Freeradius authentication using Windows via ntlm_auth and winbind

This is a discussion on Freeradius authentication using Windows via ntlm_auth and winbind within the FreeRADIUS Users forums, part of the Networking and Network Related category; This message is in MIME format. Since your mail reader does not understand this format, some or all of this ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-23-2005
Jay Ungab
 
Posts: n/a
Default Freeradius authentication using Windows via ntlm_auth and winbind

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C51960.03215C80
Content-Type: text/plain

Dear All,

I installed successfully freeradius-1.0.2 under Suse Linux 9.1 and one of
the features of freeradius is to enable the authentication using Windows
2003 via ntlm_auth and winbindd. The smbd, nmbd and winbindd are running
successfully locally. All our Windows domain users can now login
successfully to Linux Suse server. Samba integration using winbindd can
authenticate to Linux Suse server.

Under in radiusd.conf there's a line for ntlm_auth. I modified the entry and
try to change to "ntlm_auth = "/usr/bin/ntlm_auth --request-nt-key
--username=%{mschap-User-Name} --domain=%{nschap:NT-Domain}
--challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Response:-00}"
to enable to look to Windows 2003 domain. I try to use my users in Windows
2003 to dial-in but so far it's failed. But using local user can
successfully login. Any idea what wrong in my configurations? And what other
area should I check? Please help how to work this authentication. Attached
debug logs when running "radiusd -X" and during authentications using
Windows 2003 user lists.

RADIUS DEBUG LOGS:-
papillon:/usr/local/src/freeradius-1.0.2 #
/usr/local/freeradius/sbin/radiusd -X
Starting - reading configuration files ...
reread_config: reading radiusd.conf
Config: including file: /usr/local/freeradius/etc/raddb/proxy.conf
Config: including file: /usr/local/freeradius/etc/raddb/clients.conf
Config: including file: /usr/local/freeradius/etc/raddb/snmp.conf
Config: including file: /usr/local/freeradius/etc/raddb/eap.conf
Config: including file: /usr/local/freeradius/etc/raddb/sql.conf
main: prefix = "/usr/local/freeradius"
main: localstatedir = "/usr/local/freeradius/var"
main: logdir = "/usr/local/freeradius/var/log/radius"
main: libdir = "/usr/local/freeradius/lib"
main: radacctdir = "/usr/local/freeradius/var/log/radius/radacct"
main: hostname_lookups = yes
main: max_request_time = 30
main: cleanup_delay = 5
main: max_requests = 1024
main: delete_blocked_requests = 0
main: port = 1812
main: allow_core_dumps = no
main: log_stripped_names = no
main: log_file = "/usr/local/freeradius/var/log/radius/radius.log"
main: log_auth = no
main: log_auth_badpass = no
main: log_auth_goodpass = no
main: pidfile = "/usr/local/freeradius/var/run/radiusd/radiusd.pid"
main: user = "(null)"
main: group = "(null)"
main: usercollide = no
main: lower_user = "no"
main: lower_pass = "no"
main: nospace_user = "no"
main: nospace_pass = "no"
main: checkrad = "/usr/local/freeradius/sbin/checkrad"
main: proxy_requests = yes
proxy: retry_delay = 5
proxy: retry_count = 3
proxy: synchronous = no
proxy: default_fallback = yes
proxy: dead_time = 120
proxy: post_proxy_authorize = yes
proxy: wake_all_if_all_dead = no
security: max_attributes = 200
security: reject_delay = 1
security: status_server = no
main: debug_level = 0
read_config_files: reading dictionary
read_config_files: reading naslist
Using deprecated naslist file. Support for this will go away soon.
read_config_files: reading clients
read_config_files: reading realms
radiusd: entering modules setup
Module: Library search path is /usr/local/freeradius/lib
Module: Loaded exec
exec: wait = yes
exec: program = "(null)"
exec: input_pairs = "request"
exec: output_pairs = "(null)"
exec: packet_type = "(null)"
rlm_exec: Wait=yes but no output defined. Did you mean output=none?
Module: Instantiated exec (exec)
Module: Loaded expr
Module: Instantiated expr (expr)
Module: Loaded PAP
pap: encryption_scheme = "crypt"
Module: Instantiated pap (pap)
Module: Loaded CHAP
Module: Instantiated chap (chap)
Module: Loaded MS-CHAP
mschap: use_mppe = yes
mschap: require_encryption = no
mschap: require_strong = no
mschap: with_ntdomain_hack = yes
mschap: passwd = "(null)"
mschap: authtype = "MS-CHAP"
mschap: ntlm_auth = "/usr/bin/ntlm_auth --request-nt-key
--username=%{mschap-User-Name} --domain=%{nschap:NT-Domain}
--challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Response:-00}"
Module: Instantiated mschap (mschap)
Module: Loaded System
unix: cache = no
unix: passwd = "(null)"
unix: shadow = "(null)"
unix: group = "(null)"
unix: radwtmp = "/usr/local/freeradius/var/log/radius/radwtmp"
unix: usegroup = no
unix: cache_reload = 600
Module: Instantiated unix (unix)
Module: Loaded eap
eap: default_eap_type = "md5"
eap: timer_expire = 60
eap: ignore_unknown_eap_types = no
eap: cisco_accounting_username_bug = no
rlm_eap: Loaded and initialized type md5
rlm_eap: Loaded and initialized type leap
gtc: challenge = "Password: "
gtc: auth_type = "PAP"
rlm_eap: Loaded and initialized type gtc
mschapv2: with_ntdomain_hack = no
rlm_eap: Loaded and initialized type mschapv2
Module: Instantiated eap (eap)
Module: Loaded preprocess
preprocess: huntgroups = "/usr/local/freeradius/etc/raddb/huntgroups"
preprocess: hints = "/usr/local/freeradius/etc/raddb/hints"
preprocess: with_ascend_hack = no
preprocess: ascend_channels_per_line = 23
preprocess: with_ntdomain_hack = no
preprocess: with_specialix_jetstream_hack = no
preprocess: with_cisco_vsa_hack = no
Module: Instantiated preprocess (preprocess)
Module: Loaded realm
realm: format = "suffix"
realm: delimiter = "@"
realm: ignore_default = no
realm: ignore_null = no
Module: Instantiated realm (suffix)
Module: Loaded files
files: usersfile = "/usr/local/freeradius/etc/raddb/users"
files: acctusersfile = "/usr/local/freeradius/etc/raddb/acct_users"
files: preproxy_usersfile =
"/usr/local/freeradius/etc/raddb/preproxy_users"
files: compat = "no"
Module: Instantiated files (files)
Module: Loaded Acct-Unique-Session-Id
acct_unique: key = "User-Name, Acct-Session-Id, NAS-IP-Address,
Client-IP-Address, NAS-Port"
Module: Instantiated acct_unique (acct_unique)
Module: Loaded detail
detail: detailfile =
"/usr/local/freeradius/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y
%m%d"
detail: detailperm = 384
detail: dirperm = 493
detail: locking = no
Module: Instantiated detail (detail)
Module: Loaded radutmp
radutmp: filename = "/usr/local/freeradius/var/log/radius/radutmp"
radutmp: username = "%{User-Name}"
radutmp: case_sensitive = yes
radutmp: check_with_nas = yes
radutmp: perm = 384
radutmp: callerid = yes
Module: Instantiated radutmp (radutmp)
Listening on authentication *:1812
Listening on accounting *:1813
Listening on proxy *:1814
Ready to process requests.

Using user under Windows 2003:-
rad_recv: Access-Request packet from host 10.76.16.2:1645, id=255, length=76
NAS-IP-Address = 10.76.16.2
NAS-Port = 6
NAS-Port-Type = Async
User-Name = "jungab"
User-Password = "m@h@rl1k <mailto:m@h@rl1k> @"
Service-Type = Framed-User
Framed-Protocol = PPP
Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 0
modcall[authorize]: module "preprocess" returns ok for request 0
modcall[authorize]: module "chap" returns noop for request 0
modcall[authorize]: module "mschap" returns noop for request 0
rlm_realm: No '@' <mailto:'@'> in User-Name = "jungab", looking up
realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 0
rlm_eap: No EAP-Message, not doing EAP
modcall[authorize]: module "eap" returns noop for request 0
users: Matched entry DEFAULT at line 152
users: Matched entry DEFAULT at line 171
users: Matched entry DEFAULT at line 183
modcall[authorize]: module "files" returns ok for request 0
modcall: group authorize returns ok for request 0
rad_check_password: Found Auth-Type System
auth: type "System"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 0
rlm_unix: [jungab]: invalid password
modcall[authenticate]: module "unix" returns reject for request 0
modcall: group authenticate returns reject for request 0
auth: Failed to validate the user.
Delaying request 0 for 1 seconds
Finished request 0
Going to the next request
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Sending Access-Reject of id 255 to 10.76.16.2:1645
Waking up in 4 seconds...
--- Walking the entire request list ---
Cleaning up request 0 ID 255 with timestamp 421c04c2
Nothing to do. Sleeping until we see a request.

Using user under Suse Linux:-
rad_recv: Accounting-Request packet from host 10.76.16.2:1646, id=1,
length=87
NAS-IP-Address = 10.76.16.2
NAS-Port = 6
NAS-Port-Type = Async
User-Name = "jsungab"
Acct-Status-Type = Start
Acct-Authentic = RADIUS
Service-Type = Framed-User
Acct-Session-Id = "00000444"
Framed-Protocol = PPP
Acct-Delay-Time = 0
Processing the preacct section of radiusd.conf
modcall: entering group preacct for request 2
modcall[preacct]: module "preprocess" returns noop for request 2
rlm_acct_unique: Hashing 'NAS-Port = 6,Client-IP-Address =
jd3-accs1-rt.dairy-farm.com.ph,NAS-IP-Address = 10.76.16.2,Acct-Session-Id =
"00000444",User-Name = "jsungab"'
rlm_acct_unique: Acct-Unique-Session-ID = "7461be81d4b43e14".
modcall[preacct]: module "acct_unique" returns ok for request 2
rlm_realm: No '@' <mailto:'@'> in User-Name = "jsungab", looking up
realm NULL
rlm_realm: No such realm "NULL"
modcall[preacct]: module "suffix" returns noop for request 2
modcall[preacct]: module "files" returns noop for request 2
modcall: group preacct returns ok for request 2
Processing the accounting section of radiusd.conf
modcall: entering group accounting for request 2
radius_xlat:
'/usr/local/freeradius/var/log/radius/radacct/jd3-accs1-rt.dairy-farm.com.ph
/detail-20050223'
rlm_detail:
/usr/local/freeradius/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%
m%d expands to
/usr/local/freeradius/var/log/radius/radacct/jd3-accs1-rt.dairy-farm.com.ph/
detail-20050223
modcall[accounting]: module "detail" returns ok for request 2
modcall[accounting]: module "unix" returns ok for request 2
radius_xlat: '/usr/local/freeradius/var/log/radius/radutmp'
radius_xlat: 'jsungab'
modcall[accounting]: module "radutmp" returns ok for request 2
modcall: group accounting returns ok for request 2
Sending Accounting-Response of id 1 to 10.76.16.2:1646
Finished request 2



Regards,
Jay

------_=_NextPart_001_01C51960.03215C80
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<TITLE>Message</TITLE>

<META content="MSHTML 6.00.2800.1479" name=GENERATOR></HEAD>
<BODY>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005>Dear
All,</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN
class=253444703-23022005></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005>I installed
successfully freeradius-1.0.2 under Suse Linux 9.1 and one of the
features&nbsp;of freeradius&nbsp;is to&nbsp;enable the authentication&nbsp;using
Windows 2003 via ntlm_auth and winbindd. The smbd, nmbd and winbindd are
running&nbsp;successfully&nbsp;locally. All our Windows domain users can now
login successfully to Linux Suse server. Samba integration using winbindd can
authenticate to Linux Suse server.</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN
class=253444703-23022005></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005>Under in
radiusd.conf there's a line for ntlm_auth. I modified the entry and try to
change to "ntlm_auth = "/usr/bin/ntlm_auth --request-nt-key
--username=%{mschap-User-Name} --domain=%{nschap:NT-Domain}
--challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Response:-00}" to
enable to look to Windows 2003 domain. I try to use my users in Windows 2003 to
dial-in but&nbsp;so far it's failed. But&nbsp;using local user can successfully
login.&nbsp;Any idea what wrong&nbsp;in my configurations?&nbsp;And
what&nbsp;other area should I check? Please help how to work this
authentication. Attached debug logs when running "radiusd -X"&nbsp; and
during&nbsp;authentications using Windows 2003 user lists.</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN
class=253444703-23022005></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005><U><STRONG>RADIUS
DEBUG LOGS:-</STRONG></U></SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN
class=253444703-23022005>papillon:/usr/local/src/freeradius-1.0.2 #
/usr/local/freeradius/sbin/radiusd -X<BR>Starting - reading configuration files
....<BR>reread_config:&nbsp; reading radiusd.conf<BR>Config:&nbsp;&nbsp;
including file:
/usr/local/freeradius/etc/raddb/proxy.conf<BR>Config:&nbsp;&nbsp; including
file: /usr/local/freeradius/etc/raddb/clients.conf<BR>Config:&nbsp;&nbsp;
including file: /usr/local/freeradius/etc/raddb/snmp.conf<BR>Config:&nbsp;&nbsp;
including file: /usr/local/freeradius/etc/raddb/eap.conf<BR>Config:&nbsp;&nbsp;
including file: /usr/local/freeradius/etc/raddb/sql.conf<BR>&nbsp;main: prefix =
"/usr/local/freeradius"<BR>&nbsp;main: localstatedir =
"/usr/local/freeradius/var"<BR>&nbsp;main: logdir =
"/usr/local/freeradius/var/log/radius"<BR>&nbsp;main: libdir =
"/usr/local/freeradius/lib"<BR>&nbsp;main: radacctdir =
"/usr/local/freeradius/var/log/radius/radacct"<BR>&nbsp;main: hostname_lookups =
yes<BR>&nbsp;main: max_request_time = 30<BR>&nbsp;main: cleanup_delay =
5<BR>&nbsp;main: max_requests = 1024<BR>&nbsp;main: delete_blocked_requests =
0<BR>&nbsp;main: port = 1812<BR>&nbsp;main: allow_core_dumps = no<BR>&nbsp;main:
log_stripped_names = no<BR>&nbsp;main: log_file =
"/usr/local/freeradius/var/log/radius/radius.log"<BR>&nbsp;main: log_auth =
no<BR>&nbsp;main: log_auth_badpass = no<BR>&nbsp;main: log_auth_goodpass =
no<BR>&nbsp;main: pidfile =
"/usr/local/freeradius/var/run/radiusd/radiusd.pid"<BR>&nbsp;main: user =
"(null)"<BR>&nbsp;main: group = "(null)"<BR>&nbsp;main: usercollide =
no<BR>&nbsp;main: lower_user = "no"<BR>&nbsp;main: lower_pass =
"no"<BR>&nbsp;main: nospace_user = "no"<BR>&nbsp;main: nospace_pass =
"no"<BR>&nbsp;main: checkrad =
"/usr/local/freeradius/sbin/checkrad"<BR>&nbsp;main: proxy_requests =
yes<BR>&nbsp;proxy: retry_delay = 5<BR>&nbsp;proxy: retry_count =
3<BR>&nbsp;proxy: synchronous = no<BR>&nbsp;proxy: default_fallback =
yes<BR>&nbsp;proxy: dead_time = 120<BR>&nbsp;proxy: post_proxy_authorize =
yes<BR>&nbsp;proxy: wake_all_if_all_dead = no<BR>&nbsp;security: max_attributes
= 200<BR>&nbsp;security: reject_delay = 1<BR>&nbsp;security: status_server =
no<BR>&nbsp;main: debug_level = 0<BR>read_config_files:&nbsp; reading
dictionary<BR>read_config_files:&nbsp; reading naslist<BR>Using deprecated
naslist file.&nbsp; Support for this will go away
soon.<BR>read_config_files:&nbsp; reading clients<BR>read_config_files:&nbsp;
reading realms<BR>radiusd:&nbsp; entering modules setup<BR>Module: Library
search path is /usr/local/freeradius/lib<BR>Module: Loaded exec<BR>&nbsp;exec:
wait = yes<BR>&nbsp;exec: program = "(null)"<BR>&nbsp;exec: input_pairs =
"request"<BR>&nbsp;exec: output_pairs = "(null)"<BR>&nbsp;exec: packet_type =
"(null)"<BR>rlm_exec: Wait=yes but no output defined. Did you mean
output=none?<BR>Module: Instantiated exec (exec)<BR>Module: Loaded
expr<BR>Module: Instantiated expr (expr)<BR>Module: Loaded PAP<BR>&nbsp;pap:
encryption_scheme = "crypt"<BR>Module: Instantiated pap (pap)<BR>Module: Loaded
CHAP<BR>Module: Instantiated chap (chap)<BR>Module: Loaded
MS-CHAP<BR>&nbsp;mschap: use_mppe = yes<BR>&nbsp;mschap: require_encryption =
no<BR>&nbsp;mschap: require_strong = no<BR>&nbsp;mschap: with_ntdomain_hack =
yes<BR>&nbsp;mschap: passwd = "(null)"<BR>&nbsp;mschap: authtype =
"MS-CHAP"<BR>&nbsp;<STRONG>mschap: ntlm_auth = "/usr/bin/ntlm_auth
--request-nt-key --username=%{mschap-User-Name} --domain=%{nschap:NT-Domain}
--challenge=%{mschap:Challenge:-00}
--nt-response=%{mschap:NT-Response:-00}"<BR></STRONG>Module: Instantiated mschap
(mschap)<BR>Module: Loaded System<BR>&nbsp;unix: cache = no<BR>&nbsp;unix:
passwd = "(null)"<BR>&nbsp;unix: shadow = "(null)"<BR>&nbsp;unix: group =
"(null)"<BR>&nbsp;unix: radwtmp =
"/usr/local/freeradius/var/log/radius/radwtmp"<BR>&nbsp;unix: usegroup =
no<BR>&nbsp;unix: cache_reload = 600<BR>Module: Instantiated unix
(unix)<BR>Module: Loaded eap<BR>&nbsp;eap: default_eap_type =
"md5"<BR>&nbsp;eap: timer_expire = 60<BR>&nbsp;eap: ignore_unknown_eap_types =
no<BR>&nbsp;eap: cisco_accounting_username_bug = no<BR>rlm_eap: Loaded and
initialized type md5<BR>rlm_eap: Loaded and initialized type leap<BR>&nbsp;gtc:
challenge = "Password: "<BR>&nbsp;gtc: auth_type = "PAP"<BR>rlm_eap: Loaded and
initialized type gtc<BR>&nbsp;mschapv2: with_ntdomain_hack = no<BR>rlm_eap:
Loaded and initialized type mschapv2<BR>Module: Instantiated eap
(eap)<BR>Module: Loaded preprocess<BR>&nbsp;preprocess: huntgroups =
"/usr/local/freeradius/etc/raddb/huntgroups"<BR>&nbsp;preprocess: hints =
"/usr/local/freeradius/etc/raddb/hints"<BR>&nbsp;preprocess: with_ascend_hack =
no<BR>&nbsp;preprocess: ascend_channels_per_line = 23<BR>&nbsp;preprocess:
with_ntdomain_hack = no<BR>&nbsp;preprocess: with_specialix_jetstream_hack =
no<BR>&nbsp;preprocess: with_cisco_vsa_hack = no<BR>Module: Instantiated
preprocess (preprocess)<BR>Module: Loaded realm<BR>&nbsp;realm: format =
"suffix"<BR>&nbsp;realm: delimiter = "@"<BR>&nbsp;realm: ignore_default =
no<BR>&nbsp;realm: ignore_null = no<BR>Module: Instantiated realm
(suffix)<BR>Module: Loaded files<BR>&nbsp;files: usersfile =
"/usr/local/freeradius/etc/raddb/users"<BR>&nbsp;files: acctusersfile =
"/usr/local/freeradius/etc/raddb/acct_users"<BR>&nbsp;files: preproxy_usersfile
= "/usr/local/freeradius/etc/raddb/preproxy_users"<BR>&nbsp;files: compat =
"no"<BR>Module: Instantiated files (files)<BR>Module: Loaded
Acct-Unique-Session-Id<BR>&nbsp;acct_unique: key = "User-Name, Acct-Session-Id,
NAS-IP-Address, Client-IP-Address, NAS-Port"<BR>Module: Instantiated acct_unique
(acct_unique)<BR>Module: Loaded detail<BR>&nbsp;detail: detailfile =
"/usr/local/freeradius/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d"<BR>&nbsp;detail:
detailperm = 384<BR>&nbsp;detail: dirperm = 493<BR>&nbsp;detail: locking =
no<BR>Module: Instantiated detail (detail)<BR>Module: Loaded
radutmp<BR>&nbsp;radutmp: filename =
"/usr/local/freeradius/var/log/radius/radutmp"<BR>&nbsp;radutmp: username =
"%{User-Name}"<BR>&nbsp;radutmp: case_sensitive = yes<BR>&nbsp;radutmp:
check_with_nas = yes<BR>&nbsp;radutmp: perm = 384<BR>&nbsp;radutmp: callerid =
yes<BR>Module: Instantiated radutmp (radutmp)<BR>Listening on authentication
*:1812<BR>Listening on accounting *:1813<BR>Listening on proxy *:1814<BR>Ready
to process requests.<BR></SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005><U><STRONG>Using
user under Windows 2003:-</STRONG></U></DIV></SPAN></FONT>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005>rad_recv:
Access-Request packet from host 10.76.16.2:1645, id=255,
length=76<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;& nbsp; NAS-IP-Address =
10.76.16.2<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; NAS-Port =
6<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NAS-Port-Type =
Async<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp ; User-Name =
"jungab"<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n bsp; User-Password = "<A
href="mailto:m@h@rl1k">m@h@rl1k</A>@"<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp ;
Service-Type = Framed-User<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
Framed-Protocol = PPP<BR>&nbsp; Processing the authorize section of
radiusd.conf<BR>modcall: entering group authorize for request 0<BR>&nbsp;
modcall[authorize]: module "preprocess" returns ok for request 0<BR>&nbsp;
modcall[authorize]: module "chap" returns noop for request 0<BR>&nbsp;
modcall[authorize]: module "mschap" returns noop for request
0<BR>&nbsp;&nbsp;&nbsp; rlm_realm: No <A href="mailto:'@'">'@'</A> in User-Name
= "jungab", looking up realm NULL<BR>&nbsp;&nbsp;&nbsp; rlm_realm: No such realm
"NULL"<BR>&nbsp; modcall[authorize]: module "suffix" returns noop for request
0<BR>&nbsp; rlm_eap: No EAP-Message, not doing EAP<BR>&nbsp; modcall[authorize]:
module "eap" returns noop for request 0<BR>&nbsp;&nbsp;&nbsp; users: Matched
entry DEFAULT at line 152<BR>&nbsp;&nbsp;&nbsp; users: Matched entry DEFAULT at
line 171<BR>&nbsp;&nbsp;&nbsp; users: Matched entry DEFAULT at line
183<BR>&nbsp; modcall[authorize]: module "files" returns ok for request
0<BR>modcall: group authorize returns ok for request 0<BR>&nbsp;
rad_check_password:&nbsp; Found Auth-Type System<BR>auth: type
"System"<BR>&nbsp; Processing the authenticate section of
radiusd.conf<BR>modcall: entering group authenticate for request 0<BR>rlm_unix:
[jungab]: invalid password<BR>&nbsp; modcall[authenticate]: module "unix"
returns reject for request 0<BR>modcall: group authenticate returns reject for
request 0<BR>auth: Failed to validate the user.<BR>Delaying request 0 for 1
seconds<BR>Finished request 0<BR>Going to the next request<BR>--- Walking the
entire request list ---<BR>Waking up in 1 seconds...<BR>--- Walking the entire
request list ---<BR>Waking up in 1 seconds...<BR>--- Walking the entire request
list ---<BR>Sending Access-Reject of id 255 to 10.76.16.2:1645<BR>Waking up in 4
seconds...<BR>--- Walking the entire request list ---<BR>Cleaning up request 0
ID 255 with timestamp 421c04c2<BR>Nothing to do.&nbsp; Sleeping until we see a
request.<BR></SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005><U><STRONG>Using
user under Suse Linux:-</STRONG></U></DIV></SPAN></FONT>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005>rad_recv:
Accounting-Request packet from host 10.76.16.2:1646, id=1,
length=87<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;& nbsp; NAS-IP-Address =
10.76.16.2<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; NAS-Port =
6<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NAS-Port-Type =
Async<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp ; User-Name =
"jsungab"<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;& nbsp; Acct-Status-Type =
Start<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp ; Acct-Authentic =
RADIUS<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs p; Service-Type =
Framed-User<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Acct-Session-Id =
"00000444"<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; Framed-Protocol =
PPP<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Acct-Delay-Time = 0<BR>&nbsp;
Processing the preacct section of radiusd.conf<BR>modcall: entering group
preacct for request 2<BR>&nbsp; modcall[preacct]: module "preprocess" returns
noop for request 2<BR>rlm_acct_unique: Hashing 'NAS-Port = 6,Client-IP-Address =
jd3-accs1-rt.dairy-farm.com.ph,NAS-IP-Address = 10.76.16.2,Acct-Session-Id =
"00000444",User-Name = "jsungab"'<BR>rlm_acct_unique: Acct-Unique-Session-ID =
"7461be81d4b43e14".<BR>&nbsp; modcall[preacct]: module "acct_unique" returns ok
for request 2<BR>&nbsp;&nbsp;&nbsp; rlm_realm: No <A href="mailto:'@'">'@'</A>
in User-Name = "jsungab", looking up realm NULL<BR>&nbsp;&nbsp;&nbsp; rlm_realm:
No such realm "NULL"<BR>&nbsp; modcall[preacct]: module "suffix" returns noop
for request 2<BR>&nbsp; modcall[preacct]: module "files" returns noop for
request 2<BR>modcall: group preacct returns ok for request 2<BR>&nbsp;
Processing the accounting section of radiusd.conf<BR>modcall: entering group
accounting for request 2<BR>radius_xlat:&nbsp;
'/usr/local/freeradius/var/log/radius/radacct/jd3-accs1-rt.dairy-farm.com.ph/detail-20050223'<BR>rlm_detail:
/usr/local/freeradius/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d
expands to
/usr/local/freeradius/var/log/radius/radacct/jd3-accs1-rt.dairy-farm.com.ph/detail-20050223<BR>&nbsp;
modcall[accounting]: module "detail" returns ok for request 2<BR>&nbsp;
modcall[accounting]: module "unix" returns ok for request
2<BR>radius_xlat:&nbsp;
'/usr/local/freeradius/var/log/radius/radutmp'<BR>radius_xlat:&nbsp;
'jsungab'<BR>&nbsp; modcall[accounting]: module "radutmp" returns ok for request
2<BR>modcall: group accounting returns ok for request 2<BR>Sending
Accounting-Response of id 1 to 10.76.16.2:1646<BR>Finished request
2<BR></DIV></SPAN></FONT>
<DIV><FONT face=Arial size=2><SPAN
class=253444703-23022005>&nbsp;</DIV></SPAN></FONT>
<DIV><FONT face=Arial size=2><SPAN class=253444703-23022005></SPAN></FONT><FONT
face=Arial size=2><SPAN class=253444703-23022005></SPAN></FONT><FONT face=Arial
size=2><SPAN class=253444703-23022005></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN
class=253444703-23022005>Regards,</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN
class=253444703-23022005>Jay</SPAN></FONT></DIV></BODY></HTML>

------_=_NextPart_001_01C51960.03215C80--

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:43 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0