a problem about radius and ldap

This is a discussion on a problem about radius and ldap within the FreeRADIUS Users forums, part of the Networking and Network Related category; --===============0098988190== Content-Type: multipart/alternative; boundary="----=_Part_46206_30481752.1170064338638" ------=_Part_46206_30481752.1170064338638 Content-Type: text/plain; charset=ISO-8859-1; ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-29-2007
Ramazan Ulker
 
Posts: n/a
Default a problem about radius and ldap

--===============0098988190==
Content-Type: multipart/alternative;
boundary="----=_Part_46206_30481752.1170064338638"

------=_Part_46206_30481752.1170064338638
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Hi

I'm working on 802.1x implementation(cisco 2950, freeradius, ldap), i face a
problem. First of all, defining users and passwords in users file in raddb
works well with md5 authentication. Then i tried to use ldap, then with
radtest i get accept-accept packet. But while authenticating from xp client
with md5-challenge, I got

Auth:rlm_ldap:Attribute "User-Password" is required for authentication

error. In one of the e-mail you said don't authenticate from ldap, but with
radtest function i get success!!! The passwords are kept clear text. I'm
looking forward to getting your help. I also send radius debug log.

Best Regards

Ramazan





Starting - reading configuration files ...

reread_config: reading radiusd.conf

Config: including file: /etc/raddb/proxy.conf

Config: including file: /etc/raddb/clients.conf

Config: including file: /etc/raddb/snmp.conf

Config: including file: /etc/raddb/sql.conf

main: prefix = "/usr"

main: localstatedir = "/var"

main: logdir = "/var/log/radius"

main: libdir = "/usr/lib/freeradius"

main: radacctdir = "/var/log/radius/radacct"

main: hostname_lookups = no

main: max_request_time = 30

main: cleanup_delay = 5

main: max_requests = 1024

main: delete_blocked_requests = 0

main: port = 0

main: allow_core_dumps = no

main: log_stripped_names = yes

main: log_file = "/var/log/radius/radius.log"

main: log_auth = yes

main: log_auth_badpass = yes

main: log_auth_goodpass = yes

main: pidfile = "/var/run/radiusd/radiusd.pid"

main: user = "radiusd"

main: group = "radiusd"

main: usercollide = no

main: lower_user = "no"

main: lower_pass = "no"

main: nospace_user = "no"

main: nospace_pass = "no"

main: checkrad = "/usr/sbin/checkrad"

main: proxy_requests = yes

proxy: retry_delay = 5

proxy: retry_count = 3

proxy: synchronous = no

proxy: default_fallback = yes

proxy: dead_time = 120

proxy: post_proxy_authorize = yes

proxy: wake_all_if_all_dead = no

security: max_attributes = 200

security: reject_delay = 1

security: status_server = no

main: debug_level = 0

read_config_files: reading dictionary

read_config_files: reading naslist

read_config_files: reading clients

read_config_files: reading realms

radiusd: entering modules setup

Module: Library search path is /usr/lib/freeradius

Module: Loaded expr

Module: Instantiated expr (expr)

Module: Loaded PAP

pap: encryption_scheme = "crypt"

Module: Instantiated pap (pap)

Module: Loaded CHAP

Module: Instantiated chap (chap)

Module: Loaded MS-CHAP

mschap: use_mppe = yes

mschap: require_encryption = no

mschap: require_strong = no

mschap: passwd = "(null)"

mschap: authtype = "MS-CHAP"

Module: Instantiated mschap (mschap)

Module: Loaded System

unix: cache = no

unix: passwd = "(null)"

unix: shadow = "(null)"

unix: group = "(null)"

unix: radwtmp = "/var/log/radius/radwtmp"

unix: usegroup = no

unix: cache_reload = 600

Module: Instantiated unix (unix)

Module: Loaded LDAP

ldap: server = "192.168.100.18"

ldap: port = 389

ldap: net_timeout = 1

ldap: timeout = 4

ldap: timelimit = 3

ldap: identity = ""

ldap: start_tls = no

ldap: password = ""

ldap: basedn = "dc=dot1x.com"

ldap: filter = "(uid=%{Stripped-User-Name:-%{User-Name}})"

ldap: default_profile = "(null)"

ldap: profile_attribute = "(null)"

ldap: password_header = "(null)"

ldap: password_attribute = "userPassword"

ldap: access_attr = "radiusgroupname"

ldap: groupname_attribute = "cn"

ldap: groupmembership_filter =
"(|(&(objectClass=GroupOfNames)(member=%{Ldap-UserDn}))(&(objectClass=GroupOfUniqueNames)(unique member=%{Ldap-UserDn})))"

ldap: groupmembership_attribute = "radiusGroupName"

ldap: dictionary_mapping = "/etc/raddb/ldap.attrmap"

ldap: ldap_debug = 0

ldap: ldap_connections_number = 5

ldap: compare_check_items = no

ldap: access_attr_used_for_allow = yes

conns: (nil)

rlm_ldap: reading ldap<->radius mappings from file /etc/raddb/ldap.attrmap

rlm_ldap: LDAP radiusCheckItem mapped to RADIUS $GENERIC$

rlm_ldap: LDAP radiusReplyItem mapped to RADIUS $GENERIC$

rlm_ldap: LDAP radiusAuthType mapped to RADIUS Auth-Type

rlm_ldap: LDAP radiusSimultaneousUse mapped to RADIUS Simultaneous-Use

rlm_ldap: LDAP radiusCalledStationId mapped to RADIUS Called-Station-Id

rlm_ldap: LDAP radiusCallingStationId mapped to RADIUS Calling-Station-Id

rlm_ldap: LDAP lmPassword mapped to RADIUS LM-Password

rlm_ldap: LDAP ntPassword mapped to RADIUS NT-Password

rlm_ldap: LDAP acctFlags mapped to RADIUS SMB-Account-CTRL-TEXT

rlm_ldap: LDAP radiusExpiration mapped to RADIUS Expiration

rlm_ldap: LDAP radiusServiceType mapped to RADIUS Service-Type

rlm_ldap: LDAP radiusFramedProtocol mapped to RADIUS Framed-Protocol

rlm_ldap: LDAP radiusFramedIPAddress mapped to RADIUS Framed-IP-Address

rlm_ldap: LDAP radiusFramedIPNetmask mapped to RADIUS Framed-IP-Netmask

rlm_ldap: LDAP radiusFramedRoute mapped to RADIUS Framed-Route

rlm_ldap: LDAP radiusFramedRouting mapped to RADIUS Framed-Routing

rlm_ldap: LDAP radiusFilterId mapped to RADIUS Filter-Id

rlm_ldap: LDAP radiusFramedMTU mapped to RADIUS Framed-MTU

rlm_ldap: LDAP radiusFramedCompression mapped to RADIUS Framed-Compression

rlm_ldap: LDAP radiusLoginIPHost mapped to RADIUS Login-IP-Host

rlm_ldap: LDAP radiusLoginService mapped to RADIUS Login-Service

rlm_ldap: LDAP radiusLoginTCPPort mapped to RADIUS Login-TCP-Port

rlm_ldap: LDAP radiusCallbackNumber mapped to RADIUS Callback-Number

rlm_ldap: LDAP radiusCallbackId mapped to RADIUS Callback-Id

rlm_ldap: LDAP radiusFramedIPXNetwork mapped to RADIUS Framed-IPX-Network

rlm_ldap: LDAP radiusClass mapped to RADIUS Class

rlm_ldap: LDAP radiusSessionTimeout mapped to RADIUS Session-Timeout

rlm_ldap: LDAP radiusIdleTimeout mapped to RADIUS Idle-Timeout

rlm_ldap: LDAP radiusTerminationAction mapped to RADIUS Termination-Action

rlm_ldap: LDAP radiusLoginLATService mapped to RADIUS Login-LAT-Service

rlm_ldap: LDAP radiusLoginLATNode mapped to RADIUS Login-LAT-Node

rlm_ldap: LDAP radiusLoginLATGroup mapped to RADIUS Login-LAT-Group

rlm_ldap: LDAP radiusFramedAppleTalkLink mapped to RADIUS
Framed-AppleTalk-Link

rlm_ldap: LDAP radiusFramedAppleTalkNetwork mapped to RADIUS
Framed-AppleTalk-Network

rlm_ldap: LDAP radiusFramedAppleTalkZone mapped to RADIUS
Framed-AppleTalk-Zone

rlm_ldap: LDAP radiusPortLimit mapped to RADIUS Port-Limit

rlm_ldap: LDAP radiusLoginLATPort mapped to RADIUS Login-LAT-Port

rlm_ldap: LDAP userPassword mapped to RADIUS User-Password

rlm_ldap: LDAP radiusTunnelType mapped to RADIUS Tunnel-Type

rlm_ldap: LDAP radiusTunnelMediumType mapped to RADIUS Tunnel-Medium-Type

rlm_ldap: LDAP radiusTunnelPrivateGroupId mapped to RADIUS
Tunnel-Private-Group-Id

conns: 0x8101f58

Module: Instantiated ldap (ldap)

Module: Loaded eap

eap: default_eap_type = "md5"

eap: timer_expire = 60

rlm_eap: Loaded and initialized the type md5

rlm_eap: Loaded and initialized the type leap

Module: Instantiated eap (eap)

Module: Loaded preprocess

preprocess: huntgroups = "/etc/raddb/huntgroups"

preprocess: hints = "/etc/raddb/hints"

preprocess: with_ascend_hack = no

preprocess: ascend_channels_per_line = 23

preprocess: with_ntdomain_hack = no

preprocess: with_specialix_jetstream_hack = no

preprocess: with_cisco_vsa_hack = no

Module: Instantiated preprocess (preprocess)

Module: Loaded realm

realm: format = "suffix"

realm: delimiter = "@"

Module: Instantiated realm (suffix)

Module: Loaded files

files: usersfile = "/etc/raddb/users"

files: acctusersfile = "/etc/raddb/acct_users"

files: preproxy_usersfile = "/etc/raddb/preproxy_users"

files: compat = "no"

Module: Instantiated files (files)

Module: Loaded Acct-Unique-Session-Id

acct_unique: key = "User-Name, Acct-Session-Id, NAS-IP-Address,
Client-IP-Address, NAS-Port-Id"

Module: Instantiated acct_unique (acct_unique)

Module: Loaded detail

detail: detailfile =
"/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d"

detail: detailperm = 384

detail: dirperm = 493

detail: locking = no

Module: Instantiated detail (detail)

Module: Loaded radutmp

radutmp: filename = "/var/log/radius/radutmp"

radutmp: username = "%{User-Name}"

radutmp: case_sensitive = yes

radutmp: check_with_nas = yes

radutmp: perm = 384

radutmp: callerid = yes

Module: Instantiated radutmp (radutmp)

Listening on IP address *, ports 1812/udp and 1813/udp, with proxy on
1814/udp.

Ready to process requests.

rad_recv: Access-Request packet from host 192.168.100.17:1812, id=11,
length=129

NAS-IP-Address = 192.168.100.17

NAS-Port = 50001

NAS-Port-Type = Ethernet

User-Name = "ramazan"

Called-Station-Id = "00-0F-8F-77-DB-81"

Calling-Station-Id = "00-12-79-AE-D2-4D"

Service-Type = Framed-User

Framed-MTU = 1500

EAP-Message = 0x0200000c0172616d617a616e

Message-Authenticator = 0x68c41631d4feb2234d900b37a9845348

modcall: entering group authorize for request 0

modcall[authorize]: module "preprocess" returns ok for request 0

modcall[authorize]: module "chap" returns noop for request 0

rlm_eap: EAP packet type notification id 0 length 12

rlm_eap: EAP Start not found

modcall[authorize]: module "eap" returns updated for request 0

rlm_realm: No '@' in User-Name = "ramazan", looking up realm NULL

rlm_realm: No such realm "NULL"

modcall[authorize]: module "suffix" returns noop for request 0

users: Matched DEFAULT at 152

rlm_ldap: Entering ldap_groupcmp()

radius_xlat: 'dc=dot1x.com'

radius_xlat: '(uid=ramazan)'

ldap_get_conn: Got Id: 0

rlm_ldap: attempting LDAP reconnection

rlm_ldap: (re)connect to 192.168.100.18:389, authentication 0

rlm_ldap: bind as / to 192.168.100.18:389

rlm_ldap: waiting for bind result ...

rlm_ldap: performing search in dc=dot1x.com, with filter (uid=ramazan)

ldap_release_conn: Release Id: 0

radius_xlat:
'(|(&(objectClass=GroupOfNames)(member=uid=ramazan ,cn=users,cn=idc,dc=
dot1x.com
))(&(objectClass=GroupOfUniqueNames)(uniquemember= uid=ramazan,cn=users,cn=idc,dc=dot1x.com
)))'

ldap_get_conn: Got Id: 0

rlm_ldap: performing search in dc=dot1x.com, with filter
(&(cn=VPN)(|(&(objectClass=GroupOfNames)(member=ui d=ramazan,cn=users,cn=idc,dc=
dot1x.com))(&(objectClass=GroupOfUniqueNames)(uniq uemember=uid=ramazan,cn=users,cn=idc,dc=
dot1x.com))))

rlm_ldap: object not found or got ambiguous search result

ldap_release_conn: Release Id: 0

ldap_get_conn: Got Id: 0

rlm_ldap: performing search in uid=ramazan,cn=users,cn=idc,dc=dot1x.com,
with filter (objectclass=*)

rlm_ldap::ldap_groupcmp: User found in group VPN

ldap_release_conn: Release Id: 0

users: Matched DEFAULT at 171

modcall[authorize]: module "files" returns ok for request 0

modcall[authorize]: module "mschap" returns noop for request 0

rlm_ldap: - authorize

rlm_ldap: performing user authorization for ramazan

radius_xlat: '(uid=ramazan)'

radius_xlat: 'dc=dot1x.com'

ldap_get_conn: Got Id: 0

rlm_ldap: performing search in dc=dot1x.com, with filter (uid=ramazan)

rlm_ldap: checking if remote access for ramazan is allowed by
radiusgroupname

rlm_ldap: looking for check items in directory...

rlm_ldap: Adding radiusAuthType as Auth-Type, value ldap & op=21

rlm_ldap: looking for reply items in directory...

rlm_ldap: Adding radiusTunnelPrivateGroupId as Tunnel-Private-Group-Id,
value 2 & op=11

rlm_ldap: Adding radiusTunnelMediumType as Tunnel-Medium-Type, value 6 &
op=11

rlm_ldap: Adding radiusTunnelType as Tunnel-Type, value VLAN & op=11

rlm_ldap: Adding radiusClass as Class, value group-net & op=11

rlm_ldap: user ramazan authorized to use remote access

ldap_release_conn: Release Id: 0

modcall[authorize]: module "ldap" returns ok for request 0

modcall: group authorize returns updated for request 0

rad_check_password: Found Auth-Type ldap

auth: type "LDAP"

modcall: entering group Auth-Type for request 0

rlm_ldap: - authenticate

rlm_ldap: Attribute "User-Password" is required for authentication.

modcall[authenticate]: module "ldap" returns invalid for request 0

modcall: group Auth-Type returns invalid for request 0

auth: Failed to validate the user.

Login incorrect: [ramazan/<no User-Password attribute>] (from client radius
port 50001 cli 00-12-79-AE-D2-4D)

Delaying request 0 for 1 seconds

Finished request 0

Going to the next request

--- Walking the entire request list ---

Waking up in 1 seconds...

--- Walking the entire request list ---

Waking up in 1 seconds...

--- Walking the entire request list ---

Sending Access-Reject of id 11 to 192.168.100.17:1812

Waking up in 4 seconds...

------=_Part_46206_30481752.1170064338638
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

<div id="mb_0">
<p>Hi </p>
<p>I'm working on 802.1x implementation(cisco 2950, freeradius, ldap), i face a problem. First of all, defining users and passwords in users file in raddb works well with md5 authentication. Then i tried to use ldap,&nbsp;then with radtest i get accept-accept packet. But while authenticating from xp client with md5-challenge, I got
</p>
<p>Auth:rlm_ldap:Attribute &quot;User-Password&quot; is required for authentication </p>
<p>error. In one of the&nbsp;e-mail you said don't authenticate from ldap, but with radtest function i get success!!! The passwords are kept clear text. I'm looking forward to getting your help. I also send radius debug log.
</p>
<p>Best Regards </p>
<p>Ramazan</p><font face="Arial TUR" size="2">
<p>&nbsp;</p>
<p>&nbsp;</p></font><font face="Courier New" size="2">
<p>Starting - reading configuration files ...</p>
<p>reread_config: reading radiusd.conf</p>
<p>Config: including file: /etc/raddb/proxy.conf</p>
<p>Config: including file: /etc/raddb/clients.conf</p>
<p>Config: including file: /etc/raddb/snmp.conf</p>
<p>Config: including file: /etc/raddb/sql.conf</p>
<p>main: prefix = &quot;/usr&quot;</p>
<p>main: localstatedir = &quot;/var&quot;</p>
<p>main: logdir = &quot;/var/log/radius&quot;</p>
<p>main: libdir = &quot;/usr/lib/freeradius&quot;</p>
<p>main: radacctdir = &quot;/var/log/radius/radacct&quot;</p>
<p>main: hostname_lookups = no</p>
<p>main: max_request_time = 30</p>
<p>main: cleanup_delay = 5</p>
<p>main: max_requests = 1024</p>
<p>main: delete_blocked_requests = 0</p>
<p>main: port = 0</p>
<p>main: allow_core_dumps = no</p>
<p>main: log_stripped_names = yes</p>
<p>main: log_file = &quot;/var/log/radius/radius.log&quot;</p>
<p>main: log_auth = yes</p>
<p>main: log_auth_badpass = yes</p>
<p>main: log_auth_goodpass = yes</p>
<p>main: pidfile = &quot;/var/run/radiusd/radiusd.pid&quot;</p>
<p>main: user = &quot;radiusd&quot;</p>
<p>main: group = &quot;radiusd&quot;</p>
<p>main: usercollide = no</p>
<p>main: lower_user = &quot;no&quot;</p>
<p>main: lower_pass = &quot;no&quot;</p>
<p>main: nospace_user = &quot;no&quot;</p>
<p>main: nospace_pass = &quot;no&quot;</p>
<p>main: checkrad = &quot;/usr/sbin/checkrad&quot;</p>
<p>main: proxy_requests = yes</p>
<p>proxy: retry_delay = 5</p>
<p>proxy: retry_count = 3</p>
<p>proxy: synchronous = no</p>
<p>proxy: default_fallback = yes</p>
<p>proxy: dead_time = 120</p>
<p>proxy: post_proxy_authorize = yes</p>
<p>proxy: wake_all_if_all_dead = no</p>
<p>security: max_attributes = 200</p>
<p>security: reject_delay = 1</p>
<p>security: status_server = no</p>
<p>main: debug_level = 0</p>
<p>read_config_files: reading dictionary</p>
<p>read_config_files: reading naslist</p>
<p>read_config_files: reading clients</p>
<p>read_config_files: reading realms</p>
<p>radiusd: entering modules setup</p>
<p>Module: Library search path is /usr/lib/freeradius</p>
<p>Module: Loaded expr </p>
<p>Module: Instantiated expr (expr) </p>
<p>Module: Loaded PAP </p>
<p>pap: encryption_scheme = &quot;crypt&quot;</p>
<p>Module: Instantiated pap (pap) </p>
<p>Module: Loaded CHAP </p>
<p>Module: Instantiated chap (chap) </p>
<p>Module: Loaded MS-CHAP </p>
<p>mschap: use_mppe = yes</p>
<p>mschap: require_encryption = no</p>
<p>mschap: require_strong = no</p>
<p>mschap: passwd = &quot;(null)&quot;</p>
<p>mschap: authtype = &quot;MS-CHAP&quot;</p>
<p>Module: Instantiated mschap (mschap) </p>
<p>Module: Loaded System </p>
<p>unix: cache = no</p>
<p>unix: passwd = &quot;(null)&quot;</p>
<p>unix: shadow = &quot;(null)&quot;</p>
<p>unix: group = &quot;(null)&quot;</p>
<p>unix: radwtmp = &quot;/var/log/radius/radwtmp&quot;</p>
<p>unix: usegroup = no</p>
<p>unix: cache_reload = 600</p>
<p>Module: Instantiated unix (unix) </p>
<p>Module: Loaded LDAP </p>
<p>ldap: server = &quot;<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.100.18/" target="_blank">192.168.100.18</a>&quot;</p>
<p>ldap: port = 389</p>
<p>ldap: net_timeout = 1</p>
<p>ldap: timeout = 4</p>
<p>ldap: timelimit = 3</p>
<p>ldap: identity = &quot;&quot;</p>
<p>ldap: start_tls = no</p>
<p>ldap: password = &quot;&quot;</p>
<p>ldap: basedn = &quot;dc=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>&quot;</p>
<p>ldap: filter = &quot;(uid=%{Stripped-User-Name:-%{User-Name}})&quot;</p>
<p>ldap: default_profile = &quot;(null)&quot;</p>
<p>ldap: profile_attribute = &quot;(null)&quot;</p>
<p>ldap: password_header = &quot;(null)&quot;</p>
<p>ldap: password_attribute = &quot;userPassword&quot;</p>
<p>ldap: access_attr = &quot;radiusgroupname&quot;</p>
<p>ldap: groupname_attribute = &quot;cn&quot;</p>
<p>ldap: groupmembership_filter = &quot;(|(&amp;(objectClass=GroupOfNames)(member=%{ Ldap-UserDn}))(&amp;(objectClass=GroupOfUniqueNames)(un iquemember=%{Ldap-UserDn})))&quot;</p>
<p>ldap: groupmembership_attribute = &quot;radiusGroupName&quot;</p>
<p>ldap: dictionary_mapping = &quot;/etc/raddb/ldap.attrmap&quot;</p>
<p>ldap: ldap_debug = 0</p>
<p>ldap: ldap_connections_number = 5</p>
<p>ldap: compare_check_items = no</p>
<p>ldap: access_attr_used_for_allow = yes</p>
<p>conns: (nil)</p>
<p>rlm_ldap: reading ldap&lt;-&gt;radius mappings from file /etc/raddb/ldap.attrmap</p>
<p>rlm_ldap: LDAP radiusCheckItem mapped to RADIUS $GENERIC$</p>
<p>rlm_ldap: LDAP radiusReplyItem mapped to RADIUS $GENERIC$</p>
<p>rlm_ldap: LDAP radiusAuthType mapped to RADIUS Auth-Type</p>
<p>rlm_ldap: LDAP radiusSimultaneousUse mapped to RADIUS Simultaneous-Use</p>
<p>rlm_ldap: LDAP radiusCalledStationId mapped to RADIUS Called-Station-Id</p>
<p>rlm_ldap: LDAP radiusCallingStationId mapped to RADIUS Calling-Station-Id</p>
<p>rlm_ldap: LDAP lmPassword mapped to RADIUS LM-Password</p>
<p>rlm_ldap: LDAP ntPassword mapped to RADIUS NT-Password</p>
<p>rlm_ldap: LDAP acctFlags mapped to RADIUS SMB-Account-CTRL-TEXT</p>
<p>rlm_ldap: LDAP radiusExpiration mapped to RADIUS Expiration</p>
<p>rlm_ldap: LDAP radiusServiceType mapped to RADIUS Service-Type</p>
<p>rlm_ldap: LDAP radiusFramedProtocol mapped to RADIUS Framed-Protocol</p>
<p>rlm_ldap: LDAP radiusFramedIPAddress mapped to RADIUS Framed-IP-Address</p>
<p>rlm_ldap: LDAP radiusFramedIPNetmask mapped to RADIUS Framed-IP-Netmask</p>
<p>rlm_ldap: LDAP radiusFramedRoute mapped to RADIUS Framed-Route</p>
<p>rlm_ldap: LDAP radiusFramedRouting mapped to RADIUS Framed-Routing</p>
<p>rlm_ldap: LDAP radiusFilterId mapped to RADIUS Filter-Id</p>
<p>rlm_ldap: LDAP radiusFramedMTU mapped to RADIUS Framed-MTU</p>
<p>rlm_ldap: LDAP radiusFramedCompression mapped to RADIUS Framed-Compression</p>
<p>rlm_ldap: LDAP radiusLoginIPHost mapped to RADIUS Login-IP-Host</p>
<p>rlm_ldap: LDAP radiusLoginService mapped to RADIUS Login-Service</p>
<p>rlm_ldap: LDAP radiusLoginTCPPort mapped to RADIUS Login-TCP-Port</p>
<p>rlm_ldap: LDAP radiusCallbackNumber mapped to RADIUS Callback-Number</p>
<p>rlm_ldap: LDAP radiusCallbackId mapped to RADIUS Callback-Id</p>
<p>rlm_ldap: LDAP radiusFramedIPXNetwork mapped to RADIUS Framed-IPX-Network</p>
<p>rlm_ldap: LDAP radiusClass mapped to RADIUS Class</p>
<p>rlm_ldap: LDAP radiusSessionTimeout mapped to RADIUS Session-Timeout</p>
<p>rlm_ldap: LDAP radiusIdleTimeout mapped to RADIUS Idle-Timeout</p>
<p>rlm_ldap: LDAP radiusTerminationAction mapped to RADIUS Termination-Action</p>
<p>rlm_ldap: LDAP radiusLoginLATService mapped to RADIUS Login-LAT-Service</p>
<p>rlm_ldap: LDAP radiusLoginLATNode mapped to RADIUS Login-LAT-Node</p>
<p>rlm_ldap: LDAP radiusLoginLATGroup mapped to RADIUS Login-LAT-Group</p>
<p>rlm_ldap: LDAP radiusFramedAppleTalkLink mapped to RADIUS Framed-AppleTalk-Link</p>
<p>rlm_ldap: LDAP radiusFramedAppleTalkNetwork mapped to RADIUS Framed-AppleTalk-Network</p>
<p>rlm_ldap: LDAP radiusFramedAppleTalkZone mapped to RADIUS Framed-AppleTalk-Zone</p>
<p>rlm_ldap: LDAP radiusPortLimit mapped to RADIUS Port-Limit</p>
<p>rlm_ldap: LDAP radiusLoginLATPort mapped to RADIUS Login-LAT-Port</p>
<p>rlm_ldap: LDAP userPassword mapped to RADIUS User-Password</p>
<p>rlm_ldap: LDAP radiusTunnelType mapped to RADIUS Tunnel-Type</p>
<p>rlm_ldap: LDAP radiusTunnelMediumType mapped to RADIUS Tunnel-Medium-Type</p>
<p>rlm_ldap: LDAP radiusTunnelPrivateGroupId mapped to RADIUS Tunnel-Private-Group-Id</p>
<p>conns: 0x8101f58</p>
<p>Module: Instantiated ldap (ldap) </p>
<p>Module: Loaded eap </p>
<p>eap: default_eap_type = &quot;md5&quot;</p>
<p>eap: timer_expire = 60</p>
<p>rlm_eap: Loaded and initialized the type md5</p>
<p>rlm_eap: Loaded and initialized the type leap</p>
<p>Module: Instantiated eap (eap) </p>
<p>Module: Loaded preprocess </p>
<p>preprocess: huntgroups = &quot;/etc/raddb/huntgroups&quot;</p>
<p>preprocess: hints = &quot;/etc/raddb/hints&quot;</p>
<p>preprocess: with_ascend_hack = no</p>
<p>preprocess: ascend_channels_per_line = 23</p>
<p>preprocess: with_ntdomain_hack = no</p>
<p>preprocess: with_specialix_jetstream_hack = no</p>
<p>preprocess: with_cisco_vsa_hack = no</p>
<p>Module: Instantiated preprocess (preprocess) </p>
<p>Module: Loaded realm </p>
<p>realm: format = &quot;suffix&quot;</p>
<p>realm: delimiter = &quot;@&quot;</p>
<p>Module: Instantiated realm (suffix) </p>
<p>Module: Loaded files </p>
<p>files: usersfile = &quot;/etc/raddb/users&quot;</p>
<p>files: acctusersfile = &quot;/etc/raddb/acct_users&quot;</p>
<p>files: preproxy_usersfile = &quot;/etc/raddb/preproxy_users&quot;</p>
<p>files: compat = &quot;no&quot;</p>
<p>Module: Instantiated files (files) </p>
<p>Module: Loaded Acct-Unique-Session-Id </p>
<p>acct_unique: key = &quot;User-Name, Acct-Session-Id, NAS-IP-Address, Client-IP-Address, NAS-Port-Id&quot;</p>
<p>Module: Instantiated acct_unique (acct_unique) </p>
<p>Module: Loaded detail </p>
<p>detail: detailfile = &quot;/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d&quot;</p>
<p>detail: detailperm = 384</p>
<p>detail: dirperm = 493</p>
<p>detail: locking = no</p>
<p>Module: Instantiated detail (detail) </p>
<p>Module: Loaded radutmp </p>
<p>radutmp: filename = &quot;/var/log/radius/radutmp&quot;</p>
<p>radutmp: username = &quot;%{User-Name}&quot;</p>
<p>radutmp: case_sensitive = yes</p>
<p>radutmp: check_with_nas = yes</p>
<p>radutmp: perm = 384</p>
<p>radutmp: callerid = yes</p>
<p>Module: Instantiated radutmp (radutmp) </p>
<p>Listening on IP address *, ports 1812/udp and 1813/udp, with proxy on 1814/udp.</p>
<p>Ready to process requests.</p>
<p>rad_recv: Access-Request packet from host <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.100.17:1812/" target="_blank">192.168.100.17:1812</a>, id=11, length=129</p>
<p>NAS-IP-Address = <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.100.17/" target="_blank">192.168.100.17</a></p>
<p>NAS-Port = 50001</p>
<p>NAS-Port-Type = Ethernet</p>
<p>User-Name = &quot;ramazan&quot;</p>
<p>Called-Station-Id = &quot;00-0F-8F-77-DB-81&quot;</p>
<p>Calling-Station-Id = &quot;00-12-79-AE-D2-4D&quot;</p>
<p>Service-Type = Framed-User</p>
<p>Framed-MTU = 1500</p>
<p>EAP-Message = 0x0200000c0172616d617a616e</p>
<p>Message-Authenticator = 0x68c41631d4feb2234d900b37a9845348</p>
<p>modcall: entering group authorize for request 0</p>
<p>modcall[authorize]: module &quot;preprocess&quot; returns ok for request 0</p>
<p>modcall[authorize]: module &quot;chap&quot; returns noop for request 0</p>
<p>rlm_eap: EAP packet type notification id 0 length 12</p>
<p>rlm_eap: EAP Start not found</p>
<p>modcall[authorize]: module &quot;eap&quot; returns updated for request 0</p>
<p>rlm_realm: No '@' in User-Name = &quot;ramazan&quot;, looking up realm NULL</p>
<p>rlm_realm: No such realm &quot;NULL&quot;</p>
<p>modcall[authorize]: module &quot;suffix&quot; returns noop for request 0</p>
<p>users: Matched DEFAULT at 152</p>
<p>rlm_ldap: Entering ldap_groupcmp()</p>
<p>radius_xlat: 'dc=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>'</p>
<p>radius_xlat: '(uid=ramazan)'</p>
<p>ldap_get_conn: Got Id: 0</p>
<p>rlm_ldap: attempting LDAP reconnection</p>
<p>rlm_ldap: (re)connect to <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.100.18:389/" target="_blank">192.168.100.18:389</a>, authentication 0</p>
<p>rlm_ldap: bind as / to <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.100.18:389/" target="_blank">192.168.100.18:389</a></p>
<p>rlm_ldap: waiting for bind result ...</p>
<p>rlm_ldap: performing search in dc=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>, with filter (uid=ramazan)</p>
<p>ldap_release_conn: Release Id: 0</p>
<p>radius_xlat: '(|(&amp;(objectClass=GroupOfNames)(member=uid=ram azan,cn=users,cn=idc,dc=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>))(&amp;(objectClass=GroupOfUniqueNames)(uniquem ember=uid=ramazan,cn=users,cn=idc,dc=
<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank"> dot1x.com</a>)))'</p>
<p>ldap_get_conn: Got Id: 0</p>
<p>rlm_ldap: performing search in dc=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>, with filter (&amp;(cn=VPN)(|(&amp;(objectClass=GroupOfNames)(m ember=uid=ramazan,cn=users,cn=idc,dc=
<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>))(&amp;(objectClass=GroupOfUniqueNames)(uniquem ember=uid=ramazan,cn=users,cn=idc,dc= <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">
dot1x.com</a>))))</p>
<p>rlm_ldap: object not found or got ambiguous search result</p>
<p>ldap_release_conn: Release Id: 0</p>
<p>ldap_get_conn: Got Id: 0</p>
<p>rlm_ldap: performing search in uid=ramazan,cn=users,cn=idc,dc=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>, with filter (objectclass=*)</p>
<p>rlm_ldap::ldap_groupcmp: User found in group VPN</p>
<p>ldap_release_conn: Release Id: 0</p>
<p>users: Matched DEFAULT at 171</p>
<p>modcall[authorize]: module &quot;files&quot; returns ok for request 0</p>
<p>modcall[authorize]: module &quot;mschap&quot; returns noop for request 0</p>
<p>rlm_ldap: - authorize</p>
<p>rlm_ldap: performing user authorization for ramazan</p>
<p>radius_xlat: '(uid=ramazan)'</p>
<p>radius_xlat: 'dc=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>'</p>
<p>ldap_get_conn: Got Id: 0</p>
<p>rlm_ldap: performing search in dc=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://dot1x.com/" target="_blank">dot1x.com</a>, with filter (uid=ramazan)</p>
<p>rlm_ldap: checking if remote access for ramazan is allowed by radiusgroupname</p>
<p>rlm_ldap: looking for check items in directory...</p>
<p>rlm_ldap: Adding radiusAuthType as Auth-Type, value ldap &amp; op=21</p>
<p>rlm_ldap: looking for reply items in directory...</p>
<p>rlm_ldap: Adding radiusTunnelPrivateGroupId as Tunnel-Private-Group-Id, value 2 &amp; op=11</p>
<p>rlm_ldap: Adding radiusTunnelMediumType as Tunnel-Medium-Type, value 6 &amp; op=11</p>
<p>rlm_ldap: Adding radiusTunnelType as Tunnel-Type, value VLAN &amp; op=11</p>
<p>rlm_ldap: Adding radiusClass as Class, value&nbsp;group-net &amp; op=11</p>
<p>rlm_ldap: user ramazan authorized to use remote access</p>
<p>ldap_release_conn: Release Id: 0</p>
<p>modcall[authorize]: module &quot;ldap&quot; returns ok for request 0</p>
<p>modcall: group authorize returns updated for request 0</p>
<p>rad_check_password: Found Auth-Type ldap</p>
<p>auth: type &quot;LDAP&quot;</p>
<p>modcall: entering group Auth-Type for request 0</p>
<p>rlm_ldap: - authenticate</p>
<p>rlm_ldap: Attribute &quot;User-Password&quot; is required for authentication.</p>
<p>modcall[authenticate]: module &quot;ldap&quot; returns invalid for request 0</p>
<p>modcall: group Auth-Type returns invalid for request 0</p>
<p>auth: Failed to validate the user.</p>
<p>Login incorrect: [ramazan/&lt;no User-Password attribute&gt;] (from client radius port 50001 cli 00-12-79-AE-D2-4D)</p>
<p>Delaying request 0 for 1 seconds</p>
<p>Finished request 0</p>
<p>Going to the next request</p>
<p>--- Walking the entire request list ---</p>
<p>Waking up in 1 seconds...</p>
<p>--- Walking the entire request list ---</p>
<p>Waking up in 1 seconds...</p>
<p>--- Walking the entire request list ---</p>
<p>Sending Access-Reject of id 11 to <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.100.17:1812/" target="_blank">192.168.100.17:1812</a></p>
<p>Waking up in 4 seconds...</p></font><font face="Arial TUR" size="2"></font></div><br style="FONT-SIZE: 8px" clear="all">

------=_Part_46206_30481752.1170064338638--

--===============0098988190==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
--===============0098988190==--
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:18 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0