freeradius3 authorize_group_check_query/ authorize_group_reply_query don't start

George Koulyabin georgekoulyabin at gmail.com
Thu Mar 27 09:21:32 CET 2014


Hi.

I'm using FreeRADIUS 3.0.1

The authorize_group_check_query/ authorize_group_reply_query don't start.

Listing of authorizize section:
  authorize {
#       filter_username
         preprocess
         auth_log
         chap
         mschap
         pap
         digest
         suffix
#       unix
#       files
         -sql
#       daily
         expiration
         logintime
  }


DEBUG output:

Skipping...
       Loaded module rlm_sql
Skipping...
         read_groups = yes
Skipping...
         authorize_group_check_query = "SELECT id, GroupName, Attribute, 
Value, op   FROM radius.radgroupcheck   WHERE GroupName = 
'%{Sql-Group}'   ORDER BY id"
         authorize_group_reply_query = "SELECT id, GroupName, Attribute, 
Value, op   FROM radius.radgroupreply   WHERE GroupName = 
'%{Sql-Group}'   ORDER BY id"
         group_membership_query = "SELECT GroupName FROM 
radius.radusergroup WHERE UserName='%{User-Name}' ORDER BY priority"

Skipping...

(0) sql : User found in radreply table
(0) sql :       expand: "SELECT GroupName FROM radius.radusergroup 
WHERE  UserName='%{User-Name}' ORDER BY priority" -> 'SELECT GroupName 
FROM radius.radusergroup WHERE UserName='test' ORDER BY priority'
rlm_sql (sql): Executing query: 'SELECT GroupName FROM 
radius.radusergroup WHERE UserName='test' ORDER BY priority'
rlm_sql_postgresql: Status: PGRES_TUPLES_OK
rlm_sql_postgresql: query affected rows = 1 , fields = 1
rlm_sql (sql): Released connection (2)
rlm_sql (sql): Closing connection (1): Hit idle_timeout, was idle for 
881 seconds
rlm_sql_postgresql: Socket destructor called, closing socket
rlm_sql (sql): Closing connection (0): Hit idle_timeout, was idle for 
881 seconds
rlm_sql (sql): You probably need to lower "min"
rlm_sql_postgresql: Socket destructor called, closing socket
(0)   [-sql] = ok
(0)   [expiration] = noop
(0)   [logintime] = noop
(0)  } #  authorize = ok

... End of DEBUG OUTPUT

What's wrong? Why didn't authorize_group_check_query/ 
authorize_group_reply_query start?

I tried to add Fall-Through = Yes to radreply for this user. Unsuccessfully.

Thanks.



More information about the Freeradius-Users mailing list