On Sun, 2008-11-23 at 02:59 -0600, Alan DeKok wrote:
> Craig White wrote:
> > OK - that quiets the notification but I still can't figure out the issue
> > where I can authenticate RRAS, Macintosh and iPod clients against radius
> > via LDAP using mschapv2 but even with the certificates on Windows XP
> > clients, with the 'xpextensions' they always try to authenticate as
> > 'uid=anonymous' and never ask me for name/password credentials to supply
> > for authentication.
>   Then the supplicant is misconfigured.
> > While I probably would agree that the certificates should be enough and
> > not need the user/password authentication, I can't figure out how to
> > tell radiusd to accept those with the certificates.
>   No.  PEAP does MS-CHAP for username/passwd authentication.  If you
> want authentication via client certs, use TLS.
> > Either way I would be happy...getting windows clients to provide
> > username/password or getting radius to accept a client with the
> > certificate.
>   There's something else in your windows configuration that is making it
> *not* ask you for the username/password.  Maybe it's cached in the registry.
HLCU\Software\Microsoft doesn't even have an EAPOL entry at all.

fixed the cert issue but still it's trying to authenticate as
anonymous  ;-(

I realize that freeradius has little control over the supplicant but I'm
wondering if it's something in my setup of tls that the authentication
should/shouldn't be part of the tunnel because it just assumes a login
of anonymous instead of the Windows User/Password or never asks me for a

rad_recv: Access-Request packet from host, id=168,
        User-Name = "anonymous"
        NAS-IP-Address =
        NAS-Port = 0
        Called-Station-Id = "00-21-29-E3-D1-84"
        Calling-Station-Id = "00-04-23-62-BD-3D"
        Framed-MTU = 1400
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 11Mbps 802.11b"
        EAP-Message = 0x026300061900
        State = 0x7de5407f2f55958f61578bc598c219a9
        Message-Authenticator =
  Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 46
  modcall[authorize]: module "preprocess" returns ok for request 46
  modcall[authorize]: module "chap" returns noop for request 46
  modcall[authorize]: module "mschap" returns noop for request 46
    rlm_realm: No '@' in User-Name = "anonymous", looking up realm NULL
    rlm_realm: No such realm "NULL"
  modcall[authorize]: module "suffix" returns noop for request 46 
  rlm_eap: EAP packet type response id 99 length 6
  rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
  modcall[authorize]: module "eap" returns updated for request 46
    users: Matched entry DEFAULT at line 156
  modcall[authorize]: module "files" returns ok for request 46
rlm_ldap: - authorize
rlm_ldap: performing user authorization for anonymous
radius_xlat:  '(uid=anonymous)'
radius_xlat:  'ou=People,ou=Accounts,o=MyOrg'
rlm_ldap: ldap_get_conn: Checking Id: 0
rlm_ldap: ldap_get_conn: Got Id: 0
rlm_ldap: performing search in ou=People,ou=Accounts,o=MyOrg, with
filter (uid=anonymous)
rlm_ldap: object not found or got ambiguous search result
rlm_ldap: search failed
rlm_ldap: ldap_release_conn: Release Id: 0
  modcall[authorize]: module "ldap" returns notfound for request 46
modcall: leaving group authorize (returns updated) for request 46
  rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
 Processing the authenticate section of radiusd.conf 
modcall: entering group authenticate for request 46
  rlm_eap: Request found, released from the list
  rlm_eap: EAP/peap
  rlm_eap: processing type peap
  rlm_eap_peap: Authenticate
  rlm_eap_tls: processing TLS
rlm_eap_tls: Received EAP-TLS ACK message
  rlm_eap_tls: ack handshake fragment handler
  eaptls_verify returned 1
  eaptls_process returned 13
  modcall[authenticate]: module "eap" returns handled for request 46
modcall: leaving group authenticate (returns handled) for request 46
Sending Access-Challenge of id 168 to port 2054
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x28ab70e596615ccdfa8d83b1787bc31e

List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to