Error: User-Name is not the same as MS-CHAP name
Francois Gaudreault
fgaudreault at
Sat May 28 19:33:46 CEST 2011
Here is the complete debug log :
rad_recv: Access-Request packet from host port 29010,
id=194, length=179
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message = 0x02000016015354494330383836325c54656368524d43
Message-Authenticator = 0xfa084ddf06908a03fe823772e3df038e
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 0 length 22
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[ldap] performing user authorization for STIC08862\TechRMC
[ldap] expand: (uid=%{mschap:User-Name}) -> (uid=TechRMC)
[ldap] expand: o=CSPI -> o=CSPI
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in o=CSPI, with filter (uid=TechRMC)
[ldap] Added the eDirectory password 1234567 in check items as
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
[ldap] looking for reply items in directory...
[ldap] user STIC08862\TechRMC authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 194 to port 29010
EAP-Message = 0x010100061920
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x309c14c6309d0dd14b00d913c56dbe3f
Finished request 78.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 29010,
id=195, length=255
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message =
State = 0x309c14c6309d0dd14b00d913c56dbe3f
Message-Authenticator = 0xbb36f856b12e7151d07b7f62bb8ac4d1
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 1 length 80
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
TLS Length 70
[peap] Length Included
[peap] eaptls_verify returned 11
[peap] (other): before/accept initialization
[peap] TLS_accept: before/accept initialization
[peap] <<< TLS 1.0 Handshake [length 0041], ClientHello
[peap] TLS_accept: SSLv3 read client hello A
[peap] >>> TLS 1.0 Handshake [length 002a], ServerHello
[peap] TLS_accept: SSLv3 write server hello A
[peap] >>> TLS 1.0 Handshake [length 085e], Certificate
[peap] TLS_accept: SSLv3 write certificate A
[peap] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone
[peap] TLS_accept: SSLv3 write server done A
[peap] TLS_accept: SSLv3 flush data
[peap] TLS_accept: Need to read more data: SSLv3 read client
certificate A
In SSL Handshake Phase
In SSL Accept mode
[peap] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 195 to port 29010
EAP-Message =
EAP-Message =
EAP-Message =
EAP-Message =
EAP-Message = 0xa73082038fa0030201020209
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x309c14c6319e0dd14b00d913c56dbe3f
Finished request 79.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 29010,
id=196, length=181
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message = 0x020200061900
State = 0x309c14c6319e0dd14b00d913c56dbe3f
Message-Authenticator = 0xa462f5cd5ac6dd277077e9011fbf9c14
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 2 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1
[peap] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 196 to port 29010
EAP-Message =
EAP-Message =
EAP-Message =
EAP-Message =
EAP-Message = 0x3deb8931d600ea5e
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x309c14c6329f0dd14b00d913c56dbe3f
Finished request 80.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 29010,
id=197, length=181
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message = 0x020300061900
State = 0x309c14c6329f0dd14b00d913c56dbe3f
Message-Authenticator = 0xa5deb369fab7a8ab117e3a2d3a1bd99a
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 3 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1
[peap] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 197 to port 29010
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x309c14c633980dd14b00d913c56dbe3f
Finished request 81.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 29010,
id=198, length=497
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message =
EAP-Message =
State = 0x309c14c633980dd14b00d913c56dbe3f
Message-Authenticator = 0xa808596aff58e89c835ba408d22c8576
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 4 length 253
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
TLS Length 310
[peap] Length Included
[peap] eaptls_verify returned 11
[peap] <<< TLS 1.0 Handshake [length 0106], ClientKeyExchange
[peap] TLS_accept: SSLv3 read client key exchange A
[peap] <<< TLS 1.0 ChangeCipherSpec [length 0001]
[peap] <<< TLS 1.0 Handshake [length 0010], Finished
[peap] TLS_accept: SSLv3 read finished A
[peap] >>> TLS 1.0 ChangeCipherSpec [length 0001]
[peap] TLS_accept: SSLv3 write change cipher spec A
[peap] >>> TLS 1.0 Handshake [length 0010], Finished
[peap] TLS_accept: SSLv3 write finished A
[peap] TLS_accept: SSLv3 flush data
[peap] (other): SSL negotiation finished successfully
SSL Connection Established
[peap] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 198 to port 29010
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x309c14c634990dd14b00d913c56dbe3f
Finished request 82.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 29010,
id=199, length=181
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message = 0x020500061900
State = 0x309c14c634990dd14b00d913c56dbe3f
Message-Authenticator = 0xfbb387ec4960fce18fa01d5ff1c5e01e
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 5 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake is finished
[peap] eaptls_verify returned 3
[peap] eaptls_process returned 3
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state TUNNEL ESTABLISHED
++[eap] returns handled
Sending Access-Challenge of id 199 to port 29010
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x309c14c6359a0dd14b00d913c56dbe3f
Finished request 83.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host port 29010,
id=200, length=220
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message =
State = 0x309c14c6359a0dd14b00d913c56dbe3f
Message-Authenticator = 0x1d9a3ba6178e12c05cfd06e7b2a2c601
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 6 length 45
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Identity - STIC08862\TechRMC
[peap] Got inner identity 'STIC08862\TechRMC'
[peap] Setting default EAP type for tunneled EAP session.
[peap] Got tunneled request
EAP-Message = 0x02060016015354494330383836325c54656368524d43
server {
PEAP: Setting User-Name to STIC08862\TechRMC
Sending tunneled request
EAP-Message = 0x02060016015354494330383836325c54656368524d43
FreeRADIUS-Proxied-To =
User-Name = "STIC08862\\TechRMC"
server inner-tunnel {
# Executing section authorize from file
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
[eap] EAP packet type response id 6 length 22
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[ldap] performing user authorization for STIC08862\TechRMC
[ldap] expand: (uid=%{mschap:User-Name}) -> (uid=TechRMC)
[ldap] expand: o=CSPI -> o=CSPI
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in o=CSPI, with filter (uid=TechRMC)
[ldap] Added the eDirectory password 1234567 in check items as
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
[ldap] looking for reply items in directory...
[ldap] user STIC08862\TechRMC authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++? if (User-Name !~ /^host\/.*$/)
? Evaluating (User-Name !~ /^host\/.*$/) -> TRUE
++? if (User-Name !~ /^host\/.*$/) -> TRUE
++- entering if (User-Name !~ /^host\/.*$/) {...}
+++[control] returns ok
++- if (User-Name !~ /^host\/.*$/) returns ok
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
[peap] Got tunneled reply code 11
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x510e2245510938eb25e1ac3222e20688
[peap] Got tunneled reply RADIUS code 11
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x510e2245510938eb25e1ac3222e20688
[peap] Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 200 to port 29010
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x309c14c6369b0dd14b00d913c56dbe3f
Finished request 84.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host port 29010,
id=201, length=264
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message =
State = 0x309c14c6369b0dd14b00d913c56dbe3f
Message-Authenticator = 0x8d693684ec5593182b54ce7c3d5e7d8f
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 7 length 89
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state phase2
[peap] EAP type mschapv2
[peap] Got tunneled request
EAP-Message =
server {
PEAP: Setting User-Name to STIC08862\TechRMC
Sending tunneled request
EAP-Message =
FreeRADIUS-Proxied-To =
User-Name = "STIC08862\\TechRMC"
State = 0x510e2245510938eb25e1ac3222e20688
server inner-tunnel {
# Executing section authorize from file
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
[eap] EAP packet type response id 7 length 66
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[ldap] performing user authorization for STIC08862\TechRMC
[ldap] expand: (uid=%{mschap:User-Name}) -> (uid=TechRMC)
[ldap] expand: o=CSPI -> o=CSPI
[ldap] ldap_get_conn: Checking Id: 0
[ldap] ldap_get_conn: Got Id: 0
[ldap] performing search in o=CSPI, with filter (uid=TechRMC)
[ldap] Added the eDirectory password 1234567 in check items as
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
[ldap] looking for reply items in directory...
[ldap] user STIC08862\TechRMC authorized to use remote access
[ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++? if (User-Name !~ /^host\/.*$/)
? Evaluating (User-Name !~ /^host\/.*$/) -> TRUE
++? if (User-Name !~ /^host\/.*$/) -> TRUE
++- entering if (User-Name !~ /^host\/.*$/) {...}
+++[control] returns ok
++- if (User-Name !~ /^host\/.*$/) returns ok
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/mschapv2
[eap] processing type mschapv2
[mschapv2] # Executing group from file
[mschapv2] +- entering group MS-CHAP {...}
[mschap] ERROR: User-Name (STIC08862\TechRMC) is not the same as MS-CHAP
Name (TechRMC) from EAP-MSCHAPv2
++[mschap] returns reject
[eap] Freeing handler
++[eap] returns reject
Failed to authenticate the user.
} # server inner-tunnel
[peap] Got tunneled reply code 3
EAP-Message = 0x04070004
Message-Authenticator = 0x00000000000000000000000000000000
[peap] Got tunneled reply RADIUS code 3
EAP-Message = 0x04070004
Message-Authenticator = 0x00000000000000000000000000000000
[peap] Tunneled authentication was rejected.
[peap] FAILURE
++[eap] returns handled
Sending Access-Challenge of id 201 to port 29010
EAP-Message =
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x309c14c637940dd14b00d913c56dbe3f
Finished request 85.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host port 29010,
id=202, length=213
User-Name = "STIC08862\\TechRMC"
NAS-IP-Address =
NAS-Port = 0
Called-Station-Id = "58-16-26-AA-F7-A1:AVAYA-RESEAU"
Calling-Station-Id = "00-16-EA-C5-78-9C"
Framed-MTU = 1400
NAS-Port-Type = Wireless-802.11
Connect-Info = "CONNECT 0Mbps 802.11a"
EAP-Message =
State = 0x309c14c637940dd14b00d913c56dbe3f
Message-Authenticator = 0xf8e78209cd1bbc051781ce0db38fb367
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
[suffix] No '@' in User-Name = "STIC08862\TechRMC", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] Looking up realm "STIC08862" for User-Name = "STIC08862\TechRMC"
[ntdomain] No such realm "STIC08862"
++[ntdomain] returns noop
++? if ("%{User-Name}" =~ /^host\/.*$/)
expand: %{User-Name} -> STIC08862\TechRMC
? Evaluating ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++? if ("%{User-Name}" =~ /^host\/.*$/) -> FALSE
++[preprocess] returns ok
[eap] EAP packet type response id 8 length 38
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state send tlv failure
[peap] Received EAP-TLV response.
[peap] The users session was previously rejected: returning reject
[peap] *** This means you need to read the PREVIOUS messages in the
debug output
[peap] *** to find out the reason why the user was rejected.
[peap] *** Look for "reject" or "fail". Those earlier messages will
tell you.
[peap] *** what went wrong, and how to fix the problem.
[eap] Handler failed in EAP/peap
[eap] Failed in EAP select
++[eap] returns invalid
Failed to authenticate the user.
Using Post-Auth-Type Reject
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group REJECT {...}
[attr_filter.access_reject] expand: %{User-Name} -> STIC08862\TechRMC
attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 86 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 86
Sending Access-Reject of id 202 to port 29010
EAP-Message = 0x04080004
Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 3.7 seconds.
On 11-05-28 10:32 AM, Francois Gaudreault wrote:
> Hi Phil, and Alan,
> I will get you the debug output for Windows XP SP3 boxes (likely Monday).
> I will summarise what we have. Basically, this is a setup where the
> client is using eDirectory to authorize the users using the rlm_ldap
> module. On the windows boxes, it is configured to do PEAP using
> MSCHAPv2. When we send a host credential (ie.
> host/mycomputer.domain.tld) it will pass the authorization and during
> the authentication phase, it will use ntlm_auth to ensure that the
> machine is member of the domain. That part is working fine, the
> mschap module does its job. For the users, they have windows 7s and
> windows XPs. Windows 7 appears to be working without problems since
> the username is sent without the computer name as the domain prefix.
> The problem comes with the windows XP boxes. If we let windows send
> the credentials automatically (when novell logs in), the LDAP
> authorization will work properly, but the authentication will fail
> even if the Cleartext-Password attribute is set by the LDAP module.
> It will throw that MS-CHAP error. We also ensure that everything that
> comes from something that is not matching host/something will use the
> MS-CHAP-NTLM-Auth = No. The only way to make Windows XP work is to
> disable the "automatically send username" thing and only send the
> username without the domain name. However, the user experience will
> definitely be terrible.
> The NAS Client is an Avaya Access Point.
> Thanks for your feedbacks guys, it is appreciated. I will get you the
> debug information and the sites configuration as soon as I can.
> Have a nice weekend.
Francois Gaudreault, ing. jr
fgaudreault at :: +1.514.447.4918 (x130) ::
Inverse inc. :: Leaders behind SOGo ( and PacketFence (
More information about the Freeradius-Users
mailing list