<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=29&amp;t=1041" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-04-29T12:10:31+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=29&amp;t=1041</id>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2013-04-29T12:10:31+01:00</updated>
<published>2013-04-29T12:10:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1041&amp;p=3922#p3922</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1041&amp;p=3922#p3922"/>
<title type="html"><![CDATA[Re: mschap authentiation bypassing yubiradius completely]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1041&amp;p=3922#p3922"><![CDATA[
Hello,<br /><br />Can you please provide us the following log files and configuration screeshots to analyze the issue? Please send us the following details to &quot;support@yubico.com&quot;.<br /><br />1. Please configure the log files with the following settings from the webmin console:<br />1. Login to webmin<br />2. Go to &quot;System&quot; &gt;&gt; &quot;System Logs&quot;<br />3. Click on log file (ykropval.log ,etc. mentioned below)<br />4. Select &quot;all&quot; option in &quot;priorities&quot; field of &quot;Message types to log&quot; section<br />5. Please click on &quot;save&quot; button to save the changes.<br />6. Please repeat step 3, 4 and 5 for other log files mentioned below.<br />7. Please click on &quot;Apply Changes&quot; button on System Logs page<br />8. Go to &quot;Servers&quot; &gt;&gt; &quot;YubiRADIUS Virtual Appliance&quot;<br />9. Navigate 'Global Configuration' &gt;&gt; 'FreeRADIUS' menu, please enable FreeRADIUS Logging<br />10. Could you please ssh to the YRVA instance and restart the rsyslog process by executing the following command:<br />    /etc/init.d/rsyslog restart<br />11. Please try to add the user and test the user with YubiKey credentials.<br /><br />Please send us the following log files:<br />/var/log/syslog<br />/var/log/messages<br />/var/log/ykval.log<br />/var/log/ykropval.log<br />/var/log/ykmap.log<br />/var/log/freeradius/radius.log<br />/var/log/postgresql/postgresql-8.4-main.log<br />/var/log/apache2/error.log<br />/var/log/apache2/access.log<br />/var/log/debug<br /><br />2. If you have already configure the webmin logs, please send &quot;webmin.debug&quot; file available at /var/webmin/webmin.debug<br /><br />If not please configure the log file with the following settings from the webmin console: <br />1. Login to webmin<br />2. Go to &quot;Webmin&quot; &gt;&gt; &quot;Webmin Configuration&quot;<br />3. Please Click on &quot;Debugging Log File&quot;<br />4. Please Click on &quot;yes&quot; option of &quot;Debug log enabled?&quot; <br />5. Please click on &quot;save&quot; button to save the changes.<br />6. Please once again Import Users.<br /><br />Please find the &quot;webmin.debug&quot; file at /var/webmin/webmin.debug<br /><br />3. Please provide the configuration files listed here:<br /><br />/etc/freeradius/sites-available/default<br />/etc/freeradius/sites-available/innertunnel<br />/etc/freeradius/yubico.pl<br />/etc/freeradius/modules/ldap<br /><br />4. Please provide the following screenshots:<br /><br />1. Go to webmin interface &gt;&gt; click on &quot;YubiRADIUS Virtual Appliance&quot; &gt;&gt; select &quot;Global Configuration&quot; tab &gt;&gt; click on &quot;General&quot; &gt;&gt; get the screenshot of the &quot;General Configuration&quot;<br /><br />2. Go to webmin interface &gt;&gt; click on &quot;YubiRADIUS Virtual Appliance&quot; &gt;&gt; click on the domain you have created under &quot;Domain&quot; tab &gt;&gt; get the screenshot of the &quot;Users/Groups&quot; tab and &quot;Configuration&quot; tab<br />===================================<br /><br />Thanks and best regards,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Mon Apr 29, 2013 12:10 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[AndrewP]]></name></author>
<updated>2013-04-16T19:30:17+01:00</updated>
<published>2013-04-16T19:30:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1041&amp;p=3901#p3901</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1041&amp;p=3901#p3901"/>
<title type="html"><![CDATA[mschap authentiation bypassing yubiradius completely]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1041&amp;p=3901#p3901"><![CDATA[
I'm using yubiradius for a device using EAP and ldap on the yubiradius server.<br />When I get prompted for my credentials, if I use the yubikey, it fails.  If I leave the yubikey out of the equation and use submit username and password, it succeeds.  Further, I only imported two of the ldap users to the domain.  However, when using mschap, it additonally allows users not imported to connect as well.<br /><br />Here's a log file from user3 connecting.<br />Single factor turned off, user is imported, yubikey NOT used as part of password.<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Waking up in 0.9 seconds.<br />Thread 1 got semaphore<br />Thread 1 handling request 9, (2 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 1 length 10<br />&#91;eap&#93; No EAP Start, assuming it's an on-going EAP conversation<br />++&#91;eap&#93; returns updated<br />rlm_perl: Added pair NAS-Port-Type = Wireless-802.11<br />rlm_perl: Added pair Calling-Station-Id = 00-21-6A-84-92-C2<br />rlm_perl: Added pair Called-Station-Id = C0-EA-E4-46-9E-F5:wireless4<br />rlm_perl: Added pair Message-Authenticator = 0xf61d4fa204093b1bae6d66b70b9c5ad3<br />rlm_perl: Added pair User-Name = user3<br />rlm_perl: Added pair EAP-Message = 0x0201000a016f72696f6e<br />rlm_perl: Added pair Connect-Info = CONNECT 0Mbps 802.11<br />rlm_perl: Added pair EAP-Type = Identity<br />rlm_perl: Added pair NAS-IP-Address = 192.168.170.1<br />rlm_perl: Added pair NAS-Port = 0<br />rlm_perl: Added pair Framed-MTU = 1400<br />rlm_perl: Added pair Auth-Type = EAP<br />++&#91;perl&#93; returns ok<br />&#91;files&#93; users: Matched entry DEFAULT at line 147<br />++&#91;files&#93; returns ok<br />&#91;pap&#93; WARNING! No &quot;known good&quot; password found for the user.  Authentication may fail because of this.<br />++&#91;pap&#93; returns noop<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; EAP Identity<br />&#91;eap&#93; processing type md5<br />rlm_eap_md5: Issuing Challenge<br />++&#91;eap&#93; returns handled<br />Finished request 9.<br />Going to the next request<br />Thread 1 waiting to be assigned a request<br />Waking up in 0.9 seconds.<br />Thread 5 got semaphore<br />Thread 5 handling request 10, (3 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 2 length 6<br />&#91;eap&#93; No EAP Start, assuming it's an on-going EAP conversation<br />++&#91;eap&#93; returns updated<br />rlm_perl: Added pair NAS-Port-Type = Wireless-802.11<br />rlm_perl: Added pair State = 0x5f7ed3555f7cd7753e5bec7f8de022ee<br />rlm_perl: Added pair Calling-Station-Id = 00-21-6A-84-92-C2<br />rlm_perl: Added pair Called-Station-Id = C0-EA-E4-46-9E-F5:wireless4<br />rlm_perl: Added pair Message-Authenticator = 0xe93c520fd1accbe08ba8b2c0fe0c80d3<br />rlm_perl: Added pair User-Name = user3<br />rlm_perl: Added pair EAP-Message = 0x020200060319<br />rlm_perl: Added pair Connect-Info = CONNECT 0Mbps 802.11<br />rlm_perl: Added pair EAP-Type = NAK<br />rlm_perl: Added pair NAS-IP-Address = 192.168.170.1<br />rlm_perl: Added pair NAS-Port = 0<br />rlm_perl: Added pair Framed-MTU = 1400<br />rlm_perl: Added pair Auth-Type = EAP<br />++&#91;perl&#93; returns ok<br />&#91;files&#93; users: Matched entry DEFAULT at line 147<br />++&#91;files&#93; returns ok<br />&#91;pap&#93; WARNING! No &quot;known good&quot; password found for the user.  Authentication may fail because of this.<br />++&#91;pap&#93; returns noop<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP NAK<br />&#91;eap&#93; EAP-NAK asked for EAP-Type/peap<br />&#91;eap&#93; processing type tls<br />&#91;tls&#93; Initiate<br />&#91;tls&#93; Start returned 1<br />++&#91;eap&#93; returns handled<br />Finished request 10.<br />Going to the next request<br />Thread 5 waiting to be assigned a request<br />Waking up in 0.9 seconds.<br />Thread 4 got semaphore<br />Thread 4 handling request 11, (3 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 3 length 105<br />&#91;eap&#93; Continuing tunnel setup.<br />++&#91;eap&#93; returns ok<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/peap<br />&#91;eap&#93; processing type peap<br />&#91;peap&#93; processing EAP-TLS<br />  TLS Length 95<br />&#91;peap&#93; Length Included<br />&#91;peap&#93; eaptls_verify returned 11 <br />&#91;peap&#93;     (other): before/accept initialization<br />&#91;peap&#93;     TLS_accept: before/accept initialization<br />&#91;peap&#93; &lt;&lt;&lt; TLS 1.0 Handshake &#91;length 005a&#93;, ClientHello  <br />&#91;peap&#93;     TLS_accept: SSLv3 read client hello A<br />&#91;peap&#93; &gt;&gt;&gt; TLS 1.0 Handshake &#91;length 0031&#93;, ServerHello  <br />&#91;peap&#93;     TLS_accept: SSLv3 write server hello A<br />&#91;peap&#93; &gt;&gt;&gt; TLS 1.0 Handshake &#91;length 02b9&#93;, Certificate  <br />&#91;peap&#93;     TLS_accept: SSLv3 write certificate A<br />&#91;peap&#93; &gt;&gt;&gt; TLS 1.0 Handshake &#91;length 0004&#93;, ServerHelloDone  <br />&#91;peap&#93;     TLS_accept: SSLv3 write server done A<br />&#91;peap&#93;     TLS_accept: SSLv3 flush data<br />&#91;peap&#93;     TLS_accept: Need to read more data: SSLv3 read client certificate A<br />In SSL Handshake Phase <br />In SSL Accept mode  <br />&#91;peap&#93; eaptls_process returned 13 <br />&#91;peap&#93; EAPTLS_HANDLED<br />++&#91;eap&#93; returns handled<br />Finished request 11.<br />Going to the next request<br />Thread 4 waiting to be assigned a request<br />Waking up in 0.8 seconds.<br />Thread 3 got semaphore<br />Thread 3 handling request 12, (3 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 4 length 208<br />&#91;eap&#93; Continuing tunnel setup.<br />++&#91;eap&#93; returns ok<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/peap<br />&#91;eap&#93; processing type peap<br />&#91;peap&#93; processing EAP-TLS<br />  TLS Length 198<br />&#91;peap&#93; Length Included<br />&#91;peap&#93; eaptls_verify returned 11 <br />&#91;peap&#93; &lt;&lt;&lt; TLS 1.0 Handshake &#91;length 0086&#93;, ClientKeyExchange  <br />&#91;peap&#93;     TLS_accept: SSLv3 read client key exchange A<br />&#91;peap&#93; &lt;&lt;&lt; TLS 1.0 ChangeCipherSpec &#91;length 0001&#93;  <br />&#91;peap&#93; &lt;&lt;&lt; TLS 1.0 Handshake &#91;length 0010&#93;, Finished  <br />&#91;peap&#93;     TLS_accept: SSLv3 read finished A<br />&#91;peap&#93; &gt;&gt;&gt; TLS 1.0 ChangeCipherSpec &#91;length 0001&#93;  <br />&#91;peap&#93;     TLS_accept: SSLv3 write change cipher spec A<br />&#91;peap&#93; &gt;&gt;&gt; TLS 1.0 Handshake &#91;length 0010&#93;, Finished  <br />&#91;peap&#93;     TLS_accept: SSLv3 write finished A<br />&#91;peap&#93;     TLS_accept: SSLv3 flush data<br />&#91;peap&#93;     (other): SSL negotiation finished successfully<br />SSL Connection Established <br />&#91;peap&#93; eaptls_process returned 13 <br />&#91;peap&#93; EAPTLS_HANDLED<br />++&#91;eap&#93; returns handled<br />Finished request 12.<br />Going to the next request<br />Thread 3 waiting to be assigned a request<br />Waking up in 3.9 seconds.<br />Waking up in 0.9 seconds.<br />Thread 2 got semaphore<br />Thread 2 handling request 13, (3 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 5 length 6<br />&#91;eap&#93; Continuing tunnel setup.<br />++&#91;eap&#93; returns ok<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/peap<br />&#91;eap&#93; processing type peap<br />&#91;peap&#93; processing EAP-TLS<br />&#91;peap&#93; Received TLS ACK<br />&#91;peap&#93; ACK handshake is finished<br />&#91;peap&#93; eaptls_verify returned 3 <br />&#91;peap&#93; eaptls_process returned 3 <br />&#91;peap&#93; EAPTLS_SUCCESS<br />&#91;peap&#93; Session established.  Decoding tunneled attributes.<br />&#91;peap&#93; Peap state TUNNEL ESTABLISHED<br />++&#91;eap&#93; returns handled<br />Finished request 13.<br />Going to the next request<br />Thread 2 waiting to be assigned a request<br />Waking up in 0.9 seconds.<br />Thread 1 got semaphore<br />Thread 1 handling request 14, (3 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 6 length 43<br />&#91;eap&#93; Continuing tunnel setup.<br />++&#91;eap&#93; returns ok<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/peap<br />&#91;eap&#93; processing type peap<br />&#91;peap&#93; processing EAP-TLS<br />&#91;peap&#93; eaptls_verify returned 7 <br />&#91;peap&#93; Done initial handshake<br />&#91;peap&#93; eaptls_process returned 7 <br />&#91;peap&#93; EAPTLS_OK<br />&#91;peap&#93; Session established.  Decoding tunneled attributes.<br />&#91;peap&#93; Peap state WAITING FOR INNER IDENTITY<br />&#91;peap&#93; Identity - user3<br />&#91;peap&#93; Got inner identity 'user3'<br />&#91;peap&#93; Setting default EAP type for tunneled EAP session.<br />  PEAP: Setting User-Name to user3<br /># Executing section authorize from file /etc/freeradius/sites-enabled/inner-tunnel<br />+- entering group authorize {...}<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />++&#91;control&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 6 length 10<br />&#91;eap&#93; No EAP Start, assuming it's an on-going EAP conversation<br />++&#91;eap&#93; returns updated<br />rlm_perl: Added pair User-Name = user3<br />rlm_perl: Added pair EAP-Message = 0x0206000a016f72696f6e<br />rlm_perl: Added pair EAP-Type = Identity<br />rlm_perl: Added pair FreeRADIUS-Proxied-To = 127.0.0.1<br />rlm_perl: Added pair Auth-Type = EAP<br />rlm_perl: Added pair Proxy-To-Realm = LOCAL<br />rlm_perl: Added pair EAP-Type = Generic-Token-Card<br />++&#91;perl&#93; returns ok<br />&#91;files&#93; users: Matched entry DEFAULT at line 147<br />++&#91;files&#93; returns ok<br />&#91;ldap&#93; performing user authorization for user3<br />&#91;ldap&#93;    expand: (uid=%{mschap:User-Name:-%{User-Name}}) -&gt; (uid=user3)<br />&#91;ldap&#93;    expand: dc=example,dc=com -&gt; dc=example,dc=com<br />  &#91;ldap&#93; ldap_get_conn: Checking Id: 0<br />  &#91;ldap&#93; ldap_get_conn: Got Id: 0<br />  &#91;ldap&#93; performing search in dc=example,dc=com, with filter (uid=user3)<br />&#91;ldap&#93; No default NMAS login sequence<br />&#91;ldap&#93; looking for check items in directory...<br />  &#91;ldap&#93; userPassword -&gt; Cleartext-Password == &quot;test&quot;<br />  &#91;ldap&#93; userPassword -&gt; Password-With-Header == &quot;test&quot;<br />&#91;ldap&#93; looking for reply items in directory...<br />&#91;ldap&#93; user user3 authorized to use remote access<br />  &#91;ldap&#93; ldap_release_conn: Release Id: 0<br />++&#91;ldap&#93; returns ok<br />&#91;pap&#93; Config already contains &quot;known good&quot; password.  Ignoring Password-With-Header<br />&#91;pap&#93; WARNING: Auth-Type already set.  Not setting to PAP<br />++&#91;pap&#93; returns noop<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/inner-tunnel<br />+- entering group EAP {...}<br />&#91;eap&#93; EAP Identity<br />&#91;eap&#93; processing type gtc<br />++&#91;eap&#93; returns handled<br />&#91;peap&#93; Got tunneled Access-Challenge<br />++&#91;eap&#93; returns handled<br />Finished request 14.<br />Going to the next request<br />Thread 1 waiting to be assigned a request<br />Waking up in 0.9 seconds.<br />Thread 5 got semaphore<br />Thread 5 handling request 15, (4 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 7 length 43<br />&#91;eap&#93; Continuing tunnel setup.<br />++&#91;eap&#93; returns ok<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/peap<br />&#91;eap&#93; processing type peap<br />&#91;peap&#93; processing EAP-TLS<br />&#91;peap&#93; eaptls_verify returned 7 <br />&#91;peap&#93; Done initial handshake<br />&#91;peap&#93; eaptls_process returned 7 <br />&#91;peap&#93; EAPTLS_OK<br />&#91;peap&#93; Session established.  Decoding tunneled attributes.<br />&#91;peap&#93; Peap state phase2<br />&#91;peap&#93; EAP type nak<br />  PEAP: Setting User-Name to user3<br /># Executing section authorize from file /etc/freeradius/sites-enabled/inner-tunnel<br />+- entering group authorize {...}<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />++&#91;control&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 7 length 6<br />&#91;eap&#93; No EAP Start, assuming it's an on-going EAP conversation<br />++&#91;eap&#93; returns updated<br />rlm_perl: Added pair User-Name = user3<br />rlm_perl: Added pair EAP-Message = 0x02070006031a<br />rlm_perl: Added pair EAP-Type = NAK<br />rlm_perl: Added pair State = 0xe2abd2cee2acd41be1a92d5f2a444a2b<br />rlm_perl: Added pair FreeRADIUS-Proxied-To = 127.0.0.1<br />rlm_perl: Added pair Auth-Type = EAP<br />rlm_perl: Added pair Proxy-To-Realm = LOCAL<br />++&#91;perl&#93; returns ok<br />&#91;files&#93; users: Matched entry DEFAULT at line 147<br />++&#91;files&#93; returns ok<br />&#91;ldap&#93; performing user authorization for user3<br />&#91;ldap&#93;    expand: (uid=%{mschap:User-Name:-%{User-Name}}) -&gt; (uid=user3)<br />&#91;ldap&#93;    expand: dc=example,dc=com -&gt; dc=example,dc=com<br />  &#91;ldap&#93; ldap_get_conn: Checking Id: 0<br />  &#91;ldap&#93; ldap_get_conn: Got Id: 0<br />  &#91;ldap&#93; performing search in dc=example,dc=com, with filter (uid=user3)<br />&#91;ldap&#93; No default NMAS login sequence<br />&#91;ldap&#93; looking for check items in directory...<br />  &#91;ldap&#93; userPassword -&gt; Cleartext-Password == &quot;test&quot;<br />  &#91;ldap&#93; userPassword -&gt; Password-With-Header == &quot;test&quot;<br />&#91;ldap&#93; looking for reply items in directory...<br />&#91;ldap&#93; user user3 authorized to use remote access<br />  &#91;ldap&#93; ldap_release_conn: Release Id: 0<br />++&#91;ldap&#93; returns ok<br />&#91;pap&#93; Config already contains &quot;known good&quot; password.  Ignoring Password-With-Header<br />&#91;pap&#93; WARNING: Auth-Type already set.  Not setting to PAP<br />++&#91;pap&#93; returns noop<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/inner-tunnel<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP NAK<br />&#91;eap&#93; EAP-NAK asked for EAP-Type/mschapv2<br />&#91;eap&#93; processing type mschapv2<br />rlm_eap_mschapv2: Issuing Challenge<br />++&#91;eap&#93; returns handled<br />&#91;peap&#93; Got tunneled Access-Challenge<br />++&#91;eap&#93; returns handled<br />Finished request 15.<br />Going to the next request<br />Thread 5 waiting to be assigned a request<br />Waking up in 0.9 seconds.<br />Thread 4 got semaphore<br />Thread 4 handling request 16, (4 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 8 length 107<br />&#91;eap&#93; Continuing tunnel setup.<br />++&#91;eap&#93; returns ok<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/peap<br />&#91;eap&#93; processing type peap<br />&#91;peap&#93; processing EAP-TLS<br />&#91;peap&#93; eaptls_verify returned 7 <br />&#91;peap&#93; Done initial handshake<br />&#91;peap&#93; eaptls_process returned 7 <br />&#91;peap&#93; EAPTLS_OK<br />&#91;peap&#93; Session established.  Decoding tunneled attributes.<br />&#91;peap&#93; Peap state phase2<br />&#91;peap&#93; EAP type mschapv2<br />  PEAP: Setting User-Name to user3<br /># Executing section authorize from file /etc/freeradius/sites-enabled/inner-tunnel<br />+- entering group authorize {...}<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />++&#91;control&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 8 length 64<br />&#91;eap&#93; No EAP Start, assuming it's an on-going EAP conversation<br />++&#91;eap&#93; returns updated<br />rlm_perl: Added pair User-Name = user3<br />rlm_perl: Added pair EAP-Message = 0x020800401a0208003b31545386ce4bc457831cd63988df882aa40000000000000000653717bb321e3a98822dafcac8ecd77033cb3b7be768cfc3006f72696f6e<br />rlm_perl: Added pair EAP-Type = MS-CHAP-V2<br />rlm_perl: Added pair State = 0xe2abd2cee3a3c81be1a92d5f2a444a2b<br />rlm_perl: Added pair FreeRADIUS-Proxied-To = 127.0.0.1<br />rlm_perl: Added pair Auth-Type = EAP<br />rlm_perl: Added pair Proxy-To-Realm = LOCAL<br />++&#91;perl&#93; returns ok<br />&#91;files&#93; users: Matched entry DEFAULT at line 147<br />++&#91;files&#93; returns ok<br />&#91;ldap&#93; performing user authorization for user3<br />&#91;ldap&#93;    expand: (uid=%{mschap:User-Name:-%{User-Name}}) -&gt; (uid=user3)<br />&#91;ldap&#93;    expand: dc=example,dc=com -&gt; dc=example,dc=com<br />  &#91;ldap&#93; ldap_get_conn: Checking Id: 0<br />  &#91;ldap&#93; ldap_get_conn: Got Id: 0<br />  &#91;ldap&#93; performing search in dc=example,dc=com, with filter (uid=user3)<br />&#91;ldap&#93; No default NMAS login sequence<br />&#91;ldap&#93; looking for check items in directory...<br />  &#91;ldap&#93; userPassword -&gt; Cleartext-Password == &quot;test&quot;<br />  &#91;ldap&#93; userPassword -&gt; Password-With-Header == &quot;test&quot;<br />&#91;ldap&#93; looking for reply items in directory...<br />&#91;ldap&#93; user user3 authorized to use remote access<br />  &#91;ldap&#93; ldap_release_conn: Release Id: 0<br />++&#91;ldap&#93; returns ok<br />&#91;pap&#93; Config already contains &quot;known good&quot; password.  Ignoring Password-With-Header<br />&#91;pap&#93; WARNING: Auth-Type already set.  Not setting to PAP<br />++&#91;pap&#93; returns noop<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/inner-tunnel<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/mschapv2<br />&#91;eap&#93; processing type mschapv2<br />&#91;mschapv2&#93; # Executing group from file /etc/freeradius/sites-enabled/inner-tunnel<br />&#91;mschapv2&#93; +- entering group MS-CHAP {...}<br />&#91;mschap&#93; Creating challenge hash with username: user3<br />&#91;mschap&#93; Told to do MS-CHAPv2 for user3 with NT-Password<br />&#91;mschap&#93; adding MS-CHAPv2 MPPE keys<br />++&#91;mschap&#93; returns ok<br />MSCHAP Success <br />++&#91;eap&#93; returns handled<br />&#91;peap&#93; Got tunneled Access-Challenge<br />++&#91;eap&#93; returns handled<br />Finished request 16.<br />Going to the next request<br />Thread 4 waiting to be assigned a request<br />Waking up in 0.9 seconds.<br />Thread 3 got semaphore<br />Thread 3 handling request 17, (4 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 9 length 43<br />&#91;eap&#93; Continuing tunnel setup.<br />++&#91;eap&#93; returns ok<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/peap<br />&#91;eap&#93; processing type peap<br />&#91;peap&#93; processing EAP-TLS<br />&#91;peap&#93; eaptls_verify returned 7 <br />&#91;peap&#93; Done initial handshake<br />&#91;peap&#93; eaptls_process returned 7 <br />&#91;peap&#93; EAPTLS_OK<br />&#91;peap&#93; Session established.  Decoding tunneled attributes.<br />&#91;peap&#93; Peap state phase2<br />&#91;peap&#93; EAP type mschapv2<br />  PEAP: Setting User-Name to user3<br /># Executing section authorize from file /etc/freeradius/sites-enabled/inner-tunnel<br />+- entering group authorize {...}<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />++&#91;control&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 9 length 6<br />&#91;eap&#93; No EAP Start, assuming it's an on-going EAP conversation<br />++&#91;eap&#93; returns updated<br />rlm_perl: Added pair User-Name = user3<br />rlm_perl: Added pair EAP-Message = 0x020900061a03<br />rlm_perl: Added pair EAP-Type = MS-CHAP-V2<br />rlm_perl: Added pair State = 0xe2abd2cee0a2c81be1a92d5f2a444a2b<br />rlm_perl: Added pair FreeRADIUS-Proxied-To = 127.0.0.1<br />rlm_perl: Added pair Auth-Type = EAP<br />rlm_perl: Added pair Proxy-To-Realm = LOCAL<br />++&#91;perl&#93; returns ok<br />&#91;files&#93; users: Matched entry DEFAULT at line 147<br />++&#91;files&#93; returns ok<br />&#91;ldap&#93; performing user authorization for user3<br />&#91;ldap&#93;    expand: (uid=%{mschap:User-Name:-%{User-Name}}) -&gt; (uid=user3)<br />&#91;ldap&#93;    expand: dc=example,dc=com -&gt; dc=example,dc=com<br />  &#91;ldap&#93; ldap_get_conn: Checking Id: 0<br />  &#91;ldap&#93; ldap_get_conn: Got Id: 0<br />  &#91;ldap&#93; performing search in dc=example,dc=com, with filter (uid=user3)<br />&#91;ldap&#93; No default NMAS login sequence<br />&#91;ldap&#93; looking for check items in directory...<br />  &#91;ldap&#93; userPassword -&gt; Cleartext-Password == &quot;test&quot;<br />  &#91;ldap&#93; userPassword -&gt; Password-With-Header == &quot;test&quot;<br />&#91;ldap&#93; looking for reply items in directory...<br />&#91;ldap&#93; user user3 authorized to use remote access<br />  &#91;ldap&#93; ldap_release_conn: Release Id: 0<br />++&#91;ldap&#93; returns ok<br />&#91;pap&#93; Config already contains &quot;known good&quot; password.  Ignoring Password-With-Header<br />&#91;pap&#93; WARNING: Auth-Type already set.  Not setting to PAP<br />++&#91;pap&#93; returns noop<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/inner-tunnel<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/mschapv2<br />&#91;eap&#93; processing type mschapv2<br />&#91;eap&#93; Freeing handler<br />++&#91;eap&#93; returns ok<br />  WARNING: Empty post-auth section.  Using default return values.<br /># Executing section post-auth from file /etc/freeradius/sites-enabled/inner-tunnel<br />&#91;peap&#93; Tunneled authentication was successful.<br />&#91;peap&#93; SUCCESS<br />++&#91;eap&#93; returns handled<br />Finished request 17.<br />Going to the next request<br />Thread 3 waiting to be assigned a request<br />Waking up in 0.9 seconds.<br />Thread 2 got semaphore<br />Thread 2 handling request 18, (4 handled so far)<br />&#91;&lt;thread&gt;&#93; # Executing section authorize from file /etc/freeradius/sites-enabled/default<br />&#91;&lt;thread&gt;&#93; +- entering group authorize {...}<br />++&#91;preprocess&#93; returns ok<br />++&#91;chap&#93; returns noop<br />++&#91;mschap&#93; returns noop<br />&#91;suffix&#93; No '@' in User-Name = &quot;user3&quot;, looking up realm NULL<br />&#91;suffix&#93; No such realm &quot;NULL&quot;<br />++&#91;suffix&#93; returns noop<br />&#91;eap&#93; EAP packet type response id 10 length 43<br />&#91;eap&#93; Continuing tunnel setup.<br />++&#91;eap&#93; returns ok<br />Found Auth-Type = EAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group EAP {...}<br />&#91;eap&#93; Request found, released from the list<br />&#91;eap&#93; EAP/peap<br />&#91;eap&#93; processing type peap<br />&#91;peap&#93; processing EAP-TLS<br />&#91;peap&#93; eaptls_verify returned 7 <br />&#91;peap&#93; Done initial handshake<br />&#91;peap&#93; eaptls_process returned 7 <br />&#91;peap&#93; EAPTLS_OK<br />&#91;peap&#93; Session established.  Decoding tunneled attributes.<br />&#91;peap&#93; Peap state send tlv success<br />&#91;peap&#93; Received EAP-TLV response.<br />&#91;peap&#93; Success<br />&#91;eap&#93; Freeing handler<br />++&#91;eap&#93; returns ok<br /># Executing section post-auth from file /etc/freeradius/sites-enabled/default<br />+- entering group post-auth {...}<br />++&#91;exec&#93; returns noop<br />Finished request 18.<br />Going to the next request<br />Thread 2 waiting to be assigned a request<br />Waking up in 2.1 seconds.<br />Cleaning up request 9 ID 177 with timestamp +1121<br />Cleaning up request 10 ID 178 with timestamp +1121<br />Cleaning up request 11 ID 179 with timestamp +1121<br />Cleaning up request 12 ID 180 with timestamp +1121<br />Waking up in 1.7 seconds.<br />Cleaning up request 13 ID 181 with timestamp +1123<br />Cleaning up request 14 ID 182 with timestamp +1123<br />Cleaning up request 15 ID 183 with timestamp +1123<br />Cleaning up request 16 ID 184 with timestamp +1123<br />Cleaning up request 17 ID 185 with timestamp +1123<br />Cleaning up request 18 ID 186 with timestamp +1123<br />Ready to process requests.<br /></div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2409">AndrewP</a> — Tue Apr 16, 2013 7:30 pm</p><hr />
]]></content>
</entry>
</feed>