On Mon, 2009-01-19 at 14:12 +0100, Alan DeKok wrote: > You need the "libssl-dev" package. > > And then re-build && re-install the server. > > Alan DeKok.
Alan, Thanks for your mail. I have installed libssl-dev package: r...@radius:/home/radius/sbin# dpkg -l | grep ssl ii libssl-dev 0.9.8g-4ubuntu3.4 SSL development libraries, header files and ii libssl0.9.8 0.9.8g-4ubuntu3.4 SSL shared libraries I've deleted everything in /home/radius and started from scratch: ./configure --prefix=$home make make install I was running script during install here are WARNINGs: r...@radius:/home/radius# grep WARNING ../logs/configure configure: WARNING: snmpget not found - Simultaneous-Use and checkrad.pl may not work configure: WARNING: snmpwalk not found - Simultaneous-Use and checkrad.pl may not work configure: WARNING: pcap library not found, silently disabling the RADIUS sniffer. config.status: WARNING: ./Make.inc.in seems to ignore the --datarootdir setting config.status: WARNING: ./src/include/build-radpaths-h.in seems to ignore the --datarootdir setting configure: WARNING: silently not building rlm_counter. configure: WARNING: FAILURE: rlm_counter requires: libgdbm. configure: WARNING: FAILURE: rlm_dbm requires: (ndbm.h or gdbm/ndbm.h or gdbm-ndbm.h) (libndbm or libgdbm or libgdbm_compat). configure: WARNING: silently not building rlm_dbm. configure: WARNING: silently not building rlm_eap_ikev2. configure: WARNING: FAILURE: rlm_eap_ikev2 requires: libeap-ikev2 EAPIKEv2/connector.h. configure: WARNING: the TNCS library isn't found! configure: WARNING: silently not building rlm_eap_tnc. configure: WARNING: FAILURE: rlm_eap_tnc requires: -lTNCS. configure: WARNING: silently not building rlm_ippool. configure: WARNING: FAILURE: rlm_ippool requires: libgdbm. configure: WARNING: the comm_err library isn't found! configure: WARNING: silently not building rlm_krb5. configure: WARNING: FAILURE: rlm_krb5 requires: krb5.h krb5. configure: WARNING: silently not building rlm_ldap. configure: WARNING: FAILURE: rlm_ldap requires: libldap_r ldap.h. configure: WARNING: silently not building rlm_pam. configure: WARNING: FAILURE: rlm_pam requires: libpam. configure: WARNING: silently not building rlm_perl. configure: WARNING: FAILURE: rlm_perl requires: libperl.so. configure: WARNING: silently not building rlm_python. configure: WARNING: FAILURE: rlm_python requires: Python.h libpython2.5. configure: WARNING: silently not building rlm_sql_iodbc. configure: WARNING: FAILURE: rlm_sql_iodbc requires: libiodbc isql.h. configure: WARNING: MySQL libraries not found. Use --with-mysql-lib-dir=<path>. configure: WARNING: MySQL headers not found. Use --with-mysql-include-dir=<path>. configure: WARNING: silently not building rlm_sql_mysql. configure: WARNING: FAILURE: rlm_sql_mysql requires: libmysqlclient_r mysql.h. configure: WARNING: silently not building rlm_sql_postgresql. configure: WARNING: FAILURE: rlm_sql_postgresql requires: libpq-fe.h libpq. configure: WARNING: oracle headers not found. Use --with-oracle-home-dir=<path>. configure: WARNING: silently not building rlm_sql_oracle. configure: WARNING: FAILURE: rlm_sql_oracle requires: oci.h. configure: WARNING: silently not building rlm_sql_unixodbc. configure: WARNING: FAILURE: rlm_sql_unixodbc requires: libodbc sql.h. here's stuff with ssl: r...@radius:/home/radius# grep ssl ../logs/configure checking for SSL_new in -lssl... yes checking openssl/ssl.h usability... yes checking openssl/ssl.h presence... yes checking for openssl/ssl.h... yes checking openssl/crypto.h usability... yes checking openssl/crypto.h presence... yes checking for openssl/crypto.h... yes checking openssl/err.h usability... yes checking openssl/err.h presence... yes checking for openssl/err.h... yes checking openssl/evp.h usability... yes checking openssl/evp.h presence... yes checking for openssl/evp.h... yes checking openssl/engine.h usability... yes checking openssl/engine.h presence... yes checking for openssl/engine.h... yes checking for EVP_sha256 in -lc -lcrypto -lssl -lcrypto... yes checking for SSL_new in -lssl... yes checking openssl/des.h usability... yes checking openssl/des.h presence... yes checking for openssl/des.h... yes checking openssl/hmac.h usability... yes checking openssl/hmac.h presence... yes checking for openssl/hmac.h... yes checking openssl/md4.h usability... yes checking openssl/md4.h presence... yes checking for openssl/md4.h... yes checking openssl/md5.h usability... yes checking openssl/md5.h presence... yes checking for openssl/md5.h... yes checking openssl/sha.h usability... yes checking openssl/sha.h presence... yes checking for openssl/sha.h... yes if this is what I get when staring radius: r...@radius:/home/radius# ./sbin/radiusd -X FreeRADIUS Version 2.1.3, for host i686-pc-linux-gnu, built on Jan 19 2009 at 13:48:26 Copyright (C) 1999-2008 The FreeRADIUS server project and contributors. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. You may redistribute copies of FreeRADIUS under the terms of the GNU General Public License v2. Starting - reading configuration files ... including configuration file /home/radius/etc/raddb/radiusd.conf including configuration file /home/radius/etc/raddb/proxy.conf including configuration file /home/radius/etc/raddb/clients.conf including files in directory /home/radius/etc/raddb/modules/ including configuration file /home/radius/etc/raddb/modules/etc_group including configuration file /home/radius/etc/raddb/modules/files including configuration file /home/radius/etc/raddb/modules/expiration including configuration file /home/radius/etc/raddb/modules/detail.log including configuration file /home/radius/etc/raddb/modules/smbpasswd including configuration file /home/radius/etc/raddb/modules/chap including configuration file /home/radius/etc/raddb/modules/mschap including configuration file /home/radius/etc/raddb/modules/ippool including configuration file /home/radius/etc/raddb/modules/digest including configuration file /home/radius/etc/raddb/modules/radutmp including configuration file /home/radius/etc/raddb/modules/realm including configuration file /home/radius/etc/raddb/modules/attr_rewrite including configuration file /home/radius/etc/raddb/modules/echo including configuration file /home/radius/etc/raddb/modules/policy including configuration file /home/radius/etc/raddb/modules/mac2vlan including configuration file /home/radius/etc/raddb/modules/sql_log including configuration file /home/radius/etc/raddb/modules/preprocess including configuration file /home/radius/etc/raddb/modules/sqlcounter_expire_on_login including configuration file /home/radius/etc/raddb/modules/krb5 including configuration file /home/radius/etc/raddb/modules/pam including configuration file /home/radius/etc/raddb/modules/wimax including configuration file /home/radius/etc/raddb/modules/linelog including configuration file /home/radius/etc/raddb/modules/always including configuration file /home/radius/etc/raddb/modules/exec including configuration file /home/radius/etc/raddb/modules/inner-eap including configuration file /home/radius/etc/raddb/modules/checkval including configuration file /home/radius/etc/raddb/modules/passwd including configuration file /home/radius/etc/raddb/modules/expr including configuration file /home/radius/etc/raddb/modules/perl including configuration file /home/radius/etc/raddb/modules/detail.example.com including configuration file /home/radius/etc/raddb/modules/pap including configuration file /home/radius/etc/raddb/modules/ldap including configuration file /home/radius/etc/raddb/modules/unix including configuration file /home/radius/etc/raddb/modules/detail including configuration file /home/radius/etc/raddb/modules/counter including configuration file /home/radius/etc/raddb/modules/sradutmp including configuration file /home/radius/etc/raddb/modules/attr_filter including configuration file /home/radius/etc/raddb/modules/mac2ip including configuration file /home/radius/etc/raddb/modules/logintime including configuration file /home/radius/etc/raddb/modules/acct_unique including configuration file /home/radius/etc/raddb/eap.conf including configuration file /home/radius/etc/raddb/sql.conf including configuration file /home/radius/etc/raddb/sql/mysql/dialup.conf including configuration file /home/radius/etc/raddb/sql/mysql/counter.conf including configuration file /home/radius/etc/raddb/policy.conf including files in directory /home/radius/etc/raddb/sites-enabled/ including configuration file /home/radius/etc/raddb/sites-enabled/inner-tunnel including configuration file /home/radius/etc/raddb/sites-enabled/default including dictionary file /home/radius/etc/raddb/dictionary main { prefix = "/home/radius" localstatedir = "/home/radius/var" logdir = "/home/radius/var/log/radius" libdir = "/home/radius/lib" radacctdir = "/home/radius/var/log/radius/radacct" hostname_lookups = no max_request_time = 30 cleanup_delay = 5 max_requests = 1024 allow_core_dumps = no pidfile = "/home/radius/var/run/radiusd/radiusd.pid" checkrad = "/home/radius/sbin/checkrad" debug_level = 0 proxy_requests = yes log { stripped_names = no auth = no auth_badpass = no auth_goodpass = no } security { max_attributes = 200 reject_delay = 1 status_server = yes } } client localhost { ipaddr = 127.0.0.1 require_message_authenticator = no secret = "testing123" nastype = "other" } radiusd: #### Loading Realms and Home Servers #### proxy server { retry_delay = 5 retry_count = 3 default_fallback = no dead_time = 120 wake_all_if_all_dead = no } home_server localhost { ipaddr = 127.0.0.1 port = 1812 type = "auth" secret = "testing123" response_window = 20 max_outstanding = 65536 zombie_period = 40 status_check = "status-server" ping_interval = 30 check_interval = 30 num_answers_to_alive = 3 num_pings_to_alive = 3 revive_interval = 120 status_check_timeout = 4 } home_server_pool my_auth_failover { type = fail-over home_server = localhost } realm example.com { auth_pool = my_auth_failover } realm LOCAL { } radiusd: #### Instantiating modules #### instantiate { Module: Linked to module rlm_exec Module: Instantiating exec exec { wait = no input_pairs = "request" shell_escape = yes } Module: Linked to module rlm_expr Module: Instantiating expr Module: Linked to module rlm_expiration Module: Instantiating expiration expiration { reply-message = "Password Has Expired " } Module: Linked to module rlm_logintime Module: Instantiating logintime logintime { reply-message = "You are calling outside your allowed timespan " minimum-timeout = 60 } } radiusd: #### Loading Virtual Servers #### server inner-tunnel { modules { Module: Checking authenticate {...} for more modules to load Module: Linked to module rlm_pap Module: Instantiating pap pap { encryption_scheme = "auto" auto_header = no } Module: Linked to module rlm_chap Module: Instantiating chap Module: Linked to module rlm_mschap Module: Instantiating mschap mschap { use_mppe = yes require_encryption = no require_strong = no with_ntdomain_hack = no } Module: Linked to module rlm_unix Module: Instantiating unix unix { radwtmp = "/home/radius/var/log/radius/radwtmp" } Module: Linked to module rlm_eap Module: Instantiating eap eap { default_eap_type = "md5" timer_expire = 60 ignore_unknown_eap_types = no cisco_accounting_username_bug = no max_sessions = 2048 } Module: Linked to sub-module rlm_eap_md5 Module: Instantiating eap-md5 Module: Linked to sub-module rlm_eap_leap Module: Instantiating eap-leap Module: Linked to sub-module rlm_eap_gtc Module: Instantiating eap-gtc gtc { challenge = "Password: " auth_type = "PAP" } Module: Linked to sub-module rlm_eap_tls Module: Instantiating eap-tls tls { rsa_key_exchange = no dh_key_exchange = yes rsa_key_length = 512 dh_key_length = 512 verify_depth = 0 pem_file_type = yes private_key_file = "/home/radius/etc/raddb/certs/server.pem" certificate_file = "/home/radius/etc/raddb/certs/server.pem" CA_file = "/home/radius/etc/raddb/certs/ca.pem" private_key_password = "whatever" dh_file = "/home/radius/etc/raddb/certs/dh" random_file = "/home/radius/etc/raddb/certs/random" fragment_size = 1024 include_length = yes check_crl = no cipher_list = "DEFAULT" make_cert_command = "/home/radius/etc/raddb/certs/bootstrap" cache { enable = no lifetime = 24 max_entries = 255 } } make: openssl: Command not found make: *** [dh] Error 127 Exec-Program output: openssl dhparam -out dh 1024 Exec-Program-Wait: plaintext: openssl dhparam -out dh 1024 Exec-Program: returned: 2 rlm_eap: Failed to initialize type tls /home/radius/etc/raddb/eap.conf[17]: Instantiation failed for module "eap" /home/radius/etc/raddb/sites-enabled/inner-tunnel[223]: Failed to find module "eap". /home/radius/etc/raddb/sites-enabled/inner-tunnel[176]: Errors parsing authenticate section. } } Errors initializing modules I believe something is still not right with openssl, I tried running openssl, command not found... Do I need to manually build openssl? What about eap module? I've noticed few required messages; r...@radius:/home/radius# grep requires ../logs/configure configure: WARNING: FAILURE: rlm_counter requires: libgdbm. configure: WARNING: FAILURE: rlm_dbm requires: (ndbm.h or gdbm/ndbm.h or gdbm-ndbm.h) (libndbm or libgdbm or libgdbm_compat). configure: WARNING: FAILURE: rlm_eap_ikev2 requires: libeap-ikev2 EAPIKEv2/connector.h. configure: WARNING: FAILURE: rlm_eap_tnc requires: -lTNCS. configure: WARNING: FAILURE: rlm_ippool requires: libgdbm. configure: WARNING: FAILURE: rlm_krb5 requires: krb5.h krb5. configure: WARNING: FAILURE: rlm_ldap requires: libldap_r ldap.h. configure: WARNING: FAILURE: rlm_pam requires: libpam. configure: WARNING: FAILURE: rlm_perl requires: libperl.so. configure: WARNING: FAILURE: rlm_python requires: Python.h libpython2.5. configure: WARNING: FAILURE: rlm_sql_iodbc requires: libiodbc isql.h. configure: WARNING: FAILURE: rlm_sql_mysql requires: libmysqlclient_r mysql.h. configure: WARNING: FAILURE: rlm_sql_postgresql requires: libpq-fe.h libpq. configure: WARNING: FAILURE: rlm_sql_oracle requires: oci.h. configure: WARNING: FAILURE: rlm_sql_unixodbc requires: libodbc sql.h. I don't know if those can be ignored or not... Thanks for your help! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html