Freeradius-Users
Threads by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 27050 discussions
Am Mittwoch, 10. Mai 2017, 19:58:30 CEST schrieben Sie:
> i'm going to guess that its because you've left the type unconstrained
> and thus its trying to do something silly like match
> a value/variable that doesnt exist
>
> if(&EAP-Type == "PEAP") {
> }
>
/etc/raddb/policy.d/vlan-id[5]: Parse error in condition
/etc/raddb/policy.d/vlan-id[5]: (&EAP-Type == "EAP-TLS") {
/etc/raddb/policy.d/vlan-id[5]: ^ Failed to parse value for
attribute
Doesn't work either.
And I seem to remember I tried that as well.
>
>
> the 'skipping' is a sign that its optimising out the condition..
>
Regards,
Felix
--
An engineer is someone who does list processing in FORTRAN.
1
0
10 May '17
I have a problem that I not able to fix it. I am trying to authenticate a
SSH user in a H3C switch. This switch is configured to authenticate the
user in a Radius server wich is using openldap to store the user's name and
password. Everytime I try to authenticate, I see a message in the
radius.log saying that "[eap] No EAP-Message, not doing EAP". I tryed do
use PAP, but I got "[pap] WARNING! No "known good" password found for the
user. Authentication may fail because of this." Dont't know what to do
anymore. I don't know how to (and if I have to) force the switch to use EAP
packetes.
rad_recv: Access-Request packet from host *nasipaddress *port 1758, id=67,
length=237
User-Name = "*username*"
User-Password = "*userpassword*"
NAS-IP-Address = *nasipaddress*
NAS-Identifier = "SwitchTeste"
NAS-Port = 0
NAS-Port-Id = "slot=0;subslot=0;port=0;vlanid=0"
NAS-Port-Type = Virtual
Service-Type = Login-User
Login-IP-Host = login-ip-host
Calling-Station-Id = "00-00-00-00-00-00"
Acct-Session-Id = "1170409171244010"
Framed-IP-Address = *framed-ip-address*
Huawei-Connect-ID = 290817
Huawei-Product-ID = "H3C S5500-28C-PWR-EI"
Huawei-IPHost-Addr = "*X.X.X.X 00:00:00:00:00:00*"
Huawei-Startup-Stamp = 956750420
# Executing section authorize from file /usr/local/etc/raddb/radiusd.conf
+group authorize {
++[preprocess] = ok
++[mschap] = noop
[eap] No EAP-Message, not doing EAP
++[eap] = noop
[pap] WARNING! No "known good" password found for the user. Authentication
may fail because of this.
++[pap] = noop
[ldap] performing user authorization for *username*
[ldap] expand: (uid=%{mschap:User-Name:-%{User-Name}}) -> (uid=*username*)
[ldap] expand: dc=*x*,dc=*x*,dc=*x* -> dc=*x*,dc=*x*,dc=*x*
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in dc=*x*,dc=*x*,dc=*x*, with filter (uid=
*username*)
[ldap] looking for check items in directory...
[ldap] sambaNtPassword -> NT-Password == 0x3141363239333542344541464539
453736383232383241463838393445364439
[ldap] sambaLmPassword -> LM-Password == 0x3230433630443539444246304241
383345363841413236413834314138364641
[ldap] looking for reply items in directory...
[ldap] ldap_release_conn: Release Id: 0
++[ldap] = ok
+} # group authorize = ok
ERROR: No authenticate method (Auth-Type) found for the request: Rejecting
the user
Failed to authenticate the user.
Using Post-Auth-Type Reject
# Executing group from file /usr/local/etc/raddb/sites-enabled/default
+group REJECT {
[attr_filter.access_reject] expand: %{User-Name} -> *username*
attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] = updated
+} # group REJECT = updated
Delaying reject of request 12 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 12
Sending Access-Reject of id 67 to *framed-ip-address* port 1758
ps.: had to put the names in bold so that i don't expose the client's
information.
Below is the ouput of the radius -X:
[root@radius ~]# radiusd -X
radiusd: FreeRADIUS Version 2.2.9, for host x86_64-unknown-linux-gnu, built
on Feb 7 2017 at 15:49:06
Copyright (C) 1999-2015 The FreeRADIUS server project and contributors.
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE.
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License.
For more information about these matters, see the file named COPYRIGHT.
Starting - reading configuration files ...
including configuration file /usr/local/etc/raddb/radiusd.conf
including configuration file /usr/local/etc/raddb/clients.conf
including files in directory /usr/local/etc/raddb/modules/
including configuration file /usr/local/etc/raddb/modules/always
including configuration file /usr/local/etc/raddb/modules/mac2vlan
including configuration file /usr/local/etc/raddb/modules/detail.log
including configuration file /usr/local/etc/raddb/modules/counter
including configuration file /usr/local/etc/raddb/modules/radutmp
including configuration file /usr/local/etc/raddb/modules/smbpasswd
including configuration file /usr/local/etc/raddb/modules/mschap
including configuration file /usr/local/etc/raddb/modules/linelog
including configuration file /usr/local/etc/raddb/modules/expr
including configuration file /usr/local/etc/raddb/modules/etc_group
including configuration file /usr/local/etc/raddb/modules/sql_log
including configuration file
/usr/local/etc/raddb/modules/sqlcounter_expire_on_login
including configuration file /usr/local/etc/raddb/modules/acct_unique
including configuration file /usr/local/etc/raddb/modules/ippool
including configuration file /usr/local/etc/raddb/modules/realm
including configuration file /usr/local/etc/raddb/modules/mac2ip
including configuration file /usr/local/etc/raddb/modules/digest
including configuration file /usr/local/etc/raddb/modules/inner-eap
including configuration file /usr/local/etc/raddb/modules/ldap
including configuration file /usr/local/etc/raddb/modules/logintime
including configuration file /usr/local/etc/raddb/modules/wimax
including configuration file /usr/local/etc/raddb/modules/expiration
including configuration file /usr/local/etc/raddb/modules/cui
including configuration file /usr/local/etc/raddb/modules/checkval
including configuration file /usr/local/etc/raddb/modules/perl
including configuration file /usr/local/etc/raddb/modules/preprocess
including configuration file /usr/local/etc/raddb/modules/detail
including configuration file /usr/local/etc/raddb/modules/unix
including configuration file /usr/local/etc/raddb/modules/pam
including configuration file /usr/local/etc/raddb/modules/attr_filter
including configuration file /usr/local/etc/raddb/modules/chap
including configuration file /usr/local/etc/raddb/modules/policy
including configuration file /usr/local/etc/raddb/modules/files
including configuration file /usr/local/etc/raddb/modules/exec
including configuration file /usr/local/etc/raddb/modules/detail.example.com
including configuration file /usr/local/etc/raddb/modules/attr_rewrite
including configuration file /usr/local/etc/raddb/modules/otp
including configuration file /usr/local/etc/raddb/modules/passwd
including configuration file /usr/local/etc/raddb/modules/smsotp
including configuration file /usr/local/etc/raddb/modules/sradutmp
including configuration file /usr/local/etc/raddb/modules/echo
including configuration file /usr/local/etc/raddb/eap.conf
including configuration file /usr/local/etc/raddb/policy.conf
including files in directory /usr/local/etc/raddb/sites-enabled/
including configuration file
/usr/local/etc/raddb/sites-enabled/control-socket
including configuration file /usr/local/etc/raddb/sites-enabled/default
including configuration file /usr/local/etc/raddb/sites-enabled/inner-tunnel
main {
user = "radiusd"
group = "radiusd"
allow_core_dumps = no
}
including dictionary file /usr/local/etc/raddb/dictionary
main {
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/radius/"
run_dir = "/var/run/radiusd"
libdir = "/usr/lib/freeradius"
radacctdir = "/var/log/radius//radacct"
hostname_lookups = yes
max_request_time = 30
cleanup_delay = 5
max_requests = 1024
pidfile = "/var/run/radiusd/radiusd.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 2
proxy_requests = no
log {
stripped_names = yes
auth = no
auth_badpass = yes
auth_goodpass = yes
}
security {
max_attributes = 200
reject_delay = 1
status_server = yes
allow_vulnerable_openssl = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = "*xxx*"
nastype = "other"
}
client *IP1 *{
require_message_authenticator = no
secret = "*xxx*"
shortname = "*yyy*"
}
client *IP2 *{
require_message_authenticator = no
secret = "*xxx*"
shortname = "*yyy*"
}
client * IP3 *{
require_message_authenticator = no
secret = "*xxx*"
shortname = "*yyy*"
nastype = "other"
}
client *IP4 *{
require_message_authenticator = no
secret = "*xxx*"
shortname = "*yyy*"
nastype = "other"
}
client *IP5* {
require_message_authenticator = no
secret = "*xxx*"
shortname = "*yyy*"
nastype = "other"
}
client *IP6* {
require_message_authenticator = no
secret = "xxx"
shortname = "*yyy*"
nastype = "other"
}
client *IP7* {
require_message_authenticator = no
secret = "xxx"
shortname = "*yyy*"
nastype = "other"
}
client *IP8* {
require_message_authenticator = no
secret = "*xxx*"
}
client *IP9* {
require_message_authenticator = no
secret = "*xxx*"
shortname = "SwitchTeste"
nastype = "other"
}
radiusd: #### Instantiating modules ####
instantiate {
Module: Linked to module rlm_exec
Module: Instantiating module "exec" from file
/usr/local/etc/raddb/modules/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
}
Module: Linked to module rlm_expr
Module: Instantiating module "expr" from file
/usr/local/etc/raddb/modules/expr
Module: Linked to module rlm_expiration
Module: Instantiating module "expiration" from file
/usr/local/etc/raddb/modules/expiration
expiration {
reply-message = "Password Has Expired "
}
Module: Linked to module rlm_logintime
Module: Instantiating module "logintime" from file
/usr/local/etc/raddb/modules/logintime
logintime {
reply-message = "You are calling outside your allowed timespan "
minimum-timeout = 60
}
}
radiusd: #### Loading Virtual Servers ####
server { # from file /usr/local/etc/raddb/radiusd.conf
modules {
Module: Checking authenticate {...} for more modules to load
Module: Linked to module rlm_mschap
Module: Instantiating module "mschap" from file
/usr/local/etc/raddb/modules/mschap
mschap {
use_mppe = yes
require_encryption = yes
require_strong = yes
with_ntdomain_hack = yes
allow_retry = yes
}
Module: Linked to module rlm_pap
Module: Instantiating module "pap" from file
/usr/local/etc/raddb/radiusd.conf
pap {
encryption_scheme = "clear"
auto_header = no
}
Module: Linked to module rlm_eap
Module: Instantiating module "eap" from file /usr/local/etc/raddb/eap.conf
eap {
default_eap_type = "peap"
timer_expire = 120
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 2048
}
Module: Linked to sub-module rlm_eap_gtc
Module: Instantiating eap-gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
Module: Linked to sub-module rlm_eap_tls
Module: Instantiating eap-tls
tls {
rsa_key_exchange = no
dh_key_exchange = yes
rsa_key_length = 512
dh_key_length = 512
verify_depth = 0
pem_file_type = yes
private_key_file = "/etc/raddb/certs/server_key.pem"
certificate_file = "/etc/raddb/certs/server_cert.pem"
CA_file = "/etc/raddb/certs/cacert.pem"
private_key_password = "oservidorquerentrar"
dh_file = "/etc/raddb/certs/dh"
random_file = "/etc/raddb/certs/random"
fragment_size = 1024
include_length = no
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
ecdh_curve = "prime256v1"
cache {
enable = yes
lifetime = 12
max_entries = 0
}
}
Module: Linked to sub-module rlm_eap_ttls
Module: Instantiating eap-ttls
ttls {
default_eap_type = "mschapv2"
copy_request_to_tunnel = yes
use_tunneled_reply = yes
include_length = yes
}
Module: Linked to sub-module rlm_eap_peap
Module: Instantiating eap-peap
peap {
default_eap_type = "mschapv2"
copy_request_to_tunnel = yes
use_tunneled_reply = yes
proxy_tunneled_request_as_eap = yes
soh = no
}
Module: Linked to sub-module rlm_eap_mschapv2
Module: Instantiating eap-mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
Module: Checking authorize {...} for more modules to load
Module: Linked to module rlm_preprocess
Module: Instantiating module "preprocess" from file
/usr/local/etc/raddb/modules/preprocess
preprocess {
huntgroups = "/usr/local/etc/raddb/huntgroups"
hints = "/usr/local/etc/raddb/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
reading pairlist file /usr/local/etc/raddb/huntgroups
reading pairlist file /usr/local/etc/raddb/hints
Module: Linked to module rlm_ldap
Module: Instantiating module "ldap" from file
/usr/local/etc/raddb/modules/ldap
ldap {
server = "*xxx*"
port = 389
password = "*xxx*"
expect_password = yes
identity = "cn=Manager,dc=*xxx*,dc=*xxx*,dc=*xxx*"
net_timeout = 1
timeout = 4
timelimit = 3
max_uses = 0
tls_mode = no
start_tls = no
tls_require_cert = "allow"
tls {
start_tls = no
require_cert = "never"
}
basedn = "dc=*xxx*,dc=*xxx*,dc=*xxx*"
filter = "(uid=%{mschap:User-Name:-%{User-Name}})"
base_filter = "(objectclass=radiusprofile)"
auto_header = no
access_attr_used_for_allow = yes
groupname_attribute = "cn"
groupmembership_filter =
"(|(&(objectClass=GroupOfNames)(member=%{Ldap-UserDn}))(&(objectClass=GroupOfUniqueNames)(uniquemember=%{Ldap-UserDn})))"
dictionary_mapping = "/usr/local/etc/raddb/ldap.attrmap"
ldap_debug = 0
ldap_connections_number = 5
compare_check_items = no
do_xlat = yes
set_auth_type = yes
}
rlm_ldap: Registering ldap_groupcmp for Ldap-Group
rlm_ldap: Registering ldap_xlat with xlat_name ldap
rlm_ldap: Over-riding set_auth_type, as there is no module ldap listed in
the "authenticate" section.
rlm_ldap: reading ldap<->radius mappings from file
/usr/local/etc/raddb/ldap.attrmap
rlm_ldap: LDAP radiusCheckItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusReplyItem mapped to RADIUS $GENERIC$
rlm_ldap: LDAP radiusAuthType mapped to RADIUS Auth-Type
rlm_ldap: LDAP radiusSimultaneousUse mapped to RADIUS Simultaneous-Use
rlm_ldap: LDAP radiusCalledStationId mapped to RADIUS Called-Station-Id
rlm_ldap: LDAP radiusCallingStationId mapped to RADIUS Calling-Station-Id
rlm_ldap: LDAP lmPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP ntPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP sambaLmPassword mapped to RADIUS LM-Password
rlm_ldap: LDAP sambaNtPassword mapped to RADIUS NT-Password
rlm_ldap: LDAP dBCSPwd mapped to RADIUS LM-Password
rlm_ldap: LDAP acctFlags mapped to RADIUS SMB-Account-CTRL-TEXT
rlm_ldap: LDAP radiusExpiration mapped to RADIUS Expiration
rlm_ldap: LDAP radiusNASIpAddress mapped to RADIUS NAS-IP-Address
rlm_ldap: LDAP radiusServiceType mapped to RADIUS Service-Type
rlm_ldap: LDAP radiusFramedProtocol mapped to RADIUS Framed-Protocol
rlm_ldap: LDAP radiusFramedIPAddress mapped to RADIUS Framed-IP-Address
rlm_ldap: LDAP radiusFramedIPNetmask mapped to RADIUS Framed-IP-Netmask
rlm_ldap: LDAP radiusFramedRoute mapped to RADIUS Framed-Route
rlm_ldap: LDAP radiusFramedRouting mapped to RADIUS Framed-Routing
rlm_ldap: LDAP radiusFilterId mapped to RADIUS Filter-Id
rlm_ldap: LDAP radiusFramedMTU mapped to RADIUS Framed-MTU
rlm_ldap: LDAP radiusFramedCompression mapped to RADIUS Framed-Compression
rlm_ldap: LDAP radiusLoginIPHost mapped to RADIUS Login-IP-Host
rlm_ldap: LDAP radiusLoginService mapped to RADIUS Login-Service
rlm_ldap: LDAP radiusLoginTCPPort mapped to RADIUS Login-TCP-Port
rlm_ldap: LDAP radiusCallbackNumber mapped to RADIUS Callback-Number
rlm_ldap: LDAP radiusCallbackId mapped to RADIUS Callback-Id
rlm_ldap: LDAP radiusFramedIPXNetwork mapped to RADIUS Framed-IPX-Network
rlm_ldap: LDAP radiusClass mapped to RADIUS Class
rlm_ldap: LDAP radiusSessionTimeout mapped to RADIUS Session-Timeout
rlm_ldap: LDAP radiusIdleTimeout mapped to RADIUS Idle-Timeout
rlm_ldap: LDAP radiusTerminationAction mapped to RADIUS Termination-Action
rlm_ldap: LDAP radiusLoginLATService mapped to RADIUS Login-LAT-Service
rlm_ldap: LDAP radiusLoginLATNode mapped to RADIUS Login-LAT-Node
rlm_ldap: LDAP radiusLoginLATGroup mapped to RADIUS Login-LAT-Group
rlm_ldap: LDAP radiusFramedAppleTalkLink mapped to RADIUS
Framed-AppleTalk-Link
rlm_ldap: LDAP radiusFramedAppleTalkNetwork mapped to RADIUS
Framed-AppleTalk-Network
rlm_ldap: LDAP radiusFramedAppleTalkZone mapped to RADIUS
Framed-AppleTalk-Zone
rlm_ldap: LDAP radiusPortLimit mapped to RADIUS Port-Limit
rlm_ldap: LDAP radiusLoginLATPort mapped to RADIUS Login-LAT-Port
rlm_ldap: LDAP radiusReplyMessage mapped to RADIUS Reply-Message
rlm_ldap: LDAP radiusTunnelType mapped to RADIUS Tunnel-Type
rlm_ldap: LDAP radiusTunnelMediumType mapped to RADIUS Tunnel-Medium-Type
rlm_ldap: LDAP radiusTunnelPrivateGroupId mapped to RADIUS
Tunnel-Private-Group-Id
conns: 0x1e83b40
Module: Checking preacct {...} for more modules to load
Module: Linked to module rlm_acct_unique
Module: Instantiating module "acct_unique" from file
/usr/local/etc/raddb/modules/acct_unique
acct_unique {
key = "User-Name, Acct-Session-Id, NAS-IP-Address,
Client-IP-Address, NAS-Port"
}
Module: Linked to module rlm_realm
Module: Instantiating module "suffix" from file
/usr/local/etc/raddb/modules/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
Module: Linked to module rlm_files
Module: Instantiating module "files" from file
/usr/local/etc/raddb/modules/files
files {
usersfile = "/usr/local/etc/raddb/users"
acctusersfile = "/usr/local/etc/raddb/acct_users"
preproxy_usersfile = "/usr/local/etc/raddb/preproxy_users"
compat = "no"
}
reading pairlist file /usr/local/etc/raddb/users
reading pairlist file /usr/local/etc/raddb/acct_users
reading pairlist file /usr/local/etc/raddb/preproxy_users
Module: Checking accounting {...} for more modules to load
Module: Linked to module rlm_detail
Module: Instantiating module "detail" from file
/usr/local/etc/raddb/modules/detail
detail {
detailfile =
"/var/log/radius//radacct/%{Client-IP-Address}/detail-%Y%m%d"
header = "%t"
detailperm = 384
dirperm = 493
locking = no
log_packet_header = no
escape_filenames = no
}
Module: Linked to module rlm_unix
Module: Instantiating module "unix" from file
/usr/local/etc/raddb/modules/unix
unix {
radwtmp = "/var/log/radius//radwtmp"
}
Module: Linked to module rlm_radutmp
Module: Instantiating module "radutmp" from file
/usr/local/etc/raddb/modules/radutmp
radutmp {
filename = "/var/log/radius//radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
perm = 384
callerid = yes
}
Module: Linked to module rlm_attr_filter
Module: Instantiating module "attr_filter.accounting_response" from file
/usr/local/etc/raddb/modules/attr_filter
attr_filter attr_filter.accounting_response {
attrsfile = "/usr/local/etc/raddb/attrs.accounting_response"
key = "%{User-Name}"
relaxed = no
}
reading pairlist file /usr/local/etc/raddb/attrs.accounting_response
Module: Checking session {...} for more modules to load
Module: Checking post-proxy {...} for more modules to load
Module: Checking post-auth {...} for more modules to load
Module: Instantiating module "attr_filter.access_reject" from file
/usr/local/etc/raddb/modules/attr_filter
attr_filter attr_filter.access_reject {
attrsfile = "/usr/local/etc/raddb/attrs.access_reject"
key = "%{User-Name}"
relaxed = no
}
reading pairlist file /usr/local/etc/raddb/attrs.access_reject
} # modules
} # server
server inner-tunnel { # from file
/usr/local/etc/raddb/sites-enabled/inner-tunnel
modules {
Module: Checking authenticate {...} for more modules to load
Module: Linked to module rlm_chap
Module: Instantiating module "chap" from file
/usr/local/etc/raddb/radiusd.conf
Module: Checking authorize {...} for more modules to load
Module: Checking session {...} for more modules to load
Module: Checking post-proxy {...} for more modules to load
Module: Checking post-auth {...} for more modules to load
} # modules
} # server
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = *xxx*
port = 1812
}
listen {
type = "acct"
ipaddr = *xxx*
port = 1813
}
listen {
type = "control"
listen {
socket = "/var/run/radiusd/radiusd.sock"
uid = "*XXX*"
gid = "*XXX*"
mode = "rw"
}
}
Listening on authentication address *xxx* port 1812
Listening on accounting address *xxx* port 1813
Listening on command file /var/run/radiusd/radiusd.sock
Ready to process requests.
Att.
Leandro
2
1
Hi all,
I’m trying to incorporate FreeRADIUS 3 into pkgsrc.
In looking at the spec file in
https://github.com/FreeRADIUS/freeradius-server/blob/v4.0.x/redhat/freeradi…
one sees an RPM post-install script that calls /etc/raddb/certs/bootstrap if needed. Clearly, if one were actually running ‘make install’ in production, that work would be necessary as the Makefile does it. However, if one is building a package, that step in ‘raddb/all.mk’ seems superfluous, and means that one need remove a bunch of ephemeral files from the DESTDIR before packaging.
Rather than having my package build framework let the bootstrap run in the DESTDIR and nuke the artifacts it creates before packaging, is there some setting one can tweak to skip that bootstrap as part of make install?
Thanks
—
Coy Hile
coy.hile(a)coyhile.com
2
2
On Wed, May 10, 2017 at 3:30 PM, <
freeradius-users-request(a)lists.freeradius.org> wrote:
> Send Freeradius-Users mailing list submissions to
> freeradius-users(a)lists.freeradius.org
>
> To subscribe or unsubscribe via the World Wide Web, visit
> http://lists.freeradius.org/mailman/listinfo/freeradius-users
> or, via email, send a message with subject or body 'help' to
> freeradius-users-request(a)lists.freeradius.org
>
> You can reach the person managing the list at
> freeradius-users-owner(a)lists.freeradius.org
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Freeradius-Users digest..."
>
>
> Today's Topics:
>
> 1. Re: TLS Variables not set (Yusuf Siddiqui)
> 2. Re: free radius Not able to add clients from nas table mysql
> (Alan DeKok)
> 3. Bootstrap portion of 'make install' (Coy Hile)
> 4. Re: Bootstrap portion of 'make install' (Alan DeKok)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Tue, 9 May 2017 17:31:42 +0530
> From: Yusuf Siddiqui <joseph490(a)gmail.com>
> To: FreeRadius users mailing list
> <freeradius-users(a)lists.freeradius.org>
> Subject: Re: TLS Variables not set
> Message-ID:
> <CACx-Ti1nZ-S1uEJ84qa-3U77T_L-VSGWdjdBXGu45M0HpejCWA@mail.
> gmail.com>
> Content-Type: text/plain; charset=UTF-8
>
> Congrats! :-)
>
>
>
> Regards
> Mohd Yusuf Siddiqui
> email: yusuf.siddiqui(a)fiyutech.com
> www. <http://www.ibots.org/>fiyutech.com
> Mob. +91.991.033.914.3,+91.989.102.455.4
> Off:+91.120.
>
> 49.89.65.4
> U.S. +120.975.347.57
>
> *___________________________________________________________
> ____________________________________________________________
> ___________________________________________*
>
> This communication & accompanying documents ("this e-mail") contains
> confidential and/or privileged information for exclusive use of the
> individual
> to whom it is addressed. If you are not the intended recipient, please
> immediately notify the company & delete this e-mail. Any unauthorized use
> or disclosure of this e-mail is strictly prohibited. Representations in
> this
> e-mail are subject to contract. As an e-mail user please be cautious of the
> technical & other vulnerabilities of the internet which may result in
> malicious
> and/or unauthorized access to / use / alteration of e-mails/e-mail IDs.
> Thank you.
>
> *___________________________________________________________
> ____________________________________________________________
> ________________________________________*
>
> On Tue, May 9, 2017 at 10:14 AM, Luke Pascoe <luke(a)osnz.co.nz> wrote:
>
> > Finally got around to building 3.0.13 for CentOS 7, and yes, the problem
> is
> > now fixed.
> >
> > Thanks.
> >
> > Luke Pascoe
> >
> >
> >
> > *E* luke(a)osnz.co.nz
> > * P* +64 (9) 296 2961
> > * M* +64 (27) 426 6649
> > * W* www.osnz.co.nz
> >
> > 24 Wellington St
> > Papakura
> > Auckland, 2110
> > New Zealand
> >
> > On 22 April 2017 at 00:56, Alan DeKok <aland(a)deployingradius.com> wrote:
> >
> > > On Apr 20, 2017, at 11:28 PM, Luke Pascoe <luke(a)osnz.co.nz> wrote:
> > > >
> > > > Hi,
> > > >
> > > > I'm having trouble getting some basic TLS checks working for a Wifi
> > > EAP-TLS
> > > > connection.
> > > >
> > > > Centos7, freeradius 3.0.4
> > >
> > > Use 3.0.13.
> > >
> > > Alan DeKok.
> > >
> > > -
> > > List info/subscribe/unsubscribe? See http://www.freeradius.org/
> > > list/users.html
> > -
> > List info/subscribe/unsubscribe? See http://www.freeradius.org/
> > list/users.html
>
>
> ------------------------------
>
> Message: 2
> Date: Tue, 9 May 2017 08:58:37 -0400
> From: Alan DeKok <aland(a)deployingradius.com>
> To: FreeRadius users mailing list
> <freeradius-users(a)lists.freeradius.org>
> Subject: Re: free radius Not able to add clients from nas table mysql
> Message-ID: <9361521E-4EFA-4EBF-A3D0-F014241BFC03(a)deployingradius.com>
> Content-Type: text/plain; charset=us-ascii
>
> On May 9, 2017, at 7:08 AM, avnel vernon <avnelvernon(a)gmail.com> wrote:
> >
> > [root@localhost ~]# radiusd -X
> > radiusd: FreeRADIUS Version 3.0.4, for host x86_64-redhat-linux-gnu,
> built
>
> Upgrade.
>
> > rlm_sql (sql): Executing query: 'SELECT id, nasname, shortname, type,
> > secret, server FROM nas'
> > rlm_sql (sql): Adding client zd (zd) to 192.168.1.173 clients list
> > ip_hton: Name or service not known
>
> Something in your local system is broken. I've never seen this issue
> before.
>
> Upgrade.
>
> Alan DeKok.
>
>
>
>
>
> ------------------------------
>
> Message: 3
> Date: Tue, 9 May 2017 20:48:30 -0400
> From: Coy Hile <coy.hile(a)coyhile.com>
> To: freeradius-users(a)lists.freeradius.org
> Subject: Bootstrap portion of 'make install'
> Message-ID: <B2E81B39-0DCF-49BB-AD52-7BA8FFF5F213(a)coyhile.com>
> Content-Type: text/plain; charset=utf-8
>
> Hi all,
>
> I’m trying to incorporate FreeRADIUS 3 into pkgsrc.
>
>
> In looking at the spec file in
>
> https://github.com/FreeRADIUS/freeradius-server/blob/v4.0.x/
> redhat/freeradius.spec
>
> one sees an RPM post-install script that calls /etc/raddb/certs/bootstrap
> if needed. Clearly, if one were actually running ‘make install’ in
> production, that work would be necessary as the Makefile does it. However,
> if one is building a package, that step in ‘raddb/all.mk’ seems
> superfluous, and means that one need remove a bunch of ephemeral files from
> the DESTDIR before packaging.
>
> Rather than having my package build framework let the bootstrap run in the
> DESTDIR and nuke the artifacts it creates before packaging, is there some
> setting one can tweak to skip that bootstrap as part of make install?
>
> Thanks
>
> —
> Coy Hile
> coy.hile(a)coyhile.com
>
>
> ------------------------------
>
> Message: 4
> Date: Tue, 9 May 2017 21:29:16 -0400
> From: Alan DeKok <aland(a)deployingradius.com>
> To: FreeRadius users mailing list
> <freeradius-users(a)lists.freeradius.org>
> Subject: Re: Bootstrap portion of 'make install'
> Message-ID: <C73D6587-E5A4-4DD2-BB67-E034FBEC46C6(a)deployingradius.com>
> Content-Type: text/plain; charset=utf-8
>
> On May 9, 2017, at 8:48 PM, Coy Hile <coy.hile(a)coyhile.com> wrote:
> > In looking at the spec file in
> >
> > https://github.com/FreeRADIUS/freeradius-server/blob/v4.0.x/
> redhat/freeradius.spec
> >
> > one sees an RPM post-install script that calls
> /etc/raddb/certs/bootstrap if needed. Clearly, if one were actually
> running ‘make install’ in production, that work would be necessary as the
> Makefile does it. However, if one is building a package, that step in
> ‘raddb/all.mk’ seems superfluous, and means that one need remove a bunch
> of ephemeral files from the DESTDIR before packaging.
>
> Yes. That's why you can do:
>
> $ PACKAGE=yes make install
>
> And the various auto-generated certs *won't* be created or installed.
>
> > Rather than having my package build framework let the bootstrap run in
> the DESTDIR and nuke the artifacts it creates before packaging, is there
> some setting one can tweak to skip that bootstrap as part of make install?
>
> See above. The Linux packages have similar requirements, hence the
> current solution.
>
> Alan DeKok.
>
>
>
>
> ------------------------------
>
> Subject: Digest Footer
>
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/
> list/users.html
>
> ------------------------------
>
> End of Freeradius-Users Digest, Vol 145, Issue 24
> *************************************************
>
Hii i tried in another machine still facing same issue
2
1
ip_hton: Name or service not known
[root@localhost ~]# radiusd -X
radiusd: FreeRADIUS Version 3.0.4, for host x86_64-redhat-linux-gnu, built
on Jan 17 2017 at 18:49:55
Copyright (C) 1999-2014 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/raddb/dictionary
including configuration file /etc/raddb/radiusd.conf
including configuration file /etc/raddb/proxy.conf
including configuration file /etc/raddb/clients.conf
including files in directory /etc/raddb/mods-enabled/
including configuration file /etc/raddb/mods-enabled/always
including configuration file /etc/raddb/mods-enabled/attr_filter
including configuration file /etc/raddb/mods-enabled/cache_eap
including configuration file /etc/raddb/mods-enabled/chap
including configuration file /etc/raddb/mods-enabled/detail
including configuration file /etc/raddb/mods-enabled/detail.log
including configuration file /etc/raddb/mods-enabled/dhcp
including configuration file /etc/raddb/mods-enabled/digest
including configuration file /etc/raddb/mods-enabled/dynamic_clients
including configuration file /etc/raddb/mods-enabled/eap
including configuration file /etc/raddb/mods-enabled/echo
including configuration file /etc/raddb/mods-enabled/exec
including configuration file /etc/raddb/mods-enabled/expiration
including configuration file /etc/raddb/mods-enabled/expr
including configuration file /etc/raddb/mods-enabled/files
including configuration file /etc/raddb/mods-enabled/linelog
including configuration file /etc/raddb/mods-enabled/logintime
including configuration file /etc/raddb/mods-enabled/mschap
including configuration file /etc/raddb/mods-enabled/ntlm_auth
including configuration file /etc/raddb/mods-enabled/pap
including configuration file /etc/raddb/mods-enabled/passwd
including configuration file /etc/raddb/mods-enabled/preprocess
including configuration file /etc/raddb/mods-enabled/radutmp
including configuration file /etc/raddb/mods-enabled/realm
including configuration file /etc/raddb/mods-enabled/replicate
including configuration file /etc/raddb/mods-enabled/soh
including configuration file /etc/raddb/mods-enabled/sradutmp
including configuration file /etc/raddb/mods-enabled/unix
including configuration file /etc/raddb/mods-enabled/unpack
including configuration file /etc/raddb/mods-enabled/utf8
including configuration file /etc/raddb/mods-enabled/sql
including configuration file
/etc/raddb/mods-config/sql/main/mysql/queries.conf
including files in directory /etc/raddb/policy.d/
including configuration file /etc/raddb/policy.d/accounting
including configuration file /etc/raddb/policy.d/canonicalization
including configuration file /etc/raddb/policy.d/control
including configuration file /etc/raddb/policy.d/cui
including configuration file /etc/raddb/policy.d/debug
including configuration file /etc/raddb/policy.d/dhcp
including configuration file /etc/raddb/policy.d/eap
including configuration file /etc/raddb/policy.d/filter
including configuration file /etc/raddb/policy.d/operator-name
including files in directory /etc/raddb/sites-enabled/
including configuration file /etc/raddb/sites-enabled/default
including configuration file /etc/raddb/sites-enabled/inner-tunnel
main {
security {
user = "radiusd"
group = "radiusd"
allow_core_dumps = no
}
}
main {
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/radius"
run_dir = "/var/run/radiusd"
libdir = "/usr/lib64/freeradius"
radacctdir = "/var/log/radius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 1024
pidfile = "/var/run/radiusd/radiusd.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
security {
max_attributes = 200
reject_delay = 1
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
radiusd: #### Instantiating modules ####
instantiate {
}
modules {
# Loaded module rlm_always
# Instantiating module "reject" from file /etc/raddb/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Instantiating module "fail" from file /etc/raddb/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Instantiating module "ok" from file /etc/raddb/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Instantiating module "handled" from file /etc/raddb/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Instantiating module "invalid" from file /etc/raddb/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Instantiating module "userlock" from file /etc/raddb/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Instantiating module "notfound" from file /etc/raddb/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Instantiating module "noop" from file /etc/raddb/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Instantiating module "updated" from file /etc/raddb/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_attr_filter
# Instantiating module "attr_filter.post-proxy" from file
/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/etc/raddb/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
reading pairlist file /etc/raddb/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file
/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/etc/raddb/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
reading pairlist file /etc/raddb/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file
/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/etc/raddb/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
reading pairlist file /etc/raddb/mods-config/attr_filter/access_reject
# Instantiating module "attr_filter.access_challenge" from file
/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/etc/raddb/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
reading pairlist file /etc/raddb/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file
/etc/raddb/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/etc/raddb/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
reading pairlist file /etc/raddb/mods-config/attr_filter/accounting_response
# Loaded module rlm_cache
# Instantiating module "cache_eap" from file
/etc/raddb/mods-enabled/cache_eap
cache cache_eap {
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 16384
epoch = 0
add_stats = no
}
# Loaded module rlm_chap
# Instantiating module "chap" from file /etc/raddb/mods-enabled/chap
# Loaded module rlm_detail
# Instantiating module "detail" from file /etc/raddb/mods-enabled/detail
detail {
filename =
"/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
log_packet_header = no
}
# Instantiating module "auth_log" from file
/etc/raddb/mods-enabled/detail.log
detail auth_log {
filename =
"/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
log_packet_header = no
}
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in
detail output
# Instantiating module "reply_log" from file
/etc/raddb/mods-enabled/detail.log
detail reply_log {
filename =
"/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
log_packet_header = no
}
# Instantiating module "pre_proxy_log" from file
/etc/raddb/mods-enabled/detail.log
detail pre_proxy_log {
filename =
"/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
log_packet_header = no
}
# Instantiating module "post_proxy_log" from file
/etc/raddb/mods-enabled/detail.log
detail post_proxy_log {
filename =
"/var/log/radius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
log_packet_header = no
}
# Loaded module rlm_dhcp
# Instantiating module "dhcp" from file /etc/raddb/mods-enabled/dhcp
# Loaded module rlm_digest
# Instantiating module "digest" from file /etc/raddb/mods-enabled/digest
# Loaded module rlm_dynamic_clients
# Instantiating module "dynamic_clients" from file
/etc/raddb/mods-enabled/dynamic_clients
# Loaded module rlm_eap
# Instantiating module "eap" from file /etc/raddb/mods-enabled/eap
eap {
default_eap_type = "md5"
timer_expire = 60
ignore_unknown_eap_types = no
mod_accounting_username_bug = no
max_sessions = 1024
}
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_leap
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
rsa_key_exchange = no
dh_key_exchange = yes
rsa_key_length = 512
dh_key_length = 512
verify_depth = 0
ca_path = "/etc/raddb/certs"
pem_file_type = yes
private_key_file = "/etc/raddb/certs/server.pem"
certificate_file = "/etc/raddb/certs/server.pem"
ca_file = "/etc/raddb/certs/ca.pem"
private_key_password = <<< secret >>>
dh_file = "/etc/raddb/certs/dh"
fragment_size = 1024
include_length = yes
check_crl = no
cipher_list = "DEFAULT"
ecdh_curve = "prime256v1"
cache {
enable = yes
lifetime = 24
max_entries = 255
}
verify {
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = yes
}
}
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "md5"
copy_request_to_tunnel = no
use_tunneled_reply = no
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_method = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
# Loaded module rlm_exec
# Instantiating module "echo" from file /etc/raddb/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Instantiating module "exec" from file /etc/raddb/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_expiration
# Instantiating module "expiration" from file
/etc/raddb/mods-enabled/expiration
# Loaded module rlm_expr
# Instantiating module "expr" from file /etc/raddb/mods-enabled/expr
expr {
safe_characters =
"@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"
}
# Loaded module rlm_files
# Instantiating module "files" from file /etc/raddb/mods-enabled/files
files {
filename = "/etc/raddb/mods-config/files/authorize"
usersfile = "/etc/raddb/mods-config/files/authorize"
acctusersfile = "/etc/raddb/mods-config/files/accounting"
preproxy_usersfile = "/etc/raddb/mods-config/files/pre-proxy"
compat = "cistron"
}
reading pairlist file /etc/raddb/mods-config/files/authorize
[/etc/raddb/mods-config/files/authorize]:181 Cistron compatibility checks
for entry DEFAULT ...
[/etc/raddb/mods-config/files/authorize]:188 Cistron compatibility checks
for entry DEFAULT ...
[/etc/raddb/mods-config/files/authorize]:195 Cistron compatibility checks
for entry DEFAULT ...
reading pairlist file /etc/raddb/mods-config/files/authorize
[/etc/raddb/mods-config/files/authorize]:181 Cistron compatibility checks
for entry DEFAULT ...
[/etc/raddb/mods-config/files/authorize]:188 Cistron compatibility checks
for entry DEFAULT ...
[/etc/raddb/mods-config/files/authorize]:195 Cistron compatibility checks
for entry DEFAULT ...
reading pairlist file /etc/raddb/mods-config/files/accounting
reading pairlist file /etc/raddb/mods-config/files/pre-proxy
# Loaded module rlm_linelog
# Instantiating module "linelog" from file /etc/raddb/mods-enabled/linelog
linelog {
filename = "/var/log/radius/linelog"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{Packet-Type}:-default}"
}
# Instantiating module "log_accounting" from file
/etc/raddb/mods-enabled/linelog
linelog log_accounting {
filename = "/var/log/radius/linelog-accounting"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_logintime
# Instantiating module "logintime" from file
/etc/raddb/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_mschap
# Instantiating module "mschap" from file /etc/raddb/mods-enabled/mschap
mschap {
use_mppe = yes
require_encryption = no
require_strong = no
with_ntdomain_hack = yes
passchange {
}
allow_retry = yes
}
# Instantiating module "ntlm_auth" from file
/etc/raddb/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/path/to/ntlm_auth --request-nt-key --domain=MYDOMAIN
--username=%{mschap:User-Name} --password=%{User-Password}"
shell_escape = yes
}
# Loaded module rlm_pap
# Instantiating module "pap" from file /etc/raddb/mods-enabled/pap
pap {
normalise = yes
}
# Loaded module rlm_passwd
# Instantiating module "etc_passwd" from file
/etc/raddb/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Loaded module rlm_preprocess
# Instantiating module "preprocess" from file
/etc/raddb/mods-enabled/preprocess
preprocess {
huntgroups = "/etc/raddb/mods-config/preprocess/huntgroups"
hints = "/etc/raddb/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
reading pairlist file /etc/raddb/mods-config/preprocess/huntgroups
reading pairlist file /etc/raddb/mods-config/preprocess/hints
# Loaded module rlm_radutmp
# Instantiating module "radutmp" from file /etc/raddb/mods-enabled/radutmp
radutmp {
filename = "/var/log/radius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_realm
# Instantiating module "IPASS" from file /etc/raddb/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Instantiating module "suffix" from file /etc/raddb/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Instantiating module "realmpercent" from file
/etc/raddb/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Instantiating module "ntdomain" from file /etc/raddb/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\"
ignore_default = no
ignore_null = no
}
# Loaded module rlm_replicate
# Instantiating module "replicate" from file
/etc/raddb/mods-enabled/replicate
# Loaded module rlm_soh
# Instantiating module "soh" from file /etc/raddb/mods-enabled/soh
soh {
dhcp = yes
}
# Instantiating module "sradutmp" from file
/etc/raddb/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/radius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_unix
# Instantiating module "unix" from file /etc/raddb/mods-enabled/unix
unix {
radwtmp = "/var/log/radius/radwtmp"
}
# Loaded module rlm_unpack
# Instantiating module "unpack" from file /etc/raddb/mods-enabled/unpack
# Loaded module rlm_utf8
# Instantiating module "utf8" from file /etc/raddb/mods-enabled/utf8
# Loaded module rlm_sql
# Instantiating module "sql" from file /etc/raddb/mods-enabled/sql
sql {
driver = "rlm_sql_mysql"
server = "localhost"
port = "3306"
login = "root"
password = <<< secret >>>
radius_db = "radius"
read_groups = yes
read_profiles = yes
read_clients = yes
delete_stale_sessions = yes
sql_user_name = "%{User-Name}"
default_user_profile = ""
client_query = "SELECT id, nasname, shortname, type, secret, server
FROM nas"
authorize_check_query = "SELECT id, username, attribute, value, op
FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id"
authorize_reply_query = "SELECT id, username, attribute, value, op
FROM radreply WHERE username = '%{SQL-User-Name}' ORDER BY id"
authorize_group_check_query = "SELECT id, groupname, attribute,
Value, op FROM radgroupcheck WHERE groupname = '%{Sql-Group}' ORDER BY id"
authorize_group_reply_query = "SELECT id, groupname, attribute,
value, op FROM radgroupreply WHERE groupname = '%{Sql-Group}' ORDER BY id"
group_membership_query = "# SELECT groupname # FROM
radusergroup # WHERE username = BINARY '%{SQL-User-Name}' # ORDER BY
priority"
simul_count_query = ""
simul_verify_query = "SELECT radacctid, acctsessionid, username,
nasipaddress, nasportid, framedipaddress, callingstationid, framedprotocol
FROM radacct WHERE username = '%{SQL-User-Name}' AND acctstoptime IS NULL"
safe_characters =
"@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /"
}
accounting {
reference = "%{tolower:type.%{Acct-Status-Type}.query}"
}
post-auth {
reference = ".query"
}
mysql {
tls {
}
}
rlm_sql (sql): Driver rlm_sql_mysql (module rlm_sql_mysql) loaded and linked
rlm_sql (sql): Attempting to connect to database "radius"
rlm_sql (sql): Initialising connection pool
pool {
start = 5
min = 4
max = 32
spare = 3
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 1
spread = no
}
rlm_sql (sql): Opening additional connection (0)
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql (sql): Opening additional connection (1)
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql (sql): Opening additional connection (2)
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql (sql): Opening additional connection (3)
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql (sql): Opening additional connection (4)
rlm_sql_mysql: Starting connect to MySQL server
rlm_sql (sql): Processing generate_sql_clients
rlm_sql (sql) in generate_sql_clients: query is SELECT id, nasname,
shortname, type, secret, server FROM nas
rlm_sql (sql): Reserved connection (4)
rlm_sql (sql): Executing query: 'SELECT id, nasname, shortname, type,
secret, server FROM nas'
rlm_sql (sql): Adding client zd (zd) to 192.168.1.173 clients list
ip_hton: Name or service not known
rlm_sql (sql): Released connection (4)
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/raddb/radiusd.conf
} # server
server default { # from file /etc/raddb/sites-enabled/default
# Creating Auth-Type = digest
# Loading authenticate {...}
# Loading authorize {...}
Ignoring "ldap" (see raddb/mods-available/README.rst)
# Loading preacct {...}
# Loading accounting {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server default
server inner-tunnel { # from file /etc/raddb/sites-enabled/inner-tunnel
# Loading authenticate {...}
# Loading authorize {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
} # server inner-tunnel
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipv4addr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
Listening on auth address * port 1812 as server default
Listening on acct address * port 1813 as server default
Listening on auth address :: port 1812 as server default
Listening on acct address :: port 1813 as server default
Listening on auth address 127.0.0.1 port 18120 as server inner-tunnel
Opening new proxy socket 'proxy address * port 0'
Listening on proxy address * port 50778
Ready to process requests
2
1
Hi,
I'm having trouble getting some basic TLS checks working for a Wifi EAP-TLS
connection.
Centos7, freeradius 3.0.4
Basically I'm messing around with the built-in check-eap-tls virtual
server, as a pre-requisite to some more complex matching I want to do, but
it's not working as it would seem it should.
My client connects using a valid cert, I see TLS "stuff" in the logs like
this:
(5) Auth-Type eap {
(5) eap : Expiring EAP session with state 0x9e6f4ada9ae847d4
(5) eap : Finished EAP session with state 0x9e6f4ada9ae847d4
(5) eap : Previous EAP request found for state 0x9e6f4ada9ae847d4,
released from the list
(5) eap : Peer sent method TLS (13)
(5) eap : EAP TLS (13)
(5) eap : Calling eap_tls to process EAP data
(5) eap_tls : Authenticate
(5) eap_tls : processing EAP-TLS
(5) eap_tls : eaptls_verify returned 7
(5) eap_tls : Done initial handshake
(5) eap_tls : <<< TLS 1.0 Handshake [length 04c4], Certificate
(5) eap_tls : chain-depth=1,
(5) eap_tls : error=0
(5) eap_tls : --> User-Name = lpascoe
(5) eap_tls : --> BUF-Name = NZHothouse CA
(5) eap_tls : --> subject =
/C=NZ/ST=AKL/L=Auckland/O=NZHothouse/CN=NZHothouse CA/emailAddress=
admin(a)nzhothouse.co.nz
(5) eap_tls : --> issuer =
/C=NZ/ST=AKL/L=Auckland/O=NZHothouse/CN=NZHothouse CA/emailAddress=
admin(a)nzhothouse.co.nz
(5) eap_tls : --> verify return:1
(5) eap_tls : chain-depth=0,
(5) eap_tls : error=0
(5) eap_tls : --> User-Name = lpascoe
(5) eap_tls : --> BUF-Name = lpascoe
(5) eap_tls : --> subject =
/C=NZ/ST=AKL/L=Auckland/O=NZHothouse/CN=lpascoe/emailAddress=
admin(a)nzhothouse.co.nz
(5) eap_tls : --> issuer =
/C=NZ/ST=AKL/L=Auckland/O=NZHothouse/CN=NZHothouse CA/emailAddress=
admin(a)nzhothouse.co.nz
(5) eap_tls : --> verify return:1
(5) eap_tls : TLS_accept: SSLv3 read client certificate A
(5) eap_tls : <<< TLS 1.0 Handshake [length 0046], ClientKeyExchange
(5) eap_tls : TLS_accept: SSLv3 read client key exchange A
(5) eap_tls : <<< TLS 1.0 Handshake [length 0106], CertificateVerify
(5) eap_tls : TLS_accept: SSLv3 read certificate verify A
(5) eap_tls : <<< TLS 1.0 ChangeCipherSpec [length 0001]
(5) eap_tls : <<< TLS 1.0 Handshake [length 0010], Finished
(5) eap_tls : TLS_accept: SSLv3 read finished A
(5) eap_tls : >>> TLS 1.0 ChangeCipherSpec [length 0001]
(5) eap_tls : TLS_accept: SSLv3 write change cipher spec A
(5) eap_tls : >>> TLS 1.0 Handshake [length 0010], Finished
(5) eap_tls : TLS_accept: SSLv3 write finished A
(5) eap_tls : TLS_accept: SSLv3 flush data
(5) eap_tls : (other): SSL negotiation finished successfully
SSL Connection Established
(5) eap_tls : eaptls_process returned 13
So I'm pretty certail that part is working correctly.
However when we get to the check-eap-tls part, the variables it expects to
match against aren't populated:
(6) # Executing section authorize from file
/etc/raddb/sites-enabled/check-eap-tls
(6) authorize {
(6) update config {
(6) Auth-Type := Accept
(6) } # update config = noop
(6) if ("%{TLS-Client-Cert-Common-Name}" == "client.example.com")
(6) EXPAND %{TLS-Client-Cert-Common-Name}
(6) -->
(6) if ("%{TLS-Client-Cert-Common-Name}" == "client.example.com") ->
FALSE
(6) else else {
(6) update config {
(6) Auth-Type := Reject
(6) } # update config = noop
(6) update reply {
(6) Reply-Message := 'Your certificate is not valid.'
(6) } # update reply = noop
(6) } # else else = noop
As you can see the expansion for %{TLS-Client-Cert-Common-Name} is an empty
string.
This is the variable I want to match against in future.
Any suggestions around what I need to enable to get these TLS variables
populated would be greatly appreciated.
Thanks.
Luke Pascoe
*E* luke(a)osnz.co.nz
* P* +64 (9) 296 2961
* M* +64 (27) 426 6649
* W* www.osnz.co.nz
24 Wellington St
Papakura
Auckland, 2110
New Zealand
3
3
Hello,
Could someone point me out, where can I set and what to be able to see the
full Calling-Station-Id instead of truncated one?
#radwho tt23kswp17 -R
User-Name = "tt23kswp17"
Acct-Session-Id = "8140098a"
NAS-IP-Address = My-NAS-IP
NAS-Port = 15731092
Service-Type = Framed-User
Framed-Protocol = PPP
Framed-IP-Address = USER-IP-ADDR
Acct-Session-Time = 216
*Calling-Station-Id = "00:A0:C5:3F:13:"*
It does obviously miss the last pair of caller's MAC
While FreeRadius gets the full mac from the NAS:
(2) Received Accounting-Request Id 111 from NAS-IP:42841 to
FreeRaius-IP:1813 length 153
(2) Service-Type = Framed-User
(2) Framed-Protocol = PPP
(2) NAS-Port = 15731092
(2) NAS-Port-Type = Ethernet
(2) User-Name = "tt23kswp17"
(2) *Calling-Station-Id = "00:A0:C5:3F:13:2D"*
(2) Called-Station-Id = "nas-id"
(2) NAS-Port-Id = "Eth7-PPPoE"
(2) Acct-Session-Id = "8140098a"
(2) Framed-IP-Address = USER-IP-ADDR
(2) Acct-Authentic = RADIUS
(2) Event-Timestamp = "May 8 2017 14:50:09 EEST"
(2) Acct-Status-Type = Start
(2) NAS-Identifier = "nas-id
(2) Acct-Delay-Time = 0
(2) NAS-IP-Address = NAS-IP-ADDR
--
Best regards,
Roman.
3
4
09 May '17
Hello,
I have problem in adding new dictionary in FreeRADIUS Version 2.2.8,
and use the attribute to users check item, but always response Access-Reject.
Below is my create step:
First, Create 'dictionary.fitivision' in '/usr/share/freeradius2/', as following:
# -*- text -*-
#
# As posted to the list.
#
# Version: $Id$
#
VENDOR Fitivision 49809
BEGIN-VENDOR Fitivision
ATTRIBUTE Fitivision-Essid-Name 1 string
END-VENDOR Fitivision
And add include in '/usr/share/freeradius2/dictionary':
$INCLUDE dictionary.fitivision
When I test it on reply item, it's workable.
But when I used for check item, it always response Access-Reject.
The users config as following:
"test3" Cleartext-Password := "testpwd", Fitivision-Essid-Name == "test"
And the radiux log as following:
radiusd: FreeRADIUS Version 2.2.8, for host arm-openwrt-linux-gnu, built on Apr 28 2017 at 10:22:04
Copyright (C) 1999-2015 The FreeRADIUS server project and contributors.
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE.
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License.
For more information about these matters, see the file named COPYRIGHT.
Starting - reading configuration files ...
including configuration file /etc/freeradius2/radiusd.conf
including configuration file /etc/freeradius2/clients.conf
including files in directory /etc/freeradius2/modules/
including configuration file /etc/freeradius2/modules/attr_filter
including configuration file /etc/freeradius2/modules/attr_rewrite
including configuration file /etc/freeradius2/modules/chap
including configuration file /etc/freeradius2/modules/echo
including configuration file /etc/freeradius2/modules/exec
including configuration file /etc/freeradius2/modules/files
including configuration file /etc/freeradius2/modules/mschap
including configuration file /etc/freeradius2/modules/pap
including configuration file /etc/freeradius2/eap.conf
including files in directory /etc/freeradius2/sites/
including configuration file /etc/freeradius2/sites/default
main {
allow_core_dumps = no
}
including dictionary file /etc/freeradius2/dictionary
main {
name = "radiusd"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log"
run_dir = "/var/run"
libdir = "/usr/lib/freeradius2"
radacctdir = "/var/db/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 1024
pidfile = "/var/run/radiusd.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = no
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
}
security {
max_attributes = 200
reject_delay = 1
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
radiusd: #### Loading Clients ####
client 0.0.0.0/0 {
require_message_authenticator = no
secret = "testing123"
nastype = "other"
}
radiusd: #### Instantiating modules ####
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/freeradius2/radiusd.conf
modules {
Module: Checking authenticate {...} for more modules to load
Module: Linked to module rlm_pap
Module: Instantiating module "pap" from file /etc/freeradius2/modules/pap
pap {
encryption_scheme = "auto"
auto_header = yes
}
Module: Linked to module rlm_chap
Module: Instantiating module "chap" from file /etc/freeradius2/modules/chap
Module: Linked to module rlm_mschap
Module: Instantiating module "mschap" from file /etc/freeradius2/modules/mschap
mschap {
use_mppe = no
require_encryption = no
require_strong = no
with_ntdomain_hack = no
allow_retry = yes
}
Module: Linked to module rlm_eap
Module: Instantiating module "eap" from file /etc/freeradius2/eap.conf
eap {
default_eap_type = "peap"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 4096
}
Module: Linked to sub-module rlm_eap_tls
Module: Instantiating eap-tls
tls {
rsa_key_exchange = no
dh_key_exchange = yes
rsa_key_length = 512
dh_key_length = 512
verify_depth = 0
CA_path = "/etc/freeradius2/certs"
pem_file_type = yes
private_key_file = "/etc/freeradius2/certs/server.pem"
certificate_file = "/etc/freeradius2/certs/server.pem"
CA_file = "/etc/freeradius2/certs/ca.pem"
private_key_password = "whatever"
dh_file = "/etc/freeradius2/certs/dh"
random_file = "/etc/freeradius2/certs/random"
fragment_size = 1024
include_length = yes
check_crl = no
check_all_crl = no
cipher_list = "DEFAULT"
ecdh_curve = "prime256v1"
verify {
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
Module: Linked to sub-module rlm_eap_ttls
Module: Instantiating eap-ttls
ttls {
default_eap_type = "mschapv2"
copy_request_to_tunnel = yes
use_tunneled_reply = yes
include_length = yes
}
Module: Linked to sub-module rlm_eap_peap
Module: Instantiating eap-peap
peap {
default_eap_type = "mschapv2"
copy_request_to_tunnel = yes
use_tunneled_reply = yes
proxy_tunneled_request_as_eap = no
soh = no
}
Module: Linked to sub-module rlm_eap_mschapv2
Module: Instantiating eap-mschapv2
mschapv2 {
with_ntdomain_hack = no
send_error = no
}
Module: Checking authorize {...} for more modules to load
Module: Linked to module rlm_files
Module: Instantiating module "files" from file /etc/freeradius2/modules/files
files {
usersfile = "/etc/freeradius2/users"
acctusersfile = "/etc/freeradius2/acct_users"
preproxy_usersfile = "/etc/freeradius2/preproxy_users"
compat = "cistron"
}
reading pairlist file /etc/freeradius2/users
[/etc/freeradius2/users]:21 Cistron compatibility checks for entry test3 ...
reading pairlist file /etc/freeradius2/acct_users
reading pairlist file /etc/freeradius2/preproxy_users
Module: Checking accounting {...} for more modules to load
Module: Linked to module rlm_exec
Module: Instantiating module "exec" from file /etc/freeradius2/modules/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
} # modules
} # server
radiusd: #### Opening IP addresses and Ports ####
Listening on authentication address 192.168.168.205 port 1812
Listening on accounting address 192.168.168.205 port 1813
Ready to process requests.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=18, length=197
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
EAP-Message = 0x021b000a017465737433
Message-Authenticator = 0x07abb25c6fcac61aeb3d0f1e49cc98d6
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 27 length 10
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] = updated
++[files] = noop
[pap] WARNING! No "known good" password found for the user. Authentication may fail because of this.
++[pap] = noop
+} # group authorize = updated
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] EAP Identity
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] = handled
+} # group authenticate = handled
Sending Access-Challenge of id 18 to 192.168.168.205 port 42115
EAP-Message = 0x011c00061920
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xc30eff1bc312e6f65e8768c16e09584c
Finished request 0.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=19, length=336
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
011000500040100001f000a00080006001700180019000b0002010000050005010000000000120000
State = 0xc30eff1bc312e6f65e8768c16e09584c
Message-Authenticator = 0x97c6fbb9e1abd4ef3a74f02b493bd9d9
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 28 length 131
[eap] Continuing tunnel setup.
++[eap] = ok
+} # group authorize = ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
TLS Length 121
[peap] Length Included
[peap] eaptls_verify returned 11
[peap] (other): before/accept initialization
[peap] TLS_accept: before/accept initialization
[peap] <<< Unknown TLS version [length 0005]
[peap] <<< TLS 1.0 Handshake [length 0074], ClientHello
[peap] TLS_accept: unknown state
[peap] >>> Unknown TLS version [length 0005]
[peap] >>> TLS 1.0 Handshake [length 0039], ServerHello
[peap] TLS_accept: unknown state
[peap] >>> Unknown TLS version [length 0005]
[peap] >>> TLS 1.0 Handshake [length 085e], Certificate
[peap] TLS_accept: unknown state
[peap] >>> Unknown TLS version [length 0005]
[peap] >>> TLS 1.0 Handshake [length 014b], ServerKeyExchange
[peap] TLS_accept: unknown state
[peap] >>> Unknown TLS version [length 0005]
[peap] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone
[peap] TLS_accept: unknown state
[peap] TLS_accept: unknown state
[peap] TLS_accept: unknown state
[peap] TLS_accept: Need to read more data: unknown state
[peap] TLS_accept: Need to read more data: unknown state
In SSL Handshake Phase
[603087.097870] [wifi0]
[peap] eaptls_process returned 13
[peap] EAPTLS_HANDLED
++[eFWLOG: [81054832] ap] = handled
+} # group authenticate = handled
Sending AccessRATE: ChainMask 1, peer_mac a8:2e, phymode 1, ni_flags 0x00040016, vht_mcs_set 0x0000, ht_mcs_set 0xffffffff, legacy_rate_set 0x0fff
-Challenge of id 19 to 192.168.168.205 port 42115
071309536f6d65776865726531153013060355040a130c4578616d706c65200x73496e632e3120301e06092a864886f70d010901161161646d696e406578616d70, 6c652e636f6d312630240603550403131d4578616d706c6520436572746966
0xa EAP-Message = 0x696361746520417574686f72697479301e170d313630363, 0x90 )
, 0x90 )
96e406578616d706c652e636f6d30820122300d06092a864, 0x3, 0x479, 0x0, 0x9 )
886f70d01010105000382010f003082010a0282010100c946423265b4772617374660729c3c023d379b4681413b66f0de07f15b16eb15b5ee002373b664f5c61e11551f35c7
3f493e1437188fd72840aeeb6ceaf96f0203010001a317301530130603551d25040c300a06082b06010505070301300d06092a864886f70d01010505
fba07a9ee61c4c06d633ec4ec0c0885d07b45952f31d2edea03bb0bb93aa6e42fe7580a3d2f58b052a1fb56bde36002acee20f2e3b92bb99b72b0c67
EAP-Message = 0x65011ccb33e94e5fd90004ab
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xc30eff1bc213e6f65e8768c16e09584c
Finished request 1.
Going to the next request
Waking up in 4.4 seconds.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=20, length=211
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
EAP-Message = 0x021d00061900
State = 0xc30eff1bc213e6f65e8768c16e09584c
Message-Authenticator = 0xf40ff990a4a13753cc3f28b33ca5a182
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 29 length 6
[eap] Continuing tunnel setup.
++[eap] = ok
+} # group authorize = ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1
[peap] eaptls_process returned 13
[peap] EAPTLS_HANDLED
++[eap] = handled
+} # group authenticate = handled
Sending Access-Challenge of id 20 to 192.168.168.205 port 42115
7479301e170d3136303632313037343833345a170d3137303632313037343833345a308193310b3009060355040613024652310f300d060355040813
25d9d75e9faa36bacf2d256d8087504d1055532185e593fa3e07f9e6ddad8e457bf8979b2546bdc2768018764158ab0f21ae77998cecd6d1809b278b
0f8d572ebd0d9e887d3081c80603551d230481c03081bd80140e28c41f34600d01ab674c0f8d572ebd0d9e887da18199a48196308193310b30090603
fffb4632ebeca0865b13c0303e9485f59828369fe812f32b4d77d3d9706c7e97666a331797210b32c9cab80c500d4bf29224708affda268acc6bc612
EAP-Message = 0x68d2a1ab15f206e8
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xc30eff1bc110e6f65e8768c16e09584c
Finished request 2.
Going to the next request
Waking up in 4.4 seconds.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=21, length=211
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
EAP-Message = 0x021e00061900
State = 0xc30eff1bc110e6f65e8768c16e09584c
Message-Authenticator = 0xee0d464855fa5a53cf755d16de6fdb07
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 30 length 6
[eap] Continuing tunnel setup.
++[eap] = ok
+} # group authorize = ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1
[peap] eaptls_process returned 13
[peap] EAPTLS_HANDLED
++[eap] = handled
+} # group authenticate = handled
Sending Access-Challenge of id 21 to 192.168.168.205 port 42115
0001470300174104975e7a95fb4a34da8edb2ed340d161af75e08b4a69b597f4cbda60518ee060eeb29b016c3f54fd1ff7fa5f5723e02b9b2409daaa
155596da9065984a02f00d19716a270374c21be8cec30236a14cf2e6eff550a27c26bce5e22b7314a6141ecf8695d2a5a74d9ee2dfe30413058ccb62
EAP-Message = 0xadbf51cc6d2a30b94b8ba5cc45dfc686b316030100040e000000
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xc30eff1bc011e6f65e8768c16e09584c
Finished request 3.
Going to the next request
Waking up in 4.1 seconds.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=22, length=349
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
116030100304477833ffd6e82754c90f5ccfc4fd75f7c67c30f13f0e3b07d3dbd903b794dc8bf52b3eb26040ed2925a094f71bebf30
State = 0xc30eff1bc011e6f65e8768c16e09584c
Message-Authenticator = 0x981d19112699f36bcaa048ac6d5cb917
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 31 length 144
[eap] Continuing tunnel setup.
++[eap] = ok
+} # group authorize = ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
TLS Length 134
[peap] Length Included
[peap] eaptls_verify returned 11
[peap] <<< Unknown TLS version [length 0005]
[peap] <<< TLS 1.0 Handshake [length 0046], ClientKeyExchange
[peap] TLS_accept: unknown state
[peap] TLS_accept: unknown state
[peap] <<< Unknown TLS version [length 0005]
[peap] <<< TLS 1.0 ChangeCipherSpec [length 0001]
[peap] <<< Unknown TLS version [length 0005]
[peap] <<< TLS 1.0 Handshake [length 0010], Finished
[peap] TLS_accept: unknown state
[peap] >>> Unknown TLS version [length 0005]
[peap] >>> TLS 1.0 ChangeCipherSpec [length 0001]
[peap] TLS_accept: unknown state
[peap] >>> Unknown TLS version [length 0005]
[peap] >>> TLS 1.0 Handshake [length 0010], Finished
[peap] TLS_accept: unknown state
[peap] TLS_accept: unknown state
[peap] (other): SSL negotiation finished successfully
SSL Connection Established
[peap] eaptls_process returned 13
[peap] EAPTLS_HANDLED
++[eap] = handled
+} # group authenticate = handled
Sending Access-Challenge of id 22 to 192.168.168.205 port 42115
EAP-Message = 0x0120004119001403010001011603010030743a197efba6673363d52e38c84ee6af1156dc98475b254286422eec8c0d0c5e4a55682ec8483c791906496be38ca2b0
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xc30eff1bc72ee6f65e8768c16e09584c
Finished request 4.
Going to the next request
Waking up in 3.9 seconds.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=23, length=211
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
EAP-Message = 0x022000061900
State = 0xc30eff1bc72ee6f65e8768c16e09584c
Message-Authenticator = 0x3ad860d004ef3fcabba5f7614d629707
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 32 length 6
[eap] Continuing tunnel setup.
++[eap] = ok
+} # group authorize = ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake is finished
[peap] eaptls_verify returned 3
[peap] eaptls_process returned 3
[peap] EAPTLS_SUCCESS
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state TUNNEL ESTABLISHED
[peap] >>> Unknown TLS version [length 0005]
++[eap] = handled
+} # group authenticate = handled
Sending Access-Challenge of id 23 to 192.168.168.205 port 42115
EAP-Message = 0x0121002b1900170301002038f0a9de8c6c35bb8c25d91742508de0756c5f96898a5f807bbf622d860fd702
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xc30eff1bc62fe6f65e8768c16e09584c
Finished request 5.
Going to the next request
Waking up in 3.5 seconds.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=24, length=248
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
EAP-Message = 0x0221002b19001703010020d9a51a72f4d3f026ee29713f988b5ea384f63c39bca9d72cbd454c22dc9f7f6b
State = 0xc30eff1bc62fe6f65e8768c16e09584c
Message-Authenticator = 0x9598e5c8853b46372c49e0eab0d847b1
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 33 length 43
[eap] Continuing tunnel setup.
++[eap] = ok
+} # group authorize = ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] <<< Unknown TLS version [length 0005]
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state WAITING FOR INNER IDENTITY
[peap] Identity - test3
[peap] Got inner identity 'test3'
[peap] Setting default EAP type for tunneled EAP session.
[peap] Got tunneled request
EAP-Message = 0x0221000a017465737433
server {
[peap] Setting User-Name to test3
Sending tunneled request
EAP-Message = 0x0221000a017465737433
FreeRADIUS-Proxied-To = 127.0.0.1
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
server {
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 33 length 10
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] = updated
++[files] = noop
[pap] WARNING! No "known good" password found for the user. Authentication may fail because of this.
++[pap] = noop
+} # group authorize = updated
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] EAP Identity
[eap] processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] = handled
+} # group authenticate = handled
} # server
[peap] Got tunneled reply code 11
EAP-Message = 0x0122001f1a0122001a1038b1d4f1ac9d9e2d502428bcd4be1b877465737433
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xaacefa4baaece0d52cbb51841f6886cc
[peap] Got tunneled reply RADIUS code Access-Challenge
EAP-Message = 0x0122001f1a0122001a1038b1d4f1ac9d9e2d502428bcd4be1b877465737433
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xaacefa4baaece0d52cbb51841f6886cc
[peap] Got tunneled Access-Challenge
[peap] >>> Unknown TLS version [length 0005]
++[eap] = handled
+} # group authenticate = handled
Sending Access-Challenge of id 24 to 192.168.168.205 port 42115
EAP-Message = 0x0122003b19001703010030d70c7180d63f7345328c82eee2d29cc97bcbfd56bd375a88759bec5058ea295a12563bc4e70233b1f386d332e063d5c9
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xc30eff1bc52ce6f65e8768c16e09584c
Finished request 6.
Going to the next request
Waking up in 3.2 seconds.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=25, length=312
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
10519e089ae2095a3afea8dc67f17dc4b
State = 0xc30eff1bc52ce6f65e8768c16e09584c
Message-Authenticator = 0xea0f404b1fdc40e787d84bac706215d1
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 34 length 107
[eap] Continuing tunnel setup.
++[eap] = ok
+} # group authorize = ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] <<< Unknown TLS version [length 0005]
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state phase2
[peap] EAP type mschapv2
[peap] Got tunneled request
EAP-Message = 0x022200401a0222003b3131bc7ac09237790b1b2f2de3c9da70d10000000000000000ff91457ee5eb447396e409f6847c1759fead5ba59f6f7b0a007465737433
server {
[peap] Setting User-Name to test3
Sending tunneled request
EAP-Message = 0x022200401a0222003b3131bc7ac09237790b1b2f2de3c9da70d10000000000000000ff91457ee5eb447396e409f6847c1759fead5ba59f6f7b0a007465737433
FreeRADIUS-Proxied-To = 127.0.0.1
User-Name = "test3"
State = 0xaacefa4baaece0d52cbb51841f6886cc
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
server {
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 34 length 64
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] = updated
++[files] = noop
[pap] WARNING! No "known good" password found for the user. Authentication may fail because of this.
++[pap] = noop
+} # group authorize = updated
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/mschapv2
[eap] processing type mschapv2
[mschapv2] # Executing group from file /etc/freeradius2/sites/default
[mschapv2] +group MS-CHAP {
[mschap] No Cleartext-Password configured. Cannot create LM-Password.
[mschap] No Cleartext-Password configured. Cannot create NT-Password.
[mschap] Creating challenge hash with username: test3
[mschap] Client is using MS-CHAPv2 for test3, we need NT-Password
[mschap] FAILED: No NT/LM-Password. Cannot perform authentication.
[mschap] FAILED: MS-CHAP2-Response is incorrect
++[mschap] = reject
+} # group MS-CHAP = reject
[eap] Freeing handler
++[eap] = reject
+} # group authenticate = reject
Failed to authenticate the user.
Using Post-Auth-Type Reject
WARNING: Unknown value specified for Post-Auth-Type. Cannot perform requested action.
} # server
[peap] Got tunneled reply code 3
MS-CHAP-Error = "\"E=691 R=1"
EAP-Message = 0x04220004
Message-Authenticator = 0x00000000000000000000000000000000
[peap] Got tunneled reply RADIUS code Access-Reject
MS-CHAP-Error = "\"E=691 R=1"
EAP-Message = 0x04220004
Message-Authenticator = 0x00000000000000000000000000000000
[peap] Tunneled authentication was rejected.
[peap] FAILURE
[peap] >>> Unknown TLS version [length 0005]
++[eap] = handled
+} # group authenticate = handled
Sending Access-Challenge of id 25 to 192.168.168.205 port 42115
EAP-Message = 0x0123002b190017030100200a019db07d5b363141790d2b79f35448849fb36c234d074dbdcaa68b4ec312f0
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xc30eff1bc42de6f65e8768c16e09584c
Finished request 7.
Going to the next request
Waking up in 2.8 seconds.
rad_recv: Access-Request packet from host 192.168.168.205 port 42115, id=26, length=248
User-Name = "test3"
Called-Station-Id = "00-03-7F-19-4E-45:fws2310-Mm2"
NAS-Port-Type = Wireless-802.11
NAS-Port = 0
Calling-Station-Id = "A4-67-06-6D-A8-2E"
Connect-Info = "CONNECT 0Mbps 802.11b"
Acct-Session-Id = "BF8FD357-00000002"
Attr-186 = 0x0050f202
Attr-187 = 0x0050f202
Attr-188 = 0x000fac01
Fitivision-Essid-Name = "test"
Framed-MTU = 1400
EAP-Message = 0x0223002b19001703010020b8cd3f0acc578a073928fe39c5cd9910ae9fa867c95ddf1aade29daba16fd349
State = 0xc30eff1bc42de6f65e8768c16e09584c
Message-Authenticator = 0xfa5287fca7371b423b4170722af255c2
# Executing section authorize from file /etc/freeradius2/sites/default
+group authorize {
++[mschap] = noop
[eap] EAP packet type response id 35 length 43
[eap] Continuing tunnel setup.
++[eap] = ok
+} # group authorize = ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius2/sites/default
+group authenticate {
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] <<< Unknown TLS version [length 0005]
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state send tlv failure
[peap] Received EAP-TLV response.
[peap] The users session was previously rejected: returning reject (again.)
[peap] *** This means you need to read the PREVIOUS messages in the debug output
[peap] *** to find out the reason why the user was rejected.
[peap] *** Look for "reject" or "fail". Those earlier messages will tell you.
[peap] *** what went wrong, and how to fix the problem.
[eap] Handler failed in EAP/peap
[eap] Failed in EAP select
++[eap] = invalid
+} # group authenticate = invalid
Failed to authenticate the user.
Using Post-Auth-Type Reject
WARNING: Unknown value specified for Post-Auth-Type. Cannot perform requested action.
Delaying reject of request 8 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 8
Sending Access-Reject of id 26 to 192.168.168.205 port 42115
EAP-Message = 0x04230004
Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 1.7 seconds.
Cleaning up request 0 ID 18 with timestamp +3
Waking up in 0.1 seconds.
Cleaning up request 1 ID 19 with timestamp +3
Waking up in 0.4 seconds.
Cleaning up request 2 ID 20 with timestamp +4
Waking up in 0.3 seconds.
Cleaning up request 3 ID 21 with timestamp +4
Waking up in 0.1 seconds.
Cleaning up request 4 ID 22 with timestamp +4
Waking up in 0.3 seconds.
Cleaning up request 5 ID 23 with timestamp +4
Waking up in 0.3 seconds.
Cleaning up request 6 ID 24 with timestamp +5
Waking up in 0.4 seconds.
Cleaning up request 7 ID 25 with timestamp +5
Waking up in 1.0 seconds.
Cleaning up request 8 ID 26 with timestamp +5
Ready to process requests.
Do I missing something?
Thanks
Matt Wu
2
1
Hi all,
I'm trying to use the rlm_python module in FreeRadius 3.0.X and i've
followed the documentation provided in the Wiki to enable and configure the
module. The basic module seems to be working, i.e after activating the
module in mods-enabled and setting the python_path in mods-enabled/python
and enabling instantiate and authorize, i can see the calls being made to
the instantiate and authorize functions in example.py.
However, then i was trying to enable/import a new module (for example was
trying to use redis to just store some values during authorize). I added
the path of the new module in python_path (
${modconfdir/${.:name}:/usr/local/lib/python2.7/dist-packages} ) I am
unable to even launch freeradius. No matter which module I import, i always
get an error that says
python_function_load - Module 'example' not found
<type 'exceptions.ImportError'> (No module named __future__)
python_function_load - Failed to import python function 'eample.instantiate'
/etc/freeradius/mods-enabled/python[9]: Instantiation failed for module
"python"
How can I setup the rlm_python so that i can import other modules in my
example.py ?
Thanks in advance
2
1
Hello
I am trying to replace a NPS server with freeradius implantation but I am running into a hurdle that basically equates to a go/no go senerio for the project. When NPS (Microsoft Network Policy Server) denies my clients (in this case ip phones) they prompt the user to enter credentials - required for initial setup. However when I take the same device and deny it with freeradius, basically no username and password for the device it does not prompt for no credentials so there is basically no way to setup the device. What I would like to do is replicate the behavior NPS. I am including the screenshot: left is nps - right is freereadius of the reject packet, I can't seem to tell what would cause this over the other so hopefully someone has some insight. I don't think that it maters for this question but the freeradius version is 3.0.4 on Centos 7. Everything is default, clean install except for the client definition for the switch.
I am also including the entire packet capture just in case it helps.
Thanks
Jeremy
3
19