<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=29&amp;t=1135" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-11-26T17:25:13+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=29&amp;t=1135</id>
<entry>
<author><name><![CDATA[Tobias]]></name></author>
<updated>2013-11-26T17:25:13+01:00</updated>
<published>2013-11-26T17:25:13+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4668#p4668</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4668#p4668"/>
<title type="html"><![CDATA[Re: Active Directory password written in RADIUS logs]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4668#p4668"><![CDATA[
Hi,<br /><br />we have the same problem. The radius.log is looking like this, with Active Directory Auth<br />my Passwort for XXXXXXXXXXXXX <img src="https://forum.yubico.com/images/smilies/icon_e_wink.gif" alt=";-)" title="Wink" /><br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />Thread 3 got semaphore<br />Thread 3 handling request 0, (1 handled so far)<br />[&lt;thread&gt;] # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />[&lt;thread&gt;] +- entering group authorize {...}<br />++[preprocess] returns ok<br />++[chap] returns noop<br />++[mschap] returns noop<br />[suffix] No '@' in User-Name = &quot;i001000&quot;, looking up realm NULL<br />[suffix] No such realm &quot;NULL&quot;<br />++[suffix] returns noop<br />[eap] No EAP-Message, not doing EAP<br />++[eap] returns noop<br />rlm_perl: Added pair User-Name = i001000<br />rlm_perl: Added pair User-Password = XXXXXXXXXXXccccccdcbgjjvevrkgvlnlkcrntblltlicgvcgcelkdj<br />rlm_perl: Added pair NAS-Port = 0<br />rlm_perl: Added pair NAS-IP-Address = 127.0.0.1<br />++[perl] returns ok<br />[files] users: Matched entry DEFAULT at line 147<br />++[files] returns ok<br />[pap] WARNING! No &quot;known good&quot; password found for the user.  Authentication may fail because of this.<br />++[pap] returns noop<br />Found Auth-Type = PAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group PAP {...}<br />Waking up in 1.4 seconds.<br />Waking up in 2.2 seconds.<br />Waking up in 3.3 seconds.<br />Discarding duplicate request from client 1_127.0.0.1 port 48663 - ID: 62 due to unfinished request 0<br />Waking up in 3.1 seconds.<br />rlm_perl: Added pair User-Name = i001000<br />rlm_perl: Added pair User-Password = XXXXXXXXXXXX<br />rlm_perl: Added pair NAS-IP-Address = 127.0.0.1<br />rlm_perl: Added pair NAS-Port = 0<br />rlm_perl: Added pair Class =<br />rlm_perl: Added pair Auth-Type = PAP<br />++[perl] returns ok<br /># Executing section post-auth from file /etc/freeradius/sites-enabled/default<br />+- entering group post-auth {...}<br />++[exec] returns noop<br />Finished request 0.<br />Going to the next request<br />Thread 3 waiting to be assigned a request<br />Waking up in 2.6 seconds.<br />Cleaning up request 0 ID 62 with timestamp +16<br />Ready to process requests.<br /></div><br /><br />So is there a way to stop freeradius to write down the userpasswords without deaktivation logging. (at least on trouble shooting i will need a log, but never want or need to know any user passwords)<br />Also in the  Troubleshoot Menu i can see the password.<br /><br />Thanks for you help<br />Tobias<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2709">Tobias</a> — Tue Nov 26, 2013 5:25 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tiritas]]></name></author>
<updated>2013-08-20T19:34:48+01:00</updated>
<published>2013-08-20T19:34:48+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4275#p4275</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4275#p4275"/>
<title type="html"><![CDATA[Re: Active Directory password written in RADIUS logs]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4275#p4275"><![CDATA[
We are using version 3.6.1. The passwords are logged in /var/log/freeradius/radius.log when I enable logging in the Global Configuration &gt;&gt; FreeRADIUS page.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2539">tiritas</a> — Tue Aug 20, 2013 7:34 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2013-08-20T11:05:51+01:00</updated>
<published>2013-08-20T11:05:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4272#p4272</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4272#p4272"/>
<title type="html"><![CDATA[Re: Active Directory password written in RADIUS logs]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4272#p4272"><![CDATA[
Hello,<br /><br />Can you please confirm the version of the YubiRADIUS you are using? This issue was addressed in the recent version YubiRADIUS 3.6.1.<br /><br />Thanks and best regards,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Tue Aug 20, 2013 11:05 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tiritas]]></name></author>
<updated>2013-08-17T00:33:39+01:00</updated>
<published>2013-08-17T00:33:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4259#p4259</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4259#p4259"/>
<title type="html"><![CDATA[Active Directory password written in RADIUS logs]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1135&amp;p=4259#p4259"><![CDATA[
I just found that if logging is enabled on YubiRADIUS, Active Directory passwords are written to the log file. This is a extremely serious security oversight. Passwords should NEVER be written in clear-text anywhere. We were not planning to have logging on under production use, but even the possibility that passwords could leak into logs makes the use of YubiRADIUS a non-starter for us.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2539">tiritas</a> — Sat Aug 17, 2013 12:33 am</p><hr />
]]></content>
</entry>
</feed>