How to hide passwords in the log file?
Rokkhan
rokkhan at gmail.com
Fri Aug 7 11:07:23 CEST 2009
Hi,
Does anyone knows how to hide passwords in the log file? I have read
some posts about this, but the solution was to edit source, something
that I'm not able to do. I don´t know if the 2.1.6 version has been
implemented any option to do this without edit source.
This is my configuration in radiusd.conf
log {
destination = files
file = ${logdir}/radius.log
syslog_facility = daemon
stripped_names = no
auth = yes
auth_badpass = yes
auth_goodpass = yes
}
I have no problems when users are authenticated by PEAP, because the
log file doesn´t shows the passwords, but now, i want to configure a
virtual server to work like tacacs+ on a Cisco ASA Firewall. The
firewall supports only radius protocol and it sends passwords in
cleartext (PAP), so the passwords are shown on the log, something i
would like to avoid.
I know that i could set auth = no, and then no authentication will
appear in the log, but i need to keep this information to see if a
user has logged in correctly or not.
Another way to solve this problem could be (i dont know if it will
possible), don't log the auth messages from this virtual server and
keeping the auth information of other virtual server like radiusd.conf
configuration.
Thanks in advance.
More information about the Freeradius-Users
mailing list