
I'm going crazy with my RADIUS configuration. For some days all works. But
now i can't authenticate with xp client, linux still works.
It seams that it is a problem with the EAP configuration or with the
certificates, but i doesn't find any error in the debug output!?

Maybe this will be the problem, "[eap] No EAP Start, assuming it's an
on-going EAP conversation" but I don't know waht i can do. Please give me
some futher hints. I want to authenticate with EAP-PEAP and MSCHAP.

rad_recv: Access-Request packet from host port 1812, id=43,
        NAS-IP-Address =
        NAS-Port = 50005
        NAS-Port-Type = Ethernet
        User-Name = "FIRMA1\\usera"
        Called-Station-Id = "00-15-F9-D8-7C-C5"
        Calling-Station-Id = "00-1A-4B-63-69-0B"
        Service-Type = Framed-User
        Framed-MTU = 1500
        EAP-Message = 0x02000014014649524d41315c626c657273636861
        Message-Authenticator = 0x7371c1f1726066beb9dabe848c328593
+- entering group authorize {...}
++[preprocess] returns ok
[auth_log]      expand:
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d ->
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands
to /var/log/freeradius/radacct/
[auth_log]      expand: %t -> Sun Nov  7 11:36:33 2010
++[auth_log] returns ok
++[chap] returns noop
++[mschap] returns noop
[ntdomain] Looking up realm "FIRMA1" for User-Name = "FIRMA1\usera"
[ntdomain] Found realm "FIRMA1"
[ntdomain] Adding Stripped-User-Name = "usera"
[ntdomain] Adding Realm = "FIRMA1"
[ntdomain] Authentication realm is LOCAL.
++[ntdomain] returns ok
[eap] EAP packet type response id 0 length 20
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
[ldap] performing user authorization for usera
[ldap]  expand: %{Stripped-User-Name} -> usera
[ldap]  expand: (uid=%{%{Stripped-User-Name}:-%{User-Name}}) -> (uid=usera)
[ldap]  expand: dc=firma1,dc=de -> dc=firma1,dc=de
  [ldap] ldap_get_conn: Checking Id: 0
  [ldap] ldap_get_conn: Got Id: 0
  [ldap] performing search in dc=firma1,dc=de, with filter (uid=usera)
[ldap] Added User-Password = {SSHA}WNtfzJKztV/VYNqJAew//EpfaqFTTmRY in check
[ldap] No default NMAS login sequence
[ldap] looking for check items in directory...
  [ldap] sambaNtPassword -> NT-Password ==
  [ldap] sambaLmPassword -> LM-Password ==
[ldap] looking for reply items in directory...
[ldap] user usera authorized to use remote access
  [ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
Found Auth-Type = EAP
!!!    Replacing User-Password in config items with Cleartext-Password.    
!!! Please update your configuration so that the "known good"              
!!! clear text password is in Cleartext-Password, and not in User-Password.
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 43 to port 1812
        EAP-Message = 0x010100061920
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xe5811fdbe58006df807df3f78bad2b67
Finished request 42.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1812, id=44,
        NAS-IP-Address =
        NAS-Port = 50005
        NAS-Port-Type = Ethernet
        User-Name = "FIRMA1\\usera"
        Called-Station-Id = "00-15-F9-D8-7C-C5"
        Calling-Station-Id = "00-1A-4B-63-69-0B"
        Service-Type = Framed-User
        Framed-MTU = 1500
        State = 0xe5811fdbe58006df807df3f78bad2b67
        EAP-Message =
        Message-Authenticator = 0xc287af478d7c193cfcec6b09c33c099c
+- entering group authorize {...}
++[preprocess] returns ok
[auth_log]      expand:
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d ->
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands
to /var/log/freeradius/radacct/
[auth_log]      expand: %t -> Sun Nov  7 11:36:33 2010
++[auth_log] returns ok
++[chap] returns noop
++[mschap] returns noop
[ntdomain] Looking up realm "FIRMA1" for User-Name = "FIRMA1\usera"
[ntdomain] Found realm "FIRMA1"
[ntdomain] Adding Stripped-User-Name = "usera"
[ntdomain] Adding Realm = "FIRMA1"
[ntdomain] Authentication realm is LOCAL.
++[ntdomain] returns ok
[eap] EAP packet type response id 1 length 87
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
  TLS Length 77
[peap] Length Included
[peap] eaptls_verify returned 11 
[peap]     (other): before/accept initialization 
[peap]     TLS_accept: before/accept initialization 
[peap] <<< TLS 1.0 Handshake [length 0048], ClientHello  
[peap]     TLS_accept: SSLv3 read client hello A 
[peap] >>> TLS 1.0 Handshake [length 0031], ServerHello  
[peap]     TLS_accept: SSLv3 write server hello A 
[peap] >>> TLS 1.0 Handshake [length 07d8], Certificate  
[peap]     TLS_accept: SSLv3 write certificate A 
[peap] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone  
[peap]     TLS_accept: SSLv3 write server done A 
[peap]     TLS_accept: SSLv3 flush data 
[peap]     TLS_accept: Need to read more data: SSLv3 read client certificate
In SSL Handshake Phase 
In SSL Accept mode  
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 44 to port 1812
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message = 0x550406130244453116301406
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xe5811fdbe48306df807df3f78bad2b67
Finished request 43.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1812, id=45,
        NAS-IP-Address =
        NAS-Port = 50005
        NAS-Port-Type = Ethernet
        User-Name = "FIRMA1\\usera"
        Called-Station-Id = "00-15-F9-D8-7C-C5"
        Calling-Station-Id = "00-1A-4B-63-69-0B"
        Service-Type = Framed-User
        Framed-MTU = 1500
        State = 0xe5811fdbe48306df807df3f78bad2b67
        EAP-Message = 0x020200061900
        Message-Authenticator = 0x6595267991b7298210d423ea9e5e7e34
+- entering group authorize {...}
++[preprocess] returns ok
[auth_log]      expand:
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d ->
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands
to /var/log/freeradius/radacct/
[auth_log]      expand: %t -> Sun Nov  7 11:36:33 2010
++[auth_log] returns ok
++[chap] returns noop
++[mschap] returns noop
[ntdomain] Looking up realm "FIRMA1" for User-Name = "FIRMA1\usera"
[ntdomain] Found realm "FIRMA1"
[ntdomain] Adding Stripped-User-Name = "usera"
[ntdomain] Adding Realm = "FIRMA1"
[ntdomain] Authentication realm is LOCAL.
++[ntdomain] returns ok
[eap] EAP packet type response id 2 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 45 to port 1812
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message = 0xe30c97f4b32d6d07
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xe5811fdbe78206df807df3f78bad2b67
Finished request 44.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1812, id=46,
        NAS-IP-Address =
        NAS-Port = 50005
        NAS-Port-Type = Ethernet
        User-Name = "FIRMA1\\usera"
        Called-Station-Id = "00-15-F9-D8-7C-C5"
        Calling-Station-Id = "00-1A-4B-63-69-0B"
        Service-Type = Framed-User
        Framed-MTU = 1500
        State = 0xe5811fdbe78206df807df3f78bad2b67
        EAP-Message = 0x020300061900
        Message-Authenticator = 0x5b1899fb14339eca7ba59de266860af7
+- entering group authorize {...}
++[preprocess] returns ok
[auth_log]      expand:
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d ->
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands
to /var/log/freeradius/radacct/
[auth_log]      expand: %t -> Sun Nov  7 11:36:33 2010
++[auth_log] returns ok
++[chap] returns noop
++[mschap] returns noop
[ntdomain] Looking up realm "FIRMA1" for User-Name = "FIRMA1\usera"
[ntdomain] Found realm "FIRMA1"
[ntdomain] Adding Stripped-User-Name = "usera"
[ntdomain] Adding Realm = "FIRMA1"
[ntdomain] Authentication realm is LOCAL.
++[ntdomain] returns ok
[eap] EAP packet type response id 3 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 46 to port 1812
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xe5811fdbe68506df807df3f78bad2b67
Finished request 45.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1812, id=47,
        NAS-IP-Address =
        NAS-Port = 50005
        NAS-Port-Type = Ethernet
        User-Name = "FIRMA1\\usera"
        Called-Station-Id = "00-15-F9-D8-7C-C5"
        Calling-Station-Id = "00-1A-4B-63-69-0B"
        Service-Type = Framed-User
        Framed-MTU = 1500
        State = 0xe5811fdbe68506df807df3f78bad2b67
        EAP-Message = 0x020400061900
        Message-Authenticator = 0xc59a1a2d0cfb101ec430dad4e10897b6
+- entering group authorize {...}
++[preprocess] returns ok
[auth_log]      expand:
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d ->
/var/log/freeradius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands
to /var/log/freeradius/radacct/
[auth_log]      expand: %t -> Sun Nov  7 11:36:33 2010
++[auth_log] returns ok
++[chap] returns noop
++[mschap] returns noop
[ntdomain] Looking up realm "FIRMA1" for User-Name = "FIRMA1\usera"
[ntdomain] Found realm "FIRMA1"
[ntdomain] Adding Stripped-User-Name = "usera"
[ntdomain] Adding Realm = "FIRMA1"
[ntdomain] Authentication realm is LOCAL.
++[ntdomain] returns ok
[eap] EAP packet type response id 4 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 47 to port 1812
        EAP-Message = 0x010500061900
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xe5811fdbe18406df807df3f78bad2b67
Finished request 46.
Going to the next request
Waking up in 4.9 seconds.
Cleaning up request 42 ID 43 with timestamp +2802
Cleaning up request 43 ID 44 with timestamp +2802
Cleaning up request 44 ID 45 with timestamp +2802
Cleaning up request 45 ID 46 with timestamp +2802
Cleaning up request 46 ID 47 with timestamp +2802
Ready to process requests.

View this message in context: 
Sent from the FreeRadius - User mailing list archive at Nabble.com.
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to