akill
(usa Outra)
Enviado em 25/05/2012 - 11:41h
boas,
já instalei o daloRADIUS, já tenho as base de dados todas criadas (fez tudo automático), mas contiuo com o mesmo problema,
password em claro funciona, password com Crypt-password não funciona..
ID Name Username Password Groups
4 [enabled] akill mp6IeLEnieQqE
é preciso criar algum grupo especifico?!!??
deixo aqui em baixo os logs
[suffix] No '@' in User-Name = "akill", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 8 length 87
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state phase2
[peap] EAP type mschapv2
[peap] Got tunneled request
EAP-Message = 0x020800401a0208003b31e53177b7a5ba8d54af04a741a6944a830000000000000000fb37b6500eafaac594184ce976e200c7ecfe8766d33bd29400616b696c6c
server {
PEAP: Setting User-Name to akill
Sending tunneled request
EAP-Message = 0x020800401a0208003b31e53177b7a5ba8d54af04a741a6944a830000000000000000fb37b6500eafaac594184ce976e200c7ecfe8766d33bd29400616b696c6c
FreeRADIUS-Proxied-To = 127.0.0.1
User-Name = "akill"
State = 0x089343d3089b595efa1b489fc17ee0f2
server inner-tunnel {
# Executing section authorize from file /etc/freeradius/sites-enabled/inner-tunnel
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "akill", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] EAP packet type response id 8 length 64
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
[sql] expand: %{User-Name} -> akill
[sql] sql_set_user escaped user --> 'akill'
rlm_sql (sql): Reserving sql socket id: 0
[sql] expand: SELECT id, username, attribute, value, op FROM radcheck WHERE username = '%{SQL-User-Name}' ORDER BY id -> SELECT id, username, attribute, value, op FROM radcheck WHERE username = 'akill' ORDER BY id
[sql] User found in radcheck table
[sql] expand: SELECT id, username, attribute, value, op FROM radreply WHERE username = '%{SQL-User-Name}' ORDER BY id -> SELECT id, username, attribute, value, op FROM radreply WHERE username = 'akill' ORDER BY id
[sql] expand: SELECT groupname FROM radusergroup WHERE username = '%{SQL-User-Name}' ORDER BY priority -> SELECT groupname FROM radusergroup WHERE username = 'akill' ORDER BY priority
rlm_sql (sql): Released sql socket id: 0
++[sql] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING: Auth-Type already set. Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/mschapv2
[eap] processing type mschapv2
[mschapv2] # Executing group from file /etc/freeradius/sites-enabled/inner-tunnel
[mschapv2] +- entering group MS-CHAP {...}
[mschap] No Cleartext-Password configured. Cannot create LM-Password.
[mschap] No Cleartext-Password configured. Cannot create NT-Password.
[mschap] Creating challenge hash with username: akill
[mschap] Told to do MS-CHAPv2 for akill with NT-Password
[mschap] FAILED: No NT/LM-Password. Cannot perform authentication.
[mschap] FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
[eap] Freeing handler
++[eap] returns reject
Failed to authenticate the user.
} # server inner-tunnel
[peap] Got tunneled reply code 3
MS-CHAP-Error = "{TTEXTO}10E=691 R=1"
EAP-Message = 0x04080004
Message-Authenticator = 0x00000000000000000000000000000000
[peap] Got tunneled reply RADIUS code 3
MS-CHAP-Error = "{TTEXTO}10E=691 R=1"
EAP-Message = 0x04080004
Message-Authenticator = 0x00000000000000000000000000000000
[peap] Tunneled authentication was rejected.
[peap] FAILURE
++[eap] returns handled
Sending Access-Challenge of id 144 to 192.168.0.252 port 33435
EAP-Message = 0x010900261900170301001bfe5e7d03bf77e0403934cb6a7f72952d8d327b7ca9a1cd3bba5e0c
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x5422a2e5522bbb8d2131e6706010943a
Finished request 6.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host 192.168.0.252 port 33435, id=145, length=226
User-Name = "akill"
NAS-IP-Address = 10.10.250.17
NAS-Port = 0
NAS-Identifier = "10.10.250.17"
NAS-Port-Type = Wireless-802.11
Calling-Station-Id = "0019D227345D"
Called-Station-Id = "000B86653C30"
Service-Type = Login-User
Framed-MTU = 1100
EAP-Message = 0x020900261900170301001b0010353aa350c89893eb9cede468c202c58936866d490b50275982
State = 0x5422a2e5522bbb8d2131e6706010943a
Aruba-Essid-Name = "VIRUSII"
Aruba-Location-Id = "AP_Testes"
Aruba-Attr-10 = 0x47726f7570546573746573
Message-Authenticator = 0x708346c5fbee251a157e95a8d4042f6a
# Executing section authorize from file /etc/freeradius/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "akill", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 9 length 38
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established. Decoding tunneled attributes.
[peap] Peap state send tlv failure
[peap] Received EAP-TLV response.
[peap] The users session was previously rejected: returning reject (again.)
[peap] *** This means you need to read the PREVIOUS messages in the debug output
[peap] *** to find out the reason why the user was rejected.
[peap] *** Look for "reject" or "fail". Those earlier messages will tell you.
[peap] *** what went wrong, and how to fix the problem.
[eap] Handler failed in EAP/peap
[eap] Failed in EAP select
++[eap] returns invalid
Failed to authenticate the user.
Using Post-Auth-Type Reject
# Executing group from file /etc/freeradius/sites-enabled/default
+- entering group REJECT {...}
[attr_filter.access_reject] expand: %{User-Name} -> akill
attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 7 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 7
Sending Access-Reject of id 145 to 192.168.0.252 port 33435
EAP-Message = 0x04090004
Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 3.9 seconds.
Cleaning up request 0 ID 138 with timestamp +25
Cleaning up request 1 ID 139 with timestamp +25
Cleaning up request 2 ID 140 with timestamp +25
Cleaning up request 3 ID 141 with timestamp +25
Cleaning up request 4 ID 142 with timestamp +25
Cleaning up request 5 ID 143 with timestamp +25
Cleaning up request 6 ID 144 with timestamp +25