Everything lookslike it works, but PC is not authentified

Alexandros Gougousoudis gougousoudis at kh-berlin.de
Mon Sep 4 11:55:54 CEST 2006


I'am a step ahead. One problem was, that the Root-CA-cert must be put 
manually in the Trusted-Rootcertificate place (I use a german Windows, 
so I try to retranslate that into english) on the Windows-Client. It is 
not enough to import that automatically, although the cert shows up in 
the list of "Trusted Rootcertificates" in the "Authentification" menu of 
the network-settings. If made this running the mmc manually, opening the 

But it shows, that the problem is deeper. The netbiosname of the windows 
machine is "vinfo-t1", also the cert has this name as a CN. If the PC 
tries to authenticate the username comes as "host/vinfo-t1" to the 
radius server. Which makes the TLS verify fail. How can the name be 

My setup is like mentioned in this HowTo:


Here an Debug Output of the conversation:

rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         EAP-Message = 0x0201001201686f73742f76696e666f2d7431
         Message-Authenticator = 0xe009fb46107ee76bfc27e1f91b7e73f6
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 0
   modcall[authorize]: module "preprocess" returns ok for request 0
   rlm_eap: EAP packet type response id 1 length 18
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 0
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 0
modcall: leaving group authorize (returns updated) for request 0
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 0
   rlm_eap: EAP Identity
   rlm_eap: processing type tls
  rlm_eap_tls: Requiring client certificate
   rlm_eap_tls: Initiate
   rlm_eap_tls: Start returned 1
   modcall[authenticate]: module "eap" returns handled for request 0
modcall: leaving group authenticate (returns handled) for request 0
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x010200060d20
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x1eb9189838f31fb0cf1d343419acb2c0
Finished request 0
Going to the next request
--- Walking the entire request list ---
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x1eb9189838f31fb0cf1d343419acb2c0
         EAP-Message = 
         Message-Authenticator = 0x5acdcdfd4719f93fd54efbec8632096f
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 1
   modcall[authorize]: module "preprocess" returns ok for request 1
   rlm_eap: EAP packet type response id 2 length 80
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 1
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 1
modcall: leaving group authorize (returns updated) for request 1
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 1
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls:  Length Included
   eaptls_verify returned 11
     (other): before/accept initialization
     TLS_accept: before/accept initialization
   rlm_eap_tls: <<< TLS 1.0 Handshake [length 0041], ClientHello
     TLS_accept: SSLv3 read client hello A
   rlm_eap_tls: >>> TLS 1.0 Handshake [length 004a], ServerHello
     TLS_accept: SSLv3 write server hello A
   rlm_eap_tls: >>> TLS 1.0 Handshake [length 0ef8], Certificate
     TLS_accept: SSLv3 write certificate A
   rlm_eap_tls: >>> TLS 1.0 Handshake [length 00bd], CertificateRequest
     TLS_accept: SSLv3 write certificate request A
     TLS_accept: SSLv3 flush data
     TLS_accept:error in SSLv3 read client certificate A
In SSL Handshake Phase
In SSL Accept mode
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 1
modcall: leaving group authenticate (returns handled) for request 1
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 0xad529359b0a55e5bffa9cf65b3034d48c263c491b24a
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x62ac8299666f9397864e61d8e04a1f3e
Finished request 1
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x62ac8299666f9397864e61d8e04a1f3e
         EAP-Message = 0x020300060d00
         Message-Authenticator = 0x2d9b3872003fc09e22bb4d9f6056991a
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 2
   modcall[authorize]: module "preprocess" returns ok for request 2
   rlm_eap: EAP packet type response id 3 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 2
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 2
modcall: leaving group authorize (returns updated) for request 2
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 2
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack handshake fragment handler
   eaptls_verify returned 1
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 2
modcall: leaving group authenticate (returns handled) for request 2
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 0x020102020900890d6f61ac0ce005300d06092a864886
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0xd16ad97d1f76b6e6878fff568b2c4c2e
Finished request 2
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0xd16ad97d1f76b6e6878fff568b2c4c2e
         EAP-Message = 0x020400060d00
         Message-Authenticator = 0xd3cac87903c299148d8aee901bb87d85
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 3
   modcall[authorize]: module "preprocess" returns ok for request 3
   rlm_eap: EAP packet type response id 4 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 3
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 3
modcall: leaving group authorize (returns updated) for request 3
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 3
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack handshake fragment handler
   eaptls_verify returned 1
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 3
modcall: leaving group authenticate (returns handled) for request 3
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 0x18b1f4d8303d042ea181b0a481ad3081aa310b300906
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0xba5a2b49ec81141bc1deb21c9792c137
Finished request 3
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0xba5a2b49ec81141bc1deb21c9792c137
         EAP-Message = 0x020500060d00
         Message-Authenticator = 0xf7f1738e59b02e648c5cce4946e9df9c
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 4
   modcall[authorize]: module "preprocess" returns ok for request 4
   rlm_eap: EAP packet type response id 5 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 4
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 4
modcall: leaving group authorize (returns updated) for request 4
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 4
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack handshake fragment handler
   eaptls_verify returned 1
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 4
modcall: leaving group authenticate (returns handled) for request 4
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 0x1f06092a864886f70d010901161273632d6974406b68
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0xf231b7f39c1572d02d39ff49f54d210e
Finished request 4
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0xf231b7f39c1572d02d39ff49f54d210e
         EAP-Message = 0x020600060d00
         Message-Authenticator = 0x6ed026eb8c4fb95b5977cf6883d7f3ff
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 5
   modcall[authorize]: module "preprocess" returns ok for request 5
   rlm_eap: EAP packet type response id 6 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 5
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 5
modcall: leaving group authorize (returns updated) for request 5
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 5
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack handshake fragment handler
   eaptls_verify returned 1
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 5
modcall: leaving group authenticate (returns handled) for request 5
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x010700180d800000100e2d6265726c696e2e64650e000000
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x3c5f8b0008d1f3af6b3943916a23e2ff
Finished request 5
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x3c5f8b0008d1f3af6b3943916a23e2ff
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         Message-Authenticator = 0x74fd373b468d81483b5c29000421eea7
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 6
   modcall[authorize]: module "preprocess" returns ok for request 6
   rlm_eap: EAP packet type response id 7 length 253
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 6
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 6
modcall: leaving group authorize (returns updated) for request 6
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 6
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls:  Received EAP-TLS First Fragment of the message
   eaptls_verify returned 9
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 6
modcall: leaving group authenticate (returns handled) for request 6
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x010800060d00
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x359ee7405de06aa7a6b8c2e7169a6014
Finished request 6
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x359ee7405de06aa7a6b8c2e7169a6014
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         Message-Authenticator = 0x5d5a7d2d57f2a52f1f13358c8966b470
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 7
   modcall[authorize]: module "preprocess" returns ok for request 7
   rlm_eap: EAP packet type response id 8 length 253
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 7
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 7
modcall: leaving group authorize (returns updated) for request 7
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 7
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls:  More fragments to follow
   eaptls_verify returned 10
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 7
modcall: leaving group authenticate (returns handled) for request 7
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x010900060d00
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0xa9ec0e19c31f5fe70aedb7f7d0e88a2f
Finished request 7
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0xa9ec0e19c31f5fe70aedb7f7d0e88a2f
         EAP-Message = 
         Message-Authenticator = 0x696632f38a12e60fab75e2c8e5bc62ff
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 8
   modcall[authorize]: module "preprocess" returns ok for request 8
   rlm_eap: EAP packet type response id 9 length 53
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 8
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 8
modcall: leaving group authorize (returns updated) for request 8
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 8
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
   eaptls_verify returned 7
   rlm_eap_tls: Done initial handshake
   rlm_eap_tls: <<< TLS 1.0 Handshake [length 0787], Certificate
--> User-Name = host/vinfo-t1
--> BUF-Name = ServiceCenter-IT_KHB_HfM_HfS
--> subject = /C=DE/ST=Berlin/L=Berlin/O=KHB HfM 
HfS/OU=ServiceCenter-IT/CN=ServiceCenter-IT_KHB_HfM_HfS/emailAddress=sc-it at kh-berlin.de
--> issuer  = /C=DE/ST=Berlin/L=Berlin/O=KHB HfM 
HfS/OU=ServiceCenter-IT/CN=ServiceCenter-IT_KHB_HfM_HfS/emailAddress=sc-it at kh-berlin.de
--> verify return:1
--> verify error:num=9:certificate is not yet valid
   rlm_eap_tls: >>> TLS 1.0 Alert [length 0002], fatal bad_certificate
TLS Alert write:fatal:bad certificate
     TLS_accept:error in SSLv3 read client certificate B
9054:error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no 
certificate returned:s3_srvr.c:2482:
rlm_eap_tls: SSL_read failed in a system call (-1), TLS session fails.
In SSL Handshake Phase
In SSL Accept mode
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 8
modcall: leaving group authenticate (returns handled) for request 8
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x010a00110d80000000071503010002022a
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x2234f2a04eac43d7190c2eb599db66dc
Finished request 8
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x2234f2a04eac43d7190c2eb599db66dc
         EAP-Message = 0x020a00060d00
         Message-Authenticator = 0x58ed75061e4f8f0db896ce17b4ec179b
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 9
   modcall[authorize]: module "preprocess" returns ok for request 9
   rlm_eap: EAP packet type response id 10 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 9
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 9
modcall: leaving group authorize (returns updated) for request 9
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 9
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack alert
   eaptls_verify returned 4
   eaptls_process returned 4
  rlm_eap: Handler failed in EAP/tls
   rlm_eap: Failed in EAP select
   modcall[authenticate]: module "eap" returns invalid for request 9
modcall: leaving group authenticate (returns invalid) for request 9
auth: Failed to validate the user.
Delaying request 9 for 1 seconds
Finished request 9
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
Sending Access-Reject of id 0 to port 49154
         EAP-Message = 0x040a0004
         Message-Authenticator = 0x00000000000000000000000000000000
--- Walking the entire request list ---
Waking up in 4 seconds...
--- Walking the entire request list ---
Cleaning up request 9 ID 0 with timestamp 44cdf6a1
Nothing to do.  Sleeping until we see a request.
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         EAP-Message = 0x020c001201686f73742f76696e666f2d7431
         Message-Authenticator = 0x896b213f641e21cae37d8783ed92a6af
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 10
   modcall[authorize]: module "preprocess" returns ok for request 10
   rlm_eap: EAP packet type response id 12 length 18
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 10
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 10
modcall: leaving group authorize (returns updated) for request 10
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 10
   rlm_eap: EAP Identity
   rlm_eap: processing type tls
  rlm_eap_tls: Requiring client certificate
   rlm_eap_tls: Initiate
   rlm_eap_tls: Start returned 1
   modcall[authenticate]: module "eap" returns handled for request 10
modcall: leaving group authenticate (returns handled) for request 10
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x010d00060d20
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x1bb29fa8bf1aa2e286207b6fdd44a0f4
Finished request 10
Going to the next request
--- Walking the entire request list ---
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x1bb29fa8bf1aa2e286207b6fdd44a0f4
         EAP-Message = 
         Message-Authenticator = 0x3c9e43262511932f1695d966d717783b
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 11
   modcall[authorize]: module "preprocess" returns ok for request 11
   rlm_eap: EAP packet type response id 13 length 80
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 11
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 11
modcall: leaving group authorize (returns updated) for request 11
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 11
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls:  Length Included
   eaptls_verify returned 11
     (other): before/accept initialization
     TLS_accept: before/accept initialization
   rlm_eap_tls: <<< TLS 1.0 Handshake [length 0041], ClientHello
     TLS_accept: SSLv3 read client hello A
   rlm_eap_tls: >>> TLS 1.0 Handshake [length 004a], ServerHello
     TLS_accept: SSLv3 write server hello A
   rlm_eap_tls: >>> TLS 1.0 Handshake [length 0ef8], Certificate
     TLS_accept: SSLv3 write certificate A
   rlm_eap_tls: >>> TLS 1.0 Handshake [length 00bd], CertificateRequest
     TLS_accept: SSLv3 write certificate request A
     TLS_accept: SSLv3 flush data
     TLS_accept:error in SSLv3 read client certificate A
In SSL Handshake Phase
In SSL Accept mode
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 11
modcall: leaving group authenticate (returns handled) for request 11
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 0xad529359b0a55e5bffa9cf65b3034d48c263c491b24a
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x042d4a21986c4743a484d2db89cd0c33
Finished request 11
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x042d4a21986c4743a484d2db89cd0c33
         EAP-Message = 0x020e00060d00
         Message-Authenticator = 0x7540ade5dc60f3209b713f2a001bb519
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 12
   modcall[authorize]: module "preprocess" returns ok for request 12
   rlm_eap: EAP packet type response id 14 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 12
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 12
modcall: leaving group authorize (returns updated) for request 12
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 12
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack handshake fragment handler
   eaptls_verify returned 1
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 12
modcall: leaving group authenticate (returns handled) for request 12
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 0x020102020900890d6f61ac0ce005300d06092a864886
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0xb9b86fc0e4881bcc45520f173812f948
Finished request 12
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0xb9b86fc0e4881bcc45520f173812f948
         EAP-Message = 0x020f00060d00
         Message-Authenticator = 0x324813d2519a1143af74caf29d6e4cc4
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 13
   modcall[authorize]: module "preprocess" returns ok for request 13
   rlm_eap: EAP packet type response id 15 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 13
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 13
modcall: leaving group authorize (returns updated) for request 13
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 13
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack handshake fragment handler
   eaptls_verify returned 1
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 13
modcall: leaving group authenticate (returns handled) for request 13
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 0x18b1f4d8303d042ea181b0a481ad3081aa310b300906
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x6179ba5cc238e25da7d0bbfaa7f48ec2
Finished request 13
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x6179ba5cc238e25da7d0bbfaa7f48ec2
         EAP-Message = 0x021000060d00
         Message-Authenticator = 0xc4de36b8d15b71d6503d44e5064b1ac5
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 14
   modcall[authorize]: module "preprocess" returns ok for request 14
   rlm_eap: EAP packet type response id 16 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 14
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 14
modcall: leaving group authorize (returns updated) for request 14
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 14
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack handshake fragment handler
   eaptls_verify returned 1
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 14
modcall: leaving group authenticate (returns handled) for request 14
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 0x1f06092a864886f70d010901161273632d6974406b68
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x5d9d8b0057df148fc651bc9a2285fa89
Finished request 14
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x5d9d8b0057df148fc651bc9a2285fa89
         EAP-Message = 0x021100060d00
         Message-Authenticator = 0xd0f7bb33b488d0184214011d45f441cd
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 15
   modcall[authorize]: module "preprocess" returns ok for request 15
   rlm_eap: EAP packet type response id 17 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 15
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 15
modcall: leaving group authorize (returns updated) for request 15
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 15
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack handshake fragment handler
   eaptls_verify returned 1
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 15
modcall: leaving group authenticate (returns handled) for request 15
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x011200180d800000100e2d6265726c696e2e64650e000000
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0xa933742c9668ad2c0113a94a7260b40b
Finished request 15
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0xa933742c9668ad2c0113a94a7260b40b
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         Message-Authenticator = 0x240fcaee4fe2f6c8b3b0202f5614b8fe
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 16
   modcall[authorize]: module "preprocess" returns ok for request 16
   rlm_eap: EAP packet type response id 18 length 253
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 16
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 16
modcall: leaving group authorize (returns updated) for request 16
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 16
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls:  Received EAP-TLS First Fragment of the message
   eaptls_verify returned 9
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 16
modcall: leaving group authenticate (returns handled) for request 16
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x011300060d00
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0xbbe78aa63952e446ebe9ab5174aac8e8
Finished request 16
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0xbbe78aa63952e446ebe9ab5174aac8e8
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         EAP-Message = 
         Message-Authenticator = 0x3676aa85809613a74f958ade4f0e6964
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 17
   modcall[authorize]: module "preprocess" returns ok for request 17
   rlm_eap: EAP packet type response id 19 length 253
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 17
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 17
modcall: leaving group authorize (returns updated) for request 17
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 17
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls:  More fragments to follow
   eaptls_verify returned 10
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 17
modcall: leaving group authenticate (returns handled) for request 17
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x011400060d00
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x036b51ce3711c4403dc51cc5df01ecd9
Finished request 17
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x036b51ce3711c4403dc51cc5df01ecd9
         EAP-Message = 
         Message-Authenticator = 0x5edd3cd7421da0315efade97535b61ce
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 18
   modcall[authorize]: module "preprocess" returns ok for request 18
   rlm_eap: EAP packet type response id 20 length 53
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 18
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 18
modcall: leaving group authorize (returns updated) for request 18
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 18
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
   eaptls_verify returned 7
   rlm_eap_tls: Done initial handshake
   rlm_eap_tls: <<< TLS 1.0 Handshake [length 0787], Certificate
--> User-Name = host/vinfo-t1
--> BUF-Name = ServiceCenter-IT_KHB_HfM_HfS
--> subject = /C=DE/ST=Berlin/L=Berlin/O=KHB HfM 
HfS/OU=ServiceCenter-IT/CN=ServiceCenter-IT_KHB_HfM_HfS/emailAddress=sc-it at kh-berlin.de
--> issuer  = /C=DE/ST=Berlin/L=Berlin/O=KHB HfM 
HfS/OU=ServiceCenter-IT/CN=ServiceCenter-IT_KHB_HfM_HfS/emailAddress=sc-it at kh-berlin.de
--> verify return:1
--> verify error:num=9:certificate is not yet valid
   rlm_eap_tls: >>> TLS 1.0 Alert [length 0002], fatal bad_certificate
TLS Alert write:fatal:bad certificate
     TLS_accept:error in SSLv3 read client certificate B
9054:error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no 
certificate returned:s3_srvr.c:2482:
rlm_eap_tls: SSL_read failed in a system call (-1), TLS session fails.
In SSL Handshake Phase
In SSL Accept mode
   eaptls_process returned 13
   modcall[authenticate]: module "eap" returns handled for request 18
modcall: leaving group authenticate (returns handled) for request 18
Sending Access-Challenge of id 0 to port 49154
         EAP-Message = 0x011500110d80000000071503010002022a
         Message-Authenticator = 0x00000000000000000000000000000000
         State = 0x79296886e86472d17b3281f8b1a77d17
Finished request 18
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
         NAS-IP-Address =
         NAS-Port-Type = Ethernet
         NAS-Port = 2
         User-Name = "host/vinfo-t1"
         State = 0x79296886e86472d17b3281f8b1a77d17
         EAP-Message = 0x021500060d00
         Message-Authenticator = 0x537f24238453a140d4f6d3d21c17be71
   Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 19
   modcall[authorize]: module "preprocess" returns ok for request 19
   rlm_eap: EAP packet type response id 21 length 6
   rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
   modcall[authorize]: module "eap" returns updated for request 19
     users: Matched entry host/vinfo-t1 at line 219
   modcall[authorize]: module "files" returns ok for request 19
modcall: leaving group authorize (returns updated) for request 19
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 19
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/tls
   rlm_eap: processing type tls
   rlm_eap_tls: Authenticate
   rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
   rlm_eap_tls: ack alert
   eaptls_verify returned 4
   eaptls_process returned 4
  rlm_eap: Handler failed in EAP/tls
   rlm_eap: Failed in EAP select
   modcall[authenticate]: module "eap" returns invalid for request 19
modcall: leaving group authenticate (returns invalid) for request 19
auth: Failed to validate the user.
Delaying request 19 for 1 seconds
Finished request 19
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=0, 
Sending Access-Reject of id 0 to port 49154
         EAP-Message = 0x04150004
         Message-Authenticator = 0x00000000000000000000000000000000
--- Walking the entire request list ---
Waking up in 4 seconds...
--- Walking the entire request list ---
Cleaning up request 19 ID 0 with timestamp 44cdf6a8
Nothing to do.  Sleeping until we see a request.

I don't know why the request ist send over again and again. Please help...


ServiceCenter IT - Alexandros Gougousoudis (Leiter)

Gemeinsame Einrichtung der Kunsthochschule Berlin-Weissensee, Hochschule 
für Musik "Hanns Eisler" und der Hochschule für Schauspielkunst "Ernst 

Tel.: 030 / 477 05 - 444 * Fax.: 030 / 477 05 - 445

More information about the Freeradius-Users mailing list