
I tried and I'm getting the same issue.

Here's the debug.

rad_recv: Access-Request packet from host port 1034, id=6, 
        Message-Authenticator = 0x948b8c046dfeede3e79b0b99ef7afa1a
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xe1943d61e4922436507a40c0ae7feeb0
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 6 length 43
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Identity - bob
[peap] Got inner identity 'bob'
[peap] Setting default EAP type for tunneled EAP session.
[peap] Got tunneled request
        EAP-Message = 0x0206000801626f62
server  {
  PEAP: Setting User-Name to bob
Sending tunneled request
        EAP-Message = 0x0206000801626f62
        FreeRADIUS-Proxied-To =
        User-Name = "bob"
server inner-tunnel {
# Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] EAP packet type response id 6 length 8
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[files] users: Matched entry bob at line 222
++[files] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing MD5-Password from hex encoding
[pap] WARNING: Auth-Type already set.  Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
[peap] Got tunneled reply code 11
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xdcb7ba18dcb0a038bd0375a7346d3160
[peap] Got tunneled reply RADIUS code 11
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xdcb7ba18dcb0a038bd0375a7346d3160
[peap] Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 6 to port 1034
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xe1943d61e7932436507a40c0ae7feeb0
Finished request 7.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host port 1034, id=7, 
        Message-Authenticator = 0x8069a3d06eedbc23049e7abb97238b0c
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xe1943d61e7932436507a40c0ae7feeb0
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 91
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state phase2
[peap] EAP type mschapv2
[peap] Got tunneled request
        EAP-Message = 
server  {
  PEAP: Setting User-Name to bob
Sending tunneled request
        EAP-Message = 
        FreeRADIUS-Proxied-To =
        User-Name = "bob"
        State = 0xdcb7ba18dcb0a038bd0375a7346d3160
server inner-tunnel {
# Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] EAP packet type response id 7 length 62
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[files] users: Matched entry bob at line 222
++[files] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing MD5-Password from hex encoding
[pap] WARNING: Auth-Type already set.  Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/mschapv2
[eap] processing type mschapv2
[mschapv2] # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
[mschapv2] +- entering group MS-CHAP {...}
[mschap] No Cleartext-Password configured.  Cannot create LM-Password.
[mschap] No Cleartext-Password configured.  Cannot create NT-Password.
[mschap] Creating challenge hash with username: bob
[mschap] Told to do MS-CHAPv2 for bob with NT-Password
[mschap] FAILED: No NT/LM-Password.  Cannot perform authentication.
[mschap] FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
[eap] Freeing handler
++[eap] returns reject
Failed to authenticate the user.
        expand: password incorrecto -> password incorrecto
Login incorrect: [bob/<via Auth-Type = EAP>] (from client port 0 
via TLS tunnel) password incorrecto
} # server inner-tunnel
[peap] Got tunneled reply code 3
        MS-CHAP-Error = "\007E=691 R=1"
        EAP-Message = 0x04070004
        Message-Authenticator = 0x00000000000000000000000000000000
[peap] Got tunneled reply RADIUS code 3
        MS-CHAP-Error = "\007E=691 R=1"
        EAP-Message = 0x04070004
        Message-Authenticator = 0x00000000000000000000000000000000
[peap] Tunneled authentication was rejected.
[peap] FAILURE
++[eap] returns handled
Sending Access-Challenge of id 7 to port 1034
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xe1943d61e69c2436507a40c0ae7feeb0
Finished request 8.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host port 1034, id=8, 
        Message-Authenticator = 0xe3af8b2689dcb116c182ab22757afc9b
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xe1943d61e69c2436507a40c0ae7feeb0
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 8 length 43
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state send tlv failure
[peap] Received EAP-TLV response.
[peap]  The users session was previously rejected: returning reject (again.)
[peap]  *** This means you need to read the PREVIOUS messages in the debug 
[peap]  *** to find out the reason why the user was rejected.
[peap]  *** Look for "reject" or "fail".  Those earlier messages will tell you.
[peap]  *** what went wrong, and how to fix the problem.
[eap] Handler failed in EAP/peap
[eap] Failed in EAP select
++[eap] returns invalid
Failed to authenticate the user.
        expand: password incorrecto -> password incorrecto
Login incorrect: [bob/<via Auth-Type = EAP>] (from client port 3 
cli 10-40-F3-95-22-24) password incorrecto
Using Post-Auth-Type Reject
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group REJECT {...}
[attr_filter.access_reject]     expand: %{User-Name} -> bob
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 9 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 9
Sending Access-Reject of id 8 to port 1034
        EAP-Message = 0x04080004
        Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 3.8 seconds.
Cleaning up request 1 ID 0 with timestamp +22
Cleaning up request 2 ID 1 with timestamp +22
Cleaning up request 3 ID 2 with timestamp +22
Cleaning up request 4 ID 3 with timestamp +22
Cleaning up request 5 ID 4 with timestamp +22
Cleaning up request 6 ID 5 with timestamp +22
Cleaning up request 7 ID 6 with timestamp +22
Cleaning up request 8 ID 7 with timestamp +22
Waking up in 1.0 seconds.
Cleaning up request 9 ID 8 with timestamp +22
Ready to process requests.
rad_recv: Access-Request packet from host port 1036, id=0, 
        Message-Authenticator = 0xa0906d6e9baa55c0f2d52b574d79f6a4
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 0x0200000801626f62
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 0 length 8
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[files] users: Matched entry bob at line 222
++[files] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing MD5-Password from hex encoding
[pap] WARNING: Auth-Type already set.  Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type tls
[tls] Initiate
[tls] Start returned 1
++[eap] returns handled
Sending Access-Challenge of id 0 to port 1036
        EAP-Message = 0x010100061920
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xee9c16b0ee9d0f4bc37318d43ce26de7
Finished request 10.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1036, id=1, 
        Message-Authenticator = 0x5cdd8e0b50791ff49a6476fd24974e5e
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xee9c16b0ee9d0f4bc37318d43ce26de7
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 1 length 132
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
  TLS Length 122
[peap] Length Included
[peap] eaptls_verify returned 11
[peap]     (other): before/accept initialization
[peap]     TLS_accept: before/accept initialization
[peap] <<< TLS 1.0 Handshake [length 0075], ClientHello
[peap]     TLS_accept: SSLv3 read client hello A
[peap] >>> TLS 1.0 Handshake [length 002a], ServerHello
[peap]     TLS_accept: SSLv3 write server hello A
[peap] >>> TLS 1.0 Handshake [length 08f8], Certificate
[peap]     TLS_accept: SSLv3 write certificate A
[peap] >>> TLS 1.0 Handshake [length 0004], ServerHelloDone
[peap]     TLS_accept: SSLv3 write server done A
[peap]     TLS_accept: SSLv3 flush data
[peap]     TLS_accept: Need to read more data: SSLv3 read client certificate A
In SSL Handshake Phase
In SSL Accept mode
[peap] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 1 to port 1036
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 0x381cca41e1ac6b870a2a6c38
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xee9c16b0ef9e0f4bc37318d43ce26de7
Finished request 11.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1036, id=2, 
        Message-Authenticator = 0xc739fbd0ef9dcf866e7499bf3e1fc0da
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xee9c16b0ef9e0f4bc37318d43ce26de7
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 0x020200061900
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 2 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1
[peap] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 2 to port 1036
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 
        EAP-Message = 0x6e74696461642043
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xee9c16b0ec9f0f4bc37318d43ce26de7
Finished request 12.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1036, id=3, 
        Message-Authenticator = 0x9721441fee42173f4ac830082831c323
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xee9c16b0ec9f0f4bc37318d43ce26de7
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 0x020300061900
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 3 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake fragment handler
[peap] eaptls_verify returned 1
[peap] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 3 to port 1036
        EAP-Message = 
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xee9c16b0ed980f4bc37318d43ce26de7
Finished request 13.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1036, id=4, 
        Message-Authenticator = 0x5fca46c54b0196cd6fe7153f9dbfca56
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xee9c16b0ed980f4bc37318d43ce26de7
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 
        EAP-Message = 
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 4 length 253
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
  TLS Length 326
[peap] Length Included
[peap] eaptls_verify returned 11
[peap] <<< TLS 1.0 Handshake [length 0106], ClientKeyExchange
[peap]     TLS_accept: SSLv3 read client key exchange A
[peap] <<< TLS 1.0 ChangeCipherSpec [length 0001]
[peap] <<< TLS 1.0 Handshake [length 0010], Finished
[peap]     TLS_accept: SSLv3 read finished A
[peap] >>> TLS 1.0 ChangeCipherSpec [length 0001]
[peap]     TLS_accept: SSLv3 write change cipher spec A
[peap] >>> TLS 1.0 Handshake [length 0010], Finished
[peap]     TLS_accept: SSLv3 write finished A
[peap]     TLS_accept: SSLv3 flush data
[peap]     (other): SSL negotiation finished successfully
SSL Connection Established
[peap] eaptls_process returned 13
++[eap] returns handled
Sending Access-Challenge of id 4 to port 1036
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xee9c16b0ea990f4bc37318d43ce26de7
Finished request 14.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1036, id=5, 
        Message-Authenticator = 0xbe2776375b4e10ab3f30444b3ace7d8a
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xee9c16b0ea990f4bc37318d43ce26de7
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 0x020500061900
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 5 length 6
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] Received TLS ACK
[peap] ACK handshake is finished
[peap] eaptls_verify returned 3
[peap] eaptls_process returned 3
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state TUNNEL ESTABLISHED
++[eap] returns handled
Sending Access-Challenge of id 5 to port 1036
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xee9c16b0eb9a0f4bc37318d43ce26de7
Finished request 15.
Going to the next request
Waking up in 4.9 seconds.
rad_recv: Access-Request packet from host port 1036, id=6, 
        Message-Authenticator = 0x13b610bf50f117d1384d073b43625dec
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xee9c16b0eb9a0f4bc37318d43ce26de7
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 6 length 43
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Identity - bob
[peap] Got inner identity 'bob'
[peap] Setting default EAP type for tunneled EAP session.
[peap] Got tunneled request
        EAP-Message = 0x0206000801626f62
server  {
  PEAP: Setting User-Name to bob
Sending tunneled request
        EAP-Message = 0x0206000801626f62
        FreeRADIUS-Proxied-To =
        User-Name = "bob"
server inner-tunnel {
# Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] EAP packet type response id 6 length 8
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[files] users: Matched entry bob at line 222
++[files] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing MD5-Password from hex encoding
[pap] WARNING: Auth-Type already set.  Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] EAP Identity
[eap] processing type mschapv2
rlm_eap_mschapv2: Issuing Challenge
++[eap] returns handled
} # server inner-tunnel
[peap] Got tunneled reply code 11
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x3ba3714d3ba46ba312c4d56b659c6f28
[peap] Got tunneled reply RADIUS code 11
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x3ba3714d3ba46ba312c4d56b659c6f28
[peap] Got tunneled Access-Challenge
++[eap] returns handled
Sending Access-Challenge of id 6 to port 1036
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xee9c16b0e89b0f4bc37318d43ce26de7
Finished request 16.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host port 1036, id=7, 
        Message-Authenticator = 0x4d87ac714c2dd5f1386fa20d1ec9d726
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xee9c16b0e89b0f4bc37318d43ce26de7
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 7 length 91
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state phase2
[peap] EAP type mschapv2
[peap] Got tunneled request
        EAP-Message = 
server  {
  PEAP: Setting User-Name to bob
Sending tunneled request
        EAP-Message = 
        FreeRADIUS-Proxied-To =
        User-Name = "bob"
        State = 0x3ba3714d3ba46ba312c4d56b659c6f28
server inner-tunnel {
# Executing section authorize from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authorize {...}
++[chap] returns noop
++[mschap] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
++[control] returns noop
[eap] EAP packet type response id 7 length 62
[eap] No EAP Start, assuming it's an on-going EAP conversation
++[eap] returns updated
[files] users: Matched entry bob at line 222
++[files] returns ok
++[expiration] returns noop
++[logintime] returns noop
[pap] Normalizing MD5-Password from hex encoding
[pap] WARNING: Auth-Type already set.  Not setting to PAP
++[pap] returns noop
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/inner-tunnel
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/mschapv2
[eap] processing type mschapv2
[mschapv2] # Executing group from file /etc/raddb/sites-enabled/inner-tunnel
[mschapv2] +- entering group MS-CHAP {...}
[mschap] No Cleartext-Password configured.  Cannot create LM-Password.
[mschap] No Cleartext-Password configured.  Cannot create NT-Password.
[mschap] Creating challenge hash with username: bob
[mschap] Told to do MS-CHAPv2 for bob with NT-Password
[mschap] FAILED: No NT/LM-Password.  Cannot perform authentication.
[mschap] FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
[eap] Freeing handler
++[eap] returns reject
Failed to authenticate the user.
        expand: password incorrecto -> password incorrecto
Login incorrect: [bob/<via Auth-Type = EAP>] (from client port 0 
via TLS tunnel) password incorrecto
} # server inner-tunnel
[peap] Got tunneled reply code 3
        MS-CHAP-Error = "\007E=691 R=1"
        EAP-Message = 0x04070004
        Message-Authenticator = 0x00000000000000000000000000000000
[peap] Got tunneled reply RADIUS code 3
        MS-CHAP-Error = "\007E=691 R=1"
        EAP-Message = 0x04070004
        Message-Authenticator = 0x00000000000000000000000000000000
[peap] Tunneled authentication was rejected.
[peap] FAILURE
++[eap] returns handled
Sending Access-Challenge of id 7 to port 1036
        EAP-Message = 
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0xee9c16b0e9940f4bc37318d43ce26de7
Finished request 17.
Going to the next request
Waking up in 4.8 seconds.
rad_recv: Access-Request packet from host port 1036, id=8, 
        Message-Authenticator = 0xcf8322e778b5603e0bc5c162899a06b9
        Service-Type = Framed-User
        User-Name = "bob"
        Framed-MTU = 1488
        State = 0xee9c16b0e9940f4bc37318d43ce26de7
        Called-Station-Id = "40-01-C6-DF-C7-C2:Tamales"
        Calling-Station-Id = "10-40-F3-95-22-24"
        NAS-Identifier = "3Com Access Point 7760"
        NAS-Port-Type = Wireless-802.11
        Connect-Info = "CONNECT 54Mbps 802.11g"
        EAP-Message = 
        NAS-IP-Address =
        NAS-Port = 3
        NAS-Port-Id = "STA port # 3"
# Executing section authorize from file /etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "bob", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] EAP packet type response id 8 length 43
[eap] Continuing tunnel setup.
++[eap] returns ok
Found Auth-Type = EAP
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group authenticate {...}
[eap] Request found, released from the list
[eap] EAP/peap
[eap] processing type peap
[peap] processing EAP-TLS
[peap] eaptls_verify returned 7
[peap] Done initial handshake
[peap] eaptls_process returned 7
[peap] EAPTLS_OK
[peap] Session established.  Decoding tunneled attributes.
[peap] Peap state send tlv failure
[peap] Received EAP-TLV response.
[peap]  The users session was previously rejected: returning reject (again.)
[peap]  *** This means you need to read the PREVIOUS messages in the debug 
[peap]  *** to find out the reason why the user was rejected.
[peap]  *** Look for "reject" or "fail".  Those earlier messages will tell you.
[peap]  *** what went wrong, and how to fix the problem.
[eap] Handler failed in EAP/peap
[eap] Failed in EAP select
++[eap] returns invalid
Failed to authenticate the user.
        expand: password incorrecto -> password incorrecto
Login incorrect: [bob/<via Auth-Type = EAP>] (from client port 3 
cli 10-40-F3-95-22-24) password incorrecto
Using Post-Auth-Type Reject
# Executing group from file /etc/raddb/sites-enabled/default
+- entering group REJECT {...}
[attr_filter.access_reject]     expand: %{User-Name} -> bob
 attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 18 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 18
Sending Access-Reject of id 8 to port 1036
        EAP-Message = 0x04080004
        Message-Authenticator = 0x00000000000000000000000000000000
Waking up in 3.8 seconds.

I think I'm missing something on the configuration, any ideas?



On Apr 23, 2012, at 3:14 PM, Matthew Newton wrote:

> On Mon, Apr 23, 2012 at 12:48:33PM -0500, Reyes Jimenez Alfonso Alejandro 
> wrote:
>> bob Cleartext-Password := "Test"
>> and we would like to use the following:
>> bob MD5-Password := "f43ed6ad2f43ea778b65557c626262ysu"
> There are non-hex chars in that string, so it's never going to work.
>> What changes do we need to do ir order to allow that kind of authentication, 
>> any ideas?
> It works fine. Generate password:
> $ echo -n Test | md5sum
> 0cbc6611f5540bd0809a388dc95a615b  -
> Add to users:
> bob           MD5-Password := "0cbc6611f5540bd0809a388dc95a615b"
> Check:
> $ radtest bob Test localhost 1 testing123
> Sending Access-Request of id 73 to port 1812
>  User-Name = "bob"
>  User-Password = "Test"
>  NAS-IP-Address =
>  NAS-Port = 1
>  Message-Authenticator = 0x00000000000000000000000000000000
> rad_recv: Access-Accept packet from host port 1812, id=73, length=20
> Cheers,
> Matthew
> --
> Matthew Newton, Ph.D. <>
> Systems Architect (UNIX and Networks), Network Services,
> I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom
> For IT help contact helpdesk extn. 2253, <>
> -
> List info/subscribe/unsubscribe? See


El contenido de este mensaje es confidencial. Si usted ha recibido este mensaje 
por error, le ruego que no lo reenvĂ­e y lo borre inmediatamente.

The contents of this message are confidential. If message has been received in 
error, please do not forward and destroy immediately. 

List info/subscribe/unsubscribe? See

Reply via email to