Networking

NAVIGATION
CATEGORIES
REFERRENCE
LINKS
  • rlm_eap_peap: No data inside of the tunnel.

    0 answers - 21416 bytes - related search similar search Add To My Delicious Add To My Stumble Upon Add To My Google Mark Add To My Facebook Add To My Digg Add To My Reddit

    Hi All,
    I have a small problem with my FreeRadius configuration.
    I have configured FreeRadius with LDAP authentication, this part seems
    to work fine.
    I am using an Extreme Summit switch, as radius client and I am using
    an Windows XP sp2 workstation with PEAP / 802.1x authentication.
    What is happing:
    First FreeRadius shows this error:
    rlm_eap_tls: Length Included
    eaptls_verify returned 11
    (other): before/accept initialization
    TLS_accept: before/accept initialization
    rlm_eap_tls: <<< TLS 1.0 Handshake [length 0041], ClientHello
    TLS_accept: SSLv3 read client hello A
    rlm_eap_tls: TLS 1.0 Handshake [length 004a], ServerHello
    TLS_accept: SSLv3 write server hello A
    rlm_eap_tls: TLS 1.0 Handshake [length 086e], Certificate
    TLS_accept: SSLv3 write certificate A
    rlm_eap_tls: TLS 1.0 Handshake [length 0004], ServerHelloDone
    TLS_accept: SSLv3 write server done A
    TLS_accept: SSLv3 flush data
    TLS_accept:error in SSLv3 read client certificate A
    In SSL Handshake Phase
    Later on FreeRadius shows:
    rlm_eap_tls: Length Included
    eaptls_verify returned 11
    rlm_eap_tls: <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange
    TLS_accept: SSLv3 read client key exchange A
    rlm_eap_tls: <<< TLS 1.0 ChangeCipherSpec [length 0001]
    rlm_eap_tls: <<< TLS 1.0 Handshake [length 0010], Finished
    TLS_accept: SSLv3 read finished A
    rlm_eap_tls: TLS 1.0 ChangeCipherSpec [length 0001]
    TLS_accept: SSLv3 write change cipher spec A
    rlm_eap_tls: TLS 1.0 Handshake [length 0010], Finished
    TLS_accept: SSLv3 write finished A
    TLS_accept: SSLv3 flush data
    (other): SSL negotiation finished successfully
    And at the end:
    rlm_eap_tls: Length Included
    eaptls_verify returned 11
    eaptls_process returned 7
    rlm_eap_peap: EAPTLSK
    rlm_eap_peap: Session established. Decoding tunneled attributes.
    rlm_eap_tls: <<< TLS 1.0 Alert [length 0002], fatal access_denied
    TLS Alert read:fatal:access denied
    rlm_eap_peap: No data inside of the tunnel.
    rlm_eap: Handler failed in EAP/peap
    rlm_eap: Failed in EAP select
    modcall[authenticate]: module "eap" returns invalid for request 5
    modcall: group authenticate returns invalid for request 5
    auth: Failed to validate the user.
    What is going on?
    I have included the whole log:
    PuTTY log 2006.01.18 10:37:22
    rad_recv: Access-Request packet from host 10.61.100.163:1306, id=104,
    length=96
    User-Name = "gerard"
    EAP-Message = 0x0201000b01676572617264
    NAS-IP-Address = 10.61.100.163
    Service-Type = Login-User
    Calling-Station-Id = "00-10-b5-f4-98-0e"
    NAS-Port-Type = Ethernet
    Message-Authenticator =
    Processing the authorize section of radiusd.conf
    modcall: entering group authorize for request 0
    modcall[authorize]: module "preprocess" returns ok for request 0
    modcall[authorize]: module "chap" returns noop for request 0
    modcall[authorize]: module "mschap" returns noop for request 0
    rlm_realm: No '@' in User-Name = "gerard", looking up realm NULL
    rlm_realm: No such realm "NULL"
    modcall[authorize]: module "suffix" returns noop for request 0
    rlm_eap: EAP packet type response id 1 length 11
    rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
    modcall[authorize]: module "eap" returns updated for request 0
    users: Matched entry DEFAULT at line 152
    modcall[authorize]: module "files" returns ok for request 0
    rlm_ldap: - authorize
    rlm_ldap: performing user authorization for gerard
    radius_xlat: '(CN=gerard)'
    radius_xlat: 'ou=radius,ou=servicos,ou=brt,o=btp'
    rlm_ldap: ldap_get_conn: Checking Id: 0
    rlm_ldap: ldap_get_conn: Got Id: 0
    rlm_ldap: attempting LDAP reconnection
    rlm_ldap: (re)connect to ,
    authentication 0
    rlm_ldap: setting TLS CACert File to /etc/raddb/certs/root.b64
    rlm_ldap: setting TLS Require Cert to demand
    rlm_ldap: starting TLS
    rlm_ldap: bind as cn=admin,o=btp/novell to
    rlm_ldap: waiting for bind result
    rlm_ldap: Bind was successful
    rlm_ldap: performing search in ou=radius,ou=servicos,ou=brt,o=btp,
    with filter (CN=gerard)
    rlm_ldap: Added the eDirectory password in check items
    rlm_ldap: looking for check items in directory
    rlm_ldap: looking for reply items in directory
    rlm_ldap: user gerard authorized to use remote access
    rlm_ldap: ldap_release_conn: Release Id: 0
    modcall[authorize]: module "ldap" returns ok for request 0
    modcall: group authorize returns updated for request 0
    rad_check_password: Found Auth-Type EAP
    auth: type "EAP"
    Processing the authenticate section of radiusd.conf
    modcall: entering group authenticate for request 0
    rlm_eap: EAP Identity
    rlm_eap: processing type tls
    rlm_eap_tls: Initiate
    rlm_eap_tls: Start returned 1
    modcall[authenticate]: module "eap" returns handled for request 0
    modcall: group authenticate returns handled for request 0
    Sending Access-Challenge of id 104 to 10.61.100.163:1306
    EAP-Message = 0x010200061920
    Message-Authenticator =
    State =
    Finished request 0
    Going to the next request
    Walking the entire request list
    Waking up in 6 seconds
    rad_recv: Access-Request packet from host 10.61.100.163:1307, id=144,
    length=183
    User-Name = "gerard"
    EAP-Message =
    00060013001200630100
    NAS-IP-Address = 10.61.100.163
    Service-Type = Login-User
    Calling-Station-Id = "00-10-b5-f4-98-0e"
    NAS-Port-Type = Ethernet
    State =
    Message-Authenticator =
    Processing the authorize section of radiusd.conf
    modcall: entering group authorize for request 1
    modcall[authorize]: module "preprocess" returns ok for request 1
    modcall[authorize]: module "chap" returns noop for request 1
    modcall[authorize]: module "mschap" returns noop for request 1
    rlm_realm: No '@' in User-Name = "gerard", looking up realm NULL
    rlm_realm: No such realm "NULL"
    modcall[authorize]: module "suffix" returns noop for request 1
    rlm_eap: EAP packet type response id 2 length 80
    rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
    modcall[authorize]: module "eap" returns updated for request 1
    users: Matched entry DEFAULT at line 152
    modcall[authorize]: module "files" returns ok for request 1
    rlm_ldap: - authorize
    rlm_ldap: performing user authorization for gerard
    radius_xlat: '(CN=gerard)'
    radius_xlat: 'ou=radius,ou=servicos,ou=brt,o=btp'
    rlm_ldap: ldap_get_conn: Checking Id: 0
    rlm_ldap: ldap_get_conn: Got Id: 0
    rlm_ldap: performing search in ou=radius,ou=servicos,ou=brt,o=btp,
    with filter (CN=gerard)
    rlm_ldap: Added the eDirectory password in check items
    rlm_ldap: looking for check items in directory
    rlm_ldap: looking for reply items in directory
    rlm_ldap: user gerard authorized to use remote access
    rlm_ldap: ldap_release_conn: Release Id: 0
    modcall[authorize]: module "ldap" returns ok for request 1
    modcall: group authorize returns updated for request 1
    rad_check_password: Found Auth-Type EAP
    auth: type "EAP"
    Processing the authenticate section of radiusd.conf
    modcall: entering group authenticate for request 1
    rlm_eap: Request found, released from the list
    rlm_eap: EAP/peap
    rlm_eap: processing type peap
    rlm_eap_peap: Authenticate
    rlm_eap_tls: processing TLS
    rlm_eap_tls: Length Included
    eaptls_verify returned 11
    (other): before/accept initialization
    TLS_accept: before/accept initialization
    rlm_eap_tls: <<< TLS 1.0 Handshake [length 0041], ClientHello
    TLS_accept: SSLv3 read client hello A
    rlm_eap_tls: TLS 1.0 Handshake [length 004a], ServerHello
    TLS_accept: SSLv3 write server hello A
    rlm_eap_tls: TLS 1.0 Handshake [length 086e], Certificate
    TLS_accept: SSLv3 write certificate A
    rlm_eap_tls: TLS 1.0 Handshake [length 0004], ServerHelloDone
    TLS_accept: SSLv3 write server done A
    TLS_accept: SSLv3 flush data
    TLS_accept:error in SSLv3 read client certificate A
    In SSL Handshake Phase
    In SSL Accept mode
    eaptls_process returned 13
    rlm_eap_peap: EAPTLS_HANDLED
    modcall[authenticate]: module "eap" returns handled for request 1
    modcall: group authenticate returns handled for request 1
    Sending Access-Challenge of id 144 to 10.61.100.163:1307
    EAP-Message =
    5302306092a
    EAP-Message =
    0b485b502a7
    EAP-Message =
    70e3b4c6562
    EAP-Message =
    88116676d61
    EAP-Message =
    Message-Authenticator =
    State =
    Finished request 1
    Going to the next request
    Waking up in 6 seconds
    rad_recv: Access-Request packet from host 10.61.100.163:1308, id=154,
    length=109
    User-Name = "gerard"
    EAP-Message = 0x020300061900
    NAS-IP-Address = 10.61.100.163
    Service-Type = Login-User
    Calling-Station-Id = "00-10-b5-f4-98-0e"
    NAS-Port-Type = Ethernet
    State =
    Message-Authenticator =
    Processing the authorize section of radiusd.conf
    modcall: entering group authorize for request 2
    modcall[authorize]: module "preprocess" returns ok for request 2
    modcall[authorize]: module "chap" returns noop for request 2
    modcall[authorize]: module "mschap" returns noop for request 2
    rlm_realm: No '@' in User-Name = "gerard", looking up realm NULL
    rlm_realm: No such realm "NULL"
    modcall[authorize]: module "suffix" returns noop for request 2
    rlm_eap: EAP packet type response id 3 length 6
    rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
    modcall[authorize]: module "eap" returns updated for request 2
    users: Matched entry DEFAULT at line 152
    modcall[authorize]: module "files" returns ok for request 2
    rlm_ldap: - authorize
    rlm_ldap: performing user authorization for gerard
    radius_xlat: '(CN=gerard)'
    radius_xlat: 'ou=radius,ou=servicos,ou=brt,o=btp'
    rlm_ldap: ldap_get_conn: Checking Id: 0
    rlm_ldap: ldap_get_conn: Got Id: 0
    rlm_ldap: performing search in ou=radius,ou=servicos,ou=brt,o=btp,
    with filter (CN=gerard)
    rlm_ldap: Added the eDirectory password in check items
    rlm_ldap: looking for check items in directory
    rlm_ldap: looking for reply items in directory
    rlm_ldap: user gerard authorized to use remote access
    rlm_ldap: ldap_release_conn: Release Id: 0
    modcall[authorize]: module "ldap" returns ok for request 2
    modcall: group authorize returns updated for request 2
    rad_check_password: Found Auth-Type EAP
    auth: type "EAP"
    Processing the authenticate section of radiusd.conf
    modcall: entering group authenticate for request 2
    rlm_eap: Request found, released from the list
    rlm_eap: EAP/peap
    rlm_eap: processing type peap
    rlm_eap_peap: Authenticate
    rlm_eap_tls: processing TLS
    rlm_eap_tls: Received EAP-TLS ACK message
    rlm_eap_tls: ack handshake fragment handler
    eaptls_verify returned 1
    eaptls_process returned 13
    rlm_eap_peap: EAPTLS_HANDLED
    modcall[authenticate]: module "eap" returns handled for request 2
    modcall: group authenticate returns handled for request 2
    Sending Access-Challenge of id 154 to 10.61.100.163:1308
    EAP-Message =
    96c2054656c
    EAP-Message =
    56c64657240
    EAP-Message =
    086480186f8
    EAP-Message =
    03021060355
    EAP-Message =
    Message-Authenticator =
    State =
    Finished request 2
    Going to the next request
    Waking up in 6 seconds
    rad_recv: Access-Request packet from host 10.61.100.163:1309, id=159,
    length=109
    User-Name = "gerard"
    EAP-Message = 0x020400061900
    NAS-IP-Address = 10.61.100.163
    Service-Type = Login-User
    Calling-Station-Id = "00-10-b5-f4-98-0e"
    NAS-Port-Type = Ethernet
    State =
    Message-Authenticator =
    Processing the authorize section of radiusd.conf
    modcall: entering group authorize for request 3
    modcall[authorize]: module "preprocess" returns ok for request 3
    modcall[authorize]: module "chap" returns noop for request 3
    modcall[authorize]: module "mschap" returns noop for request 3
    rlm_realm: No '@' in User-Name = "gerard", looking up realm NULL
    rlm_realm: No such realm "NULL"
    modcall[authorize]: module "suffix" returns noop for request 3
    rlm_eap: EAP packet type response id 4 length 6
    rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
    modcall[authorize]: module "eap" returns updated for request 3
    users: Matched entry DEFAULT at line 152
    modcall[authorize]: module "files" returns ok for request 3
    rlm_ldap: - authorize
    rlm_ldap: performing user authorization for gerard
    radius_xlat: '(CN=gerard)'
    radius_xlat: 'ou=radius,ou=servicos,ou=brt,o=btp'
    rlm_ldap: ldap_get_conn: Checking Id: 0
    rlm_ldap: ldap_get_conn: Got Id: 0
    rlm_ldap: performing search in ou=radius,ou=servicos,ou=brt,o=btp,
    with filter (CN=gerard)
    rlm_ldap: Added the eDirectory password in check items
    rlm_ldap: looking for check items in directory
    rlm_ldap: looking for reply items in directory
    rlm_ldap: user gerard authorized to use remote access
    rlm_ldap: ldap_release_conn: Release Id: 0
    modcall[authorize]: module "ldap" returns ok for request 3
    modcall: group authorize returns updated for request 3
    rad_check_password: Found Auth-Type EAP
    auth: type "EAP"
    Processing the authenticate section of radiusd.conf
    modcall: entering group authenticate for request 3
    rlm_eap: Request found, released from the list
    rlm_eap: EAP/peap
    rlm_eap: processing type peap
    rlm_eap_peap: Authenticate
    rlm_eap_tls: processing TLS
    rlm_eap_tls: Received EAP-TLS ACK message
    rlm_eap_tls: ack handshake fragment handler
    eaptls_verify returned 1
    eaptls_process returned 13
    rlm_eap_peap: EAPTLS_HANDLED
    modcall[authenticate]: module "eap" returns handled for request 3
    modcall: group authenticate returns handled for request 3
    Sending Access-Challenge of id 159 to 10.61.100.163:1309
    EAP-Message =
    Message-Authenticator =
    State =
    Finished request 3
    Going to the next request
    Waking up in 6 seconds
    rad_recv: Access-Request packet from host 10.61.100.163:1310, id=184,
    length=295
    User-Name = "gerard"
    EAP-Message =
    NAS-IP-Address = 10.61.100.163
    Service-Type = Login-User
    Calling-Station-Id = "00-10-b5-f4-98-0e"
    NAS-Port-Type = Ethernet
    State =
    Message-Authenticator =
    Processing the authorize section of radiusd.conf
    modcall: entering group authorize for request 4
    modcall[authorize]: module "preprocess" returns ok for request 4
    modcall[authorize]: module "chap" returns noop for request 4
    modcall[authorize]: module "mschap" returns noop for request 4
    rlm_realm: No '@' in User-Name = "gerard", looking up realm NULL
    rlm_realm: No such realm "NULL"
    modcall[authorize]: module "suffix" returns noop for request 4
    rlm_eap: EAP packet type response id 5 length 192
    rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
    modcall[authorize]: module "eap" returns updated for request 4
    users: Matched entry DEFAULT at line 152
    modcall[authorize]: module "files" returns ok for request 4
    rlm_ldap: - authorize
    rlm_ldap: performing user authorization for gerard
    radius_xlat: '(CN=gerard)'
    radius_xlat: 'ou=radius,ou=servicos,ou=brt,o=btp'
    rlm_ldap: ldap_get_conn: Checking Id: 0
    rlm_ldap: ldap_get_conn: Got Id: 0
    rlm_ldap: performing search in ou=radius,ou=servicos,ou=brt,o=btp,
    with filter (CN=gerard)
    rlm_ldap: Added the eDirectory password in check items
    rlm_ldap: looking for check items in directory
    rlm_ldap: looking for reply items in directory
    rlm_ldap: user gerard authorized to use remote access
    rlm_ldap: ldap_release_conn: Release Id: 0
    modcall[authorize]: module "ldap" returns ok for request 4
    modcall: group authorize returns updated for request 4
    rad_check_password: Found Auth-Type EAP
    auth: type "EAP"
    Processing the authenticate section of radiusd.conf
    modcall: entering group authenticate for request 4
    rlm_eap: Request found, released from the list
    rlm_eap: EAP/peap
    rlm_eap: processing type peap
    rlm_eap_peap: Authenticate
    rlm_eap_tls: processing TLS
    rlm_eap_tls: Length Included
    eaptls_verify returned 11
    rlm_eap_tls: <<< TLS 1.0 Handshake [length 0086], ClientKeyExchange
    TLS_accept: SSLv3 read client key exchange A
    rlm_eap_tls: <<< TLS 1.0 ChangeCipherSpec [length 0001]
    rlm_eap_tls: <<< TLS 1.0 Handshake [length 0010], Finished
    TLS_accept: SSLv3 read finished A
    rlm_eap_tls: TLS 1.0 ChangeCipherSpec [length 0001]
    TLS_accept: SSLv3 write change cipher spec A
    rlm_eap_tls: TLS 1.0 Handshake [length 0010], Finished
    TLS_accept: SSLv3 write finished A
    TLS_accept: SSLv3 flush data
    (other): SSL negotiation finished successfully
    SSL Connection Established
    eaptls_process returned 13
    rlm_eap_peap: EAPTLS_HANDLED
    modcall[authenticate]: module "eap" returns handled for request 4
    modcall: group authenticate returns handled for request 4
    Sending Access-Challenge of id 184 to 10.61.100.163:1310
    EAP-Message =
    ae376b4eb525261d9893c440d839f
    Message-Authenticator =
    State =
    Finished request 4
    Going to the next request
    Waking up in 6 seconds
    rad_recv: Access-Request packet from host 10.61.100.163:1311, id=194,
    length=136
    User-Name = "gerard"
    EAP-Message =
    NAS-IP-Address = 10.61.100.163
    Service-Type = Login-User
    Calling-Station-Id = "00-10-b5-f4-98-0e"
    NAS-Port-Type = Ethernet
    State =
    Message-Authenticator =
    Processing the authorize section of radiusd.conf
    modcall: entering group authorize for request 5
    modcall[authorize]: module "preprocess" returns ok for request 5
    modcall[authorize]: module "chap" returns noop for request 5
    modcall[authorize]: module "mschap" returns noop for request 5
    rlm_realm: No '@' in User-Name = "gerard", looking up realm NULL
    rlm_realm: No such realm "NULL"
    modcall[authorize]: module "suffix" returns noop for request 5
    rlm_eap: EAP packet type response id 6 length 33
    rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
    modcall[authorize]: module "eap" returns updated for request 5
    users: Matched entry DEFAULT at line 152
    modcall[authorize]: module "files" returns ok for request 5
    rlm_ldap: - authorize
    rlm_ldap: performing user authorization for gerard
    radius_xlat: '(CN=gerard)'
    radius_xlat: 'ou=radius,ou=servicos,ou=brt,o=btp'
    rlm_ldap: ldap_get_conn: Checking Id: 0
    rlm_ldap: ldap_get_conn: Got Id: 0
    rlm_ldap: performing search in ou=radius,ou=servicos,ou=brt,o=btp,
    with filter (CN=gerard)
    rlm_ldap: Added the eDirectory password in check items
    rlm_ldap: looking for check items in directory
    rlm_ldap: looking for reply items in directory
    rlm_ldap: user gerard authorized to use remote access
    rlm_ldap: ldap_release_conn: Release Id: 0
    modcall[authorize]: module "ldap" returns ok for request 5
    modcall: group authorize returns updated for request 5
    rad_check_password: Found Auth-Type EAP
    auth: type "EAP"
    Processing the authenticate section of radiusd.conf
    modcall: entering group authenticate for request 5
    rlm_eap: Request found, released from the list
    rlm_eap: EAP/peap
    rlm_eap: processing type peap
    rlm_eap_peap: Authenticate
    rlm_eap_tls: processing TLS
    rlm_eap_tls: Length Included
    eaptls_verify returned 11
    eaptls_process returned 7
    rlm_eap_peap: EAPTLSK
    rlm_eap_peap: Session established. Decoding tunneled attributes.
    rlm_eap_tls: <<< TLS 1.0 Alert [length 0002], fatal access_denied
    TLS Alert read:fatal:access denied
    rlm_eap_peap: No data inside of the tunnel.
    rlm_eap: Handler failed in EAP/peap
    rlm_eap: Failed in EAP select
    modcall[authenticate]: module "eap" returns invalid for request 5
    modcall: group authenticate returns invalid for request 5
    auth: Failed to validate the user.
    Login incorrect: [gerard] (from client extreme port 0 cli 00-10-b5-f4-
    98-0e)
    Delaying request 5 for 1 seconds
    Finished request 5
    Going to the next request
    Waking up in 6 seconds
    rad_recv: Access-Request packet from host 10.61.100.163:1311, id=194,
    length=136
    Sending Access-Reject of id 194 to 10.61.100.163:1311
    EAP-Message = 0x04060004
    Message-Authenticator =
    Walking the entire request list
    Waking up in 3 seconds
    Walking the entire request list
    Cleaning up request 0 ID 104 with timestamp 43ce3715
    Cleaning up request 1 ID 144 with timestamp 43ce3715
    Cleaning up request 2 ID 154 with timestamp 43ce3715
    Cleaning up request 3 ID 159 with timestamp 43ce3715
    Cleaning up request 4 ID 184 with timestamp 43ce3715
    Cleaning up request 5 ID 194 with timestamp 43ce3715
    Nothing to do. Sleeping until we see a request.
    Thanks guys!
    Gerard
    -
    List info/subscribe/unsubscribe? See

Re: rlm_eap_peap: No data inside of the tunnel.


max 4000 letters.
Your nickname that display:
In order to stop the spam: 5 + 4 =
QUESTION ON "Networking"

EMSDN.COM