Here is the rest of the debug

Waking up in 3.3 seconds.
rad_recv: Access-Request packet from host port 32819, id=114,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message = 0x020600061900
        State = 0xaf0b06b8ab0d1f13414e4025002a7e0a
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x39806663461b05b46cf3125e79491f35
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 6 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake is finished
[peap] eaptls_verify returned 3 
[peap] eaptls_process returned 3 
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state TUNNEL ESTABLISHED
++[eap] returns handled
Sending Access-Challenge of id 114 to port 32819
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xaf0b06b8aa0c1f13414e4025002a7e0a
Finished request 14.
Going to the next request
Waking up in 3.3 seconds.
rad_recv: Access-Request packet from host port 32819, id=115,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        State = 0xaf0b06b8aa0c1f13414e4025002a7e0a
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x76eadd506811e5fbaaa9bd651c72cfa5
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 56
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap] eaptls_process returned 7 
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Identity - host/
[peap] Got inner identity 'host/'
[peap] Setting default EAP type for tunneled EAP session.
[peap] Got tunneled request
        EAP-Message =
server  {
  PEAP: Setting User-Name to host/
Sending tunneled request
        EAP-Message =
        FreeRADIUS-Proxied-To =
        User-Name = "host/"
server inner-tunnel {
# Executing section authorize from file
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] No '\' in User-Name = "host/", looking up
realm NULL
[ntdomain] No such realm "NULL"
++[ntdomain] returns noop
++[control] returns noop
[eap] EAP packet type response id 7 length 33
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
[peap] Got tunneled reply code 11
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xdff71f9adfff05115ad48af9ef7a1fd6
[peap] Got tunneled reply RADIUS code 11
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xdff71f9adfff05115ad48af9ef7a1fd6
[peap] Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 115 to port 32819
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xaf0b06b8a9031f13414e4025002a7e0a
Finished request 15.
Going to the next request
Waking up in 3.3 seconds.
rad_recv: Access-Request packet from host port 32819, id=116,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        State = 0xaf0b06b8a9031f13414e4025002a7e0a
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0xddfda2824f60dccbb3557bb433925a59
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 8 length 110
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap] eaptls_process returned 7 
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state phase2
[peap] EAP type mschapv2
[peap] Got tunneled request
        EAP-Message =
server  {
  PEAP: Setting User-Name to host/
Sending tunneled request
        EAP-Message =
        FreeRADIUS-Proxied-To =
        User-Name = "host/"
        State = 0xdff71f9adfff05115ad48af9ef7a1fd6
server inner-tunnel {
# Executing section authorize from file
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] No '\' in User-Name = "host/", looking up
realm NULL
[ntdomain] No such realm "NULL"
++[ntdomain] returns noop
++[control] returns noop
[eap] EAP packet type response id 8 length 87
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/mschapv2
[eap] processing type mschapv2
[mschapv2] # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
[mschapv2] +- entering group MS-CHAP {...}
[mschap] No Cleartext-Password configured.  Cannot create LM-Password.
[mschap] No Cleartext-Password configured.  Cannot create NT-Password.
[mschap] Creating challenge hash with username: host/
[mschap] Told to do MS-CHAPv2 for host/ with
[mschap] FAILED: No NT/LM-Password.  Cannot perform authentication.
[mschap] FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
[eap] Freeing handler
++[eap] returns reject
Failed to authenticate the user.
} # server inner-tunnel
[peap] Got tunneled reply code 3
        MS-CHAP-Error = "\010E=691 R=1"
        EAP-Message = 0x04080004
        Message-Authenticator = 0x00000000000000000000000000000000
[peap] Got tunneled reply RADIUS code 3
        MS-CHAP-Error = "\010E=691 R=1"
        EAP-Message = 0x04080004
        Message-Authenticator = 0x00000000000000000000000000000000
[peap] Tunneled authentication was rejected.
[peap] FAILURE
++[eap] returns handled
Sending Access-Challenge of id 116 to port 32819
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xaf0b06b8a8021f13414e4025002a7e0a
Finished request 16.
Going to the next request
Waking up in 3.3 seconds.
rad_recv: Access-Request packet from host port 32819, id=117,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        State = 0xaf0b06b8a8021f13414e4025002a7e0a
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x4513566759242c90b364904f4b5131dd
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 9 length 38
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap] eaptls_process returned 7 
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state send tlv failure
[peap] Received EAP-TLV response.
[peap]  The users session was previously rejected: returning reject (again.)
[peap]  *** This means you need to read the PREVIOUS messages in the debug
[peap]  *** to find out the reason why the user was rejected.
[peap]  *** Look for "reject" or "fail".  Those earlier messages will tell
[peap]  *** what went wrong, and how to fix the problem.
[eap] Handler failed in EAP/peap
[eap] Failed in EAP select
++[eap] returns invalid
Failed to authenticate the user.
Using Post-Auth-Type Reject
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group REJECT {...}
[attr_filter.access_reject]     expand: %{User-Name} ->
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 17 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 17
Sending Access-Reject of id 117 to port 32819
        EAP-Message = 0x04090004
        Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 2.3 seconds.
rad_recv: Access-Request packet from host port 32819, id=118,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x3079a4568eb504dec1712dd4b53b8d02
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 1 length 33
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
[ldap] performing user authorization for host/
[ldap]  expand: (uid=%{mschap:User-Name:-%{User-Name}}) -> (uid=TEST-11501$)
[ldap]  expand: o=hpsd_48 -> o=hpsd_48
  [ldap] ldap_get_conn: Checking Id: 0
  [ldap] ldap_get_conn: Got Id: 0
  [ldap] performing search in o=hpsd_48, with filter (uid=TEST-11501$)
[ldap] Added the eDirectory password xxxx in check items as
[ldap] looking for check items in directory...
[ldap] looking for reply items in directory...
[ldap] user host/ authorized to use remote access
  [ldap] ldap_release_conn: Release Id: 0
++[ldap] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] WARNING: Auth-Type already set.  Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 118 to port 32819
        EAP-Message = 0x010200061920
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x29d0da4429d2c35a7379c61a78aa62d0
Finished request 18.
Going to the next request
Waking up in 1.9 seconds.
rad_recv: Access-Request packet from host port 32819, id=119,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        State = 0x29d0da4429d2c35a7379c61a78aa62d0
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x060dab8335726b77ad25c74cf5654e79
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 2 length 87
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
  TLS Length 77
[peap] Length Included
[peap] eaptls_verify returned 11 
[peap]     (other): before/accept initialization
[peap]     TLS_accept: before/accept initialization
[peap] <<< TLS 1.0 Handshake [length 0048], ClientHello  
[peap]     TLS_accept: SSLv3 read client hello A
[peap] >>> TLS 1.0 Handshake [length 0031], ServerHello  
[peap]     TLS_accept: SSLv3 write server hello A
[peap] >>> TLS 1.0 Handshake [length 085e], Certificate  
[peap]     TLS_accept: SSLv3 write certificate A
[peap] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone  
[peap]     TLS_accept: SSLv3 write server done A
[peap]     TLS_accept: SSLv3 flush data
[peap]     TLS_accept: Need to read more data: SSLv3 read client certificate
In SSL Handshake Phase 
In SSL Accept mode  
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 119 to port 32819
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message = 0x860004ab308204a73082038f
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x29d0da4428d3c35a7379c61a78aa62d0
Finished request 19.
Going to the next request
Waking up in 1.9 seconds.
rad_recv: Access-Request packet from host port 32819, id=120,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message = 0x020300061900
        State = 0x29d0da4428d3c35a7379c61a78aa62d0
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x7a7426cfa0958f6618608192a3cb78ee
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 3 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 120 to port 32819
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message =
        EAP-Message = 0x53c8cb22d3f8f1f7
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x29d0da442bd4c35a7379c61a78aa62d0
Finished request 20.
Going to the next request
Waking up in 1.9 seconds.
rad_recv: Access-Request packet from host port 32819, id=121,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message = 0x020400061900
        State = 0x29d0da442bd4c35a7379c61a78aa62d0
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0xbf252b738f6dd6c069edff642dcff0a3
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 4 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 121 to port 32819
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x29d0da442ad5c35a7379c61a78aa62d0
Finished request 21.
Going to the next request
Waking up in 1.9 seconds.
rad_recv: Access-Request packet from host port 32819, id=122,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        EAP-Message =
        State = 0x29d0da442ad5c35a7379c61a78aa62d0
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x22b3c9ec5509579aebcb622ef41a99f9
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 5 length 253
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
  TLS Length 310
[peap] Length Included
[peap] eaptls_verify returned 11 
[peap] <<< TLS 1.0 Handshake [length 0106], ClientKeyExchange  
[peap]     TLS_accept: SSLv3 read client key exchange A
[peap] <<< TLS 1.0 ChangeCipherSpec [length 0001]  
[peap] <<< TLS 1.0 Handshake [length 0010], Finished  
[peap]     TLS_accept: SSLv3 read finished A
[peap] >>> TLS 1.0 ChangeCipherSpec [length 0001]  
[peap]     TLS_accept: SSLv3 write change cipher spec A
[peap] >>> TLS 1.0 Handshake [length 0010], Finished  
[peap]     TLS_accept: SSLv3 write finished A
[peap]     TLS_accept: SSLv3 flush data
[peap]     (other): SSL negotiation finished successfully
SSL Connection Established 
[peap] eaptls_process returned 13 
++[eap] returns handled
Sending Access-Challenge of id 122 to port 32819
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x29d0da442dd6c35a7379c61a78aa62d0
Finished request 22.
Going to the next request
Waking up in 1.9 seconds.
rad_recv: Access-Request packet from host port 32819, id=123,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message = 0x020600061900
        State = 0x29d0da442dd6c35a7379c61a78aa62d0
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x22b2a94e6a00270f56a88f4f5755a62a
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 6 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake is finished
[peap] eaptls_verify returned 3 
[peap] eaptls_process returned 3 
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state TUNNEL ESTABLISHED
++[eap] returns handled
Sending Access-Challenge of id 123 to port 32819
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x29d0da442cd7c35a7379c61a78aa62d0
Finished request 23.
Going to the next request
Waking up in 1.9 seconds.
rad_recv: Access-Request packet from host port 32819, id=124,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        State = 0x29d0da442cd7c35a7379c61a78aa62d0
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x1c1b6e63188001569dd59e8dd28f44fa
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 56
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap] eaptls_process returned 7 
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Identity - host/
[peap] Got inner identity 'host/'
[peap] Setting default EAP type for tunneled EAP session.
[peap] Got tunneled request
        EAP-Message =
server  {
  PEAP: Setting User-Name to host/
Sending tunneled request
        EAP-Message =
        FreeRADIUS-Proxied-To =
        User-Name = "host/"
server inner-tunnel {
# Executing section authorize from file
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] No '\' in User-Name = "host/", looking up
realm NULL
[ntdomain] No such realm "NULL"
++[ntdomain] returns noop
++[control] returns noop
[eap] EAP packet type response id 7 length 33
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
[peap] Got tunneled reply code 11
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x04a0b3fa04a8a9fd98f0050caec42b47
[peap] Got tunneled reply RADIUS code 11
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x04a0b3fa04a8a9fd98f0050caec42b47
[peap] Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 124 to port 32819
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x29d0da442fd8c35a7379c61a78aa62d0
Finished request 24.
Going to the next request
Waking up in 1.9 seconds.
rad_recv: Access-Request packet from host port 32819, id=125,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        State = 0x29d0da442fd8c35a7379c61a78aa62d0
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0x44e390f025907d46607bd59ed8e82319
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 8 length 110
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap] eaptls_process returned 7 
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state phase2
[peap] EAP type mschapv2
[peap] Got tunneled request
        EAP-Message =
server  {
  PEAP: Setting User-Name to host/
Sending tunneled request
        EAP-Message =
        FreeRADIUS-Proxied-To =
        User-Name = "host/"
        State = 0x04a0b3fa04a8a9fd98f0050caec42b47
server inner-tunnel {
# Executing section authorize from file
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[ntdomain] No '\' in User-Name = "host/", looking up
realm NULL
[ntdomain] No such realm "NULL"
++[ntdomain] returns noop
++[control] returns noop
[eap] EAP packet type response id 8 length 87
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
++[files] returns noop
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/mschapv2
[eap] processing type mschapv2
[mschapv2] # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
[mschapv2] +- entering group MS-CHAP {...}
[mschap] No Cleartext-Password configured.  Cannot create LM-Password.
[mschap] No Cleartext-Password configured.  Cannot create NT-Password.
[mschap] Creating challenge hash with username: host/
[mschap] Told to do MS-CHAPv2 for host/ with
[mschap] FAILED: No NT/LM-Password.  Cannot perform authentication.
[mschap] FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
[eap] Freeing handler
++[eap] returns reject
Failed to authenticate the user.
} # server inner-tunnel
[peap] Got tunneled reply code 3
        MS-CHAP-Error = "\010E=691 R=1"
        EAP-Message = 0x04080004
        Message-Authenticator = 0x00000000000000000000000000000000
[peap] Got tunneled reply RADIUS code 3
        MS-CHAP-Error = "\010E=691 R=1"
        EAP-Message = 0x04080004
        Message-Authenticator = 0x00000000000000000000000000000000
[peap] Tunneled authentication was rejected.
[peap] FAILURE
++[eap] returns handled
Sending Access-Challenge of id 125 to port 32819
        EAP-Message =
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x29d0da442ed9c35a7379c61a78aa62d0
Finished request 25.
Going to the next request
Waking up in 1.9 seconds.
rad_recv: Access-Request packet from host port 32819, id=126,
        User-Name = "host/"
        NAS-IP-Address =
        NAS-Port = 1
        NAS-Identifier = ""
        NAS-Port-Type = Wireless-802.11
        Calling-Station-Id = "00265EE9B2CA"
        Called-Station-Id = "000B86611894"
        Service-Type = Login-User
        Framed-MTU = 1100
        EAP-Message =
        State = 0x29d0da442ed9c35a7379c61a78aa62d0
        Aruba-Essid-Name = "HPSD_RAD2"
        Aruba-Location-Id = "Tech 01"
        Message-Authenticator = 0xbe379e062b1087985d9ec6cc244923a1
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "host/", looking up
realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 9 length 38
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7 
[peap] Done initial handshake
[peap] eaptls_process returned 7 
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state send tlv failure
[peap] Received EAP-TLV response.
[peap]  The users session was previously rejected: returning reject (again.)
[peap]  *** This means you need to read the PREVIOUS messages in the debug
[peap]  *** to find out the reason why the user was rejected.
[peap]  *** Look for "reject" or "fail".  Those earlier messages will tell
[peap]  *** what went wrong, and how to fix the problem.
[eap] Handler failed in EAP/peap
[eap] Failed in EAP select
++[eap] returns invalid
Failed to authenticate the user.
Using Post-Auth-Type Reject
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group REJECT {...}
[attr_filter.access_reject]     expand: %{User-Name} ->
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 26 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 26
Sending Access-Reject of id 126 to port 32819
        EAP-Message = 0x04090004
        Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 0.9 seconds.
Cleaning up request 0 ID 100 with timestamp +45
Cleaning up request 1 ID 101 with timestamp +45
Cleaning up request 2 ID 102 with timestamp +45
Cleaning up request 3 ID 103 with timestamp +45
Cleaning up request 4 ID 104 with timestamp +45
Cleaning up request 5 ID 105 with timestamp +45
Cleaning up request 6 ID 106 with timestamp +45
Cleaning up request 7 ID 107 with timestamp +45
Waking up in 1.0 seconds.
Cleaning up request 8 ID 108 with timestamp +45
Waking up in 0.3 seconds.
Cleaning up request 9 ID 109 with timestamp +46
Cleaning up request 10 ID 110 with timestamp +46
Cleaning up request 11 ID 111 with timestamp +46
Cleaning up request 12 ID 112 with timestamp +46
Cleaning up request 13 ID 113 with timestamp +46
Cleaning up request 14 ID 114 with timestamp +46
Cleaning up request 15 ID 115 with timestamp +46
Cleaning up request 16 ID 116 with timestamp +46
Waking up in 1.0 seconds.
Cleaning up request 17 ID 117 with timestamp +46
Waking up in 0.3 seconds.
Cleaning up request 18 ID 118 with timestamp +48
Cleaning up request 19 ID 119 with timestamp +48
Cleaning up request 20 ID 120 with timestamp +48
Cleaning up request 21 ID 121 with timestamp +48
Cleaning up request 22 ID 122 with timestamp +48
Cleaning up request 23 ID 123 with timestamp +48
Cleaning up request 24 ID 124 with timestamp +48
Cleaning up request 25 ID 125 with timestamp +48
Waking up in 1.0 seconds.
Cleaning up request 26 ID 126 with timestamp +48
Ready to process requests.

View this message in context:
Sent from the FreeRadius - User mailing list archive at
List info/subscribe/unsubscribe? See

Reply via email to