Getting PEAP/MSChap-v2 working with Cisco AP1231G Access points.
Terry Pelley
Terry.Pelley at
Fri Sep 14 14:48:06 CEST 2007
FreeRADIUS Version 1.1.3-r0.1.2
I have been using FreeRADIUS for some time now to do simple MAC
authentication for the original implementation of our wireless network.
This of course was a temporary solution and I am trying to move all of the
users over to PEAP Authentication.
I Have been unable to get the PEAP Authentication to work with MSChap-v2.
All of my Access points are Cisco AP1231G Models.
I am fairly new to FreeRADIUS, so I expect what I am doing wrong is going
to be obvious to most but any advice would be welcomed. From what I can
see it appears that the User-Password attribute may not be getting
processed correctly as indicated by the following lines.
auth: Failed to validate the user.
Login incorrect: [C12660/<no User-Password attribute>] (from client
localhost port 0)
PEAP: Tunneled authentication was rejected.
rlm_eap_peap: FAILURE
I have included my debug output below.
Terry Pelley
Network Analyst
Business and Learning Technologies
Ottawa-Carleton District School Board
Debug Output.###########
Ready to process requests.
rad_recv: Access-Request packet from host, id=1,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0x85aa28b563b14c66500cdbee3613d047
EAP-Message = 0x0202000b01433132363630
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 0
modcall[authorize]: module "preprocess" returns ok for request 0
modcall[authorize]: module "chap" returns noop for request 0
modcall[authorize]: module "mschap" returns noop for request 0
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 0
rlm_eap: EAP packet type response id 2 length 11
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 0
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 0
modcall: leaving group authorize (returns updated) for request 0
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 0
rlm_eap: EAP Identity
rlm_eap: processing type leap
rlm_eap_leap: Stage 2
rlm_eap_leap: Issuing AP Challenge
rlm_eap_leap: Successfully initiated
modcall[authenticate]: module "eap" returns handled for request 0
modcall: leaving group authenticate (returns handled) for request 0
Sending Access-Challenge of id 1 to port 1645
EAP-Message = 0x01030016110100082abab9994950d11b433132363630
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x734179eb51b60c489589265407691b5c
Finished request 0
Going to the next request
--- Walking the entire request list ---
Waking up in 6 seconds...
rad_recv: Access-Request packet from host, id=2,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0x6c47bb7bdfb40f5047245b3ff39ad738
EAP-Message = 0x020300060319
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0x734179eb51b60c489589265407691b5c
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 1
modcall[authorize]: module "preprocess" returns ok for request 1
modcall[authorize]: module "chap" returns noop for request 1
modcall[authorize]: module "mschap" returns noop for request 1
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 1
rlm_eap: EAP packet type response id 3 length 6
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 1
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 1
modcall: leaving group authorize (returns updated) for request 1
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 1
rlm_eap: Request found, released from the list
rlm_eap: EAP NAK
rlm_eap: EAP-NAK asked for EAP-Type/peap
rlm_eap: processing type tls
rlm_eap_tls: Initiate
rlm_eap_tls: Start returned 1
modcall[authenticate]: module "eap" returns handled for request 1
modcall: leaving group authenticate (returns handled) for request 1
Sending Access-Challenge of id 2 to port 1645
EAP-Message = 0x010400061920
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x13c573d53e826031d83b6b1edc7b48a8
Finished request 1
Going to the next request
--- Walking the entire request list ---
Waking up in 5 seconds...
rad_recv: Access-Request packet from host, id=3,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0x2a5655347310a8601241f7abe218f989
EAP-Message =
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0x13c573d53e826031d83b6b1edc7b48a8
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 2
modcall[authorize]: module "preprocess" returns ok for request 2
modcall[authorize]: module "chap" returns noop for request 2
modcall[authorize]: module "mschap" returns noop for request 2
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 2
rlm_eap: EAP packet type response id 4 length 80
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 2
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 2
modcall: leaving group authorize (returns updated) for request 2
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 2
rlm_eap: Request found, released from the list
rlm_eap: EAP/peap
rlm_eap: processing type peap
rlm_eap_peap: Authenticate
rlm_eap_tls: processing TLS
rlm_eap_tls: Length Included
eaptls_verify returned 11
(other): before/accept initialization
TLS_accept: before/accept initialization
rlm_eap_tls: <<< TLS 1.0 Handshake [length 0041], ClientHello
TLS_accept: SSLv3 read client hello A
rlm_eap_tls: >>> TLS 1.0 Handshake [length 004a], ServerHello
TLS_accept: SSLv3 write server hello A
rlm_eap_tls: >>> TLS 1.0 Handshake [length 09cd], Certificate
TLS_accept: SSLv3 write certificate A
rlm_eap_tls: >>> TLS 1.0 Handshake [length 0004], ServerHelloDone
TLS_accept: SSLv3 write server done A
TLS_accept: SSLv3 flush data
TLS_accept:error in SSLv3 read client certificate A
rlm_eap: SSL error error:00000000:lib(0):func(0):reason(0)
In SSL Handshake Phase
In SSL Accept mode
eaptls_process returned 13
rlm_eap_peap: EAPTLS_HANDLED
modcall[authenticate]: module "eap" returns handled for request 2
modcall: leaving group authenticate (returns handled) for request 2
Sending Access-Challenge of id 3 to port 1645
EAP-Message =
EAP-Message =
EAP-Message =
EAP-Message =
EAP-Message = 0x0306082b0601050507030406082b0601050507030806
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x5ff0a13a76110935f4f62436568f7102
Finished request 2
Going to the next request
Waking up in 5 seconds...
rad_recv: Access-Request packet from host, id=4,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0x9387267e436cd878e0b77dfa7e6a482e
EAP-Message = 0x020500061900
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0x5ff0a13a76110935f4f62436568f7102
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 3
modcall[authorize]: module "preprocess" returns ok for request 3
modcall[authorize]: module "chap" returns noop for request 3
modcall[authorize]: module "mschap" returns noop for request 3
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 3
rlm_eap: EAP packet type response id 5 length 6
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 3
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 3
modcall: leaving group authorize (returns updated) for request 3
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 3
rlm_eap: Request found, released from the list
rlm_eap: EAP/peap
rlm_eap: processing type peap
rlm_eap_peap: Authenticate
rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
rlm_eap_tls: ack handshake fragment handler
eaptls_verify returned 1
eaptls_process returned 13
rlm_eap_peap: EAPTLS_HANDLED
modcall[authenticate]: module "eap" returns handled for request 3
modcall: leaving group authenticate (returns handled) for request 3
Sending Access-Challenge of id 4 to port 1645
EAP-Message =
EAP-Message =
EAP-Message =
EAP-Message =
EAP-Message = 0x0f96ad36a181b3a481b03081ad311a301806
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x05a71bebf0e68eb436ba851a1069c1e9
Finished request 3
Going to the next request
Waking up in 5 seconds...
rad_recv: Access-Request packet from host, id=5,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0x53b6ff3e904ba17f428901174910de9f
EAP-Message = 0x020600061900
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0x05a71bebf0e68eb436ba851a1069c1e9
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 4
modcall[authorize]: module "preprocess" returns ok for request 4
modcall[authorize]: module "chap" returns noop for request 4
modcall[authorize]: module "mschap" returns noop for request 4
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 4
rlm_eap: EAP packet type response id 6 length 6
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 4
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 4
modcall: leaving group authorize (returns updated) for request 4
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 4
rlm_eap: Request found, released from the list
rlm_eap: EAP/peap
rlm_eap: processing type peap
rlm_eap_peap: Authenticate
rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
rlm_eap_tls: ack handshake fragment handler
eaptls_verify returned 1
eaptls_process returned 13
rlm_eap_peap: EAPTLS_HANDLED
modcall[authenticate]: module "eap" returns handled for request 4
modcall: leaving group authenticate (returns handled) for request 4
Sending Access-Challenge of id 5 to port 1645
EAP-Message =
EAP-Message =
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x402ad25b6167d63f4d49a90417269d2a
Finished request 4
Going to the next request
--- Walking the entire request list ---
Waking up in 4 seconds...
rad_recv: Access-Request packet from host, id=6,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0x90d4c8b0f49ded28f4259944626a11db
EAP-Message =
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0x402ad25b6167d63f4d49a90417269d2a
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 5
modcall[authorize]: module "preprocess" returns ok for request 5
modcall[authorize]: module "chap" returns noop for request 5
modcall[authorize]: module "mschap" returns noop for request 5
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 5
rlm_eap: EAP packet type response id 7 length 192
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 5
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 5
modcall: leaving group authorize (returns updated) for request 5
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 5
rlm_eap: Request found, released from the list
rlm_eap: EAP/peap
rlm_eap: processing type peap
rlm_eap_peap: Authenticate
rlm_eap_tls: processing TLS
rlm_eap_tls: Length Included
eaptls_verify returned 11
rlm_eap_tls: <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange
TLS_accept: SSLv3 read client key exchange A
rlm_eap_tls: <<< TLS 1.0 ChangeCipherSpec [length 0001]
rlm_eap_tls: <<< TLS 1.0 Handshake [length 0010], Finished
TLS_accept: SSLv3 read finished A
rlm_eap_tls: >>> TLS 1.0 ChangeCipherSpec [length 0001]
TLS_accept: SSLv3 write change cipher spec A
rlm_eap_tls: >>> TLS 1.0 Handshake [length 0010], Finished
TLS_accept: SSLv3 write finished A
TLS_accept: SSLv3 flush data
(other): SSL negotiation finished successfully
rlm_eap: SSL error error:00000000:lib(0):func(0):reason(0)
SSL Connection Established
eaptls_process returned 13
rlm_eap_peap: EAPTLS_HANDLED
modcall[authenticate]: module "eap" returns handled for request 5
modcall: leaving group authenticate (returns handled) for request 5
Sending Access-Challenge of id 6 to port 1645
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x05f8c978699fcafe9a8b8257d497b7fe
Finished request 5
Going to the next request
Waking up in 4 seconds...
rad_recv: Access-Request packet from host, id=7,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0xd6dd6119858638da70df2a9147c7a486
EAP-Message = 0x020800061900
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0x05f8c978699fcafe9a8b8257d497b7fe
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 6
modcall[authorize]: module "preprocess" returns ok for request 6
modcall[authorize]: module "chap" returns noop for request 6
modcall[authorize]: module "mschap" returns noop for request 6
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 6
rlm_eap: EAP packet type response id 8 length 6
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 6
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 6
modcall: leaving group authorize (returns updated) for request 6
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 6
rlm_eap: Request found, released from the list
rlm_eap: EAP/peap
rlm_eap: processing type peap
rlm_eap_peap: Authenticate
rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
rlm_eap_tls: ack handshake is finished
eaptls_verify returned 3
eaptls_process returned 3
rlm_eap_peap: EAPTLS_SUCCESS
modcall[authenticate]: module "eap" returns handled for request 6
modcall: leaving group authenticate (returns handled) for request 6
Sending Access-Challenge of id 7 to port 1645
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xe78002ce41f0ccf2a79c28dc1d491876
Finished request 6
Going to the next request
Waking up in 4 seconds...
rad_recv: Access-Request packet from host, id=8,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0x60a26279e0c87ed6ee707db18a9228c5
EAP-Message =
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0xe78002ce41f0ccf2a79c28dc1d491876
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 7
modcall[authorize]: module "preprocess" returns ok for request 7
modcall[authorize]: module "chap" returns noop for request 7
modcall[authorize]: module "mschap" returns noop for request 7
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 7
rlm_eap: EAP packet type response id 9 length 34
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 7
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 7
modcall: leaving group authorize (returns updated) for request 7
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 7
rlm_eap: Request found, released from the list
rlm_eap: EAP/peap
rlm_eap: processing type peap
rlm_eap_peap: Authenticate
rlm_eap_tls: processing TLS
eaptls_verify returned 7
rlm_eap_tls: Done initial handshake
eaptls_process returned 7
rlm_eap_peap: EAPTLS_OK
rlm_eap_peap: Session established. Decoding tunneled attributes.
rlm_eap_peap: Identity - C12660
rlm_eap_peap: Tunneled data is valid.
PEAP: Got tunneled identity of C12660
PEAP: Setting default EAP type for tunneled EAP session.
PEAP: Setting User-Name to C12660
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 7
modcall[authorize]: module "preprocess" returns ok for request 7
modcall[authorize]: module "chap" returns noop for request 7
modcall[authorize]: module "mschap" returns noop for request 7
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 7
rlm_eap: EAP packet type response id 9 length 11
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 7
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 7
modcall: leaving group authorize (returns updated) for request 7
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 7
rlm_eap: EAP Identity
rlm_eap: processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
modcall[authenticate]: module "eap" returns handled for request 7
modcall: leaving group authenticate (returns handled) for request 7
PEAP: Got tunneled Access-Challenge
modcall[authenticate]: module "eap" returns handled for request 7
modcall: leaving group authenticate (returns handled) for request 7
Sending Access-Challenge of id 8 to port 1645
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0xbb97c77fadc7f0fe144db4c94230c406
Finished request 7
Going to the next request
--- Walking the entire request list ---
Waking up in 3 seconds...
rad_recv: Access-Request packet from host, id=9,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0xb9cdb400a3aa33c86b387410714aa409
EAP-Message =
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0xbb97c77fadc7f0fe144db4c94230c406
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 8
modcall[authorize]: module "preprocess" returns ok for request 8
modcall[authorize]: module "chap" returns noop for request 8
modcall[authorize]: module "mschap" returns noop for request 8
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 8
rlm_eap: EAP packet type response id 10 length 88
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 8
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 8
modcall: leaving group authorize (returns updated) for request 8
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 8
rlm_eap: Request found, released from the list
rlm_eap: EAP/peap
rlm_eap: processing type peap
rlm_eap_peap: Authenticate
rlm_eap_tls: processing TLS
eaptls_verify returned 7
rlm_eap_tls: Done initial handshake
eaptls_process returned 7
rlm_eap_peap: EAPTLS_OK
rlm_eap_peap: Session established. Decoding tunneled attributes.
rlm_eap_peap: EAP type mschapv2
rlm_eap_peap: Tunneled data is valid.
PEAP: Setting User-Name to C12660
PEAP: Adding old state with 89 38
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 8
modcall[authorize]: module "preprocess" returns ok for request 8
modcall[authorize]: module "chap" returns noop for request 8
modcall[authorize]: module "mschap" returns noop for request 8
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 8
rlm_eap: EAP packet type response id 10 length 65
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 8
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 8
modcall: leaving group authorize (returns updated) for request 8
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 8
rlm_eap: Request found, released from the list
rlm_eap: EAP/mschapv2
rlm_eap: processing type mschapv2
Processing the authenticate section of radiusd.conf
modcall: entering group MS-CHAP for request 8
rlm_mschap: No User-Password configured. Cannot create LM-Password.
rlm_mschap: No User-Password configured. Cannot create NT-Password.
rlm_mschap: Told to do MS-CHAPv2 for C12660 with NT-Password
rlm_mschap: FAILED: No NT/LM-Password. Cannot perform authentication.
rlm_mschap: FAILED: MS-CHAP2-Response is incorrect
modcall[authenticate]: module "mschap" returns reject for request 8
modcall: leaving group MS-CHAP (returns reject) for request 8
rlm_eap: Freeing handler
modcall[authenticate]: module "eap" returns reject for request 8
modcall: leaving group authenticate (returns reject) for request 8
auth: Failed to validate the user.
Login incorrect: [C12660/<no User-Password attribute>] (from client
localhost port 0)
PEAP: Tunneled authentication was rejected.
rlm_eap_peap: FAILURE
modcall[authenticate]: module "eap" returns handled for request 8
modcall: leaving group authenticate (returns handled) for request 8
Sending Access-Challenge of id 9 to port 1645
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x09dc8afc60ab61b4a60d20c8118a9879
Finished request 8
Going to the next request
Waking up in 3 seconds...
rad_recv: Access-Request packet from host, id=10,
User-Name = "C12660"
Framed-MTU = 1400
Called-Station-Id = "0011.aaaa.17b0"
Calling-Station-Id = "0004.1e45.382e"
Service-Type = Login-User
Message-Authenticator = 0x69506c8cf1653acc63c6025c65831643
EAP-Message =
NAS-Port-Type = Wireless-802.11
NAS-Port = 257
State = 0x09dc8afc60ab61b4a60d20c8118a9879
NAS-IP-Address =
NAS-Identifier = "AP1231G"
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 9
modcall[authorize]: module "preprocess" returns ok for request 9
modcall[authorize]: module "chap" returns noop for request 9
modcall[authorize]: module "mschap" returns noop for request 9
rlm_realm: No '@' in User-Name = "C12660", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 9
rlm_eap: EAP packet type response id 11 length 38
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 9
users: Matched entry DEFAULT at line 875
modcall[authorize]: module "files" returns ok for request 9
modcall: leaving group authorize (returns updated) for request 9
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 9
rlm_eap: Request found, released from the list
rlm_eap: EAP/peap
rlm_eap: processing type peap
rlm_eap_peap: Authenticate
rlm_eap_tls: processing TLS
eaptls_verify returned 7
rlm_eap_tls: Done initial handshake
eaptls_process returned 7
rlm_eap_peap: EAPTLS_OK
rlm_eap_peap: Session established. Decoding tunneled attributes.
rlm_eap_peap: Received EAP-TLV response.
rlm_eap_peap: Tunneled data is valid.
rlm_eap_peap: Had sent TLV failure. User was rejcted rejected earlier
in this session.
rlm_eap: Handler failed in EAP/peap
rlm_eap: Failed in EAP select
modcall[authenticate]: module "eap" returns invalid for request 9
modcall: leaving group authenticate (returns invalid) for request 9
auth: Failed to validate the user.
Login incorrect: [C12660/<no User-Password attribute>] (from client
OCDSB_HQ port 257 cli 0004.2350.382e)
Delaying request 9 for 1 seconds
Finished request 9
Going to the next request
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Cleaning up request 0 ID 1 with timestamp 46ea79da
Sending Access-Reject of id 10 to port 1645
EAP-Message = 0x040b0004
Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 1 seconds...
--- Walking the entire request list ---
Cleaning up request 1 ID 2 with timestamp 46ea79db
Cleaning up request 2 ID 3 with timestamp 46ea79db
Cleaning up request 3 ID 4 with timestamp 46ea79db
Waking up in 1 seconds...
--- Walking the entire request list ---
Cleaning up request 4 ID 5 with timestamp 46ea79dc
Cleaning up request 5 ID 6 with timestamp 46ea79dc
Cleaning up request 6 ID 7 with timestamp 46ea79dc
Waking up in 1 seconds...
--- Walking the entire request list ---
Cleaning up request 7 ID 8 with timestamp 46ea79dd
Cleaning up request 8 ID 9 with timestamp 46ea79dd
Waking up in 1 seconds...
--- Walking the entire request list ---
Cleaning up request 9 ID 10 with timestamp 46ea79de
Nothing to do. Sleeping until we see a request.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>
More information about the Freeradius-Users
mailing list