Freeradius-Users
Threads by month
- ----- 2026 -----
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 2 participants
- 27050 discussions
Hi!
We are using FreeRADIUS as service provider. For certain realms we need
to forward the access request to customer specific radius servers while
the rest is authenticated on our radius. This work in the following ways:
1) "user(a)example.net" wants access.
2) Our NAS tries to authenticate "example.net".
3) "example.net" is a realm that needs to be forwarded to a customer
specific server so our radius sends a reply containing attributes (like
the IP) that tells the NAS which specific radius server to use. This
is implemented by a local radius user named "example.net" with the
specific set of reply attributes.
4) The NAS authenticates the user using the customer radius.
The other case is as follows:
1) "user(a)example.com" wants access.
2) Our NAS tries to authenticate "example.com".
3) "example.com" is a realm that should be authenticated locally so the
radius server returns a reject.
4) The NAS then tries a second time using "user(a)example.com" and
sucessfully authenticates the user.
As you can imagine the second case leads to a notably number of access
rejects in the statistics of the server. Monitoring the rate of rejects
alone no longer is useful to monitor the health of the system as these
rejects are expected by design.
Now we are thinking about a solution and came up with the idea of
preventing a statistics update for these rejects. A new internal
attribute (e.g. FreeRADIUS-Inhibit-Stats-Update) would be added to the
request and the statistics update function would ignore requests that have
this attribute set. Setting that attribute in unlang would be easy as it
happens in a dedicated virtual server in our case.
Does this sound like a good solution for our problem?
Could that be useful for others as well (say: a pull-request on Github)?
Thanks!
--
Stefan
2
1
Hi,
I have 2 FreeRadius + MySQL servers in 2 different locations and everything
is working with no issues, now I'd like to add redundancy for MySQL.
Options:
1) MySQL MASTER/MASTER Replication
2) MySQL Master/Slave
3) FreeRadius SQL redundancy
4) any other idea?
I have already tested the option 1 but am not happy with it as am have some
errors with the accounting id in the db as am having duplicate entries. For
option 3 when the local mariadb is stopped the server doesn't start, is it
normal?
Regards,
Pizu
2
1
Hi,
Is it possible to ignore framed ip adress if it's in a specific IP address
range? Before it is being processed in the accounting/pre accounting?
Thanks.
3
6
Hai,
Please read :
https://wiki.samba.org/index.php/Authenticating_Freeradius_against_Active_D…
This one is at the moment the only page with the complete info you need..
(for this error)
@Alan,
These pages are not fully correct.
http://deployingradius.com/documents/configuration/active_directory.html
Its not complete. (sorry).. You did add the part about : ntlm auth = mschapv2-and-ntlmv2-only
Just, im not seeing these parts. : --allow-mschapv2
Which is key to make it work.
https://wiki.freeradius.org/guide/freeradius-active-directory-integration-h…
Also i see incorrect SMB.conf settings and both are missing the part to use NTLMv2.
The link to the samba wiki contain all needed info for the freeradius part.
For the smb.conf part, that depends if its a stand alone samba server of domain member/AD-DC.
Updating these could save you lots of message in the list. ;-)
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: Freeradius-Users
> [mailto:freeradius-users-bounces+belle=bazuin.nl@lists.freerad
> ius.org] Namens Jure Simši?? via Freeradius-Users
> Verzonden: donderdag 12 augustus 2021 11:07
> Aan: Freeradius-Users
> CC: Jure Simši??
> Onderwerp: MSCHAP No logon servers are currently available
>
> Hi,
> I've been trying to set up radius+AD integration. I'm
> following the docs
> http://deployingradius.com/documents/configuration/active_dire
> ctory.html and everything is ok until I get to the last part
> where I enable ntlm_auth in mods/mschap. I'm getting back
>
> (0) mschap: ERROR: Program returned code (1) and output 'No
> logon servers are currently available to service the logon
> request. (0xc000005e)'
> (0) mschap: ERROR: No logon servers are currently available
> to service the logon request. (0xc000005e)
> (0) mschap: Authentication failed
>
> (full debug below). I've found a thread
> https://serverfault.com/questions/608227/authentication-via-ra
> dius-mschapv2-error-691 saying there is a reg setting for win
> to force radius to use ntlm2 but the link on MS KB is dead
> and their search isn't useful.. Does this seem to be this
> NTLM/NTLM2 issue or might it be something else?
>
> Also the users here are used to using their name@domain in
> their current setup and ntlm_auth expects just name as
> --username and not name@domain. I've seen the use of
> Stripped-User-Name but it seems you need to ~activate it
> somehow to use it. If I can use this there will be less
> confusion with the users. Is this possible?
>
>
> Thank you
> Cheers Jure
>
> ====================
> # freeradius -X
> FreeRADIUS Version 3.0.17
> Copyright (C) 1999-2017 The FreeRADIUS server project and contributors
> There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
> PARTICULAR PURPOSE
> You may redistribute copies of FreeRADIUS under the terms of the
> GNU General Public License
> For more information about these matters, see the file named COPYRIGHT
> Starting - reading configuration files ...
> including dictionary file /usr/share/freeradius/dictionary
> including dictionary file /usr/share/freeradius/dictionary.dhcp
> including dictionary file /usr/share/freeradius/dictionary.vqp
> including dictionary file /etc/freeradius/3.0/dictionary
> including configuration file /etc/freeradius/3.0/radiusd.conf
> including configuration file /etc/freeradius/3.0/proxy.conf
> including configuration file /etc/freeradius/3.0/clients.conf
> including files in directory /etc/freeradius/3.0/mods-enabled/
> including configuration file
> /etc/freeradius/3.0/mods-enabled/preprocess
> including configuration file
> /etc/freeradius/3.0/mods-enabled/replicate
> including configuration file
> /etc/freeradius/3.0/mods-enabled/expiration
> including configuration file /etc/freeradius/3.0/mods-enabled/utf8
> including configuration file
> /etc/freeradius/3.0/mods-enabled/logintime
> including configuration file /etc/freeradius/3.0/mods-enabled/expr
> including configuration file /etc/freeradius/3.0/mods-enabled/files
> including configuration file /etc/freeradius/3.0/mods-enabled/unpack
> including configuration file /etc/freeradius/3.0/mods-enabled/eap
> including configuration file /etc/freeradius/3.0/mods-enabled/detail
> including configuration file /etc/freeradius/3.0/mods-enabled/passwd
> including configuration file /etc/freeradius/3.0/mods-enabled/linelog
> including configuration file /etc/freeradius/3.0/mods-enabled/unix
> including configuration file /etc/freeradius/3.0/mods-enabled/mschap
> including configuration file
> /etc/freeradius/3.0/mods-enabled/ntlm_auth
> including configuration file /etc/freeradius/3.0/mods-enabled/exec
> including configuration file /etc/freeradius/3.0/mods-enabled/realm
> including configuration file /etc/freeradius/3.0/mods-enabled/echo
> including configuration file /etc/freeradius/3.0/mods-enabled/always
> including configuration file /etc/freeradius/3.0/mods-enabled/sradutmp
> including configuration file /etc/freeradius/3.0/mods-enabled/chap
> including configuration file /etc/freeradius/3.0/mods-enabled/soh
> including configuration file
> /etc/freeradius/3.0/mods-enabled/cache_eap
> including configuration file
> /etc/freeradius/3.0/mods-enabled/attr_filter
> including configuration file /etc/freeradius/3.0/mods-enabled/radutmp
> including configuration file /etc/freeradius/3.0/mods-enabled/digest
> including configuration file
> /etc/freeradius/3.0/mods-enabled/dynamic_clients
> including configuration file /etc/freeradius/3.0/mods-enabled/pap
> including configuration file
> /etc/freeradius/3.0/mods-enabled/detail.log
> including files in directory /etc/freeradius/3.0/policy.d/
> including configuration file /etc/freeradius/3.0/policy.d/filter
> including configuration file /etc/freeradius/3.0/policy.d/abfab-tr
> including configuration file /etc/freeradius/3.0/policy.d/control
> including configuration file
> /etc/freeradius/3.0/policy.d/moonshot-targeted-ids
> including configuration file
> /etc/freeradius/3.0/policy.d/canonicalization
> including configuration file /etc/freeradius/3.0/policy.d/accounting
> including configuration file /etc/freeradius/3.0/policy.d/eap
> including configuration file /etc/freeradius/3.0/policy.d/dhcp
> including configuration file
> /etc/freeradius/3.0/policy.d/operator-name
> including configuration file /etc/freeradius/3.0/policy.d/debug
> including configuration file /etc/freeradius/3.0/policy.d/cui
> including files in directory /etc/freeradius/3.0/sites-enabled/
> including configuration file
> /etc/freeradius/3.0/sites-enabled/inner-tunnel
> including configuration file /etc/freeradius/3.0/sites-enabled/default
> main {
> security {
> user = "freerad"
> group = "freerad"
> allow_core_dumps = no
> }
> name = "freeradius"
> prefix = "/usr"
> localstatedir = "/var"
> logdir = "/var/log/freeradius"
> run_dir = "/var/run/freeradius"
> }
> main {
> name = "freeradius"
> prefix = "/usr"
> localstatedir = "/var"
> sbindir = "/usr/sbin"
> logdir = "/var/log/freeradius"
> run_dir = "/var/run/freeradius"
> libdir = "/usr/lib/freeradius"
> radacctdir = "/var/log/freeradius/radacct"
> hostname_lookups = no
> max_request_time = 30
> cleanup_delay = 5
> max_requests = 16384
> pidfile = "/var/run/freeradius/freeradius.pid"
> checkrad = "/usr/sbin/checkrad"
> debug_level = 0
> proxy_requests = yes
> log {
> stripped_names = no
> auth = no
> auth_badpass = no
> auth_goodpass = no
> colourise = yes
> msg_denied = "You are already logged in - access denied"
> }
> resources {
> }
> security {
> max_attributes = 200
> reject_delay = 1.000000
> status_server = yes
> }
> }
> radiusd: #### Loading Realms and Home Servers ####
> proxy server {
> retry_delay = 5
> retry_count = 3
> default_fallback = no
> dead_time = 120
> wake_all_if_all_dead = no
> }
> home_server localhost {
> ipaddr = 127.0.0.1
> port = 1812
> type = "auth"
> secret = <<< secret >>>
> response_window = 20.000000
> response_timeouts = 1
> max_outstanding = 65536
> zombie_period = 40
> status_check = "status-server"
> ping_interval = 30
> check_interval = 30
> check_timeout = 4
> num_answers_to_alive = 3
> revive_interval = 120
> limit {
> max_connections = 16
> max_requests = 0
> lifetime = 0
> idle_timeout = 0
> }
> coa {
> irt = 2
> mrt = 16
> mrc = 5
> mrd = 30
> }
> }
> home_server_pool my_auth_failover {
> type = fail-over
> home_server = localhost
> }
> realm example.com {
> auth_pool = my_auth_failover
> }
> realm LOCAL {
> }
> radiusd: #### Loading Clients ####
> client localhost {
> ipaddr = 127.0.0.1
> require_message_authenticator = no
> secret = <<< secret >>>
> nas_type = "other"
> proto = "*"
> limit {
> max_connections = 16
> lifetime = 0
> idle_timeout = 30
> }
> }
> client localhost_ipv6 {
> ipv6addr = ::1
> require_message_authenticator = no
> secret = <<< secret >>>
> limit {
> max_connections = 16
> lifetime = 0
> idle_timeout = 30
> }
> }
> client FMFUnifiController {
> ipaddr = 10.20.12.2
> require_message_authenticator = no
> secret = <<< secret >>>
> limit {
> max_connections = 16
> lifetime = 0
> idle_timeout = 30
> }
> }
> Debugger not attached
> # Creating Auth-Type = mschap
> # Creating Auth-Type = ntlm_auth
> # Creating Auth-Type = eap
> # Creating Auth-Type = PAP
> # Creating Auth-Type = CHAP
> # Creating Auth-Type = MS-CHAP
> # Creating Auth-Type = digest
> radiusd: #### Instantiating modules ####
> modules {
> # Loaded module rlm_preprocess
> # Loading module "preprocess" from file
> /etc/freeradius/3.0/mods-enabled/preprocess
> preprocess {
> huntgroups =
> "/etc/freeradius/3.0/mods-config/preprocess/huntgroups"
> hints = "/etc/freeradius/3.0/mods-config/preprocess/hints"
> with_ascend_hack = no
> ascend_channels_per_line = 23
> with_ntdomain_hack = no
> with_specialix_jetstream_hack = no
> with_cisco_vsa_hack = no
> with_alvarion_vsa_hack = no
> }
> # Loaded module rlm_replicate
> # Loading module "replicate" from file
> /etc/freeradius/3.0/mods-enabled/replicate
> # Loaded module rlm_expiration
> # Loading module "expiration" from file
> /etc/freeradius/3.0/mods-enabled/expiration
> # Loaded module rlm_utf8
> # Loading module "utf8" from file
> /etc/freeradius/3.0/mods-enabled/utf8
> # Loaded module rlm_logintime
> # Loading module "logintime" from file
> /etc/freeradius/3.0/mods-enabled/logintime
> logintime {
> minimum_timeout = 60
> }
> # Loaded module rlm_expr
> # Loading module "expr" from file
> /etc/freeradius/3.0/mods-enabled/expr
> expr {
> safe_characters =
> "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ01234567
> 89.-_: /äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
> }
> # Loaded module rlm_files
> # Loading module "files" from file
> /etc/freeradius/3.0/mods-enabled/files
> files {
> filename = "/etc/freeradius/3.0/mods-config/files/authorize"
> acctusersfile =
> "/etc/freeradius/3.0/mods-config/files/accounting"
> preproxy_usersfile =
> "/etc/freeradius/3.0/mods-config/files/pre-proxy"
> }
> # Loaded module rlm_unpack
> # Loading module "unpack" from file
> /etc/freeradius/3.0/mods-enabled/unpack
> # Loaded module rlm_eap
> # Loading module "eap" from file
> /etc/freeradius/3.0/mods-enabled/eap
> eap {
> default_eap_type = "md5"
> timer_expire = 60
> ignore_unknown_eap_types = no
> cisco_accounting_username_bug = no
> max_sessions = 16384
> }
> # Loaded module rlm_detail
> # Loading module "detail" from file
> /etc/freeradius/3.0/mods-enabled/detail
> detail {
> filename =
> "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Pac
> ket-Src-IPv6-Address}}/detail-%Y%m%d"
> header = "%t"
> permissions = 384
> locking = no
> escape_filenames = no
> log_packet_header = no
> }
> # Loaded module rlm_passwd
> # Loading module "etc_passwd" from file
> /etc/freeradius/3.0/mods-enabled/passwd
> passwd etc_passwd {
> filename = "/etc/passwd"
> format = "*User-Name:Crypt-Password:"
> delimiter = ":"
> ignore_nislike = no
> ignore_empty = yes
> allow_multiple_keys = no
> hash_size = 100
> }
> # Loaded module rlm_linelog
> # Loading module "linelog" from file
> /etc/freeradius/3.0/mods-enabled/linelog
> linelog {
> filename = "/var/log/freeradius/linelog"
> escape_filenames = no
> syslog_severity = "info"
> permissions = 384
> format = "This is a log message for %{User-Name}"
> reference = "messages.%{%{reply:Packet-Type}:-default}"
> }
> # Loading module "log_accounting" from file
> /etc/freeradius/3.0/mods-enabled/linelog
> linelog log_accounting {
> filename = "/var/log/freeradius/linelog-accounting"
> escape_filenames = no
> syslog_severity = "info"
> permissions = 384
> format = ""
> reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
> }
> # Loaded module rlm_unix
> # Loading module "unix" from file
> /etc/freeradius/3.0/mods-enabled/unix
> unix {
> radwtmp = "/var/log/freeradius/radwtmp"
> }
> Creating attribute Unix-Group
> # Loaded module rlm_mschap
> # Loading module "mschap" from file
> /etc/freeradius/3.0/mods-enabled/mschap
> mschap {
> use_mppe = yes
> require_encryption = no
> require_strong = no
> with_ntdomain_hack = yes
> ntlm_auth = "/usr/bin/ntlm_auth --request-nt-key
> --username=%{mschap:User-Name:-None}
> --domain=%{%{mschap:NT-Domain}:-FMF.UNI-LJ.SI}
> --challenge=%{mschap:Challenge:-00}
> --nt-response=%{mschap:NT-Response:-00}"
> passchange {
> }
> allow_retry = yes
> winbind_retry_with_normalised_username = no
> }
> # Loaded module rlm_exec
> # Loading module "ntlm_auth" from file
> /etc/freeradius/3.0/mods-enabled/ntlm_auth
> exec ntlm_auth {
> wait = yes
> program = "/usr/bin/ntlm_auth --request-nt-key
> --domain=FMF.UNI-LJ.SI --username=%{mschap:User-Name}
> --password=%{User-Password}"
> shell_escape = yes
> }
> # Loading module "exec" from file
> /etc/freeradius/3.0/mods-enabled/exec
> exec {
> wait = no
> input_pairs = "request"
> shell_escape = yes
> timeout = 10
> }
> # Loaded module rlm_realm
> # Loading module "IPASS" from file
> /etc/freeradius/3.0/mods-enabled/realm
> realm IPASS {
> format = "prefix"
> delimiter = "/"
> ignore_default = no
> ignore_null = no
> }
> # Loading module "suffix" from file
> /etc/freeradius/3.0/mods-enabled/realm
> realm suffix {
> format = "suffix"
> delimiter = "@"
> ignore_default = no
> ignore_null = no
> }
> # Loading module "realmpercent" from file
> /etc/freeradius/3.0/mods-enabled/realm
> realm realmpercent {
> format = "suffix"
> delimiter = "%"
> ignore_default = no
> ignore_null = no
> }
> # Loading module "ntdomain" from file
> /etc/freeradius/3.0/mods-enabled/realm
> realm ntdomain {
> format = "prefix"
> delimiter = "\\"
> ignore_default = no
> ignore_null = no
> }
> # Loading module "echo" from file
> /etc/freeradius/3.0/mods-enabled/echo
> exec echo {
> wait = yes
> program = "/bin/echo %{User-Name}"
> input_pairs = "request"
> output_pairs = "reply"
> shell_escape = yes
> }
> # Loaded module rlm_always
> # Loading module "reject" from file
> /etc/freeradius/3.0/mods-enabled/always
> always reject {
> rcode = "reject"
> simulcount = 0
> mpp = no
> }
> # Loading module "fail" from file
> /etc/freeradius/3.0/mods-enabled/always
> always fail {
> rcode = "fail"
> simulcount = 0
> mpp = no
> }
> # Loading module "ok" from file
> /etc/freeradius/3.0/mods-enabled/always
> always ok {
> rcode = "ok"
> simulcount = 0
> mpp = no
> }
> # Loading module "handled" from file
> /etc/freeradius/3.0/mods-enabled/always
> always handled {
> rcode = "handled"
> simulcount = 0
> mpp = no
> }
> # Loading module "invalid" from file
> /etc/freeradius/3.0/mods-enabled/always
> always invalid {
> rcode = "invalid"
> simulcount = 0
> mpp = no
> }
> # Loading module "userlock" from file
> /etc/freeradius/3.0/mods-enabled/always
> always userlock {
> rcode = "userlock"
> simulcount = 0
> mpp = no
> }
> # Loading module "notfound" from file
> /etc/freeradius/3.0/mods-enabled/always
> always notfound {
> rcode = "notfound"
> simulcount = 0
> mpp = no
> }
> # Loading module "noop" from file
> /etc/freeradius/3.0/mods-enabled/always
> always noop {
> rcode = "noop"
> simulcount = 0
> mpp = no
> }
> # Loading module "updated" from file
> /etc/freeradius/3.0/mods-enabled/always
> always updated {
> rcode = "updated"
> simulcount = 0
> mpp = no
> }
> # Loaded module rlm_radutmp
> # Loading module "sradutmp" from file
> /etc/freeradius/3.0/mods-enabled/sradutmp
> radutmp sradutmp {
> filename = "/var/log/freeradius/sradutmp"
> username = "%{User-Name}"
> case_sensitive = yes
> check_with_nas = yes
> permissions = 420
> caller_id = no
> }
> # Loaded module rlm_chap
> # Loading module "chap" from file
> /etc/freeradius/3.0/mods-enabled/chap
> # Loaded module rlm_soh
> # Loading module "soh" from file
> /etc/freeradius/3.0/mods-enabled/soh
> soh {
> dhcp = yes
> }
> # Loaded module rlm_cache
> # Loading module "cache_eap" from file
> /etc/freeradius/3.0/mods-enabled/cache_eap
> cache cache_eap {
> driver = "rlm_cache_rbtree"
> key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
> ttl = 15
> max_entries = 0
> epoch = 0
> add_stats = no
> }
> # Loaded module rlm_attr_filter
> # Loading module "attr_filter.post-proxy" from file
> /etc/freeradius/3.0/mods-enabled/attr_filter
> attr_filter attr_filter.post-proxy {
> filename =
> "/etc/freeradius/3.0/mods-config/attr_filter/post-proxy"
> key = "%{Realm}"
> relaxed = no
> }
> # Loading module "attr_filter.pre-proxy" from file
> /etc/freeradius/3.0/mods-enabled/attr_filter
> attr_filter attr_filter.pre-proxy {
> filename =
> "/etc/freeradius/3.0/mods-config/attr_filter/pre-proxy"
> key = "%{Realm}"
> relaxed = no
> }
> # Loading module "attr_filter.access_reject" from file
> /etc/freeradius/3.0/mods-enabled/attr_filter
> attr_filter attr_filter.access_reject {
> filename =
> "/etc/freeradius/3.0/mods-config/attr_filter/access_reject"
> key = "%{User-Name}"
> relaxed = no
> }
> # Loading module "attr_filter.access_challenge" from file
> /etc/freeradius/3.0/mods-enabled/attr_filter
> attr_filter attr_filter.access_challenge {
> filename =
> "/etc/freeradius/3.0/mods-config/attr_filter/access_challenge"
> key = "%{User-Name}"
> relaxed = no
> }
> # Loading module "attr_filter.accounting_response" from
> file /etc/freeradius/3.0/mods-enabled/attr_filter
> attr_filter attr_filter.accounting_response {
> filename =
> "/etc/freeradius/3.0/mods-config/attr_filter/accounting_response"
> key = "%{User-Name}"
> relaxed = no
> }
> # Loading module "radutmp" from file
> /etc/freeradius/3.0/mods-enabled/radutmp
> radutmp {
> filename = "/var/log/freeradius/radutmp"
> username = "%{User-Name}"
> case_sensitive = yes
> check_with_nas = yes
> permissions = 384
> caller_id = yes
> }
> # Loaded module rlm_digest
> # Loading module "digest" from file
> /etc/freeradius/3.0/mods-enabled/digest
> # Loaded module rlm_dynamic_clients
> # Loading module "dynamic_clients" from file
> /etc/freeradius/3.0/mods-enabled/dynamic_clients
> # Loaded module rlm_pap
> # Loading module "pap" from file
> /etc/freeradius/3.0/mods-enabled/pap
> pap {
> normalise = yes
> }
> # Loading module "auth_log" from file
> /etc/freeradius/3.0/mods-enabled/detail.log
> detail auth_log {
> filename =
> "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Pac
> ket-Src-IPv6-Address}}/auth-detail-%Y%m%d"
> header = "%t"
> permissions = 384
> locking = no
> escape_filenames = no
> log_packet_header = no
> }
> # Loading module "reply_log" from file
> /etc/freeradius/3.0/mods-enabled/detail.log
> detail reply_log {
> filename =
> "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Pac
> ket-Src-IPv6-Address}}/reply-detail-%Y%m%d"
> header = "%t"
> permissions = 384
> locking = no
> escape_filenames = no
> log_packet_header = no
> }
> # Loading module "pre_proxy_log" from file
> /etc/freeradius/3.0/mods-enabled/detail.log
> detail pre_proxy_log {
> filename =
> "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Pac
> ket-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
> header = "%t"
> permissions = 384
> locking = no
> escape_filenames = no
> log_packet_header = no
> }
> # Loading module "post_proxy_log" from file
> /etc/freeradius/3.0/mods-enabled/detail.log
> detail post_proxy_log {
> filename =
> "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Pac
> ket-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
> header = "%t"
> permissions = 384
> locking = no
> escape_filenames = no
> log_packet_header = no
> }
> instantiate {
> }
> # Instantiating module "preprocess" from file
> /etc/freeradius/3.0/mods-enabled/preprocess
> reading pairlist file
> /etc/freeradius/3.0/mods-config/preprocess/huntgroups
> reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/hints
> # Instantiating module "expiration" from file
> /etc/freeradius/3.0/mods-enabled/expiration
> # Instantiating module "logintime" from file
> /etc/freeradius/3.0/mods-enabled/logintime
> # Instantiating module "files" from file
> /etc/freeradius/3.0/mods-enabled/files
> reading pairlist file /etc/freeradius/3.0/mods-config/files/authorize
> reading pairlist file /etc/freeradius/3.0/mods-config/files/accounting
> reading pairlist file /etc/freeradius/3.0/mods-config/files/pre-proxy
> # Instantiating module "eap" from file
> /etc/freeradius/3.0/mods-enabled/eap
> # Linked to sub-module rlm_eap_md5
> # Linked to sub-module rlm_eap_leap
> # Linked to sub-module rlm_eap_gtc
> gtc {
> challenge = "Password: "
> auth_type = "PAP"
> }
> # Linked to sub-module rlm_eap_tls
> tls {
> tls = "tls-common"
> }
> tls-config tls-common {
> verify_depth = 0
> ca_path = "/etc/freeradius/3.0/certs"
> pem_file_type = yes
> private_key_file = "/etc/ssl/private/ssl-cert-snakeoil.key"
> certificate_file = "/etc/ssl/certs/ssl-cert-snakeoil.pem"
> ca_file = "/etc/ssl/certs/ca-certificates.crt"
> private_key_password = <<< secret >>>
> dh_file = "/etc/freeradius/3.0/certs/dh"
> fragment_size = 1024
> include_length = yes
> auto_chain = yes
> check_crl = no
> check_all_crl = no
> cipher_list = "DEFAULT"
> cipher_server_preference = no
> ecdh_curve = "prime256v1"
> tls_max_version = ""
> tls_min_version = "1.0"
> cache {
> enable = no
> lifetime = 24
> max_entries = 255
> }
> verify {
> skip_if_ocsp_ok = no
> }
> ocsp {
> enable = no
> override_cert_url = yes
> url = "http://127.0.0.1/ocsp/"
> use_nonce = yes
> timeout = 0
> softfail = no
> }
> }
> # Linked to sub-module rlm_eap_ttls
> ttls {
> tls = "tls-common"
> default_eap_type = "md5"
> copy_request_to_tunnel = no
> use_tunneled_reply = no
> virtual_server = "inner-tunnel"
> include_length = yes
> require_client_cert = no
> }
> tls: Using cached TLS configuration from previous invocation
> # Linked to sub-module rlm_eap_peap
> peap {
> tls = "tls-common"
> default_eap_type = "mschapv2"
> copy_request_to_tunnel = no
> use_tunneled_reply = no
> proxy_tunneled_request_as_eap = yes
> virtual_server = "inner-tunnel"
> soh = no
> require_client_cert = no
> }
> tls: Using cached TLS configuration from previous invocation
> # Linked to sub-module rlm_eap_mschapv2
> mschapv2 {
> with_ntdomain_hack = no
> send_error = no
> }
> # Instantiating module "detail" from file
> /etc/freeradius/3.0/mods-enabled/detail
> # Instantiating module "etc_passwd" from file
> /etc/freeradius/3.0/mods-enabled/passwd
> rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
> # Instantiating module "linelog" from file
> /etc/freeradius/3.0/mods-enabled/linelog
> # Instantiating module "log_accounting" from file
> /etc/freeradius/3.0/mods-enabled/linelog
> # Instantiating module "mschap" from file
> /etc/freeradius/3.0/mods-enabled/mschap
> rlm_mschap (mschap): authenticating by calling 'ntlm_auth'
> # Instantiating module "IPASS" from file
> /etc/freeradius/3.0/mods-enabled/realm
> # Instantiating module "suffix" from file
> /etc/freeradius/3.0/mods-enabled/realm
> # Instantiating module "realmpercent" from file
> /etc/freeradius/3.0/mods-enabled/realm
> # Instantiating module "ntdomain" from file
> /etc/freeradius/3.0/mods-enabled/realm
> # Instantiating module "reject" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "fail" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "ok" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "handled" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "invalid" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "userlock" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "notfound" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "noop" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "updated" from file
> /etc/freeradius/3.0/mods-enabled/always
> # Instantiating module "cache_eap" from file
> /etc/freeradius/3.0/mods-enabled/cache_eap
> rlm_cache (cache_eap): Driver rlm_cache_rbtree (module
> rlm_cache_rbtree) loaded and linked
> # Instantiating module "attr_filter.post-proxy" from file
> /etc/freeradius/3.0/mods-enabled/attr_filter
> reading pairlist file
> /etc/freeradius/3.0/mods-config/attr_filter/post-proxy
> # Instantiating module "attr_filter.pre-proxy" from file
> /etc/freeradius/3.0/mods-enabled/attr_filter
> reading pairlist file
> /etc/freeradius/3.0/mods-config/attr_filter/pre-proxy
> # Instantiating module "attr_filter.access_reject" from
> file /etc/freeradius/3.0/mods-enabled/attr_filter
> reading pairlist file
> /etc/freeradius/3.0/mods-config/attr_filter/access_reject
> [/etc/freeradius/3.0/mods-config/attr_filter/access_reject]:11
> Check item "FreeRADIUS-Response-Delay" found in filter
> list for realm "DEFAULT".
> [/etc/freeradius/3.0/mods-config/attr_filter/access_reject]:11
> Check item "FreeRADIUS-Response-Delay-USec" found in filter
> list for realm "DEFAULT".
> # Instantiating module "attr_filter.access_challenge" from
> file /etc/freeradius/3.0/mods-enabled/attr_filter
> reading pairlist file
> /etc/freeradius/3.0/mods-config/attr_filter/access_challenge
> # Instantiating module "attr_filter.accounting_response"
> from file /etc/freeradius/3.0/mods-enabled/attr_filter
> reading pairlist file
> /etc/freeradius/3.0/mods-config/attr_filter/accounting_response
> # Instantiating module "pap" from file
> /etc/freeradius/3.0/mods-enabled/pap
> # Instantiating module "auth_log" from file
> /etc/freeradius/3.0/mods-enabled/detail.log
> rlm_detail (auth_log): 'User-Password' suppressed, will not
> appear in detail output
> # Instantiating module "reply_log" from file
> /etc/freeradius/3.0/mods-enabled/detail.log
> # Instantiating module "pre_proxy_log" from file
> /etc/freeradius/3.0/mods-enabled/detail.log
> # Instantiating module "post_proxy_log" from file
> /etc/freeradius/3.0/mods-enabled/detail.log
> } # modules
> radiusd: #### Loading Virtual Servers ####
> server { # from file /etc/freeradius/3.0/radiusd.conf
> } # server
> server inner-tunnel { # from file
> /etc/freeradius/3.0/sites-enabled/inner-tunnel
> # Loading authenticate {...}
> # Loading authorize {...}
> Ignoring "sql" (see raddb/mods-available/README.rst)
> Ignoring "ldap" (see raddb/mods-available/README.rst)
> # Loading session {...}
> # Loading post-proxy {...}
> # Loading post-auth {...}
> # Skipping contents of 'if' as it is always 'false' --
> /etc/freeradius/3.0/sites-enabled/inner-tunnel:335
> } # server inner-tunnel
> server default { # from file /etc/freeradius/3.0/sites-enabled/default
> # Loading authenticate {...}
> # Loading authorize {...}
> # Loading preacct {...}
> # Loading accounting {...}
> # Loading post-proxy {...}
> # Loading post-auth {...}
> } # server default
> radiusd: #### Opening IP addresses and Ports ####
> listen {
> type = "auth"
> ipaddr = 127.0.0.1
> port = 18120
> }
> listen {
> type = "auth"
> ipaddr = *
> port = 0
> limit {
> max_connections = 16
> lifetime = 0
> idle_timeout = 30
> }
> }
> listen {
> type = "acct"
> ipaddr = *
> port = 0
> limit {
> max_connections = 16
> lifetime = 0
> idle_timeout = 30
> }
> }
> listen {
> type = "auth"
> ipv6addr = ::
> port = 0
> limit {
> max_connections = 16
> lifetime = 0
> idle_timeout = 30
> }
> }
> listen {
> type = "acct"
> ipv6addr = ::
> port = 0
> limit {
> max_connections = 16
> lifetime = 0
> idle_timeout = 30
> }
> }
> Listening on auth address 127.0.0.1 port 18120 bound to
> server inner-tunnel
> Listening on auth address * port 1812 bound to server default
> Listening on acct address * port 1813 bound to server default
> Listening on auth address :: port 1812 bound to server default
> Listening on acct address :: port 1813 bound to server default
> Listening on proxy address * port 46672
> Listening on proxy address :: port 50901
> Ready to process requests
> (0) Received Access-Request Id 46 from 127.0.0.1:45380 to
> 127.0.0.1:1812 length 132
> (0) User-Name = "simsic"
> (0) NAS-IP-Address = 127.0.1.1
> (0) NAS-Port = 0
> (0) Message-Authenticator = 0x88a617ddc7958578159dfd6d5f7e5a96
> (0) MS-CHAP-Challenge = 0x70721771d4df83b1
> (0) MS-CHAP-Response =
> 0x00010000000000000000000000000000000000000000000000000fd2084c
> 631219aaeac7af9d60484cf20f14d37c7dffff42
> (0) # Executing section authorize from file
> /etc/freeradius/3.0/sites-enabled/default
> (0) authorize {
> (0) policy filter_username {
> (0) if (&User-Name) {
> (0) if (&User-Name) -> TRUE
> (0) if (&User-Name) {
> (0) if (&User-Name =~ / /) {
> (0) if (&User-Name =~ / /) -> FALSE
> (0) if (&User-Name =~ /@[^@]*@/ ) {
> (0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
> (0) if (&User-Name =~ /\.\./ ) {
> (0) if (&User-Name =~ /\.\./ ) -> FALSE
> (0) if ((&User-Name =~ /@/) && (&User-Name !~
> /(a)(.+)\.(.+)$/)) {
> (0) if ((&User-Name =~ /@/) && (&User-Name !~
> /(a)(.+)\.(.+)$/)) -> FALSE
> (0) if (&User-Name =~ /\.$/) {
> (0) if (&User-Name =~ /\.$/) -> FALSE
> (0) if (&User-Name =~ /(a)\./) {
> (0) if (&User-Name =~ /(a)\./) -> FALSE
> (0) } # if (&User-Name) = notfound
> (0) } # policy filter_username = notfound
> (0) [preprocess] = ok
> (0) [chap] = noop
> (0) mschap: Found MS-CHAP attributes. Setting 'Auth-Type = mschap'
> (0) [mschap] = ok
> (0) [digest] = noop
> (0) suffix: Checking for suffix after "@"
> (0) suffix: No '@' in User-Name = "simsic", looking up realm NULL
> (0) suffix: No such realm "NULL"
> (0) [suffix] = noop
> (0) eap: No EAP-Message, not doing EAP
> (0) [eap] = noop
> (0) [files] = noop
> (0) [expiration] = noop
> (0) [logintime] = noop
> (0) pap: WARNING: No "known good" password found for the
> user. Not setting Auth-Type
> (0) pap: WARNING: Authentication will fail unless a "known
> good" password is available
> (0) [pap] = noop
> (0) } # authorize = ok
> (0) Found Auth-Type = mschap
> (0) # Executing group from file
> /etc/freeradius/3.0/sites-enabled/default
> (0) authenticate {
> (0) mschap: Client is using MS-CHAPv1 with NT-Password
> (0) mschap: Executing: /usr/bin/ntlm_auth --request-nt-key
> --username=%{mschap:User-Name:-None}
> --domain=%{%{mschap:NT-Domain}:-FMF.UNI-LJ.SI}
> --challenge=%{mschap:Challenge:-00}
> --nt-response=%{mschap:NT-Response:-00}:
> (0) mschap: EXPAND --username=%{mschap:User-Name:-None}
> (0) mschap: --> --username=simsic
> (0) mschap: ERROR: No NT-Domain was found in the User-Name
> (0) mschap: EXPAND --domain=%{%{mschap:NT-Domain}:-FMF.UNI-LJ.SI}
> (0) mschap: --> --domain=FMF.UNI-LJ.SI
> (0) mschap: mschap1: 70
> (0) mschap: EXPAND --challenge=%{mschap:Challenge:-00}
> (0) mschap: --> --challenge=70721771d4df83b1
> (0) mschap: EXPAND --nt-response=%{mschap:NT-Response:-00}
> (0) mschap: -->
> --nt-response=0fd2084c631219aaeac7af9d60484cf20f14d37c7dffff42
> (0) mschap: ERROR: Program returned code (1) and output 'No
> logon servers are currently available to service the logon
> request. (0xc000005e)'
> (0) mschap: ERROR: No logon servers are currently available
> to service the logon request. (0xc000005e)
> (0) mschap: Authentication failed
> (0) [mschap] = fail
> (0) } # authenticate = fail
> (0) Failed to authenticate the user
> (0) Using Post-Auth-Type Reject
> (0) # Executing group from file
> /etc/freeradius/3.0/sites-enabled/default
> (0) Post-Auth-Type REJECT {
> (0) attr_filter.access_reject: EXPAND %{User-Name}
> (0) attr_filter.access_reject: --> simsic
> (0) attr_filter.access_reject: Matched entry DEFAULT at line 11
> (0) [attr_filter.access_reject] = updated
> (0) [eap] = noop
> (0) policy remove_reply_message_if_eap {
> (0) if (&reply:EAP-Message && &reply:Reply-Message) {
> (0) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
> (0) else {
> (0) [noop] = noop
> (0) } # else = noop
> (0) } # policy remove_reply_message_if_eap = noop
> (0) } # Post-Auth-Type REJECT = updated
> (0) Delaying response for 1.000000 seconds
> Waking up in 0.3 seconds.
> Waking up in 0.6 seconds.
> (0) Sending delayed response
> (0) Sent Access-Reject Id 46 from 127.0.0.1:1812 to
> 127.0.0.1:45380 length 61
> (0) MS-CHAP-Error = "\000E=691 R=1 C=fdeee1d540dd4525 V=2"
> Waking up in 3.9 seconds.
> (0) Cleaning up request packet ID 46 with timestamp +5
> Ready to process requests
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>
2
1
Hi,
I've been trying to set up radius+AD integration. I'm following the docs http://deployingradius.com/documents/configuration/active_directory.html and everything is ok until I get to the last part where I enable ntlm_auth in mods/mschap. I'm getting back
(0) mschap: ERROR: Program returned code (1) and output 'No logon servers are currently available to service the logon request. (0xc000005e)'
(0) mschap: ERROR: No logon servers are currently available to service the logon request. (0xc000005e)
(0) mschap: Authentication failed
(full debug below). I've found a thread https://serverfault.com/questions/608227/authentication-via-radius-mschapv2… saying there is a reg setting for win to force radius to use ntlm2 but the link on MS KB is dead and their search isn't useful.. Does this seem to be this NTLM/NTLM2 issue or might it be something else?
Also the users here are used to using their name@domain in their current setup and ntlm_auth expects just name as --username and not name@domain. I've seen the use of Stripped-User-Name but it seems you need to ~activate it somehow to use it. If I can use this there will be less confusion with the users. Is this possible?
Thank you
Cheers Jure
====================
# freeradius -X
FreeRADIUS Version 3.0.17
Copyright (C) 1999-2017 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/freeradius/3.0/dictionary
including configuration file /etc/freeradius/3.0/radiusd.conf
including configuration file /etc/freeradius/3.0/proxy.conf
including configuration file /etc/freeradius/3.0/clients.conf
including files in directory /etc/freeradius/3.0/mods-enabled/
including configuration file /etc/freeradius/3.0/mods-enabled/preprocess
including configuration file /etc/freeradius/3.0/mods-enabled/replicate
including configuration file /etc/freeradius/3.0/mods-enabled/expiration
including configuration file /etc/freeradius/3.0/mods-enabled/utf8
including configuration file /etc/freeradius/3.0/mods-enabled/logintime
including configuration file /etc/freeradius/3.0/mods-enabled/expr
including configuration file /etc/freeradius/3.0/mods-enabled/files
including configuration file /etc/freeradius/3.0/mods-enabled/unpack
including configuration file /etc/freeradius/3.0/mods-enabled/eap
including configuration file /etc/freeradius/3.0/mods-enabled/detail
including configuration file /etc/freeradius/3.0/mods-enabled/passwd
including configuration file /etc/freeradius/3.0/mods-enabled/linelog
including configuration file /etc/freeradius/3.0/mods-enabled/unix
including configuration file /etc/freeradius/3.0/mods-enabled/mschap
including configuration file /etc/freeradius/3.0/mods-enabled/ntlm_auth
including configuration file /etc/freeradius/3.0/mods-enabled/exec
including configuration file /etc/freeradius/3.0/mods-enabled/realm
including configuration file /etc/freeradius/3.0/mods-enabled/echo
including configuration file /etc/freeradius/3.0/mods-enabled/always
including configuration file /etc/freeradius/3.0/mods-enabled/sradutmp
including configuration file /etc/freeradius/3.0/mods-enabled/chap
including configuration file /etc/freeradius/3.0/mods-enabled/soh
including configuration file /etc/freeradius/3.0/mods-enabled/cache_eap
including configuration file /etc/freeradius/3.0/mods-enabled/attr_filter
including configuration file /etc/freeradius/3.0/mods-enabled/radutmp
including configuration file /etc/freeradius/3.0/mods-enabled/digest
including configuration file /etc/freeradius/3.0/mods-enabled/dynamic_clients
including configuration file /etc/freeradius/3.0/mods-enabled/pap
including configuration file /etc/freeradius/3.0/mods-enabled/detail.log
including files in directory /etc/freeradius/3.0/policy.d/
including configuration file /etc/freeradius/3.0/policy.d/filter
including configuration file /etc/freeradius/3.0/policy.d/abfab-tr
including configuration file /etc/freeradius/3.0/policy.d/control
including configuration file /etc/freeradius/3.0/policy.d/moonshot-targeted-ids
including configuration file /etc/freeradius/3.0/policy.d/canonicalization
including configuration file /etc/freeradius/3.0/policy.d/accounting
including configuration file /etc/freeradius/3.0/policy.d/eap
including configuration file /etc/freeradius/3.0/policy.d/dhcp
including configuration file /etc/freeradius/3.0/policy.d/operator-name
including configuration file /etc/freeradius/3.0/policy.d/debug
including configuration file /etc/freeradius/3.0/policy.d/cui
including files in directory /etc/freeradius/3.0/sites-enabled/
including configuration file /etc/freeradius/3.0/sites-enabled/inner-tunnel
including configuration file /etc/freeradius/3.0/sites-enabled/default
main {
security {
user = "freerad"
group = "freerad"
allow_core_dumps = no
}
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
}
main {
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
libdir = "/usr/lib/freeradius"
radacctdir = "/var/log/freeradius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/var/run/freeradius/freeradius.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client FMFUnifiController {
ipaddr = 10.20.12.2
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
# Creating Auth-Type = mschap
# Creating Auth-Type = ntlm_auth
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
# Creating Auth-Type = digest
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_preprocess
# Loading module "preprocess" from file /etc/freeradius/3.0/mods-enabled/preprocess
preprocess {
huntgroups = "/etc/freeradius/3.0/mods-config/preprocess/huntgroups"
hints = "/etc/freeradius/3.0/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loaded module rlm_replicate
# Loading module "replicate" from file /etc/freeradius/3.0/mods-enabled/replicate
# Loaded module rlm_expiration
# Loading module "expiration" from file /etc/freeradius/3.0/mods-enabled/expiration
# Loaded module rlm_utf8
# Loading module "utf8" from file /etc/freeradius/3.0/mods-enabled/utf8
# Loaded module rlm_logintime
# Loading module "logintime" from file /etc/freeradius/3.0/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_expr
# Loading module "expr" from file /etc/freeradius/3.0/mods-enabled/expr
expr {
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loaded module rlm_files
# Loading module "files" from file /etc/freeradius/3.0/mods-enabled/files
files {
filename = "/etc/freeradius/3.0/mods-config/files/authorize"
acctusersfile = "/etc/freeradius/3.0/mods-config/files/accounting"
preproxy_usersfile = "/etc/freeradius/3.0/mods-config/files/pre-proxy"
}
# Loaded module rlm_unpack
# Loading module "unpack" from file /etc/freeradius/3.0/mods-enabled/unpack
# Loaded module rlm_eap
# Loading module "eap" from file /etc/freeradius/3.0/mods-enabled/eap
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_detail
# Loading module "detail" from file /etc/freeradius/3.0/mods-enabled/detail
detail {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file /etc/freeradius/3.0/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loaded module rlm_linelog
# Loading module "linelog" from file /etc/freeradius/3.0/mods-enabled/linelog
linelog {
filename = "/var/log/freeradius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file /etc/freeradius/3.0/mods-enabled/linelog
linelog log_accounting {
filename = "/var/log/freeradius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_unix
# Loading module "unix" from file /etc/freeradius/3.0/mods-enabled/unix
unix {
radwtmp = "/var/log/freeradius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_mschap
# Loading module "mschap" from file /etc/freeradius/3.0/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
ntlm_auth = "/usr/bin/ntlm_auth --request-nt-key --username=%{mschap:User-Name:-None} --domain=%{%{mschap:NT-Domain}:-FMF.UNI-LJ.SI} --challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Response:-00}"
passchange {
}
allow_retry = yes
winbind_retry_with_normalised_username = no
}
# Loaded module rlm_exec
# Loading module "ntlm_auth" from file /etc/freeradius/3.0/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/usr/bin/ntlm_auth --request-nt-key --domain=FMF.UNI-LJ.SI --username=%{mschap:User-Name} --password=%{User-Password}"
shell_escape = yes
}
# Loading module "exec" from file /etc/freeradius/3.0/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_realm
# Loading module "IPASS" from file /etc/freeradius/3.0/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file /etc/freeradius/3.0/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file /etc/freeradius/3.0/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file /etc/freeradius/3.0/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loading module "echo" from file /etc/freeradius/3.0/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loaded module rlm_always
# Loading module "reject" from file /etc/freeradius/3.0/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file /etc/freeradius/3.0/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /etc/freeradius/3.0/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file /etc/freeradius/3.0/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file /etc/freeradius/3.0/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file /etc/freeradius/3.0/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file /etc/freeradius/3.0/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file /etc/freeradius/3.0/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file /etc/freeradius/3.0/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_radutmp
# Loading module "sradutmp" from file /etc/freeradius/3.0/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/freeradius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_chap
# Loading module "chap" from file /etc/freeradius/3.0/mods-enabled/chap
# Loaded module rlm_soh
# Loading module "soh" from file /etc/freeradius/3.0/mods-enabled/soh
soh {
dhcp = yes
}
# Loaded module rlm_cache
# Loading module "cache_eap" from file /etc/freeradius/3.0/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loading module "radutmp" from file /etc/freeradius/3.0/mods-enabled/radutmp
radutmp {
filename = "/var/log/freeradius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_digest
# Loading module "digest" from file /etc/freeradius/3.0/mods-enabled/digest
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file /etc/freeradius/3.0/mods-enabled/dynamic_clients
# Loaded module rlm_pap
# Loading module "pap" from file /etc/freeradius/3.0/mods-enabled/pap
pap {
normalise = yes
}
# Loading module "auth_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail auth_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail reply_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail pre_proxy_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail post_proxy_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
instantiate {
}
# Instantiating module "preprocess" from file /etc/freeradius/3.0/mods-enabled/preprocess
reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/huntgroups
reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/hints
# Instantiating module "expiration" from file /etc/freeradius/3.0/mods-enabled/expiration
# Instantiating module "logintime" from file /etc/freeradius/3.0/mods-enabled/logintime
# Instantiating module "files" from file /etc/freeradius/3.0/mods-enabled/files
reading pairlist file /etc/freeradius/3.0/mods-config/files/authorize
reading pairlist file /etc/freeradius/3.0/mods-config/files/accounting
reading pairlist file /etc/freeradius/3.0/mods-config/files/pre-proxy
# Instantiating module "eap" from file /etc/freeradius/3.0/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/freeradius/3.0/certs"
pem_file_type = yes
private_key_file = "/etc/ssl/private/ssl-cert-snakeoil.key"
certificate_file = "/etc/ssl/certs/ssl-cert-snakeoil.pem"
ca_file = "/etc/ssl/certs/ca-certificates.crt"
private_key_password = <<< secret >>>
dh_file = "/etc/freeradius/3.0/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
cipher_server_preference = no
ecdh_curve = "prime256v1"
tls_max_version = ""
tls_min_version = "1.0"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
# Instantiating module "detail" from file /etc/freeradius/3.0/mods-enabled/detail
# Instantiating module "etc_passwd" from file /etc/freeradius/3.0/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "linelog" from file /etc/freeradius/3.0/mods-enabled/linelog
# Instantiating module "log_accounting" from file /etc/freeradius/3.0/mods-enabled/linelog
# Instantiating module "mschap" from file /etc/freeradius/3.0/mods-enabled/mschap
rlm_mschap (mschap): authenticating by calling 'ntlm_auth'
# Instantiating module "IPASS" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "suffix" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "realmpercent" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "ntdomain" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "reject" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "fail" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "ok" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "handled" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "invalid" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "userlock" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "notfound" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "noop" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "updated" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "cache_eap" from file /etc/freeradius/3.0/mods-enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module rlm_cache_rbtree) loaded and linked
# Instantiating module "attr_filter.post-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/access_reject
[/etc/freeradius/3.0/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay" found in filter list for realm "DEFAULT".
[/etc/freeradius/3.0/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay-USec" found in filter list for realm "DEFAULT".
# Instantiating module "attr_filter.access_challenge" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/accounting_response
# Instantiating module "pap" from file /etc/freeradius/3.0/mods-enabled/pap
# Instantiating module "auth_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output
# Instantiating module "reply_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "pre_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/freeradius/3.0/radiusd.conf
} # server
server inner-tunnel { # from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
Ignoring "sql" (see raddb/mods-available/README.rst)
Ignoring "ldap" (see raddb/mods-available/README.rst)
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
# Skipping contents of 'if' as it is always 'false' -- /etc/freeradius/3.0/sites-enabled/inner-tunnel:335
} # server inner-tunnel
server default { # from file /etc/freeradius/3.0/sites-enabled/default
# Loading authenticate {...}
# Loading authorize {...}
# Loading preacct {...}
# Loading accounting {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server default
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
listen {
type = "auth"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on proxy address * port 46672
Listening on proxy address :: port 50901
Ready to process requests
(0) Received Access-Request Id 46 from 127.0.0.1:45380 to 127.0.0.1:1812 length 132
(0) User-Name = "simsic"
(0) NAS-IP-Address = 127.0.1.1
(0) NAS-Port = 0
(0) Message-Authenticator = 0x88a617ddc7958578159dfd6d5f7e5a96
(0) MS-CHAP-Challenge = 0x70721771d4df83b1
(0) MS-CHAP-Response = 0x00010000000000000000000000000000000000000000000000000fd2084c631219aaeac7af9d60484cf20f14d37c7dffff42
(0) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) [preprocess] = ok
(0) [chap] = noop
(0) mschap: Found MS-CHAP attributes. Setting 'Auth-Type = mschap'
(0) [mschap] = ok
(0) [digest] = noop
(0) suffix: Checking for suffix after "@"
(0) suffix: No '@' in User-Name = "simsic", looking up realm NULL
(0) suffix: No such realm "NULL"
(0) [suffix] = noop
(0) eap: No EAP-Message, not doing EAP
(0) [eap] = noop
(0) [files] = noop
(0) [expiration] = noop
(0) [logintime] = noop
(0) pap: WARNING: No "known good" password found for the user. Not setting Auth-Type
(0) pap: WARNING: Authentication will fail unless a "known good" password is available
(0) [pap] = noop
(0) } # authorize = ok
(0) Found Auth-Type = mschap
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(0) authenticate {
(0) mschap: Client is using MS-CHAPv1 with NT-Password
(0) mschap: Executing: /usr/bin/ntlm_auth --request-nt-key --username=%{mschap:User-Name:-None} --domain=%{%{mschap:NT-Domain}:-FMF.UNI-LJ.SI} --challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Response:-00}:
(0) mschap: EXPAND --username=%{mschap:User-Name:-None}
(0) mschap: --> --username=simsic
(0) mschap: ERROR: No NT-Domain was found in the User-Name
(0) mschap: EXPAND --domain=%{%{mschap:NT-Domain}:-FMF.UNI-LJ.SI}
(0) mschap: --> --domain=FMF.UNI-LJ.SI
(0) mschap: mschap1: 70
(0) mschap: EXPAND --challenge=%{mschap:Challenge:-00}
(0) mschap: --> --challenge=70721771d4df83b1
(0) mschap: EXPAND --nt-response=%{mschap:NT-Response:-00}
(0) mschap: --> --nt-response=0fd2084c631219aaeac7af9d60484cf20f14d37c7dffff42
(0) mschap: ERROR: Program returned code (1) and output 'No logon servers are currently available to service the logon request. (0xc000005e)'
(0) mschap: ERROR: No logon servers are currently available to service the logon request. (0xc000005e)
(0) mschap: Authentication failed
(0) [mschap] = fail
(0) } # authenticate = fail
(0) Failed to authenticate the user
(0) Using Post-Auth-Type Reject
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(0) Post-Auth-Type REJECT {
(0) attr_filter.access_reject: EXPAND %{User-Name}
(0) attr_filter.access_reject: --> simsic
(0) attr_filter.access_reject: Matched entry DEFAULT at line 11
(0) [attr_filter.access_reject] = updated
(0) [eap] = noop
(0) policy remove_reply_message_if_eap {
(0) if (&reply:EAP-Message && &reply:Reply-Message) {
(0) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(0) else {
(0) [noop] = noop
(0) } # else = noop
(0) } # policy remove_reply_message_if_eap = noop
(0) } # Post-Auth-Type REJECT = updated
(0) Delaying response for 1.000000 seconds
Waking up in 0.3 seconds.
Waking up in 0.6 seconds.
(0) Sending delayed response
(0) Sent Access-Reject Id 46 from 127.0.0.1:1812 to 127.0.0.1:45380 length 61
(0) MS-CHAP-Error = "\000E=691 R=1 C=fdeee1d540dd4525 V=2"
Waking up in 3.9 seconds.
(0) Cleaning up request packet ID 46 with timestamp +5
Ready to process requests
1
0
ICMP 435 Destination unreachable (Communication administratively filtered)
by Dennis Schneck 12 Aug '21
by Dennis Schneck 12 Aug '21
12 Aug '21
Hello,
if the Switch sends requests can see only in wireshark this: ICMP 435
Destination unreachable (Communication administratively filtered)
$ tshark -Y "ip.addr==192.168.1.0/24"
Capturing on 'eth0'
109 12.985452883 192.168.1.78 → 172.16.1.28 RADIUS 407
Access-Request id=5
110 12.985550915 172.16.1.28 → 192.168.1.78 ICMP 435 Destination
unreachable (Communication administratively filtered)
173 17.971115508 192.168.1.78 → 172.16.1.28 RADIUS 407
Access-Request id=5, Duplicate Request
174 17.971208619 172.16.1.28 → 192.168.1.78 ICMP 435 Destination
unreachable (Communication administratively filtered)
205 22.971310597 192.168.1.78 → 172.16.1.28 RADIUS 407
Access-Request id=5, Duplicate Request
206 22.971388225 172.16.1.28 → 192.168.1.78 ICMP 435 Destination
unreachable (Communication administratively filtered)
247 27.971195313 192.168.1.78 → 172.16.1.28 RADIUS 407
Access-Request id=5, Duplicate Request
248 27.971249900 172.16.1.28 → 192.168.1.78 ICMP 435 Destination
unreachable (Communication administratively filtered)
but in debug mode (raduisd -X) can see nothing.
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Listening on proxy address * port 49780
Listening on proxy address :: port 40915
Ready to process requests
What did I wrong ?
---------------
If I dow a local test with radtest I can see there something
radtest <PC MAC Address> none localhost 10 testing123
4
8
|Hi, We have many repeating log lines that complain about the
permissions of the log file itself : Warning: File
/var/log/freeradius/radius.log permissions are 0640 (rw-r-----) not 0600
(rw-------)) In our case this file needs to be readable by the group for
statistics and other purposes. Is there any way to reduce this verbosity
? Regards, Arnaud |
2
2
11 Aug '21
Hi
We're currently deploying numerous devices using 802.1x and EAP-TLS over wired connections to Cisco switches used as NAS. As of now it seems as if all supplicants are granted indefinite access - well at least until certificate expires.
I've been googling for answers to how I might set a session timeout in Freeradius enforcing a re-authentication by the supplicants at regular intervals but haven't found a conclusive answer.
Could someone tell if this is a function that may be enforced in Freeradius (session-timeout ?) or does it have to be enforced by the NAS?
./PerW
3
2
Hi there
The REST API we are using requires an additional HTTP header
"API-Version: 2.0".
The documention in modules-available/rest file says: Additional HTTP
headers may be specified with `control.REST-HTTP-Header`.
The only way I got it working was by putting these lines in the sites
config:
authorize {
update control {
&REST-HTTP-Header += "API-Version: 2.0"
}
}
But then it's added to every request. It would be much nicer if I could
add it to the module config, because it's module-specific. Is there a
way to do this?
Cheers
Till
2
2
Hi Alan,
I am trying to upgrade freeradius from 2.0 version to 3.0.17.
Now I am with error:
Mon Aug 9 17:00:32 2021 : Debug: # Loading authenticate {...}
Mon Aug 9 17:00:32 2021 : Debug: eap
Mon Aug 9 17:00:32 2021 : Error: /etc/raddb/sites-enabled/default[20]:
Errors parsing preacct sub-section.
Here is section:
server {
authorize {
preprocess
chap
mschap
# digest
suffix
eap {
ok = return
}
files
redundant-load-balance {
ldap-server-a
ldap-server-b
}
expiration
logintime
pap
}
authenticate {
Auth-Type PAP {
pap
}
Auth-Type CHAP {
chap
}
Auth-Type MS-CHAP {
mschap
}
# digest
# unix
eap
Auth-Type LDAP {
redundant-load-balance {
ldap-server-a
ldap-server-b
}
}
preacct {
preprocess
acct_unique
suffix
files
}
}
accounting {
detail
# unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
}
#LDAP B Service
if !(&Ldap-Group == "cn=scaler_vip,ou=resource
groups,ou=Groups,dc= company ,dc=net") {
update reply {
Service-Type = "Administrative-User",
Citrix-Group += "dwansible_netscaler_vip",
Fall-Through = Yes
}
}
#LDAP A Service
elsif !(&Ldap-Group == "cn=scaler_service,ou=resource
groups,ou=Groups,dc=company,dc=net") {
update reply {
Service-Type = "Administrative-User",
Citrix-Group += "scaler_service"
}
}
else {
reject
}
}
pre-proxy {
}
post-proxy {
eap
}
}
Could you please help to understand what is wrong, where to place LDAP
group check and what is the syntax.
Best regards,
Valery
On Mon, 9 Aug 2021 at 11:00, <freeradius-users-request(a)lists.freeradius.org>
wrote:
> Send Freeradius-Users mailing list submissions to
> freeradius-users(a)lists.freeradius.org
>
> To subscribe or unsubscribe via the World Wide Web, visit
> http://lists.freeradius.org/mailman/listinfo/freeradius-users
> or, via email, send a message with subject or body 'help' to
> freeradius-users-request(a)lists.freeradius.org
>
> You can reach the person managing the list at
> freeradius-users-owner(a)lists.freeradius.org
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Freeradius-Users digest..."
>
>
> Today's Topics:
>
> 1. Re: Freeradius-Users Digest, Vol 196, Issue 8 (Valery Kayukov)
> 2. Re: Freeradius-Users Digest, Vol 196, Issue 8 (Alan DeKok)
> 3. How to Migrate (EAP) from: 2.1.xx to: 3.0.xx ? (Dennis Schneck)
> 4. missing shared objects - proto_auth.so & proto_acct.so - on
> openSuSE LEAP 15.3 (Dennis Schneck)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Sun, 8 Aug 2021 12:44:38 +0100
> From: Valery Kayukov <kayukovvalery(a)gmail.com>
> To: freeradius-users(a)lists.freeradius.org
> Subject: Re: Freeradius-Users Digest, Vol 196, Issue 8
> Message-ID:
> <
> CAAoKmEsmGHkTC-AV+8Dm1fG7xxVa_8qc_SkDOc4txuwJ-61DBw(a)mail.gmail.com>
> Content-Type: text/plain; charset="UTF-8"
>
> Hi Alan,
>
> Thank you for your help. By the way I use 3.0.17 version. I have fixed that
> but still have this problem with LDAP groups:
> Sun Aug 8 11:36:22 2021 : Debug: # Instantiating module "files" from
> file /etc/raddb/mods-enabled/files
> Sun Aug 8 11:36:22 2021 : Debug: reading pairlist file
> /etc/raddb/mods-config/files/authorize
> Sun Aug 8 11:36:22 2021 : Error:
> /etc/raddb/mods-config/files/authorize[10]: Parse error (check) for entry
> DEFAULT: Unknown name "LDAP-Group"
> Sun Aug 8 11:36:22 2021 : Error: Failed reading
> /etc/raddb/mods-config/files/authorize
> Sun Aug 8 11:36:22 2021 : Error: /etc/raddb/mods-enabled/files[9]:
> Instantiation failed for module "files"
>
> I have read the /etc/raddb/README.rst file about LDAP-Group but still not
> getting how to apply it.
>
> In /etc/raddb/mods-config/files/authorize file I have following:
> #LDAP NetEng team members
> DEFAULT LDAP-Group == "cn=neteng,ou=system
> groups,ou=Groups,dc=company,dc=net"
> Service-Type = "Administrative-User",
> cisco-avpair := "shell:roles=network-admin,vdc-admin",
> cisco-avpair += "shell:priv-lvl=15",
> Filter-Id = ":group_name=neteng;"
>
> In /etc/raddb/sites-available/default config:
> authorize {
> ...
> ldap-server-a
> if ((ok || updated) && User-Password) {
> update control {
> Auth-Type := ldap
> }
> }
> ldap-server-b
> if ((ok || updated) && User-Password) {
> update control {
> Auth-Type := ldap
> }
> }
> ...
> }
> authenticate {
> ...
> redundant {
> location1
> location2
> }
> ...
> }
>
> In /etc/raddb/mods-available/ldap config:
> ldap ldap-server-a {
> server = "ldap-a.company.net"
> basedn = "dc=company,dc=net"
> }
> ...
> }
>
> ldap ldap-server-b {
> server = "ldap-b.company.net"
> basedn = "dc=company,dc=net"
> ...
> }
>
> How convert config in file /etc/raddb/mods-config/files/authorize to v3?
>
> Best regards,
> Valeriy
>
> On Sun, 8 Aug 2021 at 11:00, <
> freeradius-users-request(a)lists.freeradius.org>
> wrote:
>
> > Send Freeradius-Users mailing list submissions to
> > freeradius-users(a)lists.freeradius.org
> >
> > To subscribe or unsubscribe via the World Wide Web, visit
> > http://lists.freeradius.org/mailman/listinfo/freeradius-users
> > or, via email, send a message with subject or body 'help' to
> > freeradius-users-request(a)lists.freeradius.org
> >
> > You can reach the person managing the list at
> > freeradius-users-owner(a)lists.freeradius.org
> >
> > When replying, please edit your Subject line so it is more specific
> > than "Re: Contents of Freeradius-Users digest..."
> >
> >
> > Today's Topics:
> >
> > 1. Parse error (check) for entry DEFAULT: Unknown name
> > "LDAP-Group" (Valery Kayukov)
> > 2. Re: Parse error (check) for entry DEFAULT: Unknown name
> > "LDAP-Group" (Alan DeKok)
> >
> >
> > ----------------------------------------------------------------------
> >
> > Message: 1
> > Date: Sat, 7 Aug 2021 13:00:11 +0100
> > From: Valery Kayukov <kayukovvalery(a)gmail.com>
> > To: freeradius-users(a)lists.freeradius.org
> > Subject: Parse error (check) for entry DEFAULT: Unknown name
> > "LDAP-Group"
> > Message-ID:
> > <
> > CAAoKmEsJSQ4ZMxM5UxEbwHks_4JyzfejTe6spjhJZeBEyS6ThQ(a)mail.gmail.com>
> > Content-Type: text/plain; charset="UTF-8"
> >
> > Hi team,
> >
> > I am new to the freeRADIUS project. Can't start my server, it return
> error
> > message:
> > Sat Aug 7 11:48:24 2021 : Debug: # Instantiating module "files" from
> > file /etc/raddb/mods-enabled/files
> > Sat Aug 7 11:48:24 2021 : Debug: reading pairlist file
> > /etc/raddb/mods-config/files/authorize
> > Sat Aug 7 11:48:24 2021 : Error:
> > /etc/raddb/mods-config/files/authorize[10]: Parse error (check) for entry
> > DEFAULT: Unknown name "LDAP-Group"
> > Sat Aug 7 11:48:24 2021 : Error: Failed reading
> > /etc/raddb/mods-config/files/authorize
> > Sat Aug 7 11:48:24 2021 : Error: /etc/raddb/mods-enabled/files[9]:
> > Instantiation failed for module "files"
> >
> > Here is configuration file /etc/raddb/mods-config/files/authorize:
> > #LDAP Rancid service account
> > rancid LDAP-UserDN :=
> > `uid=rancid,ou=services,ou=Accounts,dc=company,dc=net`
> > Service-Type = "NAS-Prompt-User",
> > cisco-avpair := "optional shell:roles=rancid,network-operator",
> > cisco-avpair += "shell:priv-lvl=15",
> > Juniper-Local-User-Name := "rancid",
> > Citrix-Group = "rancid"
> >
> > #LDAP Apple team members
> > DEFAULT LDAP-Group == "cn=apple,ou=system groups,ou=Groups,dc=
> > company,dc=net"
> > Service-Type = "Administrative-User",
> > cisco-avpair := "shell:roles=network-admin,vdc-admin",
> > cisco-avpair += "shell:priv-lvl=15",
> > Juniper-Local-User-Name := "apple",
> > Citrix-Group = "apple",
> > Filter-Id = ":group_name=apple;"
> >
> > What is wrong here?
> >
> > --
> > Best Regards,
> > Valeriy Kayukov
> > System Engineer
> >
> >
> > ------------------------------
> >
> > Message: 2
> > Date: Sat, 7 Aug 2021 09:44:01 -0400
> > From: Alan DeKok <aland(a)deployingradius.com>
> > To: FreeRadius users mailing list
> > <freeradius-users(a)lists.freeradius.org>
> > Subject: Re: Parse error (check) for entry DEFAULT: Unknown name
> > "LDAP-Group"
> > Message-ID: <8F938E67-BB0D-4459-8968-2EE5B10CFCEE(a)deployingradius.com>
> > Content-Type: text/plain; charset=us-ascii
> >
> > On Aug 7, 2021, at 8:00 AM, Valery Kayukov <kayukovvalery(a)gmail.com>
> > wrote:
> > >
> > > I am new to the freeRADIUS project. Can't start my server, it return
> > error
> > > message:
> > > Sat Aug 7 11:48:24 2021 : Debug: # Instantiating module "files" from
> > > file /etc/raddb/mods-enabled/files
> > > Sat Aug 7 11:48:24 2021 : Debug: reading pairlist file
> > > /etc/raddb/mods-config/files/authorize
> > > Sat Aug 7 11:48:24 2021 : Error:
> > > /etc/raddb/mods-config/files/authorize[10]: Parse error (check) for
> entry
> > > DEFAULT: Unknown name "LDAP-Group"
> >
> > You haven't enabled the LDAP module.
> >
> > Or, depending on the local file system, you may need to edit
> > radiusd.conf to load the "ldap" module early:
> >
> > instantiate {
> > ...
> > ldap
> > }
> >
> > This is documented in the comments before the "instantiate" section.
> >
> > Alan DeKok.
> >
> >
> >
> >
> > ------------------------------
> >
> > Subject: Digest Footer
> >
> > -
> > List info/subscribe/unsubscribe? See
> > http://www.freeradius.org/list/users.html
> >
> > ------------------------------
> >
> > End of Freeradius-Users Digest, Vol 196, Issue 8
> > ************************************************
> >
>
>
> --
> Best Regards,
> Valeriy Kayukov
> System Engineer
>
>
> ------------------------------
>
> Message: 2
> Date: Sun, 8 Aug 2021 08:13:02 -0400
> From: Alan DeKok <aland(a)deployingradius.com>
> To: FreeRadius users mailing list
> <freeradius-users(a)lists.freeradius.org>
> Subject: Re: Freeradius-Users Digest, Vol 196, Issue 8
> Message-ID: <1E9CA5AA-E8CD-42F3-8E16-F84327D985B4(a)deployingradius.com>
> Content-Type: text/plain; charset=us-ascii
>
> On Aug 8, 2021, at 7:44 AM, Valery Kayukov <kayukovvalery(a)gmail.com>
> wrote:
> >
> > Thank you for your help. By the way I use 3.0.17 version.
>
> You should really upgrade. We have packages for 3.0.23 on
> http://packages.networkradius.com
>
> > I have fixed that
> > but still have this problem with LDAP groups:
> > Sun Aug 8 11:36:22 2021 : Debug: # Instantiating module "files" from
> > file /etc/raddb/mods-enabled/files
> > Sun Aug 8 11:36:22 2021 : Debug: reading pairlist file
> > /etc/raddb/mods-config/files/authorize
> > Sun Aug 8 11:36:22 2021 : Error:
> > /etc/raddb/mods-config/files/authorize[10]: Parse error (check) for entry
> > DEFAULT: Unknown name "LDAP-Group"
> > Sun Aug 8 11:36:22 2021 : Error: Failed reading
> > /etc/raddb/mods-config/files/authorize
> > Sun Aug 8 11:36:22 2021 : Error: /etc/raddb/mods-enabled/files[9]:
> > Instantiation failed for module "files"
> >
> > I have read the /etc/raddb/README.rst file about LDAP-Group but still not
> > getting how to apply it.
> >
> > In /etc/raddb/mods-config/files/authorize file I have following:
> > #LDAP NetEng team members
> > DEFAULT LDAP-Group == "cn=neteng,ou=system
> > groups,ou=Groups,dc=company,dc=net"
> > Service-Type = "Administrative-User",
> > cisco-avpair := "shell:roles=network-admin,vdc-admin",
> > cisco-avpair += "shell:priv-lvl=15",
> > Filter-Id = ":group_name=neteng;"
> >
> > In /etc/raddb/sites-available/default config:
> > authorize {
> > ...
> > ldap-server-a
>
> It would help to describe what you're doing.
>
> If you've renamed the LDAP module, then the LDAP group information is in
> the <LDAP-NAME>-LDAP-Group attribute.
>
> See the Wiki for documentation. Just type "LDAP-Group" into the search
> bar. This is documented.
>
> Alan DeKok.
>
>
>
>
> ------------------------------
>
> Message: 3
> Date: Mon, 9 Aug 2021 07:33:19 +0200
> From: Dennis Schneck <dennis.schneck(a)schulergroup.com>
> To: <Freeradius-Users(a)lists.freeradius.org>
> Subject: How to Migrate (EAP) from: 2.1.xx to: 3.0.xx ?
> Message-ID: <75580212-287b-3cb9-1679-7d3bf5779af0(a)schulergroup.com>
> Content-Type: text/plain; charset="utf-8"; format=flowed
>
>
> Hello,
>
> I am new in freeradius, should build a new system with the config of a
> 2.1.12.
> Did not find config parameters from /etc/raddb/eap.conf in the
> /etc/raddb/policy.d/eap
>
> Where can I find how to migrate from Version 2.1.12 to 3.0.21
>
> Thanks
>
>
> /etc/raddb/eap.conf
>
> eap {
>
> default_eap_type = peap
>
> timer_expire = 60
>
> ignore_unknown_eap_types = no
> cisco_accounting_username_bug = no
>
> md5 {
> }
>
> tls {
>
> private_key_password = password
>
> private_key_file = ${raddbdir}/certs/my/key.pem
> certificate_file = ${raddbdir}/certs/my/server.pem
> # Trusted Root CA list
> CA_file = ${raddbdir}/certs/my/our.pem
>
> dh_file = ${raddbdir}/certs/my/DH
> random_file = ${raddbdir}/certs/my/random
> #random_file = /dev/urandom
> fragment_size = 1024
>
> include_length = yes
> #check_crl = yes
>
> }
> peap {
> default_eap_type = mschapv2
> #VIRTUAL_SERVER = "inner-Tunnel"
> #scopy_request_to_tunnel = yes
> #use_tunneled_reply = yes
> #proxy_tunneled_request_as_eap = yes
> }
> mschapv2 {
> }
> }
>
>
>
>
> ------------------------------
>
> Message: 4
> Date: Mon, 9 Aug 2021 11:18:57 +0200
> From: Dennis Schneck <dennis.schneck(a)schulergroup.com>
> To: <Freeradius-Users(a)lists.freeradius.org>
> Subject: missing shared objects - proto_auth.so & proto_acct.so - on
> openSuSE LEAP 15.3
> Message-ID: <1aa004d4-3e29-eab2-486d-49537bd90f68(a)schulergroup.com>
> Content-Type: text/plain; charset="utf-8"; format=flowed
>
>
> Hello,
>
> installed freeradius 3.0.21 on OpenSuSE LEAP 15.3.
>
> created the certificates. (cd /etc/raddb/certs && ./bootstrap)
>
> Checked then the config with: radiusd -XXX
>
>
> there are 2 shared objects missing...
>
> ||
>
> |/usr/lib64/freeradius/proto_auth.so |
> ||
>
> ||
>
> |/usr/lib64/freeradius/proto_acct.so|
> |
>
> But can not find this shared objects to install....
>
> How to fix this ?
>
> Thanks
>
>
> |
>
>
>
> ------------------------------
>
> Subject: Digest Footer
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>
> ------------------------------
>
> End of Freeradius-Users Digest, Vol 196, Issue 9
> ************************************************
>
--
Best Regards,
Valeriy Kayukov
System Engineer
2
3