Norbert Wegener <[EMAIL PROTECTED]> wrote: > I do not see the usual eap messages flying around, but nevertheless > radius sends an Access-Accept: ... > modcall: leaving group authorize (returns updated) for request 0 > rad_check_password: Found Auth-Type Accept
Who sets that? The server doesn't do that by default. Some part of your configuration sets Auth-Type := Accept. As a result, the EAP module is not run during the "authenticate" stage, and no EAP-Message (or Message-Authenticator) gets sent back in the Access-Accept. I suggest walking through the debug log, looking at each module that's mentioned. Run the LDAP queries by hand, to see if they return Auth-Type = Accept. Look at the "users" file entries. My guess is that the entry at line 25 of the "users" file has the Accept. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html