Freeradius-Users
Threads by month
- ----- 2026 -----
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 2 participants
- 27050 discussions
Thanks for the response. It resolved my issue. I was however getting an
authentication not found error which I fixed by making a slight adjustment
because we don't check password for mobile:
-ldap-mobile
if (notfound) {
reject
}
else {
accept
}
On Thu, 23 Feb 2023 at 14:00, <freeradius-users-request(a)lists.freeradius.org>
wrote:
> Send Freeradius-Users mailing list submissions to
> freeradius-users(a)lists.freeradius.org
>
> To subscribe or unsubscribe via the World Wide Web, visit
> https://lists.freeradius.org/mailman/listinfo/freeradius-users
> or, via email, send a message with subject or body 'help' to
> freeradius-users-request(a)lists.freeradius.org
>
> You can reach the person managing the list at
> freeradius-users-owner(a)lists.freeradius.org
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Freeradius-Users digest..."
>
>
> Today's Topics:
>
> 1. Freeradius Upgrade from 3.0.1 to 3.2.2 (Steven Walters)
> 2. Re: Freeradius Upgrade from 3.0.1 to 3.2.2 (Alan DeKok)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Wed, 22 Feb 2023 20:47:42 +0200
> From: Steven Walters <steven.walters1(a)gmail.com>
> To: freeradius-users(a)lists.freeradius.org
> Subject: Freeradius Upgrade from 3.0.1 to 3.2.2
> Message-ID:
> <CALF=EMJUde0_Y=XEOENp5Ro3a3PJFnF5fYCx-=
> UOdSOb5aGKzA(a)mail.gmail.com>
> Content-Type: text/plain; charset="UTF-8"
>
> Hi
>
> I agree, we should have updated our freeradius a long time ago, but we will
> do better going forward.
>
> Just to explain what we are training to achieve.
>
> Our fixed line customers authenticate with username and password. Our fixed
> line customers can have a mobile VAS linked to fixed line. Customer can
> have single SIM or multiple SIM linked to fixed line username on LDAP.
>
> In the case of mobile service, we receive the MSISDN in the radius access
> request. We then lookup the username which has the MSISDN linked on LDAP.
> If subscriber name has this MSISDN linked, the radius will respond with the
> username in the access-accept. If no match is found it will respond with
> access-reject.
>
> When the radius receives the accounting start for this session it will have
> the username of the fixed line service returned in the access-accept and
> not the MSISDN which was original in the access request.
>
> So basically, in the case of the mobile VAS, the authentication finds the
> username on LDAP which has the MSISDN linked as a VAS and if no username
> has the MSISDN (for example customer cancelled the VAS but is still trying
> to use the SIM) it will send an access reject. No password checks are done
> for mobile service.
>
> This mobile VAS was implemented before I joined so there might be better
> alternative to provide the same result.
>
> Kind regards
> Steven
>
>
> On Wed, 22 Feb 2023 at 14:00, <
> freeradius-users-request(a)lists.freeradius.org>
> wrote:
>
> > Send Freeradius-Users mailing list submissions to
> > freeradius-users(a)lists.freeradius.org
> >
> > To subscribe or unsubscribe via the World Wide Web, visit
> > https://lists.freeradius.org/mailman/listinfo/freeradius-users
> > or, via email, send a message with subject or body 'help' to
> > freeradius-users-request(a)lists.freeradius.org
> >
> > You can reach the person managing the list at
> > freeradius-users-owner(a)lists.freeradius.org
> >
> > When replying, please edit your Subject line so it is more specific
> > than "Re: Contents of Freeradius-Users digest..."
> >
> >
> > Today's Topics:
> >
> > 1. Freeradius Upgrade from 3.0.1 to 3.2.2 (Steven Walters)
> > 2. Re: Freeradius Upgrade from 3.0.1 to 3.2.2 (Alan DeKok)
> > 3. Some new documentation for "how to make FreeRADIUS do what I
> > want" (Alan DeKok)
> >
> >
> > ----------------------------------------------------------------------
> >
> > Message: 1
> > Date: Tue, 21 Feb 2023 23:47:05 +0200
> > From: Steven Walters <steven.walters1(a)gmail.com>
> > To: freeradius-users(a)lists.freeradius.org
> > Subject: Freeradius Upgrade from 3.0.1 to 3.2.2
> > Message-ID:
> > <CALF=EMKe4Ky91x7A2GgAKaQkVv0D+qxjWqFkaTOgzq=
> > BvBFA2w(a)mail.gmail.com>
> > Content-Type: text/plain; charset="UTF-8"
> >
> > Hi
> >
> > I am in the process of upgrading our radius servers but have one issue
> > outstanding.
> >
> > Basically we receive in the radius request from mobile a MSISDN. We then
> go
> > do a lookup to find the username on LDAP matching the MSISDN.
> >
> > In the old version everything works fine but after upgrading the radius
> > responds with access rejection even though MSISDN finds a username on
> LDAP.
> >
> > Below are extracts from the mobile virtual server file and ldap file.
> >
> > mobile virtual server:
> >
> > # The ldap module reads passwords from the LDAP database.
> > -ldap-mobile
> > if (!ok) {
> > reject
> >
> > ldap:
> >
> > user {
> > # Where to start searching in the tree for users
> > base_dn = "${..base_dn}"
> >
> > # Filter for user objects, should be specific enough
> > # to identify a single user object.
> > #filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
> > #filter =
> > "(mobileradiusCallingStationId=%{Calling-Station-Id})"
> > filter =
> > "(&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))"
> >
> > Below is debug from version 3.0.1
> >
> > rlm_ldap (ldap-mobile): Reserved connection (11)
> > (9) ldap-mobile : expand:
> > "(&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))"
> ->
> > '(&(mobileradiusCallingStationId=27671946862)(status=10100))'
> > (9) ldap-mobile : expand: "cn=radius,ou=isp" -> 'cn=radius,ou=isp'
> > (9) ldap-mobile : Performing search in 'cn=radius,ou=isp' with filter
> > '(&(mobileradiusCallingStationId=27671946862)(status=10100))'
> > (9) ldap-mobile : Waiting for search result...
> > (9) ldap-mobile : User object found at DN "uid=onyebilanma(a)telkomsa.net
> > ,cn=radius,ou=isp"
> > (9) ldap-mobile : Processing user attributes
> > (9) ldap-mobile : reply:User-Name := '
> > onyebilanma(a)telkomsa.net
> > '
> > (9) ldap-mobile : control:User-Name := '
> > onyebilanma(a)telkomsa.net'
> > rlm_ldap (ldap-mobile): Released connection (11)
> > rlm_ldap (ldap-mobile): Opening additional connection (12)
> > rlm_ldap (ldap-mobile): Connecting to 10.146.46.133:389
> > TLSMC: MozNSS compatibility interception begins.
> > tlsmc_convert: INFO: cannot open the NSS DB, expecting PEM configuration
> is
> > present.
> > tlsmc_intercept_initialization: INFO: successfully intercepted TLS
> > initialization. Continuing with OpenSSL only.
> > TLSMC: MozNSS compatibility interception ends.
> > rlm_ldap (ldap-mobile): Waiting for bind result...
> > rlm_ldap (ldap-mobile): Bind successful
> > (9) [-ldap-mobile] = ok
> > (9) ? if (!ok)
> > (9) ? if (!ok) -> FALSE
> > (9) } # authorize = ok
> > (9) Found Auth-Type = Accept
> > (9) Auth-Type = Accept, accepting the user
> > (9) Login OK: [27671946862] (from client 105.187.248.220 port 0 cli
> > 27671946862)
> > (9) # Executing section post-auth from file
> /etc/raddb/sites-enabled/mobile
> > (9) post-auth {
> > (9) [exec] = noop
> > (9) remove_reply_message_if_eap remove_reply_message_if_eap {
> > (9) ? if (reply:EAP-Message && reply:Reply-Message)
> > (9) ? if (reply:EAP-Message && reply:Reply-Message) -> FALSE
> > (9) else else {
> > (9) [noop] = noop
> > (9) } # else else = noop
> > (9) } # remove_reply_message_if_eap remove_reply_message_if_eap = noop
> > (9) update reply {
> > (9) Acct-Interim-Interval = 14400
> > (9) } # update reply = noop
> > (9) } # post-auth = noop
> > Sending Access-Accept of id 134 from 10.146.44.71 port 1812 to
> > 105.187.248.220 port 4017
> > User-Name = 'onyebilanma(a)telkomsa.net'
> > Acct-Interim-Interval = 14400
> >
> > Below is debug from version 3.2.2
> >
> > rlm_ldap (ldap-mobile): Reserved connection (2)
> > (5) ldap-mobile: EXPAND
> > (&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))
> > (5) ldap-mobile: -->
> > (&(mobileradiusCallingStationId=27659066168)(status=10100))
> > (5) ldap-mobile: Performing search in "cn=radius,ou=isp" with filter
> > "(&(mobileradiusCallingStationId=27659066168)(status=10100))", scope
> "sub"
> > (5) ldap-mobile: Waiting for search result...
> > (5) ldap-mobile: User object found at DN "uid=
> ahmed.elhefnawy(a)telkomsa.net
> > ,cn=radius,ou=isp"
> > (5) ldap-mobile: Processing user attributes
> > (5) ldap-mobile: reply:User-Name := 'ahmed.elhefnawy(a)telkomsa.net'
> > (5) ldap-mobile: control:User-Name := 'ahmed.elhefnawy(a)telkomsa.net'
> > rlm_ldap (ldap-mobile): Released connection (2)
> > Need 4 more connections to reach min connections (8)
> > Need more connections to reach 16 spares
> > rlm_ldap (ldap-mobile): Opening additional connection (9), 1 of 28
> pending
> > slots used
> > rlm_ldap (ldap-mobile): Connecting to ldap://10.146.46.133:389
> > rlm_ldap (ldap-mobile): Waiting for bind result...
> > rlm_ldap (ldap-mobile): Bind successful
> > (5) [ldap-mobile] = updated
> > (5) if (!ok) {
> > (5) if (!ok) -> TRUE
> > (5) if (!ok) {
> > (5) [reject] = reject
> > (5) } # if (!ok) = reject
> > (5) } # authorize = reject
> > (5) Invalid user: [27659066168] (from client 105.187.248.220 port 0 cli
> > 27659066168)
> > (5) Using Post-Auth-Type Reject
> > (5) # Executing group from file /etc/raddb/sites-enabled/mobile
> > (5) Post-Auth-Type REJECT {
> > (5) policy remove_reply_message_if_eap {
> > (5) if (&reply:EAP-Message && &reply:Reply-Message) {
> > (5) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
> > (5) else {
> > (5) [noop] = noop
> > (5) } # else = noop
> > (5) } # policy remove_reply_message_if_eap = noop
> > (5) } # Post-Auth-Type REJECT = noop
> > (5) Login incorrect: [27659066168] (from client 105.187.248.220 port 0
> cli
> > 27659066168)
> > (5) Delaying response for 2.000000 seconds
> >
> > Any advice would be appreciated?
> >
> > Regards
> > Steven
> >
> >
> > ------------------------------
> >
> > Message: 2
> > Date: Tue, 21 Feb 2023 17:47:47 -0500
> > From: Alan DeKok <aland(a)deployingradius.com>
> > To: FreeRadius users mailing list
> > <freeradius-users(a)lists.freeradius.org>
> > Subject: Re: Freeradius Upgrade from 3.0.1 to 3.2.2
> > Message-ID: <407E5AF6-AD76-468D-97CD-1D5858D63AC1(a)deployingradius.com>
> > Content-Type: text/plain; charset=us-ascii
> >
> > On Feb 21, 2023, at 4:47 PM, Steven Walters <steven.walters1(a)gmail.com>
> > wrote:
> > > Below is debug from version 3.0.1
> >
> > To be honest... 3.0.1 is about ten years old. We're not going to worry
> > a lot about compatibility with every little piece of it.
> >
> > Plus, there have been many bug fixes since then, including security
> > fixes. If you don't like people attacking your RADIUS server, it should
> > have been updated regularly.
> > > ...
> > > Below is debug from version 3.2.2
> > > ...
> > > (5) [ldap-mobile] = updated
> > > (5) if (!ok) {
> >
> > Change that to:
> >
> > if (!ok || !updated) {
> > ...
> >
> > and it will work.
> >
> > > Any advice would be appreciated?
> >
> > Upgrade regularly.
> >
> > Plus, it helps to explain *why* you have this configuration. You
> > generally don't have to explicitly reject users who don't have passwords.
> > The server will do this automatically.
> >
> > So you don't need a "if not found in LDAP, reject" configuration. Just
> > check LDAP. If the user isn't found, they won't have a password read
> from
> > LDAP. And the server won't be able to authenticate them.
> >
> > Alan DeKok.
> >
> >
> >
> > ------------------------------
> >
> > Message: 3
> > Date: Tue, 21 Feb 2023 17:58:56 -0500
> > From: Alan DeKok <aland(a)deployingradius.com>
> > To: FreeRadius users mailing list
> > <freeradius-users(a)lists.freeradius.org>
> > Subject: Some new documentation for "how to make FreeRADIUS do what I
> > want"
> > Message-ID: <98543E7C-E533-4DBC-9D27-09E9E9261717(a)deployingradius.com>
> > Content-Type: text/plain; charset=us-ascii
> >
> > We've been busy working on v4, including making sure that every aspect
> > of the server is extensively documented.
> >
> >
> > I've just written a document on "policies". But it's really "how do I
> > get this software to do what I want, without going crazy".
> >
> >
> >
> https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
> >
> > It gives a detailed guide to the methods used to create FreeRADIUS
> > configurations.
> >
> > There's also a document on why FreeRADIUS is so complex to configure:
> >
> >
> >
> https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
> >
> > This should help to explain why we can't just have a shiny button which
> > says "do what I want". The configuration is much, much, more complex
> than
> > that.
> >
> > v4 also has complete documentation for each unlang keyword:
> >
> https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
> >
> > This documentation applies to v4, but it's _mostly_ compatible with v3.
> > Where there are changes from v3, the documentation explains it.
> >
> > Hopefully this helps. We're not just wishing that v4 comes out one
> > day. We're actively working on it.
> >
> > Alan DeKok.
> >
> >
> >
> > ------------------------------
> >
> > Subject: Digest Footer
> >
> > -
> > List info/subscribe/unsubscribe? See
> > http://www.freeradius.org/list/users.html
> >
> >
> > ------------------------------
> >
> > End of Freeradius-Users Digest, Vol 214, Issue 21
> > *************************************************
> >
>
>
> --
> Warm Regards
>
> Steven Walters
> 0814287179
>
>
> ------------------------------
>
> Message: 2
> Date: Wed, 22 Feb 2023 14:11:54 -0500
> From: Alan DeKok <aland(a)deployingradius.com>
> To: FreeRadius users mailing list
> <freeradius-users(a)lists.freeradius.org>
> Subject: Re: Freeradius Upgrade from 3.0.1 to 3.2.2
> Message-ID: <AB4430D0-F05B-4484-B471-C38C4F07572B(a)deployingradius.com>
> Content-Type: text/plain; charset=us-ascii
>
> On Feb 22, 2023, at 1:47 PM, Steven Walters <steven.walters1(a)gmail.com>
> wrote:
> > Our fixed line customers authenticate with username and password. Our
> fixed
> > line customers can have a mobile VAS linked to fixed line. Customer can
> > have single SIM or multiple SIM linked to fixed line username on LDAP.
> >
> > In the case of mobile service, we receive the MSISDN in the radius access
> > request. We then lookup the username which has the MSISDN linked on LDAP.
> > If subscriber name has this MSISDN linked, the radius will respond with
> the
> > username in the access-accept. If no match is found it will respond with
> > access-reject.
>
> OK. So "if not found in LDAP, reject". Luckily, the ldap module will
> return "notfound", which is a bit better indication than "!ok" or
> "!updated".
>
> ldap
> if (notfound) {
> reject
> }
>
>
> > When the radius receives the accounting start for this session it will
> have
> > the username of the fixed line service returned in the access-accept and
> > not the MSISDN which was original in the access request.
>
> That makes sense.
>
> > So basically, in the case of the mobile VAS, the authentication finds the
> > username on LDAP which has the MSISDN linked as a VAS and if no username
> > has the MSISDN (for example customer cancelled the VAS but is still
> trying
> > to use the SIM) it will send an access reject. No password checks are
> done
> > for mobile service.
> >
> > This mobile VAS was implemented before I joined so there might be better
> > alternative to provide the same result.
>
> The "notfound' return code is the best indication of "not found" .
>
> Alan DeKok.
>
>
>
> ------------------------------
>
> Subject: Digest Footer
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>
>
> ------------------------------
>
> End of Freeradius-Users Digest, Vol 214, Issue 22
> *************************************************
>
--
Warm Regards
Steven Walters
0814287179
1
0
Hi
I agree, we should have updated our freeradius a long time ago, but we will
do better going forward.
Just to explain what we are training to achieve.
Our fixed line customers authenticate with username and password. Our fixed
line customers can have a mobile VAS linked to fixed line. Customer can
have single SIM or multiple SIM linked to fixed line username on LDAP.
In the case of mobile service, we receive the MSISDN in the radius access
request. We then lookup the username which has the MSISDN linked on LDAP.
If subscriber name has this MSISDN linked, the radius will respond with the
username in the access-accept. If no match is found it will respond with
access-reject.
When the radius receives the accounting start for this session it will have
the username of the fixed line service returned in the access-accept and
not the MSISDN which was original in the access request.
So basically, in the case of the mobile VAS, the authentication finds the
username on LDAP which has the MSISDN linked as a VAS and if no username
has the MSISDN (for example customer cancelled the VAS but is still trying
to use the SIM) it will send an access reject. No password checks are done
for mobile service.
This mobile VAS was implemented before I joined so there might be better
alternative to provide the same result.
Kind regards
Steven
On Wed, 22 Feb 2023 at 14:00, <freeradius-users-request(a)lists.freeradius.org>
wrote:
> Send Freeradius-Users mailing list submissions to
> freeradius-users(a)lists.freeradius.org
>
> To subscribe or unsubscribe via the World Wide Web, visit
> https://lists.freeradius.org/mailman/listinfo/freeradius-users
> or, via email, send a message with subject or body 'help' to
> freeradius-users-request(a)lists.freeradius.org
>
> You can reach the person managing the list at
> freeradius-users-owner(a)lists.freeradius.org
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Freeradius-Users digest..."
>
>
> Today's Topics:
>
> 1. Freeradius Upgrade from 3.0.1 to 3.2.2 (Steven Walters)
> 2. Re: Freeradius Upgrade from 3.0.1 to 3.2.2 (Alan DeKok)
> 3. Some new documentation for "how to make FreeRADIUS do what I
> want" (Alan DeKok)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Tue, 21 Feb 2023 23:47:05 +0200
> From: Steven Walters <steven.walters1(a)gmail.com>
> To: freeradius-users(a)lists.freeradius.org
> Subject: Freeradius Upgrade from 3.0.1 to 3.2.2
> Message-ID:
> <CALF=EMKe4Ky91x7A2GgAKaQkVv0D+qxjWqFkaTOgzq=
> BvBFA2w(a)mail.gmail.com>
> Content-Type: text/plain; charset="UTF-8"
>
> Hi
>
> I am in the process of upgrading our radius servers but have one issue
> outstanding.
>
> Basically we receive in the radius request from mobile a MSISDN. We then go
> do a lookup to find the username on LDAP matching the MSISDN.
>
> In the old version everything works fine but after upgrading the radius
> responds with access rejection even though MSISDN finds a username on LDAP.
>
> Below are extracts from the mobile virtual server file and ldap file.
>
> mobile virtual server:
>
> # The ldap module reads passwords from the LDAP database.
> -ldap-mobile
> if (!ok) {
> reject
>
> ldap:
>
> user {
> # Where to start searching in the tree for users
> base_dn = "${..base_dn}"
>
> # Filter for user objects, should be specific enough
> # to identify a single user object.
> #filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
> #filter =
> "(mobileradiusCallingStationId=%{Calling-Station-Id})"
> filter =
> "(&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))"
>
> Below is debug from version 3.0.1
>
> rlm_ldap (ldap-mobile): Reserved connection (11)
> (9) ldap-mobile : expand:
> "(&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))" ->
> '(&(mobileradiusCallingStationId=27671946862)(status=10100))'
> (9) ldap-mobile : expand: "cn=radius,ou=isp" -> 'cn=radius,ou=isp'
> (9) ldap-mobile : Performing search in 'cn=radius,ou=isp' with filter
> '(&(mobileradiusCallingStationId=27671946862)(status=10100))'
> (9) ldap-mobile : Waiting for search result...
> (9) ldap-mobile : User object found at DN "uid=onyebilanma(a)telkomsa.net
> ,cn=radius,ou=isp"
> (9) ldap-mobile : Processing user attributes
> (9) ldap-mobile : reply:User-Name := '
> onyebilanma(a)telkomsa.net
> '
> (9) ldap-mobile : control:User-Name := '
> onyebilanma(a)telkomsa.net'
> rlm_ldap (ldap-mobile): Released connection (11)
> rlm_ldap (ldap-mobile): Opening additional connection (12)
> rlm_ldap (ldap-mobile): Connecting to 10.146.46.133:389
> TLSMC: MozNSS compatibility interception begins.
> tlsmc_convert: INFO: cannot open the NSS DB, expecting PEM configuration is
> present.
> tlsmc_intercept_initialization: INFO: successfully intercepted TLS
> initialization. Continuing with OpenSSL only.
> TLSMC: MozNSS compatibility interception ends.
> rlm_ldap (ldap-mobile): Waiting for bind result...
> rlm_ldap (ldap-mobile): Bind successful
> (9) [-ldap-mobile] = ok
> (9) ? if (!ok)
> (9) ? if (!ok) -> FALSE
> (9) } # authorize = ok
> (9) Found Auth-Type = Accept
> (9) Auth-Type = Accept, accepting the user
> (9) Login OK: [27671946862] (from client 105.187.248.220 port 0 cli
> 27671946862)
> (9) # Executing section post-auth from file /etc/raddb/sites-enabled/mobile
> (9) post-auth {
> (9) [exec] = noop
> (9) remove_reply_message_if_eap remove_reply_message_if_eap {
> (9) ? if (reply:EAP-Message && reply:Reply-Message)
> (9) ? if (reply:EAP-Message && reply:Reply-Message) -> FALSE
> (9) else else {
> (9) [noop] = noop
> (9) } # else else = noop
> (9) } # remove_reply_message_if_eap remove_reply_message_if_eap = noop
> (9) update reply {
> (9) Acct-Interim-Interval = 14400
> (9) } # update reply = noop
> (9) } # post-auth = noop
> Sending Access-Accept of id 134 from 10.146.44.71 port 1812 to
> 105.187.248.220 port 4017
> User-Name = 'onyebilanma(a)telkomsa.net'
> Acct-Interim-Interval = 14400
>
> Below is debug from version 3.2.2
>
> rlm_ldap (ldap-mobile): Reserved connection (2)
> (5) ldap-mobile: EXPAND
> (&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))
> (5) ldap-mobile: -->
> (&(mobileradiusCallingStationId=27659066168)(status=10100))
> (5) ldap-mobile: Performing search in "cn=radius,ou=isp" with filter
> "(&(mobileradiusCallingStationId=27659066168)(status=10100))", scope "sub"
> (5) ldap-mobile: Waiting for search result...
> (5) ldap-mobile: User object found at DN "uid=ahmed.elhefnawy(a)telkomsa.net
> ,cn=radius,ou=isp"
> (5) ldap-mobile: Processing user attributes
> (5) ldap-mobile: reply:User-Name := 'ahmed.elhefnawy(a)telkomsa.net'
> (5) ldap-mobile: control:User-Name := 'ahmed.elhefnawy(a)telkomsa.net'
> rlm_ldap (ldap-mobile): Released connection (2)
> Need 4 more connections to reach min connections (8)
> Need more connections to reach 16 spares
> rlm_ldap (ldap-mobile): Opening additional connection (9), 1 of 28 pending
> slots used
> rlm_ldap (ldap-mobile): Connecting to ldap://10.146.46.133:389
> rlm_ldap (ldap-mobile): Waiting for bind result...
> rlm_ldap (ldap-mobile): Bind successful
> (5) [ldap-mobile] = updated
> (5) if (!ok) {
> (5) if (!ok) -> TRUE
> (5) if (!ok) {
> (5) [reject] = reject
> (5) } # if (!ok) = reject
> (5) } # authorize = reject
> (5) Invalid user: [27659066168] (from client 105.187.248.220 port 0 cli
> 27659066168)
> (5) Using Post-Auth-Type Reject
> (5) # Executing group from file /etc/raddb/sites-enabled/mobile
> (5) Post-Auth-Type REJECT {
> (5) policy remove_reply_message_if_eap {
> (5) if (&reply:EAP-Message && &reply:Reply-Message) {
> (5) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
> (5) else {
> (5) [noop] = noop
> (5) } # else = noop
> (5) } # policy remove_reply_message_if_eap = noop
> (5) } # Post-Auth-Type REJECT = noop
> (5) Login incorrect: [27659066168] (from client 105.187.248.220 port 0 cli
> 27659066168)
> (5) Delaying response for 2.000000 seconds
>
> Any advice would be appreciated?
>
> Regards
> Steven
>
>
> ------------------------------
>
> Message: 2
> Date: Tue, 21 Feb 2023 17:47:47 -0500
> From: Alan DeKok <aland(a)deployingradius.com>
> To: FreeRadius users mailing list
> <freeradius-users(a)lists.freeradius.org>
> Subject: Re: Freeradius Upgrade from 3.0.1 to 3.2.2
> Message-ID: <407E5AF6-AD76-468D-97CD-1D5858D63AC1(a)deployingradius.com>
> Content-Type: text/plain; charset=us-ascii
>
> On Feb 21, 2023, at 4:47 PM, Steven Walters <steven.walters1(a)gmail.com>
> wrote:
> > Below is debug from version 3.0.1
>
> To be honest... 3.0.1 is about ten years old. We're not going to worry
> a lot about compatibility with every little piece of it.
>
> Plus, there have been many bug fixes since then, including security
> fixes. If you don't like people attacking your RADIUS server, it should
> have been updated regularly.
> > ...
> > Below is debug from version 3.2.2
> > ...
> > (5) [ldap-mobile] = updated
> > (5) if (!ok) {
>
> Change that to:
>
> if (!ok || !updated) {
> ...
>
> and it will work.
>
> > Any advice would be appreciated?
>
> Upgrade regularly.
>
> Plus, it helps to explain *why* you have this configuration. You
> generally don't have to explicitly reject users who don't have passwords.
> The server will do this automatically.
>
> So you don't need a "if not found in LDAP, reject" configuration. Just
> check LDAP. If the user isn't found, they won't have a password read from
> LDAP. And the server won't be able to authenticate them.
>
> Alan DeKok.
>
>
>
> ------------------------------
>
> Message: 3
> Date: Tue, 21 Feb 2023 17:58:56 -0500
> From: Alan DeKok <aland(a)deployingradius.com>
> To: FreeRadius users mailing list
> <freeradius-users(a)lists.freeradius.org>
> Subject: Some new documentation for "how to make FreeRADIUS do what I
> want"
> Message-ID: <98543E7C-E533-4DBC-9D27-09E9E9261717(a)deployingradius.com>
> Content-Type: text/plain; charset=us-ascii
>
> We've been busy working on v4, including making sure that every aspect
> of the server is extensively documented.
>
>
> I've just written a document on "policies". But it's really "how do I
> get this software to do what I want, without going crazy".
>
>
> https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
>
> It gives a detailed guide to the methods used to create FreeRADIUS
> configurations.
>
> There's also a document on why FreeRADIUS is so complex to configure:
>
>
> https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
>
> This should help to explain why we can't just have a shiny button which
> says "do what I want". The configuration is much, much, more complex than
> that.
>
> v4 also has complete documentation for each unlang keyword:
> https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
>
> This documentation applies to v4, but it's _mostly_ compatible with v3.
> Where there are changes from v3, the documentation explains it.
>
> Hopefully this helps. We're not just wishing that v4 comes out one
> day. We're actively working on it.
>
> Alan DeKok.
>
>
>
> ------------------------------
>
> Subject: Digest Footer
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>
>
> ------------------------------
>
> End of Freeradius-Users Digest, Vol 214, Issue 21
> *************************************************
>
--
Warm Regards
Steven Walters
0814287179
2
1
21 Feb '23
We've been busy working on v4, including making sure that every aspect of the server is extensively documented.
I've just written a document on "policies". But it's really "how do I get this software to do what I want, without going crazy".
https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
It gives a detailed guide to the methods used to create FreeRADIUS configurations.
There's also a document on why FreeRADIUS is so complex to configure:
https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
This should help to explain why we can't just have a shiny button which says "do what I want". The configuration is much, much, more complex than that.
v4 also has complete documentation for each unlang keyword: https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modu…
This documentation applies to v4, but it's _mostly_ compatible with v3. Where there are changes from v3, the documentation explains it.
Hopefully this helps. We're not just wishing that v4 comes out one day. We're actively working on it.
Alan DeKok.
1
0
Hi
I am in the process of upgrading our radius servers but have one issue
outstanding.
Basically we receive in the radius request from mobile a MSISDN. We then go
do a lookup to find the username on LDAP matching the MSISDN.
In the old version everything works fine but after upgrading the radius
responds with access rejection even though MSISDN finds a username on LDAP.
Below are extracts from the mobile virtual server file and ldap file.
mobile virtual server:
# The ldap module reads passwords from the LDAP database.
-ldap-mobile
if (!ok) {
reject
ldap:
user {
# Where to start searching in the tree for users
base_dn = "${..base_dn}"
# Filter for user objects, should be specific enough
# to identify a single user object.
#filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
#filter =
"(mobileradiusCallingStationId=%{Calling-Station-Id})"
filter =
"(&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))"
Below is debug from version 3.0.1
rlm_ldap (ldap-mobile): Reserved connection (11)
(9) ldap-mobile : expand:
"(&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))" ->
'(&(mobileradiusCallingStationId=27671946862)(status=10100))'
(9) ldap-mobile : expand: "cn=radius,ou=isp" -> 'cn=radius,ou=isp'
(9) ldap-mobile : Performing search in 'cn=radius,ou=isp' with filter
'(&(mobileradiusCallingStationId=27671946862)(status=10100))'
(9) ldap-mobile : Waiting for search result...
(9) ldap-mobile : User object found at DN "uid=onyebilanma(a)telkomsa.net
,cn=radius,ou=isp"
(9) ldap-mobile : Processing user attributes
(9) ldap-mobile : reply:User-Name := 'onyebilanma(a)telkomsa.net
'
(9) ldap-mobile : control:User-Name := '
onyebilanma(a)telkomsa.net'
rlm_ldap (ldap-mobile): Released connection (11)
rlm_ldap (ldap-mobile): Opening additional connection (12)
rlm_ldap (ldap-mobile): Connecting to 10.146.46.133:389
TLSMC: MozNSS compatibility interception begins.
tlsmc_convert: INFO: cannot open the NSS DB, expecting PEM configuration is
present.
tlsmc_intercept_initialization: INFO: successfully intercepted TLS
initialization. Continuing with OpenSSL only.
TLSMC: MozNSS compatibility interception ends.
rlm_ldap (ldap-mobile): Waiting for bind result...
rlm_ldap (ldap-mobile): Bind successful
(9) [-ldap-mobile] = ok
(9) ? if (!ok)
(9) ? if (!ok) -> FALSE
(9) } # authorize = ok
(9) Found Auth-Type = Accept
(9) Auth-Type = Accept, accepting the user
(9) Login OK: [27671946862] (from client 105.187.248.220 port 0 cli
27671946862)
(9) # Executing section post-auth from file /etc/raddb/sites-enabled/mobile
(9) post-auth {
(9) [exec] = noop
(9) remove_reply_message_if_eap remove_reply_message_if_eap {
(9) ? if (reply:EAP-Message && reply:Reply-Message)
(9) ? if (reply:EAP-Message && reply:Reply-Message) -> FALSE
(9) else else {
(9) [noop] = noop
(9) } # else else = noop
(9) } # remove_reply_message_if_eap remove_reply_message_if_eap = noop
(9) update reply {
(9) Acct-Interim-Interval = 14400
(9) } # update reply = noop
(9) } # post-auth = noop
Sending Access-Accept of id 134 from 10.146.44.71 port 1812 to
105.187.248.220 port 4017
User-Name = 'onyebilanma(a)telkomsa.net'
Acct-Interim-Interval = 14400
Below is debug from version 3.2.2
rlm_ldap (ldap-mobile): Reserved connection (2)
(5) ldap-mobile: EXPAND
(&(mobileradiusCallingStationId=%{Calling-Station-Id})(status=10100))
(5) ldap-mobile: -->
(&(mobileradiusCallingStationId=27659066168)(status=10100))
(5) ldap-mobile: Performing search in "cn=radius,ou=isp" with filter
"(&(mobileradiusCallingStationId=27659066168)(status=10100))", scope "sub"
(5) ldap-mobile: Waiting for search result...
(5) ldap-mobile: User object found at DN "uid=ahmed.elhefnawy(a)telkomsa.net
,cn=radius,ou=isp"
(5) ldap-mobile: Processing user attributes
(5) ldap-mobile: reply:User-Name := 'ahmed.elhefnawy(a)telkomsa.net'
(5) ldap-mobile: control:User-Name := 'ahmed.elhefnawy(a)telkomsa.net'
rlm_ldap (ldap-mobile): Released connection (2)
Need 4 more connections to reach min connections (8)
Need more connections to reach 16 spares
rlm_ldap (ldap-mobile): Opening additional connection (9), 1 of 28 pending
slots used
rlm_ldap (ldap-mobile): Connecting to ldap://10.146.46.133:389
rlm_ldap (ldap-mobile): Waiting for bind result...
rlm_ldap (ldap-mobile): Bind successful
(5) [ldap-mobile] = updated
(5) if (!ok) {
(5) if (!ok) -> TRUE
(5) if (!ok) {
(5) [reject] = reject
(5) } # if (!ok) = reject
(5) } # authorize = reject
(5) Invalid user: [27659066168] (from client 105.187.248.220 port 0 cli
27659066168)
(5) Using Post-Auth-Type Reject
(5) # Executing group from file /etc/raddb/sites-enabled/mobile
(5) Post-Auth-Type REJECT {
(5) policy remove_reply_message_if_eap {
(5) if (&reply:EAP-Message && &reply:Reply-Message) {
(5) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(5) else {
(5) [noop] = noop
(5) } # else = noop
(5) } # policy remove_reply_message_if_eap = noop
(5) } # Post-Auth-Type REJECT = noop
(5) Login incorrect: [27659066168] (from client 105.187.248.220 port 0 cli
27659066168)
(5) Delaying response for 2.000000 seconds
Any advice would be appreciated?
Regards
Steven
2
1
We have today released FreeRADIUS version 3.2.2.
Full changelog is in the source at doc/ChangeLog. Some highlights:
- Ability to add a header to linelog output files
- Config for xlats in rlm_rest
- Default configuration improvements, such as attr_filter and SQL.
- Thread stats now available from radmin
- Clearer "configure" output when building from source
- rlm_unbound added to packages and default build
- Obsolete Dockerfiles for centos8 and debian9 removed
- Fix EAP-TTLS-MSCHAPv2 with TLS 1.3
Download from the usual places:
https://freeradius.org/releases/
ftp://ftp.freeradius.org/pub/freeradius/
https://github.com/FreeRADIUS/freeradius-server/releases/tag/release_3_2_2
Packages are available from Network RADIUS:
https://packages.networkradius.com/
Docker images are available on Dockerhub. The default Ubuntu Docker
image has been bumped from ubuntu20 to ubuntu22:
https://hub.docker.com/u/freeradius
--
Matthew
1
0
Hi,
We use EAP-PEAP and use ldap to normalize usernames and retrieve group
membership (via ldaps). We recently found that our freeradius servers were
only connecting to the first of four ldap servers specified in
mods-available/ldap. The servers are listed on separate lines like this:
server = 'ldaps://dc1.ad.stolaf.edu'
server = 'ldaps://dc2.ad.stolaf.edu'
server = 'ldaps://dc3.ad.stolaf.edu'
server = 'ldaps://dc4.ad.stolaf.edu'
The certificates used for ldaps have SANs that include our domain name '
ad.stolaf.edu' and on my dev server I found that using "server = '
ad.stolaf.edu'" will start connections with all ldap servers, modulo DNS
round robin results.
I consulted some openldap documentation, but am still left with the
question: what is the best practice for listing and utilizing multiple LDAP
servers (for both failover and load balancing)?
Also, is URI or hostname more preferred? (both seem to work in my testing,
I do specify "port = 636" elsewhere in the config)
radiusd -X output from our production config (4 servers listed one per
line):
Wed Feb 15 07:38:33 2023 : Info: rlm_ldap: libldap vendor: OpenLDAP,
version: 20446
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Initialising connection
pool
Wed Feb 15 07:38:33 2023 : Debug: pool {
Wed Feb 15 07:38:33 2023 : Debug: start = 5
Wed Feb 15 07:38:33 2023 : Debug: min = 3
Wed Feb 15 07:38:33 2023 : Debug: max = 32
Wed Feb 15 07:38:33 2023 : Debug: spare = 10
Wed Feb 15 07:38:33 2023 : Debug: uses = 0
Wed Feb 15 07:38:33 2023 : Debug: lifetime = 0
Wed Feb 15 07:38:33 2023 : Debug: cleanup_interval = 30
Wed Feb 15 07:38:33 2023 : Debug: idle_timeout = 60
Wed Feb 15 07:38:33 2023 : Debug: retry_delay = 30
Wed Feb 15 07:38:33 2023 : Debug: spread = no
Wed Feb 15 07:38:33 2023 : Debug: }
Wed Feb 15 07:38:33 2023 : Info: rlm_ldap (ldap): Opening additional
connection (0), 1 of 32 pending slots used
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Connecting to ldaps://
dc1.ad.stolaf.edu:636 ldaps://dc2.ad.stolaf.edu:636 ldaps://
dc3.ad.stolaf.edu:636 ldaps://dc4.ad.stolaf.edu:636
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): New libldap handle
0x564cf7a99500
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Waiting for bind
result...
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Bind successful
Wed Feb 15 07:38:33 2023 : Info: rlm_ldap (ldap): Opening additional
connection (1), 1 of 31 pending slots used
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Connecting to ldaps://
dc1.ad.stolaf.edu:636 ldaps://dc2.ad.stolaf.edu:636 ldaps://
dc3.ad.stolaf.edu:636 ldaps://dc4.ad.stolaf.edu:636
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): New libldap handle
0x564cf7ac04b0
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Waiting for bind
result...
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Bind successful
Wed Feb 15 07:38:33 2023 : Info: rlm_ldap (ldap): Opening additional
connection (2), 1 of 30 pending slots used
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Connecting to ldaps://
dc1.ad.stolaf.edu:636 ldaps://dc2.ad.stolaf.edu:636 ldaps://
dc3.ad.stolaf.edu:636 ldaps://dc4.ad.stolaf.edu:636
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): New libldap handle
0x564cf7aae7a0
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Waiting for bind
result...
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Bind successful
Wed Feb 15 07:38:33 2023 : Info: rlm_ldap (ldap): Opening additional
connection (3), 1 of 29 pending slots used
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Connecting to ldaps://
dc1.ad.stolaf.edu:636 ldaps://dc2.ad.stolaf.edu:636 ldaps://
dc3.ad.stolaf.edu:636 ldaps://dc4.ad.stolaf.edu:636
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): New libldap handle
0x564cf7ac1390
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Waiting for bind
result...
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Bind successful
Wed Feb 15 07:38:33 2023 : Info: rlm_ldap (ldap): Opening additional
connection (4), 1 of 28 pending slots used
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Connecting to ldaps://
dc1.ad.stolaf.edu:636 ldaps://dc2.ad.stolaf.edu:636 ldaps://
dc3.ad.stolaf.edu:636 ldaps://dc4.ad.stolaf.edu:636
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): New libldap handle
0x564cf7ab5cc0
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Waiting for bind
result...
Wed Feb 15 07:38:33 2023 : Debug: rlm_ldap (ldap): Bind successful
Connections from radius server to ldap server - note 5 connections to same
server:
[root@rad-dev ~]# lsof -i | grep radiusd | grep ldaps
radiusd 1023016 radiusd 5u IPv6 16259147 0t0 TCP
rad-dev:56548->[DEAD::BEEF]:ldaps (ESTABLISHED)
radiusd 1023016 radiusd 6u IPv6 16259152 0t0 TCP
rad-dev:56554->[DEAD::BEEF]:ldaps (ESTABLISHED)
radiusd 1023016 radiusd 7u IPv6 16259157 0t0 TCP
rad-dev:56556->[DEAD::BEEF]:ldaps (ESTABLISHED)
radiusd 1023016 radiusd 8u IPv6 16259162 0t0 TCP
rad-dev:56562->[DEAD::BEEF]:ldaps (ESTABLISHED)
radiusd 1023016 radiusd 9u IPv6 16259167 0t0 TCP
rad-dev:56566->[DEAD::BEEF]:ldaps (ESTABLISHED)
dc1.ad.stolaf.edu <--> DEAD::BEEF
Thanks!
ajs
--
*Tony Skalski (he/him/his)*
System Administrator | IT
Office: 507-786-3227 <(507)786-3227>
1510 St. Olaf Avenue Northfield, MN 55057
stolaf.edu
4
7
Connect ldaps(azure ad ds) user on wifi network with ttls/pap protocols
by Chris Nzengue - dejamobile externe 15 Feb '23
by Chris Nzengue - dejamobile externe 15 Feb '23
15 Feb '23
Hello
Before introduce my issue, I would like to thank you for your help and the time you will spend for helping me .
What i am trying to do: i am trying to connect users who are registry on an ldaps to access at the wifi network. The ldaps is an azure ad ds. i am also trying to use ttls/pap protocol.
Why i am trying to do it?: I want do it because i want secure the wifi network and not use a single keyword. i don't want also oblige users to know a new password and id . I want they use the same password and id. i decided to use ttls protocole because i don't want have to manage a certificate server. For the pap protocol part, it is just because i saw this procotol can handle every cases.
What i expect the server to do?: i expect the server check on the ldaps if the id and the password received by the acces point are right. If the id and the password are right then the user join the network.
What the server does instead?:
FreeRADIUS Version 3.0.26
Copyright (C) 1999-2021 The FreeRADIUS server project and contributors
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE
You may redistribute copies of FreeRADIUS under the terms of the
GNU General Public License
For more information about these matters, see the file named COPYRIGHT
Starting - reading configuration files ...
including dictionary file /usr/share/freeradius/dictionary
including dictionary file /usr/share/freeradius/dictionary.dhcp
including dictionary file /usr/share/freeradius/dictionary.vqp
including dictionary file /etc/freeradius/3.0/dictionary
including configuration file /etc/freeradius/3.0/radiusd.conf
including configuration file /etc/freeradius/3.0/proxy.conf
including configuration file /etc/freeradius/3.0/clients.conf
including files in directory /etc/freeradius/3.0/mods-enabled/
including configuration file /etc/freeradius/3.0/mods-enabled/sradutmp
including configuration file /etc/freeradius/3.0/mods-enabled/chap
including configuration file /etc/freeradius/3.0/mods-enabled/exec
including configuration file /etc/freeradius/3.0/mods-enabled/files
including configuration file /etc/freeradius/3.0/mods-enabled/replicate
including configuration file /etc/freeradius/3.0/mods-enabled/cache_eap
including configuration file /etc/freeradius/3.0/mods-enabled/preprocess
including configuration file /etc/freeradius/3.0/mods-enabled/radutmp
including configuration file /etc/freeradius/3.0/mods-enabled/ldap
including configuration file /etc/freeradius/3.0/mods-enabled/logintime
including configuration file /etc/freeradius/3.0/mods-enabled/detail.log
including configuration file /etc/freeradius/3.0/mods-enabled/attr_filter
including configuration file /etc/freeradius/3.0/mods-enabled/digest
including configuration file /etc/freeradius/3.0/mods-enabled/unix
including configuration file /etc/freeradius/3.0/mods-enabled/expr
including configuration file /etc/freeradius/3.0/mods-enabled/dynamic_clients
including configuration file /etc/freeradius/3.0/mods-enabled/linelog
including configuration file /etc/freeradius/3.0/mods-enabled/unpack
including configuration file /etc/freeradius/3.0/mods-enabled/passwd
including configuration file /etc/freeradius/3.0/mods-enabled/pap
including configuration file /etc/freeradius/3.0/mods-enabled/echo
including configuration file /etc/freeradius/3.0/mods-enabled/detail
including configuration file /etc/freeradius/3.0/mods-enabled/always
including configuration file /etc/freeradius/3.0/mods-enabled/utf8
including configuration file /etc/freeradius/3.0/mods-enabled/expiration
including configuration file /etc/freeradius/3.0/mods-enabled/ntlm_auth
including configuration file /etc/freeradius/3.0/mods-enabled/realm
including configuration file /etc/freeradius/3.0/mods-enabled/eap
including configuration file /etc/freeradius/3.0/mods-enabled/soh
including files in directory /etc/freeradius/3.0/policy.d/
including configuration file /etc/freeradius/3.0/policy.d/control
including configuration file /etc/freeradius/3.0/policy.d/operator-name
including configuration file /etc/freeradius/3.0/policy.d/moonshot-targeted-ids
including configuration file /etc/freeradius/3.0/policy.d/dhcp
including configuration file /etc/freeradius/3.0/policy.d/filter
including configuration file /etc/freeradius/3.0/policy.d/canonicalization
including configuration file /etc/freeradius/3.0/policy.d/accounting
including configuration file /etc/freeradius/3.0/policy.d/rfc7542
including configuration file /etc/freeradius/3.0/policy.d/abfab-tr
including configuration file /etc/freeradius/3.0/policy.d/debug
including configuration file /etc/freeradius/3.0/policy.d/cui
including configuration file /etc/freeradius/3.0/policy.d/ntlm_auth
including configuration file /etc/freeradius/3.0/policy.d/eap
including files in directory /etc/freeradius/3.0/sites-enabled/
including configuration file /etc/freeradius/3.0/sites-enabled/inner-tunnel
including configuration file /etc/freeradius/3.0/sites-enabled/default
main {
security {
user = "freerad"
group = "freerad"
allow_core_dumps = no
}
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
}
main {
name = "freeradius"
prefix = "/usr"
localstatedir = "/var"
sbindir = "/usr/sbin"
logdir = "/var/log/freeradius"
run_dir = "/var/run/freeradius"
libdir = "/usr/lib/freeradius"
radacctdir = "/var/log/freeradius/radacct"
hostname_lookups = no
max_request_time = 30
cleanup_delay = 5
max_requests = 16384
postauth_client_lost = no
pidfile = "/var/run/freeradius/freeradius.pid"
checkrad = "/usr/sbin/checkrad"
debug_level = 0
proxy_requests = yes
log {
stripped_names = no
auth = no
auth_badpass = no
auth_goodpass = no
colourise = yes
msg_denied = "You are already logged in - access denied"
}
resources {
}
security {
max_attributes = 200
reject_delay = 1.000000
status_server = yes
}
}
radiusd: #### Loading Realms and Home Servers ####
proxy server {
retry_delay = 5
retry_count = 3
default_fallback = no
dead_time = 120
wake_all_if_all_dead = no
}
home_server localhost {
ipaddr = 127.0.0.1
port = 1812
type = "auth"
secret = <<< secret >>>
response_window = 20.000000
response_timeouts = 1
max_outstanding = 65536
zombie_period = 40
status_check = "status-server"
ping_interval = 30
check_interval = 30
check_timeout = 4
num_answers_to_alive = 3
revive_interval = 120
limit {
max_connections = 16
max_requests = 0
lifetime = 0
idle_timeout = 0
}
coa {
irt = 2
mrt = 16
mrc = 5
mrd = 30
}
}
home_server_pool my_auth_failover {
type = fail-over
home_server = localhost
}
realm example.com {
auth_pool = my_auth_failover
}
realm LOCAL {
}
radiusd: #### Loading Clients ####
client localhost {
ipaddr = 127.0.0.1
require_message_authenticator = no
secret = <<< secret >>>
nas_type = "other"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client AP_cisco1 {
ipaddr = 192.168.200.20
require_message_authenticator = no
secret = <<< secret >>>
virtual_server = "inner-tunnel"
proto = "*"
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
client localhost_ipv6 {
ipv6addr = ::1
require_message_authenticator = no
secret = <<< secret >>>
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Debugger not attached
systemd watchdog is disabled
# Creating Auth-Type = PAP
# Creating Auth-Type = LDAP
# Creating Auth-Type = digest
# Creating Auth-Type = eap
# Creating Autz-Type = New-TLS-Connection
radiusd: #### Instantiating modules ####
modules {
# Loaded module rlm_radutmp
# Loading module "sradutmp" from file /etc/freeradius/3.0/mods-enabled/sradutmp
radutmp sradutmp {
filename = "/var/log/freeradius/sradutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 420
caller_id = no
}
# Loaded module rlm_chap
# Loading module "chap" from file /etc/freeradius/3.0/mods-enabled/chap
# Loaded module rlm_exec
# Loading module "exec" from file /etc/freeradius/3.0/mods-enabled/exec
exec {
wait = no
input_pairs = "request"
shell_escape = yes
timeout = 10
}
# Loaded module rlm_files
# Loading module "files" from file /etc/freeradius/3.0/mods-enabled/files
files {
filename = "/etc/freeradius/3.0/mods-config/files/authorize"
acctusersfile = "/etc/freeradius/3.0/mods-config/files/accounting"
preproxy_usersfile = "/etc/freeradius/3.0/mods-config/files/pre-proxy"
}
# Loaded module rlm_replicate
# Loading module "replicate" from file /etc/freeradius/3.0/mods-enabled/replicate
# Loaded module rlm_cache
# Loading module "cache_eap" from file /etc/freeradius/3.0/mods-enabled/cache_eap
cache cache_eap {
driver = "rlm_cache_rbtree"
key = "%{%{control:State}:-%{%{reply:State}:-%{State}}}"
ttl = 15
max_entries = 0
epoch = 0
add_stats = no
}
# Loaded module rlm_preprocess
# Loading module "preprocess" from file /etc/freeradius/3.0/mods-enabled/preprocess
preprocess {
huntgroups = "/etc/freeradius/3.0/mods-config/preprocess/huntgroups"
hints = "/etc/freeradius/3.0/mods-config/preprocess/hints"
with_ascend_hack = no
ascend_channels_per_line = 23
with_ntdomain_hack = no
with_specialix_jetstream_hack = no
with_cisco_vsa_hack = no
with_alvarion_vsa_hack = no
}
# Loading module "radutmp" from file /etc/freeradius/3.0/mods-enabled/radutmp
radutmp {
filename = "/var/log/freeradius/radutmp"
username = "%{User-Name}"
case_sensitive = yes
check_with_nas = yes
permissions = 384
caller_id = yes
}
# Loaded module rlm_ldap
# Loading module "ldap" from file /etc/freeradius/3.0/mods-enabled/ldap
ldap {
server = "ldaps://aadds.*******.com"
port = 636
identity = "cn=Radius,ou=AADDC Users, dc=*********,dc=com"
password = <<< secret >>>
sasl {
}
user_dn = "LDAP-UserDn"
user {
scope = "sub"
access_positive = yes
sasl {
}
}
group {
filter = "(objectClass=posixGroup)"
scope = "sub"
name_attribute = "cn"
membership_attribute = "memberOf"
cacheable_name = no
cacheable_dn = no
allow_dangling_group_ref = no
}
client {
filter = "(objectClass=radiusClient)"
scope = "sub"
base_dn = "ou=AADDC Users,dc=********,dc=com"
}
profile {
}
options {
ldap_debug = 40
chase_referrals = yes
rebind = yes
net_timeout = 1
res_timeout = 10
srv_timelimit = 3
idle = 60
probes = 3
interval = 3
}
tls {
tls_min_version = "1.2"
start_tls = no
require_cert = "never"
}
}
Creating attribute LDAP-Group
# Loaded module rlm_logintime
# Loading module "logintime" from file /etc/freeradius/3.0/mods-enabled/logintime
logintime {
minimum_timeout = 60
}
# Loaded module rlm_detail
# Loading module "auth_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail auth_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/auth-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "reply_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail reply_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/reply-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "pre_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail pre_proxy_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/pre-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loading module "post_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
detail post_proxy_log {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/post-proxy-detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_attr_filter
# Loading module "attr_filter.post-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.post-proxy {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/post-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.pre-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.pre-proxy {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/pre-proxy"
key = "%{Realm}"
relaxed = no
}
# Loading module "attr_filter.access_reject" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.access_reject {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/access_reject"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.access_challenge" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.access_challenge {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/access_challenge"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.accounting_response" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.accounting_response {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/accounting_response"
key = "%{User-Name}"
relaxed = no
}
# Loading module "attr_filter.coa" from file /etc/freeradius/3.0/mods-enabled/attr_filter
attr_filter attr_filter.coa {
filename = "/etc/freeradius/3.0/mods-config/attr_filter/coa"
key = "%{User-Name}"
relaxed = no
}
# Loaded module rlm_digest
# Loading module "digest" from file /etc/freeradius/3.0/mods-enabled/digest
# Loaded module rlm_unix
# Loading module "unix" from file /etc/freeradius/3.0/mods-enabled/unix
unix {
radwtmp = "/var/log/freeradius/radwtmp"
}
Creating attribute Unix-Group
# Loaded module rlm_expr
# Loading module "expr" from file /etc/freeradius/3.0/mods-enabled/expr
expr {
safe_characters = "@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_: /äéöüàâæçèéêëîïôœùûüaÿÄÉÖÜßÀÂÆÇÈÉÊËÎÏÔŒÙÛÜŸ"
}
# Loaded module rlm_dynamic_clients
# Loading module "dynamic_clients" from file /etc/freeradius/3.0/mods-enabled/dynamic_clients
# Loaded module rlm_linelog
# Loading module "linelog" from file /etc/freeradius/3.0/mods-enabled/linelog
linelog {
filename = "/var/log/freeradius/linelog"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = "This is a log message for %{User-Name}"
reference = "messages.%{%{reply:Packet-Type}:-default}"
}
# Loading module "log_accounting" from file /etc/freeradius/3.0/mods-enabled/linelog
linelog log_accounting {
filename = "/var/log/freeradius/linelog-accounting"
escape_filenames = no
syslog_severity = "info"
permissions = 384
format = ""
reference = "Accounting-Request.%{%{Acct-Status-Type}:-unknown}"
}
# Loaded module rlm_unpack
# Loading module "unpack" from file /etc/freeradius/3.0/mods-enabled/unpack
# Loaded module rlm_passwd
# Loading module "etc_passwd" from file /etc/freeradius/3.0/mods-enabled/passwd
passwd etc_passwd {
filename = "/etc/passwd"
format = "*User-Name:Crypt-Password:"
delimiter = ":"
ignore_nislike = no
ignore_empty = yes
allow_multiple_keys = no
hash_size = 100
}
# Loaded module rlm_pap
# Loading module "pap" from file /etc/freeradius/3.0/mods-enabled/pap
pap {
normalise = yes
}
# Loading module "echo" from file /etc/freeradius/3.0/mods-enabled/echo
exec echo {
wait = yes
program = "/bin/echo %{User-Name}"
input_pairs = "request"
output_pairs = "reply"
shell_escape = yes
}
# Loading module "detail" from file /etc/freeradius/3.0/mods-enabled/detail
detail {
filename = "/var/log/freeradius/radacct/%{%{Packet-Src-IP-Address}:-%{Packet-Src-IPv6-Address}}/detail-%Y%m%d"
header = "%t"
permissions = 384
locking = no
escape_filenames = no
log_packet_header = no
}
# Loaded module rlm_always
# Loading module "reject" from file /etc/freeradius/3.0/mods-enabled/always
always reject {
rcode = "reject"
simulcount = 0
mpp = no
}
# Loading module "fail" from file /etc/freeradius/3.0/mods-enabled/always
always fail {
rcode = "fail"
simulcount = 0
mpp = no
}
# Loading module "ok" from file /etc/freeradius/3.0/mods-enabled/always
always ok {
rcode = "ok"
simulcount = 0
mpp = no
}
# Loading module "handled" from file /etc/freeradius/3.0/mods-enabled/always
always handled {
rcode = "handled"
simulcount = 0
mpp = no
}
# Loading module "invalid" from file /etc/freeradius/3.0/mods-enabled/always
always invalid {
rcode = "invalid"
simulcount = 0
mpp = no
}
# Loading module "userlock" from file /etc/freeradius/3.0/mods-enabled/always
always userlock {
rcode = "userlock"
simulcount = 0
mpp = no
}
# Loading module "notfound" from file /etc/freeradius/3.0/mods-enabled/always
always notfound {
rcode = "notfound"
simulcount = 0
mpp = no
}
# Loading module "noop" from file /etc/freeradius/3.0/mods-enabled/always
always noop {
rcode = "noop"
simulcount = 0
mpp = no
}
# Loading module "updated" from file /etc/freeradius/3.0/mods-enabled/always
always updated {
rcode = "updated"
simulcount = 0
mpp = no
}
# Loaded module rlm_utf8
# Loading module "utf8" from file /etc/freeradius/3.0/mods-enabled/utf8
# Loaded module rlm_expiration
# Loading module "expiration" from file /etc/freeradius/3.0/mods-enabled/expiration
# Loading module "ntlm_auth" from file /etc/freeradius/3.0/mods-enabled/ntlm_auth
exec ntlm_auth {
wait = yes
program = "/etc/freeadius/3.0/mods-available/ntlm_auth --request-nt-key --domain=********.com --username=Radius --password=R7)LhEf3Y}Uv)l"
shell_escape = yes
}
# Loaded module rlm_realm
# Loading module "IPASS" from file /etc/freeradius/3.0/mods-enabled/realm
realm IPASS {
format = "prefix"
delimiter = "/"
ignore_default = no
ignore_null = no
}
# Loading module "suffix" from file /etc/freeradius/3.0/mods-enabled/realm
realm suffix {
format = "suffix"
delimiter = "@"
ignore_default = no
ignore_null = no
}
# Loading module "bangpath" from file /etc/freeradius/3.0/mods-enabled/realm
realm bangpath {
format = "prefix"
delimiter = "!"
ignore_default = no
ignore_null = no
}
# Loading module "realmpercent" from file /etc/freeradius/3.0/mods-enabled/realm
realm realmpercent {
format = "suffix"
delimiter = "%"
ignore_default = no
ignore_null = no
}
# Loading module "ntdomain" from file /etc/freeradius/3.0/mods-enabled/realm
realm ntdomain {
format = "prefix"
delimiter = "\\"
ignore_default = no
ignore_null = no
}
# Loaded module rlm_eap
# Loading module "eap" from file /etc/freeradius/3.0/mods-enabled/eap
eap {
default_eap_type = "ttls"
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no
max_sessions = 16384
}
# Loaded module rlm_soh
# Loading module "soh" from file /etc/freeradius/3.0/mods-enabled/soh
soh {
dhcp = yes
}
instantiate {
}
# Instantiating module "files" from file /etc/freeradius/3.0/mods-enabled/files
reading pairlist file /etc/freeradius/3.0/mods-config/files/authorize
reading pairlist file /etc/freeradius/3.0/mods-config/files/accounting
reading pairlist file /etc/freeradius/3.0/mods-config/files/pre-proxy
# Instantiating module "cache_eap" from file /etc/freeradius/3.0/mods-enabled/cache_eap
rlm_cache (cache_eap): Driver rlm_cache_rbtree (module rlm_cache_rbtree) loaded and linked
# Instantiating module "preprocess" from file /etc/freeradius/3.0/mods-enabled/preprocess
reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/huntgroups
reading pairlist file /etc/freeradius/3.0/mods-config/preprocess/hints
# Instantiating module "ldap" from file /etc/freeradius/3.0/mods-enabled/ldap
rlm_ldap: libldap vendor: OpenLDAP, version: 20513
accounting {
reference = "%{tolower:type.%{Acct-Status-Type}}"
}
post-auth {
reference = "."
}
rlm_ldap (ldap): Initialising connection pool
pool {
start = 5
min = 3
max = 32
spare = 10
uses = 0
lifetime = 0
cleanup_interval = 30
idle_timeout = 60
retry_delay = 30
spread = no
}
rlm_ldap (ldap): Opening additional connection (0), 1 of 32 pending slots used
rlm_ldap (ldap): Connecting to ldaps://aadds.********.com:636
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (1), 1 of 31 pending slots used
rlm_ldap (ldap): Connecting to ldaps://aadds.********.com:636
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (2), 1 of 30 pending slots used
rlm_ldap (ldap): Connecting to ldaps://aadds.********.com:636
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (3), 1 of 29 pending slots used
rlm_ldap (ldap): Connecting to ldaps://aadds.********.com:636
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Opening additional connection (4), 1 of 28 pending slots used
rlm_ldap (ldap): Connecting to ldaps://aadds.********.com:636
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
# Instantiating module "logintime" from file /etc/freeradius/3.0/mods-enabled/logintime
# Instantiating module "auth_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
rlm_detail (auth_log): 'User-Password' suppressed, will not appear in detail output
# Instantiating module "reply_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "pre_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "post_proxy_log" from file /etc/freeradius/3.0/mods-enabled/detail.log
# Instantiating module "attr_filter.post-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/post-proxy
# Instantiating module "attr_filter.pre-proxy" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/pre-proxy
# Instantiating module "attr_filter.access_reject" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/access_reject
# Instantiating module "attr_filter.access_challenge" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/access_challenge
# Instantiating module "attr_filter.accounting_response" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/accounting_response
# Instantiating module "attr_filter.coa" from file /etc/freeradius/3.0/mods-enabled/attr_filter
reading pairlist file /etc/freeradius/3.0/mods-config/attr_filter/coa
# Instantiating module "linelog" from file /etc/freeradius/3.0/mods-enabled/linelog
# Instantiating module "log_accounting" from file /etc/freeradius/3.0/mods-enabled/linelog
# Instantiating module "etc_passwd" from file /etc/freeradius/3.0/mods-enabled/passwd
rlm_passwd: nfields: 3 keyfield 0(User-Name) listable: no
# Instantiating module "pap" from file /etc/freeradius/3.0/mods-enabled/pap
# Instantiating module "detail" from file /etc/freeradius/3.0/mods-enabled/detail
# Instantiating module "reject" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "fail" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "ok" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "handled" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "invalid" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "userlock" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "notfound" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "noop" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "updated" from file /etc/freeradius/3.0/mods-enabled/always
# Instantiating module "expiration" from file /etc/freeradius/3.0/mods-enabled/expiration
# Instantiating module "IPASS" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "suffix" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "bangpath" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "realmpercent" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "ntdomain" from file /etc/freeradius/3.0/mods-enabled/realm
# Instantiating module "eap" from file /etc/freeradius/3.0/mods-enabled/eap
# Linked to sub-module rlm_eap_md5
# Linked to sub-module rlm_eap_gtc
gtc {
challenge = "Password: "
auth_type = "PAP"
}
# Linked to sub-module rlm_eap_tls
tls {
tls = "tls-common"
}
tls-config tls-common {
verify_depth = 0
ca_path = "/etc/freeradius/3.0/certs"
pem_file_type = yes
private_key_file = "/etc/ssl/private/ssl-cert-snakeoil.key"
certificate_file = "/etc/ssl/certs/ssl-cert-snakeoil.pem"
ca_file = "/etc/ssl/certs/ca-certificates.crt"
private_key_password = <<< secret >>>
fragment_size = 1024
include_length = yes
auto_chain = yes
check_crl = no
check_all_crl = no
ca_path_reload_interval = 0
cipher_list = "DEFAULT"
cipher_server_preference = no
reject_unknown_intermediate_ca = no
ecdh_curve = ""
tls_max_version = "1.2"
tls_min_version = "1.2"
cache {
enable = no
lifetime = 24
max_entries = 255
}
verify {
skip_if_ocsp_ok = no
}
ocsp {
enable = no
override_cert_url = yes
url = "http://127.0.0.1/ocsp/"
use_nonce = yes
timeout = 0
softfail = no
}
}
# Linked to sub-module rlm_eap_ttls
ttls {
tls = "tls-common"
default_eap_type = "pap"
copy_request_to_tunnel = yes
use_tunneled_reply = yes
virtual_server = "inner-tunnel"
include_length = yes
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
# Linked to sub-module rlm_eap_peap
peap {
tls = "tls-common"
default_eap_type = "mschapv2"
copy_request_to_tunnel = no
use_tunneled_reply = no
proxy_tunneled_request_as_eap = yes
virtual_server = "inner-tunnel"
soh = no
require_client_cert = no
}
tls: Using cached TLS configuration from previous invocation
} # modules
radiusd: #### Loading Virtual Servers ####
server { # from file /etc/freeradius/3.0/radiusd.conf
} # server
server inner-tunnel { # from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
# Loading authenticate {...}
Compiling Auth-Type PAP for attr Auth-Type
Compiling Auth-Type LDAP for attr Auth-Type
# Loading authorize {...}
# Loading session {...}
# Loading post-proxy {...}
# Loading post-auth {...}
Ignoring "sql" (see raddb/mods-available/README.rst)
# Skipping contents of 'if' as it is always 'false' -- /etc/freeradius/3.0/sites-enabled/inner-tunnel:342
Compiling Post-Auth-Type REJECT for attr Post-Auth-Type
} # server inner-tunnel
server default { # from file /etc/freeradius/3.0/sites-enabled/default
# Loading authenticate {...}
Compiling Auth-Type LDAP for attr Auth-Type
# Loading authorize {...}
Compiling Autz-Type New-TLS-Connection for attr Autz-Type
# Loading preacct {...}
# Loading accounting {...}
# Loading post-proxy {...}
# Loading post-auth {...}
Compiling Post-Auth-Type REJECT for attr Post-Auth-Type
Compiling Post-Auth-Type Challenge for attr Post-Auth-Type
Compiling Post-Auth-Type Client-Lost for attr Post-Auth-Type
} # server default
radiusd: #### Opening IP addresses and Ports ####
listen {
type = "auth"
ipaddr = 127.0.0.1
port = 18120
}
listen {
type = "auth"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipaddr = *
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "auth"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
listen {
type = "acct"
ipv6addr = ::
port = 0
limit {
max_connections = 16
lifetime = 0
idle_timeout = 30
}
}
Listening on auth address 127.0.0.1 port 18120 bound to server inner-tunnel
Listening on auth address * port 1812 bound to server default
Listening on acct address * port 1813 bound to server default
Listening on auth address :: port 1812 bound to server default
Listening on acct address :: port 1813 bound to server default
Listening on proxy address * port 60552
Listening on proxy address :: port 35305
Ready to process requests
(0) Received Access-Request Id 153 from 192.168.200.20:51098 to 192.168.10.124:1812 length 269
(0) User-Name = "chris.********"
(0) Chargeable-User-Identity = 0x14
(0) Location-Capable = Civic-Location
(0) Calling-Station-Id = "98-5a-eb-8e-1c-5c"
(0) Called-Station-Id = "00-fc-ba-e1-98-e0:radius_test"
(0) NAS-Port = 1
(0) Cisco-AVPair = "audit-session-id=14c8a8c000003a87a5e9c663"
(0) Acct-Session-Id = "63c6e996/98:5a:eb:8e:1c:5c/15436"
(0) NAS-IP-Address = 192.168.200.20
(0) NAS-Identifier = "********"
(0) Airespace-Wlan-Id = 6
(0) Service-Type = Framed-User
(0) Framed-MTU = 1300
(0) NAS-Port-Type = Wireless-802.11
(0) EAP-Message = 0x020100120163687269732e6e7a656e677565
(0) Message-Authenticator = 0x974324719f4ff1b1116600ab28a17e4b
(0) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) suffix: Checking for suffix after "@"
(0) suffix: No '@' in User-Name = "chris.********", looking up realm NULL
(0) suffix: No such realm "NULL"
(0) [suffix] = noop
(0) update control {
(0) &Proxy-To-Realm := LOCAL
(0) } # update control = noop
(0) files: Searching for user in group "CN=********Team,OU=AADDC Users,DC=********,DC=com"
rlm_ldap (ldap): Reserved connection (0)
(0) files: EXPAND (&(objectClass=user)(sAMAccountName=%{%{Stripped-User-Name}:-%{User-Name}}))
(0) files: --> (&(objectClass=user)(sAMAccountName=chris.********))
(0) files: Performing search in "ou=AADDC Users,dc=********,dc=com" with filter "(&(objectClass=user)(sAMAccountName=chris.********))", scope "sub"
(0) files: Waiting for search result...
(0) files: User object found at DN "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com"
(0) files: Checking user object's memberOf attributes
(0) files: Performing unfiltered search in "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com", scope "base"
(0) files: Waiting for search result...
(0) files: Processing memberOf value "CN=SSL_VPN_SSO,OU=AADDC Users,DC=********,DC=com" as a DN
(0) files: Processing memberOf value "CN=********Team,OU=AADDC Users,DC=********,DC=com" as a DN
(0) files: User found in group DN "CN=********Team,OU=AADDC Users,DC=********,DC=com". Comparison between membership: dn, check: dn
rlm_ldap (ldap): Released connection (0)
Need more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (5), 1 of 27 pending slots used
rlm_ldap (ldap): Connecting to ldaps://aadds.********.com:636
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
rlm_ldap (ldap): Closing expired connection (4) - Hit idle_timeout limit
rlm_ldap (ldap): Closing expired connection (3) - Hit idle_timeout limit
rlm_ldap (ldap): Closing expired connection (2) - Hit idle_timeout limit
rlm_ldap (ldap): You probably need to lower "min"
rlm_ldap (ldap): Closing expired connection (1) - Hit idle_timeout limit
(0) files: users: Matched entry DEFAULT at line 72
(0) [files] = ok
rlm_ldap (ldap): Reserved connection (0)
(0) ldap: EXPAND (&(objectClass=user)(sAMAccountName=%{%{Stripped-User-Name}:-%{User-Name}}))
(0) ldap: --> (&(objectClass=user)(sAMAccountName=chris.********))
(0) ldap: Performing search in "ou=AADDC Users,dc=********,dc=com" with filter "(&(objectClass=user)(sAMAccountName=chris.********))", scope "sub"
(0) ldap: Waiting for search result...
(0) ldap: User object found at DN "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com"
(0) ldap: Processing user attributes
(0) ldap: control:My_Group = 'CN=SSL_VPN_SSO,OU=AADDC Users,DC=********,DC=com'
(0) ldap: WARNING: No "known good" password added. Ensure the admin user has permission to read the password attribute
(0) ldap: WARNING: PAP authentication will *NOT* work with Active Directory (if that is what you were trying to configure)
rlm_ldap (ldap): Released connection (0)
(0) [ldap] = updated
(0) if ((ok || updated) && User-Password && !control:Auth-Type) {
(0) if ((ok || updated) && User-Password && !control:Auth-Type) -> FALSE
(0) [expiration] = noop
(0) [logintime] = noop
(0) [pap] = noop
(0) } # authorize = updated
(0) ERROR: No Auth-Type found: rejecting the user via Post-Auth-Type = Reject
(0) Failed to authenticate the user
(0) Using Post-Auth-Type Reject
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(0) Post-Auth-Type REJECT {
(0) attr_filter.access_reject: EXPAND %{User-Name}
(0) attr_filter.access_reject: --> chris.********
(0) attr_filter.access_reject: Matched entry DEFAULT at line 11
(0) [attr_filter.access_reject] = updated
(0) update outer.session-state {
(0) ERROR: Mapping "&request:Module-Failure-Message" -> "&Module-Failure-Message" invalid in this context
(0) } # update outer.session-state = invalid
(0) } # Post-Auth-Type REJECT = invalid
(0) Delaying response for 1.000000 seconds
Waking up in 0.1 seconds.
Waking up in 0.8 seconds.
(0) Sending delayed response
(0) Sent Access-Reject Id 153 from 192.168.10.124:1812 to 192.168.200.20:51098 length 20
Waking up in 3.9 seconds.
(0) Cleaning up request packet ID 153 with timestamp +75 due to cleanup_delay was reached
Ready to process requests
(1) Received Access-Request Id 154 from 192.168.200.20:51098 to 192.168.10.124:1812 length 269
(1) User-Name = "chris.********"
(1) Chargeable-User-Identity = 0x14
(1) Location-Capable = Civic-Location
(1) Calling-Station-Id = "98-5a-eb-8e-1c-5c"
(1) Called-Station-Id = "00-fc-ba-e1-8f-a0:radius_test"
(1) NAS-Port = 1
(1) Cisco-AVPair = "audit-session-id=14c8a8c000003a87a5e9c663"
(1) Acct-Session-Id = "63c6e996/98:5a:eb:8e:1c:5c/15436"
(1) NAS-IP-Address = 192.168.200.20
(1) NAS-Identifier = "********"
(1) Airespace-Wlan-Id = 6
(1) Service-Type = Framed-User
(1) Framed-MTU = 1300
(1) NAS-Port-Type = Wireless-802.11
(1) EAP-Message = 0x020100120163687269732e6e7a656e677565
(1) Message-Authenticator = 0xa0ca0c245aef7cfc9b3da3a37d812c5f
(1) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(1) authorize {
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # if (&User-Name) = notfound
(1) } # policy filter_username = notfound
(1) suffix: Checking for suffix after "@"
(1) suffix: No '@' in User-Name = "chris.********", looking up realm NULL
(1) suffix: No such realm "NULL"
(1) [suffix] = noop
(1) update control {
(1) &Proxy-To-Realm := LOCAL
(1) } # update control = noop
(1) files: Searching for user in group "CN=********Team,OU=AADDC Users,DC=********,DC=com"
rlm_ldap (ldap): Reserved connection (5)
(1) files: EXPAND (&(objectClass=user)(sAMAccountName=%{%{Stripped-User-Name}:-%{User-Name}}))
(1) files: --> (&(objectClass=user)(sAMAccountName=chris.********))
(1) files: Performing search in "ou=AADDC Users,dc=********,dc=com" with filter "(&(objectClass=user)(sAMAccountName=chris.********))", scope "sub"
(1) files: Waiting for search result...
(1) files: User object found at DN "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com"
(1) files: Checking user object's memberOf attributes
(1) files: Performing unfiltered search in "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com", scope "base"
(1) files: Waiting for search result...
(1) files: Processing memberOf value "CN=SSL_VPN_SSO,OU=AADDC Users,DC=********,DC=com" as a DN
(1) files: Processing memberOf value "CN=********Team,OU=AADDC Users,DC=********,DC=com" as a DN
(1) files: User found in group DN "CN=********Team,OU=AADDC Users,DC=********,DC=com". Comparison between membership: dn, check: dn
rlm_ldap (ldap): Released connection (5)
Need 1 more connections to reach min connections (3)
Need more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (6), 1 of 30 pending slots used
rlm_ldap (ldap): Connecting to ldaps://aadds.********.com:636
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
(1) files: users: Matched entry DEFAULT at line 72
(1) [files] = ok
rlm_ldap (ldap): Reserved connection (0)
(1) ldap: EXPAND (&(objectClass=user)(sAMAccountName=%{%{Stripped-User-Name}:-%{User-Name}}))
(1) ldap: --> (&(objectClass=user)(sAMAccountName=chris.********))
(1) ldap: Performing search in "ou=AADDC Users,dc=********,dc=com" with filter "(&(objectClass=user)(sAMAccountName=chris.********))", scope "sub"
(1) ldap: Waiting for search result...
(1) ldap: User object found at DN "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com"
(1) ldap: Processing user attributes
(1) ldap: control:My_Group = 'CN=SSL_VPN_SSO,OU=AADDC Users,DC=********,DC=com'
(1) ldap: WARNING: No "known good" password added. Ensure the admin user has permission to read the password attribute
(1) ldap: WARNING: PAP authentication will *NOT* work with Active Directory (if that is what you were trying to configure)
rlm_ldap (ldap): Released connection (0)
(1) [ldap] = updated
(1) if ((ok || updated) && User-Password && !control:Auth-Type) {
(1) if ((ok || updated) && User-Password && !control:Auth-Type) -> FALSE
(1) [expiration] = noop
(1) [logintime] = noop
(1) [pap] = noop
(1) } # authorize = updated
(1) ERROR: No Auth-Type found: rejecting the user via Post-Auth-Type = Reject
(1) Failed to authenticate the user
(1) Using Post-Auth-Type Reject
(1) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(1) Post-Auth-Type REJECT {
(1) attr_filter.access_reject: EXPAND %{User-Name}
(1) attr_filter.access_reject: --> chris.********
(1) attr_filter.access_reject: Matched entry DEFAULT at line 11
(1) [attr_filter.access_reject] = updated
(1) update outer.session-state {
(1) ERROR: Mapping "&request:Module-Failure-Message" -> "&Module-Failure-Message" invalid in this context
(1) } # update outer.session-state = invalid
(1) } # Post-Auth-Type REJECT = invalid
(1) Delaying response for 1.000000 seconds
Waking up in 0.1 seconds.
Waking up in 0.8 seconds.
(1) Sending delayed response
(1) Sent Access-Reject Id 154 from 192.168.10.124:1812 to 192.168.200.20:51098 length 20
Waking up in 3.9 seconds.
(1) Cleaning up request packet ID 154 with timestamp +95 due to cleanup_delay was reached
Ready to process requests
(2) Received Access-Request Id 155 from 192.168.200.20:51098 to 192.168.10.124:1812 length 269
(2) User-Name = "chris.********"
(2) Chargeable-User-Identity = 0x14
(2) Location-Capable = Civic-Location
(2) Calling-Station-Id = "98-5a-eb-8e-1c-5c"
(2) Called-Station-Id = "00-fc-ba-e1-8f-a0:radius_test"
(2) NAS-Port = 1
(2) Cisco-AVPair = "audit-session-id=14c8a8c000003a87a5e9c663"
(2) Acct-Session-Id = "63c6e996/98:5a:eb:8e:1c:5c/15436"
(2) NAS-IP-Address = 192.168.200.20
(2) NAS-Identifier = "********"
(2) Airespace-Wlan-Id = 6
(2) Service-Type = Framed-User
(2) Framed-MTU = 1300
(2) NAS-Port-Type = Wireless-802.11
(2) EAP-Message = 0x020100120163687269732e6e7a656e677565
(2) Message-Authenticator = 0x1ed012aae54a89fb6558ea0019fafe02
(2) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(2) authorize {
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) } # if (&User-Name) = notfound
(2) } # policy filter_username = notfound
(2) suffix: Checking for suffix after "@"
(2) suffix: No '@' in User-Name = "chris.********", looking up realm NULL
(2) suffix: No such realm "NULL"
(2) [suffix] = noop
(2) update control {
(2) &Proxy-To-Realm := LOCAL
(2) } # update control = noop
(2) files: Searching for user in group "CN=********Team,OU=AADDC Users,DC=********,DC=com"
rlm_ldap (ldap): Reserved connection (5)
(2) files: EXPAND (&(objectClass=user)(sAMAccountName=%{%{Stripped-User-Name}:-%{User-Name}}))
(2) files: --> (&(objectClass=user)(sAMAccountName=chris.********))
(2) files: Performing search in "ou=AADDC Users,dc=********,dc=com" with filter "(&(objectClass=user)(sAMAccountName=chris.********))", scope "sub"
(2) files: Waiting for search result...
(2) files: User object found at DN "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com"
(2) files: Checking user object's memberOf attributes
(2) files: Performing unfiltered search in "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com", scope "base"
(2) files: Waiting for search result...
(2) files: Processing memberOf value "CN=SSL_VPN_SSO,OU=AADDC Users,DC=********,DC=com" as a DN
(2) files: Processing memberOf value "CN=********Team,OU=AADDC Users,DC=********,DC=com" as a DN
(2) files: User found in group DN "CN=********Team,OU=AADDC Users,DC=********,DC=com". Comparison between membership: dn, check: dn
rlm_ldap (ldap): Released connection (5)
Need more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (7), 1 of 29 pending slots used
rlm_ldap (ldap): Connecting to ldaps://aadds.********.com:636
rlm_ldap (ldap): Waiting for bind result...
rlm_ldap (ldap): Bind successful
(2) files: users: Matched entry DEFAULT at line 72
(2) [files] = ok
rlm_ldap (ldap): Reserved connection (6)
(2) ldap: EXPAND (&(objectClass=user)(sAMAccountName=%{%{Stripped-User-Name}:-%{User-Name}}))
(2) ldap: --> (&(objectClass=user)(sAMAccountName=chris.********))
(2) ldap: Performing search in "ou=AADDC Users,dc=********,dc=com" with filter "(&(objectClass=user)(sAMAccountName=chris.********))", scope "sub"
(2) ldap: Waiting for search result...
(2) ldap: User object found at DN "CN=Chris ******** - ******** externe,OU=AADDC Users,DC=********,DC=com"
(2) ldap: Processing user attributes
(2) ldap: control:My_Group = 'CN=SSL_VPN_SSO,OU=AADDC Users,DC=********,DC=com'
(2) ldap: WARNING: No "known good" password added. Ensure the admin user has permission to read the password attribute
(2) ldap: WARNING: PAP authentication will *NOT* work with Active Directory (if that is what you were trying to configure)
rlm_ldap (ldap): Released connection (6)
(2) [ldap] = updated
(2) if ((ok || updated) && User-Password && !control:Auth-Type) {
(2) if ((ok || updated) && User-Password && !control:Auth-Type) -> FALSE
(2) [expiration] = noop
(2) [logintime] = noop
(2) [pap] = noop
(2) } # authorize = updated
(2) ERROR: No Auth-Type found: rejecting the user via Post-Auth-Type = Reject
(2) Failed to authenticate the user
(2) Using Post-Auth-Type Reject
(2) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(2) Post-Auth-Type REJECT {
(2) attr_filter.access_reject: EXPAND %{User-Name}
(2) attr_filter.access_reject: --> chris.********
(2) attr_filter.access_reject: Matched entry DEFAULT at line 11
(2) [attr_filter.access_reject] = updated
(2) update outer.session-state {
(2) ERROR: Mapping "&request:Module-Failure-Message" -> "&Module-Failure-Message" invalid in this context
(2) } # update outer.session-state = invalid
(2) } # Post-Auth-Type REJECT = invalid
(2) Delaying response for 1.000000 seconds
Waking up in 0.1 seconds.
Waking up in 0.8 seconds.
(2) Sending delayed response
(2) Sent Access-Reject Id 155 from 192.168.10.124:1812 to 192.168.200.20:51098 length 20
Waking up in 3.9 seconds.
(2) Cleaning up request packet ID 155 with timestamp +101 due to cleanup_delay was reached
Ready to process requests
<https://www.dejamobile.com/><https://www.dejamobile.com/><https://www.dejamobile.com/><https://www.dejamobile.com/><https://www.dejamobile.com/>
<https://dejamobile.com/>[cid:logo-500x500_504d48b6-dc99-43ec-874c-af726c18f56e.png]
Chris Nzengue
Stagiaire DEVOPS
DEVOPS internship
<https://www.linkedin.com/company/dejamobile> [cid:SocialLink_Linkedin_32x32_b9896d3d-92f0-40ba-b3a3-c8ead42de0f5.png] <https://www.linkedin.com/company/dejamobile> <https://www.linkedin.com/company/dejamobile> <https://www.twitter.com/dejamobile> [cid:SocialLink_Twitter_32x32_d8c0f93a-95bb-4ab2-8384-cc2e43456b2f.png] <https://twitter.com/dejamobile>
Fixe / Office: +33(2)14747500
chris.nzengue(a)dejamobile.com<mailto:%7BE-mail%7D>
<https://www.linkedin.com/company/dejamobile><http://www.linkedin.com/company/dejamobile><https://www.linkedin.com/company/dejamobile><https://dejamobile.com/dejamobile-at-mpe-2022/><https://www.linkedin.com/company/dejamobile/>[cid:mpe23mail_c31705da-edc4-4d9a-aa24-bb15583ff32a.png]<https://www.merchantpaymentsecosystem.com/>
2
1
Hello All,
how in unlang can a list attribute be converted into a string of the values,
eg. the DHCP-Parameter-Request-List into something like:
"DHCP-Subnet-Mask,DHCP-Router-Address,DHCP-Domain-Name-Server" ?
Thanks and greetings
Hermann
3
2
Hello,
I followed this tutorial (https://www.nasirhafeez.com/wp-comments-post.php) for testing purposes several times and it worked flawlessly. several month later I wanted to put it in production and it stop working.
This is my setup: 2 Raspberry PIs with freeradius 3.0.12 (allready tried the Backport version 3.2.1 as well) Unifi AC HD AccessPoints and as clients macOS and iOS devices (tried macOS versions 11.7 to 13.1) for testing I tried an Ubuntu client as well.
Binding to Google LDAP works without any issues (radtest results in Access-Accept) I even see that the Radius server sends an “Access-Accept” to the clients but shortly after the client starts another Access-Request an that fails with:
(9) eap: ERROR: rlm_eap (EAP): No EAP session matching state 0x864de94f8144fc95
(9) eap: Either EAP-request timed out OR EAP-response to an unknown EAP-request
(9) eap: Failed in handler
Any idea what is happening here?
Here the full output of a test with freeradius -X
Ready to process requests
(0) Received Access-Request Id 18 from 10.100.2.39:54686 to 10.100.1.65:1812 length 253
(0) User-Name = "klaus.mustermann"
(0) NAS-IP-Address = 10.100.2.39
(0) NAS-Identifier = "8283c219e7f9"
(0) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(0) NAS-Port-Type = Wireless-802.11
(0) Service-Type = Framed-User
(0) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(0) Connect-Info = "CONNECT 0Mbps 802.11b"
(0) Acct-Session-Id = "690B866461ACEC60"
(0) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(0) Mobility-Domain-Id = 46476
(0) WLAN-Pairwise-Cipher = 1027076
(0) WLAN-Group-Cipher = 1027076
(0) WLAN-AKM-Suite = 1027075
(0) Framed-MTU = 1400
(0) EAP-Message = 0x02670015016b6c6175732e6d75737465726d616e6e
(0) Message-Authenticator = 0x8d4fe3c9b693e2d71ed16670b1d148a8
(0) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(0) authorize {
(0) policy filter_username {
(0) if (&User-Name) {
(0) if (&User-Name) -> TRUE
(0) if (&User-Name) {
(0) if (&User-Name =~ / /) {
(0) if (&User-Name =~ / /) -> FALSE
(0) if (&User-Name =~ /@[^@]*@/ ) {
(0) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(0) if (&User-Name =~ /\.\./ ) {
(0) if (&User-Name =~ /\.\./ ) -> FALSE
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(0) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(0) if (&User-Name =~ /\.$/) {
(0) if (&User-Name =~ /\.$/) -> FALSE
(0) if (&User-Name =~ /(a)\./) {
(0) if (&User-Name =~ /(a)\./) -> FALSE
(0) } # if (&User-Name) = notfound
(0) } # policy filter_username = notfound
(0) [preprocess] = ok
(0) [chap] = noop
(0) [mschap] = noop
(0) [digest] = noop
(0) suffix: Checking for suffix after "@"
(0) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(0) suffix: No such realm "NULL"
(0) [suffix] = noop
(0) eap: Peer sent EAP Response (code 2) ID 103 length 21
(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(0) [eap] = ok
(0) } # authorize = ok
(0) Found Auth-Type = eap
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(0) authenticate {
(0) eap: Peer sent packet with method EAP Identity (1)
(0) eap: Calling submodule eap_ttls to process data
(0) eap_ttls: (TLS) Initiating new session
(0) eap: Sending EAP Request (code 1) ID 104 length 6
(0) eap: EAP session adding &reply:State = 0x33754777331d52c5
(0) [eap] = handled
(0) } # authenticate = handled
(0) Using Post-Auth-Type Challenge
(0) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(0) Challenge { ... } # empty sub-section is ignored
(0) session-state: Saving cached attributes
(0) Framed-MTU = 994
(0) Sent Access-Challenge Id 18 from 10.100.1.65:1812 to 10.100.2.39:54686 length 64
(0) EAP-Message = 0x016800061520
(0) Message-Authenticator = 0x00000000000000000000000000000000
(0) State = 0x33754777331d52c5d9592c39c6f43193
(0) Finished request
Waking up in 4.9 seconds.
(1) Received Access-Request Id 19 from 10.100.2.39:54686 to 10.100.1.65:1812 length 411
(1) User-Name = "klaus.mustermann"
(1) NAS-IP-Address = 10.100.2.39
(1) NAS-Identifier = "8283c219e7f9"
(1) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(1) NAS-Port-Type = Wireless-802.11
(1) Service-Type = Framed-User
(1) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(1) Connect-Info = "CONNECT 0Mbps 802.11b"
(1) Acct-Session-Id = "690B866461ACEC60"
(1) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(1) Mobility-Domain-Id = 46476
(1) WLAN-Pairwise-Cipher = 1027076
(1) WLAN-Group-Cipher = 1027076
(1) WLAN-AKM-Suite = 1027075
(1) Framed-MTU = 1400
(1) EAP-Message = 0x026800a115800000009716030100920100008e030363ce9a00af0158c4304b8191e349a5c4d7e344c71cf9ceb42fc1dc05eee1d4ea00002c00ffc02cc02bc024c023c00ac009c008c030c02fc028c027c014c013c012009d009c003d003c0035002f000a01000039000a00080006001700180019000b00020100000d00120010040102010501060104030203050306030005000501000000000012000000170000
(1) State = 0x33754777331d52c5d9592c39c6f43193
(1) Message-Authenticator = 0xaf2835db2d901930a1abf923e81f8d4b
(1) Restoring &session-state
(1) &session-state:Framed-MTU = 994
(1) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(1) authorize {
(1) policy filter_username {
(1) if (&User-Name) {
(1) if (&User-Name) -> TRUE
(1) if (&User-Name) {
(1) if (&User-Name =~ / /) {
(1) if (&User-Name =~ / /) -> FALSE
(1) if (&User-Name =~ /@[^@]*@/ ) {
(1) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(1) if (&User-Name =~ /\.\./ ) {
(1) if (&User-Name =~ /\.\./ ) -> FALSE
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(1) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(1) if (&User-Name =~ /\.$/) {
(1) if (&User-Name =~ /\.$/) -> FALSE
(1) if (&User-Name =~ /(a)\./) {
(1) if (&User-Name =~ /(a)\./) -> FALSE
(1) } # if (&User-Name) = notfound
(1) } # policy filter_username = notfound
(1) [preprocess] = ok
(1) [chap] = noop
(1) [mschap] = noop
(1) [digest] = noop
(1) suffix: Checking for suffix after "@"
(1) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(1) suffix: No such realm "NULL"
(1) [suffix] = noop
(1) eap: Peer sent EAP Response (code 2) ID 104 length 161
(1) eap: Continuing tunnel setup
(1) [eap] = ok
(1) } # authorize = ok
(1) Found Auth-Type = eap
(1) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(1) authenticate {
(1) eap: Expiring EAP session with state 0x33754777331d52c5
(1) eap: Finished EAP session with state 0x33754777331d52c5
(1) eap: Previous EAP request found for state 0x33754777331d52c5, released from the list
(1) eap: Peer sent packet with method EAP TTLS (21)
(1) eap: Calling submodule eap_ttls to process data
(1) eap_ttls: Authenticate
(1) eap_ttls: (TLS) EAP Peer says that the final record size will be 151 bytes
(1) eap_ttls: (TLS) EAP Got all data (151 bytes)
(1) eap_ttls: (TLS) Handshake state - before SSL initialization
(1) eap_ttls: (TLS) Handshake state - Server before SSL initialization
(1) eap_ttls: (TLS) Handshake state - Server before SSL initialization
(1) eap_ttls: (TLS) recv TLS 1.3 Handshake, ClientHello
(1) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS read client hello
(1) eap_ttls: (TLS) send TLS 1.2 Handshake, ServerHello
(1) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS write server hello
(1) eap_ttls: (TLS) send TLS 1.2 Handshake, Certificate
(1) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS write certificate
(1) eap_ttls: (TLS) send TLS 1.2 Handshake, ServerKeyExchange
(1) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS write key exchange
(1) eap_ttls: (TLS) send TLS 1.2 Handshake, ServerHelloDone
(1) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS write server done
(1) eap_ttls: (TLS) Server : Need to read more data: SSLv3/TLS write server done
(1) eap_ttls: (TLS) In Handshake Phase
(1) eap: Sending EAP Request (code 1) ID 105 length 1004
(1) eap: EAP session adding &reply:State = 0x33754777321c52c5
(1) [eap] = handled
(1) } # authenticate = handled
(1) Using Post-Auth-Type Challenge
(1) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(1) Challenge { ... } # empty sub-section is ignored
(1) session-state: Saving cached attributes
(1) Framed-MTU = 994
(1) Sent Access-Challenge Id 19 from 10.100.1.65:1812 to 10.100.2.39:54686 length 1068
(1) EAP-Message = 0x016903ec15c000001151160303003d02000039030333251bb0257a7e942419ced1c14e2115f3355723303c682158f6d50e662be4da00c030000011ff01000100000b000403000102001700001603030eaf0b000eab000ea800071930820715308204fda0030201020208651e057cf4b3407c300d06092a864886f70d01010b05003081bd310b3009060355040613024445310f300d060355040813064265726c696e310f300d060355040713064265726c696e31183016060355040a130f42756464796272616e6420476d624831293027060355040b132042756464796272616e6420436572746966696361746520417574686f72697479312630240603550403131d42756464796272616e6420496e7465726d656469617465204341203034311f301d06092a864886f70d010901161069744062756464796272616e642e6465301e170d3233303130323030303030305a170d3235303430353233353935395a3081bb310b3009060355040613024445310f300d0603
(1) Message-Authenticator = 0x00000000000000000000000000000000
(1) State = 0x33754777321c52c5d9592c39c6f43193
(1) Finished request
Waking up in 4.8 seconds.
(2) Received Access-Request Id 20 from 10.100.2.39:54686 to 10.100.1.65:1812 length 256
(2) User-Name = "klaus.mustermann"
(2) NAS-IP-Address = 10.100.2.39
(2) NAS-Identifier = "8283c219e7f9"
(2) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(2) NAS-Port-Type = Wireless-802.11
(2) Service-Type = Framed-User
(2) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(2) Connect-Info = "CONNECT 0Mbps 802.11b"
(2) Acct-Session-Id = "690B866461ACEC60"
(2) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(2) Mobility-Domain-Id = 46476
(2) WLAN-Pairwise-Cipher = 1027076
(2) WLAN-Group-Cipher = 1027076
(2) WLAN-AKM-Suite = 1027075
(2) Framed-MTU = 1400
(2) EAP-Message = 0x026900061500
(2) State = 0x33754777321c52c5d9592c39c6f43193
(2) Message-Authenticator = 0x61c34e69e7f5f253a9fdf8868c0f8826
(2) Restoring &session-state
(2) &session-state:Framed-MTU = 994
(2) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(2) authorize {
(2) policy filter_username {
(2) if (&User-Name) {
(2) if (&User-Name) -> TRUE
(2) if (&User-Name) {
(2) if (&User-Name =~ / /) {
(2) if (&User-Name =~ / /) -> FALSE
(2) if (&User-Name =~ /@[^@]*@/ ) {
(2) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(2) if (&User-Name =~ /\.\./ ) {
(2) if (&User-Name =~ /\.\./ ) -> FALSE
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(2) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(2) if (&User-Name =~ /\.$/) {
(2) if (&User-Name =~ /\.$/) -> FALSE
(2) if (&User-Name =~ /(a)\./) {
(2) if (&User-Name =~ /(a)\./) -> FALSE
(2) } # if (&User-Name) = notfound
(2) } # policy filter_username = notfound
(2) [preprocess] = ok
(2) [chap] = noop
(2) [mschap] = noop
(2) [digest] = noop
(2) suffix: Checking for suffix after "@"
(2) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(2) suffix: No such realm "NULL"
(2) [suffix] = noop
(2) eap: Peer sent EAP Response (code 2) ID 105 length 6
(2) eap: Continuing tunnel setup
(2) [eap] = ok
(2) } # authorize = ok
(2) Found Auth-Type = eap
(2) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(2) authenticate {
(2) eap: Expiring EAP session with state 0x33754777321c52c5
(2) eap: Finished EAP session with state 0x33754777321c52c5
(2) eap: Previous EAP request found for state 0x33754777321c52c5, released from the list
(2) eap: Peer sent packet with method EAP TTLS (21)
(2) eap: Calling submodule eap_ttls to process data
(2) eap_ttls: Authenticate
(2) eap_ttls: (TLS) Peer ACKed our handshake fragment
(2) eap: Sending EAP Request (code 1) ID 106 length 1004
(2) eap: EAP session adding &reply:State = 0x33754777311f52c5
(2) [eap] = handled
(2) } # authenticate = handled
(2) Using Post-Auth-Type Challenge
(2) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(2) Challenge { ... } # empty sub-section is ignored
(2) session-state: Saving cached attributes
(2) Framed-MTU = 994
(2) Sent Access-Challenge Id 20 from 10.100.1.65:1812 to 10.100.2.39:54686 length 1068
(2) EAP-Message = 0x016a03ec15c000001151634a5ca32fca591c963a10e1e4fc909ecc4cf2f3259d2cc70fde28bea17fe514687c8e2ceb902a9d47fde53d01733845bba3e9d6a95f90195118e26a7a98ef957393cd519e06e02ec652ceb9fef0ef8e67a1dc250203010001a382011730820113300c0603551d130101ff04023000301d0603551d0e041604140d3fc210b4abae8368f6656c2f4182ded3cba973301f0603551d23041830168014bb50e659b6554824eb10703f59de33b5ab10d343300e0603551d0f0101ff0404030203e830130603551d25040c300a06082b0601050507030130260603551d11041f301d821b6265723072616430342e696e742e62756464796272616e642e646530430603551d1f0101ff043930373035a033a031862f687474703a2f2f63726c2e62756464796272616e642e64653a383038302f696e746572636130345f63726c2e70656d301106096086480186f8420101040403020640301e06096086480186f842010d0411160f7863612063657274
(2) Message-Authenticator = 0x00000000000000000000000000000000
(2) State = 0x33754777311f52c5d9592c39c6f43193
(2) Finished request
Waking up in 4.8 seconds.
(3) Received Access-Request Id 21 from 10.100.2.39:54686 to 10.100.1.65:1812 length 256
(3) User-Name = "klaus.mustermann"
(3) NAS-IP-Address = 10.100.2.39
(3) NAS-Identifier = "8283c219e7f9"
(3) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(3) NAS-Port-Type = Wireless-802.11
(3) Service-Type = Framed-User
(3) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(3) Connect-Info = "CONNECT 0Mbps 802.11b"
(3) Acct-Session-Id = "690B866461ACEC60"
(3) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(3) Mobility-Domain-Id = 46476
(3) WLAN-Pairwise-Cipher = 1027076
(3) WLAN-Group-Cipher = 1027076
(3) WLAN-AKM-Suite = 1027075
(3) Framed-MTU = 1400
(3) EAP-Message = 0x026a00061500
(3) State = 0x33754777311f52c5d9592c39c6f43193
(3) Message-Authenticator = 0xc8e04779851766a986a21ceea4790d00
(3) Restoring &session-state
(3) &session-state:Framed-MTU = 994
(3) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(3) authorize {
(3) policy filter_username {
(3) if (&User-Name) {
(3) if (&User-Name) -> TRUE
(3) if (&User-Name) {
(3) if (&User-Name =~ / /) {
(3) if (&User-Name =~ / /) -> FALSE
(3) if (&User-Name =~ /@[^@]*@/ ) {
(3) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(3) if (&User-Name =~ /\.\./ ) {
(3) if (&User-Name =~ /\.\./ ) -> FALSE
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(3) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(3) if (&User-Name =~ /\.$/) {
(3) if (&User-Name =~ /\.$/) -> FALSE
(3) if (&User-Name =~ /(a)\./) {
(3) if (&User-Name =~ /(a)\./) -> FALSE
(3) } # if (&User-Name) = notfound
(3) } # policy filter_username = notfound
(3) [preprocess] = ok
(3) [chap] = noop
(3) [mschap] = noop
(3) [digest] = noop
(3) suffix: Checking for suffix after "@"
(3) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(3) suffix: No such realm "NULL"
(3) [suffix] = noop
(3) eap: Peer sent EAP Response (code 2) ID 106 length 6
(3) eap: Continuing tunnel setup
(3) [eap] = ok
(3) } # authorize = ok
(3) Found Auth-Type = eap
(3) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(3) authenticate {
(3) eap: Expiring EAP session with state 0x33754777311f52c5
(3) eap: Finished EAP session with state 0x33754777311f52c5
(3) eap: Previous EAP request found for state 0x33754777311f52c5, released from the list
(3) eap: Peer sent packet with method EAP TTLS (21)
(3) eap: Calling submodule eap_ttls to process data
(3) eap_ttls: Authenticate
(3) eap_ttls: (TLS) Peer ACKed our handshake fragment
(3) eap: Sending EAP Request (code 1) ID 107 length 1004
(3) eap: EAP session adding &reply:State = 0x33754777301e52c5
(3) [eap] = handled
(3) } # authenticate = handled
(3) Using Post-Auth-Type Challenge
(3) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(3) Challenge { ... } # empty sub-section is ignored
(3) session-state: Saving cached attributes
(3) Framed-MTU = 994
(3) Sent Access-Challenge Id 21 from 10.100.1.65:1812 to 10.100.2.39:54686 length 1068
(3) EAP-Message = 0x016b03ec15c0000011516e31183016060355040a130f42756464796272616e6420476d624831293027060355040b132042756464796272616e6420436572746966696361746520417574686f72697479311b30190603550403131242756464796272616e6420526f6f74204341311f301d06092a864886f70d010901161069744062756464796272616e642e6465301e170d3231303432333131353030305a170d3331303432333131353030305a3081bd310b3009060355040613024445310f300d060355040813064265726c696e310f300d060355040713064265726c696e31183016060355040a130f42756464796272616e6420476d624831293027060355040b132042756464796272616e6420436572746966696361746520417574686f72697479312630240603550403131d42756464796272616e6420496e7465726d656469617465204341203034311f301d06092a864886f70d010901161069744062756464796272616e642e646530820222300d06092a
(3) Message-Authenticator = 0x00000000000000000000000000000000
(3) State = 0x33754777301e52c5d9592c39c6f43193
(3) Finished request
Waking up in 4.8 seconds.
(4) Received Access-Request Id 22 from 10.100.2.39:54686 to 10.100.1.65:1812 length 256
(4) User-Name = "klaus.mustermann"
(4) NAS-IP-Address = 10.100.2.39
(4) NAS-Identifier = "8283c219e7f9"
(4) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(4) NAS-Port-Type = Wireless-802.11
(4) Service-Type = Framed-User
(4) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(4) Connect-Info = "CONNECT 0Mbps 802.11b"
(4) Acct-Session-Id = "690B866461ACEC60"
(4) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(4) Mobility-Domain-Id = 46476
(4) WLAN-Pairwise-Cipher = 1027076
(4) WLAN-Group-Cipher = 1027076
(4) WLAN-AKM-Suite = 1027075
(4) Framed-MTU = 1400
(4) EAP-Message = 0x026b00061500
(4) State = 0x33754777301e52c5d9592c39c6f43193
(4) Message-Authenticator = 0x8ebe69d74f104b81490506fbfd4fcc22
(4) Restoring &session-state
(4) &session-state:Framed-MTU = 994
(4) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(4) authorize {
(4) policy filter_username {
(4) if (&User-Name) {
(4) if (&User-Name) -> TRUE
(4) if (&User-Name) {
(4) if (&User-Name =~ / /) {
(4) if (&User-Name =~ / /) -> FALSE
(4) if (&User-Name =~ /@[^@]*@/ ) {
(4) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(4) if (&User-Name =~ /\.\./ ) {
(4) if (&User-Name =~ /\.\./ ) -> FALSE
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(4) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(4) if (&User-Name =~ /\.$/) {
(4) if (&User-Name =~ /\.$/) -> FALSE
(4) if (&User-Name =~ /(a)\./) {
(4) if (&User-Name =~ /(a)\./) -> FALSE
(4) } # if (&User-Name) = notfound
(4) } # policy filter_username = notfound
(4) [preprocess] = ok
(4) [chap] = noop
(4) [mschap] = noop
(4) [digest] = noop
(4) suffix: Checking for suffix after "@"
(4) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(4) suffix: No such realm "NULL"
(4) [suffix] = noop
(4) eap: Peer sent EAP Response (code 2) ID 107 length 6
(4) eap: Continuing tunnel setup
(4) [eap] = ok
(4) } # authorize = ok
(4) Found Auth-Type = eap
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(4) authenticate {
(4) eap: Expiring EAP session with state 0x33754777301e52c5
(4) eap: Finished EAP session with state 0x33754777301e52c5
(4) eap: Previous EAP request found for state 0x33754777301e52c5, released from the list
(4) eap: Peer sent packet with method EAP TTLS (21)
(4) eap: Calling submodule eap_ttls to process data
(4) eap_ttls: Authenticate
(4) eap_ttls: (TLS) Peer ACKed our handshake fragment
(4) eap: Sending EAP Request (code 1) ID 108 length 1004
(4) eap: EAP session adding &reply:State = 0x33754777371952c5
(4) [eap] = handled
(4) } # authenticate = handled
(4) Using Post-Auth-Type Challenge
(4) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(4) Challenge { ... } # empty sub-section is ignored
(4) session-state: Saving cached attributes
(4) Framed-MTU = 994
(4) Sent Access-Challenge Id 22 from 10.100.1.65:1812 to 10.100.2.39:54686 length 1068
(4) EAP-Message = 0x016c03ec15c00000115155040613024445310f300d060355040813064265726c696e310f300d060355040713064265726c696e31183016060355040a130f42756464796272616e6420476d624831293027060355040b132042756464796272616e6420436572746966696361746520417574686f72697479311b30190603550403131242756464796272616e6420526f6f74204341311f301d06092a864886f70d010901161069744062756464796272616e642e64658209009ce5d9f001129991300e0603551d0f0101ff04040302018630400603551d1f0101ff043630343032a030a02e862c687474703a2f2f63726c2e62756464796272616e642e64653a383038302f726f6f7463615f63726c2e70656d301106096086480186f8420101040403020007301e06096086480186f842010d0411160f786361206365727469666963617465300d06092a864886f70d01010b0500038202010014ba00b7b369be8d469dc9fe7cb4ea2b8b69f5ddf664529e7cfa7e5c23
(4) Message-Authenticator = 0x00000000000000000000000000000000
(4) State = 0x33754777371952c5d9592c39c6f43193
(4) Finished request
Waking up in 4.7 seconds.
(5) Received Access-Request Id 23 from 10.100.2.39:54686 to 10.100.1.65:1812 length 256
(5) User-Name = "klaus.mustermann"
(5) NAS-IP-Address = 10.100.2.39
(5) NAS-Identifier = "8283c219e7f9"
(5) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(5) NAS-Port-Type = Wireless-802.11
(5) Service-Type = Framed-User
(5) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(5) Connect-Info = "CONNECT 0Mbps 802.11b"
(5) Acct-Session-Id = "690B866461ACEC60"
(5) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(5) Mobility-Domain-Id = 46476
(5) WLAN-Pairwise-Cipher = 1027076
(5) WLAN-Group-Cipher = 1027076
(5) WLAN-AKM-Suite = 1027075
(5) Framed-MTU = 1400
(5) EAP-Message = 0x026c00061500
(5) State = 0x33754777371952c5d9592c39c6f43193
(5) Message-Authenticator = 0x2954664567eb90b58df983559fafc7ef
(5) Restoring &session-state
(5) &session-state:Framed-MTU = 994
(5) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(5) authorize {
(5) policy filter_username {
(5) if (&User-Name) {
(5) if (&User-Name) -> TRUE
(5) if (&User-Name) {
(5) if (&User-Name =~ / /) {
(5) if (&User-Name =~ / /) -> FALSE
(5) if (&User-Name =~ /@[^@]*@/ ) {
(5) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(5) if (&User-Name =~ /\.\./ ) {
(5) if (&User-Name =~ /\.\./ ) -> FALSE
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(5) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(5) if (&User-Name =~ /\.$/) {
(5) if (&User-Name =~ /\.$/) -> FALSE
(5) if (&User-Name =~ /(a)\./) {
(5) if (&User-Name =~ /(a)\./) -> FALSE
(5) } # if (&User-Name) = notfound
(5) } # policy filter_username = notfound
(5) [preprocess] = ok
(5) [chap] = noop
(5) [mschap] = noop
(5) [digest] = noop
(5) suffix: Checking for suffix after "@"
(5) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(5) suffix: No such realm "NULL"
(5) [suffix] = noop
(5) eap: Peer sent EAP Response (code 2) ID 108 length 6
(5) eap: Continuing tunnel setup
(5) [eap] = ok
(5) } # authorize = ok
(5) Found Auth-Type = eap
(5) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(5) authenticate {
(5) eap: Expiring EAP session with state 0x33754777371952c5
(5) eap: Finished EAP session with state 0x33754777371952c5
(5) eap: Previous EAP request found for state 0x33754777371952c5, released from the list
(5) eap: Peer sent packet with method EAP TTLS (21)
(5) eap: Calling submodule eap_ttls to process data
(5) eap_ttls: Authenticate
(5) eap_ttls: (TLS) Peer ACKed our handshake fragment
(5) eap: Sending EAP Request (code 1) ID 109 length 467
(5) eap: EAP session adding &reply:State = 0x33754777361852c5
(5) [eap] = handled
(5) } # authenticate = handled
(5) Using Post-Auth-Type Challenge
(5) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(5) Challenge { ... } # empty sub-section is ignored
(5) session-state: Saving cached attributes
(5) Framed-MTU = 994
(5) Sent Access-Challenge Id 23 from 10.100.1.65:1812 to 10.100.2.39:54686 length 527
(5) EAP-Message = 0x016d01d3158000001151c7ae0d9a4018dc0ce7aab22f77890b68228d8c81607a7cd59e58e5b314f938dfe8d81ca660735e53afd3f6eb0939e78859296a954ea1d3046dbcf4333aa72aaad39f3f152ab2b3a2ed59dc1bfdbc773787acbba803d0201cda94c46c440afa65d844464271d2a2dcb7e409ff9c9c30a411ea245b8c2424110ac5191f2c594afe070d15b670dd08c238fd3b672b5bbed9bc7141c3b6e95b61bb78889da5182b33b0883e08339b927b4fd0ef118175f30d3e232be2fc5c92ef1eae2a30a21ba88a0477b8a0a89b903ea37327d4b41dc15ac604f4c057eff9a454748056d6b919f4756ee70de3878196b23441f9252252e5ee8bebe2519a11cb9967ff91ce3d43a9f3e3e39e82277f7bc39200d0e9d8178afdf2b479684b66ee8b2c6b6d258d172684d801780ede278d3c6bbce36875649bc181dcecd10a2ecc83bc920f0b97cf3f2b51a234b69f88e884f5c248fb1062aba73cb402765bf2005825f8379389178cafae7ad9723c0f9e3f63b375c2
(5) Message-Authenticator = 0x00000000000000000000000000000000
(5) State = 0x33754777361852c5d9592c39c6f43193
(5) Finished request
Waking up in 4.7 seconds.
(6) Received Access-Request Id 24 from 10.100.2.39:54686 to 10.100.1.65:1812 length 386
(6) User-Name = "klaus.mustermann"
(6) NAS-IP-Address = 10.100.2.39
(6) NAS-Identifier = "8283c219e7f9"
(6) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(6) NAS-Port-Type = Wireless-802.11
(6) Service-Type = Framed-User
(6) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(6) Connect-Info = "CONNECT 0Mbps 802.11b"
(6) Acct-Session-Id = "690B866461ACEC60"
(6) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(6) Mobility-Domain-Id = 46476
(6) WLAN-Pairwise-Cipher = 1027076
(6) WLAN-Group-Cipher = 1027076
(6) WLAN-AKM-Suite = 1027075
(6) Framed-MTU = 1400
(6) EAP-Message = 0x026d008815800000007e16030300461000004241041bdfa74e961e11ce04aae11e59adff899c7e45c93c23a868913c8e6dbc6b61c8c93027484c43331a120609e34bb63d4a01335611c152662eda522aa015747d24140303000101160303002896671043239b41663014b73a88eb2b056a398cc8c31e8c6f1940273f2cc64b884907fe10b3c697de
(6) State = 0x33754777361852c5d9592c39c6f43193
(6) Message-Authenticator = 0x02f8f3ac8779506b6dc11ac581eb8a01
(6) Restoring &session-state
(6) &session-state:Framed-MTU = 994
(6) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(6) authorize {
(6) policy filter_username {
(6) if (&User-Name) {
(6) if (&User-Name) -> TRUE
(6) if (&User-Name) {
(6) if (&User-Name =~ / /) {
(6) if (&User-Name =~ / /) -> FALSE
(6) if (&User-Name =~ /@[^@]*@/ ) {
(6) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(6) if (&User-Name =~ /\.\./ ) {
(6) if (&User-Name =~ /\.\./ ) -> FALSE
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(6) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(6) if (&User-Name =~ /\.$/) {
(6) if (&User-Name =~ /\.$/) -> FALSE
(6) if (&User-Name =~ /(a)\./) {
(6) if (&User-Name =~ /(a)\./) -> FALSE
(6) } # if (&User-Name) = notfound
(6) } # policy filter_username = notfound
(6) [preprocess] = ok
(6) [chap] = noop
(6) [mschap] = noop
(6) [digest] = noop
(6) suffix: Checking for suffix after "@"
(6) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(6) suffix: No such realm "NULL"
(6) [suffix] = noop
(6) eap: Peer sent EAP Response (code 2) ID 109 length 136
(6) eap: Continuing tunnel setup
(6) [eap] = ok
(6) } # authorize = ok
(6) Found Auth-Type = eap
(6) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(6) authenticate {
(6) eap: Expiring EAP session with state 0x33754777361852c5
(6) eap: Finished EAP session with state 0x33754777361852c5
(6) eap: Previous EAP request found for state 0x33754777361852c5, released from the list
(6) eap: Peer sent packet with method EAP TTLS (21)
(6) eap: Calling submodule eap_ttls to process data
(6) eap_ttls: Authenticate
(6) eap_ttls: (TLS) EAP Peer says that the final record size will be 126 bytes
(6) eap_ttls: (TLS) EAP Got all data (126 bytes)
(6) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS write server done
(6) eap_ttls: (TLS) recv TLS 1.2 Handshake, ClientKeyExchange
(6) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS read client key exchange
(6) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS read change cipher spec
(6) eap_ttls: (TLS) recv TLS 1.2 Handshake, Finished
(6) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS read finished
(6) eap_ttls: (TLS) send TLS 1.2 ChangeCipherSpec
(6) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS write change cipher spec
(6) eap_ttls: (TLS) send TLS 1.2 Handshake, Finished
(6) eap_ttls: (TLS) Handshake state - Server SSLv3/TLS write finished
(6) eap_ttls: (TLS) Handshake state - SSL negotiation finished successfully
(6) eap_ttls: (TLS) Connection Established
(6) eap_ttls: TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(6) eap_ttls: TLS-Session-Version = "TLS 1.2"
(6) eap: Sending EAP Request (code 1) ID 110 length 61
(6) eap: EAP session adding &reply:State = 0x33754777351b52c5
(6) [eap] = handled
(6) } # authenticate = handled
(6) Using Post-Auth-Type Challenge
(6) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(6) Challenge { ... } # empty sub-section is ignored
(6) session-state: Saving cached attributes
(6) Framed-MTU = 994
(6) TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(6) TLS-Session-Version = "TLS 1.2"
(6) Sent Access-Challenge Id 24 from 10.100.1.65:1812 to 10.100.2.39:54686 length 119
(6) EAP-Message = 0x016e003d1580000000331403030001011603030028c5e315035630988a3b83c13d63026f7f68b51fc4cae498e85bec63a7b3beba6177951acbd7c9e48e
(6) Message-Authenticator = 0x00000000000000000000000000000000
(6) State = 0x33754777351b52c5d9592c39c6f43193
(6) Finished request
Waking up in 4.7 seconds.
(7) Received Access-Request Id 25 from 10.100.2.39:54686 to 10.100.1.65:1812 length 321
(7) User-Name = "klaus.mustermann"
(7) NAS-IP-Address = 10.100.2.39
(7) NAS-Identifier = "8283c219e7f9"
(7) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(7) NAS-Port-Type = Wireless-802.11
(7) Service-Type = Framed-User
(7) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(7) Connect-Info = "CONNECT 0Mbps 802.11b"
(7) Acct-Session-Id = "690B866461ACEC60"
(7) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(7) Mobility-Domain-Id = 46476
(7) WLAN-Pairwise-Cipher = 1027076
(7) WLAN-Group-Cipher = 1027076
(7) WLAN-AKM-Suite = 1027075
(7) Framed-MTU = 1400
(7) EAP-Message = 0x026e004715800000003d170303003896671043239b4167e00afbeca8b555b120c23769698d81a6b5a879ecc3c8fd3cd740dc135bdef5fcadd7fda6a166609e4d7957502348d9f3
(7) State = 0x33754777351b52c5d9592c39c6f43193
(7) Message-Authenticator = 0xa8b841519028def71e27cfef249be756
(7) Restoring &session-state
(7) &session-state:Framed-MTU = 994
(7) &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(7) &session-state:TLS-Session-Version = "TLS 1.2"
(7) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(7) authorize {
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = notfound
(7) } # policy filter_username = notfound
(7) [preprocess] = ok
(7) [chap] = noop
(7) [mschap] = noop
(7) [digest] = noop
(7) suffix: Checking for suffix after "@"
(7) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(7) suffix: No such realm "NULL"
(7) [suffix] = noop
(7) eap: Peer sent EAP Response (code 2) ID 110 length 71
(7) eap: Continuing tunnel setup
(7) [eap] = ok
(7) } # authorize = ok
(7) Found Auth-Type = eap
(7) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(7) authenticate {
(7) eap: Expiring EAP session with state 0x33754777351b52c5
(7) eap: Finished EAP session with state 0x33754777351b52c5
(7) eap: Previous EAP request found for state 0x33754777351b52c5, released from the list
(7) eap: Peer sent packet with method EAP TTLS (21)
(7) eap: Calling submodule eap_ttls to process data
(7) eap_ttls: Authenticate
(7) eap_ttls: (TLS) EAP Peer says that the final record size will be 61 bytes
(7) eap_ttls: (TLS) EAP Got all data (61 bytes)
(7) eap_ttls: Session established. Proceeding to decode tunneled attributes
(7) eap_ttls: Got tunneled request
(7) eap_ttls: EAP-Message = 0x02000015016b6c6175732e6d75737465726d616e6e
(7) eap_ttls: FreeRADIUS-Proxied-To = 127.0.0.1
(7) eap_ttls: Got tunneled identity of klaus.mustermann
(7) eap_ttls: Setting default EAP type for tunneled EAP session
(7) eap_ttls: Sending tunneled request
(7) Virtual server inner-tunnel received request
(7) EAP-Message = 0x02000015016b6c6175732e6d75737465726d616e6e
(7) FreeRADIUS-Proxied-To = 127.0.0.1
(7) User-Name = "klaus.mustermann"
(7) WARNING: Outer and inner identities are the same. User privacy is compromised.
(7) server inner-tunnel {
(7) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(7) authorize {
(7) policy filter_username {
(7) if (&User-Name) {
(7) if (&User-Name) -> TRUE
(7) if (&User-Name) {
(7) if (&User-Name =~ / /) {
(7) if (&User-Name =~ / /) -> FALSE
(7) if (&User-Name =~ /@[^@]*@/ ) {
(7) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(7) if (&User-Name =~ /\.\./ ) {
(7) if (&User-Name =~ /\.\./ ) -> FALSE
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(7) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(7) if (&User-Name =~ /\.$/) {
(7) if (&User-Name =~ /\.$/) -> FALSE
(7) if (&User-Name =~ /(a)\./) {
(7) if (&User-Name =~ /(a)\./) -> FALSE
(7) } # if (&User-Name) = notfound
(7) } # policy filter_username = notfound
(7) [chap] = noop
(7) [mschap] = noop
(7) suffix: Checking for suffix after "@"
(7) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(7) suffix: No such realm "NULL"
(7) [suffix] = noop
(7) update control {
(7) &Proxy-To-Realm := LOCAL
(7) } # update control = noop
(7) eap: Peer sent EAP Response (code 2) ID 0 length 21
(7) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize
(7) [eap] = ok
(7) } # authorize = ok
(7) Found Auth-Type = eap
(7) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(7) authenticate {
(7) eap: Peer sent packet with method EAP Identity (1)
(7) eap: Calling submodule eap_gtc to process data
(7) eap_gtc: EXPAND Password:
(7) eap_gtc: --> Password:
(7) eap: Sending EAP Request (code 1) ID 1 length 15
(7) eap: EAP session adding &reply:State = 0xb4a2b867b4a3bebf
(7) [eap] = handled
(7) } # authenticate = handled
(7) } # server inner-tunnel
(7) Virtual server sending reply
(7) EAP-Message = 0x0101000f0650617373776f72643a20
(7) Message-Authenticator = 0x00000000000000000000000000000000
(7) State = 0xb4a2b867b4a3bebfd5edaac839855c28
(7) eap_ttls: Got tunneled Access-Challenge
(7) eap: Sending EAP Request (code 1) ID 111 length 63
(7) eap: EAP session adding &reply:State = 0x33754777341a52c5
(7) [eap] = handled
(7) } # authenticate = handled
(7) Using Post-Auth-Type Challenge
(7) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(7) Challenge { ... } # empty sub-section is ignored
(7) session-state: Saving cached attributes
(7) Framed-MTU = 994
(7) TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(7) TLS-Session-Version = "TLS 1.2"
(7) Sent Access-Challenge Id 25 from 10.100.1.65:1812 to 10.100.2.39:54686 length 121
(7) EAP-Message = 0x016f003f1580000000351703030030c5e315035630988b4ad830befda4dba2a51fa8f9388f8da63a7ea11b76e432bbb988ecf99f49e2ebe5cd501621aec81b
(7) Message-Authenticator = 0x00000000000000000000000000000000
(7) State = 0x33754777341a52c5d9592c39c6f43193
(7) Finished request
Waking up in 4.6 seconds.
(8) Received Access-Request Id 26 from 10.100.2.39:54686 to 10.100.1.65:1812 length 317
(8) User-Name = "klaus.mustermann"
(8) NAS-IP-Address = 10.100.2.39
(8) NAS-Identifier = "8283c219e7f9"
(8) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(8) NAS-Port-Type = Wireless-802.11
(8) Service-Type = Framed-User
(8) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(8) Connect-Info = "CONNECT 0Mbps 802.11b"
(8) Acct-Session-Id = "690B866461ACEC60"
(8) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(8) Mobility-Domain-Id = 46476
(8) WLAN-Pairwise-Cipher = 1027076
(8) WLAN-Group-Cipher = 1027076
(8) WLAN-AKM-Suite = 1027075
(8) Framed-MTU = 1400
(8) EAP-Message = 0x026f0043158000000039170303003496671043239b41683128359379c1a6a7ff944f84eb0b3f626e65ecb31042ebf597e0b5314226e2bcea13a41d6e380c98153d5dd7
(8) State = 0x33754777341a52c5d9592c39c6f43193
(8) Message-Authenticator = 0xe468605d47fb0bba1b52f632f0e1589a
(8) Restoring &session-state
(8) &session-state:Framed-MTU = 994
(8) &session-state:TLS-Session-Cipher-Suite = "ECDHE-RSA-AES256-GCM-SHA384"
(8) &session-state:TLS-Session-Version = "TLS 1.2"
(8) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(8) authorize {
(8) policy filter_username {
(8) if (&User-Name) {
(8) if (&User-Name) -> TRUE
(8) if (&User-Name) {
(8) if (&User-Name =~ / /) {
(8) if (&User-Name =~ / /) -> FALSE
(8) if (&User-Name =~ /@[^@]*@/ ) {
(8) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(8) if (&User-Name =~ /\.\./ ) {
(8) if (&User-Name =~ /\.\./ ) -> FALSE
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(8) if (&User-Name =~ /\.$/) {
(8) if (&User-Name =~ /\.$/) -> FALSE
(8) if (&User-Name =~ /(a)\./) {
(8) if (&User-Name =~ /(a)\./) -> FALSE
(8) } # if (&User-Name) = notfound
(8) } # policy filter_username = notfound
(8) [preprocess] = ok
(8) [chap] = noop
(8) [mschap] = noop
(8) [digest] = noop
(8) suffix: Checking for suffix after "@"
(8) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(8) suffix: No such realm "NULL"
(8) [suffix] = noop
(8) eap: Peer sent EAP Response (code 2) ID 111 length 67
(8) eap: Continuing tunnel setup
(8) [eap] = ok
(8) } # authorize = ok
(8) Found Auth-Type = eap
(8) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(8) authenticate {
(8) eap: Expiring EAP session with state 0xb4a2b867b4a3bebf
(8) eap: Finished EAP session with state 0x33754777341a52c5
(8) eap: Previous EAP request found for state 0x33754777341a52c5, released from the list
(8) eap: Peer sent packet with method EAP TTLS (21)
(8) eap: Calling submodule eap_ttls to process data
(8) eap_ttls: Authenticate
(8) eap_ttls: (TLS) EAP Peer says that the final record size will be 57 bytes
(8) eap_ttls: (TLS) EAP Got all data (57 bytes)
(8) eap_ttls: Session established. Proceeding to decode tunneled attributes
(8) eap_ttls: Got tunneled request
(8) eap_ttls: EAP-Message = 0x0201001306736167616e382e53697a61626c65
(8) eap_ttls: FreeRADIUS-Proxied-To = 127.0.0.1
(8) eap_ttls: Sending tunneled request
(8) Virtual server inner-tunnel received request
(8) EAP-Message = 0x0201001306736167616e382e53697a61626c65
(8) FreeRADIUS-Proxied-To = 127.0.0.1
(8) User-Name = "klaus.mustermann"
(8) State = 0xb4a2b867b4a3bebfd5edaac839855c28
(8) WARNING: Outer and inner identities are the same. User privacy is compromised.
(8) server inner-tunnel {
(8) session-state: No cached attributes
(8) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(8) authorize {
(8) policy filter_username {
(8) if (&User-Name) {
(8) if (&User-Name) -> TRUE
(8) if (&User-Name) {
(8) if (&User-Name =~ / /) {
(8) if (&User-Name =~ / /) -> FALSE
(8) if (&User-Name =~ /@[^@]*@/ ) {
(8) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(8) if (&User-Name =~ /\.\./ ) {
(8) if (&User-Name =~ /\.\./ ) -> FALSE
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(8) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(8) if (&User-Name =~ /\.$/) {
(8) if (&User-Name =~ /\.$/) -> FALSE
(8) if (&User-Name =~ /(a)\./) {
(8) if (&User-Name =~ /(a)\./) -> FALSE
(8) } # if (&User-Name) = notfound
(8) } # policy filter_username = notfound
(8) [chap] = noop
(8) [mschap] = noop
(8) suffix: Checking for suffix after "@"
(8) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(8) suffix: No such realm "NULL"
(8) [suffix] = noop
(8) update control {
(8) &Proxy-To-Realm := LOCAL
(8) } # update control = noop
(8) eap: Peer sent EAP Response (code 2) ID 1 length 19
(8) eap: No EAP Start, assuming it's an on-going EAP conversation
(8) [eap] = updated
(8) [files] = noop
rlm_ldap (ldap): Reserved connection (0)
(8) ldap: EXPAND (uid=%{%{Stripped-User-Name}:-%{User-Name}})
(8) ldap: --> (uid=klaus.mustermann)
(8) ldap: Performing search in "dc=pretendco,dc=de" with filter "(uid=klaus.mustermann)", scope "sub"
(8) ldap: Waiting for search result...
(8) ldap: User object found at DN "uid=klaus.mustermann,ou=Standard Mitarbeiter,ou=Mitarbeiter,ou=Users,dc=pretendco,dc=de"
(8) ldap: Processing user attributes
(8) ldap: WARNING: No "known good" password added. Ensure the admin user has permission to read the password attribute
(8) ldap: WARNING: PAP authentication will *NOT* work with Active Directory (if that is what you were trying to configure)
rlm_ldap (ldap): Released connection (0)
Need more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (5), 1 of 27 pending slots used
rlm_ldap (ldap): Connecting to ldaps://ldap.google.com:636
rlm_ldap (ldap): Waiting for bind result...
ber_get_next failed, errno=11.
rlm_ldap (ldap): Bind successful
(8) [ldap] = ok
(8) [expiration] = noop
(8) [logintime] = noop
(8) [pap] = noop
(8) if (User-Password) {
(8) if (User-Password) -> FALSE
(8) } # authorize = updated
(8) Found Auth-Type = eap
(8) # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(8) authenticate {
(8) eap: Expiring EAP session with state 0xb4a2b867b4a3bebf
(8) eap: Finished EAP session with state 0xb4a2b867b4a3bebf
(8) eap: Previous EAP request found for state 0xb4a2b867b4a3bebf, released from the list
(8) eap: Peer sent packet with method EAP GTC (6)
(8) eap: Calling submodule eap_gtc to process data
(8) eap_gtc: # Executing group from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(8) eap_gtc: Auth-Type PAP {
rlm_ldap (ldap): Reserved connection (1)
(8) ldap: Login attempt by "klaus.mustermann"
(8) ldap: Using user DN from request "uid=klaus.mustermann,ou=Standard Mitarbeiter,ou=Mitarbeiter,ou=Users,dc=pretendco,dc=de"
(8) ldap: Waiting for bind result...
(8) ldap: Bind successful
(8) ldap: Bind as user "uid=klaus.mustermann,ou=Standard Mitarbeiter,ou=Mitarbeiter,ou=Users,dc=pretendco,dc=de" was successful
rlm_ldap (ldap): Released connection (1)
Need more connections to reach 10 spares
rlm_ldap (ldap): Opening additional connection (6), 1 of 26 pending slots used
rlm_ldap (ldap): Connecting to ldaps://ldap.google.com:636
rlm_ldap (ldap): Waiting for bind result...
ber_get_next failed, errno=11.
rlm_ldap (ldap): Bind successful
(8) eap_gtc: [ldap] = ok
(8) eap_gtc: } # Auth-Type PAP = ok
(8) eap: Sending EAP Success (code 3) ID 1 length 4
(8) eap: Freeing handler
(8) [eap] = ok
(8) } # authenticate = ok
(8) # Executing section post-auth from file /etc/freeradius/3.0/sites-enabled/inner-tunnel
(8) post-auth {
(8) if (0) {
(8) if (0) -> FALSE
(8) } # post-auth = noop
(8) } # server inner-tunnel
(8) Virtual server sending reply
(8) EAP-Message = 0x03010004
(8) Message-Authenticator = 0x00000000000000000000000000000000
(8) User-Name = "klaus.mustermann"
(8) eap_ttls: Got tunneled Access-Accept
(8) eap: Sending EAP Success (code 3) ID 111 length 4
(8) eap: Freeing handler
(8) [eap] = ok
(8) } # authenticate = ok
(8) # Executing section post-auth from file /etc/freeradius/3.0/sites-enabled/default
(8) post-auth {
(8) if (session-state:User-Name && reply:User-Name && request:User-Name && (reply:User-Name == request:User-Name)) {
(8) if (session-state:User-Name && reply:User-Name && request:User-Name && (reply:User-Name == request:User-Name)) -> FALSE
(8) update {
(8) &reply::Framed-MTU += &session-state:Framed-MTU[*] -> 994
(8) &reply::TLS-Session-Cipher-Suite += &session-state:TLS-Session-Cipher-Suite[*] -> 'ECDHE-RSA-AES256-GCM-SHA384'
(8) &reply::TLS-Session-Version += &session-state:TLS-Session-Version[*] -> 'TLS 1.2'
(8) } # update = noop
(8) [exec] = noop
(8) policy remove_reply_message_if_eap {
(8) if (&reply:EAP-Message && &reply:Reply-Message) {
(8) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(8) else {
(8) [noop] = noop
(8) } # else = noop
(8) } # policy remove_reply_message_if_eap = noop
(8) } # post-auth = noop
(8) Sent Access-Accept Id 26 from 10.100.1.65:1812 to 10.100.2.39:54686 length 184
(8) MS-MPPE-Recv-Key = 0xeb472d316fdc874c9b4fab09804dffb9627d034a793910ca0f276473f2db3e62
(8) MS-MPPE-Send-Key = 0x3cde6513ea1f92c64ee3d938a85980091ecccdeb288c640f958a8f0d4324af64
(8) EAP-Message = 0x036f0004
(8) Message-Authenticator = 0x00000000000000000000000000000000
(8) User-Name = "klaus.mustermann"
(8) Framed-MTU += 994
(8) Finished request
Waking up in 1.1 seconds.
(9) Received Access-Request Id 26 from 10.100.2.39:38737 to 10.100.1.65:1812 length 317
(9) User-Name = "klaus.mustermann"
(9) NAS-IP-Address = 10.100.2.39
(9) NAS-Identifier = "8283c219e7f9"
(9) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(9) NAS-Port-Type = Wireless-802.11
(9) Service-Type = Framed-User
(9) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(9) Connect-Info = "CONNECT 0Mbps 802.11b"
(9) Acct-Session-Id = "690B866461ACEC60"
(9) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(9) Mobility-Domain-Id = 46476
(9) WLAN-Pairwise-Cipher = 1027076
(9) WLAN-Group-Cipher = 1027076
(9) WLAN-AKM-Suite = 1027075
(9) Framed-MTU = 1400
(9) EAP-Message = 0x026f0043158000000039170303003496671043239b41683128359379c1a6a7ff944f84eb0b3f626e65ecb31042ebf597e0b5314226e2bcea13a41d6e380c98153d5dd7
(9) State = 0x33754777341a52c5d9592c39c6f43193
(9) Message-Authenticator = 0xe468605d47fb0bba1b52f632f0e1589a
(9) session-state: No cached attributes
(9) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(9) authorize {
(9) policy filter_username {
(9) if (&User-Name) {
(9) if (&User-Name) -> TRUE
(9) if (&User-Name) {
(9) if (&User-Name =~ / /) {
(9) if (&User-Name =~ / /) -> FALSE
(9) if (&User-Name =~ /@[^@]*@/ ) {
(9) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(9) if (&User-Name =~ /\.\./ ) {
(9) if (&User-Name =~ /\.\./ ) -> FALSE
(9) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(9) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(9) if (&User-Name =~ /\.$/) {
(9) if (&User-Name =~ /\.$/) -> FALSE
(9) if (&User-Name =~ /(a)\./) {
(9) if (&User-Name =~ /(a)\./) -> FALSE
(9) } # if (&User-Name) = notfound
(9) } # policy filter_username = notfound
(9) [preprocess] = ok
(9) [chap] = noop
(9) [mschap] = noop
(9) [digest] = noop
(9) suffix: Checking for suffix after "@"
(9) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(9) suffix: No such realm "NULL"
(9) [suffix] = noop
(9) eap: Peer sent EAP Response (code 2) ID 111 length 67
(9) eap: Continuing tunnel setup
(9) [eap] = ok
(9) } # authorize = ok
(9) Found Auth-Type = eap
(9) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(9) authenticate {
(9) eap: ERROR: rlm_eap (EAP): No EAP session matching state 0x33754777341a52c5
(9) eap: Either EAP-request timed out OR EAP-response to an unknown EAP-request
(9) eap: Failed in handler
(9) [eap] = invalid
(9) } # authenticate = invalid
(9) Failed to authenticate the user
(9) Using Post-Auth-Type Reject
(9) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(9) Post-Auth-Type REJECT {
(9) attr_filter.access_reject: EXPAND %{User-Name}
(9) attr_filter.access_reject: --> klaus.mustermann
(9) attr_filter.access_reject: Matched entry DEFAULT at line 11
(9) [attr_filter.access_reject] = updated
(9) eap: ERROR: rlm_eap (EAP): No EAP session matching state 0x33754777341a52c5
(9) eap: Either EAP-request timed out OR EAP-response to an unknown EAP-request
(9) eap: Failed to get handler, probably already removed, not inserting EAP-Failure
(9) [eap] = noop
(9) policy remove_reply_message_if_eap {
(9) if (&reply:EAP-Message && &reply:Reply-Message) {
(9) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(9) else {
(9) [noop] = noop
(9) } # else = noop
(9) } # policy remove_reply_message_if_eap = noop
(9) } # Post-Auth-Type REJECT = updated
(9) Delaying response for 1.000000 seconds
Waking up in 0.3 seconds.
Waking up in 0.6 seconds.
(10) Received Access-Request Id 26 from 10.100.2.39:45497 to 10.100.1.65:1812 length 317
(10) User-Name = "klaus.mustermann"
(10) NAS-IP-Address = 10.100.2.39
(10) NAS-Identifier = "8283c219e7f9"
(10) Called-Station-Id = "82-83-C2-19-E7-F9:pretendco_int"
(10) NAS-Port-Type = Wireless-802.11
(10) Service-Type = Framed-User
(10) Calling-Station-Id = "F8-4D-89-6D-CB-AE"
(10) Connect-Info = "CONNECT 0Mbps 802.11b"
(10) Acct-Session-Id = "690B866461ACEC60"
(10) Acct-Multi-Session-Id = "3EA4011978DCDC0A"
(10) Mobility-Domain-Id = 46476
(10) WLAN-Pairwise-Cipher = 1027076
(10) WLAN-Group-Cipher = 1027076
(10) WLAN-AKM-Suite = 1027075
(10) Framed-MTU = 1400
(10) EAP-Message = 0x026f0043158000000039170303003496671043239b41683128359379c1a6a7ff944f84eb0b3f626e65ecb31042ebf597e0b5314226e2bcea13a41d6e380c98153d5dd7
(10) State = 0x33754777341a52c5d9592c39c6f43193
(10) Message-Authenticator = 0xe468605d47fb0bba1b52f632f0e1589a
(10) session-state: No cached attributes
(10) # Executing section authorize from file /etc/freeradius/3.0/sites-enabled/default
(10) authorize {
(10) policy filter_username {
(10) if (&User-Name) {
(10) if (&User-Name) -> TRUE
(10) if (&User-Name) {
(10) if (&User-Name =~ / /) {
(10) if (&User-Name =~ / /) -> FALSE
(10) if (&User-Name =~ /@[^@]*@/ ) {
(10) if (&User-Name =~ /@[^@]*@/ ) -> FALSE
(10) if (&User-Name =~ /\.\./ ) {
(10) if (&User-Name =~ /\.\./ ) -> FALSE
(10) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) {
(10) if ((&User-Name =~ /@/) && (&User-Name !~ /(a)(.+)\.(.+)$/)) -> FALSE
(10) if (&User-Name =~ /\.$/) {
(10) if (&User-Name =~ /\.$/) -> FALSE
(10) if (&User-Name =~ /(a)\./) {
(10) if (&User-Name =~ /(a)\./) -> FALSE
(10) } # if (&User-Name) = notfound
(10) } # policy filter_username = notfound
(10) [preprocess] = ok
(10) [chap] = noop
(10) [mschap] = noop
(10) [digest] = noop
(10) suffix: Checking for suffix after "@"
(10) suffix: No '@' in User-Name = "klaus.mustermann", looking up realm NULL
(10) suffix: No such realm "NULL"
(10) [suffix] = noop
(10) eap: Peer sent EAP Response (code 2) ID 111 length 67
(10) eap: Continuing tunnel setup
(10) [eap] = ok
(10) } # authorize = ok
(10) Found Auth-Type = eap
(10) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(10) authenticate {
(10) eap: ERROR: rlm_eap (EAP): No EAP session matching state 0x33754777341a52c5
(10) eap: Either EAP-request timed out OR EAP-response to an unknown EAP-request
(10) eap: Failed in handler
(10) [eap] = invalid
(10) } # authenticate = invalid
(10) Failed to authenticate the user
(10) Using Post-Auth-Type Reject
(10) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(10) Post-Auth-Type REJECT {
(10) attr_filter.access_reject: EXPAND %{User-Name}
(10) attr_filter.access_reject: --> klaus.mustermann
(10) attr_filter.access_reject: Matched entry DEFAULT at line 11
(10) [attr_filter.access_reject] = updated
(10) eap: ERROR: rlm_eap (EAP): No EAP session matching state 0x33754777341a52c5
(10) eap: Either EAP-request timed out OR EAP-response to an unknown EAP-request
(10) eap: Failed to get handler, probably already removed, not inserting EAP-Failure
(10) [eap] = noop
(10) policy remove_reply_message_if_eap {
(10) if (&reply:EAP-Message && &reply:Reply-Message) {
(10) if (&reply:EAP-Message && &reply:Reply-Message) -> FALSE
(10) else {
(10) [noop] = noop
(10) } # else = noop
(10) } # policy remove_reply_message_if_eap = noop
(10) } # Post-Auth-Type REJECT = updated
(10) Delaying response for 1.000000 seconds
Waking up in 0.3 seconds.
Waking up in 0.2 seconds.
(9) Sending delayed response
(9) Sent Access-Reject Id 26 from 10.100.1.65:1812 to 10.100.2.39:38737 length 20
Waking up in 0.1 seconds.
(0) Cleaning up request packet ID 18 with timestamp +35 due to cleanup_delay was reached
Waking up in 0.1 seconds.
(1) Cleaning up request packet ID 19 with timestamp +35 due to cleanup_delay was reached
(2) Cleaning up request packet ID 20 with timestamp +35 due to cleanup_delay was reached
(3) Cleaning up request packet ID 21 with timestamp +35 due to cleanup_delay was reached
(4) Cleaning up request packet ID 22 with timestamp +35 due to cleanup_delay was reached
(5) Cleaning up request packet ID 23 with timestamp +35 due to cleanup_delay was reached
(6) Cleaning up request packet ID 24 with timestamp +35 due to cleanup_delay was reached
(7) Cleaning up request packet ID 25 with timestamp +35 due to cleanup_delay was reached
(10) Sending delayed response
(10) Sent Access-Reject Id 26 from 10.100.1.65:1812 to 10.100.2.39:45497 length 20
Any Idea what I am doing wrong here?
Regards
Henning
3
4
2
1