Freeradius-Users
Threads by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 27050 discussions
25 Jul '19
Hi Alan
Concerning mapping attributes of an LDAP group (not evaluating group
memberships), I have made and attempt but failed so far.
Mapping an attribute from a LDAP user to a FreeRADIUS attribute is very
simple in and straightforward:
- Add a custom myattrib to dictionary
- Extend the mapping of LDAP attribute control:<myattrib> in the
update{ } section of mods-available/ldap
- Add a simple if { } check for control:<myattrib> in post-auth
of sites-enabled/<yourserver> and be happy :-)
The problem is that in that particular directory (whether I like it or
not...) the relevant permission can be set for the user but it can also
be set on a group is a member of.
Thus both LDAP filters would need to yield an ACCESS-ACCEPT:
(&(objectClass=posixGroup)(memberUid=bob)(univentionNetworkAccess=1))
OR
(&(objectClass=posixUser)(uid=bob)(univentionNetworkAccess=1))
If I configure both user and group filter, the attribute would be
required on both the user and the group for example.
Instead said permission attribute, this could also be a VLAN ID
attribute that is set at the level of an LDAP group. I've also tried
searching if others have attempted mapping VLANs based on LDAP
attributes, not group memberships alone, but it doesn't seem so.
Creative use of search engines and an attempted areading rlm_ldap's
source code hasn't brought a step ahead yet. - Maybe I'm looking at it
the wrong way? Sorry...
Am 23.07.2019 um 04:29 schrieb Alan DeKok:
> On Jul 22, 2019, at 4:37 PM, Mathieu Simon (Lists) <matsimon.lists(a)simweb.ch> wrote:
>> Thank you for your precise feedback, definitely helped me to better
>> understand where I am and have to poke with the stick.
>
> You're welcome. FreeRADIUS is a complex system, even without adding LDAP.
>
>>> In v3, it's a little complex. In (coming some time soon) v4, it's a "map" command. :(
>>>
>> Ah, now that look interesting indeed! Without you mentioning it here I
>> wouldn't have been able to locate it other than with the 2 lines in v4's
>> doc/ChangeLog. Definitely something worth mentioning prominentely IMO.
>
> The doc/ChangeLog for v4 says little more than "it's version 4".
Yes, but not much yet about its usage, nonetheless very exciting to hear
about what is coming with v4.
[...]
>
> It should be listed in "man unlang". And in doc/unlang/map.adoc
OK, neither is present yet, but as you mentioned: v4 is WiP, I hope to
give a look at v4, I can't promise providing docs but I'd like to if
time allows.
[...]
>
>> I do plan on looking at v4 anyway even more so now. :)
>
> It's stable. There are large parts which work. But also large parts with "here be dragons".
>
> We're not comfortable releasing an official v4 until (a) there are no "gotchas" with features that sort of almost work, and (b) everything is fully documented.
Perfect: Again, your work and the work of the other main contributors is
highly appreciated.
-- Mathieu
2
3
I need some guidance on my setup. I currently have a FreeIPA intallation setup as my LDAP database. Currently I am trying to test using a 3rd party 2FA with it. Currently I have FreeRADIUS setup on a server and connected to FreeIPA. My question is, would I set this up similar to the way I would if it were a doing Wireless authentication?
In other words would I set up FreeRADIUS with EAP-TTLS?
I am following this - Using FreeIPA and FreeRadius as a RADIUS based software token OTP system with CentOS/RedHat 7 - FreeIPA
|
|
|
| | |
|
|
|
| |
Using FreeIPA and FreeRadius as a RADIUS based software token OTP system...
|
|
|
4
3
Hello, All
When trying to build a dynamic VLAN, the contact point of ldap differs
depending on AP,
Can I control which LDAP attribute to map per ldap query?
And what should I offer to receive advice?
Any help would be appreciated.
4
12
Hello! All.
I try to authenticate with EAP-TTLS at the customer's request, but I
would like help if I have a problem.
Authentication itself is also possible on the real machine, but there
is a log of user's Login OK in radius.log at the time of
authentication,
but two of username and anonymous will be output. (Location of the symbol of ★)
The customer's request is very embarrassing to say that the output of
this Login OK log can be combined with the Login OK output by
username.
Are there any good plans or methods?
Paste the problem log below.
Any help would be appreciated.
-------------------------------------------------------------------------------
Jul 12 13:37:54 xradius radiusd[2415]: Loaded virtual server inner-tunnel
Jul 12 13:37:54 xradius radiusd[2415]: Ready to process requests
Jul 12 13:38:37 xradius radiusd[2415]: Need 5 more connections to
reach 10 spares
Jul 12 13:38:37 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Opening additional connection (5), 1 of 27 pending slots used
★Jul 12 13:38:37 xradius radiusd[2415]: (5) Login OK: [rt015] (from
client testwlc01 port 0 via TLS tunnel)
LDAP;50-3E-AA-6D-ED-7E;;;;;;rt015
★Jul 12 13:38:37 xradius radiusd[2415]: (5) Login OK: [anonymous]
(from client testwlc01 port 12289 cli 50-3E-AA-6D-ED-7E)
eap;50-3E-AA-6D-ED-7E;08-35-71-F2-CE-05;CONNECT 802.11g;;;;anonymous
Jul 12 15:04:23 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Closing connection (2): Hit idle_timeout, was idle for 5189 seconds
Jul 12 15:04:23 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Closing connection (3): Hit idle_timeout, was idle for 5189 seconds
Jul 12 15:04:23 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Closing connection (4): Hit idle_timeout, was idle for 5189 seconds
Jul 12 15:04:23 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Closing connection (0): Hit idle_timeout, was idle for 5146 seconds
Jul 12 15:04:23 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Closing connection (5): Hit idle_timeout, was idle for 5146 seconds
Jul 12 15:04:23 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Closing connection (1): Hit idle_timeout, was idle for 5146 seconds
Jul 12 15:04:23 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Opening additional connection (6), 1 of 32 pending slots used
Jul 12 15:04:24 xradius radiusd[2415]: rlm_ldap (ldap_allusers): Bind
with uid=radius,ou=systems,dc=hoge,dc=fuga,dc=co,dc=jp to
ldaps://ldap.hoge.fuga.co.jp:636 failed: Can't contact LDAP server
Jul 12 15:04:24 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Opening connection failed (6)
Jul 12 15:04:24 xradius radiusd[2415]: (11) Invalid user: [rt015]
(from client testwlc01 port 0 via TLS tunnel)
;50-3E-AA-6D-ED-7E;;;;;;rt015
Jul 12 15:04:24 xradius radiusd[2415]: (11) Login incorrect (eap:
Failed continuing EAP TTLS (21) session. EAP sub-module failed):
[anonymous] (from client testwlc01 port 12289 cli 50-3E-AA-6D-ED-7E)
eap;50-3E-AA-6D-ED-7E;08-35-71-F2-CE-05;CONNECT 802.11g;;;;anonymous
Jul 12 15:09:11 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Opening additional connection (7), 1 of 1 pending slots used
Jul 12 15:09:11 xradius radiusd[2415]: Need 2 more connections to
reach min connections (3)
Jul 12 15:09:11 xradius radiusd[2415]: rlm_ldap (ldap_allusers):
Opening additional connection (8), 1 of 2 pending slots used
★Jul 12 15:09:11 xradius radiusd[2415]: (24) Login OK: [rt015] (from
client testwlc01 port 0 via TLS tunnel)
LDAP;50-3E-AA-6D-ED-7E;;;;;;rt015
★Jul 12 15:09:11 xradius radiusd[2415]: (24) Login OK: [anonymous]
(from client testwlc01 port 12289 cli 50-3E-AA-6D-ED-7E)
eap;50-3E-AA-6D-ED-7E;08-35-71-F2-CE-05;CONNECT 802.11g;;;;anonymous
Jul 12 15:16:48 xradius radiusd[2415]: Signalled to terminate
Jul 12 15:16:48 xradius radiusd[2415]: Exiting normally
2
7
Hi,
We have TLS enabled AWS elasticache.
By default if we try to connect to redis-server with password Freeradius-DHCP server is not connecting with DB.
# cat /etc/raddb/mods-enabled/redis
redis {
server = clustercfg.naw01-dhcpdb.oovb0g.usw2.cache.amazonaws.com
port = 6379
password = PASSWORD
pool {
start = ${thread[pool].num_workers}
min = ${thread[pool].num_workers}
max = ${thread[pool].num_workers}
spare = 1
uses = 0
retry_delay = 30
lifetime = 86400
cleanup_interval = 300
idle_timeout = 600
connect_timeout = 3.0
}
}
radiusd process got stuck while connecting to redis server:
Instantiating module "redis"
rlm_redis (redis) [1] - Initialising connection pool
pool {
start = 4
min = 4
max = 4
max_pending = 0
spare = 1
uses = 0
lifetime = 86400
cleanup_interval = 300
idle_timeout = 600
connect_timeout = 3.000000
held_trigger_min = 0.000000
held_trigger_max = 0.500000
retry_delay = 30
spread = no
}
rlm_redis (redis) [1] - Ignoring "spare = 1", forcing to "spare = 0"
rlm_redis (redis) [1] - Opening additional connection (0), 1 of 4 pending slots used
rlm_redis (redis) - [1] Connecting to node 10.43.16.181:6379
<<<no output hereafter.
Then, I established a stunnel(secure tunnel) between localhost and redis-server and connected Freeradius-DHCP to localhost. This works sometimes but most of the times we are getting "MOVED" error from redis-server(as this is in a cluster).
Stunnel config:
# cat /etc/stunnel/redis-stunnel.conf
fips = no
setuid = root
setgid = root
pid = /var/run/stunnel.pid
debug = warning
delay = yes
options = NO_SSLv2
options = NO_SSLv3
[redis-stunnel]
client = yes
accept = 127.0.0.1:6379
connect = clustercfg.naw01-dhcpdb.oovb0g.usw2.cache.amazonaws.com:6379
redis_module:
# cat /etc/raddb/mods-enabled/redis
redis {
server = localhost
port = 6379
password = PASSWORD
pool {
start = ${thread[pool].num_workers}
min = ${thread[pool].num_workers}
max = ${thread[pool].num_workers}
spare = 1
uses = 0
retry_delay = 30
lifetime = 86400
cleanup_interval = 300
idle_timeout = 600
connect_timeout = 3.0
}
}
(4) redis_ippool - EXPAND %{DHCP-Client-Hardware-Address}_%{DHCP-Client-Identifier}
(4) redis_ippool - --> 00:a0:bc:11:22:33_0x00a0bc112233
(4) redis_ippool - Allocating lease from pool "healthcheck_VSAT-UT", to "00:a0:bc:11:22:33_0x00a0bc112233", expires in 30s
(4) redis_ippool - Reserved connection (3)
(4) redis_ippool - [1] >>> Sending command(s) to 127.0.0.1:6379
(4) redis_ippool - ERROR: (0) error : MOVED 12826 naw01-dhcpdb-0001-001.naw01-dhcpdb.oovb0g.usw2.cache.amazonaws.com:6379
(4) redis_ippool - [1] <<< Returned: move
(4) redis_ippool - Initiating cluster remap
(4) redis_ippool - Not IPv4/6 address, and asked not to resolve
(4) redis_ippool - Released connection (3)
(4) redis_ippool - Need 2 more connections to reach min connections (4)
(4) redis_ippool - Opening additional connection (4), 1 of 2 pending slots used
rlm_redis (redis) - [1] Connecting to node 127.0.0.1:6379
(4) redis_ippool - [1] Processing redirect "MOVED 12826 naw01-dhcpdb-0001-001.naw01-dhcpdb.oovb0g.usw2.cache.amazonaws.com:6379"
(4) redis_ippool (fail)
(4) } # recv DHCP-Discover (fail)
This MOVED error will be resolved if redis_ippool retries the command many times.(I am saying this because even redis-cli does not support TLS authentication. With stunnel, redis-cli gives the same "MOVED" error. Retrying many times works there.)
If possible how to configure number of retries in redis_ippool/redis module?
Or Is there a way in which I can directly connect to redis-server from DHCP server without the need of stunnel?
I am using 4.x branch(with commit id #2e26049fae00508fe722ae0f04b00b5d9f3726dc)
Regards,
Nagamani Chinnapaiyan
2
2
I know this is an old thread, but I am attempting to configure the same scenario in Freeradius.
The backend database is Azure AD DS with LDAPS enabled, and the goal is to have EAP-TTLS/PAP for wifi access points. Obviously passwords are not in cleartext so users should be authenticated by a simple LDAP bind by the rlm_ldap module.
I added Alan’s if statement to default and inner-tunnel to force Auth-Type LDAP but am still getting the error No Auth-Type Found. It doesn’t look like the given credentials are tested with an LDAP bind.
Any specific config or documentation to investigate would be appreciated
See the below log of a request from wifi client.
FreeRADIUS Version 3.0.19
Copyright (C) 1999-2019 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/local/Cellar/freeradius-server/3.0.19/share/freeradius/dictionary
including dictionary file /usr/local/Cellar/freeradius-server/3.0.19/share/freeradius/dictionary.dhcp
including dictionary file /usr/local/Cellar/freeradius-server/3.0.19/share/freeradius/dictionary.vqp
including dictionary file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/dictionary
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/radiusd.conf
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/proxy.conf
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/clients.conf
including files in directory /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/cache_eap
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/chap
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/date
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/digest
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/dynamic_clients
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/eap
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/echo
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/exec
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/expiration
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/expr
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/files
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/ldap
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/linelog
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/logintime
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/mschap
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/ntlm_auth
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/pap
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/passwd
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/preprocess
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/radutmp
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/replicate
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/soh
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/sradutmp
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/unix
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/unpack
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/utf8
including files in directory /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/abfab-tr
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/accounting
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/canonicalization
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/control
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/cui
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/debug
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/dhcp
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/eap
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/filter
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/moonshot-targeted-ids
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/operator-name
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/policy.d/rfc7542
including files in directory /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
including configuration file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/inner-tunnel
main {
name = "radiusd"
prefix = "/usr/local/Cellar/freeradius-server/3.0.19"
localstatedir = "/usr/local/var"
sbindir = "/usr/local/Cellar/freeradius-server/3.0.19/bin"
logdir = "/usr/local/var/log/radius"
run_dir = "/usr/local/var/run/radiusd"
libdir = "/usr/local/Cellar/freeradius-server/3.0.19/lib"
radacctdir = "/usr/local/var/log/radius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/usr/local/var/run/radiusd/radiusd.pid"
checkrad = "/usr/local/Cellar/freeradius-server/3.0.19/bin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
allow_vulnerable_openssl = "no"
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client dynamic {
ipaddr = 10.11.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
proto = "*"
limit {
max_connections = 0
lifetime = 0
idle_timeout = 30
}
}
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
# Creating Auth-Type = ldap
# Creating Auth-Type = mschap
# Creating Auth-Type = digest
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_always
# Loading module "reject" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loaded module rlm_cache
# Loading module "cache_eap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_chap
# Loading module "chap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/chap
# Loaded module rlm_date
# Loading module "date" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/date
date {
format = "%b %e %Y %H:%M:%S %Z"
utc = no
}
# Loading module "wispr2date" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/date
date wispr2date {
format = "%Y-%m-%dT%H:%M:%S"
utc = no
}
# Loaded module rlm_detail
# Loading module "detail" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail
detail {
filename = "/usr/local/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "auth_log" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
detail auth_log {
filename = "/usr/local/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
detail reply_log {
filename = "/usr/local/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
detail pre_proxy_log {
filename = "/usr/local/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
detail post_proxy_log {
filename = "/usr/local/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_digest
# Loading module "digest" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/digest
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/dynamic_clients
# Loaded module rlm_eap
# Loading module "eap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/eap
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_exec
# Loading module "echo" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loading module "exec" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_expiration
# Loading module "expiration" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/expiration
# Loaded module rlm_expr
# Loading module "expr" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/expr
expr {
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loaded module rlm_files
# Loading module "files" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/files
files {
filename = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/files/authorize"
acctusersfile = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/files/accounting"
preproxy_usersfile = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/files/pre-proxy"
}
# Loaded module rlm_ldap
# Loading module "ldap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/ldap
ldap {
server = "ldaps.domain.ca"
port = 636
identity = "ldaps(a)domain.ca"
password = <<< secret >>>
sasl {
}
user_dn = "LDAP-UserDn"
user {
scope = "sub"
access_positive = yes
sasl {
}
}
group {
filter = "(objectClass=posixGroup)"
scope = "sub"
name_attribute = "cn"
membership_attribute = "memberOf"
cacheable_name = no
cacheable_dn = no
}
client {
filter = "(objectClass=radiusClient)"
scope = "sub"
base_dn = "OU=AADDC Users,DC=domain,DC=ca"
}
profile {
}
options {
ldap_debug = 40
chase_referrals = yes
rebind = yes
net_timeout = 1
res_timeout = 10
srv_timelimit = 3
idle = 60
probes = 3
interval = 3
}
tls {
start_tls = no
}
}
Creating attribute LDAP-Group
# Loaded module rlm_linelog
# Loading module "linelog" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/linelog
linelog {
filename = "/usr/local/var/log/radius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/linelog
linelog log_accounting {
filename = "/usr/local/var/log/radius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_logintime
# Loading module "logintime" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_mschap
# Loading module "mschap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
winbind_retry_with_normalised_username = no
use_open_directory = yes
}
# Loading module "ntlm_auth" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN --username=%{mschap:User-Name} --password=%{User-Password}"
shell_escape = yes
}
# Loaded module rlm_pap
# Loading module "pap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/pap
pap {
normalise = yes
}
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loaded module rlm_preprocess
# Loading module "preprocess" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/preprocess
preprocess {
huntgroups = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/preprocess/huntgroups"
hints = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loaded module rlm_radutmp
# Loading module "radutmp" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/radutmp
radutmp {
filename = "/usr/local/var/log/radius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_realm
# Loading module "IPASS" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "bangpath" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
realm bangpath {
format = "prefix"
delimiter = "!"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loaded module rlm_replicate
# Loading module "replicate" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/replicate
# Loaded module rlm_soh
# Loading module "soh" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/soh
soh {
dhcp = yes
}
# Loading module "sradutmp" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/usr/local/var/log/radius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_unix
# Loading module "unix" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/unix
unix {
radwtmp = "/usr/local/var/log/radius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_unpack
# Loading module "unpack" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/unpack
# Loaded module rlm_utf8
# Loading module "utf8" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/utf8
instantiate {
}
# Instantiating module "reject" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "fail" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "ok" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "handled" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "invalid" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "userlock" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "notfound" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "noop" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "updated" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/always
# Instantiating module "attr_filter.post-proxy" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/access_reject
# Instantiating module "attr_filter.access_challenge" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/attr_filter
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/attr_filter/accounting_response
# Instantiating module "cache_eap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module rlm_cache_rbtree) loaded and linked
# Instantiating module "detail" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail
# Instantiating module "auth_log" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output
# Instantiating module "reply_log" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
# Instantiating module "pre_proxy_log" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/detail.log
# Instantiating module "eap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/certs/server.pem"
certificate_file = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/certs/server.pem"
ca_file = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
cipher_server_preference = no
ecdh_curve = "prime256v1"
tls_max_version = ""
tls_min_version = "1.0"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
# Instantiating module "expiration" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/expiration
# Instantiating module "files" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/files
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/files/authorize
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/files/accounting
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/files/pre-proxy
# Instantiating module "ldap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/ldap
rlm_ldap: libldap vendor: OpenLDAP, version: 20428
accounting {
reference = "%{tolower:type.%{Acct-Status-Type}}"
}
post-auth {
reference = "."
}
rlm_ldap (ldap): Initialising connection pool
pool {
start = 5
min = 3
max = 32
spare = 10
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 30
spread = no
}
rlm_ldap (ldap): Opening additional connection (0), 1 of 32 pending slots used
rlm_ldap (ldap): Connecting to ldap://ldaps.domain.ca:636
TLS: during handshake: peer cert is valid, or was ignored if verification disabled (-9841)
TLS: during handshake: Peer certificate is trusted
TLS: TLSv1.2 session established using 256-bit TLS_RSA_WITH_AES_256_GCM_SHA384 cipher
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (1), 1 of 31 pending slots used
rlm_ldap (ldap): Connecting to ldap://ldaps.domain.ca:636
TLS: during handshake: peer cert is valid, or was ignored if verification disabled (-9841)
TLS: during handshake: Peer certificate is trusted
TLS: TLSv1.2 session established using 256-bit TLS_RSA_WITH_AES_256_GCM_SHA384 cipher
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (2), 1 of 30 pending slots used
rlm_ldap (ldap): Connecting to ldap://ldaps.domain.ca:636
TLS: during handshake: peer cert is valid, or was ignored if verification disabled (-9841)
TLS: during handshake: Peer certificate is trusted
TLS: TLSv1.2 session established using 256-bit TLS_RSA_WITH_AES_256_GCM_SHA384 cipher
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (3), 1 of 29 pending slots used
rlm_ldap (ldap): Connecting to ldap://ldaps.domain.ca:636
TLS: during handshake: peer cert is valid, or was ignored if verification disabled (-9841)
TLS: during handshake: Peer certificate is trusted
TLS: TLSv1.2 session established using 256-bit TLS_RSA_WITH_AES_256_GCM_SHA384 cipher
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (4), 1 of 28 pending slots used
rlm_ldap (ldap): Connecting to ldap://ldaps.domain.ca:636
TLS: during handshake: peer cert is valid, or was ignored if verification disabled (-9841)
TLS: during handshake: Peer certificate is trusted
TLS: TLSv1.2 session established using 256-bit TLS_RSA_WITH_AES_256_GCM_SHA384 cipher
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
# Instantiating module "linelog" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/linelog
# Instantiating module "log_accounting" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/linelog
# Instantiating module "logintime" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/logintime
# Instantiating module "mschap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/mschap
rlm_mschap (mschap): using internal authentication
# Instantiating module "pap" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/pap
# Instantiating module "etc_passwd" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "preprocess" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/preprocess
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/preprocess/huntgroups
reading pairlist file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-config/preprocess/hints
# Instantiating module "IPASS" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
# Instantiating module "suffix" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
# Instantiating module "bangpath" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
# Instantiating module "realmpercent" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
# Instantiating module "ntdomain" from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/mods-enabled/realm
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/radiusd.conf
} # server
server default { # from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
# Loading authenticate {...}
# Loading authorize {...}
Ignoring "sql" (see raddb/mods-available/README.rst)
# Loading preacct {...}
# Loading accounting {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server default
server inner-tunnel { # from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
# Skipping contents of 'if' as it is always 'false' -- /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/inner-tunnel:341
} # server inner-tunnel
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = 10.11.12.62
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on auth address 10.11.12.62 port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Listening on proxy address * port 63972
Listening on proxy address :: port 63973
Ready to process requests
(0) Received Access-Request Id 55 from 10.11.12.207:59118 to 10.11.12.62:1812 length 191
(0) User-Name = "ldaps(a)domain.ca"
(0) NAS-IP-Address = 10.11.12.207
(0) NAS-Port = 736
(0) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(0) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(0) Framed-MTU = 1400
(0) NAS-Port-Type = Wireless-802.11
(0) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(0) EAP-Message = 0x0200001c016c64617073406b696e677363687269737469616e2e6361
(0) Message-Authenticator = 0x5fc7a5fa4f247c8d85cda267b269d910
(0) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) [preprocess] = ok
(0) [chap] = noop
(0) [mschap] = noop
(0) [digest] = noop
(0) suffix: Checking for suffix after "@"
(0) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(0) suffix: No such realm "domain.ca"
(0) [suffix] = noop
(0) eap: Peer sent EAP Response (code 2) ID 0 length 28
(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(0) [eap] = ok
(0) } # authorize = ok
(0) Found Auth-Type = eap
(0) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(0) authenticate {
(0) eap: Peer sent packet with method EAP Identity (1)
(0) eap: Calling submodule eap_md5 to process data
(0) eap_md5: Issuing MD5 Challenge
(0) eap: Sending EAP Request (code 1) ID 1 length 22
(0) eap: EAP session adding &reply:State = 0x82acad7c82ada94f
(0) [eap] = handled
(0) } # authenticate = handled
(0) Using Post-Auth-Type Challenge
(0) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(0) Challenge { ... } # empty sub-section is ignored
(0) Sent Access-Challenge Id 55 from 10.11.12.62:1812 to 10.11.12.207:59118 length 0
(0) EAP-Message = 0x010100160410323dc8ee4193e3228d24f6b415a22dd0
(0) Message-Authenticator = 0x00000000000000000000000000000000
(0) State = 0x82acad7c82ada94f1bfb0011896e6929
(0) Finished request
Waking up in 4.9 seconds.
(1) Received Access-Request Id 56 from 10.11.12.207:59118 to 10.11.12.62:1812 length 189
(1) User-Name = "ldaps(a)domain.ca"
(1) NAS-IP-Address = 10.11.12.207
(1) NAS-Port = 736
(1) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(1) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(1) Framed-MTU = 1400
(1) NAS-Port-Type = Wireless-802.11
(1) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(1) EAP-Message = 0x020100080319152b
(1) State = 0x82acad7c82ada94f1bfb0011896e6929
(1) Message-Authenticator = 0xfa1fa3aebbe14b2929e9aff5fc492fea
(1) session-state: No cached attributes
(1) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(1) authorize {
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # if (&User-Name) = notfound
(1) } # policy filter_username = notfound
(1) [preprocess] = ok
(1) [chap] = noop
(1) [mschap] = noop
(1) [digest] = noop
(1) suffix: Checking for suffix after "@"
(1) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(1) suffix: No such realm "domain.ca"
(1) [suffix] = noop
(1) eap: Peer sent EAP Response (code 2) ID 1 length 8
(1) eap: No EAP Start, assuming it's an on-going EAP conversation
(1) [eap] = updated
(1) [files] = noop
rlm_ldap (ldap): Reserved connection (0)
(1) ldap: EXPAND (userPrincipalName=%{%{Stripped-User-Name}:-%{User-Name}})
(1) ldap: --> (userPrincipalName=ldaps(a)domain.ca)
(1) ldap: Performing search in "OU=AADDC Users,DC=domain,DC=ca" with filter "(userPrincipalName=ldaps(a)domain.ca)", scope "sub"
(1) ldap: Waiting for search result...
(1) ldap: User object found at DN "CN=LDAPS,OU=AADDC Users,DC=domain,DC=ca"
(1) ldap: Processing user attributes
(1) ldap: WARNING: No "known good" password added. Ensure the admin user has permission to read the password attribute
(1) ldap: WARNING: PAP authentication will *NOT* work with Active Directory (if that is what you were trying to configure)
rlm_ldap (ldap): Released connection (0)
Need 5 more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (5), 1 of 27 pending slots used
rlm_ldap (ldap): Connecting to ldap://ldaps.domain.ca:636
TLS: during handshake: peer cert is valid, or was ignored if verification disabled (-9841)
TLS: during handshake: Peer certificate is trusted
TLS: TLSv1.2 session established using 256-bit TLS_RSA_WITH_AES_256_GCM_SHA384 cipher
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
(1) [ldap] = ok
(1) [expiration] = noop
(1) [logintime] = noop
Not doing PAP as Auth-Type is already set.
(1) [pap] = noop
(1) if (noop && User-Password) {
(1) if (noop && User-Password) -> FALSE
(1) } # authorize = updated
(1) Found Auth-Type = eap
(1) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(1) authenticate {
(1) eap: Expiring EAP session with state 0x82acad7c82ada94f
(1) eap: Finished EAP session with state 0x82acad7c82ada94f
(1) eap: Previous EAP request found for state 0x82acad7c82ada94f, released from the list
(1) eap: Peer sent packet with method EAP NAK (3)
(1) eap: Found mutually acceptable type PEAP (25)
(1) eap: Calling submodule eap_peap to process data
(1) eap_peap: Initiating new TLS session
(1) eap_peap: [eaptls start] = request
(1) eap: Sending EAP Request (code 1) ID 2 length 6
(1) eap: EAP session adding &reply:State = 0x82acad7c83aeb44f
(1) [eap] = handled
(1) } # authenticate = handled
(1) Using Post-Auth-Type Challenge
(1) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(1) Challenge { ... } # empty sub-section is ignored
(1) Sent Access-Challenge Id 56 from 10.11.12.62:1812 to 10.11.12.207:59118 length 0
(1) EAP-Message = 0x010200061920
(1) Message-Authenticator = 0x00000000000000000000000000000000
(1) State = 0x82acad7c83aeb44f1bfb0011896e6929
(1) Finished request
Waking up in 4.9 seconds.
(2) Received Access-Request Id 57 from 10.11.12.207:59118 to 10.11.12.62:1812 length 342
(2) User-Name = "ldaps(a)domain.ca"
(2) NAS-IP-Address = 10.11.12.207
(2) NAS-Port = 736
(2) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(2) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(2) Framed-MTU = 1400
(2) NAS-Port-Type = Wireless-802.11
(2) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(2) EAP-Message = 0x020200a119800000009716030100920100008e03035d3752bc4dd01f70ca7820c44591b0838514535fffba5a0e22a3ad100cc0e73400002c00ffc02cc02bc024c023c00ac009c008c030c02fc028c027c014c013c012009d009c003d003c0035002f000a01000039000a00080006001700180019000b00020100000d00120010040102010501060104030203050306030005000501000000000012000000170000
(2) State = 0x82acad7c83aeb44f1bfb0011896e6929
(2) Message-Authenticator = 0xd96f97654989472c63ccdc9127008329
(2) session-state: No cached attributes
(2) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(2) authorize {
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) } # if (&User-Name) = notfound
(2) } # policy filter_username = notfound
(2) [preprocess] = ok
(2) [chap] = noop
(2) [mschap] = noop
(2) [digest] = noop
(2) suffix: Checking for suffix after "@"
(2) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(2) suffix: No such realm "domain.ca"
(2) [suffix] = noop
(2) eap: Peer sent EAP Response (code 2) ID 2 length 161
(2) eap: Continuing tunnel setup
(2) [eap] = ok
(2) } # authorize = ok
(2) Found Auth-Type = eap
(2) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(2) authenticate {
(2) eap: Expiring EAP session with state 0x82acad7c83aeb44f
(2) eap: Finished EAP session with state 0x82acad7c83aeb44f
(2) eap: Previous EAP request found for state 0x82acad7c83aeb44f, released from the list
(2) eap: Peer sent packet with method EAP PEAP (25)
(2) eap: Calling submodule eap_peap to process data
(2) eap_peap: Continuing EAP-TLS
(2) eap_peap: Peer indicated complete TLS record size will be 151 bytes
(2) eap_peap: Got complete TLS record (151 bytes)
(2) eap_peap: [eaptls verify] = length included
(2) eap_peap: (other): before/accept initialization
(2) eap_peap: TLS_accept: before/accept initialization
(2) eap_peap: <<< recv TLS 1.2 [length 0092]
(2) eap_peap: TLS_accept: unknown state
(2) eap_peap: >>> send TLS 1.2 [length 0039]
(2) eap_peap: TLS_accept: unknown state
(2) eap_peap: >>> send TLS 1.2 [length 08d3]
(2) eap_peap: TLS_accept: unknown state
(2) eap_peap: >>> send TLS 1.2 [length 014d]
(2) eap_peap: TLS_accept: unknown state
(2) eap_peap: >>> send TLS 1.2 [length 0004]
(2) eap_peap: TLS_accept: unknown state
(2) eap_peap: TLS_accept: unknown state
(2) eap_peap: TLS_accept: unknown state
(2) eap_peap: TLS_accept: Need to read more data: unknown state
(2) eap_peap: TLS_accept: Need to read more data: unknown state
(2) eap_peap: TLS - In Handshake Phase
(2) eap_peap: TLS - got 2673 bytes of data
(2) eap_peap: [eaptls process] = handled
(2) eap: Sending EAP Request (code 1) ID 3 length 1004
(2) eap: EAP session adding &reply:State = 0x82acad7c80afb44f
(2) [eap] = handled
(2) } # authenticate = handled
(2) Using Post-Auth-Type Challenge
(2) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(2) Challenge { ... } # empty sub-section is ignored
(2) Sent Access-Challenge Id 57 from 10.11.12.62:1812 to 10.11.12.207:59118 length 0
(2) EAP-Message = 0x010303ec19c000000a711603030039020000350303836676df3615a6fdf6e18367e607ed6c5dd76ee5fff553f869be6c56960ba19700c03000000dff01000100000b00040300010216030308d30b0008cf0008cc0003de308203da308202c2a003020102020101300d06092a864886f70d01010b0500308193310b3009060355040613024652310f300d06035504080c065261646975733112301006035504070c09536f6d65776865726531153013060355040a0c0c4578616d706c6520496e632e3120301e06092a864886f70d010901161161646d696e406578616d706c652e6f72673126302406035504030c1d4578616d706c6520436572746966696361746520417574686f72697479301e170d3139303732333138303430365a170d3139303932313138303430365a307c310b3009060355040613024652310f300d06035504080c0652616469757331153013060355040a0c0c4578616d706c6520496e632e3123302106035504030c1a4578616d706c652053
(2) Message-Authenticator = 0x00000000000000000000000000000000
(2) State = 0x82acad7c80afb44f1bfb0011896e6929
(2) Finished request
Waking up in 4.8 seconds.
(3) Received Access-Request Id 58 from 10.11.12.207:59118 to 10.11.12.62:1812 length 187
(3) User-Name = "ldaps(a)domain.ca"
(3) NAS-IP-Address = 10.11.12.207
(3) NAS-Port = 736
(3) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(3) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(3) Framed-MTU = 1400
(3) NAS-Port-Type = Wireless-802.11
(3) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(3) EAP-Message = 0x020300061900
(3) State = 0x82acad7c80afb44f1bfb0011896e6929
(3) Message-Authenticator = 0xe79738b873d0b96b0e6dd1bc3c3fa9e2
(3) session-state: No cached attributes
(3) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(3) authorize {
(3) policy filter_username {
(3) if (&User-Name) {
(3) if (&User-Name) -> TRUE
(3) if (&User-Name) {
(3) if (&User-Name =~ / /) {
(3) if (&User-Name =~ / /) -> FALSE
(3) if (&User-Name =~ /@[^@]*@/ ) {
(3) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(3) if (&User-Name =~ /\.\./ ) {
(3) if (&User-Name =~ /\.\./ ) -> FALSE
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(3) if (&User-Name =~ /\.$/) {
(3) if (&User-Name =~ /\.$/) -> FALSE
(3) if (&User-Name =~ /(a)\./) {
(3) if (&User-Name =~ /(a)\./) -> FALSE
(3) } # if (&User-Name) = notfound
(3) } # policy filter_username = notfound
(3) [preprocess] = ok
(3) [chap] = noop
(3) [mschap] = noop
(3) [digest] = noop
(3) suffix: Checking for suffix after "@"
(3) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(3) suffix: No such realm "domain.ca"
(3) [suffix] = noop
(3) eap: Peer sent EAP Response (code 2) ID 3 length 6
(3) eap: Continuing tunnel setup
(3) [eap] = ok
(3) } # authorize = ok
(3) Found Auth-Type = eap
(3) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(3) authenticate {
(3) eap: Expiring EAP session with state 0x82acad7c80afb44f
(3) eap: Finished EAP session with state 0x82acad7c80afb44f
(3) eap: Previous EAP request found for state 0x82acad7c80afb44f, released from the list
(3) eap: Peer sent packet with method EAP PEAP (25)
(3) eap: Calling submodule eap_peap to process data
(3) eap_peap: Continuing EAP-TLS
(3) eap_peap: Peer ACKed our handshake fragment
(3) eap_peap: [eaptls verify] = request
(3) eap_peap: [eaptls process] = handled
(3) eap: Sending EAP Request (code 1) ID 4 length 1000
(3) eap: EAP session adding &reply:State = 0x82acad7c81a8b44f
(3) [eap] = handled
(3) } # authenticate = handled
(3) Using Post-Auth-Type Challenge
(3) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(3) Challenge { ... } # empty sub-section is ignored
(3) Sent Access-Challenge Id 58 from 10.11.12.62:1812 to 10.11.12.207:59118 length 0
(3) EAP-Message = 0x010403e81940e00c0130f60fdb3a84e30232b718cda7dfd99d8a0009344a7d0aaab8a44222621e867adf00060561e7bab8752edacacfb75421af0c740de1d96ed6e33c17566bf3c01ff5dfdffd86210004e8308204e4308203cca00302010202090098fc431c2057d15c300d06092a864886f70d01010b0500308193310b3009060355040613024652310f300d06035504080c065261646975733112301006035504070c09536f6d65776865726531153013060355040a0c0c4578616d706c6520496e632e3120301e06092a864886f70d010901161161646d696e406578616d706c652e6f72673126302406035504030c1d4578616d706c6520436572746966696361746520417574686f72697479301e170d3139303732333138303430365a170d3139303932313138303430365a308193310b3009060355040613024652310f300d06035504080c065261646975733112301006035504070c09536f6d65776865726531153013060355040a0c0c4578616d706c6520
(3) Message-Authenticator = 0x00000000000000000000000000000000
(3) State = 0x82acad7c81a8b44f1bfb0011896e6929
(3) Finished request
Waking up in 4.7 seconds.
(4) Received Access-Request Id 59 from 10.11.12.207:59118 to 10.11.12.62:1812 length 187
(4) User-Name = "ldaps(a)domain.ca"
(4) NAS-IP-Address = 10.11.12.207
(4) NAS-Port = 736
(4) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(4) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(4) Framed-MTU = 1400
(4) NAS-Port-Type = Wireless-802.11
(4) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(4) EAP-Message = 0x020400061900
(4) State = 0x82acad7c81a8b44f1bfb0011896e6929
(4) Message-Authenticator = 0xb084d992c649b97a05c97fdfb2f62a20
(4) session-state: No cached attributes
(4) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(4) authorize {
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) } # if (&User-Name) = notfound
(4) } # policy filter_username = notfound
(4) [preprocess] = ok
(4) [chap] = noop
(4) [mschap] = noop
(4) [digest] = noop
(4) suffix: Checking for suffix after "@"
(4) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(4) suffix: No such realm "domain.ca"
(4) [suffix] = noop
(4) eap: Peer sent EAP Response (code 2) ID 4 length 6
(4) eap: Continuing tunnel setup
(4) [eap] = ok
(4) } # authorize = ok
(4) Found Auth-Type = eap
(4) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(4) authenticate {
(4) eap: Expiring EAP session with state 0x82acad7c81a8b44f
(4) eap: Finished EAP session with state 0x82acad7c81a8b44f
(4) eap: Previous EAP request found for state 0x82acad7c81a8b44f, released from the list
(4) eap: Peer sent packet with method EAP PEAP (25)
(4) eap: Calling submodule eap_peap to process data
(4) eap_peap: Continuing EAP-TLS
(4) eap_peap: Peer ACKed our handshake fragment
(4) eap_peap: [eaptls verify] = request
(4) eap_peap: [eaptls process] = handled
(4) eap: Sending EAP Request (code 1) ID 5 length 691
(4) eap: EAP session adding &reply:State = 0x82acad7c86a9b44f
(4) [eap] = handled
(4) } # authenticate = handled
(4) Using Post-Auth-Type Challenge
(4) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(4) Challenge { ... } # empty sub-section is ignored
(4) Sent Access-Challenge Id 59 from 10.11.12.62:1812 to 10.11.12.207:59118 length 0
(4) EAP-Message = 0x010502b319000530030101ff30360603551d1f042f302d302ba029a0278625687474703a2f2f7777772e6578616d706c652e6f72672f6578616d706c655f63612e63726c300d06092a864886f70d01010b050003820101006a9a75e2b06d30b1eaeb6af5c4d8a5116814657e075512549aa3743f93a75519c31e3b8febea9d9469e1276109955af35889c625c809269e284aba15384456178e4e9d5745102ee103afb61a585cc0c0fed02ca6b4f77dca2bb4aeb90175cb5c3ad253ef65e8a83935b99b73a28645a16efea7a77ddc111a6f116705af07138b79d47d98b1d24d7f19eebccf2b3e6e1fcd9279a53d8fd04a9b9603891e28f04b857dfb80db76fae49bc64394aa4785c33c75913511d2ceeb37c21a0a43fe71ae7bf636ec6091fe3ee5b2ba5168da85bec24180e490fdb177e4e66b9daa582f85da7e5de9e4740b0a5bf4c8c75de74366a49db297ff94956348532ff761956e2a160303014d0c000149030017410462e227dd5aadf67578111bb4e86daf5721
(4) Message-Authenticator = 0x00000000000000000000000000000000
(4) State = 0x82acad7c86a9b44f1bfb0011896e6929
(4) Finished request
Waking up in 4.7 seconds.
(5) Received Access-Request Id 60 from 10.11.12.207:59118 to 10.11.12.62:1812 length 317
(5) User-Name = "ldaps(a)domain.ca"
(5) NAS-IP-Address = 10.11.12.207
(5) NAS-Port = 736
(5) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(5) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(5) Framed-MTU = 1400
(5) NAS-Port-Type = Wireless-802.11
(5) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(5) EAP-Message = 0x0205008819800000007e16030300461000004241044e2a5405204c749624ab5743557771b8894447e81ab936ac1105631fdcaba7312ab78292caaa799084eb74031555a236f5b538768cfe422432a179f8b0e4e0161403030001011603030028e55213cc96d61f81d907a32a1ce9327ae5a6d68702b6e3af3fd834369983c644795ada796dc5738f
(5) State = 0x82acad7c86a9b44f1bfb0011896e6929
(5) Message-Authenticator = 0xd83517b1c089a67af74981323141225b
(5) session-state: No cached attributes
(5) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(5) authorize {
(5) policy filter_username {
(5) if (&User-Name) {
(5) if (&User-Name) -> TRUE
(5) if (&User-Name) {
(5) if (&User-Name =~ / /) {
(5) if (&User-Name =~ / /) -> FALSE
(5) if (&User-Name =~ /@[^@]*@/ ) {
(5) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(5) if (&User-Name =~ /\.\./ ) {
(5) if (&User-Name =~ /\.\./ ) -> FALSE
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(5) if (&User-Name =~ /\.$/) {
(5) if (&User-Name =~ /\.$/) -> FALSE
(5) if (&User-Name =~ /(a)\./) {
(5) if (&User-Name =~ /(a)\./) -> FALSE
(5) } # if (&User-Name) = notfound
(5) } # policy filter_username = notfound
(5) [preprocess] = ok
(5) [chap] = noop
(5) [mschap] = noop
(5) [digest] = noop
(5) suffix: Checking for suffix after "@"
(5) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(5) suffix: No such realm "domain.ca"
(5) [suffix] = noop
(5) eap: Peer sent EAP Response (code 2) ID 5 length 136
(5) eap: Continuing tunnel setup
(5) [eap] = ok
(5) } # authorize = ok
(5) Found Auth-Type = eap
(5) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(5) authenticate {
(5) eap: Expiring EAP session with state 0x82acad7c86a9b44f
(5) eap: Finished EAP session with state 0x82acad7c86a9b44f
(5) eap: Previous EAP request found for state 0x82acad7c86a9b44f, released from the list
(5) eap: Peer sent packet with method EAP PEAP (25)
(5) eap: Calling submodule eap_peap to process data
(5) eap_peap: Continuing EAP-TLS
(5) eap_peap: Peer indicated complete TLS record size will be 126 bytes
(5) eap_peap: Got complete TLS record (126 bytes)
(5) eap_peap: [eaptls verify] = length included
(5) eap_peap: <<< recv TLS 1.2 [length 0046]
(5) eap_peap: TLS_accept: unknown state
(5) eap_peap: TLS_accept: unknown state
(5) eap_peap: <<< recv TLS 1.2 [length 0001]
(5) eap_peap: <<< recv TLS 1.2 [length 0010]
(5) eap_peap: TLS_accept: unknown state
(5) eap_peap: >>> send TLS 1.2 [length 0001]
(5) eap_peap: TLS_accept: unknown state
(5) eap_peap: >>> send TLS 1.2 [length 0010]
(5) eap_peap: TLS_accept: unknown state
(5) eap_peap: TLS_accept: unknown state
(5) eap_peap: (other): SSL negotiation finished successfully
(5) eap_peap: TLS - Connection Established
(5) eap_peap: TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(5) eap_peap: TLS-Session-Version = "TLS 1.2"
(5) eap_peap: TLS - got 51 bytes of data
(5) eap_peap: [eaptls process] = handled
(5) eap: Sending EAP Request (code 1) ID 6 length 57
(5) eap: EAP session adding &reply:State = 0x82acad7c87aab44f
(5) [eap] = handled
(5) } # authenticate = handled
(5) Using Post-Auth-Type Challenge
(5) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(5) Challenge { ... } # empty sub-section is ignored
(5) session-state: Saving cached attributes
(5) TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(5) TLS-Session-Version = "TLS 1.2"
(5) Sent Access-Challenge Id 60 from 10.11.12.62:1812 to 10.11.12.207:59118 length 0
(5) EAP-Message = 0x0106003919001403030001011603030028e0cda00b6a448a56ed39cd795dbd504f1b7ed97f26645577169999a2a82878b014797a35667560d6
(5) Message-Authenticator = 0x00000000000000000000000000000000
(5) State = 0x82acad7c87aab44f1bfb0011896e6929
(5) Finished request
Waking up in 4.7 seconds.
(6) Received Access-Request Id 61 from 10.11.12.207:59118 to 10.11.12.62:1812 length 187
(6) User-Name = "ldaps(a)domain.ca"
(6) NAS-IP-Address = 10.11.12.207
(6) NAS-Port = 736
(6) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(6) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(6) Framed-MTU = 1400
(6) NAS-Port-Type = Wireless-802.11
(6) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(6) EAP-Message = 0x020600061900
(6) State = 0x82acad7c87aab44f1bfb0011896e6929
(6) Message-Authenticator = 0x640d37eed321b5aa62c0e07e2618caff
(6) Restoring &session-state
(6) &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(6) &session-state:TLS-Session-Version = "TLS 1.2"
(6) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(6) authorize {
(6) policy filter_username {
(6) if (&User-Name) {
(6) if (&User-Name) -> TRUE
(6) if (&User-Name) {
(6) if (&User-Name =~ / /) {
(6) if (&User-Name =~ / /) -> FALSE
(6) if (&User-Name =~ /@[^@]*@/ ) {
(6) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(6) if (&User-Name =~ /\.\./ ) {
(6) if (&User-Name =~ /\.\./ ) -> FALSE
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(6) if (&User-Name =~ /\.$/) {
(6) if (&User-Name =~ /\.$/) -> FALSE
(6) if (&User-Name =~ /(a)\./) {
(6) if (&User-Name =~ /(a)\./) -> FALSE
(6) } # if (&User-Name) = notfound
(6) } # policy filter_username = notfound
(6) [preprocess] = ok
(6) [chap] = noop
(6) [mschap] = noop
(6) [digest] = noop
(6) suffix: Checking for suffix after "@"
(6) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(6) suffix: No such realm "domain.ca"
(6) [suffix] = noop
(6) eap: Peer sent EAP Response (code 2) ID 6 length 6
(6) eap: Continuing tunnel setup
(6) [eap] = ok
(6) } # authorize = ok
(6) Found Auth-Type = eap
(6) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(6) authenticate {
(6) eap: Expiring EAP session with state 0x82acad7c87aab44f
(6) eap: Finished EAP session with state 0x82acad7c87aab44f
(6) eap: Previous EAP request found for state 0x82acad7c87aab44f, released from the list
(6) eap: Peer sent packet with method EAP PEAP (25)
(6) eap: Calling submodule eap_peap to process data
(6) eap_peap: Continuing EAP-TLS
(6) eap_peap: Peer ACKed our handshake fragment. handshake is finished
(6) eap_peap: [eaptls verify] = success
(6) eap_peap: [eaptls process] = success
(6) eap_peap: Session established. Decoding tunneled attributes
(6) eap_peap: PEAP state TUNNEL ESTABLISHED
(6) eap: Sending EAP Request (code 1) ID 7 length 40
(6) eap: EAP session adding &reply:State = 0x82acad7c84abb44f
(6) [eap] = handled
(6) } # authenticate = handled
(6) Using Post-Auth-Type Challenge
(6) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(6) Challenge { ... } # empty sub-section is ignored
(6) session-state: Saving cached attributes
(6) TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(6) TLS-Session-Version = "TLS 1.2"
(6) Sent Access-Challenge Id 61 from 10.11.12.62:1812 to 10.11.12.207:59118 length 0
(6) EAP-Message = 0x010700281900170303001de0cda00b6a448a57f0cba2e144a2103493fda50453cc6de21c896c4b85
(6) Message-Authenticator = 0x00000000000000000000000000000000
(6) State = 0x82acad7c84abb44f1bfb0011896e6929
(6) Finished request
Waking up in 4.7 seconds.
(7) Received Access-Request Id 62 from 10.11.12.207:59118 to 10.11.12.62:1812 length 240
(7) User-Name = "ldaps(a)domain.ca"
(7) NAS-IP-Address = 10.11.12.207
(7) NAS-Port = 736
(7) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(7) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(7) Framed-MTU = 1400
(7) NAS-Port-Type = Wireless-802.11
(7) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(7) EAP-Message = 0x0207003b19001703030030e55213cc96d61f8273f8db4f99f175e3fac2195247dae9cca274fb3182542f50a5c4d6d5ac946e82d1bad337d66e8eff
(7) State = 0x82acad7c84abb44f1bfb0011896e6929
(7) Message-Authenticator = 0x868a63fa3da822ea71589759443a8a06
(7) Restoring &session-state
(7) &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(7) &session-state:TLS-Session-Version = "TLS 1.2"
(7) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(7) authorize {
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = notfound
(7) } # policy filter_username = notfound
(7) [preprocess] = ok
(7) [chap] = noop
(7) [mschap] = noop
(7) [digest] = noop
(7) suffix: Checking for suffix after "@"
(7) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(7) suffix: No such realm "domain.ca"
(7) [suffix] = noop
(7) eap: Peer sent EAP Response (code 2) ID 7 length 59
(7) eap: Continuing tunnel setup
(7) [eap] = ok
(7) } # authorize = ok
(7) Found Auth-Type = eap
(7) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(7) authenticate {
(7) eap: Expiring EAP session with state 0x82acad7c84abb44f
(7) eap: Finished EAP session with state 0x82acad7c84abb44f
(7) eap: Previous EAP request found for state 0x82acad7c84abb44f, released from the list
(7) eap: Peer sent packet with method EAP PEAP (25)
(7) eap: Calling submodule eap_peap to process data
(7) eap_peap: Continuing EAP-TLS
(7) eap_peap: [eaptls verify] = ok
(7) eap_peap: Done initial handshake
(7) eap_peap: [eaptls process] = ok
(7) eap_peap: Session established. Decoding tunneled attributes
(7) eap_peap: PEAP state WAITING FOR INNER IDENTITY
(7) eap_peap: Identity - ldaps(a)domain.ca
(7) eap_peap: Got inner identity 'ldaps(a)domain.ca'
(7) eap_peap: Setting default EAP type for tunneled EAP session
(7) eap_peap: Got tunneled request
(7) eap_peap: EAP-Message = 0x0207001c016c64617073406b696e677363687269737469616e2e6361
(7) eap_peap: Setting User-Name to ldaps(a)domain.ca
(7) eap_peap: Sending tunneled request to inner-tunnel
(7) eap_peap: EAP-Message = 0x0207001c016c64617073406b696e677363687269737469616e2e6361
(7) eap_peap: FreeRADIUS-Proxied-To = 127.0.0.1
(7) eap_peap: User-Name = "ldaps(a)domain.ca"
(7) Virtual server inner-tunnel received request
(7) EAP-Message = 0x0207001c016c64617073406b696e677363687269737469616e2e6361
(7) FreeRADIUS-Proxied-To = 127.0.0.1
(7) User-Name = "ldaps(a)domain.ca"
(7) WARNING: Outer and inner identities are the same. User privacy is compromised.
(7) server inner-tunnel {
(7) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/inner-tunnel
(7) authorize {
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = notfound
(7) } # policy filter_username = notfound
(7) [chap] = noop
(7) [mschap] = noop
(7) suffix: Checking for suffix after "@"
(7) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(7) suffix: No such realm "domain.ca"
(7) [suffix] = noop
(7) update control {
(7) &Proxy-To-Realm := LOCAL
(7) } # update control = noop
(7) [files] = noop
rlm_ldap (ldap): Reserved connection (1)
(7) ldap: EXPAND (userPrincipalName=%{%{Stripped-User-Name}:-%{User-Name}})
(7) ldap: --> (userPrincipalName=ldaps(a)domain.ca)
(7) ldap: Performing search in "OU=AADDC Users,DC=domain,DC=ca" with filter "(userPrincipalName=ldaps(a)domain.ca)", scope "sub"
(7) ldap: Waiting for search result...
(7) ldap: User object found at DN "CN=LDAPS,OU=AADDC Users,DC=domain,DC=ca"
(7) ldap: Processing user attributes
(7) ldap: WARNING: No "known good" password added. Ensure the admin user has permission to read the password attribute
(7) ldap: WARNING: PAP authentication will *NOT* work with Active Directory (if that is what you were trying to configure)
rlm_ldap (ldap): Released connection (1)
(7) [ldap] = ok
(7) [expiration] = noop
(7) [logintime] = noop
(7) [pap] = noop
(7) if (noop && User-Password) {
(7) if (noop && User-Password) -> FALSE
(7) } # authorize = ok
(7) ERROR: No Auth-Type found: rejecting the user via Post-Auth-Type = Reject
(7) Failed to authenticate the user
(7) Using Post-Auth-Type Reject
(7) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/inner-tunnel
(7) Post-Auth-Type REJECT {
(7) attr_filter.access_reject: EXPAND %{User-Name}
(7) attr_filter.access_reject: --> ldaps(a)domain.ca
(7) attr_filter.access_reject: Matched entry DEFAULT at line 11
(7) [attr_filter.access_reject] = updated
(7) update outer.session-state {
(7) &Module-Failure-Message := &request:Module-Failure-Message -> 'No Auth-Type found: rejecting the user via Post-Auth-Type = Reject'
(7) } # update outer.session-state = noop
(7) } # Post-Auth-Type REJECT = updated
(7) } # server inner-tunnel
(7) Virtual server sending reply
(7) eap_peap: Got tunneled reply code 3
(7) eap_peap: Got tunneled reply RADIUS code 3
(7) eap_peap: Tunneled authentication was rejected
(7) eap_peap: FAILURE
(7) eap: Sending EAP Request (code 1) ID 8 length 46
(7) eap: EAP session adding &reply:State = 0x82acad7c85a4b44f
(7) [eap] = handled
(7) } # authenticate = handled
(7) Using Post-Auth-Type Challenge
(7) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(7) Challenge { ... } # empty sub-section is ignored
(7) session-state: Saving cached attributes
(7) TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(7) TLS-Session-Version = "TLS 1.2"
(7) Module-Failure-Message := "No Auth-Type found: rejecting the user via Post-Auth-Type = Reject"
(7) Sent Access-Challenge Id 62 from 10.11.12.62:1812 to 10.11.12.207:59118 length 0
(7) EAP-Message = 0x0108002e19001703030023e0cda00b6a448a58373ab699fedf00aa2c781b582a7df63ce8e090a5ad3c7a71069e29
(7) Message-Authenticator = 0x00000000000000000000000000000000
(7) State = 0x82acad7c85a4b44f1bfb0011896e6929
(7) Finished request
Waking up in 4.7 seconds.
(8) Received Access-Request Id 63 from 10.11.12.207:59118 to 10.11.12.62:1812 length 227
(8) User-Name = "ldaps(a)domain.ca"
(8) NAS-IP-Address = 10.11.12.207
(8) NAS-Port = 736
(8) Called-Station-Id = "50-60-28-5A-23-F7:RADIUS"
(8) Calling-Station-Id = "5C-F7-E6-30-B3-2E"
(8) Framed-MTU = 1400
(8) NAS-Port-Type = Wireless-802.11
(8) Connect-Info = "CONNECT 6Mbps/6Mbps 802.11a"
(8) EAP-Message = 0x0208002e19001703030023e55213cc96d61f8324ff2b4fdca0a00061bbed2c04d869f30da768cd9b19b1ecc9e6a7
(8) State = 0x82acad7c85a4b44f1bfb0011896e6929
(8) Message-Authenticator = 0x1e760f2cdb7366845fa2ce36101be0ed
(8) Restoring &session-state
(8) &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(8) &session-state:TLS-Session-Version = "TLS 1.2"
(8) &session-state:Module-Failure-Message := "No Auth-Type found: rejecting the user via Post-Auth-Type = Reject"
(8) # Executing section authorize from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(8) authorize {
(8) policy filter_username {
(8) if (&User-Name) {
(8) if (&User-Name) -> TRUE
(8) if (&User-Name) {
(8) if (&User-Name =~ / /) {
(8) if (&User-Name =~ / /) -> FALSE
(8) if (&User-Name =~ /@[^@]*@/ ) {
(8) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(8) if (&User-Name =~ /\.\./ ) {
(8) if (&User-Name =~ /\.\./ ) -> FALSE
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(8) if (&User-Name =~ /\.$/) {
(8) if (&User-Name =~ /\.$/) -> FALSE
(8) if (&User-Name =~ /(a)\./) {
(8) if (&User-Name =~ /(a)\./) -> FALSE
(8) } # if (&User-Name) = notfound
(8) } # policy filter_username = notfound
(8) [preprocess] = ok
(8) [chap] = noop
(8) [mschap] = noop
(8) [digest] = noop
(8) suffix: Checking for suffix after "@"
(8) suffix: Looking up realm "domain.ca" for User-Name = "ldaps(a)domain.ca"
(8) suffix: No such realm "domain.ca"
(8) [suffix] = noop
(8) eap: Peer sent EAP Response (code 2) ID 8 length 46
(8) eap: Continuing tunnel setup
(8) [eap] = ok
(8) } # authorize = ok
(8) Found Auth-Type = eap
(8) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(8) authenticate {
(8) eap: Expiring EAP session with state 0x82acad7c85a4b44f
(8) eap: Finished EAP session with state 0x82acad7c85a4b44f
(8) eap: Previous EAP request found for state 0x82acad7c85a4b44f, released from the list
(8) eap: Peer sent packet with method EAP PEAP (25)
(8) eap: Calling submodule eap_peap to process data
(8) eap_peap: Continuing EAP-TLS
(8) eap_peap: [eaptls verify] = ok
(8) eap_peap: Done initial handshake
(8) eap_peap: [eaptls process] = ok
(8) eap_peap: Session established. Decoding tunneled attributes
(8) eap_peap: PEAP state send tlv failure
(8) eap_peap: Received EAP-TLV response
(8) eap_peap: ERROR: The users session was previously rejected: returning reject (again.)
(8) eap_peap: This means you need to read the PREVIOUS messages in the debug output
(8) eap_peap: to find out the reason why the user was rejected
(8) eap_peap: Look for "reject" or "fail". Those earlier messages will tell you
(8) eap_peap: what went wrong, and how to fix the problem
(8) eap: ERROR: Failed continuing EAP PEAP (25) session. EAP sub-module failed
(8) eap: Sending EAP Failure (code 4) ID 8 length 4
(8) eap: Failed in EAP select
(8) [eap] = invalid
(8) } # authenticate = invalid
(8) Failed to authenticate the user
(8) Using Post-Auth-Type Reject
(8) # Executing group from file /usr/local/Cellar/freeradius-server/3.0.19/etc/raddb/sites-enabled/default
(8) Post-Auth-Type REJECT {
(8) attr_filter.access_reject: EXPAND %{User-Name}
(8) attr_filter.access_reject: --> ldaps(a)domain.ca
(8) attr_filter.access_reject: Matched entry DEFAULT at line 11
(8) [attr_filter.access_reject] = updated
(8) [eap] = noop
(8) policy remove_reply_message_if_eap {
(8) if (&reply:EAP-Message && &reply:Reply-Message) {
(8) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(8) else {
(8) [noop] = noop
(8) } # else = noop
(8) } # policy remove_reply_message_if_eap = noop
(8) } # Post-Auth-Type REJECT = updated
(8) Delaying response for 1.000000 seconds
Waking up in 0.3 seconds.
Waking up in 0.6 seconds.
(8) Sending delayed response
(8) Sent Access-Reject Id 63 from 10.11.12.62:1812 to 10.11.12.207:59118 length 44
(8) EAP-Message = 0x04080004
(8) Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 3.7 seconds.
(0) Cleaning up request packet ID 55 with timestamp +16
(1) Cleaning up request packet ID 56 with timestamp +16
(2) Cleaning up request packet ID 57 with timestamp +16
(3) Cleaning up request packet ID 58 with timestamp +16
(4) Cleaning up request packet ID 59 with timestamp +16
(5) Cleaning up request packet ID 60 with timestamp +16
(6) Cleaning up request packet ID 61 with timestamp +16
(7) Cleaning up request packet ID 62 with timestamp +16
(8) Cleaning up request packet ID 63 with timestamp +16
Ready to process requests
3
4
Hello,
any ETA on Buster package?
Regards
Marek
4
3
22 Jul '19
Hi
I have an (OpenLDAP-based) directory that sets a specific attribute
(univentionNetworkAccess) on either the user or the group based on which
network Access is being granted. (1 means you are permitted, 0 or access
of that attribtue indicates no access)
I think this is where using access_attribute wouldn't work, as it is
only defined in the users section but not groups - right?
Additionnaly access should also only be granted if certain other
Attributes have specific values (such as sambaAcctFlags, meaning if a
user is locked or disabled).
I'm looking into where this could be configured in the most meaningful
way without adding to many chunks of custom logic to the default
configuration... as in my experience staying close to the default config
usually helps avoiding stupid errors...
So far I've thought about mapping these attributes from LDAP to FR and
then using unlang statements in post-auth for example to check for each
condition.
Q: How could I map attributes from LDAP groups to FreeRADIUS?
(I've only ever done this with user attributes)
(Somewhat similar as to what a guy asked in 2016:
http://lists.freeradius.org/pipermail/freeradius-users/2016-August/084450.h…)
If all attributes are mappable to FreeRADIUS using unlang, making
conditions in the post-auth section would look possible ... right?
Or would it be better to modify the LDAP "filter =" statemens of the
ldap module in the user{ } and group{ } sections with the required
attributes ? (likely ending up in somewhat clunky LDAP queries)
Regards
Mathieu
2
2
Hello,Please can any one tell me how to configure linelog module for accounting start stop interim update i would like to use it instead of detail module i have changed log format for accounting to be in one line instead of multiline and i would like to send accounting log to syslog serverI appreciate your helpThanksBassemEnvoyé depuis mon smartphone Samsung Galaxy.
4
5
List,
Anyone see this before?
My radius server is plugging away doing it's job, then suddenly I get this:
Sun Jul 7 10:37:47 2019 : Error: Received conflicting packet from
client 2.3.23.90 port 53874 - ID: 119 due to unfinished request. Giving
up on old request.
Sun Jul 7 10:37:50 2019 : Error: Received conflicting packet from
client 2.3.23.90 port 53874 - ID: 119 due to unfinished request. Giving
up on old request.
Sun Jul 7 10:37:53 2019 : Error: Received conflicting packet from
client 2.3.22.14 port 39039 - ID: 36 due to unfinished request. Giving
up on old request.
Sun Jul 7 10:37:56 2019 : Error: Received conflicting packet from
client 2.3.22.14 port 39039 - ID: 36 due to unfinished request. Giving
up on old request.
Sun Jul 7 10:37:56 2019 : Error: Received conflicting packet from
client 2.3.22.9 port 46417 - ID: 203 due to unfinished request. Giving
up on old request.
Sun Jul 7 10:37:57 2019 : Error: Received conflicting packet from
client 2.3.23.75 port 57383 - ID: 228 due to unfinished request. Giving
up on old request.
Now, I know that's normally because my underlying stack isn't returning
fast enough, but in this case I never again see a working radius request
until a restart, and my secondary radius server which relies on the same
stack works just fine. The primary continued for a few hours recording
nothing but logs like above, until it hit the max queue then
transitioned to:
Sun Jul 7 12:52:26 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:26 2019 : Error: (18606025) Ignoring duplicate packet
from client 2.3.9.250 port 59296 - ID: 120 due to unfinished request in
component <core> module <queue>
Sun Jul 7 12:52:27 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:28 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:29 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:30 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:30 2019 : Error: (18606051) Ignoring duplicate packet
from client 2.3.9.241 port 32851 - ID: 126 due to unfinished request in
component <core> module <queue>
Sun Jul 7 12:52:30 2019 : Error: (18606052) Ignoring duplicate packet
from client 2.3.9.236 port 44942 - ID: 179 due to unfinished request in
component <core> module <queue>
Sun Jul 7 12:52:30 2019 : Error: (18606053) Ignoring duplicate packet
from client 2.3.9.236 port 42423 - ID: 180 due to unfinished request in
component <core> module <queue>
Sun Jul 7 12:52:31 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:32 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:33 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:34 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:35 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:36 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Sun Jul 7 12:52:37 2019 : Error: Something is blocking the server.
There are 65536 packets in the queue, waiting to be processed. Ignoring
the new request.
Then nothing but this until I had to kill -9 the process.
The underlying stack is an ldap and sql lookup. Both of those systems
are well indexed with care taken to make sure they return quickly. In
fact, once I restarted the radiusd daemon, I was able to immediately
authenticate very quickly:
$ time radtest user password localhost:1645 1 naspassword
Sent Access-Request Id 187 from 0.0.0.0:47859 to 127.0.0.1:1645 length 76
User-Name = "user"
User-Password = "password"
NAS-IP-Address = 192.168.103.7
NAS-Port = 1
Message-Authenticator = 0x00
Cleartext-Password = "password"
Received Access-Accept Id 187 from 127.0.0.1:1645 to 127.0.0.1:47859
length 57
Service-Type = Framed-User
Framed-Protocol = PPP
Framed-MTU = 1492
real 0m0.035s
user 0m0.017s
sys 0m0.009s
Seems that starting up radtest, making a connection, asking,
authenticating, and closing out in 35ms is fast enough.
I'm about to upgrade to 3.0.19, but generally don't like the guess and
check method. Any reason to believe that this is a bug and if it's been
fixed?
schu
3
7