Problem with CHAP

Javier Fernando jcomputacion at hotmail.com
Mon Nov 26 13:47:17 CET 2007


I connect to the radius over a dialup modem, I add a CHAP user with this line in the users file:
 
usuario3 Cleartext-Password := "testusuario3"
 
When I connect I use this username and password and the radius don't validate the request.
 
Javier.
> To: freeradius-users at lists.freeradius.org> Subject: RE: Problem with CHAP> Date: Sat, 24 Nov 2007 01:16:04 +0100> From: tnt at kalik.co.yu> > You are not sending that username:> > User-Name = "chap"> > Put usuario3 as a username on XP PC.> > Ivan Kalik> Kalik Informatika ISP> > > Dana 23/11/2007, "Javier Fernando" <jcomputacion at hotmail.com> piše:> > >> >I think that this is a CHAP USER:> > > >usuario3 Cleartext-Password := "testusuario3"> > > >How to add a Chap user to the users file?> > > >Javier.> >> > Do you have user chap in your users file? You have posted entries for> some other usernames.> > Ivan Kalik> Kalik Informatika ISP> > > Dana 23/11/2007, "Javier Fernando" <jcomputacion at hotmail.com> pi�e:> > >> >I configure Freeradius , when the client try to connect with CHAP i have this error, and only connect with linux system users. When I connect locally with radtest i connect ok but when i connect remotely whit Windows Xp using CHAP don't connect. I run radius in debug mode with -X option.> > > >Part of clients.conf> > > >usuario1 Auth-Type := Local, Cleartext-Password := "testusuario1"> >usuario2 Auth-Type := Local, Password := "testusuario2"> >usuario3 Cleartext-Password := "testusuario3"> > > >Error of freeradius running with -X option:> > > >rad_recv: Access-Request packet from host 192.168..1.100:1645, id=106, length=126 Framed-Protocol = PPP User-Name = "chap" CHAP-Password = 0x019c1a0fb685942ed07fdb1e2d100e93f0 NAS-Port-Type = Virtual NAS-Port = 1586 Calling-Station-Id = "1141323200" Called-Station-Id = "8003450410" Connect-Info = "TLS-MISERVER-DIALUP" Service-Type = Framed-User NAS-IP-Address = 192.168.1.100 Processing the authorize section of radiusd.confmodcall: entering group authorize for request 2 modcall[authorize]: module "preprocess" returns ok for request 2 rlm_chap: Setting 'Auth-Type := CHAP' modcall[authorize]: module "chap" returns ok for request 2 modcall[authorize]: module "mschap" returns noop for request 2 rlm_realm: No '@' in User-Name = "chap", looking up realm NULL rlm_realm: No such realm "NULL" modcall[authorize]: module "suffix" returns noop for request 2 rlm_eap: No EAP-Message, not doing EAP modcall[authorize]: module "eap" returns noop for request 2 users: Matched entry DEFAULT at line 173 users: Matched entry DEFAULT at line 185 modcall[authorize]: module "files" returns ok for request 2rlm_pap: WARNING! No "known good" password found for the user. Authentication may fail because of this. modcall[authorize]: module "pap" returns noop for request 2modcall: leaving group authorize (returns ok) for request 2 rad_check_password: Found Auth-Type CHAPauth: type "CHAP" Processing the authenticate section of radiusd.confmodcall: entering group CHAP for request 2 rlm_chap: login attempt by "chap" with CHAP password rlm_chap: Could not find clear text password for user chap modcall[authenticate]: module "chap" returns invalid for request 2modcall: leaving group CHAP (returns invalid) for request 2auth: Failed to validate the user.Login incorrect (rlm_chap: Clear text password not available): [chap/<CHAP-Password>] (from client rasiplan2 port 1586 cli 1141323200)Delaying request 2 for 1 secondsFinished request 2Going to the next request--- Walking the entire request list ---Waking up in 1 seconds...--- Walking the entire request list ---Waking up in 1 seconds...--- Walking the entire request list ---Sending Access-Reject of id 106 to 192.168.1.1 port 1645Waking up in 4 seconds.....--- Walking the entire request list ---Cleaning up request 2 ID 106 with timestamp 47472e23Nothing to do. Sleeping until we see a request.> >_________________________________________________________________> >Tecnología, moda, motor, viajes,�suscríbete a nuestros boletines para estar a la última> >http://newsletters.msn.com/hm/maintenanceeses.asp?L=ES&C=ES&P=WCMaintenance&Brand=WL&RU=http%3a%2f%2fmail.live.com> >> > -> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html> >_________________________________________________________________> >Tecnología, moda, motor, viajes,�suscríbete a nuestros boletines para estar a la última> >http://newsletters.msn.com/hm/maintenanceeses.asp?L=ES&C=ES&P=WCMaintenance&Brand=WL&RU=http%3a%2f%2fmail.live.com> >> > -> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
_________________________________________________________________
Tecnología, moda, motor, viajes,…suscríbete a nuestros boletines para estar a la última
http://newsletters.msn.com/hm/maintenanceeses.asp?L=ES&C=ES&P=WCMaintenance&Brand=WL&RU=http%3a%2f%2fmail.live.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20071126/a2210b8a/attachment.html>


More information about the Freeradius-Users mailing list