EAP/TLS ,after access-challenge nothing happen

tnt at kalik.co.yu tnt at kalik.co.yu
Fri Jun 22 14:17:45 CEST 2007


Ivan Kalik
Kalik Informatika ISP

Dana 22/6/2007, "stefek143" <stefek143 at wp.pl> piše:

>I have a little problem with authenticate using EAP/TLS on freeradius. 
>After Access Challenge freeradius not display Reject or Accept, only 
>going to the begin and repeat the same operation. What`s wrong ?? as NAS 
>i`m using CISCO catalyst 2950 and client supplicant WinXP.
>this is logs from tcpdump:
>21:43:21.547329 IP > RADIUS, 
>Access Request (1), id: 0x7d length: 120
>21:43:21.648845 IP > RADIUS, 
>Access Challenge (11), id: 0x7d length: 64
>21:43:21.572693 IP > RADIUS, 
>Access Request (1), id: 0x7e length: 189
>21:43:21.587661 IP > RADIUS, 
>Access Challenge (11), id: 0x7e length: 1100
>21:43:21.602274 IP > RADIUS, 
>Access Request (1), id: 0x7f length: 115
>21:43:21.604767 IP > RADIUS, 
>Access Challenge (11), id: 0x7f length: 976
>21:43:21.620631 IP > RADIUS, 
>Access Request (1), id: 0x80 length: 115
>21:43:21.629087 IP > RADIUS, 
>Access Challenge (11), id: 0x80 length: 68
>and this is logs from freeradius debug mode:
>rad_recv: Access-Request packet from host, id=207, 
>        NAS-IP-Address =
>        NAS-Port-Type = Async
>        User-Name = "client"
>        Service-Type = Framed-User
>        Framed-MTU = 1500
>        Calling-Station-Id = "00-11-09-26-48-fa"
>        State = 0xf4dbd9e74648ce65d56e471171d0e7f3
>        EAP-Message = 0x020200060d00
>        Message-Authenticator = 0x767944f13525d633320393682cb2403f
>  Processing the authorize section of radiusd.conf
>modcall: entering group authorize for request 90
>  modcall[authorize]: module "preprocess" returns ok for request 90
>  modcall[authorize]: module "chap" returns noop for request 90
>  modcall[authorize]: module "mschap" returns noop for request 90
>    rlm_realm: No '@' in User-Name = "client", looking up realm NULL
>    rlm_realm: No such realm "NULL"
>  modcall[authorize]: module "suffix" returns noop for request 90
>  rlm_eap: EAP packet type response id 2 length 6
>  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
>  modcall[authorize]: module "eap" returns updated for request 90
>  modcall[authorize]: module "files" returns notfound for request 90
>rlm_pap: WARNING! No "known good" password found for the user.  
>Authentication may fail because of this.
>  modcall[authorize]: module "pap" returns noop for request 90
>modcall: leaving group authorize (returns updated) for request 90
>  rad_check_password:  Found Auth-Type EAP
>auth: type "EAP"
>  Processing the authenticate section of radiusd.conf
>modcall: entering group authenticate for request 90
>  rlm_eap: Request found, released from the list
>  rlm_eap: EAP/tls
>  rlm_eap: processing type tls
>  rlm_eap_tls: Authenticate
>  rlm_eap_tls: processing TLS
>rlm_eap_tls: Received EAP-TLS ACK message
>  rlm_eap_tls: ack handshake fragment handler
>  eaptls_verify returned 1
>  eaptls_process returned 13
>  modcall[authenticate]: module "eap" returns handled for request 90
>modcall: leaving group authenticate (returns handled) for request 90
>Sending Access-Challenge of id 207 to port 1812
>        EAP-Message = 
>        EAP-Message = 
>        EAP-Message = 
>        EAP-Message = 
>        Message-Authenticator = 0x00000000000000000000000000000000
>        State = 0x8a37dd36bf1bbbf6747bb6c4216ea380
>Finished request 90
>Going to the next request
>Waking up in 6 seconds...
>rad_recv: Access-Request packet from host, id=208, 
>        NAS-IP-Address =
>        NAS-Port-Type = Async
>        User-Name = "client"
>        Service-Type = Framed-User
>        Framed-MTU = 1500
>        Calling-Station-Id = "00-11-09-26-48-fa"
>        State = 0x8a37dd36bf1bbbf6747bb6c4216ea380
>        EAP-Message = 0x020300060d00
>        Message-Authenticator = 0x6de0700bd6d131fc1cec8bec76fcea72
>  Processing the authorize section of radiusd.conf
>modcall: entering group authorize for request 91
>  modcall[authorize]: module "preprocess" returns ok for request 91
>  modcall[authorize]: module "chap" returns noop for request 91
>  modcall[authorize]: module "mschap" returns noop for request 91
>    rlm_realm: No '@' in User-Name = "client", looking up realm NULL
>    rlm_realm: No such realm "NULL"
>  modcall[authorize]: module "suffix" returns noop for request 91
>  rlm_eap: EAP packet type response id 3 length 6
>  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
>  modcall[authorize]: module "eap" returns updated for request 91
>  modcall[authorize]: module "files" returns notfound for request 91
>rlm_pap: WARNING! No "known good" password found for the user.  
>Authentication may fail because of this.
>  modcall[authorize]: module "pap" returns noop for request 91
>modcall: leaving group authorize (returns updated) for request 91
>  rad_check_password:  Found Auth-Type EAP
>auth: type "EAP"
>  Processing the authenticate section of radiusd.conf
>modcall: entering group authenticate for request 91
>  rlm_eap: Request found, released from the list
>  rlm_eap: EAP/tls
>  rlm_eap: processing type tls
>  rlm_eap_tls: Authenticate
>  rlm_eap_tls: processing TLS
>rlm_eap_tls: Received EAP-TLS ACK message
>  rlm_eap_tls: ack handshake fragment handler
>  eaptls_verify returned 1
>  eaptls_process returned 13
>  modcall[authenticate]: module "eap" returns handled for request 91
>modcall: leaving group authenticate (returns handled) for request 91
>Sending Access-Challenge of id 208 to port 1812
>        EAP-Message = 0x0104000a0d8000000000
>        Message-Authenticator = 0x00000000000000000000000000000000
>        State = 0x7b7eac5f542d1c6ec0abd77c3ce3c509
>Finished request 91
>Going to the next request
>Waking up in 6 seconds...
>--- Walking the entire request list ---
>Cleaning up request 88 ID 205 with timestamp 467ad8b7
>Cleaning up request 89 ID 206 with timestamp 467ad8b7
>Cleaning up request 90 ID 207 with timestamp 467ad8b7
>Cleaning up request 91 ID 208 with timestamp 467ad8b7
>Nothing to do.  Sleeping until we see a request.
>Nieważne, kim jesteś i jak wyglądasz. Jesteś wart 
>tyle, ile ktoś chce zapłacić za twoją śmierć... 
>Przerażający thriller HOSTEL 2 - w kinach od 22 czerwca! 
>List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

More information about the Freeradius-Users mailing list