Freeradius-Users
Threads by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 27050 discussions
Hello,
I'm happy to be able to talk about an enhancement for Enterprise Wi-Fi
made recently in the Wi-Fi Alliance, with "code" for 3.0.x that
implements this. Please see my pull request at
https://github.com/FreeRADIUS/freeradius-server/pull/3230
The problem that this is trying to solve is the following: as a RADIUS
administrator, you can configure your EAP type for Enterprise Wi-Fi and
have a server certificate from a specific CA. You tell your users that
they should send their username/password ONLY to your server, which can
be validated by looking at the CA chain and server name. You create
configuration instructions, either in form of a PDF file or by using
configuration generators such as on https://enterprise-wifi.net.
And then your users ignore all those instructions and simply type their
username and password at the prompt, not validating any server identity,
possibly sending it to a rogue attacker. Academic field studies suggest
that some 50% of end users are that lazy, leading to an easy attack
vector to grab credentials from Wi-Fi logins.
Bespoke additions by Wi-Fi Alliance allow you as the admin to limit how
ignorant your users can be when connecting to your network. By including
a certain policy OID field in your server certificate, you can apply
validation policy directly at the supplicant level: if the user has not
properly configured the network with CA/servername/cert fingerprint,
then you can tell the supplicant to not even attempt the authentication,
and tell the user to get a proper configuration first. Only if the
configuration is sufficient to actually identify the server correctly
will the authentication be attempted.
This comes in two flavours
a) "Trust Override Disabled - Strict": There are no exceptions. Have a
proper configuration, or the supplicant won't try to authenticate you.
b) "Trust Override Disabled- Trust On First Use": If this is the very
first time you connect to a network, and the configuration is
insufficient, take the incoming server certificate, ask user to confirm
that this is okay, and take that one as the one trusted certificate. If
the certificate changes at any point in the future, the supplicant will
not ask the user again; it will unconditionally stop the authentication
attempt prior to sending username/password.
b) is actually extremely similar to SSH and its reaction to your first
connection to a new host. That first time asks you a question of trust,
and any subsequent change of server-side identity will raise all alarm
bells.
Thinking this through, here's a few considerations:
1. What happens if your very first connection is directly to an
attacker? The supplicant will not be told to be picky, will prompt for
trust, and will send the username/password to the attacker. Since you
have never ever contacted your proper authentication server, it can't
tell your supplicant to be picky, so this is a hard problem that can't
be solved. It can be compared to your first SSH connection attempt, and
you immediately end up at an impostor, and trust its SSH key.
2. With TOD-TOFU, the server certificate is pinned "forever". Now what
happens if you feel the need to change the server cert? It is possible
to delete the entire Wi-Fi config - this will also delete the stickiness
to the old cert. While that's possible, it is best to do everything you
can to let your server cert live very very long. E.g. have a CA cert
with 30 years validity, and a server cert *with the same 30 years
validity*. The TOD-TOFU configuration is then good for a very long time,
and the only reasons to exchange the cert are an actual key compromise
or crypto algorithms decaying over time. Using a root CA with the same
lifetime has the additional plus that those clients who configured the
(CA,name) tuple, instead of relying on the ad-hoc first use trust, will
even accept the new server certificate without needing any change.
The new policies are now part of raddb/certs/xpextensions and default to
enabling "TOD-TOFU". This should be part of the next 3.0.x release. But
of course it will only start having an effect once you have created a
certificate with the respective scripts; and its effect will only be on
"new" supplicants that have the latest Wi-Fi Alliance WPA3 Security Dec
2019 Release certification. There will be a slow phase-in of such
supplicants over time. This has the advantage that turning it on *today*
won't all of a sudden break all your deployed base. Which is good.
Greetings,
Stefan
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
2
3
We've created a python module that we use to process authorization requests (ie. func_authorize). Each call to the authorize method seems to block any subsequent calls until it completes, then it moves on the next one. In other words it’s processing them one at a time. This is not the behavior we were expecting since rlm_python is set to RLM_TYPE_THREAD_SAFE.
We’ve done some research on this and found a post from 2015 (referencing FreeRADIUS 2.X) in which someone was complaining about a similar issue, and someone responded that rlm_python is not thread safe in FreeRADIUS 2.X. Could someone here help us understand the expected threading behavior of rlm_python in FreeRADIUS 3.0.19? Is there some way to configure FreeRADIUS, rlm_python or the Python runtime to enable calling the authorize function in a multithreaded fashion?
Here are the details of our runtime environment:
FreeRADIUS Version: 3.0.19
Python Version: 2.7.15
Please let us know if you need any additional environmental or configuration information.
We thank you in advance for any help you can provide.
2
1
in my vps centos 7 with ocserv 12.5 and freeradius 3.0.5 standard installation when in connect from clinet to server 2 database record created with same "acctsessionid" and in daloradius i see 2 connect with same user id but when i disconnected 1 of records terminate and clear from daloradius online user but other don't and if i limit Simultaneous-Use := 1 or 2 after that can't connect until manualy delet that session from online user, please help if pasible
### radiusd -Xoutput for connect
Ready to process requests
(0) Received Access-Request Id 40 from 127.0.0.1:40914 to 127.0.0.1:1812 length 122
(0) User-Name = "0001"
(0) User-Password = "6028"
(0) Calling-Station-Id = "185.131.136.61"
(0) Connect-Info = "AnyConnect Windows 4.8.01090"
(0) Service-Type = Authenticate-Only
(0) NAS-Port-Type = Async
(0) NAS-Port = 2565
(0) NAS-IP-Address = 127.0.0.1
(0) NAS-Identifier = "ocserv"
(0) # Executing section authorize from file /etc/raddb/sites-enabled/default
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]@/ ) {
(0) if (&User-Name =~ /@[^@]@/ ) -> FALSE
(0) if (&User-Name =~ /../ ) {
(0) if (&User-Name =~ /../ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+).(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+).(.+)$/)) -> FALS E
(0) if (&User-Name =~ /.$/) {
(0) if (&User-Name =~ /.$/) -> FALSE
(0) if (&User-Name =~ /@./) {
(0) if (&User-Name =~ /@./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) [preprocess] = ok
(0) [chap] = noop
(0) [mschap] = noop
(0) [digest] = noop
(0) suffix: Checking for suffix after "@"
(0) suffix: No '@' in User-Name = "0001", looking up realm NULL
(0) suffix: No such realm "NULL"
(0) [suffix] = noop
(0) eap: No EAP-Message, not doing EAP
(0) [eap] = noop
(0) sql: EXPAND %{User-Name}
(0) sql: --> 0001
(0) sql: SQL-User-Name set to '0001'
rlm_sql (sql): Closing connection (1): Hit idle_timeout, was idle for 64 seconds
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (2): Hit idle_timeout, was idle for 64 seconds
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (3): Hit idle_timeout, was idle for 64 seconds
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (4): Hit idle_timeout, was idle for 64 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (0): Hit idle_timeout, was idle for 64 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (5): Hit idle_timeout, was idle for 64 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): 0 of 0 connections in use. You may need to increase "spare"
rlm_sql (sql): Opening additional connection (6), 1 of 32 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, serv er version 5.5.64-MariaDB, protocol version 10
rlm_sql (sql): Reserved connection (6)
(0) sql: EXPAND SELECT id, username, attribute, value, op FROM radcheck WHERE us ername = '%{SQL-User-Name}' ORDER BY id
(0) sql: --> SELECT id, username, attribute, value, op FROM radcheck WHERE us ername = '0001' ORDER BY id
(0) sql: Executing select query: SELECT id, username, attribute, value, op FROM radcheck WHERE username = '0001' ORDER BY id
(0) sql: User found in radcheck table
(0) sql: Conditional check items matched, merging assignment check items
(0) sql: Cleartext-Password := "6028"
(0) sql: EXPAND SELECT id, username, attribute, value, op FROM radreply WHERE us ername = '%{SQL-User-Name}' ORDER BY id
(0) sql: --> SELECT id, username, attribute, value, op FROM radreply WHERE us ername = '0001' ORDER BY id
(0) sql: Executing select query: SELECT id, username, attribute, value, op FROM radreply WHERE username = '0001' ORDER BY id
(0) sql: EXPAND SELECT groupname FROM radusergroup WHERE username = '%{SQL-User- Name}' ORDER BY priority
(0) sql: --> SELECT groupname FROM radusergroup WHERE username = '0001' ORDER BY priority
(0) sql: Executing select query: SELECT groupname FROM radusergroup WHERE userna me = '0001' ORDER BY priority
(0) sql: User found in the group table
(0) sql: EXPAND SELECT id, groupname, attribute, Value, op FROM radgroupcheck WH ERE groupname = '%{SQL-Group}' ORDER BY id
(0) sql: --> SELECT id, groupname, attribute, Value, op FROM radgroupcheck WH ERE groupname = '01-month' ORDER BY id
(0) sql: Executing select query: SELECT id, groupname, attribute, Value, op FROM radgroupcheck WHERE groupname = '01-month' ORDER BY id
(0) sql: Group "01-month": Conditional check items matched
(0) sql: Group "01-month": Merging assignment check items
(0) sql: Simultaneous-Use := 12
(0) sql: Expire-After := 2592000
(0) sql: EXPAND SELECT id, groupname, attribute, value, op FROM radgroupreply WH ERE groupname = '%{SQL-Group}' ORDER BY id
(0) sql: --> SELECT id, groupname, attribute, value, op FROM radgroupreply WH ERE groupname = '01-month' ORDER BY id
(0) sql: Executing select query: SELECT id, groupname, attribute, value, op FROM radgroupreply WHERE groupname = '01-month' ORDER BY id
(0) sql: Group "01-month": Merging reply items
rlm_sql (sql): Released connection (6)
Need 2 more connections to reach min connections (3)
rlm_sql (sql): Opening additional connection (7), 1 of 31 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, serv er version 5.5.64-MariaDB, protocol version 10
(0) [sql] = ok
(0) [expiration] = noop
(0) [logintime] = noop
sqlcounter_expand: 'SELECT IFNULL( MAX(TIME_TO_SEC(TIMEDIFF(NOW(), acctstarttime ))),0) FROM radacct WHERE UserName='%{User-Name}' ORDER BY acctstarttime LIMIT 1 ;'
(0) expire_on_login: EXPAND %{User-Name}
(0) expire_on_login: --> 0001
(0) expire_on_login: SQL-User-Name set to '0001'
rlm_sql (sql): Reserved connection (6)
(0) expire_on_login: Executing select query: SELECT IFNULL( MAX(TIME_TO_SEC(TIME DIFF(NOW(), acctstarttime))),0) FROM radacct WHERE UserName='0001' ORDER BY acct starttime LIMIT 1;
rlm_sql (sql): Released connection (6)
(0) expire_on_login: EXPAND %{sql:SELECT IFNULL( MAX(TIME_TO_SEC(TIMEDIFF(NOW(), acctstarttime))),0) FROM radacct WHERE UserName='%{User-Name}' ORDER BY acctsta rttime LIMIT 1;}
(0) expire_on_login: --> 262897
(0) expire_on_login: Allowing user, &control:Expire-After value (2592000) is gre ater than counter value (262897)
(0) expire_on_login: Setting &reply:Session-Timeout value to 2329103
(0) [expire_on_login] = ok
(0) [pap] = updated
(0) } # authorize = updated
(0) Found Auth-Type = PAP
(0) # Executing group from file /etc/raddb/sites-enabled/default
(0) Auth-Type PAP {
(0) pap: Login attempt with password
(0) pap: Comparing with "known good" Cleartext-Password
(0) pap: User authenticated successfully
(0) [pap] = ok
(0) } # Auth-Type PAP = ok
(0) # Executing section session from file /etc/raddb/sites-enabled/default
(0) session {
(0) sql: EXPAND %{User-Name}
(0) sql: --> 0001
(0) sql: SQL-User-Name set to '0001'
(0) sql: EXPAND SELECT COUNT() FROM radacct WHERE username = '%{SQL-User-Name}' AND acctstoptime IS NULL
(0) sql: --> SELECT COUNT() FROM radacct WHERE username = '0001' AND acctsto ptime IS NULL
rlm_sql (sql): Reserved connection (7)
(0) sql: Executing select query: SELECT COUNT(*) FROM radacct WHERE username = ' 0001' AND acctstoptime IS NULL
rlm_sql (sql): Released connection (7)
(0) [sql] = ok
(0) } # session = ok
(0) # Executing section post-auth from file /etc/raddb/sites-enabled/default
(0) post-auth {
(0) update {
(0) No attributes updated
(0) } # update = noop
(0) sql: EXPAND .query
(0) sql: --> .query
(0) sql: Using query template 'query'
rlm_sql (sql): Reserved connection (6)
(0) sql: EXPAND %{User-Name}
(0) sql: --> 0001
(0) sql: SQL-User-Name set to '0001'
(0) sql: EXPAND INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( '%{SQL-User-Name}', '%{%{User-Password}:-%{Chap-Password}}', '%{reply:Packet- Type}', '%S')
(0) sql: --> INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( '0001', '6028', 'Access-Accept', '2020-01-01 02:23:25.578473')
(0) sql: Executing query: INSERT INTO radpostauth (username, pass, reply, authda te) VALUES ( '0001', '6028', 'Access-Accept', '2020-01-01 02:23:25.578473')
(0) sql: SQL query returned: success
(0) sql: 1 record(s) updated
rlm_sql (sql): Released connection (6)
(0) [sql] = ok
(0) [exec] = noop
(0) policy remove_reply_message_if_eap {
(0) if (&reply:EAP-Message && &reply:Reply-Message) {
(0) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(0) else {
(0) [noop] = noop
(0) } # else = noop
(0) } # policy remove_reply_message_if_eap = noop
(0) } # post-auth = ok
(0) Login OK: [0001/6028] (from client localhost port 2565 cli 185.131.136.61)
(0) Sent Access-Accept Id 40 from 127.0.0.1:1812 to 127.0.0.1:40914 length 0
(0) Session-Timeout = 2329103
(0) Finished request
Waking up in 4.9 seconds.
(0) Cleaning up request packet ID 40 with timestamp +64
Ready to process requests
(1) Received Accounting-Request Id 195 from 127.0.0.1:56449 to 127.0.0.1:1813 le ngth 152
(1) Acct-Status-Type = Start
(1) Connect-Info = "AnyConnect Windows 4.8.01090"
(1) User-Name = "0001"
(1) Service-Type = Framed-User
(1) Framed-Protocol = PPP
(1) Calling-Station-Id = "185.131.136.61"
(1) Acct-Session-Id = "YokGL5neiA2JyiM49N9Bytg0hYk="
(1) Acct-Authentic = RADIUS
(1) NAS-Port = 2565
(1) Acct-Delay-Time = 0
(1) NAS-IP-Address = 127.0.0.1
(1) NAS-Identifier = "ocserv"
(1) # Executing section preacct from file /etc/raddb/sites-enabled/default
(1) preacct {
(1) [preprocess] = ok
(1) policy acct_unique {
(1) update request {
(1) &Tmp-String-9 := "ai:"
(1) } # update request = noop
(1) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:& Class}" =~ /^ai:([0-9a-f]{32})/i)) {
(1) EXPAND %{hex:&Class}
(1) -->
(1) EXPAND ^%{hex:&Tmp-String-9}
(1) --> ^61693a
(1) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:& Class}" =~ /^ai:([0-9a-f]{32})/i)) -> FALSE
(1) else {
(1) update request {
(1) EXPAND %{md5:%{User-Name},%{Acct-Session-ID},%{%{NAS-IPv6-Address} :-%{NAS-IP-Address}},%{NAS-Identifier},%{NAS-Port-ID},%{NAS-Port}}
(1) --> 440bf34dbf28bc1cb53423b82d8bad65
(1) &Acct-Unique-Session-Id := 440bf34dbf28bc1cb53423b82d8bad65
(1) } # update request = noop
(1) } # else = noop
(1) } # policy acct_unique = noop
(1) suffix: Checking for suffix after "@"
(1) suffix: No '@' in User-Name = "0001", looking up realm NULL
(1) suffix: No such realm "NULL"
(1) [suffix] = noop
(1) } # preacct = ok
(1) # Executing section accounting from file /etc/raddb/sites-enabled/default
(1) accounting {
(1) detail: EXPAND /var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet- Src-IPv6-Address}}/detail-%Y%m%d
(1) detail: --> /var/log/radius/radacct/127.0.0.1/detail-20200101
(1) detail: /var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv 6-Address}}/detail-%Y%m%d expands to /var/log/radius/radacct/127.0.0.1/detail-20 200101
(1) detail: EXPAND %t
(1) detail: --> Wed Jan 1 02:23:34 2020
(1) [detail] = ok
(1) [unix] = ok
(1) sql: EXPAND %{tolower:type.%{Acct-Status-Type}.query}
(1) sql: --> type.start.query
(1) sql: Using query template 'query'
rlm_sql (sql): Reserved connection (7)
(1) sql: EXPAND %{User-Name}
(1) sql: --> 0001
(1) sql: SQL-User-Name set to '0001'
(1) sql: EXPAND INSERT INTO radacct (acctsessionid, acctuniqueid, u sername, realm, nasipaddress, nasportid, nasporttype,a cctstarttime, acctupdatetime, acctstoptime, acctsessiontime, acctauthentic, connectinfo_start, connectinfo_stop, acctinpu toctets, acctoutputoctets, calledstationid, callingstationid, acctte rminatecause, servicetype, framedprotocol, framedipaddress) VALUES ('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm }', '%{NAS-IP-Address}', '%{%{NAS-Port-ID}:-%{NAS-Port}}', '%{NAS-Port-Type}', F ROM_UNIXTIME(%{integer:Event-Timestamp}), FROM_UNIXTIME(%{integer:Event-Timestam p}), NULL, '0', '%{Acct-Authentic}', '%{Connect-Info}', '', '0', '0', '%{Called- Station-Id}', '%{Calling-Station-Id}', '', '%{Service-Type}', '%{Framed-Protocol }', '%{Framed-IP-Address}')
(1) sql: --> INSERT INTO radacct (acctsessionid, acctuniqueid, u sername, realm, nasipaddress, nasportid, nasporttype,a cctstarttime, acctupdatetime, acctstoptime, acctsessiontime, acctauthentic, connectinfo_start, connectinfo_stop, acctinpu toctets, acctoutputoctets, calledstationid, callingstationid, acctte rminatecause, servicetype, framedprotocol, framedipaddress) VALUES ('YokGL5neiA2JyiM49N9Bytg0hYk=3D', '440bf34dbf28bc1cb53423b82d8bad65', '0001', ' ', '127.0.0.1', '2565', '', FROM_UNIXTIME(1577832814), FROM_UNIXTIME(1577832814) , NULL, '0', 'RADIUS', 'AnyConnect Windows 4.8.01090', '', '0', '0', '', '185.13 1.136.61', '', 'Framed-User', 'PPP', '')
(1) sql: Executing query: INSERT INTO radacct (acctsessionid, acctuniq ueid, username, realm, nasipaddress, n asportid, nasporttype, acctstarttime, acctupdatetime, acctstop time, acctsessiontime, acctauthentic, connectinfo_start, c onnectinfo_stop, acctinputoctets, acctoutputoctets, calledstationid, callingstationid, acctterminatecause, servicetype, framedpr otocol, framedipaddress) VALUES ('YokGL5neiA2JyiM49N9Bytg0hYk=3D', '440bf34dbf28 bc1cb53423b82d8bad65', '0001', '', '127.0.0.1', '2565', '', FROM_UNIXTIME(157783 2814), FROM_UNIXTIME(1577832814), NULL, '0', 'RADIUS', 'AnyConnect Windows 4.8.0 1090', '', '0', '0', '', '185.131.136.61', '', 'Framed-User', 'PPP', '')
(1) sql: SQL query returned: success
(1) sql: 1 record(s) updated
rlm_sql (sql): Released connection (7)
Need 1 more connections to reach min connections (3)
rlm_sql (sql): Opening additional connection (8), 1 of 30 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, serv er version 5.5.64-MariaDB, protocol version 10
(1) [sql] = ok
(1) [exec] = noop
(1) attr_filter.accounting_response: EXPAND %{User-Name}
(1) attr_filter.accounting_response: --> 0001
(1) attr_filter.accounting_response: Matched entry DEFAULT at line 12
(1) [attr_filter.accounting_response] = updated
(1) } # accounting = updated
(1) Sent Accounting-Response Id 195 from 127.0.0.1:1813 to 127.0.0.1:56449 lengt h 0
(1) Finished request
(1) Cleaning up request packet ID 195 with timestamp +73
Ready to process requests
(2) Received Accounting-Request Id 32 from 127.0.0.1:36675 to 127.0.0.1:1813 len gth 152
(2) Acct-Status-Type = Interim-Update
(2) User-Name = "0001"
(2) Service-Type = Framed-User
(2) Framed-Protocol = PPP
(2) Framed-IP-Address = 10.10.1.186
(2) Calling-Station-Id = "185.131.136.61"
(2) Acct-Session-Id = "YokGL5neiA2JyiM49N9Bytg0hYk="
(2) Acct-Authentic = RADIUS
(2) Acct-Input-Octets = 0
(2) Acct-Output-Octets = 0
(2) Acct-Input-Gigawords = 0
(2) Acct-Output-Gigawords = 0
(2) NAS-Port = 2575
(2) Acct-Delay-Time = 0
(2) NAS-IP-Address = 127.0.0.1
(2) NAS-Identifier = "ocserv"
(2) # Executing section preacct from file /etc/raddb/sites-enabled/default
(2) preacct {
(2) [preprocess] = ok
(2) policy acct_unique {
(2) update request {
(2) &Tmp-String-9 := "ai:"
(2) } # update request = noop
(2) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:& Class}" =~ /^ai:([0-9a-f]{32})/i)) {
(2) EXPAND %{hex:&Class}
(2) -->
(2) EXPAND ^%{hex:&Tmp-String-9}
(2) --> ^61693a
(2) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:& Class}" =~ /^ai:([0-9a-f]{32})/i)) -> FALSE
(2) else {
(2) update request {
(2) EXPAND %{md5:%{User-Name},%{Acct-Session-ID},%{%{NAS-IPv6-Address} :-%{NAS-IP-Address}},%{NAS-Identifier},%{NAS-Port-ID},%{NAS-Port}}
(2) --> 2f664aa021eff0bd90754442f6900278
(2) &Acct-Unique-Session-Id := 2f664aa021eff0bd90754442f6900278
(2) } # update request = noop
(2) } # else = noop
(2) } # policy acct_unique = noop
(2) suffix: Checking for suffix after "@"
(2) suffix: No '@' in User-Name = "0001", looking up realm NULL
(2) suffix: No such realm "NULL"
(2) [suffix] = noop
(2) } # preacct = ok
(2) # Executing section accounting from file /etc/raddb/sites-enabled/default
(2) accounting {
(2) detail: EXPAND /var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet- Src-IPv6-Address}}/detail-%Y%m%d
(2) detail: --> /var/log/radius/radacct/127.0.0.1/detail-20200101
(2) detail: /var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv 6-Address}}/detail-%Y%m%d expands to /var/log/radius/radacct/127.0.0.1/detail-20 200101
(2) detail: EXPAND %t
(2) detail: --> Wed Jan 1 02:23:34 2020
(2) [detail] = ok
(2) [unix] = noop
(2) sql: EXPAND %{tolower:type.%{Acct-Status-Type}.query}
(2) sql: --> type.interim-update.query
(2) sql: Using query template 'query'
rlm_sql (sql): Reserved connection (6)
(2) sql: EXPAND %{User-Name}
(2) sql: --> 0001
(2) sql: SQL-User-Name set to '0001'
(2) sql: EXPAND UPDATE radacct SET acctupdatetime = (@acctupdatetime_old:=acctu pdatetime), acctupdatetime = FROM_UNIXTIME(%{integer:Event-Timestamp}), acctint erval = %{integer:Event-Timestamp} - UNIX_TIMESTAMP(@acctupdatetime_old), fra medipaddress = '%{Framed-IP-Address}', acctsessiontime = %{%{Acct-Session-Time}: -NULL}, acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Inpu t-Octets}:-0}', acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{% {Acct-Output-Octets}:-0}' WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'
(2) sql: --> UPDATE radacct SET acctupdatetime = (@acctupdatetime_old:=acctu pdatetime), acctupdatetime = FROM_UNIXTIME(1577832814), acctinterval = 15778 32814 - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '10.10.1.186', ac ctsessiontime = NULL, acctinputoctets = '0' << 32 | '0', acctoutputoctets = '0' << 32 | '0' WHERE AcctUniqueId = '2f664aa021eff0bd90754442f6900278'
(2) sql: Executing query: UPDATE radacct SET acctupdatetime = (@acctupdatetime_ old:=acctupdatetime), acctupdatetime = FROM_UNIXTIME(1577832814), acctinterval = 1577832814 - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '10.10. 1.186', acctsessiontime = NULL, acctinputoctets = '0' << 32 | '0', acctoutputoct ets = '0' << 32 | '0' WHERE AcctUniqueId = '2f664aa021eff0bd90754442f6900278'
rlm_sql_mysql: Rows matched: 0 Changed: 0 Warnings: 0
(2) sql: SQL query returned: success
(2) sql: 0 record(s) updated
(2) sql: Trying next query...
(2) sql: EXPAND INSERT INTO radacct (acctsessionid, acctuniqueid, u sername, realm, nasipaddress, nasportid, nasporttype,a cctstarttime, acctupdatetime, acctstoptime, acctsessiontime, acctauthentic, connectinfo_start, connectinfo_stop, acctinpu toctets, acctoutputoctets, calledstationid, callingstationid, acctte rminatecause, servicetype, framedprotocol, framedipaddress) VALUES ('%{Acct-Session-Id}', '%{Acct-Unique-Session-Id}', '%{SQL-User-Name}', '%{Realm }', '%{NAS-IP-Address}', '%{%{NAS-Port-ID}:-%{NAS-Port}}', '%{NAS-Port-Type}', F ROM_UNIXTIME(%{integer:Event-Timestamp} - %{%{Acct-Session-Time}:-0}), FROM_UNIX TIME(%{integer:Event-Timestamp}), NULL, %{%{Acct-Session-Time}:-NULL}, '%{Acct-A uthentic}', '%{Connect-Info}', '', '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{ Acct-Input-Octets}:-0}', '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{%{Acct-Outp ut-Octets}:-0}', '%{Called-Station-Id}', '%{Calling-Station-Id}', '', '%{Service -Type}', '%{Framed-Protocol}', '%{Framed-IP-Address}')
(2) sql: --> INSERT INTO radacct (acctsessionid, acctuniqueid, u sername, realm, nasipaddress, nasportid, nasporttype,a cctstarttime, acctupdatetime, acctstoptime, acctsessiontime, acctauthentic, connectinfo_start, connectinfo_stop, acctinpu toctets, acctoutputoctets, calledstationid, callingstationid, acctte rminatecause, servicetype, framedprotocol, framedipaddress) VALUES ('YokGL5neiA2JyiM49N9Bytg0hYk=3D', '2f664aa021eff0bd90754442f6900278', '0001', ' ', '127.0.0.1', '2575', '', FROM_UNIXTIME(1577832814 - 0), FROM_UNIXTIME(1577832 814), NULL, NULL, 'RADIUS', '', '', '0' << 32 | '0', '0' << 32 | '0', '', '185.1 31.136.61', '', 'Framed-User', 'PPP', '10.10.1.186')
(2) sql: Executing query: INSERT INTO radacct (acctsessionid, acctuniq ueid, username, realm, nasipaddress, n asportid, nasporttype, acctstarttime, acctupdatetime, acctstop time, acctsessiontime, acctauthentic, connectinfo_start, c onnectinfo_stop, acctinputoctets, acctoutputoctets, calledstationid, callingstationid, acctterminatecause, servicetype, framedpr otocol, framedipaddress) VALUES ('YokGL5neiA2JyiM49N9Bytg0hYk=3D', '2f664aa021ef f0bd90754442f6900278', '0001', '', '127.0.0.1', '2575', '', FROM_UNIXTIME(157783 2814 - 0), FROM_UNIXTIME(1577832814), NULL, NULL, 'RADIUS', '', '', '0' << 32 | '0', '0' << 32 | '0', '', '185.131.136.61', '', 'Framed-User', 'PPP', '10.10.1.1 86')
(2) sql: SQL query returned: success
(2) sql: 1 record(s) updated
rlm_sql (sql): Released connection (6)
(2) [sql] = ok
(2) [exec] = noop
(2) attr_filter.accounting_response: EXPAND %{User-Name}
(2) attr_filter.accounting_response: --> 0001
(2) attr_filter.accounting_response: Matched entry DEFAULT at line 12
(2) [attr_filter.accounting_response] = updated
(2) } # accounting = updated
(2) Sent Accounting-Response Id 32 from 127.0.0.1:1813 to 127.0.0.1:36675 length 0
(2) Finished request
(2) Cleaning up request packet ID 32 with timestamp +73
Ready to process requests
(3) Received Accounting-Request Id 95 from 127.0.0.1:50916 to 127.0.0.1:1813 len gth 158
(3) Acct-Status-Type = Interim-Update
(3) User-Name = "0001"
(3) Service-Type = Framed-User
(3) Framed-Protocol = PPP
(3) Framed-IP-Address = 10.10.1.186
(3) Calling-Station-Id = "185.131.136.61"
(3) Acct-Session-Id = "YokGL5neiA2JyiM49N9Bytg0hYk="
(3) Acct-Authentic = RADIUS
(3) Acct-Session-Time = 97
(3) Acct-Input-Octets = 26528
(3) Acct-Output-Octets = 11973
(3) Acct-Input-Gigawords = 0
(3) Acct-Output-Gigawords = 0
(3) NAS-Port = 2575
(3) Acct-Delay-Time = 0
(3) NAS-IP-Address = 127.0.0.1
(3) NAS-Identifier = "ocserv"
(3) # Executing section preacct from file /etc/raddb/sites-enabled/default
(3) preacct {
(3) [preprocess] = ok
(3) policy acct_unique {
(3) update request {
(3) &Tmp-String-9 := "ai:"
(3) } # update request = noop
(3) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:& Class}" =~ /^ai:([0-9a-f]{32})/i)) {
(3) EXPAND %{hex:&Class}
(3) -->
(3) EXPAND ^%{hex:&Tmp-String-9}
(3) --> ^61693a
(3) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:& Class}" =~ /^ai:([0-9a-f]{32})/i)) -> FALSE
(3) else {
(3) update request {
(3) EXPAND %{md5:%{User-Name},%{Acct-Session-ID},%{%{NAS-IPv6-Address} :-%{NAS-IP-Address}},%{NAS-Identifier},%{NAS-Port-ID},%{NAS-Port}}
(3) --> 2f664aa021eff0bd90754442f6900278
(3) &Acct-Unique-Session-Id := 2f664aa021eff0bd90754442f6900278
(3) } # update request = noop
(3) } # else = noop
(3) } # policy acct_unique = noop
(3) suffix: Checking for suffix after "@"
(3) suffix: No '@' in User-Name = "0001", looking up realm NULL
(3) suffix: No such realm "NULL"
(3) [suffix] = noop
(3) } # preacct = ok
(3) # Executing section accounting from file /etc/raddb/sites-enabled/default
(3) accounting {
(3) detail: EXPAND /var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet- Src-IPv6-Address}}/detail-%Y%m%d
(3) detail: --> /var/log/radius/radacct/127.0.0.1/detail-20200101
(3) detail: /var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv 6-Address}}/detail-%Y%m%d expands to /var/log/radius/radacct/127.0.0.1/detail-20 200101
(3) detail: EXPAND %t
(3) detail: --> Wed Jan 1 02:25:11 2020
(3) [detail] = ok
(3) [unix] = noop
(3) sql: EXPAND %{tolower:type.%{Acct-Status-Type}.query}
(3) sql: --> type.interim-update.query
(3) sql: Using query template 'query'
rlm_sql (sql): Closing connection (7): Hit idle_timeout, was idle for 97 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (8): Hit idle_timeout, was idle for 97 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (6): Hit idle_timeout, was idle for 97 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): 0 of 0 connections in use. You may need to increase "spare"
rlm_sql (sql): Opening additional connection (9), 1 of 32 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, serv er version 5.5.64-MariaDB, protocol version 10
rlm_sql (sql): Reserved connection (9)
(3) sql: EXPAND %{User-Name}
(3) sql: --> 0001
(3) sql: SQL-User-Name set to '0001'
(3) sql: EXPAND UPDATE radacct SET acctupdatetime = (@acctupdatetime_old:=acctu pdatetime), acctupdatetime = FROM_UNIXTIME(%{integer:Event-Timestamp}), acctint erval = %{integer:Event-Timestamp} - UNIX_TIMESTAMP(@acctupdatetime_old), fra medipaddress = '%{Framed-IP-Address}', acctsessiontime = %{%{Acct-Session-Time}: -NULL}, acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Inpu t-Octets}:-0}', acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{% {Acct-Output-Octets}:-0}' WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'
(3) sql: --> UPDATE radacct SET acctupdatetime = (@acctupdatetime_old:=acctu pdatetime), acctupdatetime = FROM_UNIXTIME(1577832911), acctinterval = 15778 32911 - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '10.10.1.186', ac ctsessiontime = 97, acctinputoctets = '0' << 32 | '26528', acctoutputoctets = '0 ' << 32 | '11973' WHERE AcctUniqueId = '2f664aa021eff0bd90754442f6900278'
(3) sql: Executing query: UPDATE radacct SET acctupdatetime = (@acctupdatetime_ old:=acctupdatetime), acctupdatetime = FROM_UNIXTIME(1577832911), acctinterval = 1577832911 - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '10.10. 1.186', acctsessiontime = 97, acctinputoctets = '0' << 32 | '26528', acctoutputo ctets = '0' << 32 | '11973' WHERE AcctUniqueId = '2f664aa021eff0bd90754442f69002 78'
rlm_sql_mysql: Rows matched: 1 Changed: 1 Warnings: 0
(3) sql: SQL query returned: success
(3) sql: 1 record(s) updated
rlm_sql (sql): Released connection (9)
Need 2 more connections to reach min connections (3)
rlm_sql (sql): Opening additional connection (10), 1 of 31 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, serv er version 5.5.64-MariaDB, protocol version 10
(3) [sql] = ok
(3) [exec] = noop
(3) attr_filter.accounting_response: EXPAND %{User-Name}
(3) attr_filter.accounting_response: --> 0001
(3) attr_filter.accounting_response: Matched entry DEFAULT at line 12
(3) [attr_filter.accounting_response] = updated
(3) } # accounting = updated
(3) Sent Accounting-Response Id 95 from 127.0.0.1:1813 to 127.0.0.1:50916 length 0
(3) Finished request
(3) Cleaning up request packet ID 95 with timestamp +170
Ready to process requests
(4) Received Accounting-Request Id 155 from 127.0.0.1:33090 to 127.0.0.1:1813 le ngth 158
(4) Acct-Status-Type = Interim-Update
(4) User-Name = "0001"
(4) Service-Type = Framed-User
(4) Framed-Protocol = PPP
(4) Framed-IP-Address = 10.10.1.186
(4) Calling-Station-Id = "185.131.136.61"
(4) Acct-Session-Id = "YokGL5neiA2JyiM49N9Bytg0hYk="
(4) Acct-Authentic = RADIUS
(4) Acct-Session-Time = 209
(4) Acct-Input-Octets = 31377
(4) Acct-Output-Octets = 18986
(4) Acct-Input-Gigawords = 0
(4) Acct-Output-Gigawords = 0
(4) NAS-Port = 2575
(4) Acct-Delay-Time = 0
(4) NAS-IP-Address = 127.0.0.1
(4) NAS-Identifier = "ocserv"
(4) # Executing section preacct from file /etc/raddb/sites-enabled/default
(4) preacct {
(4) [preprocess] = ok
(4) policy acct_unique {
(4) update request {
(4) &Tmp-String-9 := "ai:"
(4) } # update request = noop
(4) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:& Class}" =~ /^ai:([0-9a-f]{32})/i)) {
(4) EXPAND %{hex:&Class}
(4) -->
(4) EXPAND ^%{hex:&Tmp-String-9}
(4) --> ^61693a
(4) if (("%{hex:&Class}" =~ /^%{hex:&Tmp-String-9}/) && ("%{string:& Class}" =~ /^ai:([0-9a-f]{32})/i)) -> FALSE
(4) else {
(4) update request {
(4) EXPAND %{md5:%{User-Name},%{Acct-Session-ID},%{%{NAS-IPv6-Address} :-%{NAS-IP-Address}},%{NAS-Identifier},%{NAS-Port-ID},%{NAS-Port}}
(4) --> 2f664aa021eff0bd90754442f6900278
(4) &Acct-Unique-Session-Id := 2f664aa021eff0bd90754442f6900278
(4) } # update request = noop
(4) } # else = noop
(4) } # policy acct_unique = noop
(4) suffix: Checking for suffix after "@"
(4) suffix: No '@' in User-Name = "0001", looking up realm NULL
(4) suffix: No such realm "NULL"
(4) [suffix] = noop
(4) } # preacct = ok
(4) # Executing section accounting from file /etc/raddb/sites-enabled/default
(4) accounting {
(4) detail: EXPAND /var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet- Src-IPv6-Address}}/detail-%Y%m%d
(4) detail: --> /var/log/radius/radacct/127.0.0.1/detail-20200101
(4) detail: /var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv 6-Address}}/detail-%Y%m%d expands to /var/log/radius/radacct/127.0.0.1/detail-20 200101
(4) detail: EXPAND %t
(4) detail: --> Wed Jan 1 02:27:03 2020
(4) [detail] = ok
(4) [unix] = noop
(4) sql: EXPAND %{tolower:type.%{Acct-Status-Type}.query}
(4) sql: --> type.interim-update.query
(4) sql: Using query template 'query'
rlm_sql (sql): Closing connection (9): Hit idle_timeout, was idle for 112 second s
rlm_sql (sql): You probably need to lower "min"
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (10): Hit idle_timeout, was idle for 112 secon ds
rlm_sql (sql): You probably need to lower "min"
rlm_sql_mysql: Socket destructor called, closing socket
rlm_sql (sql): 0 of 0 connections in use. You may need to increase "spare"
rlm_sql (sql): Opening additional connection (11), 1 of 32 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, serv er version 5.5.64-MariaDB, protocol version 10
rlm_sql (sql): Reserved connection (11)
(4) sql: EXPAND %{User-Name}
(4) sql: --> 0001
(4) sql: SQL-User-Name set to '0001'
(4) sql: EXPAND UPDATE radacct SET acctupdatetime = (@acctupdatetime_old:=acctu pdatetime), acctupdatetime = FROM_UNIXTIME(%{integer:Event-Timestamp}), acctint erval = %{integer:Event-Timestamp} - UNIX_TIMESTAMP(@acctupdatetime_old), fra medipaddress = '%{Framed-IP-Address}', acctsessiontime = %{%{Acct-Session-Time}: -NULL}, acctinputoctets = '%{%{Acct-Input-Gigawords}:-0}' << 32 | '%{%{Acct-Inpu t-Octets}:-0}', acctoutputoctets = '%{%{Acct-Output-Gigawords}:-0}' << 32 | '%{% {Acct-Output-Octets}:-0}' WHERE AcctUniqueId = '%{Acct-Unique-Session-Id}'
(4) sql: --> UPDATE radacct SET acctupdatetime = (@acctupdatetime_old:=acctu pdatetime), acctupdatetime = FROM_UNIXTIME(1577833023), acctinterval = 15778 33023 - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '10.10.1.186', ac ctsessiontime = 209, acctinputoctets = '0' << 32 | '31377', acctoutputoctets = ' 0' << 32 | '18986' WHERE AcctUniqueId = '2f664aa021eff0bd90754442f6900278'
(4) sql: Executing query: UPDATE radacct SET acctupdatetime = (@acctupdatetime_ old:=acctupdatetime), acctupdatetime = FROM_UNIXTIME(1577833023), acctinterval = 1577833023 - UNIX_TIMESTAMP(@acctupdatetime_old), framedipaddress = '10.10. 1.186', acctsessiontime = 209, acctinputoctets = '0' << 32 | '31377', acctoutput octets = '0' << 32 | '18986' WHERE AcctUniqueId = '2f664aa021eff0bd90754442f6900 278'
rlm_sql_mysql: Rows matched: 1 Changed: 1 Warnings: 0
(4) sql: SQL query returned: success
(4) sql: 1 record(s) updated
rlm_sql (sql): Released connection (11)
Need 2 more connections to reach min connections (3)
rlm_sql (sql): Opening additional connection (12), 1 of 31 pending slots used
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql_mysql: Connected to database 'radius' on Localhost via UNIX socket, serv er version 5.5.64-MariaDB, protocol version 10
(4) [sql] = ok
(4) [exec] = noop
(4) attr_filter.accounting_response: EXPAND %{User-Name}
(4) attr_filter.accounting_response: --> 0001
(4) attr_filter.accounting_response: Matched entry DEFAULT at line 12
(4) [attr_filter.accounting_response] = updated
(4) } # accounting = updated
(4) Sent Accounting-Response Id 155 from 127.0.0.1:1813 to 127.0.0.1:33090 lengt h 0
(4) Finished request
(4) Cleaning up request packet ID 155 with timestamp +282
Ready to process requests
3
3
Hello.
I want to configure the second authorisation factor with EAP-type, and md5
hashed password saved in MySQL.
I found several modules and services like MultiOTP and Smsotp, but I can't
understand how to provide the SMS before the authorisation or how to ask
FreeRadius to wait for the process sends SMS?
Could you please explain this to me?
--
Best regards,
Anton Kiryushkin
3
9
How to grant some (!) devices access to network but all others have to provide passwords
by uj2.hahn@posteo.de 27 Dec '19
by uj2.hahn@posteo.de 27 Dec '19
27 Dec '19
Hi, all!
I'm pretty sure this is a very basic question which might have been
discussed in the past already.
But I'm new in this area so you might apologize this silly question....
In a school all devices (students laptops, mobiles, tablets) have to use
username/password via Freeradius
to get access to WLAN. But there are some well-defined school-owned
devices (laptops, tablets) which should
connect to WLAN immediately w/o any credentials.
Which options do I have to realize that? MAC checks? Certificates?
Thanks for your help
Uwe
3
5
Hi,
I met below error when run "/usr/sbin/radiusd -C -X", Could someone
experts at this help to
give me some hint what configuration maybe wrong? Thanks
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/etc/raddb/certs/server.pem"
certificate_file = "/etc/raddb/certs/server.pem"
ca_file = "/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/etc/raddb/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
cipher_server_preference = no
tls_max_version = ""
tls_min_version = "1.0"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
tls: Failed reading private key file "/etc/raddb/certs/server.pem"
tls: error:0607606B:digital envelope
routines:PKCS5_v2_PBE_keyivgen:unsupported cipher
tls: error:06074078:digital envelope routines:EVP_PBE_CipherInit:keygen
failure
tls: error:23077073:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 algor
cipherinit error
tls: error:2306A075:PKCS12 routines:PKCS12_item_decrypt_d2i:pkcs12 pbe
crypt error
tls: error:0907B00D:PEM routines:PEM_read_bio_PrivateKey:ASN1 lib
tls: error:140B0009:SSL routines:SSL_CTX_use_PrivateKey_file:PEM lib
rlm_eap_tls: Failed initializing SSL context
rlm_eap (EAP): Failed to initialise rlm_eap_tls
/etc/raddb/mods-enabled/eap[14]: Instantiation failed for module "eap"
3
3
Hello.
I am trying to use exec and I am receiving the next log on version 3.0.15:
Mon Dec 23 18:54:42 2019 : Debug: (1) multiotp: Program returned code (0)
and output 'Auth-Type = Accept'
Mon Dec 23 18:54:42 2019 : Debug: (1) multiotp: Program executed
successfully
Mon Dec 23 18:54:42 2019 : Debug: (1) modsingle[authenticate]: returned
from multiotp (rlm_exec)
Mon Dec 23 18:54:42 2019 : Debug: (1) [multiotp] = ok
Mon Dec 23 18:54:42 2019 : Debug: (1) } # Auth-Type multiotp = ok
CONSISTENCY CHECK FAILED src/main/process.c[2800]: Expected VALUE_PAIR
"Auth-Type" to be parented by 0x555d99f0afc0 (RADIUS_PACKET), instead
parented by 0x555d99f0ae10 (REQUEST)
Talloc chunk lineage:
0x555d99f0afc0 (RADIUS_PACKET) < 0x555d99f0ae10 (REQUEST) < 0x555d99f0aba0
(auth_listener_pool)
Talloc context level 0:
Talloc chunk lineage:
0x555d99f0ae10 (REQUEST) < 0x555d99f0aba0 (auth_listener_pool)
Talloc context level 0:
SOFT ASSERT FAILED src/lib/pair.c[2437]: 0
CAUGHT SIGNAL: Aborted
Backtrace of last 16 frames:
/usr/lib64/freeradius/libfreeradius-radius.so(fr_fault+0x115)[0x7fac5bb3defc]
/usr/lib64/freeradius/libfreeradius-radius.so(fr_assert_cond+0x4c)[0x7fac5bb3e98f]
/usr/lib64/freeradius/libfreeradius-radius.so(fr_pair_list_verify+0x117)[0x7fac5bb4fb48]
/usr/lib64/freeradius/libfreeradius-server.so(+0x249c7)[0x7fac5bda09c7]
/usr/lib64/freeradius/libfreeradius-server.so(verify_request+0x124)[0x7fac5bda0af1]
radiusd(+0x4664a)[0x555d98c2b64a]
radiusd(+0x43b5a)[0x555d98c28b5a]
radiusd(+0x428a5)[0x555d98c278a5]
radiusd(request_receive+0x7c8)[0x555d98c293d0]
radiusd(+0x1e888)[0x555d98c03888]
radiusd(+0x4b373)[0x555d98c30373]
/usr/lib64/freeradius/libfreeradius-radius.so(fr_event_loop+0x5a6)[0x7fac5bb65f9c]
radiusd(radius_event_process+0x26)[0x555d98c3215a]
radiusd(main+0xc80)[0x555d98c1c426]
/lib64/libc.so.6(__libc_start_main+0xf5)[0x7fac5a22b765]
radiusd(_start+0x29)[0x555d98bf9e69]
Calling: gdb radiusd 14119
(gdb) bt
#0 0x00007fac5a2c6eba in waitpid () from /lib64/libc.so.6
#1 0x00007fac5a24bdab in do_system () from /lib64/libc.so.6
#2 0x00007fac5bb3e0b8 in fr_fault () from
/usr/lib64/freeradius/libfreeradius-radius.so
#3 0x00007fac5bb3e98f in fr_assert_cond () from
/usr/lib64/freeradius/libfreeradius-radius.so
#4 0x00007fac5bb4fb48 in fr_pair_list_verify () from
/usr/lib64/freeradius/libfreeradius-radius.so
#5 0x00007fac5bda09c7 in verify_packet () from
/usr/lib64/freeradius/libfreeradius-server.so
#6 0x00007fac5bda0af1 in verify_request () from
/usr/lib64/freeradius/libfreeradius-server.so
#7 0x0000555d98c2b64a in request_will_proxy ()
#8 0x0000555d98c28b5a in request_running ()
#9 0x0000555d98c278a5 in request_queue_or_run ()
#10 0x0000555d98c293d0 in request_receive ()
#11 0x0000555d98c03888 in auth_socket_recv ()
#12 0x0000555d98c30373 in event_socket_handler ()
#13 0x00007fac5bb65f9c in fr_event_loop () from
/usr/lib64/freeradius/libfreeradius-radius.so
#14 0x0000555d98c3215a in radius_event_process ()
#15 0x0000555d98c1c426 in main ()
Could you please where am I wrong?
The exec is simple:
exec py-exec {
wait = yes
input_pairs = request
output_pairs = reply
program = "/local/pyexec/pyexec.py --user=%{User-Name}
--key=%{User-Password}"
shell_escape = yes
}
--
Best regards,
Anton Kiryushkin
2
1
I’ve seen a strange one… I’ve created the test certs, etc, that enable the EAP configuration to work. Running radiusd -X, one sees (in relevant part):
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/opt/local/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/opt/local/etc/raddb/certs/server.pem"
certificate_file = "/opt/local/etc/raddb/certs/server.pem"
ca_file = "/opt/local/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/opt/local/etc/raddb/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
cipher_server_preference = no
ecdh_curve = "prime256v1"
tls_max_version = ""
tls_min_version = "1.0"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
[…]
However, if I try to start radiusd as normal (not via -X), I end up with this behavior in the logs:
Fri Dec 20 20:46:38 2019 : Error: tls: Failed reading certificate file "/opt/local/etc/raddb/certs/server.pem": error:0906D06C:PEM routines:PEM_read_bio:no start line
Fri Dec 20 20:46:38 2019 : Error: rlm_eap_tls: Failed initializing SSL context
Fri Dec 20 20:46:38 2019 : Error: rlm_eap (EAP): Failed to initialise rlm_eap_tls
Fri Dec 20 20:46:38 2019 : Error: /opt/local/etc/raddb/mods-enabled/eap[14]: Instantiation failed for module “eap"
Clearly, I can disable EAP (as I don’t use it at the moment) and get things working; however, I’m trying to disable as little of the default configs as possible. Is there something different in the code path when debugging is enabled vs not that is making OpenSSL libraries do something weird?
--
Coy Hile
coy.hile(a)coyhile.com
2
7
Hi,
I have a feeling I'm really close to getting this to work. Spent a
lot of time reading old posts and such. If I don't use mschap it works
(first try). If I use mschap it doesn't (Second try).
Fedora 31 server.
[root@ldap raddb]# rpm -qi freeradius
Name : freeradius
Version : 3.0.20
Release : 1.fc31
Architecture: x86_64
Install Date: Thu 19 Dec 2019 02:50:05 PM EST
[root@ldap raddb]# rpm -qi freeipa-server
Name : freeipa-server
Version : 4.8.3
Release : 1.fc31
Architecture: x86_64
Install Date: Thu 19 Dec 2019 01:36:44 AM EST
[root@ldap ~]# radtest wifiuser testing1234 ldap.n-voice.com 1812
testing123
Sent Access-Request Id 163 from 0.0.0.0:40406 to 192.168.2.22:1812
length 78
User-Name = "wifiuser"
User-Password = "testing1234"
NAS-IP-Address = 192.168.2.22
NAS-Port = 1812
Message-Authenticator = 0x00
Cleartext-Password = "testing1234"
Received Access-Accept Id 163 from 192.168.2.22:1812 to
192.168.2.22:40406 length 20
[root@ldap ~]# radtest -t mschap wifiuser testing1234 ldap.n-voice.com
1812 testing123
Sent Access-Request Id 109 from 0.0.0.0:48868 to 192.168.2.22:1812
length 134
User-Name = "wifiuser"
MS-CHAP-Password = "testing1234"
NAS-IP-Address = 192.168.2.22
NAS-Port = 1812
Message-Authenticator = 0x00
Cleartext-Password = "testing1234"
MS-CHAP-Challenge = 0xd1561e8a052a4ff6
MS-CHAP-Response =
0x00010000000000000000000000000000000000000000000000009a3c3b9778a207ed4
64ba7a33a14629b299382f9a534b726
Received Access-Reject Id 109 from 192.168.2.22:1812 to
192.168.2.22:48868 length 20
(0) -: Expected Access-Accept got Access-Reject
[root@ldap ~]#
[root@ldap raddb]# radiusd -X
FreeRADIUS Version 3.0.20
Copyright (C) 1999-2019 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/raddb/dictionary
including configuration file /etc/raddb/radiusd.conf
including configuration file /etc/raddb/proxy.conf
including configuration file /etc/raddb/clients.conf
including files in directory /etc/raddb/mods-enabled/
including configuration file /etc/raddb/mods-enabled/unpack
including configuration file /etc/raddb/mods-enabled/unix
including configuration file /etc/raddb/mods-enabled/chap
including configuration file /etc/raddb/mods-enabled/cache_eap
including configuration file /etc/raddb/mods-enabled/digest
including configuration file /etc/raddb/mods-enabled/always
including configuration file /etc/raddb/mods-enabled/radutmp
including configuration file /etc/raddb/mods-enabled/pap
including configuration file /etc/raddb/mods-enabled/logintime
including configuration file /etc/raddb/mods-enabled/dynamic_clients
including configuration file /etc/raddb/mods-enabled/mschap
including configuration file /etc/raddb/mods-enabled/eap
including configuration file /etc/raddb/mods-enabled/soh
including configuration file /etc/raddb/mods-enabled/ntlm_auth
including configuration file /etc/raddb/mods-enabled/passwd
including configuration file /etc/raddb/mods-enabled/realm
including configuration file /etc/raddb/mods-enabled/attr_filter
including configuration file /etc/raddb/mods-enabled/files
including configuration file /etc/raddb/mods-enabled/ldap
including configuration file /etc/raddb/mods-enabled/linelog
including configuration file /etc/raddb/mods-enabled/sradutmp
including configuration file /etc/raddb/mods-enabled/exec
including configuration file /etc/raddb/mods-enabled/expr
including configuration file /etc/raddb/mods-enabled/detail
including configuration file /etc/raddb/mods-enabled/expiration
including configuration file /etc/raddb/mods-enabled/utf8
including configuration file /etc/raddb/mods-enabled/preprocess
including configuration file /etc/raddb/mods-enabled/echo
including configuration file /etc/raddb/mods-enabled/date
including configuration file /etc/raddb/mods-enabled/replicate
including configuration file /etc/raddb/mods-enabled/detail.log
including files in directory /etc/raddb/policy.d/
including configuration file /etc/raddb/policy.d/accounting
including configuration file /etc/raddb/policy.d/eap
including configuration file /etc/raddb/policy.d/rfc7542
including configuration file /etc/raddb/policy.d/debug
including configuration file /etc/raddb/policy.d/dhcp
including configuration file /etc/raddb/policy.d/cui
including configuration file /etc/raddb/policy.d/canonicalization
including configuration file /etc/raddb/policy.d/operator-name
including configuration file /etc/raddb/policy.d/filter
including configuration file /etc/raddb/policy.d/control
including files in directory /etc/raddb/sites-enabled/
including configuration file /etc/raddb/sites-enabled/default
including configuration file /etc/raddb/sites-enabled/inner-tunnel
main {
security {
user = "radiusd"
group = "radiusd"
allow_core_dumps = no
}
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/radius"
run_dir = "/var/run/radiusd"
}
main {
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/radius"
run_dir = "/var/run/radiusd"
libdir = "/usr/lib64/freeradius"
radacctdir = "/var/log/radius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/var/run/radiusd/radiusd.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
shortname = "auth2"
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client private-network-1 {
ipaddr = 192.168.2.0/24
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
# Creating Auth-Type = mschap
# Creating Auth-Type = digest
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
# Creating Auth-Type = LDAP
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_unpack
# Loading module "unpack" from file /etc/raddb/mods-enabled/unpack
# Loaded module rlm_unix
# Loading module "unix" from file /etc/raddb/mods-enabled/unix
unix {
radwtmp = "/var/log/radius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_chap
# Loading module "chap" from file /etc/raddb/mods-enabled/chap
# Loaded module rlm_cache
# Loading module "cache_eap" from file /etc/raddb/mods-
enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_digest
# Loading module "digest" from file /etc/raddb/mods-enabled/digest
# Loaded module rlm_always
# Loading module "reject" from file /etc/raddb/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file /etc/raddb/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /etc/raddb/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file /etc/raddb/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file /etc/raddb/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file /etc/raddb/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file /etc/raddb/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file /etc/raddb/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file /etc/raddb/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_radutmp
# Loading module "radutmp" from file /etc/raddb/mods-enabled/radutmp
radutmp {
filename = "/var/log/radius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_pap
# Loading module "pap" from file /etc/raddb/mods-enabled/pap
pap {
normalise = yes
}
# Loaded module rlm_logintime
# Loading module "logintime" from file /etc/raddb/mods-
enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file /etc/raddb/mods-
enabled/dynamic_clients
# Loaded module rlm_mschap
# Loading module "mschap" from file /etc/raddb/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
winbind_retry_with_normalised_username = no
}
# Loaded module rlm_eap
# Loading module "eap" from file /etc/raddb/mods-enabled/eap
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_soh
# Loading module "soh" from file /etc/raddb/mods-enabled/soh
soh {
dhcp = yes
}
# Loaded module rlm_exec
# Loading module "ntlm_auth" from file /etc/raddb/mods-
enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key --
domain=MYDOMAIN --username=%{mschap:User-Name} --password=%{User-
Password}"
shell_escape = yes
}
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file /etc/raddb/mods-
enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loaded module rlm_realm
# Loading module "IPASS" from file /etc/raddb/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file /etc/raddb/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "bangpath" from file /etc/raddb/mods-enabled/realm
realm bangpath {
format = "prefix"
delimiter = "!"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file /etc/raddb/mods-
enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file /etc/raddb/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file /etc/raddb/mods-
enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/etc/raddb/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file /etc/raddb/mods-
enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/etc/raddb/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file
/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/etc/raddb/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file
/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/etc/raddb/mods-
config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file
/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/etc/raddb/mods-
config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loaded module rlm_files
# Loading module "files" from file /etc/raddb/mods-enabled/files
files {
filename = "/etc/raddb/mods-config/files/authorize"
acctusersfile = "/etc/raddb/mods-config/files/accounting"
preproxy_usersfile = "/etc/raddb/mods-config/files/pre-proxy"
}
# Loaded module rlm_ldap
# Loading module "ldap" from file /etc/raddb/mods-enabled/ldap
ldap {
server = "localhost"
identity = "cn=Directory Manager"
password = <<< secret >>>
sasl {
}
user_dn = "LDAP-UserDn"
user {
scope = "sub"
access_positive = yes
sasl {
}
}
group {
filter = "(objectClass=posixGroup)"
scope = "sub"
name_attribute = "cn"
membership_attribute = "memberOf"
cacheable_name = no
cacheable_dn = no
allow_dangling_group_ref = no
}
client {
filter = "(objectClass=radiusClient)"
scope = "sub"
base_dn = "cn=users,cn=accounts,dc=n-voice,dc=com"
}
profile {
}
options {
ldap_debug = 40
chase_referrals = yes
rebind = yes
net_timeout = 1
res_timeout = 10
srv_timelimit = 3
idle = 60
probes = 3
interval = 3
}
tls {
start_tls = no
}
}
Creating attribute LDAP-Group
# Loaded module rlm_linelog
# Loading module "linelog" from file /etc/raddb/mods-enabled/linelog
linelog {
filename = "/var/log/radius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file /etc/raddb/mods-
enabled/linelog
linelog log_accounting {
filename = "/var/log/radius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-
unknown}"
}
# Loading module "sradutmp" from file /etc/raddb/mods-
enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/radius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loading module "exec" from file /etc/raddb/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_expr
# Loading module "expr" from file /etc/raddb/mods-enabled/expr
expr {
safe_characters =
"@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_:
/äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loaded module rlm_detail
# Loading module "detail" from file /etc/raddb/mods-enabled/detail
detail {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-
Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_expiration
# Loading module "expiration" from file /etc/raddb/mods-
enabled/expiration
# Loaded module rlm_utf8
# Loading module "utf8" from file /etc/raddb/mods-enabled/utf8
# Loaded module rlm_preprocess
# Loading module "preprocess" from file /etc/raddb/mods-
enabled/preprocess
preprocess {
huntgroups = "/etc/raddb/mods-config/preprocess/huntgroups"
hints = "/etc/raddb/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loading module "echo" from file /etc/raddb/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loaded module rlm_date
# Loading module "date" from file /etc/raddb/mods-enabled/date
date {
format = "%b %e %Y %H:%M:%S %Z"
utc = no
}
# Loading module "wispr2date" from file /etc/raddb/mods-enabled/date
date wispr2date {
format = "%Y-%m-%dT%H:%M:%S"
utc = no
}
# Loaded module rlm_replicate
# Loading module "replicate" from file /etc/raddb/mods-
enabled/replicate
# Loading module "auth_log" from file /etc/raddb/mods-
enabled/detail.log
detail auth_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-
Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file /etc/raddb/mods-
enabled/detail.log
detail reply_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-
Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file /etc/raddb/mods-
enabled/detail.log
detail pre_proxy_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-
Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file /etc/raddb/mods-
enabled/detail.log
detail post_proxy_log {
filename = "/var/log/radius/radacct/%{%{Packet-Src-IP-
Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
instantiate {
}
# Instantiating module "cache_eap" from file /etc/raddb/mods-
enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module
rlm_cache_rbtree) loaded and linked
# Instantiating module "reject" from file /etc/raddb/mods-
enabled/always
# Instantiating module "fail" from file /etc/raddb/mods-
enabled/always
# Instantiating module "ok" from file /etc/raddb/mods-enabled/always
# Instantiating module "handled" from file /etc/raddb/mods-
enabled/always
# Instantiating module "invalid" from file /etc/raddb/mods-
enabled/always
# Instantiating module "userlock" from file /etc/raddb/mods-
enabled/always
# Instantiating module "notfound" from file /etc/raddb/mods-
enabled/always
# Instantiating module "noop" from file /etc/raddb/mods-
enabled/always
# Instantiating module "updated" from file /etc/raddb/mods-
enabled/always
# Instantiating module "pap" from file /etc/raddb/mods-enabled/pap
# Instantiating module "logintime" from file /etc/raddb/mods-
enabled/logintime
# Instantiating module "mschap" from file /etc/raddb/mods-
enabled/mschap
rlm_mschap (mschap): using internal authentication
# Instantiating module "eap" from file /etc/raddb/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/etc/raddb/certs/server.pem"
certificate_file = "/etc/raddb/certs/server.pem"
ca_file = "/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/etc/raddb/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "PROFILE=SYSTEM"
cipher_server_preference = no
ecdh_curve = "prime256v1"
disable_tlsv1 = yes
disable_tlsv1_1 = yes
tls_max_version = "1.2"
tls_min_version = "1.2"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
Please use tls_min_version and tls_max_version instead of disable_tlsv1
Please use tls_min_version and tls_max_version instead of
disable_tlsv1_2
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
# Instantiating module "etc_passwd" from file /etc/raddb/mods-
enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "IPASS" from file /etc/raddb/mods-
enabled/realm
# Instantiating module "suffix" from file /etc/raddb/mods-
enabled/realm
# Instantiating module "bangpath" from file /etc/raddb/mods-
enabled/realm
# Instantiating module "realmpercent" from file /etc/raddb/mods-
enabled/realm
# Instantiating module "ntdomain" from file /etc/raddb/mods-
enabled/realm
# Instantiating module "attr_filter.post-proxy" from file
/etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file
/etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file
/etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-config/attr_filter/access_reject
# Instantiating module "attr_filter.access_challenge" from file
/etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-
config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file
/etc/raddb/mods-enabled/attr_filter
reading pairlist file /etc/raddb/mods-
config/attr_filter/accounting_response
# Instantiating module "files" from file /etc/raddb/mods-
enabled/files
reading pairlist file /etc/raddb/mods-config/files/authorize
reading pairlist file /etc/raddb/mods-config/files/accounting
reading pairlist file /etc/raddb/mods-config/files/pre-proxy
# Instantiating module "ldap" from file /etc/raddb/mods-enabled/ldap
rlm_ldap: libldap vendor: OpenLDAP, version: 20447
accounting {
reference = "%{tolower:type.%{Acct-Status-Type}}"
}
post-auth {
reference = "."
}
rlm_ldap (ldap): Initialising connection pool
pool {
start = 5
min = 3
max = 32
spare = 10
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 30
spread = no
}
rlm_ldap (ldap): Opening additional connection (0), 1 of 32 pending
slots used
rlm_ldap (ldap): Connecting to ldap://localhost:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (1), 1 of 31 pending
slots used
rlm_ldap (ldap): Connecting to ldap://localhost:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (2), 1 of 30 pending
slots used
rlm_ldap (ldap): Connecting to ldap://localhost:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (3), 1 of 29 pending
slots used
rlm_ldap (ldap): Connecting to ldap://localhost:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (4), 1 of 28 pending
slots used
rlm_ldap (ldap): Connecting to ldap://localhost:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
# Instantiating module "linelog" from file /etc/raddb/mods-
enabled/linelog
# Instantiating module "log_accounting" from file /etc/raddb/mods-
enabled/linelog
# Instantiating module "detail" from file /etc/raddb/mods-
enabled/detail
# Instantiating module "expiration" from file /etc/raddb/mods-
enabled/expiration
# Instantiating module "preprocess" from file /etc/raddb/mods-
enabled/preprocess
reading pairlist file /etc/raddb/mods-config/preprocess/huntgroups
reading pairlist file /etc/raddb/mods-config/preprocess/hints
# Instantiating module "auth_log" from file /etc/raddb/mods-
enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in
detail output
# Instantiating module "reply_log" from file /etc/raddb/mods-
enabled/detail.log
# Instantiating module "pre_proxy_log" from file /etc/raddb/mods-
enabled/detail.log
# Instantiating module "post_proxy_log" from file /etc/raddb/mods-
enabled/detail.log
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/raddb/radiusd.conf
} # server
server default { # from file /etc/raddb/sites-enabled/default
# Loading authenticate {...}
# Loading authorize {...}
# Loading preacct {...}
# Loading accounting {...}
# Loading post-proxy {...}
# Loading post-auth {...}
Ignoring "sql" (see raddb/mods-available/README.rst)
} # server default
server inner-tunnel { # from file /etc/raddb/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
# Skipping contents of 'if' as it is always 'false' --
/etc/raddb/sites-enabled/inner-tunnel:336
} # server inner-tunnel
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on auth address 127.0.0.1 port 18120 bound to server inner-
tunnel
Listening on proxy address * port 51206
Listening on proxy address :: port 43983
Ready to process requests
(0) Received Access-Request Id 163 from 192.168.2.22:40406 to
192.168.2.22:1812 length 78
(0) User-Name = "wifiuser"
(0) User-Password = "testing1234"
(0) NAS-IP-Address = 192.168.2.22
(0) NAS-Port = 1812
(0) Message-Authenticator = 0x209a8f3a29c9e325e76f8f9883568b49
(0) # Executing section authorize from file /etc/raddb/sites-
enabled/default
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) [preprocess] = ok
(0) [chap] = noop
(0) [mschap] = noop
(0) [digest] = noop
(0) suffix: Checking for suffix after "@"
(0) suffix: No '@' in User-Name = "wifiuser", looking up realm NULL
(0) suffix: No such realm "NULL"
(0) [suffix] = noop
(0) eap: No EAP-Message, not doing EAP
(0) [eap] = noop
(0) [files] = noop
rlm_ldap (ldap): Reserved connection (0)
(0) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(0) ldap: --> (uid=wifiuser)
(0) ldap: Performing search in "cn=users,cn=accounts,dc=n-voice,dc=com"
with filter "(uid=wifiuser)", scope "sub"
(0) ldap: Waiting for search result...
(0) ldap: User object found at DN
"uid=wifiuser,cn=users,cn=accounts,dc=n-voice,dc=com"
(0) ldap: Processing user attributes
(0) ldap: control:Password-With-Header +=
'{PBKDF2_SHA256}AAAIAEhOrJwqZkQ2Xq6WP4lVdbpoUu6uUvswCNAcoxTx1yHPt79yzSK
ZC1pPccla4Pmnkcj1HPeKF6zuWC0srkIND9fiJuG6Q3Npsd8la6B6smIqgt4mI0WhYtY2Us
dGd2uloy15ST+tK+WO4pZfOJbZ4zI82qbd3zgzeD1QSnT/F0oxLZ4yUcr6aYbSi1/I4KCYP
6tJFb9Cnq8eXXbdp6JCpNw1VCn+a9TYrjCPkP+kwglCX28Ovq9zt8VX5K/19PysnChU9vaX
ZWwbfiTk0rbissyoBcYIzruO73f18zsyWUYiXHpq0GyybK0d8X4ddC5DxRTDilzZ3GuCBUm
uFNaviktPV66jfoMclpPI1LFRZJjND5T6/xSTTKIyO7GDrERM2HdX1oVElLKzdBCbu0IfhS
kHw6dcYaJ2cx5DQM/tdv5u'
rlm_ldap (ldap): Released connection (0)
Need 5 more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (5), 1 of 27 pending
slots used
rlm_ldap (ldap): Connecting to ldap://localhost:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
(0) [ldap] = updated
(0) [expiration] = noop
(0) [logintime] = noop
(0) pap: Unknown header {PBKDF2_SHA256} in Password-With-Header, re-
writing to Cleartext-Password
(0) pap: Removing &control:Password-With-Header
(0) [pap] = updated
(0) if (User-Password) {
(0) if (User-Password) -> TRUE
(0) if (User-Password) {
(0) update control {
(0) Auth-Type := LDAP
(0) } # update control = noop
(0) } # if (User-Password) = noop
(0) } # authorize = updated
(0) Found Auth-Type = LDAP
(0) # Executing group from file /etc/raddb/sites-enabled/default
(0) Auth-Type LDAP {
rlm_ldap (ldap): Reserved connection (1)
(0) ldap: Login attempt by "wifiuser"
(0) ldap: Using user DN from request
"uid=wifiuser,cn=users,cn=accounts,dc=n-voice,dc=com"
(0) ldap: Waiting for bind result...
(0) ldap: Bind successful
(0) ldap: Bind as user "uid=wifiuser,cn=users,cn=accounts,dc=n-
voice,dc=com" was successful
rlm_ldap (ldap): Released connection (1)
(0) [ldap] = ok
(0) } # Auth-Type LDAP = ok
(0) # Executing section post-auth from file /etc/raddb/sites-
enabled/default
(0) post-auth {
(0) if (session-state:User-Name && reply:User-Name && request:User-
Name && (reply:User-Name == request:User-Name)) {
(0) if (session-state:User-Name && reply:User-Name && request:User-
Name && (reply:User-Name == request:User-Name)) -> FALSE
(0) update {
(0) No attributes updated for RHS &session-state:
(0) } # update = noop
(0) ldap: EXPAND .
(0) ldap: --> .
(0) ldap: EXPAND Authenticated at %S
(0) ldap: --> Authenticated at 2019-12-19 19:24:44
rlm_ldap (ldap): Reserved connection (2)
(0) ldap: Using user DN from request
"uid=wifiuser,cn=users,cn=accounts,dc=n-voice,dc=com"
(0) ldap: Modifying object with DN
"uid=wifiuser,cn=users,cn=accounts,dc=n-voice,dc=com"
(0) ldap: Waiting for modify result...
rlm_ldap (ldap): Released connection (2)
(0) [ldap] = ok
(0) [exec] = noop
(0) policy remove_reply_message_if_eap {
(0) if (&reply:EAP-Message && &reply:Reply-Message) {
(0) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(0) else {
(0) [noop] = noop
(0) } # else = noop
(0) } # policy remove_reply_message_if_eap = noop
(0) } # post-auth = ok
(0) Sent Access-Accept Id 163 from 192.168.2.22:1812 to
192.168.2.22:40406 length 0
(0) Finished request
Waking up in 4.9 seconds.
(1) Received Access-Request Id 109 from 192.168.2.22:48868 to
192.168.2.22:1812 length 134
(1) User-Name = "wifiuser"
(1) NAS-IP-Address = 192.168.2.22
(1) NAS-Port = 1812
(1) Message-Authenticator = 0xdb1fd8ed25ede2827388f5af6d9302c3
(1) MS-CHAP-Challenge = 0xd1561e8a052a4ff6
(1) MS-CHAP-Response =
0x00010000000000000000000000000000000000000000000000009a3c3b9778a207ed4
64ba7a33a14629b299382f9a534b726
(1) # Executing section authorize from file /etc/raddb/sites-
enabled/default
(1) authorize {
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~
/(a)(.+)\.(.+)$/)) -> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # if (&User-Name) = notfound
(1) } # policy filter_username = notfound
(1) [preprocess] = ok
(1) [chap] = noop
(1) mschap: Found MS-CHAP attributes. Setting 'Auth-Type = mschap'
(1) [mschap] = ok
(1) [digest] = noop
(1) suffix: Checking for suffix after "@"
(1) suffix: No '@' in User-Name = "wifiuser", looking up realm NULL
(1) suffix: No such realm "NULL"
(1) [suffix] = noop
(1) eap: No EAP-Message, not doing EAP
(1) [eap] = noop
(1) [files] = noop
rlm_ldap (ldap): Reserved connection (3)
(1) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(1) ldap: --> (uid=wifiuser)
(1) ldap: Performing search in "cn=users,cn=accounts,dc=n-voice,dc=com"
with filter "(uid=wifiuser)", scope "sub"
(1) ldap: Waiting for search result...
(1) ldap: User object found at DN
"uid=wifiuser,cn=users,cn=accounts,dc=n-voice,dc=com"
(1) ldap: Processing user attributes
(1) ldap: control:Password-With-Header +=
'{PBKDF2_SHA256}AAAIAEhOrJwqZkQ2Xq6WP4lVdbpoUu6uUvswCNAcoxTx1yHPt79yzSK
ZC1pPccla4Pmnkcj1HPeKF6zuWC0srkIND9fiJuG6Q3Npsd8la6B6smIqgt4mI0WhYtY2Us
dGd2uloy15ST+tK+WO4pZfOJbZ4zI82qbd3zgzeD1QSnT/F0oxLZ4yUcr6aYbSi1/I4KCYP
6tJFb9Cnq8eXXbdp6JCpNw1VCn+a9TYrjCPkP+kwglCX28Ovq9zt8VX5K/19PysnChU9vaX
ZWwbfiTk0rbissyoBcYIzruO73f18zsyWUYiXHpq0GyybK0d8X4ddC5DxRTDilzZ3GuCBUm
uFNaviktPV66jfoMclpPI1LFRZJjND5T6/xSTTKIyO7GDrERM2HdX1oVElLKzdBCbu0IfhS
kHw6dcYaJ2cx5DQM/tdv5u'
rlm_ldap (ldap): Released connection (3)
Need 4 more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (6), 1 of 26 pending
slots used
rlm_ldap (ldap): Connecting to ldap://localhost:389
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
(1) [ldap] = updated
(1) [expiration] = noop
(1) [logintime] = noop
(1) pap: Unknown header {PBKDF2_SHA256} in Password-With-Header, re-
writing to Cleartext-Password
(1) pap: Removing &control:Password-With-Header
(1) pap: WARNING: Auth-Type already set. Not setting to PAP
(1) [pap] = noop
(1) if (User-Password) {
(1) if (User-Password) -> FALSE
(1) } # authorize = updated
(1) Found Auth-Type = mschap
(1) # Executing group from file /etc/raddb/sites-enabled/default
(1) authenticate {
(1) mschap: Found Cleartext-Password, hashing to create NT-Password
(1) mschap: ERROR: Failed generating NT-Password
(1) [mschap] = fail
(1) } # authenticate = fail
(1) Failed to authenticate the user
(1) Using Post-Auth-Type Reject
(1) # Executing group from file /etc/raddb/sites-enabled/default
(1) Post-Auth-Type REJECT {
(1) attr_filter.access_reject: EXPAND %{User-Name}
(1) attr_filter.access_reject: --> wifiuser
(1) attr_filter.access_reject: Matched entry DEFAULT at line 11
(1) [attr_filter.access_reject] = updated
(1) [eap] = noop
(1) policy remove_reply_message_if_eap {
(1) if (&reply:EAP-Message && &reply:Reply-Message) {
(1) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(1) else {
(1) [noop] = noop
(1) } # else = noop
(1) } # policy remove_reply_message_if_eap = noop
(1) } # Post-Auth-Type REJECT = updated
(1) Delaying response for 1.000000 seconds
Waking up in 0.2 seconds.
Waking up in 0.7 seconds.
(1) Sending delayed response
(1) Sent Access-Reject Id 109 from 192.168.2.22:1812 to
192.168.2.22:48868 length 20
Waking up in 1.6 seconds.
(0) Cleaning up request packet ID 163 with timestamp +5
Waking up in 2.3 seconds.
Please let me know if I can provide anything else that would be useful.
If there is a guide on how to get dd_wrt, freeradius and freeipa
working I'd like to see that. I've read a bunch of them so far. This is
the closest I can get.
python3-samba-4.11.3-0.fc31.x86_64 Thu 19 Dec 2019 05:50:53
PM EST
python3-libsss_nss_idmap-2.2.2-3.fc31.x86_64 Thu 19 Dec 2019 05:50:53
PM EST
freeipa-server-trust-ad-4.8.3-1.fc31.x86_64 Thu 19 Dec 2019 05:50:53
PM EST
python3-tevent-0.10.1-1.fc31.x86_64 Thu 19 Dec 2019 05:50:52
PM EST
python3-tdb-1.4.2-1.fc31.x86_64 Thu 19 Dec 2019 05:50:52
PM EST
python3-talloc-2.3.0-1.fc31.x86_64 Thu 19 Dec 2019 05:50:52
PM EST
python3-ldb-2.0.7-1.fc31.x86_64 Thu 19 Dec 2019 05:50:52
PM EST
libtevent-devel-0.10.1-1.fc31.x86_64 Thu 19 Dec 2019 05:50:52
PM EST
libtdb-devel-1.4.2-1.fc31.x86_64 Thu 19 Dec 2019 05:50:52
PM EST
libtalloc-devel-2.3.0-1.fc31.x86_64 Thu 19 Dec 2019 05:50:52
PM EST
libldb-devel-2.0.7-1.fc31.x86_64 Thu 19 Dec 2019 05:50:52
PM EST
samba-4.11.3-0.fc31.x86_64 Thu 19 Dec 2019 04:34:11
PM EST
freeradius-utils-3.0.20-1.fc31.x86_64 Thu 19 Dec 2019 02:50:05
PM EST
freeradius-ldap-3.0.20-1.fc31.x86_64 Thu 19 Dec 2019 02:50:05
PM EST
freeradius-3.0.20-1.fc31.x86_64 Thu 19 Dec 2019 02:50:05
PM EST
perl-Math-Complex-1.59-449.fc31.noarch Thu 19 Dec 2019 02:50:02
PM EST
perl-Math-BigInt-1.9998.16-439.fc31.noarch Thu 19 Dec 2019 02:50:02
PM EST
perl-DBI-1.642-5.fc31.x86_64 Thu 19 Dec 2019 02:50:02
PM EST
make-4.2.1-15.fc31.x86_64 Thu 19 Dec 2019 02:50:02
PM EST
libyubikey-1.13-12.fc31.x86_64 Thu 19 Dec 2019 02:50:02
PM EST
guile22-2.2.6-2.fc31.x86_64 Thu 19 Dec 2019 02:50:01
PM EST
ykclient-2.15-9.fc31.x86_64 Thu 19 Dec 2019 02:49:59
PM EST
perl-Time-HiRes-1.9760-439.fc31.x86_64 Thu 19 Dec 2019 02:49:59
PM EST
libatomic_ops-7.6.10-2.fc31.x86_64 Thu 19 Dec 2019 02:49:59
PM EST
gc-7.6.4-6.fc31.x86_64 Thu 19 Dec 2019 02:49:59
PM EST
freeipa-server-dns-4.8.3-1.fc31.noarch Thu 19 Dec 2019 01:57:57
PM EST
opendnssec-1.4.14-5.fc31.x86_64 Thu 19 Dec 2019 01:57:56
PM EST
opencryptoki-libs-3.11.0-4.fc31.x86_64 Thu 19 Dec 2019 01:57:55
PM EST
opencryptoki-icsftok-3.11.0-4.fc31.x86_64 Thu 19 Dec 2019 01:57:55
PM EST
opencryptoki-3.11.0-4.fc31.x86_64 Thu 19 Dec 2019 01:57:55
PM EST
ldns-1.7.0-26.fc31.x86_64 Thu 19 Dec 2019 01:57:55
PM EST
libitm-9.2.1-1.fc31.x86_64 Thu 19 Dec 2019 01:57:54
PM EST
bind-dyndb-ldap-11.2-2.fc31.x86_64 Thu 19 Dec 2019 01:36:45
AM EST
freeipa-server-4.8.3-1.fc31.x86_64 Thu 19 Dec 2019 01:36:44
AM EST
Thanks,
Rob
2
1
Hi all,
I'm stuck on an issue with FreeRADIUS configuration and after a few days of reading and searching I'm out of ideas. Hopefully it's just a simple mistake which someone can pick up and help me out with.
I've been using FreeRADIUS to handle EAP authentication (both EAP-TLS and EAP-PEAP-MSCHAPv2) and dynamic VLAN assignments for wireless networks and it's been working flawlessly.
Recently I've had to look at making some configuration changes to suit a more complex situation and this is where I'm getting stuck and going around in circles.
Previously I have been defining the dynamic VLAN on a per-user basis within the "users" configuration file as such:
testuser NT-Password := "XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
Tunnel-Type = 13,
Tunnel-Medium-Type = 6,
Tunnel-Private-Group-Id = "125" # CLIENT-VPN
This has been working fine and the dynamic VLAN gets assigned as expected.
I need to change this now so that the "users" file only contains the username and password hash and the dynamic VLAN assignment actually happens using unlang logic in the post-auth section of the "/etc/freeradius/3.0/sites-enabled/default" file.
After a bit of reading, it appears that I can create an attribute in the users file which get's added into a control list which I can reference in the post-auth phase. So I try doing that by first defining the attribute in the "dictionary" file:
#tail -n 2 /etc/freeradius/3.0/dictionary
ATTRIBUTE VLAN-Name 3000 string
And then I add the attribute (and the desired value) in the users file:
testuser NT-Password := "XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX", VLAN-Name := "CLIENT-VPN"
I then create the relevant unlang logic. What I'm trying to do with this logic is determine the NAS-IP (WAP) and assigned VLAN-Name for the user. Based on this, I'll send back the approrpiate VLAN-ID.
# cat /etc/freeradius/3.0/sites-enabled/default
...
post-auth {
debug_all
...
if ((&request:NAS-IP-Address == 192.168.40.21) && (&control:VLAN-Name == "CLIENT-VPN")) {
update reply {
&Tunnel-Type := VLAN
&Tunnel-Medium-Type := IEEE-802
&Tunnel-Private-Group-Id := "225"
}
}
The unlang logic works fine just against the NAS-IP-Address however fails when used with the VLAN-Name custom attribute.
Looking through the debugs, I find two areas indicating a problem. The most obvious is the ERROR below indicating a failure to get my attribute:
(10) &reply::User-Name += &session-state:User-Name[*] -> 'testuser'
(10) } # update = noop
(10) if ((&request:NAS-IP-Address == 192.168.40.21) && (&control:VLAN-Name == "CLIENT-VPN")) {
(10) ERROR: Failed retrieving values required to evaluate condition
(10) [exec] = noop
(10) policy remove_reply_message_if_eap {
(10) if (&reply:EAP-Message && &reply:Reply-Message) {
(10) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(10) else {
(10) [noop] = noop
(10) } # else = noop
(10) } # policy remove_reply_message_if_eap = noop
(10) } # post-auth = noop
Enabling the "debug_all" option in the post-auth section (to dump all attributes) also reveals that my control list attribute "&control:VLAN-Name" doesn't appear to be available for use. The only control list attribute is "&control:Auth-Type".
(10) eap: Freeing handler
(10) [eap] = ok
(10) } # authenticate = ok
(10) # Executing section post-auth from file /etc/freeradius/3.0/sites-enabled/default
(10) post-auth {
(10) policy debug_all {
(10) policy debug_control {
(10) if ("%{debug_attr:control:}" == '') {
(10) Attributes matching "control:"
(10) &control:Auth-Type = eap
(10) EXPAND %{debug_attr:control:}
(10) -->
(10) if ("%{debug_attr:control:}" == '') -> TRUE
(10) if ("%{debug_attr:control:}" == '') {
(10) [noop] = noop
(10) } # if ("%{debug_attr:control:}" == '') = noop
(10) } # policy debug_control = noop
(10) policy debug_request {
(10) if ("%{debug_attr:request:}" == '') {
Appreciate any help you can provide.
Thank you.
P.S. I've included the full debug output here as requested in the mailing list rules/FAQ:
freeradius -X
FreeRADIUS Version 3.0.12
Copyright (C) 1999-2016 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/freeradius/3.0/dictionary
including configuration file /etc/freeradius/3.0/radiusd.conf
including configuration file /etc/freeradius/3.0/proxy.conf
including configuration file /etc/freeradius/3.0/clients.conf
including files in directory /etc/freeradius/3.0/mods-enabled/
including configuration file /etc/freeradius/3.0/mods-enabled/always
including configuration file /etc/freeradius/3.0/mods-enabled/unpack
including configuration file /etc/freeradius/3.0/mods-enabled/ntlm_auth
including configuration file /etc/freeradius/3.0/mods-enabled/attr_filter
including configuration file /etc/freeradius/3.0/mods-enabled/realm
including configuration file /etc/freeradius/3.0/mods-enabled/detail
including configuration file /etc/freeradius/3.0/mods-enabled/utf8
including configuration file /etc/freeradius/3.0/mods-enabled/detail.log
including configuration file /etc/freeradius/3.0/mods-enabled/chap
including configuration file /etc/freeradius/3.0/mods-enabled/expiration
including configuration file /etc/freeradius/3.0/mods-enabled/sradutmp
including configuration file /etc/freeradius/3.0/mods-enabled/dynamic_clients
including configuration file /etc/freeradius/3.0/mods-enabled/expr
including configuration file /etc/freeradius/3.0/mods-enabled/echo
including configuration file /etc/freeradius/3.0/mods-enabled/linelog
including configuration file /etc/freeradius/3.0/mods-enabled/preprocess
including configuration file /etc/freeradius/3.0/mods-enabled/eap
including configuration file /etc/freeradius/3.0/mods-enabled/mschap
including configuration file /etc/freeradius/3.0/mods-enabled/cache_eap
including configuration file /etc/freeradius/3.0/mods-enabled/replicate
including configuration file /etc/freeradius/3.0/mods-enabled/exec
including configuration file /etc/freeradius/3.0/mods-enabled/digest
including configuration file /etc/freeradius/3.0/mods-enabled/files
including configuration file /etc/freeradius/3.0/mods-enabled/soh
including configuration file /etc/freeradius/3.0/mods-enabled/pap
including configuration file /etc/freeradius/3.0/mods-enabled/unix
including configuration file /etc/freeradius/3.0/mods-enabled/radutmp
including configuration file /etc/freeradius/3.0/mods-enabled/logintime
including configuration file /etc/freeradius/3.0/mods-enabled/passwd
including files in directory /etc/freeradius/3.0/policy.d/
including configuration file /etc/freeradius/3.0/policy.d/operator-name
including configuration file /etc/freeradius/3.0/policy.d/filter
including configuration file /etc/freeradius/3.0/policy.d/canonicalization
including configuration file /etc/freeradius/3.0/policy.d/moonshot-targeted-ids
including configuration file /etc/freeradius/3.0/policy.d/control
including configuration file /etc/freeradius/3.0/policy.d/accounting
including configuration file /etc/freeradius/3.0/policy.d/dhcp
including configuration file /etc/freeradius/3.0/policy.d/debug
including configuration file /etc/freeradius/3.0/policy.d/cui
including configuration file /etc/freeradius/3.0/policy.d/abfab-tr
including configuration file /etc/freeradius/3.0/policy.d/eap
including files in directory /etc/freeradius/3.0/sites-enabled/
including configuration file /etc/freeradius/3.0/sites-enabled/default
including configuration file /etc/freeradius/3.0/sites-enabled/inner-tunnel
main {
security {
user = "freerad"
group = "freerad"
allow_core_dumps = no
}
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
}
main {
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
libdir = "/usr/lib/freeradius"
radacctdir = "/var/log/freeradius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/var/run/freeradius/freeradius.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = yes
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client GC-WLAN-UAP1 {
ipaddr = 192.168.8.21
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client BNE-WLAN-UAP1 {
ipaddr = 192.168.40.21
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
# Creating Auth-Type = mschap
# Creating Auth-Type = digest
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_always
# Loading module "reject" from file /etc/freeradius/3.0/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file /etc/freeradius/3.0/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /etc/freeradius/3.0/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file /etc/freeradius/3.0/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file /etc/freeradius/3.0/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file /etc/freeradius/3.0/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file /etc/freeradius/3.0/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file /etc/freeradius/3.0/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file /etc/freeradius/3.0/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_unpack
# Loading module "unpack" from file /etc/freeradius/3.0/mods-enabled/unpack
# Loaded module rlm_exec
# Loading module "ntlm_auth" from file /etc/freeradius/3.0/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN --username=%{mschap:User-Name} --password=%{User-Password}"
shell_escape = yes
}
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loaded module rlm_realm
# Loading module "IPASS" from file /etc/freeradius/3.0/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file /etc/freeradius/3.0/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file /etc/freeradius/3.0/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file /etc/freeradius/3.0/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loaded module rlm_detail
# Loading module "detail" from file /etc/freeradius/3.0/mods-enabled/detail
detail {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_utf8
# Loading module "utf8" from file /etc/freeradius/3.0/mods-enabled/utf8
# Loading module "auth_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail auth_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail reply_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail pre_proxy_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail post_proxy_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_chap
# Loading module "chap" from file /etc/freeradius/3.0/mods-enabled/chap
# Loaded module rlm_expiration
# Loading module "expiration" from file /etc/freeradius/3.0/mods-enabled/expiration
# Loaded module rlm_radutmp
# Loading module "sradutmp" from file /etc/freeradius/3.0/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/freeradius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file /etc/freeradius/3.0/mods-enabled/dynamic_clients
# Loaded module rlm_expr
# Loading module "expr" from file /etc/freeradius/3.0/mods-enabled/expr
expr {
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loading module "echo" from file /etc/freeradius/3.0/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loaded module rlm_linelog
# Loading module "linelog" from file /etc/freeradius/3.0/mods-enabled/linelog
linelog {
filename = "/var/log/freeradius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file /etc/freeradius/3.0/mods-enabled/linelog
linelog log_accounting {
filename = "/var/log/freeradius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_preprocess
# Loading module "preprocess" from file /etc/freeradius/3.0/mods-enabled/preprocess
preprocess {
huntgroups = "/etc/freeradius/3.0/mods-config/preprocess/huntgroups"
hints = "/etc/freeradius/3.0/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loaded module rlm_eap
# Loading module "eap" from file /etc/freeradius/3.0/mods-enabled/eap
eap {
default_eap_type = "peap"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_mschap
# Loading module "mschap" from file /etc/freeradius/3.0/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
}
# Loaded module rlm_cache
# Loading module "cache_eap" from file /etc/freeradius/3.0/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_replicate
# Loading module "replicate" from file /etc/freeradius/3.0/mods-enabled/replicate
# Loading module "exec" from file /etc/freeradius/3.0/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_digest
# Loading module "digest" from file /etc/freeradius/3.0/mods-enabled/digest
# Loaded module rlm_files
# Loading module "files" from file /etc/freeradius/3.0/mods-enabled/files
files {
filename = "/etc/freeradius/3.0/mods-config/files/authorize"
acctusersfile = "/etc/freeradius/3.0/mods-config/files/accounting"
preproxy_usersfile = "/etc/freeradius/3.0/mods-config/files/pre-proxy"
}
# Loaded module rlm_soh
# Loading module "soh" from file /etc/freeradius/3.0/mods-enabled/soh
soh {
dhcp = yes
}
# Loaded module rlm_pap
# Loading module "pap" from file /etc/freeradius/3.0/mods-enabled/pap
pap {
normalise = yes
}
# Loaded module rlm_unix
# Loading module "unix" from file /etc/freeradius/3.0/mods-enabled/unix
unix {
radwtmp = "/var/log/freeradius/radwtmp"
}
Creating attribute Unix-Group
# Loading module "radutmp" from file /etc/freeradius/3.0/mods-enabled/radutmp
radutmp {
filename = "/var/log/freeradius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_logintime
# Loading module "logintime" from file /etc/freeradius/3.0/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file /etc/freeradius/3.0/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
instantiate {
}
# Instantiating module "reject" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "fail" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "ok" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "handled" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "invalid" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "userlock" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "notfound" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "noop" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "updated" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "attr_filter.post-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/access_reject
[/etc/freeradius/3.0/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay" found in filter list for realm "DEFAULT".
[/etc/freeradius/3.0/mods-config/attr_filter/access_reject]:11 Check item "FreeRADIUS-Response-Delay-USec" found in filter list for realm "DEFAULT".
# Instantiating module "attr_filter.access_challenge" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/accounting_response
# Instantiating module "IPASS" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "suffix" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "realmpercent" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "ntdomain" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "detail" from file /etc/freeradius/3.0/mods-enabled/detail
# Instantiating module "auth_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output
# Instantiating module "reply_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "pre_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "expiration" from file /etc/freeradius/3.0/mods-enabled/expiration
# Instantiating module "linelog" from file /etc/freeradius/3.0/mods-enabled/linelog
# Instantiating module "log_accounting" from file /etc/freeradius/3.0/mods-enabled/linelog
# Instantiating module "preprocess" from file /etc/freeradius/3.0/mods-enabled/preprocess
reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/huntgroups
reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/hints
# Instantiating module "eap" from file /etc/freeradius/3.0/mods-enabled/eap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/freeradius/3.0/certs"
pem_file_type = yes
private_key_file = "/etc/ssl/private/XXXXXX.key.pem"
certificate_file = "/etc/ssl/certs/XXXXXX.cert.pem"
ca_file = "/etc/ssl/certs/ca-certificates.crt"
dh_file = "/etc/freeradius/3.0/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "HIGH"
ecdh_curve = "prime256v1"
cache {
enable = yes
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
# Instantiating module "mschap" from file /etc/freeradius/3.0/mods-enabled/mschap
rlm_mschap (mschap): using internal authentication
# Instantiating module "cache_eap" from file /etc/freeradius/3.0/mods-enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module rlm_cache_rbtree) loaded and linked
# Instantiating module "files" from file /etc/freeradius/3.0/mods-enabled/files
reading pairlist file /etc/freeradius/3.0/mods-config/files/authorize
reading pairlist file /etc/freeradius/3.0/mods-config/files/accounting
reading pairlist file /etc/freeradius/3.0/mods-config/files/pre-proxy
# Instantiating module "pap" from file /etc/freeradius/3.0/mods-enabled/pap
# Instantiating module "logintime" from file /etc/freeradius/3.0/mods-enabled/logintime
# Instantiating module "etc_passwd" from file /etc/freeradius/3.0/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/freeradius/3.0/radiusd.conf
} # server
server default { # from file /etc/freeradius/3.0/sites-enabled/default
# Loading authenticate {...}
# Loading authorize {...}
Ignoring "sql" (see raddb/mods-available/README.rst)
Ignoring "ldap" (see raddb/mods-available/README.rst)
# Loading preacct {...}
# Loading accounting {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server default
server inner-tunnel { # from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server inner-tunnel
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Listening on proxy address * port 53109
Listening on proxy address :: port 50014
Ready to process requests
(0) Received Access-Request Id 196 from 192.168.40.21:46541 to 192.168.8.35:1812 length 163
(0) User-Name = "anonymous"
(0) NAS-Identifier = "802aa8d3d475"
(0) NAS-Port = 0
(0) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(0) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(0) Framed-MTU = 1400
(0) NAS-Port-Type = Wireless-802.11
(0) Connect-Info = "CONNECT 0Mbps 802.11b"
(0) EAP-Message = 0x0295000e01616e6f6e796d6f7573
(0) Message-Authenticator = 0x39e811b49e0603269b2b13734db8c4d3
(0) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) [preprocess] = ok
(0) [chap] = noop
(0) [mschap] = noop
(0) [digest] = noop
(0) suffix: Checking for suffix after "@"
(0) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(0) suffix: No such realm "NULL"
(0) [suffix] = noop
(0) eap: Peer sent EAP Response (code 2) ID 149 length 14
(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(0) [eap] = ok
(0) } # authorize = ok
(0) Found Auth-Type = eap
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(0) authenticate {
(0) eap: Peer sent packet with method EAP Identity (1)
(0) eap: Calling submodule eap_peap to process data
(0) eap_peap: Initiating new EAP-TLS session
(0) eap_peap: [eaptls start] = request
(0) eap: Sending EAP Request (code 1) ID 150 length 6
(0) eap: EAP session adding &reply:State = 0xdcff01a1dc691842
(0) [eap] = handled
(0) } # authenticate = handled
(0) Using Post-Auth-Type Challenge
(0) Post-Auth-Type sub-section not found. Ignoring.
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(0) Sent Access-Challenge Id 196 from 192.168.8.35:1812 to 192.168.40.21:46541 length 0
(0) EAP-Message = 0x019600061920
(0) Message-Authenticator = 0x00000000000000000000000000000000
(0) State = 0xdcff01a1dc6918422343d3b59bbb1704
(0) Finished request
Waking up in 4.9 seconds.
(1) Received Access-Request Id 197 from 192.168.40.21:46541 to 192.168.8.35:1812 length 320
(1) User-Name = "anonymous"
(1) NAS-Identifier = "802aa8d3d475"
(1) NAS-Port = 0
(1) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(1) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(1) Framed-MTU = 1400
(1) NAS-Port-Type = Wireless-802.11
(1) Connect-Info = "CONNECT 0Mbps 802.11b"
(1) EAP-Message = 0x0296009919800000008f160301008a010000860303ec979b7b6f81e04f09f5d9b8d7ed3378828f001f372eb2fbf8b912717f1d834500002acca9cca8c02bc02fc02cc030c009c023c013c027c00ac024c014c028009c009d002f003c0035003d000a01000033ff0100010000170000000d001400120403
(1) State = 0xdcff01a1dc6918422343d3b59bbb1704
(1) Message-Authenticator = 0x76ea1adde71a5cdad501da5ad77f89a2
(1) session-state: No cached attributes
(1) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(1) authorize {
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # if (&User-Name) = notfound
(1) } # policy filter_username = notfound
(1) [preprocess] = ok
(1) [chap] = noop
(1) [mschap] = noop
(1) [digest] = noop
(1) suffix: Checking for suffix after "@"
(1) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(1) suffix: No such realm "NULL"
(1) [suffix] = noop
(1) eap: Peer sent EAP Response (code 2) ID 150 length 153
(1) eap: Continuing tunnel setup
(1) [eap] = ok
(1) } # authorize = ok
(1) Found Auth-Type = eap
(1) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(1) authenticate {
(1) eap: Expiring EAP session with state 0xdcff01a1dc691842
(1) eap: Finished EAP session with state 0xdcff01a1dc691842
(1) eap: Previous EAP request found for state 0xdcff01a1dc691842, released from the list
(1) eap: Peer sent packet with method EAP PEAP (25)
(1) eap: Calling submodule eap_peap to process data
(1) eap_peap: Continuing EAP-TLS
(1) eap_peap: Peer indicated complete TLS record size will be 143 bytes
(1) eap_peap: Got complete TLS record (143 bytes)
(1) eap_peap: [eaptls verify] = length included
(1) eap_peap: (other): before SSL initialization
(1) eap_peap: TLS_accept: before SSL initialization
(1) eap_peap: TLS_accept: before SSL initialization
(1) eap_peap: <<< recv TLS 1.2 [length 008a]
(1) eap_peap: TLS_accept: SSLv3/TLS read client hello
(1) eap_peap: >>> send TLS 1.2 [length 003d]
(1) eap_peap: TLS_accept: SSLv3/TLS write server hello
(1) eap_peap: >>> send TLS 1.2 [length 0c06]
(1) eap_peap: TLS_accept: SSLv3/TLS write certificate
(1) eap_peap: >>> send TLS 1.2 [length 024d]
(1) eap_peap: TLS_accept: SSLv3/TLS write key exchange
(1) eap_peap: >>> send TLS 1.2 [length 0004]
(1) eap_peap: TLS_accept: SSLv3/TLS write server done
(1) eap_peap: TLS_accept: Need to read more data: SSLv3/TLS write server done
(1) eap_peap: In SSL Handshake Phase
(1) eap_peap: In SSL Accept mode
(1) eap_peap: [eaptls process] = handled
(1) eap: Sending EAP Request (code 1) ID 151 length 1014
(1) eap: EAP session adding &reply:State = 0xdcff01a1dd681842
(1) [eap] = handled
(1) } # authenticate = handled
(1) Using Post-Auth-Type Challenge
(1) Post-Auth-Type sub-section not found. Ignoring.
(1) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(1) Sent Access-Challenge Id 197 from 192.168.8.35:1812 to 192.168.40.21:46541 length 0
(1) EAP-Message = 0x019703f619c000000ea8160303003d020000390303cb0dbbaebc37affb9ea861ad9cdd5229b60032c5c5e051bca74530ed8fa78d2e00cca8000011ff01000100000b000403000102001700001603030c060b000c02000bff00065f3082065b30820443a0030201020202100b300d06092a864886f70d01
(1) Message-Authenticator = 0x00000000000000000000000000000000
(1) State = 0xdcff01a1dd6818422343d3b59bbb1704
(1) Finished request
Waking up in 4.9 seconds.
(2) Received Access-Request Id 198 from 192.168.40.21:46541 to 192.168.8.35:1812 length 173
(2) User-Name = "anonymous"
(2) NAS-Identifier = "802aa8d3d475"
(2) NAS-Port = 0
(2) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(2) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(2) Framed-MTU = 1400
(2) NAS-Port-Type = Wireless-802.11
(2) Connect-Info = "CONNECT 0Mbps 802.11b"
(2) EAP-Message = 0x029700061900
(2) State = 0xdcff01a1dd6818422343d3b59bbb1704
(2) Message-Authenticator = 0xe6bd97dd94d0e74610db361cdabe26f1
(2) session-state: No cached attributes
(2) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(2) authorize {
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) } # if (&User-Name) = notfound
(2) } # policy filter_username = notfound
(2) [preprocess] = ok
(2) [chap] = noop
(2) [mschap] = noop
(2) [digest] = noop
(2) suffix: Checking for suffix after "@"
(2) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(2) suffix: No such realm "NULL"
(2) [suffix] = noop
(2) eap: Peer sent EAP Response (code 2) ID 151 length 6
(2) eap: Continuing tunnel setup
(2) [eap] = ok
(2) } # authorize = ok
(2) Found Auth-Type = eap
(2) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(2) authenticate {
(2) eap: Expiring EAP session with state 0xdcff01a1dd681842
(2) eap: Finished EAP session with state 0xdcff01a1dd681842
(2) eap: Previous EAP request found for state 0xdcff01a1dd681842, released from the list
(2) eap: Peer sent packet with method EAP PEAP (25)
(2) eap: Calling submodule eap_peap to process data
(2) eap_peap: Continuing EAP-TLS
(2) eap_peap: Peer ACKed our handshake fragment
(2) eap_peap: [eaptls verify] = request
(2) eap_peap: [eaptls process] = handled
(2) eap: Sending EAP Request (code 1) ID 152 length 1010
(2) eap: EAP session adding &reply:State = 0xdcff01a1de671842
(2) [eap] = handled
(2) } # authenticate = handled
(2) Using Post-Auth-Type Challenge
(2) Post-Auth-Type sub-section not found. Ignoring.
(2) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(2) Sent Access-Challenge Id 198 from 192.168.8.35:1812 to 192.168.40.21:46541 length 0
(2) EAP-Message = 0x019803f2194081890603551d23048181307f8014f5a4fe043082531ea9c9e8894ce371c0d8b76e0ca15ca45a3058310b30090603550406130241553113301106035504080c0a517565656e736c616e6431153013060355040a0c0c4950414e59414e59204c7464311d301b06035504030c144950414e59
(2) Message-Authenticator = 0x00000000000000000000000000000000
(2) State = 0xdcff01a1de6718422343d3b59bbb1704
(2) Finished request
Waking up in 4.9 seconds.
(3) Received Access-Request Id 199 from 192.168.40.21:46541 to 192.168.8.35:1812 length 173
(3) User-Name = "anonymous"
(3) NAS-Identifier = "802aa8d3d475"
(3) NAS-Port = 0
(3) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(3) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(3) Framed-MTU = 1400
(3) NAS-Port-Type = Wireless-802.11
(3) Connect-Info = "CONNECT 0Mbps 802.11b"
(3) EAP-Message = 0x029800061900
(3) State = 0xdcff01a1de6718422343d3b59bbb1704
(3) Message-Authenticator = 0xd4e4a6306a82241636efbaedeb77614e
(3) session-state: No cached attributes
(3) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(3) authorize {
(3) policy filter_username {
(3) if (&User-Name) {
(3) if (&User-Name) -> TRUE
(3) if (&User-Name) {
(3) if (&User-Name =~ / /) {
(3) if (&User-Name =~ / /) -> FALSE
(3) if (&User-Name =~ /@[^@]*@/ ) {
(3) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(3) if (&User-Name =~ /\.\./ ) {
(3) if (&User-Name =~ /\.\./ ) -> FALSE
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(3) if (&User-Name =~ /\.$/) {
(3) if (&User-Name =~ /\.$/) -> FALSE
(3) if (&User-Name =~ /(a)\./) {
(3) if (&User-Name =~ /(a)\./) -> FALSE
(3) } # if (&User-Name) = notfound
(3) } # policy filter_username = notfound
(3) [preprocess] = ok
(3) [chap] = noop
(3) [mschap] = noop
(3) [digest] = noop
(3) suffix: Checking for suffix after "@"
(3) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(3) suffix: No such realm "NULL"
(3) [suffix] = noop
(3) eap: Peer sent EAP Response (code 2) ID 152 length 6
(3) eap: Continuing tunnel setup
(3) [eap] = ok
(3) } # authorize = ok
(3) Found Auth-Type = eap
(3) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(3) authenticate {
(3) eap: Expiring EAP session with state 0xdcff01a1de671842
(3) eap: Finished EAP session with state 0xdcff01a1de671842
(3) eap: Previous EAP request found for state 0xdcff01a1de671842, released from the list
(3) eap: Peer sent packet with method EAP PEAP (25)
(3) eap: Calling submodule eap_peap to process data
(3) eap_peap: Continuing EAP-TLS
(3) eap_peap: Peer ACKed our handshake fragment
(3) eap_peap: [eaptls verify] = request
(3) eap_peap: [eaptls process] = handled
(3) eap: Sending EAP Request (code 1) ID 153 length 1010
(3) eap: EAP session adding &reply:State = 0xdcff01a1df661842
(3) [eap] = handled
(3) } # authenticate = handled
(3) Using Post-Auth-Type Challenge
(3) Post-Auth-Type sub-section not found. Ignoring.
(3) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(3) Sent Access-Challenge Id 199 from 192.168.8.35:1812 to 192.168.40.21:46541 length 0
(3) EAP-Message = 0x019903f219403db777b2ab1db344d5c78cff8c6741f67e95299b96815e5bcb66eb71439eb8a99050aa381ef4d9d7cc65154cbd3dcdc50a20d6f4da6c3eedc4a6c4c4adb072c4d5d71a4e6ed7456e5e0c9f73de1367f00dbd34e027282672811a6dd2aecdebd2cb615ccddf147d02b1c65fde6b28ea22f7
(3) Message-Authenticator = 0x00000000000000000000000000000000
(3) State = 0xdcff01a1df6618422343d3b59bbb1704
(3) Finished request
Waking up in 4.8 seconds.
(4) Received Access-Request Id 200 from 192.168.40.21:46541 to 192.168.8.35:1812 length 173
(4) User-Name = "anonymous"
(4) NAS-Identifier = "802aa8d3d475"
(4) NAS-Port = 0
(4) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(4) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(4) Framed-MTU = 1400
(4) NAS-Port-Type = Wireless-802.11
(4) Connect-Info = "CONNECT 0Mbps 802.11b"
(4) EAP-Message = 0x029900061900
(4) State = 0xdcff01a1df6618422343d3b59bbb1704
(4) Message-Authenticator = 0x4a07d878ea0ab40860bd41840d9b53d1
(4) session-state: No cached attributes
(4) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(4) authorize {
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) } # if (&User-Name) = notfound
(4) } # policy filter_username = notfound
(4) [preprocess] = ok
(4) [chap] = noop
(4) [mschap] = noop
(4) [digest] = noop
(4) suffix: Checking for suffix after "@"
(4) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(4) suffix: No such realm "NULL"
(4) [suffix] = noop
(4) eap: Peer sent EAP Response (code 2) ID 153 length 6
(4) eap: Continuing tunnel setup
(4) [eap] = ok
(4) } # authorize = ok
(4) Found Auth-Type = eap
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(4) authenticate {
(4) eap: Expiring EAP session with state 0xdcff01a1df661842
(4) eap: Finished EAP session with state 0xdcff01a1df661842
(4) eap: Previous EAP request found for state 0xdcff01a1df661842, released from the list
(4) eap: Peer sent packet with method EAP PEAP (25)
(4) eap: Calling submodule eap_peap to process data
(4) eap_peap: Continuing EAP-TLS
(4) eap_peap: Peer ACKed our handshake fragment
(4) eap_peap: [eaptls verify] = request
(4) eap_peap: [eaptls process] = handled
(4) eap: Sending EAP Request (code 1) ID 154 length 746
(4) eap: EAP session adding &reply:State = 0xdcff01a1d8651842
(4) [eap] = handled
(4) } # authenticate = handled
(4) Using Post-Auth-Type Challenge
(4) Post-Auth-Type sub-section not found. Ignoring.
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(4) Sent Access-Challenge Id 200 from 192.168.8.35:1812 to 192.168.40.21:46541 length 0
(4) EAP-Message = 0x019a02ea19008fba9616587fb1ea32ee83f2f0972c1cde589ebb9e94a1deba7339756e56e802e9439eb0c62667a97b0b7771ab622fe5422684d07d5f276180e361a9ab2cb3db23c2705d0c12b7d25b66bcacdff1c531817bd650abe21e1ef3df65ca76f81e5cf091d43d31f95c97e8dcaf3269fbc18cfe
(4) Message-Authenticator = 0x00000000000000000000000000000000
(4) State = 0xdcff01a1d86518422343d3b59bbb1704
(4) Finished request
Waking up in 4.8 seconds.
(5) Received Access-Request Id 201 from 192.168.40.21:46541 to 192.168.8.35:1812 length 295
(5) User-Name = "anonymous"
(5) NAS-Identifier = "802aa8d3d475"
(5) NAS-Port = 0
(5) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(5) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(5) Framed-MTU = 1400
(5) NAS-Port-Type = Wireless-802.11
(5) Connect-Info = "CONNECT 0Mbps 802.11b"
(5) EAP-Message = 0x029a0080198000000076160303004610000042410489c8bd0afbba1b5226f36bba36403153a0adc35a301aad07d58b9688b3371475eacc1ad36aa2fa043d225c347d21f1d8d8581073ea0db0c403ad488a53a8f85d140303000101160303002005961f8818b3e5348683646f8a541de9ea5073ce2efa66
(5) State = 0xdcff01a1d86518422343d3b59bbb1704
(5) Message-Authenticator = 0x3311ca3d5bfb4e1796cc1d6c70cb725c
(5) session-state: No cached attributes
(5) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(5) authorize {
(5) policy filter_username {
(5) if (&User-Name) {
(5) if (&User-Name) -> TRUE
(5) if (&User-Name) {
(5) if (&User-Name =~ / /) {
(5) if (&User-Name =~ / /) -> FALSE
(5) if (&User-Name =~ /@[^@]*@/ ) {
(5) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(5) if (&User-Name =~ /\.\./ ) {
(5) if (&User-Name =~ /\.\./ ) -> FALSE
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(5) if (&User-Name =~ /\.$/) {
(5) if (&User-Name =~ /\.$/) -> FALSE
(5) if (&User-Name =~ /(a)\./) {
(5) if (&User-Name =~ /(a)\./) -> FALSE
(5) } # if (&User-Name) = notfound
(5) } # policy filter_username = notfound
(5) [preprocess] = ok
(5) [chap] = noop
(5) [mschap] = noop
(5) [digest] = noop
(5) suffix: Checking for suffix after "@"
(5) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(5) suffix: No such realm "NULL"
(5) [suffix] = noop
(5) eap: Peer sent EAP Response (code 2) ID 154 length 128
(5) eap: Continuing tunnel setup
(5) [eap] = ok
(5) } # authorize = ok
(5) Found Auth-Type = eap
(5) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(5) authenticate {
(5) eap: Expiring EAP session with state 0xdcff01a1d8651842
(5) eap: Finished EAP session with state 0xdcff01a1d8651842
(5) eap: Previous EAP request found for state 0xdcff01a1d8651842, released from the list
(5) eap: Peer sent packet with method EAP PEAP (25)
(5) eap: Calling submodule eap_peap to process data
(5) eap_peap: Continuing EAP-TLS
(5) eap_peap: Peer indicated complete TLS record size will be 118 bytes
(5) eap_peap: Got complete TLS record (118 bytes)
(5) eap_peap: [eaptls verify] = length included
(5) eap_peap: TLS_accept: SSLv3/TLS write server done
(5) eap_peap: <<< recv TLS 1.2 [length 0046]
(5) eap_peap: TLS_accept: SSLv3/TLS read client key exchange
(5) eap_peap: TLS_accept: SSLv3/TLS read change cipher spec
(5) eap_peap: <<< recv TLS 1.2 [length 0010]
(5) eap_peap: TLS_accept: SSLv3/TLS read finished
(5) eap_peap: >>> send TLS 1.2 [length 0001]
(5) eap_peap: TLS_accept: SSLv3/TLS write change cipher spec
(5) eap_peap: >>> send TLS 1.2 [length 0010]
(5) eap_peap: TLS_accept: SSLv3/TLS write finished
(5) eap_peap: (other): SSL negotiation finished successfully
(5) eap_peap: SSL Connection Established
(5) eap_peap: [eaptls process] = handled
(5) eap: Sending EAP Request (code 1) ID 155 length 49
(5) eap: EAP session adding &reply:State = 0xdcff01a1d9641842
(5) [eap] = handled
(5) } # authenticate = handled
(5) Using Post-Auth-Type Challenge
(5) Post-Auth-Type sub-section not found. Ignoring.
(5) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(5) Sent Access-Challenge Id 201 from 192.168.8.35:1812 to 192.168.40.21:46541 length 0
(5) EAP-Message = 0x019b003119001403030001011603030020928339ca9a02fb4881ae249f612df4a26df59326e0672ac8e445c34168991d32
(5) Message-Authenticator = 0x00000000000000000000000000000000
(5) State = 0xdcff01a1d96418422343d3b59bbb1704
(5) Finished request
Waking up in 4.7 seconds.
(6) Received Access-Request Id 202 from 192.168.40.21:46541 to 192.168.8.35:1812 length 173
(6) User-Name = "anonymous"
(6) NAS-Identifier = "802aa8d3d475"
(6) NAS-Port = 0
(6) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(6) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(6) Framed-MTU = 1400
(6) NAS-Port-Type = Wireless-802.11
(6) Connect-Info = "CONNECT 0Mbps 802.11b"
(6) EAP-Message = 0x029b00061900
(6) State = 0xdcff01a1d96418422343d3b59bbb1704
(6) Message-Authenticator = 0xf6be5cee51e32fdacbbef344781223d3
(6) session-state: No cached attributes
(6) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(6) authorize {
(6) policy filter_username {
(6) if (&User-Name) {
(6) if (&User-Name) -> TRUE
(6) if (&User-Name) {
(6) if (&User-Name =~ / /) {
(6) if (&User-Name =~ / /) -> FALSE
(6) if (&User-Name =~ /@[^@]*@/ ) {
(6) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(6) if (&User-Name =~ /\.\./ ) {
(6) if (&User-Name =~ /\.\./ ) -> FALSE
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(6) if (&User-Name =~ /\.$/) {
(6) if (&User-Name =~ /\.$/) -> FALSE
(6) if (&User-Name =~ /(a)\./) {
(6) if (&User-Name =~ /(a)\./) -> FALSE
(6) } # if (&User-Name) = notfound
(6) } # policy filter_username = notfound
(6) [preprocess] = ok
(6) [chap] = noop
(6) [mschap] = noop
(6) [digest] = noop
(6) suffix: Checking for suffix after "@"
(6) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(6) suffix: No such realm "NULL"
(6) [suffix] = noop
(6) eap: Peer sent EAP Response (code 2) ID 155 length 6
(6) eap: Continuing tunnel setup
(6) [eap] = ok
(6) } # authorize = ok
(6) Found Auth-Type = eap
(6) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(6) authenticate {
(6) eap: Expiring EAP session with state 0xdcff01a1d9641842
(6) eap: Finished EAP session with state 0xdcff01a1d9641842
(6) eap: Previous EAP request found for state 0xdcff01a1d9641842, released from the list
(6) eap: Peer sent packet with method EAP PEAP (25)
(6) eap: Calling submodule eap_peap to process data
(6) eap_peap: Continuing EAP-TLS
(6) eap_peap: Peer ACKed our handshake fragment. handshake is finished
(6) eap_peap: [eaptls verify] = success
(6) eap_peap: [eaptls process] = success
(6) eap_peap: Session established. Decoding tunneled attributes
(6) eap_peap: PEAP state TUNNEL ESTABLISHED
(6) eap: Sending EAP Request (code 1) ID 156 length 32
(6) eap: EAP session adding &reply:State = 0xdcff01a1da631842
(6) [eap] = handled
(6) } # authenticate = handled
(6) Using Post-Auth-Type Challenge
(6) Post-Auth-Type sub-section not found. Ignoring.
(6) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(6) Sent Access-Challenge Id 202 from 192.168.8.35:1812 to 192.168.40.21:46541 length 0
(6) EAP-Message = 0x019c00201900170303001599b5f4133e2b7766900ad78dd36daf40d396f375f2
(6) Message-Authenticator = 0x00000000000000000000000000000000
(6) State = 0xdcff01a1da6318422343d3b59bbb1704
(6) Finished request
Waking up in 4.7 seconds.
(7) Received Access-Request Id 203 from 192.168.40.21:46541 to 192.168.8.35:1812 length 203
(7) User-Name = "anonymous"
(7) NAS-Identifier = "802aa8d3d475"
(7) NAS-Port = 0
(7) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(7) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(7) Framed-MTU = 1400
(7) NAS-Port-Type = Wireless-802.11
(7) Connect-Info = "CONNECT 0Mbps 802.11b"
(7) EAP-Message = 0x029c002419001703030019dfbe3664b6ba25228ceeefd1544ec446fce8a53f317c6cdc30
(7) State = 0xdcff01a1da6318422343d3b59bbb1704
(7) Message-Authenticator = 0xe33ca0e8b373f089e411f537f6aa90b8
(7) session-state: No cached attributes
(7) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(7) authorize {
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = notfound
(7) } # policy filter_username = notfound
(7) [preprocess] = ok
(7) [chap] = noop
(7) [mschap] = noop
(7) [digest] = noop
(7) suffix: Checking for suffix after "@"
(7) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(7) suffix: No such realm "NULL"
(7) [suffix] = noop
(7) eap: Peer sent EAP Response (code 2) ID 156 length 36
(7) eap: Continuing tunnel setup
(7) [eap] = ok
(7) } # authorize = ok
(7) Found Auth-Type = eap
(7) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(7) authenticate {
(7) eap: Expiring EAP session with state 0xdcff01a1da631842
(7) eap: Finished EAP session with state 0xdcff01a1da631842
(7) eap: Previous EAP request found for state 0xdcff01a1da631842, released from the list
(7) eap: Peer sent packet with method EAP PEAP (25)
(7) eap: Calling submodule eap_peap to process data
(7) eap_peap: Continuing EAP-TLS
(7) eap_peap: [eaptls verify] = ok
(7) eap_peap: Done initial handshake
(7) eap_peap: [eaptls process] = ok
(7) eap_peap: Session established. Decoding tunneled attributes
(7) eap_peap: PEAP state WAITING FOR INNER IDENTITY
(7) eap_peap: Identity - testuser
(7) eap_peap: Got inner identity 'testuser'
(7) eap_peap: Setting default EAP type for tunneled EAP session
(7) eap_peap: Got tunneled request
(7) eap_peap: EAP-Message = 0x029c000d017465737475736572
(7) eap_peap: Setting User-Name to testuser
(7) eap_peap: Sending tunneled request to inner-tunnel
(7) eap_peap: EAP-Message = 0x029c000d017465737475736572
(7) eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(7) eap_peap: User-Name = "testuser"
(7) Virtual server inner-tunnel received request
(7) EAP-Message = 0x029c000d017465737475736572
(7) FreeRADIUS-Proxied-To = 127.0.0.1
(7) User-Name = "testuser"
(7) server inner-tunnel {
(7) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(7) authorize {
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = notfound
(7) } # policy filter_username = notfound
(7) [chap] = noop
(7) [mschap] = noop
(7) suffix: Checking for suffix after "@"
(7) suffix: No '@' in User-Name = "testuser", looking up realm NULL
(7) suffix: No such realm "NULL"
(7) [suffix] = noop
(7) update control {
(7) &Proxy-To-Realm := LOCAL
(7) } # update control = noop
(7) eap: Peer sent EAP Response (code 2) ID 156 length 13
(7) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(7) [eap] = ok
(7) } # authorize = ok
(7) Found Auth-Type = eap
(7) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(7) authenticate {
(7) eap: Peer sent packet with method EAP Identity (1)
(7) eap: Calling submodule eap_mschapv2 to process data
(7) eap_mschapv2: Issuing Challenge
(7) eap: Sending EAP Request (code 1) ID 157 length 43
(7) eap: EAP session adding &reply:State = 0x73614bc173fc510e
(7) [eap] = handled
(7) } # authenticate = handled
(7) } # server inner-tunnel
(7) Virtual server sending reply
(7) EAP-Message = 0x019d002b1a019d002610e5e45786ca3a29b6956bd8375f1639c0667265657261646975732d332e302e3132
(7) Message-Authenticator = 0x00000000000000000000000000000000
(7) State = 0x73614bc173fc510eb5bcf37c76b9f7ee
(7) eap_peap: Got tunneled reply code 11
(7) eap_peap: EAP-Message = 0x019d002b1a019d002610e5e45786ca3a29b6956bd8375f1639c0667265657261646975732d332e302e3132
(7) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(7) eap_peap: State = 0x73614bc173fc510eb5bcf37c76b9f7ee
(7) eap_peap: Got tunneled reply RADIUS code 11
(7) eap_peap: EAP-Message = 0x019d002b1a019d002610e5e45786ca3a29b6956bd8375f1639c0667265657261646975732d332e302e3132
(7) eap_peap: Message-Authenticator = 0x00000000000000000000000000000000
(7) eap_peap: State = 0x73614bc173fc510eb5bcf37c76b9f7ee
(7) eap_peap: Got tunneled Access-Challenge
(7) eap: Sending EAP Request (code 1) ID 157 length 66
(7) eap: EAP session adding &reply:State = 0xdcff01a1db621842
(7) [eap] = handled
(7) } # authenticate = handled
(7) Using Post-Auth-Type Challenge
(7) Post-Auth-Type sub-section not found. Ignoring.
(7) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(7) Sent Access-Challenge Id 203 from 192.168.8.35:1812 to 192.168.40.21:46541 length 0
(7) EAP-Message = 0x019d004219001703030037dffc0f74fbf5c2a1c1b4e813f1bedcd02a226b0d28b1fcd482c11a0c445a5769fb76b4160a1592400e1e3132b40adfcd8487ab156e0774
(7) Message-Authenticator = 0x00000000000000000000000000000000
(7) State = 0xdcff01a1db6218422343d3b59bbb1704
(7) Finished request
Waking up in 4.6 seconds.
(8) Received Access-Request Id 204 from 192.168.40.21:46541 to 192.168.8.35:1812 length 257
(8) User-Name = "anonymous"
(8) NAS-Identifier = "802aa8d3d475"
(8) NAS-Port = 0
(8) Called-Station-Id = "82-2A-A8-D5-D4-75:WLAN"
(8) Calling-Station-Id = "EC-1F-72-7E-BC-BB"
(8) Framed-MTU = 1400
(8) NAS-Port-Type = Wireless-802.11
(8) Connect-Info = "CONNECT 0Mbps 802.11b"
(8) EAP-Message = 0x029d005a1900170303004fac11437186f600192f1d060baa8875d682df61ad47e0e246cf391949b2272efd532220d5f3bc4898f73b36d4b0bbd67f76b79d8085469c0d42c14266c541c8ac5832394b2a9c58d4c996d2c12052b5
(8) State = 0xdcff01a1db6218422343d3b59bbb1704
(8) Message-Authenticator = 0xae99edf0405ba34c80a232350a88654d
(8) session-state: No cached attributes
(8) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(8) authorize {
(8) policy filter_username {
(8) if (&User-Name) {
(8) if (&User-Name) -> TRUE
(8) if (&User-Name) {
(8) if (&User-Name =~ / /) {
(8) if (&User-Name =~ / /) -> FALSE
(8) if (&User-Name =~ /@[^@]*@/ ) {
(8) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(8) if (&User-Name =~ /\.\./ ) {
(8) if (&User-Name =~ /\.\./ ) -> FALSE
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(8) if (&User-Name =~ /\.$/) {
(8) if (&User-Name =~ /\.$/) -> FALSE
(8) if (&User-Name =~ /(a)\./) {
(8) if (&User-Name =~ /(a)\./) -> FALSE
(8) } # if (&User-Name) = notfound
(8) } # policy filter_username = notfound
(8) [preprocess] = ok
(8) [chap] = noop
(8) [mschap] = noop
(8) [digest] = noop
(8) suffix: Checking for suffix after "@"
(8) suffix: No '@' in User-Name = "anonymous", looking up realm NULL
(8) suffix: No such realm "NULL"
(8) [suffix] = noop
(8) eap: Peer sent EAP Response (code 2) ID 157 length 90
(8) eap: Continuing tunnel setup
(8) [eap] = ok
(8) } # authorize = ok
(8) Found Auth-Type = eap
(8) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(8) authenticate {
(8) eap: Expiring EAP session with state 0x73614bc173fc510e
(8) eap: Finished EAP session with state 0xdcff01a1db621842
(8) eap: Previous EAP request found for state 0xdcff01a1db621842, released from the list
(8) eap: Peer sent packet with method EAP PEAP (25)
(8) eap: Calling submodule eap_peap to process data
(8) eap_peap: Continuing EAP-TLS
(8) eap_peap: [eaptls verify] = ok
(8) eap_peap: Done initial handshake
(8) eap_peap: [eaptls process] = ok
(8) eap_peap: Session established. Decoding tunneled attributes
(8) eap_peap: PEAP state phase2
(8) eap_peap: EAP method MSCHAPv2 (26)
(8) eap_peap: Got tunneled request
(8) eap_peap: EAP-Message = 0x029d00431a029d003e316faa2fa72f071a07fc2fa07c14a760890000000000000000f12df86a0605ad36f6429ce8687a49633d5dde6fff3d7153007465737475736572
(8) eap_peap: Setting User-Name to testuser
(8) eap_peap: Sending tunneled request to inner-tunnel
(8) eap_peap: EAP-Message = 0x029d00431a029d003e316faa2fa72f071a07fc2fa07c14a760890000000000000000f12df86a0605ad36f6429ce8687a49633d5dde6fff3d7153007465737475736572
(8) eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(8) eap_peap: User-Name = "testuser"
(8) eap_peap: State = 0x73614bc173fc510eb5bcf37c76b9f7ee
(8) Virtual server inner-tunnel received request
(8) EAP-Message = 0x029d00431a029d003e316faa2fa72f071a07fc2fa07c14a760890000000000000000f12df86a0605ad36f6429ce8687a49633d5dde6fff3d7153007465737475736572
(8) FreeRADIUS-Proxied-To = 127.0.0.1
(8) User-Name = "testuser"
(8) State = 0x73614bc173fc510eb5bcf37c76b9f7ee
(8) server inner-tunnel {
(8) session-state: No cached attributes
(8) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(8) authorize {
(8) policy filter_username {
(8) if (&User-Name) {
(8)
1
3