I set up freeradius 2.1.1 for EAP-TTLS, on Debian Lenny. As client I'm using Ubuntu. When I try to connect, first user, (on the logs, "heruan") connect successfully, but subsequent users (e.g. "jamila") won't. If I restart freeradius, and try to connect first with "jamila" and then with "heruan", "jamila" connects and "heruan" doesn't. The only error I'm able to see on the log is:

798:[ttls] FAIL: Forcibly stopping session resumption as it is not allowed.
799-[eap] Freeing handler
800-++[eap] returns reject
801-Failed to authenticate the user.
802-Using Post-Auth-Type Reject
803-+- entering group REJECT {...}

But I really don't know what it means.
rad_recv: Access-Request packet from host port 3073, id=1, 
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x0200000b0168657275616e
        Message-Authenticator = 0x4bd473610ad7dcfdcb6b1016a23acb10
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 0 length 11
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[unix] returns notfound
++[files] returns noop
[ldap] performing user authorization for heruan
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap]  expand: 
 -> (|(uid=heruan)(cn=heruan))
[ldap]  expand: dc=aldu,dc=net -> dc=aldu,dc=net
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: attempting LDAP reconnection
rlm_ldap: (re)connect to ldap.laurelin.aldu.net:389, authentication 0
rlm_ldap: bind as cn=radius,dc=aldu,dc=net/RaD-802.1X to 
rlm_ldap: waiting for bind result ...
rlm_ldap: Bind was successful
rlm_ldap: performing search in dc=aldu,dc=net, with filter 
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
rlm_ldap: sambaNtPassword -> NT-Password == 0x30...
rlm_ldap: sambaLmPassword -> LM-Password == 0x35...
[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP.  Are you sure that the 
user is configured correctly?
[ldap] user heruan authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing NT-Password from hex encoding
[pap] Normalizing LM-Password from hex encoding
[pap] Found existing Auth-Type, not changing it.
++[pap] returns noop
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type md5
rlm_eap_md5: Issuing Challenge
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 0x010100160410faf366dabc0e2d2eada92aed8a1beef5
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2f46e07fbc157e3e44121daf3
Finished request 0.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 0 ID 1 with timestamp +11
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2f46e07fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x020100060315
        Message-Authenticator = 0x24f629997ec0167cb1d9418bb69bf17a
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 1 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[unix] returns notfound
++[files] returns noop
[ldap] performing user authorization for heruan
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap]  expand: 
 -> (|(uid=heruan)(cn=heruan))
[ldap]  expand: dc=aldu,dc=net -> dc=aldu,dc=net
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in dc=aldu,dc=net, with filter 
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
rlm_ldap: sambaNtPassword -> NT-Password == 0x30...
rlm_ldap: sambaLmPassword -> LM-Password == 0x35...
[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP.  Are you sure that the 
user is configured correctly?
[ldap] user heruan authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing NT-Password from hex encoding
[pap] Normalizing LM-Password from hex encoding
[pap] Found existing Auth-Type, not changing it.
++[pap] returns noop
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP NAK
[eap] EAP-NAK asked for EAP-Type/ttls
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 0x010200061520
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2f56d16fbc157e3e44121daf3
Finished request 1.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 1 ID 1 with timestamp +12
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2f56d16fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 
        EAP-Message = 0x1884e21d7209
        Message-Authenticator = 0x5ef1bef4e588c171b000e3c9c399544b
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 2 length 253
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] eaptls_verify returned 7 
[ttls] Done initial handshake
[ttls]     (other): before/accept initialization 
[ttls]     TLS_accept: before/accept initialization 
[ttls] <<< TLS 1.0 Handshake [length 00f8], ClientHello  
[ttls]     TLS_accept: SSLv3 read client hello A 
[ttls] >>> TLS 1.0 Handshake [length 0030], ServerHello  
[ttls]     TLS_accept: SSLv3 write server hello A 
[ttls] >>> TLS 1.0 Handshake [length 0d44], Certificate  
[ttls]     TLS_accept: SSLv3 write certificate A 
[ttls] >>> TLS 1.0 Handshake [length 030d], ServerKeyExchange  
[ttls]     TLS_accept: SSLv3 write key exchange A 
[ttls] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone  
[ttls]     TLS_accept: SSLv3 write server done A 
[ttls]     TLS_accept: SSLv3 flush data 
[ttls]     TLS_accept: Need to read more data: SSLv3 read client certificate A
In SSL Handshake Phase 
In SSL Accept mode  
[ttls] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 0x42010d0421161f416c647520
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2f66c16fbc157e3e44121daf3
Finished request 2.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 2 ID 1 with timestamp +12
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2f66c16fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x020300061500
        Message-Authenticator = 0x0014a82ba883ba4ae3b8e24f61745d69
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 3 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] Received TLS ACK
[ttls] ACK handshake fragment handler
[ttls] eaptls_verify returned 1 
[ttls] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 0x0b3009060355040613024954
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2f76b16fbc157e3e44121daf3
Finished request 3.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 3 ID 1 with timestamp +12
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2f76b16fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x020400061500
        Message-Authenticator = 0x7d696164144cc750f1bdd7cca30cc641
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 4 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] Received TLS ACK
[ttls] ACK handshake fragment handler
[ttls] eaptls_verify returned 1 
[ttls] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 0x6fb6b25244e2b2eac310fef7
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2f06a16fbc157e3e44121daf3
Finished request 4.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 4 ID 1 with timestamp +12
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2f06a16fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x020500061500
        Message-Authenticator = 0x11fda5dbe435a0608c3a63c5155aa8b1
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 5 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] Received TLS ACK
[ttls] ACK handshake fragment handler
[ttls] eaptls_verify returned 1 
[ttls] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 0xa6fca7afb134ff1b5e08890f
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2f16916fbc157e3e44121daf3
Finished request 5.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 5 ID 1 with timestamp +12
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2f16916fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x020600061500
        Message-Authenticator = 0xff6b6c02b603f2c9cc862800ffbc096c
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 6 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] Received TLS ACK
[ttls] ACK handshake fragment handler
[ttls] eaptls_verify returned 1 
[ttls] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2f26816fbc157e3e44121daf3
Finished request 6.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 6 ID 1 with timestamp +12
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2f26816fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 
        Message-Authenticator = 0xb9d62831c9c7caefdf69c3b99c4d8957
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 204
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] eaptls_verify returned 7 
[ttls] Done initial handshake
[ttls] <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange  
[ttls]     TLS_accept: SSLv3 read client key exchange A 
[ttls] <<< TLS 1.0 ChangeCipherSpec [length 0001]  
[ttls] <<< TLS 1.0 Handshake [length 0010], Finished  
[ttls]     TLS_accept: SSLv3 read finished A 
[ttls] >>> TLS 1.0 Handshake [length 00aa]???  
[ttls]     TLS_accept: unknown state 
[ttls] >>> TLS 1.0 ChangeCipherSpec [length 0001]  
[ttls]     TLS_accept: SSLv3 write change cipher spec A 
[ttls] >>> TLS 1.0 Handshake [length 0010], Finished  
[ttls]     TLS_accept: SSLv3 write finished A 
[ttls]     TLS_accept: SSLv3 flush data 
[ttls]     (other): SSL negotiation finished successfully 
SSL Connection Established 
[ttls] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2f36716fbc157e3e44121daf3
Finished request 7.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 7 ID 1 with timestamp +12
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2f36716fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 
        Message-Authenticator = 0x8486851c6545cab5b42fd05d3a183a04
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 8 length 176
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] eaptls_verify returned 7 
[ttls] Done initial handshake
[ttls] eaptls_process returned 7 
[ttls] Session established.  Proceeding to decode tunneled attributes.
[ttls] Got tunneled request
        User-Name = "heruan"
        MS-CHAP-Challenge = 0x21baa0943340f88f07f8802a8ac6690f
        MS-CHAP2-Response = 
        FreeRADIUS-Proxied-To =
[ttls] Sending tunneled request
        User-Name = "heruan"
        MS-CHAP-Challenge = 0x21baa0943340f88f07f8802a8ac6690f
        MS-CHAP2-Response = 
        FreeRADIUS-Proxied-To =
server inner-tunnel {
+- entering group authorize {...}
++[chap] returns noop
[mschap] Found MS-CHAP attributes.  Setting 'Auth-Type  = mschap'
++[mschap] returns ok
++[unix] returns notfound
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] No EAP-Message, not doing EAP
++[eap] returns noop
++[files] returns noop
[ldap] performing user authorization for heruan
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap]  expand: 
 -> (|(uid=heruan)(cn=heruan))
[ldap]  expand: dc=aldu,dc=net -> dc=aldu,dc=net
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in dc=aldu,dc=net, with filter 
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
rlm_ldap: sambaNtPassword -> NT-Password == 0x30...
rlm_ldap: sambaLmPassword -> LM-Password == 0x35...
[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP.  Are you sure that the 
user is configured correctly?
[ldap] user heruan authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing NT-Password from hex encoding
[pap] Normalizing LM-Password from hex encoding
[pap] Found existing Auth-Type, not changing it.
++[pap] returns noop
Found Auth-Type = MSCHAP
+- entering group MS-CHAP {...}
[mschap] Found LM-Password
[mschap] Found NT-Password
[mschap] Told to do MS-CHAPv2 for heruan with NT-Password
[mschap] adding MS-CHAPv2 MPPE keys
++[mschap] returns ok
} # server inner-tunnel
[ttls] Got tunneled reply code 2
        MS-CHAP2-Success = 
        MS-MPPE-Recv-Key = 0x90e46fe588c50f30b1fabcf942019be5
        MS-MPPE-Send-Key = 0xea3ea373e2e1e279c847a7beb2c5f588
        MS-MPPE-Encryption-Policy = 0x00000001
        MS-MPPE-Encryption-Types = 0x00000006
[ttls] Got tunneled Access-Accept
[ttls] Got MS-CHAP2-Success, tunneling it to the client in a challenge.
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xf46f03b2fc6616fbc157e3e44121daf3
Finished request 8.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 8 ID 1 with timestamp +12
        User-Name = "heruan"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0xf46f03b2fc6616fbc157e3e44121daf3
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x020900061500
        Message-Authenticator = 0xa01f486fa472b238ae70656c633e9340
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "heruan", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 9 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] Received TLS ACK
[ttls] ACK handshake is finished
[ttls] eaptls_verify returned 3 
[ttls] eaptls_process returned 3 
[eap] Freeing handler
++[eap] returns ok
+- entering group post-auth {...}
++[exec] returns noop
Sending Access-Accept of id 1 to port 3073
        MS-MPPE-Recv-Key = 
        MS-MPPE-Send-Key = 
        EAP-Message = 0x03090004
        Message-Authenticator = 0x00000000000000000000000000000000
        User-Name = "heruan"
Finished request 9.
Going to the next request
Waking up in 4.9 seconds.
Cleaning up request 9 ID 1 with timestamp +12
Ready to process requests.
rad_recv: Access-Request packet from host port 3073, id=1, 
        User-Name = "jamila"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x0200000b016a616d696c61
        Message-Authenticator = 0xcdae13a716b61cabbcb70e726276d665
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "jamila", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 0 length 11
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[unix] returns notfound
++[files] returns noop
[ldap] performing user authorization for jamila
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap]  expand: 
 -> (|(uid=jamila)(cn=jamila))
[ldap]  expand: dc=aldu,dc=net -> dc=aldu,dc=net
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in dc=aldu,dc=net, with filter 
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
rlm_ldap: sambaNtPassword -> NT-Password == 0x44...
rlm_ldap: sambaLmPassword -> LM-Password == 0x42...
[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP.  Are you sure that the 
user is configured correctly?
[ldap] user jamila authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing NT-Password from hex encoding
[pap] Normalizing LM-Password from hex encoding
[pap] Found existing Auth-Type, not changing it.
++[pap] returns noop
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type md5
rlm_eap_md5: Issuing Challenge
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 0x01010016041067c2d2ac231b541d1ebb9d5e9aef272e
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x7d75f9417d74fd26c22394ad8dcd0b12
Finished request 10.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 10 ID 1 with timestamp +25
        User-Name = "jamila"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0x7d75f9417d74fd26c22394ad8dcd0b12
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 0x020100060315
        Message-Authenticator = 0xa8d0e7d17c0e5240d1bb804c2703807d
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "jamila", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 1 length 6
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[unix] returns notfound
++[files] returns noop
[ldap] performing user authorization for jamila
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap] WARNING: Deprecated conditional expansion ":-".  See "man unlang" for 
[ldap]  expand: 
 -> (|(uid=jamila)(cn=jamila))
[ldap]  expand: dc=aldu,dc=net -> dc=aldu,dc=net
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in dc=aldu,dc=net, with filter 
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
rlm_ldap: sambaNtPassword -> NT-Password == 0x44...
rlm_ldap: sambaLmPassword -> LM-Password == 0x42...
[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP.  Are you sure that the 
user is configured correctly?
[ldap] user jamila authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing NT-Password from hex encoding
[pap] Normalizing LM-Password from hex encoding
[pap] Found existing Auth-Type, not changing it.
++[pap] returns noop
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP NAK
[eap] EAP-NAK asked for EAP-Type/ttls
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 0x010200061520
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x7d75f9417c77ec26c22394ad8dcd0b12
Finished request 11.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 11 ID 1 with timestamp +25
        User-Name = "jamila"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0x7d75f9417c77ec26c22394ad8dcd0b12
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 
        EAP-Message = 0x6480b89d4c5a
        Message-Authenticator = 0x89044f83ea2af62d3bcf0b6260d427df
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "jamila", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 2 length 253
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] eaptls_verify returned 7 
[ttls] Done initial handshake
[ttls]     (other): before/accept initialization 
[ttls]     TLS_accept: before/accept initialization 
[ttls] <<< TLS 1.0 Handshake [length 00f8], ClientHello  
[ttls]     TLS_accept: SSLv3 read client hello A 
[ttls] >>> TLS 1.0 Handshake [length 002a], ServerHello  
[ttls]     TLS_accept: SSLv3 write server hello A 
[ttls] >>> TLS 1.0 ChangeCipherSpec [length 0001]  
[ttls]     TLS_accept: SSLv3 write change cipher spec A 
[ttls] >>> TLS 1.0 Handshake [length 0010], Finished  
[ttls]     TLS_accept: SSLv3 write finished A 
[ttls]     TLS_accept: SSLv3 flush data 
[ttls]     TLS_accept: Need to read more data: SSLv3 read finished A
In SSL Handshake Phase 
In SSL Accept mode  
[ttls] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 1 to port 3073
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x7d75f9417f76ec26c22394ad8dcd0b12
Finished request 12.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 3073, id=1, 
Cleaning up request 12 ID 1 with timestamp +25
        User-Name = "jamila"
        NAS-IP-Address =
        Called-Station-Id = "00c049d3f40e"
        Calling-Station-Id = "002268c0eb93"
        NAS-Identifier = "00c049d3f40e"
        NAS-Port = 184
        Framed-MTU = 1400
        State = 0x7d75f9417f76ec26c22394ad8dcd0b12
        NAS-Port-Type = Wireless-802.11
        EAP-Message = 
        Message-Authenticator = 0x600117a5ce085e9040580d94a1a0becf
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "jamila", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 3 length 65
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/ttls
[eap] processing type ttls
[ttls] Authenticate
[ttls] processing EAP-TLS
[ttls] eaptls_verify returned 7 
[ttls] Done initial handshake
[ttls] <<< TLS 1.0 ChangeCipherSpec [length 0001]  
[ttls] <<< TLS 1.0 Handshake [length 0010], Finished  
[ttls]     TLS_accept: SSLv3 read finished A 
[ttls]     (other): SSL negotiation finished successfully 
SSL Connection Established 
SSL Application Data
[ttls] eaptls_process returned 3 
[ttls] Skipping Phase2 due to session resumption
[ttls] FAIL: Forcibly stopping session resumption as it is not allowed.
[eap] Freeing handler
++[eap] returns reject
Failed to authenticate the user.
Using Post-Auth-Type Reject
+- entering group REJECT {...}
[attr_filter.access_reject]     expand: %{User-Name} -> jamila
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 13 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 13
Sending Access-Reject of id 1 to port 3073
        EAP-Message = 0x04030004
        Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 4.9 seconds.
Cleaning up request 13 ID 1 with timestamp +25
Ready to process requests.


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to