x6d696e406565626c652e6e6574312830260603550403131f4565626c652e6e6574204365727469666963617465
State = 0x9106cfd8956cc28160f4a77ced516b61
Message-Authenticator = 0x7f9e18fbc6764ac5d67ed14f4b9af68f
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 106 length 253
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
TLS Length 2600
[tls] Received EAP-TLS First Fragment of the message
[tls] eaptls_verify returned 9
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 83 to 192.168.183.110 port 55425
EAP-Message = 0x016b00060d00
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9106cfd8946dc28160f4a77ced516b61
Finished request 13.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=84, length=1479
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x026b051a0d0020417574686f7269747930820122300d06092a864886f70d01010105000382010f003082010a02820101009a8f48c1dab2627525533672059ac65f037f7e96dca2744211718eda8e799239ada3486e9872eb0b811e888df90de8d5fc0837f5a146191528f1d1ff35adbad8a9b8928080363eb64a6ab03942480f48534902136d8c94b34e01d7e331ad215c11b35bb6990bafc17fd261890769bb00533729a6fcc0b5d4d18e08bf54b1d66127996136d9577f12a4513304da016917577afdf64b02cf91d0a39b3c451dce5a920c810b4d23bd34931bb03d156f8d7fe834536b9ae11bd62195b59177db765d9982b232369e5bd89b10f4a0
EAP-Message =
0x031ba2dbff86f672ac101a155d11ae07b904a4f74ffbb86f2524bc227167e41ca889fa9c56735a5665cfa5de0ad81b7ddaa0785d0203010001a381fc3081f9301d0603551d0e04160414a1454d2d4a35b362e6397fe81e7964fa6d2e9a9a3081c90603551d230481c13081be8014a1454d2d4a35b362e6397fe81e7964fa6d2e9a9aa1819aa48197308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e65743128302606035504
EAP-Message =
0x03131f4565626c652e6e657420436572746966696361746520417574686f7269747982090097852e5140914149300c0603551d13040530030101ff300d06092a864886f70d010105050003820101004a090448190a316f43d373decd0d9e53a75d10c17c49043984a6c492f8bf96d303796e7c4e4539c5c3d49ebbe972a9ca204067bbf9886462119bb1ce627ffb6fe9beb21a56dc152facef5040cfcbdd5a55e31c0c9eb904914f2148c7338774e1eb3f21449d3bbf86fe03d78f34a07df485fbff7dc3b305fadf41bfcbc41ec076c5c542b8f858008b3b3be00f858d2737331cf567c738692d8723ac6307cac62801513bf055cd6a9c726953195fbd
EAP-Message =
0x7dbcf9e0a44289e5f1eee447c9ce87570f77a7e8574bc1fff0a2dbf4f85b545d5b6fa0b4c96b5f8db94b42686f9fdc9b7daebd59d83ddbf5dd64e1ac041d4653a4a5175ce9079c27b4a60d4115166c619f3d1603010086100000820080b6a6fc11dae5b0d91c974b23f5776da3286d51dcc75025f7c365a81ee0549d08874f95a097f285ee3a3cce4fdb904f7b3185a82d3481ab460ced11dff2a41eeaaddd17a9244340ea3ff2528e0166cd881bba22eb4430c0912d549f812860cf3b63dbb074e8fc33725756ab1b2f710b3675f49e0ec8718bf1c58dd8638625cf1d16030101060f000102010065ff0cdee1f13a073180ed689e5b2f589463c9ec0e
EAP-Message =
0x61ebef4b3bc295e8dbc4c54e118053c49235e051480ab69237c3e50f1440072ebca811ae9e2f41435ae59b87a5032edaae224c416acdc06a9c0226244bb52fccd4d3eb3e9b565762923c7ccafd3d2f9140a705cd5aea3bae0a69b9e3acaf2f93aa68a9f7fb188068bd6e5ef5c3a60abf7bee8a2e6b59bb97ca7cb5ab2eefa0f94956920692c62930e794d5d97c33868b5f6a80b6e1c9732ff5cf42c4fa45e4a96d467b379149cabfd92645560ed128d3d2e295fbb7c1906cfe8497bcb266272e0f659038f9a32b98f6f3264983120b590a5e7ff75cffe1c0b1ea09e45e24536ce0990ecf42d99b2a9a1e8314030100010116030100309cc7400c95d751
EAP-Message =
0xf414988cf618ea3991159a7bcc648fb85a02c193b13b9b4171037012a120b2e36bf4f046a626235d30
State = 0x9106cfd8946dc28160f4a77ced516b61
Message-Authenticator = 0x5ffcc1fbcd380454fd25524389e7c6b3
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 107 length 253
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] eaptls_verify returned 7
[tls] Done initial handshake
[tls] <<< TLS 1.0 Handshake [length 0852], Certificate
[tls] chain-depth=1,
[tls] error=0
[tls] --> User-Name = invaliduser2
[tls] --> BUF-Name = Example.net Certificate Authority
[tls] --> subject =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> issuer =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> verify return:1
[tls] chain-depth=0,
[tls] error=0
[tls] --> User-Name = invaliduser2
[tls] --> BUF-Name = andy(a)example.net
[tls] --> subject =
/C=US/ST=Virginia/O=Example.net/CN=andy@example.net/emailAddress=andy@example.net
[tls] --> issuer =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> verify return:1
[tls] TLS_accept: SSLv3 read client certificate A
[tls] <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange
[tls] TLS_accept: SSLv3 read client key exchange A
[tls] <<< TLS 1.0 Handshake [length 0106], CertificateVerify
[tls] TLS_accept: SSLv3 read certificate verify A
[tls] <<< TLS 1.0 ChangeCipherSpec [length 0001]
[tls] <<< TLS 1.0 Handshake [length 0010], Finished
[tls] TLS_accept: SSLv3 read finished A
[tls] >>> TLS 1.0 ChangeCipherSpec [length 0001]
[tls] TLS_accept: SSLv3 write change cipher spec A
[tls] >>> TLS 1.0 Handshake [length 0010], Finished
[tls] TLS_accept: SSLv3 write finished A
[tls] TLS_accept: SSLv3 flush data
[tls] (other): SSL negotiation finished successfully
SSL Connection Established
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 84 to 192.168.183.110 port 55425
EAP-Message =
0x016c00450d800000003b1403010001011603010030963977704c781d4f4d8f2aa3b335d363af8d81e6263bee6d1c02a09b7a0e47957e42cb94ecad93a231e257b94f0abcbd
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9106cfd8976ac28160f4a77ced516b61
Finished request 14.
Going to the next request
Waking up in 4.7 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=85, length=169
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x026c00060d00
State = 0x9106cfd8976ac28160f4a77ced516b61
Message-Authenticator = 0x1a64cfaaa61f800e099a0432de248e44
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 108 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake is finished
[tls] eaptls_verify returned 3
[tls] eaptls_process returned 3
[tls] Adding user data to cached session
[eap] Freeing handler
++[eap] returns ok
# Executing section post-auth from file
/etc/freeradius/sites-enabled/default
+- entering group post-auth {...}
++[exec] returns noop
Sending Access-Accept of id 85 to 192.168.183.110 port 55425
MS-MPPE-Recv-Key =
0x2d08d6053dd69463c00f28fa96253e6fef7ce1c25fcd636ac7801ea4b30f0c9e
MS-MPPE-Send-Key =
0x2436262b744f0612e2b44f856b7e3fa2569a1ee6e6dc68ff6eee62e13fedefb9
EAP-Message = 0x036c0004
Message-Authenticator = 0x00000000000000000000000000000000
User-Name = "invaliduser2"
Finished request 15.
Going to the next request
Waking up in 4.7 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=86, length=156
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02de000b01626f6f676572
Message-Authenticator = 0x9c78554a3a8b563535d0d903b0c89b00
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 222 length 11
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user.
Authentication may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type md5
rlm_eap_md5: Issuing Challenge
++[eap] returns handled
Sending Access-Challenge of id 86 to 192.168.183.110 port 55425
EAP-Message = 0x01df001604105ce2f52a06b4da9a957fd7800282dd99
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9d0db2769dd2b6bf32cdba76f867f4ab
Finished request 16.
Going to the next request
Waking up in 0.5 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=87, length=169
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02df0006030d
State = 0x9d0db2769dd2b6bf32cdba76f867f4ab
Message-Authenticator = 0x417840b8fd464fb1b5c3de9d7fbab021
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 223 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING! No "known good" password found for the user.
Authentication may fail because of this.
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP NAK
[eap] EAP-NAK asked for EAP-Type/tls
[eap] processing type tls
[tls] Requiring client certificate
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 87 to 192.168.183.110 port 55425
EAP-Message = 0x01e000060d20
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9d0db2769cedbfbf32cdba76f867f4ab
Finished request 17.
Going to the next request
Waking up in 0.5 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=88, length=278
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x02e000730d0016030100680100006403014cf481b8c295486f451587fade5111838f65298e8700ee9b233d48421510c46000003600390038003500880087008400160013000a00330032002f0045004400410007000500040015001200090014001100080006000300ff020100000400230000
State = 0x9d0db2769cedbfbf32cdba76f867f4ab
Message-Authenticator = 0x8a9e14310b6e47c2c3de26023dae497c
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 224 length 115
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] eaptls_verify returned 7
[tls] Done initial handshake
[tls] (other): before/accept initialization
[tls] TLS_accept: before/accept initialization
[tls] <<< TLS 1.0 Handshake [length 0068], ClientHello
[tls] TLS_accept: SSLv3 read client hello A
[tls] >>> TLS 1.0 Handshake [length 002a], ServerHello
[tls] TLS_accept: SSLv3 write server hello A
[tls] >>> TLS 1.0 Handshake [length 0861], Certificate
[tls] TLS_accept: SSLv3 write certificate A
[tls] >>> TLS 1.0 Handshake [length 020d], ServerKeyExchange
[tls] TLS_accept: SSLv3 write key exchange A
[tls] >>> TLS 1.0 Handshake [length 00a9], CertificateRequest
[tls] TLS_accept: SSLv3 write certificate request A
[tls] TLS_accept: SSLv3 flush data
[tls] TLS_accept: Need to read more data: SSLv3 read client
certificate A
In SSL Handshake Phase
In SSL Accept mode
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 88 to 192.168.183.110 port 55425
EAP-Message =
0x01e104000dc000000b55160301002a0200002603014cf481b46e40ddcb8f677105b2abcbca4ea593ed6f3982f0b5f536ad4d045fe70000390116030108610b00085d00085a0003a6308203a23082028aa003020102020101300d06092a864886f70d0101040500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f726974
EAP-Message =
0x79301e170d3130313132363037323333305a170d3131313132363037323333305a307b310b30090603550406130255533111300f0603550408130856697267696e696131123010060355040a13094565626c652e6e6574312530230603550403131c4565626c652e6e657420536572766572204365727469666963617465311e301c06092a864886f70d010901160f61646d696e406565626c652e6e657430820122300d06092a864886f70d01010105000382010f003082010a0282010100ab4afd83acd6fea4fce7bb07d045a43436798b06b2f2be86ab6f19386c5e7d536585255834652f9a40160c6d19947c5fd02148f127b1d6d58558e055a952
EAP-Message =
0xaaaaaeb915a8475944790f539aa2084dfcd4de24636182bf350426db1a04320019b47a8d32229c4f4d4f0039bf7c4840673502f1eaefe170447fc3a508944ea8cd2197867ddb4e8f3cf5cba3da5d10f4714f40f4b28e1f48805023bb26cd940e96a68a4dc2a73243321c0af06b9b5356162641a5099fc439255340c3c02df4433f88969ce4e6035d40db3a0b4f74d31ac421e2faeec27c6fc6385d91755c1c4ed458ff850d37d7e06e9f95e87a59a5d63b25e44d3e608f6802ee9ef42619251a13ef0203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d0101040500038201010048267d769b012e4e35
EAP-Message =
0xee42366711bc376d503f76bd2da75c7a4040a07878b5bc5a1ad52e5e3e803b526cefeb61c58bb3db5041f4383377c39b5a72b0d35a0edde4fc3469abdaf0acb14920cc11ca1bf93e95089a627a1b99de8124c51a2dc7524e473e9333eda0aa213b11ecf188fcacbc20c2840beb0906e283d8e9025bbb2eb83ac816b2dcefe20edadddc2d5dfc171882bb8dde3f07a008fb4caa66e98a1c9ae3b452dee84971cfe892cfeab83846a60d9be8dfc0866ab93473c83541dd2d182076da789ec03128445292be43d0150e299e33030f45e4344a32ba4f6ed33a10e1e10f4a472649b92b2da7233986ed251adc2ea59764ef2187070e23a8743c0004ae308204
EAP-Message = 0xaa30820392a0030201020209
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9d0db2769fecbfbf32cdba76f867f4ab
Finished request 18.
Going to the next request
Waking up in 0.4 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=89, length=169
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02e100060d00
State = 0x9d0db2769fecbfbf32cdba76f867f4ab
Message-Authenticator = 0x3b7277d4745b9e98ca72f95ab5737f7e
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 225 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake fragment handler
[tls] eaptls_verify returned 1
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 89 to 192.168.183.110 port 55425
EAP-Message =
0x01e204000dc000000b550097852e5140914149300d06092a864886f70d0101050500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037323333305a170d3230313132333037323333305a308194310b30090603550406130255533111300f0603550408130856697267696e696131
EAP-Message =
0x1430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f7269747930820122300d06092a864886f70d01010105000382010f003082010a02820101009a8f48c1dab2627525533672059ac65f037f7e96dca2744211718eda8e799239ada3486e9872eb0b811e888df90de8d5fc0837f5a146191528f1d1ff35adbad8a9b8928080363eb64a6ab03942480f48534902136d8c94b34e01d7e331ad215c11b35bb6990bafc17f
EAP-Message =
0xd261890769bb00533729a6fcc0b5d4d18e08bf54b1d66127996136d9577f12a4513304da016917577afdf64b02cf91d0a39b3c451dce5a920c810b4d23bd34931bb03d156f8d7fe834536b9ae11bd62195b59177db765d9982b232369e5bd89b10f4a0031ba2dbff86f672ac101a155d11ae07b904a4f74ffbb86f2524bc227167e41ca889fa9c56735a5665cfa5de0ad81b7ddaa0785d0203010001a381fc3081f9301d0603551d0e04160414a1454d2d4a35b362e6397fe81e7964fa6d2e9a9a3081c90603551d230481c13081be8014a1454d2d4a35b362e6397fe81e7964fa6d2e9a9aa1819aa48197308194310b30090603550406130255533111
EAP-Message =
0x300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f7269747982090097852e5140914149300c0603551d13040530030101ff300d06092a864886f70d010105050003820101004a090448190a316f43d373decd0d9e53a75d10c17c49043984a6c492f8bf96d303796e7c4e4539c5c3d49ebbe972a9ca204067bbf9886462119bb1ce627ffb6fe9beb21a56dc152facef50
EAP-Message = 0x40cfcbdd5a55e31c0c9eb904
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9d0db2769eefbfbf32cdba76f867f4ab
Finished request 19.
Going to the next request
Waking up in 0.4 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=90, length=169
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02e200060d00
State = 0x9d0db2769eefbfbf32cdba76f867f4ab
Message-Authenticator = 0xf97c53a2038663a789e7316935e0a570
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 226 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake fragment handler
[tls] eaptls_verify returned 1
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 90 to 192.168.183.110 port 55425
EAP-Message =
0x01e303730d8000000b55914f2148c7338774e1eb3f21449d3bbf86fe03d78f34a07df485fbff7dc3b305fadf41bfcbc41ec076c5c542b8f858008b3b3be00f858d2737331cf567c738692d8723ac6307cac62801513bf055cd6a9c726953195fbd7dbcf9e0a44289e5f1eee447c9ce87570f77a7e8574bc1fff0a2dbf4f85b545d5b6fa0b4c96b5f8db94b42686f9fdc9b7daebd59d83ddbf5dd64e1ac041d4653a4a5175ce9079c27b4a60d4115166c619f3d160301020d0c0002090080ff1dbabee46297bf06de02f05ad815fdf518ce607e3dd1ff5c528dd383fd71430fc86fe3a57b4e2d8e6b2d017f89ff90d03477d409b591bde4502eee1aeb02
EAP-Message =
0x38c518226df76f43435eba774de8611277591c7cbc23913412d8067e5cd7ea38c53f314e3198473832c4f1737a0edb3a09d44f512c4b4131f3e1b5d6d91732691b000102008045c25ccb2d5fcda4484bd4389895809c2e8bc4ea510ba6c61b2ac53cced54dee16374e3f77d57da1bdd8cad9097bc427581db803f46445b362993f9601bbb8f571de5b8b1874db5a14100f49bf541c82ad0edae92b1d6ff27494ec12872792f88edb19d2fa08d30908c857590b5ed85f6855b88ac7f5ac13bd71bf41a79426b101004c19fc04acceb057ee3b9a5c2083c2803841a17d7d8998feeb2b3966ce510fd9745bb0bfc40dfc00bc2841c0f84ef0360bc103135e
EAP-Message =
0x44c8c94508352176b28e83b5bc3db4e2295136fb775d0b48a0d5fe8a1908b26e698f1ac6af338af3acdb6b3b1925e6f0d149ea4da6b9f172ca702562877890f1ef8e551fc46edddf4101087298b9c2d2065e55289acc82102987b090606069b9d4da96c8c96f9b838d97c4a3c10354dadf2bc90873fba7b89213f4b33f19c89e325e842f3b2f2e0d4eae3f55d7693b4837279417914e2c300456d9a99eba20effbc1ac663e4a4bb90607a62ca30aff1fa9f30d7e745a88505b60ebdb5e6473e918051afe27c2990e1d973b16030100a90d0000a105030401024000990097308194310b30090603550406130255533111300f0603550408130856697267
EAP-Message =
0x696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f726974790e000000
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9d0db27699eebfbf32cdba76f867f4ab
Finished request 20.
Going to the next request
Waking up in 0.4 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=91, length=1483
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x02e3051e0dc000000a2816030108520b00084e00084b000397308203933082027ba003020102020102300d06092a864886f70d0101040500308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037333533385a170d3131313132363037333533385a306c310b30090603550406130255
EAP-Message =
0x533111300f0603550408130856697267696e696131123010060355040a13094565626c652e6e6574311730150603550403140e616e6479406565626c652e6e6574311d301b06092a864886f70d010901160e616e6479406565626c652e6e657430820122300d06092a864886f70d01010105000382010f003082010a0282010100b4023777541709e539867d3033954f764c3a207c352dba4ee043642002ed4df123cb5edbe0d7a35cf9c21c88cd4ea537f3f297d9be68cb7bcbc49fdbc6ed94745d1aa057fcf259ad7898a6eb1b123b277e55da4d877972f169d29b922bfedd8dab070dbe905d1437ef1c84e9c7be7fd9736882d153993e36aa498819
EAP-Message =
0x68e526722d720427a9b2cccece64fcae119806c9ae5a925f68c09d0df5fcd9ebc6e20040cb97dac3f44a32ade71f6cfc40f90ac4b64f2585d45fd6901b13b2ae12347460853c30dab72c88c4f0becccd393433e47037ecb61544cb38155bb8ce9f75a9e5a024b5e03139cacb74d47d4af87aa3b9781903b8b6976260c39fc83df288482f0203010001a317301530130603551d25040c300a06082b06010505070302300d06092a864886f70d0101040500038201010049c7d67a933fd63a42cf33f6adb61bdc203bc30007ed3dfa9da446a6c3e78bced49ae68d7fd3611a431e888a9144d196bf30f46ae1be3d673006bbb6e50d3191f6756b38506838
EAP-Message =
0xad445350dfa97ac88297b8f36979dea39a92c4add1e5f6050eb5af41f3c8702b682365719456074d7623c2a0bca5be7c86c65ad538d4e8c615dde70df4967e6ea2acc5e2e76dde0ca0f13c4a34eddc93615cc7eba93b75ea9c23a85f74f1240ee999c08416d080a36246deec5b552046232ad3470f042bbe1774bb386c84aaa3ddcd4dc38acd816de90983e5a44231e77ae4d641ea14d6e822bbf969852387230eef0e02b3f84916b2bd0ba4aa159a4cb7aeb542b8cf3bd8dd0004ae308204aa30820392a00302010202090097852e5140914149300d06092a864886f70d0101050500308194310b30090603550406130255533111300f060355040813
EAP-Message =
0x0856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e6574312830260603550403131f4565626c652e6e657420436572746966696361746520417574686f72697479301e170d3130313132363037323333305a170d3230313132333037323333305a308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f6164
EAP-Message =
0x6d696e406565626c652e6e6574312830260603550403131f4565626c652e6e6574204365727469666963617465
State = 0x9d0db27699eebfbf32cdba76f867f4ab
Message-Authenticator = 0x30fdfb43685b57ab7bddfa43385223e6
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 227 length 253
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
TLS Length 2600
[tls] Received EAP-TLS First Fragment of the message
[tls] eaptls_verify returned 9
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 91 to 192.168.183.110 port 55425
EAP-Message = 0x01e400060d00
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9d0db27698e9bfbf32cdba76f867f4ab
Finished request 21.
Going to the next request
Waking up in 0.4 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=92, length=1479
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message =
0x02e4051a0d0020417574686f7269747930820122300d06092a864886f70d01010105000382010f003082010a02820101009a8f48c1dab2627525533672059ac65f037f7e96dca2744211718eda8e799239ada3486e9872eb0b811e888df90de8d5fc0837f5a146191528f1d1ff35adbad8a9b8928080363eb64a6ab03942480f48534902136d8c94b34e01d7e331ad215c11b35bb6990bafc17fd261890769bb00533729a6fcc0b5d4d18e08bf54b1d66127996136d9577f12a4513304da016917577afdf64b02cf91d0a39b3c451dce5a920c810b4d23bd34931bb03d156f8d7fe834536b9ae11bd62195b59177db765d9982b232369e5bd89b10f4a0
EAP-Message =
0x031ba2dbff86f672ac101a155d11ae07b904a4f74ffbb86f2524bc227167e41ca889fa9c56735a5665cfa5de0ad81b7ddaa0785d0203010001a381fc3081f9301d0603551d0e04160414a1454d2d4a35b362e6397fe81e7964fa6d2e9a9a3081c90603551d230481c13081be8014a1454d2d4a35b362e6397fe81e7964fa6d2e9a9aa1819aa48197308194310b30090603550406130255533111300f0603550408130856697267696e6961311430120603550407130b43656e74726576696c6c6531123010060355040a13094565626c652e6e6574311e301c06092a864886f70d010901160f61646d696e406565626c652e6e65743128302606035504
EAP-Message =
0x03131f4565626c652e6e657420436572746966696361746520417574686f7269747982090097852e5140914149300c0603551d13040530030101ff300d06092a864886f70d010105050003820101004a090448190a316f43d373decd0d9e53a75d10c17c49043984a6c492f8bf96d303796e7c4e4539c5c3d49ebbe972a9ca204067bbf9886462119bb1ce627ffb6fe9beb21a56dc152facef5040cfcbdd5a55e31c0c9eb904914f2148c7338774e1eb3f21449d3bbf86fe03d78f34a07df485fbff7dc3b305fadf41bfcbc41ec076c5c542b8f858008b3b3be00f858d2737331cf567c738692d8723ac6307cac62801513bf055cd6a9c726953195fbd
EAP-Message =
0x7dbcf9e0a44289e5f1eee447c9ce87570f77a7e8574bc1fff0a2dbf4f85b545d5b6fa0b4c96b5f8db94b42686f9fdc9b7daebd59d83ddbf5dd64e1ac041d4653a4a5175ce9079c27b4a60d4115166c619f3d1603010086100000820080ed1f82c9867a16a46cb828ce67569e8089fa292015add6108605ea65c4b1554f7b03010348b72c9a17540747297560723b4c115a40c201e125d39fe4f751885bef6072ed0712145558e2832085195599ae2f561e1b03ab2e487940ec879517aee794f152e57fc8edc9ba5e1fd9e01d5da21ce38361653a91a238c72c30ea2bf616030101060f000102010097aa1d029159d31e299046a532069c6fa27ad603af
EAP-Message =
0xbbc4a426ab9760c880d3f02266acbe7f1ad4315154f756f2991d5102055a26ec46662645be4d8345ce6b4d205527345e23742c0aa4b1856c022029b1366a047d3bb9a990774c066e955fe8abe2e07f5f1eae43e8b35e1e0bedc5e40ee6171ffaf30a3be80509da4d7d14523bf8f983bd70ceef55db745a4e4921a6e31a40024ce4bb980a91a425b298a8a11bce5927cebf9c42fe4bcfc9135027406153830d17aec39512f7361a69d9678bcd3cc612dd316a21abbc66b20d783c8c06eb0ae7f4bf350f43d12f0a53a8b645a5427685b4124c7a1a0aba8dd080baccf4348c532820142970aaee354abe4aea140301000101160301003032caee1780b846
EAP-Message =
0x4f130f80978d53109065f1989f1e9b08d533c103173afaa6ee21584832f318c702f65213964facd4e4
State = 0x9d0db27698e9bfbf32cdba76f867f4ab
Message-Authenticator = 0x0e8e533bf04c8f47d5f5da946752536b
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 228 length 253
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] eaptls_verify returned 7
[tls] Done initial handshake
[tls] <<< TLS 1.0 Handshake [length 0852], Certificate
[tls] chain-depth=1,
[tls] error=0
[tls] --> User-Name = invaliduser2
[tls] --> BUF-Name = Example.net Certificate Authority
[tls] --> subject =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> issuer =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> verify return:1
[tls] chain-depth=0,
[tls] error=0
[tls] --> User-Name = invaliduser2
[tls] --> BUF-Name = andy(a)example.net
[tls] --> subject =
/C=US/ST=Virginia/O=Example.net/CN=andy@example.net/emailAddress=andy@example.net
[tls] --> issuer =
/C=US/ST=Virginia/L=Centreville/O=Example.net/emailAddress=admin(a)example.net/CN=Example.net
Certificate Authority
[tls] --> verify return:1
[tls] TLS_accept: SSLv3 read client certificate A
[tls] <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange
[tls] TLS_accept: SSLv3 read client key exchange A
[tls] <<< TLS 1.0 Handshake [length 0106], CertificateVerify
[tls] TLS_accept: SSLv3 read certificate verify A
[tls] <<< TLS 1.0 ChangeCipherSpec [length 0001]
[tls] <<< TLS 1.0 Handshake [length 0010], Finished
[tls] TLS_accept: SSLv3 read finished A
[tls] >>> TLS 1.0 ChangeCipherSpec [length 0001]
[tls] TLS_accept: SSLv3 write change cipher spec A
[tls] >>> TLS 1.0 Handshake [length 0010], Finished
[tls] TLS_accept: SSLv3 write finished A
[tls] TLS_accept: SSLv3 flush data
[tls] (other): SSL negotiation finished successfully
SSL Connection Established
[tls] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 92 to 192.168.183.110 port 55425
EAP-Message =
0x01e500450d800000003b1403010001011603010030be498792743bbd0dd2b9ac5f315cc590c4c89eefa413141655418f169cf411a0165c48f0f9da635b73b2fee915b73da9
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x9d0db2769be8bfbf32cdba76f867f4ab
Finished request 22.
Going to the next request
Waking up in 0.3 seconds.
rad_recv: Access-Request packet from host 192.168.183.110 port 55425,
id=93, length=169
User-Name = "invaliduser2"
NAS-Identifier = "openwrt"
NAS-Port = 2
Called-Station-Id = "00-18-F8-C1-66-46:testbed"
Calling-Station-Id = "00-1F-3A-49-EC-73"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 54Mbps 802.11g"
EAP-Message = 0x02e500060d00
State = 0x9d0db2769be8bfbf32cdba76f867f4ab
Message-Authenticator = 0x476057e77b2c0c0518242a8f101cc275
# Executing section authorize from file
/etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "invaliduser2", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 229 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/tls
[eap] processing type tls
[tls] Authenticate
[tls] processing EAP-TLS
[tls] Received TLS ACK
[tls] ACK handshake is finished
[tls] eaptls_verify returned 3
[tls] eaptls_process returned 3
[tls] Adding user data to cached session
[eap] Freeing handler
++[eap] returns ok
# Executing section post-auth from file
/etc/freeradius/sites-enabled/default
+- entering group post-auth {...}
++[exec] returns noop
Sending Access-Accept of id 93 to 192.168.183.110 port 55425
MS-MPPE-Recv-Key =
0xbaf2429720d7a5b7d92ace08ca21d2b623a379f67f25b406a314df47b51da996
MS-MPPE-Send-Key =
0xad7b449fcfdc531ebc0c985bab1d25d8843bd0fba29b646bc7c49b97f31df4d7
EAP-Message = 0x03e50004
Message-Authenticator = 0x00000000000000000000000000000000
User-Name = "invaliduser2"
Finished request 23.
Going to the next request
Waking up in 0.3 seconds.
Cleaning up request 8 ID 78 with timestamp +1040
Cleaning up request 9 ID 79 with timestamp +1040
Cleaning up request 10 ID 80 with timestamp +1040
Cleaning up request 11 ID 81 with timestamp +1040
Cleaning up request 12 ID 82 with timestamp +1040
Cleaning up request 13 ID 83 with timestamp +1041
Cleaning up request 14 ID 84 with timestamp +1041
Cleaning up request 15 ID 85 with timestamp +1041
Waking up in 4.1 seconds.
Cleaning up request 16 ID 86 with timestamp +1045
Cleaning up request 17 ID 87 with timestamp +1045
Cleaning up request 18 ID 88 with timestamp +1045
Cleaning up request 19 ID 89 with timestamp +1045
Cleaning up request 20 ID 90 with timestamp +1045
Cleaning up request 21 ID 91 with timestamp +1045
Cleaning up request 22 ID 92 with timestamp +1045
Cleaning up request 23 ID 93 with timestamp +1045
Ready to process requests.
3
5
Hi,
I'm trying to setup Dialup Admin to use HTTP authentication credentials to
connect to a mysql database. The HTTP authentication works, but the
PHP_AUTH_USER and PHP_AUTH_PW don't seem to be getting set, when trying to
connect to the DB I get "DEBUG(SQL,MYSQL DRIVER): Connect: User=,Password=
Could not connect to SQL database" (with SQL Debug enabled for Dialup Admin
and after setting "sql_use_http_credentials = yes" in my admin.conf).
This is with Apache2 2.2 and mod_php5 5.33. The mysql/functions.php3 file
is using the $HTTP_SERVER_VARS array, is that going to work with php5? Or
is there something else that I need to configure?
Thanks in advance!
--
View this message in context: http://freeradius.1045715.n5.nabble.com/Dialup-Admin-and-HTTP-Authenticatio…
Sent from the FreeRadius - User mailing list archive at Nabble.com.
1
1
hi
I have the operating system ubunto 10.4 with freeradisUs-server-2.1.10
I want to know if I should modify the archive in the clients.conf to get rid of or register clients.
Can anyone help me ??
Jessica Alejandra Martinez Bautista
3
3
Sorry Alan
I've not realized that the logs had became a garbage :O( - maybe a webmail realted issue of my ISP.
Now I Bcc myself to see how does it appear to recipients
I tried "man unlang" but got no manual entry - I'm using Freeradius packaged for CentOS - I'll give a look to http://freeradius.org/radiusd/man/unlang.html, I think is the same.
As for the previous post, ... here it is
Hi,
I'm facing this issue in configuring radius: I'm developing a GPLv3 script that will easily setup a whole linux server with lots of usefull services (NTP,DHCP,DNS with DDNS update to DHCP, MIT-Kerberos, OpenLDAP (Kerberized), FreeRadius,
MySQL, Apache, ProFTP, SQUID, Samba (kerberized), Appletalk File Protocol, Postfix and Dovecot (also with public and shared folders), roundcube webmail, LDAP Addressbook, PPTP and L2TP over IPSec VPNs, Egroupware. And it works with
SeLinux enabled.The script is quite mature (it is named ECK - you can download from sourceforge if you want to). It can install almost everything mentioned above, and they could even work ;O) - I've started the development of a GTKmm-
based GUI that will easily administer almost everything (although I have not published the GUI yet - the app is stable, but I've just finished the user manager, so I have a lot of work more to have somthing to publish)
And now the trouble with freeradius: I' d like to have most of the services with Radius Based Authentication - I think this will let me have a better loggiAggiungi un appuntamento per ogging system, expecially to trace sessions. As about
authentication everything works fine.
But I want also to do Authorization: I mean that I want to allow services FTP, VPN, Apache userdirs, Squid proxy, ecc. on per user basisI started with proftpd with mod_radius:
the idea is to use checkval module to catch the NAS-Identifier parameter that the proftpd module set as "ftp".
here is an example requestrad_recv:
Access-Request packet from host 127.0.0.1:9409, id=74, length=93
User-Name = "testuser"
User-Password = "test1Test"
NAS-Identifier = "ftp"
NAS-Port = 21
NAS-Port-Type = Virtual
Calling-Station-Id = "::ffff:127.0.0.1"
Service-Type = 0x0000000100000000
I inserted the following lines in my radiusd.conf:
checkval NAS{
item-name = NAS-Identifier
check-name = NAS-Identifier
data-type = string
notfound-reject=yes
}
and added "NAS" in the authorize sectionauthorize {
...
NAS
...
}
I also updated ldap.attrmap inserting the following line
checkItem NAS-Identifier eckAllowedServices
and obviously extended the LDAP schema (eck.schema)
attributetype ( 1.3.6.1.4.1.26309.1.1.11 NAME 'eckAllowedServices' DESC 'Services the user is allowed to login' EQUALITY caseIgnoreIA5Match SUBSTR caseIgnoreIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{128} )
objectClass ( 1.3.6.1.4.1.26309.1.1.1 NAME 'eckGenericObject' AUXILIARY DESC 'an ECK generic object' MAY ( locked $ eckPublicKey $ eckPrivateKey $ userPKCS12 $ allowProxy $ eckAllowedServices))
The script creates 2 users: Administrator - that is actually an administrator, and testuser. In my test environment I added 2 attributes eckAllowedServices to testuser (ftp and httpproxy) and left Administrator without eckAllowedServices
attributeAnd now the weird issue:
checkval is able to realize that testuser has the ftp attribute
modcall: entering group authorize for request 0
modcall[authorize]: module "preprocess" returns ok for request 0
modcall[authorize]: module "chap" returns noop for request 0
modcall[authorize]: module "mschap" returns noop for request 0
rlm_realm: No '@' in User-Name = "testuser", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 0
rlm_eap: No EAP-Message, not doing EAP
modcall[authorize]: module "eap" returns noop for request 0
rlm_ldap: - authorize
rlm_ldap: performing user authorization for testuser
radius_xlat: '(uid=testuser)'
radius_xlat: 'DC=marcolinux,DC=local'
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: attempting LDAP reconnection
rlm_ldap: (re)connect to 127.0.0.1:389, authentication 0
rlm_ldap: bind as CN=FreeRADIUS,OU=AAA,OU=Services,DC=marcolinux,DC=local/wRtEYnd3sGkEa.Y4 to 127.0.0.1:389
rlm_ldap: waiting for bind result ...
rlm_ldap: Bind was successful
rlm_ldap: performing search in DC=marcolinux,DC=local, with filter (uid=testuser)
rlm_ldap: checking if remote access for testuser is allowed by dialupAccess
rlm_ldap: Added password AB39C1761CF4947661DAB7AF9849A61E in check items
rlm_ldap: looking for check items in directory...
rlm_ldap: Adding eckAllowedServices as NAS-Identifier, value ftp & op=21
rlm_ldap: Adding eckAllowedServices as NAS-Identifier, value httpProxy & op=21
rlm_ldap: Adding sambaAcctFlags as SMB-Account-CTRL-TEXT, value [U ] & op=21
rlm_ldap: Adding sambaNTPassword as NT-Password, value AB39C1761CF4947661DAB7AF9849A61E & op=21
rlm_ldap: Adding radiusAuthType as Auth-Type, value pam & op=21
rlm_ldap: looking for reply items in directory...
rlm_ldap: Adding FTPQuotaFilesTransferred as ArticaECK-FTP-Quota-Files-Transferred, value 0 & op=11
rlm_ldap: Adding FTPQuotaFilesOutgoing as ArticaECK-FTP-Quota-Files-Outgoing, value 0 & op=11
rlm_ldap: Adding FTPQuotaFilesIncoming as ArticaECK-FTP-Quota-Files-Incoming, value 50 & op=11
rlm_ldap: Adding FTPQuotaBytesTransferred as ArticaECK-FTP-Quota-Bytes-Transferred, value 0 & op=11
rlm_ldap: Adding FTPQuotaBytesOutgoing as ArticaECK-FTP-Quota-Bytes-Outgoing, value 0 & op=11
rlm_ldap: Adding FTPQuotaBytesIncoming as ArticaECK-FTP-Quota-Bytes-Incoming, value 200 & op=11
rlm_ldap: Adding FTPQuotaIsPerSession as ArticaECK-FTP-Quota-Is-Per-Session, value FALSE & op=11
rlm_ldap: Adding FTPQuotaLimitType as ArticaECK-FTP-Quota-Limit-Type, value soft & op=11
rlm_ldap: Adding loginShell as ArticaECK-FTP-Shell, value /bin/tcsh & op=11
rlm_ldap: Adding homeDirectory as ArticaECK-FTP-Home, value /home/testuser & op=11
rlm_ldap: Adding gidNumber as ArticaECK-FTP-GID, value 100 & op=11
rlm_ldap: Adding uidNumber as ArticaECK-FTP-UID, value 1001 & op=11
rlm_ldap: user testuser authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
modcall[authorize]: module "ldap" returns ok for request 0
rlm_checkval: Item Name: NAS-Identifier, Value: ftp
rlm_checkval: Value Name: NAS-Identifier, Value: ftp
modcall[authorize]: module "NAS" returns ok for request 0
modcall: leaving group authorize (returns ok) for request 0
rad_check_password: Found Auth-Type pam
auth: type "PAM"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 0
pam_pass: using pamauth string <radiusd> for pam.conf lookup
pam_pass: authentication succeeded for <testuser>
modcall[authenticate]: module "pam" returns ok for request 0
modcall: leaving group authenticate (returns ok) for request 0
Processing the post-auth section of radiusd.conf
and that Administrator doesn't
rlm_ldap: Adding loginShell as ArticaECK-FTP-Shell, value /bin/bash & op=11
rlm_ldap: Adding homeDirectory as ArticaECK-FTP-Home, value /home/Administrator & op=11
rlm_ldap: Adding gidNumber as ArticaECK-FTP-GID, value 100 & op=11
rlm_ldap: Adding uidNumber as ArticaECK-FTP-UID, value 1000 & op=11
rlm_ldap: user Administrator authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
modcall[authorize]: module "ldap" returns ok for request 0
rlm_checkval: Item Name: NAS-Identifier, Value: ftp
rlm_checkval: Could not find attribute named NAS-Identifier in check pairs
modcall[authorize]: module "NAS" returns notfound for request 0
modcall: leaving group authorize (returns ok) for request 0
rad_check_password: Found Auth-Type pam
auth: type "PAM"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 0
pam_pass: using pamauth string <radiusd> for pam.conf lookup
pam_pass: authentication succeeded for <Administrator>
modcall[authenticate]: module "pam" returns ok for request 0
modcall: leaving group authenticate (returns ok) for request 0
Processing the post-auth section of radiusd.conf
but I always got both of them authorized. How is it possible? What I did wrong? Why freeradius goes to the authentication section altought checkval module module "NAS" returned notfound? I'm sure I did some kind of mistake, but I really am not able to find it. Now are days I'm googling around and getting quite crazy - I hope that someone of you may help meThank you very much
Marco Carcano
Configuration files
########################RADIUSD.CONF###############################
prefix = /usr
exec_prefix = /usr
sysconfdir = /etc
localstatedir = /var
sbindir = /usr/sbin
logdir = ${localstatedir}/log/radius
raddbdir = ${sysconfdir}/raddb
radacctdir = ${logdir}/radacct
confdir = ${raddbdir}
run_dir = ${localstatedir}/run/radiusd
log_file = ${logdir}/radius.log
libdir = /usr/lib
pidfile = ${run_dir}/radiusd.pid
user = radiusd
group = radiusd
max_request_time = 30
delete_blocked_requests = no
cleanup_delay = 5
max_requests = 1024
bind_address = *
port = 0
hostname_lookups = no
allow_core_dumps = no
regular_expressions = yes
extended_expressions = yes
log_stripped_names = no
log_auth = no
log_auth_badpass = no
log_auth_goodpass = no
usercollide = no
lower_user = no
lower_pass = no
nospace_user = no
nospace_pass = no
checkrad = ${sbindir}/checkrad
security {
max_attributes = 200
reject_delay = 1
status_server = no
}
proxy_requests = yes
$INCLUDE ${confdir}/proxy.conf
$INCLUDE ${confdir}/clients.conf
snmp = no
$INCLUDE ${confdir}/snmp.conf
thread pool {
start_servers = 5
max_servers = 32
min_spare_servers = 3
max_spare_servers = 10
max_requests_per_server = 0
}
modules {
pap {
encryption_scheme = crypt
}
chap {
authtype = CHAP
}
pam {
pam_auth = radiusd
}
$INCLUDE ${confdir}/eap.conf
mschap {
use_mppe = yes
require_encryption = yes
require_strong = yes
}
ldap {
server = "127.0.0.1"
identity = "CN=FreeRADIUS,OU=AAA,OU=Services,DC=marcolinux,DC=local"
password = wRtEYnd3sGkEa.Y4
basedn = "DC=marcolinux,DC=local"
filter = "(uid=%{Stripped-User-Name:-%{User-Name}})"
start_tls = no
access_attr = "dialupAccess"
dictionary_mapping = ${raddbdir}/ldap.attrmap
ldap_connections_number = 5
password_attribute = sambaNTPassword
timeout = 4
timelimit = 3
net_timeout = 1
}
realm IPASS {
format = prefix
delimiter = "/"
ignore_default = no
ignore_null = no
}
realm suffix {
format = suffix
delimiter = "@"
ignore_default = no
ignore_null = no
}
realm realmpercent {
format = suffix
delimiter = "%"
ignore_default = no
ignore_null = no
}
realm ntdomain {
format = prefix
delimiter = "\"
ignore_default = no
ignore_null = no
}
checkval NAS{
item-name = NAS-Identifier
check-name = NAS-Identifier
data-type = string
notfound-reject=yes
}
preprocess {
huntgroups = ${confdir}/huntgroups
hints = ${confdir}/hints
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
}
files {
usersfile = ${confdir}/users
acctusersfile = ${confdir}/acct_users
preproxy_usersfile = ${confdir}/preproxy_users
compat = no
}
detail {
detailfile = ${radacctdir}/%{Client-IP-Address}/detail-%Y%m%d
detailperm = 0600
}
acct_unique {
key = "User-Name, Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port"
}
$INCLUDE ${confdir}/sql.conf
radutmp {
filename = ${logdir}/radutmp
username = %{User-Name}
case_sensitive = yes
check_with_nas = yes
perm = 0600
callerid = "yes"
}
radutmp sradutmp {
filename = ${logdir}/sradutmp
perm = 0644
callerid = "no"
}
attr_filter {
attrsfile = ${confdir}/attrs
}
counter daily {
filename = ${raddbdir}/db.daily
key = User-Name
count-attribute = Acct-Session-Time
reset = daily
counter-name = Daily-Session-Time
check-name = Max-Daily-Session
allowed-servicetype = Framed-User
cache-size = 5000
}
sqlcounter dailycounter {
counter-name = Daily-Session-Time
check-name = Max-Daily-Session
sqlmod-inst = sql
key = User-Name
reset = daily
query = "SELECT SUM(AcctSessionTime - GREATEST((%b - UNIX_TIMESTAMP(AcctStartTime)), 0)) FROM radacct WHERE UserName='%{%k}' AND UNIX_TIMESTAMP(AcctStartTime) + AcctSessionTime > '%b'"
}
sqlcounter monthlycounter {
counter-name = Monthly-Session-Time
check-name = Max-Monthly-Session
sqlmod-inst = sql
key = User-Name
reset = monthly
query = "SELECT SUM(AcctSessionTime - GREATEST((%b - UNIX_TIMESTAMP(AcctStartTime)), 0)) FROM radacct WHERE UserName='%{%k}' AND UNIX_TIMESTAMP(AcctStartTime) + AcctSessionTime > '%b'"
}
always fail {
rcode = fail
}
always reject {
rcode = reject
}
always ok {
rcode = ok
simulcount = 0
mpp = no
}
expr {
}
digest {
}
exec {
wait = yes
input_pairs = request
}
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = request
output_pairs = reply
}
ippool main_pool {
range-start = 192.168.1.150
range-stop = 192.168.1.199
netmask = 255.255.255.0
cache-size = 800
session-db = ${localstatedir}/lib/raddb/db.ippool
ip-index = ${localstatedir}/lib/raddb/db.ipindex
override = no
maximum-timeout = 0
}
}
instantiate {
exec
expr
}
authorize {
preprocess
chap
mschap
suffix
eap
ldap
NAS
}
authenticate {
Auth-Type PAP {
pap
}
Auth-Type CHAP {
chap
}
Auth-Type MS-CHAP {
mschap
}
pam
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
radutmp
main_pool
sql
}
session {
radutmp
}
post-auth {
main_pool
}
pre-proxy {
}
post-proxy {
eap
}
##########################USERS################################
DEFAULT Auth-Type = pam
Fall-Through = 1
DEFAULT Service-Type == Framed-User
Framed-MTU = 576,
Service-Type = Framed-User,
Fall-Through = Yes
DEFAULT Pool-Name := main_pool
Fall-Through = Yes
DEFAULT Framed-Protocol == PPP
Framed-Protocol = PPP,
Framed-Compression = Van-Jacobson-TCP-IP
DEFAULT Hint == "CSLIP"
Framed-Protocol = SLIP,
Framed-Compression = Van-Jacobson-TCP-IP
DEFAULT Hint == "SLIP"
Framed-Protocol = SLIP
##################radiusd -X -f output ##############
Starting - reading configuration files ...
reread_config: reading radiusd.conf
Config: including file: /etc/raddb/proxy.conf
Config: including file: /etc/raddb/clients.conf
Config: including file: /etc/raddb/snmp.conf
Config: including file: /etc/raddb/eap.conf
Config: including file: /etc/raddb/sql.conf
main: prefix = "/usr"
main: localstatedir = "/var"
main: logdir = "/var/log/radius"
main: libdir = "/usr/lib"
main: radacctdir = "/var/log/radius/radacct"
main: hostname_lookups = no
main: snmp = no
main: max_request_time = 30
main: cleanup_delay = 5
main: max_requests = 1024
main: delete_blocked_requests = 0
main: port = 0
main: allow_core_dumps = no
main: log_stripped_names = no
main: log_file = "/var/log/radius/radius.log"
main: log_auth = no
main: log_auth_badpass = no
main: log_auth_goodpass = no
main: pidfile = "/var/run/radiusd/radiusd.pid"
main: user = "radiusd"
main: group = "radiusd"
main: usercollide = no
main: lower_user = "no"
main: lower_pass = "no"
main: nospace_user = "no"
main: nospace_pass = "no"
main: checkrad = "/usr/sbin/checkrad"
main: proxy_requests = yes
proxy: retry_delay = 5
proxy: retry_count = 3
proxy: synchronous = no
proxy: default_fallback = yes
proxy: dead_time = 120
proxy: post_proxy_authorize = no
proxy: wake_all_if_all_dead = no
security: max_attributes = 200
security: reject_delay = 1
security: status_server = no
main: debug_level = 0
read_config_files: reading dictionary
read_config_files: reading naslist
Using deprecated naslist file. Support for this will go away soon.
read_config_files: reading clients
read_config_files: reading realms
radiusd: entering modules setup
Module: Library search path is /usr/lib
Module: Loaded exec
exec: wait = yes
exec: program = "(null)"
exec: input_pairs = "request"
exec: output_pairs = "(null)"
exec: packet_type = "(null)"
rlm_exec: Wait=yes but no output defined. Did you mean output=none?
Module: Instantiated exec (exec)
Module: Loaded expr
Module: Instantiated expr (expr)
Module: Loaded PAP
pap: encryption_scheme = "crypt"
Module: Instantiated pap (pap)
Module: Loaded CHAP
Module: Instantiated chap (chap)
Module: Loaded MS-CHAP
mschap: use_mppe = yes
mschap: require_encryption = yes
mschap: require_strong = yes
mschap: with_ntdomain_hack = no
mschap: passwd = "(null)"
mschap: ntlm_auth = "(null)"
Module: Instantiated mschap (mschap)
Module: Loaded Pam
pam: pam_auth = "radiusd"
Module: Instantiated pam (pam)
Module: Loaded eap
eap: default_eap_type = "md5"
eap: timer_expire = 60
eap: ignore_unknown_eap_types = no
eap: cisco_accounting_username_bug = no
rlm_eap: Loaded and initialized type md5
rlm_eap: Loaded and initialized type leap
gtc: challenge = "Password: "
gtc: auth_type = "PAP"
rlm_eap: Loaded and initialized type gtc
mschapv2: with_ntdomain_hack = no
rlm_eap: Loaded and initialized type mschapv2
Module: Instantiated eap (eap)
Module: Loaded preprocess
preprocess: huntgroups = "/etc/raddb/huntgroups"
preprocess: hints = "/etc/raddb/hints"
preprocess: with_ascend_hack = no
preprocess: ascend_channels_per_line = 23
preprocess: with_ntdomain_hack = no
preprocess: with_specialix_jetstream_hack = no
preprocess: with_cisco_vsa_hack = no
preprocess: with_alvarion_vsa_hack = no
Module: Instantiated preprocess (preprocess)
Module: Loaded realm
realm: format = "suffix"
realm: delimiter = "@"
realm: ignore_default = no
realm: ignore_null = no
Module: Instantiated realm (suffix)
Module: Loaded LDAP
ldap: server = "127.0.0.1"
ldap: port = 389
ldap: net_timeout = 1
ldap: timeout = 4
ldap: timelimit = 3
ldap: identity = "CN=FreeRADIUS,OU=AAA,OU=Services,DC=marcolinux,DC=local"
ldap: tls_mode = no
ldap: start_tls = no
ldap: tls_cacertfile = "(null)"
ldap: tls_cacertdir = "(null)"
ldap: tls_certfile = "(null)"
ldap: tls_keyfile = "(null)"
ldap: tls_randfile = "(null)"
ldap: tls_require_cert = "allow"
ldap: password = "wRtEYnd3sGkEa.Y4"
ldap: basedn = "DC=marcolinux,DC=local"
ldap: filter = "(uid=%{Stripped-User-Name:-%{User-Name}})"
ldap: base_filter = "(objectclass=radiusprofile)"
ldap: default_profile = "(null)"
ldap: profile_attribute = "(null)"
ldap: password_header = "(null)"
ldap: password_attribute = "sambaNTPassword"
ldap: access_attr = "dialupAccess"
ldap: groupname_attribute = "cn"
ldap: groupmembership_filter = "(|(&(objectClass=GroupOfNames)(member=%{Ldap-UserDn}))(&(objectClass=GroupOfUniqueNames)(uniquemember=%{Ldap-UserDn})))"
ldap: groupmembership_attribute = "(null)"
ldap: dictionary_mapping = "/etc/raddb/ldap.attrmap"
ldap: ldap_debug = 0
ldap: ldap_connections_number = 5
ldap: compare_check_items = no
ldap: access_attr_used_for_allow = yes
ldap: do_xlat = yes
ldap: set_auth_type = yes
rlm_ldap: Registering ldap_groupcmp for Ldap-Group
rlm_ldap: Registering ldap_xlat with xlat_name ldap
rlm_ldap: Over-riding set_auth_type, as we're not listed in the "authenticate" section.
rlm_ldap: reading ldap<->radius mappings from file /etc/raddb/ldap.attrmap
rlm_ldap: LDAP radiusCheckItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusReplyItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusAuthType mapped to RADIUS Auth-Type
rlm_ldap: LDAP radiusSimultaneousUse mapped to RADIUS Simultaneous-Use
rlm_ldap: LDAP radiusCalledStationId mapped to RADIUS Called-Station-Id
rlm_ldap: LDAP radiusCallingStationId mapped to RADIUS Calling-Station-Id
rlm_ldap: LDAP sambaLMPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP sambaNTPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP sambaAcctFlags mapped to RADIUS SMB-Account-CTRL-TEXT
rlm_ldap: LDAP radiusExpiration mapped to RADIUS Expiration
rlm_ldap: LDAP radiusNASIpAddress mapped to RADIUS NAS-IP-Address
rlm_ldap: LDAP eckAllowedServices mapped to RADIUS NAS-Identifier
rlm_ldap: LDAP radiusServiceType mapped to RADIUS Service-Type
rlm_ldap: LDAP radiusFramedProtocol mapped to RADIUS Framed-Protocol
rlm_ldap: LDAP radiusFramedIPAddress mapped to RADIUS Framed-IP-Address
rlm_ldap: LDAP radiusFramedIPNetmask mapped to RADIUS Framed-IP-Netmask
rlm_ldap: LDAP radiusFramedRoute mapped to RADIUS Framed-Route
rlm_ldap: LDAP radiusFramedRouting mapped to RADIUS Framed-Routing
rlm_ldap: LDAP radiusFilterId mapped to RADIUS Filter-Id
rlm_ldap: LDAP radiusFramedMTU mapped to RADIUS Framed-MTU
rlm_ldap: LDAP radiusFramedCompression mapped to RADIUS Framed-Compression
rlm_ldap: LDAP radiusLoginIPHost mapped to RADIUS Login-IP-Host
rlm_ldap: LDAP radiusLoginService mapped to RADIUS Login-Service
rlm_ldap: LDAP radiusLoginTCPPort mapped to RADIUS Login-TCP-Port
rlm_ldap: LDAP radiusCallbackNumber mapped to RADIUS Callback-Number
rlm_ldap: LDAP radiusCallbackId mapped to RADIUS Callback-Id
rlm_ldap: LDAP radiusFramedIPXNetwork mapped to RADIUS Framed-IPX-Network
rlm_ldap: LDAP radiusClass mapped to RADIUS Class
rlm_ldap: LDAP radiusSessionTimeout mapped to RADIUS Session-Timeout
rlm_ldap: LDAP radiusIdleTimeout mapped to RADIUS Idle-Timeout
rlm_ldap: LDAP radiusTerminationAction mapped to RADIUS Termination-Action
rlm_ldap: LDAP radiusLoginLATService mapped to RADIUS Login-LAT-Service
rlm_ldap: LDAP radiusLoginLATNode mapped to RADIUS Login-LAT-Node
rlm_ldap: LDAP radiusLoginLATGroup mapped to RADIUS Login-LAT-Group
rlm_ldap: LDAP radiusFramedAppleTalkLink mapped to RADIUS Framed-AppleTalk-Link
rlm_ldap: LDAP radiusFramedAppleTalkNetwork mapped to RADIUS Framed-AppleTalk-Network
rlm_ldap: LDAP radiusFramedAppleTalkZone mapped to RADIUS Framed-AppleTalk-Zone
rlm_ldap: LDAP radiusPortLimit mapped to RADIUS Port-Limit
rlm_ldap: LDAP radiusLoginLATPort mapped to RADIUS Login-LAT-Port
rlm_ldap: LDAP radiusReplyMessage mapped to RADIUS Reply-Message
rlm_ldap: LDAP uidNumber mapped to RADIUS ArticaECK-FTP-UID
rlm_ldap: LDAP gidNumber mapped to RADIUS ArticaECK-FTP-GID
rlm_ldap: LDAP homeDirectory mapped to RADIUS ArticaECK-FTP-Home
rlm_ldap: LDAP loginShell mapped to RADIUS ArticaECK-FTP-Shell
rlm_ldap: LDAP FTPQuotaLimitType mapped to RADIUS ArticaECK-FTP-Quota-Limit-Type
rlm_ldap: LDAP FTPQuotaIsPerSession mapped to RADIUS ArticaECK-FTP-Quota-Is-Per-Session
rlm_ldap: LDAP FTPQuotaBytesIncoming mapped to RADIUS ArticaECK-FTP-Quota-Bytes-Incoming
rlm_ldap: LDAP FTPQuotaBytesOutgoing mapped to RADIUS ArticaECK-FTP-Quota-Bytes-Outgoing
rlm_ldap: LDAP FTPQuotaBytesTransferred mapped to RADIUS ArticaECK-FTP-Quota-Bytes-Transferred
rlm_ldap: LDAP FTPQuotaFilesIncoming mapped to RADIUS ArticaECK-FTP-Quota-Files-Incoming
rlm_ldap: LDAP FTPQuotaFilesOutgoing mapped to RADIUS ArticaECK-FTP-Quota-Files-Outgoing
rlm_ldap: LDAP FTPQuotaFilesTransferred mapped to RADIUS ArticaECK-FTP-Quota-Files-Transferred
conns: 0x2ba4857109b0
Module: Instantiated ldap (ldap)
Module: Loaded checkval
checkval: item-name = "NAS-Identifier"
checkval: check-name = "NAS-Identifier"
checkval: data-type = "string"
checkval: notfound-reject = yes
rlm_checkval: Registered name NAS-Identifier for attribute 32
Module: Instantiated checkval (NAS)
Module: Loaded Acct-Unique-Session-Id
acct_unique: key = "User-Name, Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port"
Module: Instantiated acct_unique (acct_unique)
Module: Loaded files
files: usersfile = "/etc/raddb/users"
files: acctusersfile = "/etc/raddb/acct_users"
files: preproxy_usersfile = "/etc/raddb/preproxy_users"
files: compat = "no"
Module: Instantiated files (files)
Module: Loaded detail
detail: detailfile = "/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d"
detail: detailperm = 384
detail: dirperm = 493
detail: locking = no
Module: Instantiated detail (detail)
Module: Loaded radutmp
radutmp: filename = "/var/log/radius/radutmp"
radutmp: username = "%{User-Name}"
radutmp: case_sensitive = yes
radutmp: check_with_nas = yes
radutmp: perm = 384
radutmp: callerid = yes
Module: Instantiated radutmp (radutmp)
Module: Loaded IPPOOL
ippool: session-db = "/var/lib/raddb/db.ippool"
ippool: ip-index = "/var/lib/raddb/db.ipindex"
ippool: range-start = 192.168.1.150 IP address [192.168.1.150]
ippool: range-stop = 192.168.1.199 IP address [192.168.1.199]
ippool: netmask = 255.255.255.0 IP address [255.255.255.0]
ippool: cache-size = 800
ippool: override = no
ippool: maximum-timeout = 0
Module: Instantiated ippool (main_pool)
Module: Loaded SQL
sql: driver = "rlm_sql_mysql"
sql: server = "localhost"
sql: port = ""
sql: login = "FreeRADIUS"
sql: password = "wRtEYnd3sGkEa.Y4"
sql: radius_db = "radius"
sql: nas_table = "nas"
sql: sqltrace = no
sql: sqltracefile = "/var/log/radius/sqltrace.sql"
sql: readclients = no
sql: deletestalesessions = yes
sql: num_sql_socks = 5
sql: sql_user_name = "%{User-Name}"
sql: default_user_profile = ""
sql: query_on_not_found = no
sql: authorize_check_query = "SELECT id, UserName, Attribute, Value, op FROM radcheck WHERE Username = '%{SQL-User-Name}' ORDER BY id"
sql: authorize_reply_query = "SELECT id, UserName, Attribute, Value, op FROM radreply WHERE Username = '%{SQL-User-Name}' ORDER BY id"
sql: authorize_group_check_query = "SELECT radgroupcheck.id,radgroupcheck.GroupName,radgroupcheck.Attribute,radgroupcheck.Value,radgroupcheck.op FROM radgroupcheck,usergroup WHERE usergroup.Username = '%{SQL-User-Name}' AND usergroup.GroupName = radgroupcheck.GroupName ORDER BY radgroupcheck.id"
sql: authorize_group_reply_query = "SELECT radgroupreply.id,radgroupreply.GroupName,radgroupreply.Attribute,radgroupreply.Value,radgroupreply.op FROM radgroupreply,usergroup WHERE usergroup.Username = '%{SQL-User-Name}' AND usergroup.GroupName = radgroupreply.GroupName ORDER BY radgroupreply.id"
sql: accounting_onoff_query = "UPDATE radacct SET AcctStopTime='%S', AcctSessionTime=unix_timestamp('%S') - unix_timestamp(AcctStartTime), AcctTerminateCause='%{Acct-Terminate-Cause}', AcctStopDelay = '%{Acct-Delay-Time}' WHERE AcctSessionTime=0 AND AcctStopTime=0 AND NASIPAddress= '%{NAS-IP-Address}' AND AcctStartTime <= '%S'"
sql: accounting_update_query = "UPDATE radacct SET FramedIPAddress = '%{Framed-IP-Address}', AcctSessionTime = '%{Acct-Session-Time}', AcctInputOctets = '%{Acct-Input-Octets}', AcctOutputOctets = '%{Acct-Output-Octets}' WHERE AcctSessionId = '%{Acct-Session-Id}' AND UserName = '%{SQL-User-Name}' AND NASIPAddress= '%{NAS-IP-Address}'"
sql: accounting_update_query_alt = "INSERT into radacct (AcctSessionId, AcctUniqueId, UserName, Realm, NASIPAddress, NASPortId, NASPortType, AcctStartTime, AcctSessionTime, AcctAuthentic, ConnectInfo_start, AcctInputOctets, AcctOutputOctets, CalledStationId, CallingStationId, ServiceType, FramedProtocol, FramedIPAddress, AcctStartDelay) values('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port}', '%{NAS-Port-Type}', DATE_SUB('%S',INTERVAL (%{Acct-Session-Time:-0} + %{Acct-Delay-Time:-0}) SECOND), '%{Acct-Session-Time}', '%{Acct-Authentic}', '', '%{Acct-Input-Octets}', '%{Acct-Output-Octets}', '%{Called-Station-Id}', '%{Calling-Station-Id}', '%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}', '0')"
sql: accounting_start_query = "INSERT into radacct (AcctSessionId, AcctUniqueId, UserName, Realm, NASIPAddress, NASPortId, NASPortType, AcctStartTime, AcctStopTime, AcctSessionTime, AcctAuthentic, ConnectInfo_start, ConnectInfo_stop, AcctInputOctets, AcctOutputOctets, CalledStationId, CallingStationId, AcctTerminateCause, ServiceType, FramedProtocol, FramedIPAddress, AcctStartDelay, AcctStopDelay) values('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port}', '%{NAS-Port-Type}', '%S', '0', '0', '%{Acct-Authentic}', '%{Connect-Info}', '', '0', '0', '%{Called-Station-Id}', '%{Calling-Station-Id}', '', '%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}', '%{Acct-Delay-Time}', '0')"
sql: accounting_start_query_alt = "UPDATE radacct SET AcctStartTime = '%S', AcctStartDelay = '%{Acct-Delay-Time}', ConnectInfo_start = '%{Connect-Info}' WHERE AcctSessionId = '%{Acct-Session-Id}' AND UserName = '%{SQL-User-Name}' AND NASIPAddress = '%{NAS-IP-Address}'"
sql: accounting_stop_query = "UPDATE radacct SET AcctStopTime = '%S', AcctSessionTime = '%{Acct-Session-Time}', AcctInputOctets = '%{Acct-Input-Octets}', AcctOutputOctets = '%{Acct-Output-Octets}', AcctTerminateCause = '%{Acct-Terminate-Cause}', AcctStopDelay = '%{Acct-Delay-Time}', ConnectInfo_stop = '%{Connect-Info}' WHERE AcctSessionId = '%{Acct-Session-Id}' AND UserName = '%{SQL-User-Name}' AND NASIPAddress = '%{NAS-IP-Address}'"
sql: accounting_stop_query_alt = "INSERT into radacct (AcctSessionId, AcctUniqueId, UserName, Realm, NASIPAddress, NASPortId, NASPortType, AcctStartTime, AcctStopTime, AcctSessionTime, AcctAuthentic, ConnectInfo_start, ConnectInfo_stop, AcctInputOctets, AcctOutputOctets, CalledStationId, CallingStationId, AcctTerminateCause, ServiceType, FramedProtocol, FramedIPAddress, AcctStartDelay, AcctStopDelay) values('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm}', '%{NAS-IP-Address}', '%{NAS-Port}', '%{NAS-Port-Type}', DATE_SUB('%S', INTERVAL (%{Acct-Session-Time:-0} + %{Acct-Delay-Time:-0}) SECOND), '%S', '%{Acct-Session-Time}', '%{Acct-Authentic}', '', '%{Connect-Info}', '%{Acct-Input-Octets}', '%{Acct-Output-Octets}', '%{Called-Station-Id}', '%{Calling-Station-Id}', '%{Acct-Terminate-Cause}', '%{Service-Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}', '0', '%{Acct-Delay-Time}')"
sql: group_membership_query = "SELECT GroupName FROM usergroup WHERE UserName='%{SQL-User-Name}'"
sql: connect_failure_retry_delay = 60
sql: simul_count_query = ""
sql: simul_verify_query = "SELECT RadAcctId, AcctSessionId, UserName, NASIPAddress, NASPortId, FramedIPAddress, CallingStationId, FramedProtocol FROM radacct WHERE UserName='%{SQL-User-Name}' AND AcctStopTime = 0"
sql: postauth_query = "INSERT into radpostauth (id, user, pass, reply, date) values ('', '%{User-Name}', '%{User-Password:-Chap-Password}', '%{reply:Packet-Type}', NOW())"
sql: safe-characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"
rlm_sql (sql): Driver rlm_sql_mysql (module rlm_sql_mysql) loaded and linked
rlm_sql (sql): Attempting to connect to FreeRADIUS@localhost:/radius
rlm_sql (sql): starting 0
rlm_sql (sql): Attempting to connect rlm_sql_mysql #0
rlm_sql_mysql: Starting connect to MySQL server for #0
rlm_sql (sql): Connected new DB handle, #0
rlm_sql (sql): starting 1
rlm_sql (sql): Attempting to connect rlm_sql_mysql #1
rlm_sql_mysql: Starting connect to MySQL server for #1
rlm_sql (sql): Connected new DB handle, #1
rlm_sql (sql): starting 2
rlm_sql (sql): Attempting to connect rlm_sql_mysql #2
rlm_sql_mysql: Starting connect to MySQL server for #2
rlm_sql (sql): Connected new DB handle, #2
rlm_sql (sql): starting 3
rlm_sql (sql): Attempting to connect rlm_sql_mysql #3
rlm_sql_mysql: Starting connect to MySQL server for #3
rlm_sql (sql): Connected new DB handle, #3
rlm_sql (sql): starting 4
rlm_sql (sql): Attempting to connect rlm_sql_mysql #4
rlm_sql_mysql: Starting connect to MySQL server for #4
rlm_sql (sql): Connected new DB handle, #4
Module: Instantiated sql (sql)
Listening on authentication *:1812
Listening on accounting *:1813
Ready to process requests.
4
11
Hi
I have ubuntu 10.4 with freeradisUs-server-2.1.10
my question is, where to add the Mac address? in users or clients.conf file, I have to change any line of any of them or use Terminal to do it?
Thank you.
Viridiana Ambriz Robles
3
2
Hi list,
today I discover a strange behaviour with FR and the PG backend: if the
authorize_group_check_query query returns a value that has a plus sign
(+) inside the groupname, FR thread that value as unicode. I think this
because into the next authorize_group_reply_query query, it use the
'=2B' chars.
The log:
[sql] expand: SELECT id, GroupName, Attribute, Value, op FROM
pppoe_group_check('%{SQL-User-Name}') -> SELECT id, GroupName,
Attribute, Value, op FROM pppoe_group_check('VALUE')
rlm_sql_postgresql: Status: PGRES_TUPLES_OK
rlm_sql_postgresql: query affected rows = 1 , fields = 5
[sql] User found in group G1+
[sql] expand: SELECT id, GroupName, Attribute, Value, op FROM
pppoe_group_reply() WHERE GroupName = '%{Sql-Group}' ORDER BY id ->
SELECT id, GroupName, Attribute, Value, op FROM pppoe_group_reply()
WHERE GroupName = 'G1=2B' ORDER BY id
rlm_sql_postgresql: Status: PGRES_TUPLES_OK
rlm_sql_postgresql: query affected rows = 0 , fields = 5
Like you can see I modify the queries, but I can't believe that is this
the problem
Thanks,
Michele
2
3
Hi list,
I'm looking if there is the possibility to send an "ntp server"
attribute to a pppoe-client (through nas, of course)
googleing I didn't found this option, or better, I found only like
dhcp-, but not for pppoe.
Thanks,
Michele
3
3