Freeradius-Users
Threads by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 27050 discussions
Hi,
I'm setting up a freeradius cluster, and my question would be what to do
best.
Have mysql and freeradius on different servers (for example 2 freeradius
servers and three mysql (galera) servers) or just three freeradius+mysql
servers.
Thank you.
3
2
Hello everyone!
We're suddenly having issues where Freeradius will not start. doing
freeradius -X shows the list below the line.
Any ideas to help us get it working again? We set it up using an
install guide so, we are very much newbs at using Freeradius.
Thanks! =)
FreeRADIUS Version 3.0.15
Copyright (C) 1999-2017 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/freeradius/dictionary
including configuration file /etc/freeradius/radiusd.conf
including configuration file /etc/freeradius/clients.conf
including files in directory /etc/freeradius/mods-enabled/
including configuration file /etc/freeradius/mods-enabled/detail
including configuration file /etc/freeradius/mods-enabled/expr
including configuration file /etc/freeradius/mods-enabled/replicate
including configuration file /etc/freeradius/mods-enabled/soh
including configuration file /etc/freeradius/mods-enabled/unpack
including configuration file /etc/freeradius/mods-enabled/attr_filter
including configuration file /etc/freeradius/mods-enabled/digest
including configuration file /etc/freeradius/mods-enabled/passwd
including configuration file /etc/freeradius/mods-enabled/chap
including configuration file /etc/freeradius/mods-enabled/date
including configuration file
/etc/freeradius/mods-enabled/dynamic_clients
including configuration file /etc/freeradius/mods-enabled/sradutmp
including configuration file /etc/freeradius/mods-enabled/unix
including configuration file /etc/freeradius/mods-enabled/files
including configuration file /etc/freeradius/mods-enabled/detail.log
including configuration file /etc/freeradius/mods-enabled/ntlm_auth
including configuration file /etc/freeradius/mods-enabled/eap
including configuration file /etc/freeradius/mods-enabled/always
including configuration file /etc/freeradius/mods-enabled/utf8
including configuration file /etc/freeradius/mods-enabled/pap
including configuration file /etc/freeradius/mods-enabled/exec
including configuration file /etc/freeradius/mods-enabled/realm
including configuration file /etc/freeradius/mods-enabled/radutmp
including configuration file /etc/freeradius/mods-enabled/linelog
including configuration file /etc/freeradius/mods-enabled/logintime
including configuration file /etc/freeradius/mods-enabled/echo
including configuration file /etc/freeradius/mods-enabled/cache_eap
including configuration file /etc/freeradius/mods-enabled/mschap
including configuration file /etc/freeradius/mods-enabled/preprocess
including configuration file /etc/freeradius/mods-enabled/expiration
including files in directory /etc/freeradius/policy.d/
including configuration file /etc/freeradius/policy.d/accounting
including configuration file /etc/freeradius/policy.d/filter
including configuration file /etc/freeradius/policy.d/control
including configuration file /etc/freeradius/policy.d/debug
including configuration file
/etc/freeradius/policy.d/moonshot-targeted-ids
including configuration file /etc/freeradius/policy.d/eap
including configuration file /etc/freeradius/policy.d/cui
including configuration file /etc/freeradius/policy.d/operator-name
including configuration file /etc/freeradius/policy.d/dhcp
including configuration file /etc/freeradius/policy.d/abfab-tr
including configuration file /etc/freeradius/policy.d/canonicalization
including files in directory /etc/freeradius/sites-enabled/
including configuration file
/etc/freeradius/sites-enabled/inner-tunnel
including configuration file /etc/freeradius/sites-enable
d/mynetwork
including configuration file /etc/freeradius/sites-enabled/default
main {
security {
user = "freerad"
group = "freerad"
allow_core_dumps = no
}
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
}
main {
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
libdir = "/usr/lib/freeradius"
radacctdir = "/var/log/freeradius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
pidfile = "/var/run/freeradius/freeradius.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = no
log {
stripped_names = no
auth = yes
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client iscwifi {
ipaddr = 10.125.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client adminwifi {
ipaddr = 10.126.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client tmwifi {
ipaddr = 10.127.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client mcdwifi {
ipaddr = 10.128.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client johnsonwifi {
ipaddr = 10.129.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client eastwifi {
ipaddr = 10.130.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client northwifi {
ipaddr = 10.131.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client centwifi {
ipaddr = 10.132.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client nsidewifi {
ipaddr = 10.133.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client cliftywifi {
ipaddr = 10.134.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client csafwifi {
ipaddr = 10.135.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client csalwifi {
ipaddr = 10.136.0.0/16
require_message_
authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client mthwifi {
ipaddr = 10.137.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client psidewifi {
ipaddr = 10.138.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client richwifi {
ipaddr = 10.139.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client rockwifi {
ipaddr = 10.140.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client schmittwifi {
ipaddr = 10.141.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client smithwifi {
ipaddr = 10.142.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client ssidewifi {
ipaddr = 10.143.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client tvillewifi {
ipaddr = 10.144.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client csahwifi {
ipaddr = 10.145.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client Restartwifi {
ipaddr = 10.146.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client CBCwifi {
ipaddr = 10.149.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client centlan {
ipaddr = 10.9.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client eastlan {
ipaddr = 10.15.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client northlan {
ipaddr = 10.17.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client mcdlan {
ipaddr = 10.18.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client cliftylan {
ipaddr = 10.28.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client csallan {
ipaddr = 10.45.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client johnsonlan {
ipaddr = 10.50.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client nsidelan {
ipaddr = 10.53.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client mthlan {
ipaddr = 10.54.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client psidelan {
ipaddr = 10.57.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client richlan {
ipaddr = 10.63.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client rocklan {
ipaddr = 10.66.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client schmittlan {
ipaddr = 10.69.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client smithlan {
ipaddr = 10.71.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client csaflan {
ipaddr = 10.74.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client csahlan {
ipaddr = 10.75.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client tvillelan {
ipaddr = 10.77.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client ssidelan {
ipaddr = 10.92.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client tmlan {
ipaddr = 10.96.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client adminlan {
ipaddr = 10.98.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client isclan {
ipaddr = 10.101.0.0/16
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
# Creating Auth-Type = mschap
# Creating Auth-Type = eap
# Creating Auth-Type = PAP
# Creating Auth-Type = CHAP
# Creating Auth-Type = MS-CHAP
# Creating Auth-Type = digest
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_detail
# Loading module "detail" from file
/etc/freeradius/mods-enabled/detail
detail {
filename =
"/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_expr
# Loading module "expr" from file /etc/freeradius/mods-enabled/expr
expr {
safe_characters =
"@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_:
/äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loaded module rlm_replicate
# Loading module "replicate" from file
/etc/freeradius/mods-enabled/replicate
# Loaded module rlm_soh
# Loading module "soh" from file /etc/freeradius/mods-enabled/soh
soh {
dhcp = yes
}
# Loaded module rlm_unpack
# Loading module "unpack" from file
/etc/freeradius/mods-enabled/unpack
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file
/etc/freeradius/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename =
"/etc/freeradius/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file
/etc/freeradius/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename =
"/etc/freeradius/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file
/etc/freeradius/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename =
"/etc/freeradius/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file
/etc/freeradius/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename =
"/etc/freeradius/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file
/etc/freeradius/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename =
"/etc/freeradius/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loaded module rlm_digest
# Loading module "digest" from file
/etc/freeradius/mods-enabled/digest
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file
/etc/freeradius/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loaded module rlm_chap
# Loading module "chap" from file /etc/freeradius/mods-enabled/chap
# Loaded module rlm_date
# Loading module "date" from file /etc/freeradius/mods-enabled/date
date {
format = "%b %e %Y %H:%M:%S %Z"
utc = no
}
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file
/etc/freeradius/mods-enabled/dynamic_clients
# Loaded module rlm_radutmp
# Loading module "sradutmp" from file
/etc/freeradius/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/freeradius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_unix
# Loading module "unix" from file /etc/freeradius/mods-enabled/unix
unix {
radwtmp = "/var/log/freeradius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_files
# Loading module "files" from file
/etc/freeradius/mods-enabled/files
files {
filename = "/etc/freeradius/mods-config/files/authorize"
acctusersfile =
"/etc/freeradius/mods-config/files/accounting"
preproxy_usersfile =
"/etc/freeradius/mods-config/files/pre-proxy"
}
# Loading module "auth_log" from file
/etc/freeradius/mods-enabled/detail.log
detail auth_log {
filename =
"/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file
/etc/freeradius/mods-enabled/detail.log
detail reply_log {
filename =
"/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file
/etc/freeradius/mods-enabled/detail.log
detail pre_proxy_log {
filename =
"/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file
/etc/freeradius
/mods-enabled/detail.log
detail post_proxy_log {
filename =
"/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_exec
# Loading module "ntlm_auth" from file
/etc/freeradius/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key
--domain=MYDOMAIN --username=%{mschap:User-Name}
--password=%{User-Password}"
shell_escape = yes
}
# Loaded module rlm_eap
# Loading module "eap" from file /etc/freeradius/mods-enabled/eap
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_always
# Loading module "reject" from file
/etc/freeradius/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file
/etc/freeradius/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /etc/freeradius/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file
/etc/freeradius/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file
/etc/freeradius/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file
/etc/freeradius/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file
/etc/freeradius/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file
/etc/freeradius/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file
/etc/freeradius/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_utf8
# Loading module "utf8" from file /etc/freeradius/mods-enabled/utf8
# Loaded module rlm_pap
# Loading module "pap" from file /etc/freeradius/mods-enabled/pap
pap {
normalise = yes
}
# Loading module "exec" from file /etc/freeradius/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_realm
# Loading module "IPASS" from file
/etc/freeradius/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file
/etc/freeradius/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file
/etc/freeradius/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file
/etc/freeradius/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loading module "radutmp" from file
/etc/freeradius/mods-enabled/radutmp
radutmp {
filename = "/var/log/freeradius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_linelog
# Loading module "linelog" from file
/etc/freeradius/mods-enabled/linelog
linelog {
filename = "/var/log/freeradius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file
/etc/freeradius/mods-enabled/linelog
linelog log_accounting {
filename = "/var/log/freeradius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference =
"Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_logintime
# Loading module "logintime" from file
/etc/freeradius/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loading module "echo" from file /etc/freeradius/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loaded module rlm_cache
# Loading module "cache_eap" from file
/etc/freeradius/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_mschap
# Loading module "mschap" from file
/etc/freeradius/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
winbind_retry_with_normalised_username = no
}
# Loaded module rlm_preprocess
# Loading module "preprocess" from file
/etc/freeradius/mods-enabled/preprocess
preprocess {
huntgroups =
"/etc/freeradius/mods-config/preprocess/huntgroups"
hints = "/etc/freeradius/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loaded module rlm_expiration
# Loading module "expiration" from file
/etc/freeradius/mods-enabled/expiration
instantiate {
}
# Instantiating module "detail" from file
/etc/freeradius/mods-enabled/detail
# Instantiating module "attr_filter.post-proxy" from file
/etc/freeradius/mods-enabled/attr_filter
reading pairlist file
/etc/freeradius/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file
/etc/freeradius/mods-enabled/attr_filter
reading pairlist file
/etc/freeradius/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file
/etc/freeradius/mods-enabled/attr_filter
reading pairlist file
/etc/freeradius/mods-config/attr_filter/access_reject
[/etc/freeradius/mods-config/attr_filter/access_reject]:11 Check item
"FreeRADIUS-Response-Delay" found in filter list for realm
"DEFAULT".
[/etc/freeradius/mods-config/attr_filter/access_reject]:11 Check item
"FreeRADIUS-Response-Delay-USec" found in filter list for realm
"DEFAULT".
# Instantiating module "attr_filter.access_challenge" from file
/etc/freeradius/mods-enabled/attr_filter
reading pairlist file
/etc/freeradius/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file
/etc/freeradius/mods-enabled/attr_filter
reading pairlist file
/etc/freeradius/mods-config/attr_filter/accounting_response
# Instantiating module "etc_passwd" from file
/etc/freeradius/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "files" from file
/etc/freeradius/mods-enabled/files
reading pairlist file /etc/freeradius/mods-config/files/authorize
reading pairlist file /etc/freeradius/mods-config/files/accounting
reading pairlist file /etc/freeradius/mods-config/files/pre-proxy
# Instantiating module "auth_log" from file
/etc/freeradius/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in
detail output
# Instantiating module "reply_log" from file
/etc/freeradius/mods-enabled/detai
l.log
# Instantiating module "pre_proxy_log" from file
/etc/freeradius/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file
/etc/freeradius/mods-enabled/detail.log
# Instantiating module "eap" from file
/etc/freeradius/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/freeradius/certs"
pem_file_type = yes
private_key_file = "/etc/freeradius/certs/server.pem"
certificate_file = "/etc/freeradius/certs/server.pem"
ca_file = "/etc/freeradius/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/etc/freeradius/certs/dh"
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
cipher_server_preference = no
ecdh_curve = "prime256v1"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
tls: Failed reading private key file
"/etc/freeradius/certs/server.pem"
tls: error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad
decrypt
tls: error:23077074:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 cipherfinal
error
tls: error:2306A075:PKCS12 routines:PKCS12_item_decrypt_d2i:pkcs12 pbe
crypt error
tls: error:0907B00D:PEM routines:PEM_READ_BIO_PRIVATEKEY:ASN1 lib
tls: error:140B0009:SSL routines:SSL_CTX_use_PrivateKey_file:PEM lib
rlm_eap_tls: Failed initializing SSL context
rlm_eap (EAP): Failed to initialise rlm_eap_tls
/etc/freeradius/mods-enabled/eap[14]: Instantiation failed for module
"eap"
3
8
Hello Team,
I successfully built freeradius-server 4 from master branch using this
requirements https://wiki.freeradius.org/building/RHEL%20and%20Centos
And I would like to test tacacs, but when I trying to run the app, I
get an error proto_tacacs.so library.
Debug output is below:
[root@localhost sbin]# ./radiusd -xX
Fri May 17 10:27:56 2019: Debug : Server was built with:
Fri May 17 10:27:56 2019: Debug : accounting : yes
Fri May 17 10:27:56 2019: Debug : authentication : yes
Fri May 17 10:27:56 2019: Debug : ascend-binary-attributes : yes
Fri May 17 10:27:56 2019: Debug : coa : yes
Fri May 17 10:27:56 2019: Debug : control-socket : yes
Fri May 17 10:27:56 2019: Debug : detail : yes
Fri May 17 10:27:56 2019: Debug : dhcp : yes
Fri May 17 10:27:56 2019: Debug : dynamic-clients : yes
Fri May 17 10:27:56 2019: Debug : proxy : yes
Fri May 17 10:27:56 2019: Debug : regex-pcre : yes
Fri May 17 10:27:56 2019: Debug : regex-pcre2 : no
Fri May 17 10:27:56 2019: Debug : regex-posix : no
Fri May 17 10:27:56 2019: Debug : regex-posix-extended : no
Fri May 17 10:27:56 2019: Debug : stats : yes
Fri May 17 10:27:56 2019: Debug : systemd : yes
Fri May 17 10:27:56 2019: Debug : tls : yes
Fri May 17 10:27:56 2019: Debug : tls-key-agility : yes
Fri May 17 10:27:56 2019: Debug : unlang : yes
Fri May 17 10:27:56 2019: Debug : vmps : yes
Fri May 17 10:27:56 2019: Debug : socket-timestamps : yes
Fri May 17 10:27:56 2019: Debug : developer : yes
Fri May 17 10:27:56 2019: Debug : address-sanitizer : no
Fri May 17 10:27:56 2019: Debug : runtime-debugger : no
Fri May 17 10:27:56 2019: Debug : Server core libs:
Fri May 17 10:27:56 2019: Debug : freeradius-server : 4.0.0
Fri May 17 10:27:56 2019: Debug : talloc : 2.1.*
Fri May 17 10:27:56 2019: Debug : ssl : 1.0.2k release
Fri May 17 10:27:56 2019: Debug : pcre : 8.32 2012-11-30
Fri May 17 10:27:56 2019: Debug : OpenSSL engines:
Fri May 17 10:27:56 2019: Debug : dynamic : Dynamic
engine loading support
Fri May 17 10:27:56 2019: Debug : Endianness:
Fri May 17 10:27:56 2019: Debug : little
Fri May 17 10:27:56 2019: Debug : Compilation flags:
Fri May 17 10:27:56 2019: Debug : cppflags :
Fri May 17 10:27:56 2019: Debug : cflags : -I. -Isrc -include
src/freeradius-devel/autoconf.h -include src/freeradius-devel/build.h
-include src/freeradius-devel/features.h -include
src/freeradius-devel/radpaths.h -fno-strict-aliasing -Wno-date-time
-g3 -std=c11 -Wall -D_GNU_SOURCE -D_REENTRANT
-D_POSIX_PTHREAD_SEMANTICS -pthread -DOPENSSL_NO_KRB5 -Wshadow
-Wpointer-arith -Wcast-qual -Wcast-align -Wwrite-strings
-Wstrict-prototypes -Wmissing-prototypes -Wmissing-declarations
-Wnested-externs -W -Wredundant-decls -Wundef -Wformat-y2k
-Wno-missing-field-initializers -Wno-format-extra-args
-Wno-format-zero-length -Wno-cast-align -Wformat-nonliteral
-Wformat-security -Wformat=2 -DWITH_VERIFY_PTR=1 -DWITH_OPENSSL_MD4
-DWITH_OPENSSL_MD5
Fri May 17 10:27:56 2019: Debug : ldflags :
Fri May 17 10:27:56 2019: Debug : libs : -lcrypto -lssl -ltalloc
-lkqueue -lpcre -lcap -lrt -lnsl -lresolv -ldl -lpthread -lreadline
Fri May 17 10:27:56 2019: Debug :
Fri May 17 10:27:56 2019: Info : FreeRADIUS Version 4.0.0
Fri May 17 10:27:56 2019: Info : Copyright 1999-2019 The FreeRADIUS
server project and contributors
Fri May 17 10:27:56 2019: Info : There is NO warranty; not even for
MERCHANTABILITY or FITNESS FOR A
Fri May 17 10:27:56 2019: Info : PARTICULAR PURPOSE
Fri May 17 10:27:56 2019: Info : You may redistribute copies of
FreeRADIUS under the terms of the
Fri May 17 10:27:56 2019: Info : GNU General Public License
Fri May 17 10:27:56 2019: Info : For more information about these
matters, see the file named COPYRIGHT
Fri May 17 10:27:56 2019: Info : Starting - reading configuration files ...
Fri May 17 10:27:56 2019: Debug : Including dictionary file
"/opt/freeradius/usr/etc/raddb/dictionary"
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/radiusd.conf
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/clients.conf
Fri May 17 10:27:56 2019: Debug : Including files in directory
"/opt/freeradius/usr/etc/raddb/mods-enabled/"
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/always
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/attr_filter
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/cache_eap
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/chap
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/client
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/delay
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/detail
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/detail.log
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/digest
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/dhcpv4
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/echo
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/escape
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/exec
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/expiration
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/expr
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/files
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/linelog
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/logintime
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/mschap
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/ntlm_auth
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/pap
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/passwd
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/radius
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/radutmp
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/soh
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/sradutmp
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/stats
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/unix
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/unpack
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/mods-enabled/utf8
Fri May 17 10:27:56 2019: Debug : Including files in directory
"/opt/freeradius/usr/etc/raddb/policy.d/"
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/abfab-tr
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/accounting
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/canonicalization
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/control
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/cui
Fri May 17 10:27:56 2019: Debug : OPTIMIZING
(${policy.cui_require_operator_name} == yes) --> FALSE
Fri May 17 10:27:56 2019: Debug : OPTIMIZING (no == yes) --> FALSE
Fri May 17 10:27:56 2019: Debug : OPTIMIZING
(${policy.cui_require_operator_name} == yes) --> FALSE
Fri May 17 10:27:56 2019: Debug : OPTIMIZING (no == yes) --> FALSE
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/debug
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/dhcp
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/eap
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/filter
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/operator-name
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/time
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/policy.d/vendor
Fri May 17 10:27:56 2019: Debug : Including files in directory
"/opt/freeradius/usr/etc/raddb/sites-enabled/"
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/sites-enabled/default
Fri May 17 10:27:56 2019: Debug : proto_radius loaded, checking if it's valid
Fri May 17 10:27:56 2019: Debug : proto_radius validated. Handle
address 0x2349660, symbol address 0x7f98321b9280
Fri May 17 10:27:56 2019: Info : Loaded module "proto_radius"
Fri May 17 10:27:56 2019: Debug : including configuration file
/opt/freeradius/usr/etc/raddb/sites-enabled/tacacs
Fri May 17 10:27:56 2019: Error : src/lib/server/cf_file.c[1568]:
Failed to link to module "proto_tacacs":
/opt/freeradius/usr/lib/proto_tacacs.so: undefined symbol:
common_socket_parse
Fri May 17 10:27:56 2019: Error : src/lib/server/cf_file.c[1568]: Make
sure it (and all its dependent libraries!) are in the search path of
your system's ld
CAUGHT SIGNAL: Segmentation fault
Backtrace of last 16 frames:
/opt/freeradius/usr/lib/libfreeradius-util.so(fr_fault+0xe9)[0x7f9837d947a9]
/lib64/libpthread.so.0(+0xf5d0)[0x7f98363e25d0]
/opt/freeradius/usr/lib/libfreeradius-server.so(+0x307a2)[0x7f98384817a2]
/lib64/libtalloc.so.2(+0x31ab)[0x7f98374a11ab]
/opt/freeradius/usr/lib/libfreeradius-server.so(dl_module+0x314)[0x7f9838481b2b]
/opt/freeradius/usr/lib/libfreeradius-server.so(+0x5a975)[0x7f98384ab975]
/opt/freeradius/usr/lib/libfreeradius-server.so(_cf_section_alloc+0x4f4)[0x7f983846f146]
/opt/freeradius/usr/lib/libfreeradius-server.so(+0x18075)[0x7f9838469075]
/opt/freeradius/usr/lib/libfreeradius-server.so(+0x18391)[0x7f9838469391]
/opt/freeradius/usr/lib/libfreeradius-server.so(+0x167a3)[0x7f98384677a3]
/opt/freeradius/usr/lib/libfreeradius-server.so(+0x18391)[0x7f9838469391]
/opt/freeradius/usr/lib/libfreeradius-server.so(cf_file_read+0x23d)[0x7f983846962b]
/opt/freeradius/usr/lib/libfreeradius-server.so(main_config_init+0x402)[0x7f983848883e]
./radiusd(main+0x95c)[0x404cee]
/lib64/libc.so.6(__libc_start_main+0xf5)[0x7f9835bb13d5]
./radiusd[0x404159]
No panic action set
_EXIT(139) CALLED src/lib/util/debug.c[921]
Does tacacs working in freeradius 4 and can I somehow fix this?
--
Best regards,
Viktor Kolesnikov
2
2
Hi,
When I do lease query I get the following error. What might be the problem?
Debug output:
# /sbin/radiusd -X
Info : FreeRADIUS Version 4.0.0
Info : Copyright 1999-2019 The FreeRADIUS server project and contributors
Info : There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
Info : PARTICULAR PURPOSE
Info : You may redistribute copies of FreeRADIUS under the terms of the
Info : GNU General Public License
Info : For more information about these matters, see the file named COPYRIGHT
Info : Starting - reading configuration files ...
Debug : Including dictionary file "/etc/raddb/dictionary"
Debug : including configuration file /etc/raddb/radiusd.conf
Debug : including configuration file /etc/raddb/clients.conf
Debug : Including files in directory "/etc/raddb/mods-enabled/"
Debug : including configuration file /etc/raddb/mods-enabled/always
Debug : including configuration file /etc/raddb/mods-enabled/dhcpv4
Debug : including configuration file /etc/raddb/mods-enabled/stats
Debug : including configuration file /etc/raddb/mods-enabled/redis_ippool
Debug : including configuration file /etc/raddb/mods-enabled/redis
Debug : Including files in directory "/etc/raddb/policy.d/"
Debug : including configuration file /etc/raddb/policy.d/abfab-tr
Debug : including configuration file /etc/raddb/policy.d/accounting
Debug : including configuration file /etc/raddb/policy.d/canonicalization
Debug : including configuration file /etc/raddb/policy.d/control
Debug : including configuration file /etc/raddb/policy.d/cui
Debug : including configuration file /etc/raddb/policy.d/debug
Debug : including configuration file /etc/raddb/policy.d/dhcp
Debug : including configuration file /etc/raddb/policy.d/eap
Debug : including configuration file /etc/raddb/policy.d/filter
Debug : including configuration file /etc/raddb/policy.d/operator-name
Debug : including configuration file /etc/raddb/policy.d/time
Debug : including configuration file /etc/raddb/policy.d/vendor
Debug : Including files in directory "/etc/raddb/sites-enabled/"
Debug : including configuration file /etc/raddb/sites-enabled/dhcp
Debug : Loading dictionaries for proto_dhcpv4
Info : Loaded module "proto_dhcpv4"
Debug : Parsing security rules to bootstrap UID / GID / chroot / etc.
Debug : main {
Debug : security {
Debug : allow_core_dumps = no
Debug : allow_vulnerable_openssl = "no"
Debug : openssl_fips_mode = no
Debug : }
Debug : name = radiusd
Debug : name = "radiusd"
Debug : prefix = "/usr"
Debug : local_state_dir = "/usr/var"
Debug : run_dir = "/var/run/radiusd"
Debug : }
Debug : Parsing main configuration.
Debug : main {
Debug : server dhcp {
Debug : listen {
Debug : type = DHCP-Discover
Debug : Loading dictionaries for proto_dhcpv4_base
Info : Loaded module "proto_dhcpv4_base"
Debug : type = DHCP-Request
Debug : type = DHCP-Inform
Debug : type = DHCP-Release
Debug : type = DHCP-Decline
Debug : transport = udp
Debug : Loading dictionaries for proto_dhcpv4_udp
Info : Loaded module "proto_dhcpv4_udp"
Debug : udp {
Debug : ipaddr = 10.43.18.107
Debug : src_ipaddr = 10.43.18.107
Debug : port = 67
Debug : broadcast = no
Debug : networks {
Debug : }
Debug : max_packet_size = 4096
Debug : max_attributes = 0
Debug : }
Debug : limit {
Debug : idle_timeout = 30.000000
Debug : nak_lifetime = 30.000000
Debug : max_connections = 1024
Debug : max_clients = 256
Debug : max_pending_packets = 256
Debug : priority {
Debug : DHCP-Discover = normal
Debug : DHCP-Request = normal
Debug : DHCP-Decline = normal
Debug : DHCP-Release = normal
Debug : DHCP-Inform = normal
Debug : DHCP-Lease-Query = low
Debug : DHCP-Bulk-Lease-Query = low
Debug : }
Debug : }
Debug : }
Debug : }
Debug : security {
Debug : }
Debug : sbin_dir = "/usr/sbin"
Debug : logdir = "/var/log/radius"
Debug : libdir = "/usr/lib64/freeradius"
Debug : radacctdir = "/var/log/radius/radacct"
Debug : reverse_lookups = no
Debug : reverse_lookups = no
Debug : hostname_lookups = yes
Debug : hostname_lookups = yes
Debug : max_request_time = 30
Debug : max_request_time = 30
Debug : pidfile = "/var/run/radiusd/radiusd.pid"
Debug : debug_level = 0
Debug : log {
Debug : colourise = yes
Debug : }
Debug : resources {
Debug : }
Debug : thread pool {
Debug : num_networks = 1
Debug : num_networks = 1
Debug : num_workers = 4
Debug : num_workers = 4
Debug : }
Debug : }
Switching to configured log settings
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
trigger { ... } subsection not found, triggers will be disabled
systemd watchdog is disabled
#### Bootstrapping listeners ####
#### Bootstrapping modules ####
modules {
Loaded module "rlm_always"
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
Loading dictionaries for rlm_dhcpv4
Loaded module "rlm_dhcpv4"
Loading dictionaries for rlm_stats
Loaded module "rlm_stats"
stats {
}
libfreeradius-redis: libhiredis version: 0.12.1
Loading dictionaries for rlm_redis_ippool
Loaded module "rlm_redis_ippool"
redis_ippool {
copy_on_update = yes
redis {
server = "devstack08-db-eval1-0001-001.oovb0g.0001.usw2.cache.amazonaws.com"
port = 6379
database = 0
max_nodes = 20
max_alt = 3
max_redirects = 2
}
}
libfreeradius-redis: libhiredis version: 0.12.1
Loaded module "rlm_redis"
redis {
server = "devstack08-db-eval1-0001-001.oovb0g.0001.usw2.cache.amazonaws.com"
port = 6379
database = 0
max_nodes = 20
max_alt = 3
max_redirects = 2
}
Bootstrapping module "redis"
instantiate {
}
} # modules
#### Instantiating listeners ####
Compiling policies in server dhcp { ... }
Compiling policies in - recv DHCP-Discover {...}
Compiling policies in - recv DHCP-Request {...}
Compiling policies in - recv DHCP-Release {...}
Compiling policies in - recv DHCP-Inform {...}
Compiling policies in - recv DHCP-Lease-Query {...}
/etc/raddb/sites-enabled/dhcp[303]: recv DHCP-Decline { ... } section is unused
#### Instantiating modules ####
Instantiating module "fail"
Instantiating module "handled"
Instantiating module "invalid"
Instantiating module "noop"
Instantiating module "notfound"
Instantiating module "ok"
Instantiating module "redis"
rlm_redis (redis) [1] - Initialising connection pool
pool {
start = 4
min = 4
max = 4
max_pending = 0
spare = 1
uses = 0
lifetime = 86400
cleanup_interval = 300
idle_timeout = 600
connect_timeout = 3.000000
held_trigger_min = 0.000000
held_trigger_max = 0.500000
retry_delay = 30
spread = no
}
rlm_redis (redis) [1] - Ignoring "spare = 1", forcing to "spare = 0"
rlm_redis (redis) [1] - Opening additional connection (0), 1 of 4 pending slots used
rlm_redis (redis) - [1] Connecting to node 10.43.17.86:6379
rlm_redis (redis) [1] - Opening additional connection (1), 1 of 3 pending slots used
rlm_redis (redis) - [1] Connecting to node 10.43.17.86:6379
rlm_redis (redis) [1] - Opening additional connection (2), 1 of 2 pending slots used
rlm_redis (redis) - [1] Connecting to node 10.43.17.86:6379
rlm_redis (redis) [1] - Opening additional connection (3), 1 of 1 pending slots used
rlm_redis (redis) - [1] Connecting to node 10.43.17.86:6379
rlm_redis (redis) [1] - Reserved connection (3)
rlm_redis (redis) [1] - Released connection (3)
rlm_redis (redis) - Cluster map consists of 1 key ranges
rlm_redis (redis) - 0 - keys 0-16383
rlm_redis (redis) - master: 10.43.17.86:6379
rlm_redis (redis) - slave0: 10.43.16.148:6379
rlm_redis (redis) - slave1: 10.43.16.109:6379
rlm_redis (redis) [2] - Initialising connection pool
pool {
start = 4
min = 4
max = 4
max_pending = 0
spare = 1
uses = 0
lifetime = 86400
cleanup_interval = 300
idle_timeout = 600
connect_timeout = 3.000000
held_trigger_min = 0.000000
held_trigger_max = 0.500000
retry_delay = 30
spread = no
}
rlm_redis (redis) [2] - Ignoring "spare = 1", forcing to "spare = 0"
rlm_redis (redis) [2] - Opening additional connection (0), 1 of 4 pending slots used
rlm_redis (redis) - [2] Connecting to node 10.43.16.148:6379
rlm_redis (redis) [2] - Opening additional connection (1), 1 of 3 pending slots used
rlm_redis (redis) - [2] Connecting to node 10.43.16.148:6379
rlm_redis (redis) [2] - Opening additional connection (2), 1 of 2 pending slots used
rlm_redis (redis) - [2] Connecting to node 10.43.16.148:6379
rlm_redis (redis) [2] - Opening additional connection (3), 1 of 1 pending slots used
rlm_redis (redis) - [2] Connecting to node 10.43.16.148:6379
rlm_redis (redis) [3] - Initialising connection pool
pool {
start = 4
min = 4
max = 4
max_pending = 0
spare = 1
uses = 0
lifetime = 86400
cleanup_interval = 300
idle_timeout = 600
connect_timeout = 3.000000
held_trigger_min = 0.000000
held_trigger_max = 0.500000
retry_delay = 30
spread = no
}
rlm_redis (redis) [3] - Ignoring "spare = 1", forcing to "spare = 0"
rlm_redis (redis) [3] - Opening additional connection (0), 1 of 4 pending slots used
rlm_redis (redis) - [3] Connecting to node 10.43.16.109:6379
rlm_redis (redis) [3] - Opening additional connection (1), 1 of 3 pending slots used
rlm_redis (redis) - [3] Connecting to node 10.43.16.109:6379
rlm_redis (redis) [3] - Opening additional connection (2), 1 of 2 pending slots used
rlm_redis (redis) - [3] Connecting to node 10.43.16.109:6379
rlm_redis (redis) [3] - Opening additional connection (3), 1 of 1 pending slots used
rlm_redis (redis) - [3] Connecting to node 10.43.16.109:6379
Instantiating module "redis_ippool"
rlm_redis (redis) [1] - Initialising connection pool
pool {
start = 0
min = 4
max = 4
max_pending = 0
spare = 1
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
connect_timeout = 3.000000
held_trigger_min = 0.000000
held_trigger_max = 0.500000
retry_delay = 30
spread = no
}
rlm_redis (redis) [1] - Ignoring "spare = 1", forcing to "spare = 0"
rlm_redis (redis) [1] - 0 of 0 connections in use. You may need to increase "spare"
rlm_redis (redis) [1] - Opening additional connection (0), 1 of 4 pending slots used
rlm_redis (redis) - [1] Connecting to node 10.43.17.86:6379
rlm_redis (redis) [1] - Reserved connection (0)
rlm_redis (redis) [1] - Released connection (0)
rlm_redis (redis) [1] - Need 3 more connections to reach min connections (4)
rlm_redis (redis) [1] - Opening additional connection (1), 1 of 3 pending slots used
rlm_redis (redis) - [1] Connecting to node 10.43.17.86:6379
Instantiating module "reject"
Instantiating module "stats"
Instantiating module "updated"
Instantiating module "userlock"
Scheduler created in single-threaded mode
#### Opening listener interfaces ####
Listening on dhcpv4 address proto_dhcpv4_udp server 10.43.18.107 port 67 bound to virtual server dhcp
Ready to process requests
Ready to process requests
Ready to process requests
proto_dhcpv4_udp - Received DHCP-Lease-Query XID 0a000029 length 311 proto_dhcpv4_udp server 10.43.18.107 port 67
(0) ERROR: No module available to handle packet code 10
(0) ERROR: Protocol failed to set 'process' function
Ready to process requests
Regards,
Nagamani Chinnapaiyan
2
11
Hi Team,
i am facing issue when i am testing from test client(NTRadping) , showing error "Ignoring request to authentication address * port 1812 from unknown client 192.168.1.16 port 59345" . I was hosting through docker. So inside docker container i am able to do radtest and also getting Accept-Accept in response.I have already added all required client IP in client config. but when i am trying from tool it is not working. Please help...
2
1
Hi,
We are upgrading our freeradius servers : 3.0.19 (from
packages.networkradius.com) under Ubuntu 18.04.
Tests are good with most clients (linux, windows, mac) but fail with
Android clients (version 7) with a EAP error message.
The first EAP exchanges seem to work fine (sections 0 to 4) then fail in
section 5.
Here is the log :
Ready to process requests
(0) Received Access-Request Id 102 from 195.220.94.1:1645 to
194.57.4.197:1812 length 157
(0) User-Name = "anonymous(a)renater.fr"
(0) Framed-MTU = 1400
(0) Called-Station-Id = "0012.d942.a460"
(0) Calling-Station-Id = "ccc0.7942.6070"
(0) Service-Type = Login-User
(0) Message-Authenticator = 0xa0adc019dd45f629b627b8812b24032b
(0) EAP-Message = 0x0201001901616e6f6e796d6f75734072656e617465722e6672
(0) NAS-Port-Type = Wireless-802.11
(0) NAS-Port = 314
(0) NAS-IP-Address = 195.220.94.1
(0) NAS-Identifier = "ap1000"
(0) # Executing section authorize from file
/etc/freeradius/sites-enabled/eduroam
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) if (&User-Name !~ /(a)renater.fr/) {
(0) if (&User-Name !~ /(a)renater.fr/) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(0) EXPAND %{client:shortname}
(0) --> borne-rennes-1100
(0) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) -> TRUE
(0) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(0) update request {
(0) Operator-Name := "1renater.fr"
(0) } # update request = noop
(0) } # if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) = noop
(0) policy cui.authorize {
(0) if ("%{client:add_cui}" == 'yes') {
(0) EXPAND %{client:add_cui}
(0) --> yes
(0) if ("%{client:add_cui}" == 'yes') -> TRUE
(0) if ("%{client:add_cui}" == 'yes') {
(0) update request {
(0) &Chargeable-User-Identity := 0x00
(0) } # update request = noop
(0) } # if ("%{client:add_cui}" == 'yes') = noop
(0) } # policy cui.authorize = noop
(0) auth_log: EXPAND
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
(0) auth_log: -->
/var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(0) auth_log:
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
expands to /var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(0) auth_log: EXPAND %t
(0) auth_log: --> Wed May 15 10:01:24 2019
(0) [auth_log] = ok
(0) suffix: Checking for suffix after "@"
(0) suffix: Looking up realm "renater.fr" for User-Name =
"anonymous(a)renater.fr"
(0) suffix: Found realm "renater.fr"
(0) suffix: Adding Realm = "renater.fr"
(0) suffix: Authentication realm is LOCAL
(0) [suffix] = ok
(0) eap: Peer sent EAP Response (code 2) ID 1 length 25
(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the
rest of authorize
(0) [eap] = ok
(0) } # authorize = ok
(0) Found Auth-Type = eap
(0) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(0) authenticate {
(0) eap: Peer sent packet with method EAP Identity (1)
(0) eap: Calling submodule eap_peap to process data
(0) eap_peap: Initiating new TLS session
(0) eap_peap: [eaptls start] = request
(0) eap: Sending EAP Request (code 1) ID 2 length 6
(0) eap: EAP session adding &reply:State = 0xcaaa2a6ccaa833e7
(0) [eap] = handled
(0) } # authenticate = handled
(0) Using Post-Auth-Type Challenge
(0) Post-Auth-Type sub-section not found. Ignoring.
(0) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(0) Sent Access-Challenge Id 102 from 194.57.4.197:1812 to
195.220.94.1:1645 length 0
(0) EAP-Message = 0x010200061920
(0) Message-Authenticator = 0x00000000000000000000000000000000
(0) State = 0xcaaa2a6ccaa833e7ad7633b276a93937
(0) Finished request
Waking up in 4.9 seconds.
(1) Received Access-Request Id 103 from 195.220.94.1:1645 to
194.57.4.197:1812 length 317
(1) User-Name = "anonymous(a)renater.fr"
(1) Framed-MTU = 1400
(1) Called-Station-Id = "0012.d942.a460"
(1) Calling-Station-Id = "ccc0.7942.6070"
(1) Service-Type = Login-User
(1) Message-Authenticator = 0xb384c184c8fe45956c9246c04902dc31
(1) EAP-Message =
0x020200a719800000009d1603010098010000940303f94b22c62eeae3503df6f5e1bff784a2afda34d472918e62076ac43a07b9b3bc00003cc02bc02f009ec02cc030009fcca9cca8c009c023c013c02700330067c00ac024c014c0280039006bc007c011009c009d002f003c0035003d0005000a0100002fff0100010000170000000d0010000e0403040105030501060306010201000b00020100000a00080006001d00170018
(1) NAS-Port-Type = Wireless-802.11
(1) NAS-Port = 314
(1) State = 0xcaaa2a6ccaa833e7ad7633b276a93937
(1) NAS-IP-Address = 195.220.94.1
(1) NAS-Identifier = "ap1000"
(1) session-state: No cached attributes
(1) # Executing section authorize from file
/etc/freeradius/sites-enabled/eduroam
(1) authorize {
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) if (&User-Name !~ /(a)renater.fr/) {
(1) if (&User-Name !~ /(a)renater.fr/) -> FALSE
(1) } # if (&User-Name) = notfound
(1) } # policy filter_username = notfound
(1) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(1) EXPAND %{client:shortname}
(1) --> borne-rennes-1100
(1) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) -> TRUE
(1) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(1) update request {
(1) Operator-Name := "1renater.fr"
(1) } # update request = noop
(1) } # if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) = noop
(1) policy cui.authorize {
(1) if ("%{client:add_cui}" == 'yes') {
(1) EXPAND %{client:add_cui}
(1) --> yes
(1) if ("%{client:add_cui}" == 'yes') -> TRUE
(1) if ("%{client:add_cui}" == 'yes') {
(1) update request {
(1) &Chargeable-User-Identity := 0x00
(1) } # update request = noop
(1) } # if ("%{client:add_cui}" == 'yes') = noop
(1) } # policy cui.authorize = noop
(1) auth_log: EXPAND
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
(1) auth_log: -->
/var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(1) auth_log:
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
expands to /var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(1) auth_log: EXPAND %t
(1) auth_log: --> Wed May 15 10:01:24 2019
(1) [auth_log] = ok
(1) suffix: Checking for suffix after "@"
(1) suffix: Looking up realm "renater.fr" for User-Name =
"anonymous(a)renater.fr"
(1) suffix: Found realm "renater.fr"
(1) suffix: Adding Realm = "renater.fr"
(1) suffix: Authentication realm is LOCAL
(1) [suffix] = ok
(1) eap: Peer sent EAP Response (code 2) ID 2 length 167
(1) eap: Continuing tunnel setup
(1) [eap] = ok
(1) } # authorize = ok
(1) Found Auth-Type = eap
(1) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(1) authenticate {
(1) eap: Expiring EAP session with state 0xcaaa2a6ccaa833e7
(1) eap: Finished EAP session with state 0xcaaa2a6ccaa833e7
(1) eap: Previous EAP request found for state 0xcaaa2a6ccaa833e7,
released from the list
(1) eap: Peer sent packet with method EAP PEAP (25)
(1) eap: Calling submodule eap_peap to process data
(1) eap_peap: Continuing EAP-TLS
(1) eap_peap: Peer indicated complete TLS record size will be 157 bytes
(1) eap_peap: Got complete TLS record (157 bytes)
(1) eap_peap: [eaptls verify] = length included
(1) eap_peap: (other): before SSL initialization
(1) eap_peap: TLS_accept: before SSL initialization
(1) eap_peap: TLS_accept: before SSL initialization
(1) eap_peap: <<< recv TLS 1.2 [length 0098]
(1) eap_peap: TLS_accept: SSLv3/TLS read client hello
(1) eap_peap: >>> send TLS 1.2 [length 003d]
(1) eap_peap: TLS_accept: SSLv3/TLS write server hello
(1) eap_peap: >>> send TLS 1.2 [length 0c90]
(1) eap_peap: TLS_accept: SSLv3/TLS write certificate
(1) eap_peap: >>> send TLS 1.2 [length 014d]
(1) eap_peap: TLS_accept: SSLv3/TLS write key exchange
(1) eap_peap: >>> send TLS 1.2 [length 0004]
(1) eap_peap: TLS_accept: SSLv3/TLS write server done
(1) eap_peap: TLS_accept: Need to read more data: SSLv3/TLS write server
done
(1) eap_peap: TLS - In Handshake Phase
(1) eap_peap: TLS - got 3634 bytes of data
(1) eap_peap: [eaptls process] = handled
(1) eap: Sending EAP Request (code 1) ID 3 length 1024
(1) eap: EAP session adding &reply:State = 0xcaaa2a6ccba933e7
(1) [eap] = handled
(1) } # authenticate = handled
(1) Using Post-Auth-Type Challenge
(1) Post-Auth-Type sub-section not found. Ignoring.
(1) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(1) Sent Access-Challenge Id 103 from 194.57.4.197:1812 to
195.220.94.1:1645 length 0
(1) EAP-Message =
0x0103040019c000000e32160303003d02000039030349a0e794e6bc9ac98b22c390967324e4711c255b0bafc92c5c0b74d1b437b35e00c02f000011ff01000100000b000403000102001700001603030c900b000c8c000c890007843082078030820668a00302010202100cf0c689f2b6db0e4f019ae302502e32300d06092a864886f70d01010b05003064310b3009060355040613024e4c311630140603550408130d4e6f6f72642d486f6c6c616e643112301006035504071309416d7374657264616d310f300d060355040a1306544552454e41311830160603550403130f544552454e412053534c2043412033301e170d3139303431363030303030305a170d3231303731393030303030305a30818f310b3009060355040613024652310e300c060355040713055061726973313f303d060355040a13365245532e204e41542e2044452054454c45434f4d2e20504f5552204c4120544543482e204420454e532e204554204c4120524543482e312f302d060355
(1) Message-Authenticator = 0x00000000000000000000000000000000
(1) State = 0xcaaa2a6ccba933e7ad7633b276a93937
(1) Finished request
Waking up in 4.9 seconds.
(2) Received Access-Request Id 104 from 195.220.94.1:1645 to
194.57.4.197:1812 length 156
(2) User-Name = "anonymous(a)renater.fr"
(2) Framed-MTU = 1400
(2) Called-Station-Id = "0012.d942.a460"
(2) Calling-Station-Id = "ccc0.7942.6070"
(2) Service-Type = Login-User
(2) Message-Authenticator = 0xc3b7d99ca284d8f861e93b8a9ecb97b8
(2) EAP-Message = 0x020300061900
(2) NAS-Port-Type = Wireless-802.11
(2) NAS-Port = 314
(2) State = 0xcaaa2a6ccba933e7ad7633b276a93937
(2) NAS-IP-Address = 195.220.94.1
(2) NAS-Identifier = "ap1000"
(2) session-state: No cached attributes
(2) # Executing section authorize from file
/etc/freeradius/sites-enabled/eduroam
(2) authorize {
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) if (&User-Name !~ /(a)renater.fr/) {
(2) if (&User-Name !~ /(a)renater.fr/) -> FALSE
(2) } # if (&User-Name) = notfound
(2) } # policy filter_username = notfound
(2) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(2) EXPAND %{client:shortname}
(2) --> borne-rennes-1100
(2) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) -> TRUE
(2) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(2) update request {
(2) Operator-Name := "1renater.fr"
(2) } # update request = noop
(2) } # if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) = noop
(2) policy cui.authorize {
(2) if ("%{client:add_cui}" == 'yes') {
(2) EXPAND %{client:add_cui}
(2) --> yes
(2) if ("%{client:add_cui}" == 'yes') -> TRUE
(2) if ("%{client:add_cui}" == 'yes') {
(2) update request {
(2) &Chargeable-User-Identity := 0x00
(2) } # update request = noop
(2) } # if ("%{client:add_cui}" == 'yes') = noop
(2) } # policy cui.authorize = noop
(2) auth_log: EXPAND
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
(2) auth_log: -->
/var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(2) auth_log:
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
expands to /var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(2) auth_log: EXPAND %t
(2) auth_log: --> Wed May 15 10:01:24 2019
(2) [auth_log] = ok
(2) suffix: Checking for suffix after "@"
(2) suffix: Looking up realm "renater.fr" for User-Name =
"anonymous(a)renater.fr"
(2) suffix: Found realm "renater.fr"
(2) suffix: Adding Realm = "renater.fr"
(2) suffix: Authentication realm is LOCAL
(2) [suffix] = ok
(2) eap: Peer sent EAP Response (code 2) ID 3 length 6
(2) eap: Continuing tunnel setup
(2) [eap] = ok
(2) } # authorize = ok
(2) Found Auth-Type = eap
(2) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(2) authenticate {
(2) eap: Expiring EAP session with state 0xcaaa2a6ccba933e7
(2) eap: Finished EAP session with state 0xcaaa2a6ccba933e7
(2) eap: Previous EAP request found for state 0xcaaa2a6ccba933e7,
released from the list
(2) eap: Peer sent packet with method EAP PEAP (25)
(2) eap: Calling submodule eap_peap to process data
(2) eap_peap: Continuing EAP-TLS
(2) eap_peap: Peer ACKed our handshake fragment
(2) eap_peap: [eaptls verify] = request
(2) eap_peap: [eaptls process] = handled
(2) eap: Sending EAP Request (code 1) ID 4 length 1020
(2) eap: EAP session adding &reply:State = 0xcaaa2a6cc8ae33e7
(2) [eap] = handled
(2) } # authenticate = handled
(2) Using Post-Auth-Type Challenge
(2) Post-Auth-Type sub-section not found. Ignoring.
(2) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(2) Sent Access-Challenge Id 104 from 194.57.4.197:1812 to
195.220.94.1:1645 length 0
(2) EAP-Message =
0x010403fc1940332e63726c304c0603551d2004453043303706096086480186fd6c0101302a302806082b06010505070201161c68747470733a2f2f7777772e64696769636572742e636f6d2f4350533008060667810c010202306e06082b0601050507010104623060302406082b060105050730018618687474703a2f2f6f6373702e64696769636572742e636f6d303806082b06010505073002862c687474703a2f2f636163657274732e64696769636572742e636f6d2f544552454e4153534c4341332e637274300c0603551d130101ff04023000308201f6060a2b06010401d679020402048201e6048201e201e0007600ee4bbdb775ce60bae142691fabe19e66a30f7e5fb072d88300c47b897aa8fdcb0000016a268a5a9d000004030047304502201d5d5db28b56e2d37b6d45a00c9f7818066493c657cbb0bf6f03bc2683529e8c022100eeee46573a2cb109e769cb71924f257162c62983e5029ee9ff2420a62554f6430077008775bfe7597cf88c43995f
(2) Message-Authenticator = 0x00000000000000000000000000000000
(2) State = 0xcaaa2a6cc8ae33e7ad7633b276a93937
(2) Finished request
Waking up in 4.9 seconds.
(3) Received Access-Request Id 105 from 195.220.94.1:1645 to
194.57.4.197:1812 length 156
(3) User-Name = "anonymous(a)renater.fr"
(3) Framed-MTU = 1400
(3) Called-Station-Id = "0012.d942.a460"
(3) Calling-Station-Id = "ccc0.7942.6070"
(3) Service-Type = Login-User
(3) Message-Authenticator = 0x0eec5ab7b19d608c9d73b4c13de1df93
(3) EAP-Message = 0x020400061900
(3) NAS-Port-Type = Wireless-802.11
(3) NAS-Port = 314
(3) State = 0xcaaa2a6cc8ae33e7ad7633b276a93937
(3) NAS-IP-Address = 195.220.94.1
(3) NAS-Identifier = "ap1000"
(3) session-state: No cached attributes
(3) # Executing section authorize from file
/etc/freeradius/sites-enabled/eduroam
(3) authorize {
(3) policy filter_username {
(3) if (&User-Name) {
(3) if (&User-Name) -> TRUE
(3) if (&User-Name) {
(3) if (&User-Name =~ / /) {
(3) if (&User-Name =~ / /) -> FALSE
(3) if (&User-Name =~ /@[^@]*@/ ) {
(3) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(3) if (&User-Name =~ /\.\./ ) {
(3) if (&User-Name =~ /\.\./ ) -> FALSE
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(3) if (&User-Name =~ /\.$/) {
(3) if (&User-Name =~ /\.$/) -> FALSE
(3) if (&User-Name =~ /(a)\./) {
(3) if (&User-Name =~ /(a)\./) -> FALSE
(3) if (&User-Name !~ /(a)renater.fr/) {
(3) if (&User-Name !~ /(a)renater.fr/) -> FALSE
(3) } # if (&User-Name) = notfound
(3) } # policy filter_username = notfound
(3) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(3) EXPAND %{client:shortname}
(3) --> borne-rennes-1100
(3) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) -> TRUE
(3) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(3) update request {
(3) Operator-Name := "1renater.fr"
(3) } # update request = noop
(3) } # if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) = noop
(3) policy cui.authorize {
(3) if ("%{client:add_cui}" == 'yes') {
(3) EXPAND %{client:add_cui}
(3) --> yes
(3) if ("%{client:add_cui}" == 'yes') -> TRUE
(3) if ("%{client:add_cui}" == 'yes') {
(3) update request {
(3) &Chargeable-User-Identity := 0x00
(3) } # update request = noop
(3) } # if ("%{client:add_cui}" == 'yes') = noop
(3) } # policy cui.authorize = noop
(3) auth_log: EXPAND
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
(3) auth_log: -->
/var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(3) auth_log:
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
expands to /var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(3) auth_log: EXPAND %t
(3) auth_log: --> Wed May 15 10:01:24 2019
(3) [auth_log] = ok
(3) suffix: Checking for suffix after "@"
(3) suffix: Looking up realm "renater.fr" for User-Name =
"anonymous(a)renater.fr"
(3) suffix: Found realm "renater.fr"
(3) suffix: Adding Realm = "renater.fr"
(3) suffix: Authentication realm is LOCAL
(3) [suffix] = ok
(3) eap: Peer sent EAP Response (code 2) ID 4 length 6
(3) eap: Continuing tunnel setup
(3) [eap] = ok
(3) } # authorize = ok
(3) Found Auth-Type = eap
(3) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(3) authenticate {
(3) eap: Expiring EAP session with state 0xcaaa2a6cc8ae33e7
(3) eap: Finished EAP session with state 0xcaaa2a6cc8ae33e7
(3) eap: Previous EAP request found for state 0xcaaa2a6cc8ae33e7,
released from the list
(3) eap: Peer sent packet with method EAP PEAP (25)
(3) eap: Calling submodule eap_peap to process data
(3) eap_peap: Continuing EAP-TLS
(3) eap_peap: Peer ACKed our handshake fragment
(3) eap_peap: [eaptls verify] = request
(3) eap_peap: [eaptls process] = handled
(3) eap: Sending EAP Request (code 1) ID 5 length 1020
(3) eap: EAP session adding &reply:State = 0xcaaa2a6cc9af33e7
(3) [eap] = handled
(3) } # authenticate = handled
(3) Using Post-Auth-Type Challenge
(3) Post-Auth-Type sub-section not found. Ignoring.
(3) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(3) Sent Access-Challenge Id 105 from 194.57.4.197:1812 to
195.220.94.1:1645 length 0
(3) EAP-Message =
0x010503fc19403fdb959a91cb6aeeefe465300d06092a864886f70d01010b05003065310b300906035504061302555331153013060355040a130c446967694365727420496e6331193017060355040b13107777772e64696769636572742e636f6d312430220603550403131b4469676943657274204173737572656420494420526f6f74204341301e170d3134313131383132303030305a170d3234313131383132303030305a3064310b3009060355040613024e4c311630140603550408130d4e6f6f72642d486f6c6c616e643112301006035504071309416d7374657264616d310f300d060355040a1306544552454e41311830160603550403130f544552454e412053534c204341203330820122300d06092a864886f70d01010105000382010f003082010a0282010100c5760f0fd943293b6c6dd147adde10bf23c278a84a7735f1235be04c1e41e7c23100bd88374575ddb90210801e8fed64230445a7a0393b814dcf633fc249ff229e88b0d296b95c8a74
(3) Message-Authenticator = 0x00000000000000000000000000000000
(3) State = 0xcaaa2a6cc9af33e7ad7633b276a93937
(3) Finished request
Waking up in 4.9 seconds.
(4) Received Access-Request Id 106 from 195.220.94.1:1645 to
194.57.4.197:1812 length 156
(4) User-Name = "anonymous(a)renater.fr"
(4) Framed-MTU = 1400
(4) Called-Station-Id = "0012.d942.a460"
(4) Calling-Station-Id = "ccc0.7942.6070"
(4) Service-Type = Login-User
(4) Message-Authenticator = 0xd94cb1d71dbe58181bc61743c36af928
(4) EAP-Message = 0x020500061900
(4) NAS-Port-Type = Wireless-802.11
(4) NAS-Port = 314
(4) State = 0xcaaa2a6cc9af33e7ad7633b276a93937
(4) NAS-IP-Address = 195.220.94.1
(4) NAS-Identifier = "ap1000"
(4) session-state: No cached attributes
(4) # Executing section authorize from file
/etc/freeradius/sites-enabled/eduroam
(4) authorize {
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) if (&User-Name !~ /(a)renater.fr/) {
(4) if (&User-Name !~ /(a)renater.fr/) -> FALSE
(4) } # if (&User-Name) = notfound
(4) } # policy filter_username = notfound
(4) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(4) EXPAND %{client:shortname}
(4) --> borne-rennes-1100
(4) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) -> TRUE
(4) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(4) update request {
(4) Operator-Name := "1renater.fr"
(4) } # update request = noop
(4) } # if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) = noop
(4) policy cui.authorize {
(4) if ("%{client:add_cui}" == 'yes') {
(4) EXPAND %{client:add_cui}
(4) --> yes
(4) if ("%{client:add_cui}" == 'yes') -> TRUE
(4) if ("%{client:add_cui}" == 'yes') {
(4) update request {
(4) &Chargeable-User-Identity := 0x00
(4) } # update request = noop
(4) } # if ("%{client:add_cui}" == 'yes') = noop
(4) } # policy cui.authorize = noop
(4) auth_log: EXPAND
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
(4) auth_log: -->
/var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(4) auth_log:
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
expands to /var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(4) auth_log: EXPAND %t
(4) auth_log: --> Wed May 15 10:01:24 2019
(4) [auth_log] = ok
(4) suffix: Checking for suffix after "@"
(4) suffix: Looking up realm "renater.fr" for User-Name =
"anonymous(a)renater.fr"
(4) suffix: Found realm "renater.fr"
(4) suffix: Adding Realm = "renater.fr"
(4) suffix: Authentication realm is LOCAL
(4) [suffix] = ok
(4) eap: Peer sent EAP Response (code 2) ID 5 length 6
(4) eap: Continuing tunnel setup
(4) [eap] = ok
(4) } # authorize = ok
(4) Found Auth-Type = eap
(4) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(4) authenticate {
(4) eap: Expiring EAP session with state 0xcaaa2a6cc9af33e7
(4) eap: Finished EAP session with state 0xcaaa2a6cc9af33e7
(4) eap: Previous EAP request found for state 0xcaaa2a6cc9af33e7,
released from the list
(4) eap: Peer sent packet with method EAP PEAP (25)
(4) eap: Calling submodule eap_peap to process data
(4) eap_peap: Continuing EAP-TLS
(4) eap_peap: Peer ACKed our handshake fragment
(4) eap_peap: [eaptls verify] = request
(4) eap_peap: [eaptls process] = handled
(4) eap: Sending EAP Request (code 1) ID 6 length 598
(4) eap: EAP session adding &reply:State = 0xcaaa2a6cceac33e7
(4) [eap] = handled
(4) } # authenticate = handled
(4) Using Post-Auth-Type Challenge
(4) Post-Auth-Type sub-section not found. Ignoring.
(4) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(4) Sent Access-Challenge Id 106 from 194.57.4.197:1812 to
195.220.94.1:1645 length 0
(4) EAP-Message =
0x01060256190098cf27364f11327474e640dd1dcdf2687735afb38c5dc604bf15f423678bb96f9704eb469dc2cdc9d1a4ae812ec9bab1e880d01cc939c15676596c9c7de3a9f0d3d134d83c49598b1a98cebfc6f2d83035ffe96f5da0af3aee6653aeaa8c69c8be9aa7a07bd8824b3313c807f377d7f364cd9e63f9422753ae103389723715f1bef71e35a2cec32df2d7b2e60bc769c0e51f5f7c699b7ece261a3344c3ba77053bba5d3f4189fa163bee046e5bac564bef8c70f24a7b57bd196e8b360754262d8609941f5f37abf0233f8f2c5f969e4771a844dea9b9852fb53460a55f09a09a431dd4bf2d44d68ddafd75cb5f16a00e61c2703d36160303014d0c0001490300174104338c12bd74ede52c52ca7f42320ec6f8b6504ffbee03cf64072b00d86733e5bdd64ad52a632dc45754243f5aeb2a255f98aaf93eed501786b8ec1e063e791ff104010100a09b99efec1da8d887c2b04a9f2085dd42d2880a6265447194091665e1c7f159b7aeea5e0217e455b641
(4) Message-Authenticator = 0x00000000000000000000000000000000
(4) State = 0xcaaa2a6cceac33e7ad7633b276a93937
(4) Finished request
Waking up in 4.9 seconds.
(5) Received Access-Request Id 107 from 195.220.94.1:1645 to
194.57.4.197:1812 length 167
(5) User-Name = "anonymous(a)renater.fr"
(5) Framed-MTU = 1400
(5) Called-Station-Id = "0012.d942.a460"
(5) Calling-Station-Id = "ccc0.7942.6070"
(5) Service-Type = Login-User
(5) Message-Authenticator = 0xd4447da78b6f5e04c59616dc33ec3fbe
(5) EAP-Message = 0x0206001119800000000715030300020250
(5) NAS-Port-Type = Wireless-802.11
(5) NAS-Port = 314
(5) State = 0xcaaa2a6cceac33e7ad7633b276a93937
(5) NAS-IP-Address = 195.220.94.1
(5) NAS-Identifier = "ap1000"
(5) session-state: No cached attributes
(5) # Executing section authorize from file
/etc/freeradius/sites-enabled/eduroam
(5) authorize {
(5) policy filter_username {
(5) if (&User-Name) {
(5) if (&User-Name) -> TRUE
(5) if (&User-Name) {
(5) if (&User-Name =~ / /) {
(5) if (&User-Name =~ / /) -> FALSE
(5) if (&User-Name =~ /@[^@]*@/ ) {
(5) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(5) if (&User-Name =~ /\.\./ ) {
(5) if (&User-Name =~ /\.\./ ) -> FALSE
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/))
-> FALSE
(5) if (&User-Name =~ /\.$/) {
(5) if (&User-Name =~ /\.$/) -> FALSE
(5) if (&User-Name =~ /(a)\./) {
(5) if (&User-Name =~ /(a)\./) -> FALSE
(5) if (&User-Name !~ /(a)renater.fr/) {
(5) if (&User-Name !~ /(a)renater.fr/) -> FALSE
(5) } # if (&User-Name) = notfound
(5) } # policy filter_username = notfound
(5) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(5) EXPAND %{client:shortname}
(5) --> borne-rennes-1100
(5) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) -> TRUE
(5) if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) {
(5) update request {
(5) Operator-Name := "1renater.fr"
(5) } # update request = noop
(5) } # if ("%{client:shortname}" !~ /rad[1-2]\.eduroam\.fr/) = noop
(5) policy cui.authorize {
(5) if ("%{client:add_cui}" == 'yes') {
(5) EXPAND %{client:add_cui}
(5) --> yes
(5) if ("%{client:add_cui}" == 'yes') -> TRUE
(5) if ("%{client:add_cui}" == 'yes') {
(5) update request {
(5) &Chargeable-User-Identity := 0x00
(5) } # update request = noop
(5) } # if ("%{client:add_cui}" == 'yes') = noop
(5) } # policy cui.authorize = noop
(5) auth_log: EXPAND
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
(5) auth_log: -->
/var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(5) auth_log:
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
expands to /var/log/freeradius/radacct/195.220.94.1/auth-detail-20190515
(5) auth_log: EXPAND %t
(5) auth_log: --> Wed May 15 10:01:24 2019
(5) [auth_log] = ok
(5) suffix: Checking for suffix after "@"
(5) suffix: Looking up realm "renater.fr" for User-Name =
"anonymous(a)renater.fr"
(5) suffix: Found realm "renater.fr"
(5) suffix: Adding Realm = "renater.fr"
(5) suffix: Authentication realm is LOCAL
(5) [suffix] = ok
(5) eap: Peer sent EAP Response (code 2) ID 6 length 17
(5) eap: Continuing tunnel setup
(5) [eap] = ok
(5) } # authorize = ok
(5) Found Auth-Type = eap
(5) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(5) authenticate {
(5) eap: Expiring EAP session with state 0xcaaa2a6cceac33e7
(5) eap: Finished EAP session with state 0xcaaa2a6cceac33e7
(5) eap: Previous EAP request found for state 0xcaaa2a6cceac33e7,
released from the list
(5) eap: Peer sent packet with method EAP PEAP (25)
(5) eap: Calling submodule eap_peap to process data
(5) eap_peap: Continuing EAP-TLS
(5) eap_peap: Peer indicated complete TLS record size will be 7 bytes
(5) eap_peap: Got complete TLS record (7 bytes)
(5) eap_peap: [eaptls verify] = length included
(5) eap_peap: <<< recv TLS 1.2 [length 0002]
(5) eap_peap: ERROR: TLS Alert read:fatal:internal error
(5) eap_peap: TLS_accept: Need to read more data: SSLv3/TLS write server
done
(5) eap_peap: ERROR: Failed in __FUNCTION__ (SSL_read):
error:14094438:SSL routines:ssl3_read_bytes:tlsv1 alert internal error
(5) eap_peap: ERROR: System call (I/O) error (-1)
(5) eap_peap: ERROR: TLS receive handshake failed during operation
(5) eap_peap: ERROR: [eaptls process] = fail
(5) eap: ERROR: Failed continuing EAP PEAP (25) session. EAP sub-module
failed
(5) eap: Sending EAP Failure (code 4) ID 6 length 4
(5) eap: Failed in EAP select
(5) [eap] = invalid
(5) } # authenticate = invalid
(5) Failed to authenticate the user
(5) Using Post-Auth-Type Reject
(5) # Executing group from file /etc/freeradius/sites-enabled/eduroam
(5) Post-Auth-Type REJECT {
(5) reply_log: EXPAND
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d
(5) reply_log: -->
/var/log/freeradius/radacct/195.220.94.1/reply-detail-20190515
(5) reply_log:
/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d
expands to /var/log/freeradius/radacct/195.220.94.1/reply-detail-20190515
(5) reply_log: EXPAND %t
(5) reply_log: --> Wed May 15 10:01:24 2019
(5) [reply_log] = ok
(5) eduroam_cui_log: EXPAND eduroam_log.%{%{reply:Packet-Type}:-format}
(5) eduroam_cui_log: --> eduroam_log.Access-Reject
(5) eduroam_cui_log: EXPAND %t :
eduroam-auth#ORG=%{request:Realm}#USER=%{User-Name}#CSI=%{%{Calling-Station-Id}:-Unknown
Caller Id}#NAS=%{%{Called-Station-Id}:-Unknown Access
Point}#CUI=%{%{reply:Chargeable-User-Identity}:-Unknown}#MSG=%{%{reply:Reply-Message}:-No
Failure Reason}#RESULT=FAIL#
(5) eduroam_cui_log: --> Wed May 15 10:01:24 2019 :
eduroam-auth#ORG=renater.fr#USER=anonymous@renater.fr#CSI=ccc0.7942.6070#NAS=0012.d942.a460#CUI=Unknown#MSG=No
Failure Reason#RESULT=FAIL#
(5) eduroam_cui_log: EXPAND /var/log/freeradius/radius.log
(5) eduroam_cui_log: --> /var/log/freeradius/radius.log
(5) [eduroam_cui_log] = ok
(5) } # Post-Auth-Type REJECT = ok
(5) Login incorrect (eap_peap: TLS Alert read:fatal:internal error):
[anonymous(a)renater.fr] (from client borne-rennes-1100 port 314 cli
ccc0.7942.6070)
(5) Sent Access-Reject Id 107 from 194.57.4.197:1812 to
195.220.94.1:1645 length 0
(5) EAP-Message = 0x04060004
(5) Message-Authenticator = 0x00000000000000000000000000000000
(5) Finished request
Any idea how to correct this error ?
Regards,
Arnaud Lauriou
1
1
16 May '19
Hi,
I follow "systemctl start-up not working correctly" thread because I'm
trying to integrate systemd watchdog support to Gentoo/Sabayon distro.
Currently, I'm testing Freeradius v3.0.x-HEAD with systemd-239 but it
seems that notifications returned to systemd aren't correct.
# systemctl --version
systemd 239
+PAM -AUDIT -SELINUX +IMA -APPARMOR +SMACK -SYSVINIT +UTMP
+LIBCRYPTSETUP +GCRYPT -GNUTLS +ACL +XZ +LZ4 +SECCOMP +BLKID -ELFUTILS
+KMOD -IDN2 -IDN +PCRE2 default-hierarchy=hybrid
# radiusd -v
radiusd: FreeRADIUS Version 3.0.20 (git #136ba4541), for host x86_64-
pc-linux-gnu, built on May 13 2019 at 16:31:56
FreeRADIUS Version 3.0.20
Copyright (C) 1999-2019 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
>From systemctl log I see that watchdog notification are returned by
freeradius server but probably are wrong because service receive
timeout.
May 13 19:51:35 radius radiusd[8093]: Mon May 13 19:51:35 2019 : Debug:
Waking up in 29.6 seconds.
May 13 19:52:04 radius radiusd[8093]: Mon May 13 19:52:04 2019 : Debug:
Emitting systemd watchdog notification
May 13 19:52:04 radius radiusd[8093]: Mon May 13 19:52:04 2019 : Debug:
Waking up in 29.9 seconds.
May 13 19:52:34 radius radiusd[8093]: Mon May 13 19:52:34 2019 : Debug:
Emitting systemd watchdog notification
May 13 19:52:34 radius radiusd[8093]: Mon May 13 19:52:34 2019 : Debug:
Waking up in 29.9 seconds.
May 13 19:53:04 radius radiusd[8093]: Mon May 13 19:53:04 2019 : Debug:
Emitting systemd watchdog notification
May 13 19:53:04 radius radiusd[8093]: Mon May 13 19:53:04 2019 : Debug:
Waking up in 29.9 seconds.
May 13 19:53:04 radius radiusd[8093]: Mon May 13 19:53:04 2019 : Info:
Signalled to terminate
May 13 19:53:04 radius systemd[1]: freeradius.service: Start operation
timed out. Terminating.
May 13 19:53:04 radius systemd[1]: freeradius.service: Failed with
result 'timeout'.
May 13 19:53:04 radius systemd[1]: Failed to start FreeRADIUS Server.
I will try to investigate better in the next days also with systemd
v.242.
-- geaaru
3
5
Hi,
I'm in the process of updating our radius servers from 3.0.3 to 3.0.18 and I can't seem to get the unix timestamps into redis the way it is currently done.
Currently my configuration is like this:
start-insert = "LPUSH logs|%{User-Name} %{Event-Timestamp#}, ...
On the new servers I'm building,
Seems like that changed in the current version freeradius. I've been over the documentation and read the configuration files to no avail.
I have tried to use date module, I have tried to use %S and %T from reading a few threads on this list but it keeps failing to convert into unix time..
I've tried this in the preacct section:
update request {
&Event-Timestamp := "%{date:%{Event-Timestamp}}"
}
Can someone point me to the # equivalent to get conversion to unix time?
Thanks.
-Mike
2
2
Hi list!
This issue was probably already answered but I cannot find it. I have a setup where FreeRADIUS can't have access to the database where NT hashes are stored. I would like FreeRADIUS to fire up a script and than fallback to SQL. This way I could at least temporarily grab the hash to local database with the script, script would "Reject", and FreeRADIUS would fall back to local SQL where the hash temporarily exists. After all the EAP magic - FreeRADIUS would try authorize the user via local database.
This is a VPN (not NAS, WiFi..) setup that for best compatibility with most operating systems would use EAP-MSCHAPv2 or EAP-TTLS but in any case - server is not receiving plaintext password from the user (like with PAP) so I can't pass it to the script.
I have tried the following configuration, but the only SQL queries fired after script "Rejects" the user are INSERTS logging this failure:
authorize {
filter_username
preprocess
auth_log
mschap
digest
expiration
logintime
eap
pap
update control {
Auth-Type := `/bin/python /scripts/radiusauth.py '%{User-Name}' 'rejectme'`
}
if (fail) {
sql
}
}
Please find the log below.
(2) Received Access-Request Id 197 from 127.0.0.1:28318 to 127.0.0.1:1812 length 144
(2) User-Name = "provided-username"
(2) NAS-Port-Type = Virtual
(2) Service-Type = Framed-User
(2) NAS-Port = 35
(2) NAS-Port-Id = "IKEv2"
(2) NAS-IP-Address = server-public-ip
(2) Called-Station-Id = "server-public-ip[4500]"
(2) Calling-Station-Id = "client-public-ip[60403]"
(2) EAP-Message = 0x0200000a0121349a
(2) NAS-Identifier = "vpn-software"
(2) Message-Authenticator = 0xa123abc123abc123abc123abc123abc1
(2) # Executing section authorize from file /etc/raddb/sites-enabled/default
(2) authorize {
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) } # if (&User-Name) = notfound
(2) } # policy filter_username = notfound
(2) [preprocess] = ok
(2) auth_log: EXPAND /var/log/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d
(2) auth_log: --> /var/log/radacct/127.0.0.1/auth-detail-20190503
(2) auth_log: /var/log/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d expands to /var/log/radacct/127.0.0.1/auth-detail-20190503
(2) auth_log: EXPAND %t
(2) auth_log: --> Fri May 3 07:11:31 2019
(2) [auth_log] = ok
(2) [chap] = noop
(2) [mschap] = noop
(2) [digest] = noop
(2) [expiration] = noop
(2) [logintime] = noop
(2) eap: Peer sent EAP Response (code 2) ID 0 length 10
(2) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(2) [eap] = ok
(2) pap: WARNING: No "known good" password found for the user. Not setting Auth-Type
(2) pap: WARNING: Authentication will fail unless a "known good" password is available
(2) [pap] = noop
(2) update control {
(2) Executing: /bin/python /scripts/radiusauth.py '%{User-Name}' 'rejectme':
(2) EXPAND %{User-Name}
(2) --> provided-username
(2) ERROR: Program returned code (1) and output 'Reject'
(2) } # update control = fail
(2) } # authorize = fail
(2) Invalid user (Program returned code (1) and output 'Reject'): [provided-username/<via Auth-Type = eap>] (from client localhost port 35 cli client-public-ip[60403])
(2) Using Post-Auth-Type Reject
(2) # Executing group from file /etc/raddb/sites-enabled/default
(2) Post-Auth-Type REJECT {
(2) sql: EXPAND .query
(2) sql: --> .query
(2) sql: Using query template 'query'
rlm_sql (sql): Closing connection (6): Hit idle_timeout, was idle for 5679 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql (sql): Closing connection (7): Hit idle_timeout, was idle for 5679 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql (sql): 0 of 0 connections in use. You may need to increase "spare"
rlm_sql (sql): Opening additional connection (8), 1 of 32 pending slots used
rlm_sql (sql): Reserved connection (8)
(2) sql: EXPAND %{User-Name}
(2) sql: --> provided-username
(2) sql: SQL-User-Name set to 'provided-username'
(2) sql: EXPAND INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( '%{SQL-User-Name}', '%{%{User-Password}:-%{Chap-Password}}', '%{reply:Packet-Type}', '%S')
(2) sql: --> INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( 'provided-username', '', 'Access-Reject', '2019-05-03 07:11:31')
(2) sql: Executing query: INSERT INTO radpostauth (username, pass, reply, authdate) VALUES ( 'provided-username', '', 'Access-Reject', '2019-05-03 07:11:31')
(2) sql: SQL query returned: success
(2) sql: 1 record(s) updated
rlm_sql (sql): Released connection (8)
Need 2 more connections to reach min connections (3)
rlm_sql (sql): Opening additional connection (9), 1 of 31 pending slots used
(2) [sql] = ok
(2) attr_filter.access_reject: EXPAND %{User-Name}
(2) attr_filter.access_reject: --> provided-username
(2) attr_filter.access_reject: Matched entry DEFAULT at line 11
(2) [attr_filter.access_reject] = updated
(2) eap: Request was previously rejected, inserting EAP-Failure
(2) eap: Sending EAP Failure (code 4) ID 0 length 4
(2) [eap] = updated
(2) } # Post-Auth-Type REJECT = updated
(2) Login incorrect (Program returned code (1) and output 'Reject'): [provided-username/<via Auth-Type = eap>] (from client localhost port 35 cli client-public-ip[60403])
(2) Delaying response for 1.000000 seconds
Waking up in 0.9 seconds.
(2) Sending delayed response
(2) Sent Access-Reject Id 197 from 127.0.0.1:1812 to 127.0.0.1:28318 length 44
(2) EAP-Message = 0x04000004
(2) Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 3.9 seconds.
(2) Cleaning up request packet ID 197 with timestamp +6729
Ready to process requests
TIA and apologies again if the question was already answered.
3
6
Hi I am trying to implement a freeradius solution for a firewall. i cant find documentation on how to configure yubikeys OTP with ldap. i am getting some errors with my config.
trying to see if there is good documentation out there
Thanks
rlm_ldap (ldap): Released connection (6)
(0) files: users: Matched entry DEFAULT at line 13
(0) [files] = ok
(0) yubikey: &request:Yubikey-OTP := <<< secret >>>
(0) yubikey: &request:User-Password := <<< secret >>>
(0) [yubikey] = ok
(0) if (ok) {
(0) if (ok) -> TRUE
(0) if (ok) {
(0) update control {
(0) Auth-Type := yubikey
(0) } # update control = noop
(0) } # if (ok) = noop
(0) } # authorize = ok
(0) Found Auth-Type = yubikey
(0) Found Auth-Type = yubikey
(0) ERROR: Warning: Found 2 auth-types on request for user 'chula'
(0) # Executing group from file /etc/raddb/sites-enabled/default
(0) Auth-Type yubikey {
(0) [yubikey] = noop
(0) update request {
(0) User-Password := Yubikey-Public-ID -> 'cccccckirnie'
(0) } # update request = noop
rlm_ldap (ldap): Reserved connection (5)
(0) ldap: Login attempt by "chula"
(0) ldap: Using user DN from request "cn=chula,ou=users,dc=xxxx,dc=yyyy"
(0) ldap: Waiting for bind result...
(0) ldap: ERROR: Bind credentials incorrect: Invalid credentials
rlm_ldap (ldap): Released connection (5)
(0) [ldap] = reject
(0) } # Auth-Type yubikey = reject
(0) Failed to authenticate the user
(0) Using Post-Auth-Type Reject
(0) Post-Auth-Type sub-section not found. Ignoring.
(0) # Executing group from file /etc/raddb/sites-enabled/default
Sent with [ProtonMail](https://protonmail.com) Secure Email.
2
1