>> This is an issue with PAM on the client machine.  Some other module is
> doing password checking.  When the password check fails, it re-sets the
> password to "INCORRECT".  That password is then sent to the pam_radius
> module.  
> Go fix the client so that the PAM modules don't change the password.
> My /etc/pam.d/sshd file contains the following settings:

I had a similar problem today. PAM considered the user illegal because 
the uid in question was unknown on the machine to be accessed by ssh. 
Adding the user locally was required anyway, I had forgotten that on
that particular machine, there are only local accounts.

HTH (and thanx to Alan)

