hablas español?

Yo quieor hacer lo mismo, quizá nos podamos ayudar

Le Mercredi 06 Avril 2005 12:20, Israel Fabio Alves a écrit :
> Hi,
>
>   I try to authenticate user Windows XP + PEAP + MSCHAPV2. The
> authetication using user + password + domain.
>
> Always occur de same error: rlm_eap: Identity does not match User-Name,
> setting from EAP Identity.
>
>
>
> Thanks for help.
>
> tp-opengate:/usr/local/radius/etc/raddb# /usr/local/radius/sbin/radiusd
> -X -A
> Starting - reading configuration files ...
> reread_config:  reading radiusd.conf
> Config:   including file: /usr/local/radius/etc/raddb/proxy.conf
> Config:   including file: /usr/local/radius/etc/raddb/clients.conf
> Config:   including file: /usr/local/radius/etc/raddb/snmp.conf
> Config:   including file: /usr/local/radius/etc/raddb/eap.conf
> Config:   including file: /usr/local/radius/etc/raddb/sql.conf
>   main: prefix = "/usr/local/radius"
>   main: localstatedir = "/usr/local/radius/var"
>   main: logdir = "/usr/local/radius/var/log/radius"
>   main: libdir = "/usr/local/radius/lib"
>   main: radacctdir = "/usr/local/radius/var/log/radius/radacct"
>   main: hostname_lookups = no
>   main: max_request_time = 30
>   main: cleanup_delay = 5
>   main: max_requests = 1024
>   main: delete_blocked_requests = 0
>   main: port = 0
>   main: allow_core_dumps = no
>   main: log_stripped_names = yes
>   main: log_file = "/usr/local/radius/var/log/radius/radius.log"
>   main: log_auth = yes
>   main: log_auth_badpass = yes
>   main: log_auth_goodpass = yes
>   main: pidfile = "/usr/local/radius/var/run/radiusd/radiusd.pid"
>   main: user = "(null)"
>   main: group = "(null)"
>   main: usercollide = no
>   main: lower_user = "no"
>   main: lower_pass = "no"
>   main: nospace_user = "no"
>   main: nospace_pass = "no"
>   main: checkrad = "/usr/local/radius/sbin/checkrad"
>   main: proxy_requests = yes
>   proxy: retry_delay = 5
>   proxy: retry_count = 3
>   proxy: synchronous = no
>   proxy: default_fallback = yes
>   proxy: dead_time = 120
>   proxy: post_proxy_authorize = yes
>   proxy: wake_all_if_all_dead = no
>   security: max_attributes = 200
>   security: reject_delay = 1
>   security: status_server = no
>   main: debug_level = 0
> read_config_files:  reading dictionary
> read_config_files:  reading naslist
> Using deprecated naslist file.  Support for this will go away soon.
> read_config_files:  reading clients
> read_config_files:  reading realms
> radiusd:  entering modules setup
> Module: Library search path is /usr/local/radius/lib
> Module: Loaded exec
>   exec: wait = yes
>   exec: program = "(null)"
>   exec: input_pairs = "request"
>   exec: output_pairs = "(null)"
>   exec: packet_type = "(null)"
> rlm_exec: Wait=yes but no output defined. Did you mean output=none?
> Module: Instantiated exec (exec)
> Module: Loaded expr
> Module: Instantiated expr (expr)
> Module: Loaded PAP
>   pap: encryption_scheme = "crypt"
> Module: Instantiated pap (pap)
> Module: Loaded CHAP
> Module: Instantiated chap (chap)
> Module: Loaded MS-CHAP
>   mschap: use_mppe = yes
>   mschap: require_encryption = yes
>   mschap: require_strong = yes
>   mschap: with_ntdomain_hack = yes
>   mschap: passwd = "(null)"
>   mschap: authtype = "MS-CHAP"
>   mschap: ntlm_auth = "/usr/bin/ntlm_auth --request-nt-key
> --username=%{mschap:User-Name} --domain=NTRSSRV
> --challenge=%{mschap:Challenge:-00}
> --nt-response=%{mschap:NT-Response:-00}" Module: Instantiated mschap
> (mschap)
> Module: Loaded System
>   unix: cache = no
>   unix: passwd = "(null)"
>   unix: shadow = "(null)"
>   unix: group = "(null)"
>   unix: radwtmp = "/usr/local/radius/var/log/radius/radwtmp"
>   unix: usegroup = no
>   unix: cache_reload = 600
> Module: Instantiated unix (unix)
> Module: Loaded eap
>   eap: default_eap_type = "peap"
>   eap: timer_expire = 60
>   eap: ignore_unknown_eap_types = no
>   eap: cisco_accounting_username_bug = no
>   tls: rsa_key_exchange = no
>   tls: dh_key_exchange = yes
>   tls: rsa_key_length = 512
>   tls: dh_key_length = 512
>   tls: verify_depth = 0
>   tls: CA_path = "(null)"
>   tls: pem_file_type = yes
>   tls: private_key_file = "/usr/local/openssl/ssl/misc/radius/newreq.pem"
>   tls: certificate_file = "/usr/local/openssl/ssl/misc/radius/newcert.pem"
>   tls: CA_file = "/usr/local/openssl/ssl/misc/radius/cacert.pem"
>   tls: private_key_password = "whatever"
>   tls: dh_file = "/usr/local/openssl/ssl/misc/radius/dh"
>   tls: random_file = "/usr/local/openssl/ssl/misc/radius/random"
>   tls: fragment_size = 1024
>   tls: include_length = yes
>   tls: check_crl = no
>   tls: check_cert_cn = "(null)"
> rlm_eap: Loaded and initialized type tls
>   peap: default_eap_type = "mschapv2"
>   peap: copy_request_to_tunnel = no
>   peap: use_tunneled_reply = no
>   peap: proxy_tunneled_request_as_eap = yes
> rlm_eap: Loaded and initialized type peap
>   mschapv2: with_ntdomain_hack = no
> rlm_eap: Loaded and initialized type mschapv2
> Module: Instantiated eap (eap)
> Module: Loaded preprocess
>   preprocess: huntgroups = "/usr/local/radius/etc/raddb/huntgroups"
>   preprocess: hints = "/usr/local/radius/etc/raddb/hints"
>   preprocess: with_ascend_hack = no
>   preprocess: ascend_channels_per_line = 23
>   preprocess: with_ntdomain_hack = yes
>   preprocess: with_specialix_jetstream_hack = no
>   preprocess: with_cisco_vsa_hack = no
> Module: Instantiated preprocess (preprocess)
> Module: Loaded detail
>   detail: detailfile =
> "/usr/local/radius/var/log/radius/radacct/%{Client-IP-Address}/auth-detail-
>%Y%m%d" detail: detailperm = 384
>   detail: dirperm = 493
>   detail: locking = no
> Module: Instantiated detail (auth_log)
> Module: Loaded realm
>   realm: format = "suffix"
>   realm: delimiter = "@"
>   realm: ignore_default = no
>   realm: ignore_null = no
> Module: Instantiated realm (suffix)
>   realm: format = "prefix"
>   realm: delimiter = "\"
>   realm: ignore_default = no
>   realm: ignore_null = no
> Module: Instantiated realm (ntdomain)
> Module: Loaded files
>   files: usersfile = "/usr/local/radius/etc/raddb/users"
>   files: acctusersfile = "/usr/local/radius/etc/raddb/acct_users"
>   files: preproxy_usersfile = "/usr/local/radius/etc/raddb/preproxy_users"
>   files: compat = "no"
> Module: Instantiated files (files)
> Module: Loaded checkval
>   checkval: item-name = "Calling-Station-Id"
>   checkval: check-name = "Calling-Station-Id"
>   checkval: data-type = "string"
>   checkval: notfound-reject = no
> rlm_checkval: Registered name Calling-Station-Id for attribute 31
> Module: Instantiated checkval (checkval)
>   detail: detailfile =
> "/usr/local/radius/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%
>d" detail: detailperm = 384
>   detail: dirperm = 493
>   detail: locking = no
> Module: Instantiated detail (detail)
> Module: Loaded radutmp
>   radutmp: filename = "/usr/local/radius/var/log/radius/radutmp"
>   radutmp: username = "%{User-Name}"
>   radutmp: case_sensitive = yes
>   radutmp: check_with_nas = yes
>   radutmp: perm = 384
>   radutmp: callerid = yes
> Module: Instantiated radutmp (radutmp)
>   detail: detailfile =
> "/usr/local/radius/var/log/radius/radacct/%{Client-IP-Address}/pre-proxy-de
>tail-%Y%m%d" detail: detailperm = 384
>   detail: dirperm = 493
>   detail: locking = no
> Module: Instantiated detail (pre_proxy_log)
>   detail: detailfile =
> "/usr/local/radius/var/log/radius/radacct/%{Client-IP-Address}/post-proxy-d
>etail-%Y%m%d" detail: detailperm = 384
>   detail: dirperm = 493
>   detail: locking = no
> Module: Instantiated detail (post_proxy_log)
>   detail: detailfile =
> "/usr/local/radius/var/log/radius/radacct/%{Client-IP-Address}/reply-detail
>-%Y%m%d" detail: detailperm = 384
>   detail: dirperm = 493
>   detail: locking = no
> Module: Instantiated detail (reply_log)
> Listening on authentication *:1812
> Listening on accounting *:1813
> Listening on proxy *:1814
> Ready to process requests.
> rad_recv: Access-Request packet from host 172.22.2.32:3183, id=233,
> length=102
>          User-Name = "[EMAIL PROTECTED]"
>          EAP-Message = 0x02020013014e5452535352565c69737261656c
>          NAS-IP-Address = 172.22.2.32
>          Service-Type = Login-User
>          Calling-Station-Id = "0.0.0.0"
>          NAS-Port-Type = Ethernet
>          Message-Authenticator = 0x1bbc239dfe037525192df19fbe71c1bb
>    Processing the authorize section of radiusd.conf
> modcall: entering group authorize for request 0
>    modcall[authorize]: module "preprocess" returns ok for request 0
> radius_xlat:
> '/usr/local/radius/var/log/radius/radacct/172.22.2.32/auth-detail-20050406'
> rlm_detail:
> /usr/local/radius/var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%
>Y%m%d expands to
> /usr/local/radius/var/log/radius/radacct/172.22.2.32/auth-detail-20050406
>    modcall[authorize]: module "auth_log" returns ok for request 0
>    modcall[authorize]: module "chap" returns noop for request 0
>    modcall[authorize]: module "mschap" returns noop for request 0
>      rlm_realm: Looking up realm "NTRSSRV" for User-Name = "[EMAIL PROTECTED]"
>      rlm_realm: Found realm "NTRSSRV"
>      rlm_realm: Adding Stripped-User-Name = "israel"
>      rlm_realm: Proxying request from user israel to realm NTRSSRV
>      rlm_realm: Adding Realm = "NTRSSRV"
>      rlm_realm: Authentication realm is LOCAL.
>    modcall[authorize]: module "suffix" returns noop for request 0
>      rlm_realm: Request already proxied.  Ignoring.
>    modcall[authorize]: module "ntdomain" returns noop for request 0
>    rlm_eap: EAP packet type response id 2 length 19
>    rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
>    modcall[authorize]: module "eap" returns updated for request 0
>      users: Matched DEFAULT at 6
>    modcall[authorize]: module "files" returns ok for request 0
> rlm_checkval: Item Name: Calling-Station-Id, Value: 0.0.0.0
> rlm_checkval: Could not find attribute named Calling-Station-Id in check
> pairs
>    modcall[authorize]: module "checkval" returns notfound for request 0
> modcall: group authorize returns updated for request 0
>    rad_check_password:  Found Auth-Type EAP
> auth: type "EAP"
>    Processing the authenticate section of radiusd.conf
> modcall: entering group authenticate for request 0
> rlm_eap: Identity does not match User-Name, setting from EAP Identity.
>    rlm_eap: Failed in handler
>    modcall[authenticate]: module "eap" returns invalid for request 0
> modcall: group authenticate returns invalid for request 0
> auth: Failed to validate the user.
> Login incorrect: [israel/<no User-Password attribute>] (from client
> extreme port 0 cli 0.0.0.0)
> Delaying request 0 for 1 seconds
> Finished request 0
> Going to the next request
> --- Walking the entire request list ---
> Waking up in 1 seconds...
> --- Walking the entire request list ---
> Waking up in 1 seconds...
> --- Walking the entire request list ---
> Sending Access-Reject of id 233 to 172.22.2.32:3183
> Waking up in 4 seconds...
> --- Walking the entire request list ---
> Cleaning up request 0 ID 233 with timestamp 42541856
> Nothing to do.  Sleeping until we see a request.
>
>
>
>
>
>
> Packet-Type = Access-Request
> Wed Apr  6 14:11:50 2005
>          User-Name = "[EMAIL PROTECTED]"
>          EAP-Message = 0x02020013014e5452535352565c69737261656c
>          NAS-IP-Address = 172.22.2.32
>          Service-Type = Login-User
>          Calling-Station-Id = "0.0.0.0"
>          NAS-Port-Type = Ethernet
>          Message-Authenticator = 0x1bbc239dfe037525192df19fbe71c1bb
>          Client-IP-Address = 172.22.2.32
>
>
>
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to