testing: Config changes for FreeRADIUS 3.0

Also includes some changes for jessie's version of FreeRADIUS 2 (was
previously a custom version).

Besides the move to a subdir the config files were adapted for 3.0.

The rlm_sim_files module was removed with FreeRADIUS 3 and Debian's
package of FreeRADIUS 2 does not ship it, so we now replicate it using
the files module (via users file, which is actually a symlink to
mods-config/files/authorize in the default installation of FreeRADIUS 3).
Another approach was tried using rlm_passwd, however, that module does
not read binary/hex data, only printable strings, which would require
changing the triplets.
For 2.x a hack in the site config is necessary to make the attributes
available to the EAP-SIM module.
This commit is contained in:
Tobias Brunner
2018-11-21 14:32:25 +01:00
parent a8112cc174
commit 231828f810
104 changed files with 1284 additions and 68 deletions
@@ -0,0 +1,5 @@
eap {
default_eap_type = md5
md5 {
}
}
@@ -0,0 +1,5 @@
realm strongswan.org {
type = radius
authhost = LOCAL
accthost = LOCAL
}
@@ -0,0 +1,56 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
suffix
files
eap {
ok = return
}
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1 @@
carol Cleartext-Password := "4iChxLT3"
@@ -0,0 +1,5 @@
realm strongswan.org {
type = radius
authhost = LOCAL
accthost = LOCAL
}
@@ -0,0 +1,53 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
suffix
files
pap
}
authenticate {
Auth-Type PAP {
pap
}
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
}
}
pre-proxy {
}
post-proxy {
}
}
@@ -0,0 +1 @@
carol Cleartext-Password := "4iChxLT3"
@@ -0,0 +1,5 @@
eap {
default_eap_type = sim
sim {
}
}
@@ -0,0 +1,58 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
files
eap {
ok = return
}
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1,2 @@
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
228060123456002 EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
@@ -1,3 +0,0 @@
sim_files {
simtriplets = "/etc/freeradius/triplets.dat"
}
@@ -2,13 +2,23 @@ authorize {
preprocess
chap
mschap
sim_files
suffix
files
update reply {
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
}
eap {
ok = return
}
unix
files
expiration
logintime
pap
@@ -1,6 +0,0 @@
228060123456001,30000000000000000000000000000000,30112233,305566778899AABB
228060123456001,31000000000000000000000000000000,31112233,315566778899AABB
228060123456001,32000000000000000000000000000000,32112233,325566778899AABB
228060123456002,33000000000000000000000000000000,33112233,335566778899AABB
228060123456002,34000000000000000000000000000000,34112233,345566778899AABB
228060123456002,35000000000000000000000000000000,35112233,355566778899AABB
@@ -0,0 +1,2 @@
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
228060123456002 EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
@@ -1,7 +1,3 @@
alice::cat /etc/freeradius/clients.conf
alice::cat /etc/freeradius/eap.conf
alice::cat /etc/freeradius/proxy.conf
alice::cat /etc/freeradius/triplets.dat
carol::cat /etc/ipsec.d/triplets.dat
dave::cat /etc/ipsec.d/triplets.dat
alice::freeradius
@@ -0,0 +1,5 @@
eap {
default_eap_type = md5
md5 {
}
}
@@ -0,0 +1,58 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1,4 @@
carol Cleartext-Password := "Ar3etTnp"
Framed-IP-Address = 10.3.0.1
dave Cleartext-Password := "W7R0g3do"
Framed-IP-Address = 10.3.0.2
@@ -0,0 +1,5 @@
eap {
default_eap_type = md5
md5 {
}
}
@@ -0,0 +1,58 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1,4 @@
carol Cleartext-Password := "Ar3etTnp"
Class = "Research"
dave Cleartext-Password := "W7R0g3do"
Class = "Accounting"
@@ -0,0 +1,5 @@
eap {
default_eap_type = md5
md5 {
}
}
@@ -0,0 +1,58 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1 @@
carol Cleartext-Password := "Ar3etTnp"
@@ -0,0 +1,5 @@
eap {
default_eap_type = md5
md5 {
}
}
@@ -0,0 +1,5 @@
realm strongswan.org {
type = radius
authhost = LOCAL
accthost = LOCAL
}
@@ -0,0 +1,59 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
suffix
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1 @@
carol Cleartext-Password := "Ar3etTnp"
@@ -0,0 +1,21 @@
eap {
md5 {
}
default_eap_type = peap
tls-config tls-common {
private_key_file = ${certdir}/aaaKey.pem
certificate_file = ${certdir}/aaaCert.pem
ca_file = ${cadir}/strongswanCert.pem
cipher_list = "DEFAULT"
dh_file = ${certdir}/dh
random_file = ${certdir}/random
}
peap {
tls = tls-common
default_eap_type = md5
use_tunneled_reply = yes
virtual_server = "inner-tunnel"
}
}
@@ -0,0 +1,5 @@
realm strongswan.org {
type = radius
authhost = LOCAL
accthost = LOCAL
}
@@ -0,0 +1,59 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
suffix
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1,38 @@
server inner-tunnel {
authorize {
filter_username
suffix
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
session {
radutmp
}
post-auth {
Post-Auth-Type REJECT {
attr_filter.access_reject
update outer.session-state {
&Module-Failure-Message := &request:Module-Failure-Message
}
}
}
pre-proxy {
}
post-proxy {
eap
}
} # inner-tunnel server block
@@ -0,0 +1,2 @@
carol Cleartext-Password := "Ar3etTnp"
dave Cleartext-Password := "W7R0g3do"
@@ -0,0 +1,5 @@
eap {
default_eap_type = sim
sim {
}
}
@@ -0,0 +1,58 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
files
eap {
ok = return
}
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1 @@
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
@@ -1,3 +0,0 @@
sim_files {
simtriplets = "/etc/freeradius/triplets.dat"
}
@@ -1,5 +1,16 @@
authorize {
sim_files
files
update reply {
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
}
eap {
ok = return
}
@@ -1,3 +0,0 @@
228060123456001,30000000000000000000000000000000,30112233,305566778899AABB
228060123456001,31000000000000000000000000000000,31112233,315566778899AABB
228060123456001,32000000000000000000000000000000,32112233,325566778899AABB
@@ -0,0 +1 @@
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
@@ -1,6 +1,5 @@
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
alice::cat /etc/freeradius/triplets.dat
carol::cat /etc/ipsec.d/triplets.dat
alice::freeradius
moon::ipsec start
@@ -0,0 +1,5 @@
eap {
default_eap_type = sim
sim {
}
}
@@ -0,0 +1,59 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
suffix
files
eap {
ok = return
}
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1,2 @@
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
@@ -1,3 +0,0 @@
sim_files {
simtriplets = "/etc/freeradius/triplets.dat"
}
@@ -1,6 +1,17 @@
authorize {
sim_files
files
suffix
update reply {
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
}
eap {
ok = return
}
@@ -1,6 +0,0 @@
[email protected],30000000000000000000000000000000,30112233,305566778899AABB
[email protected],31000000000000000000000000000000,31112233,315566778899AABB
[email protected],32000000000000000000000000000000,32112233,325566778899AABB
[email protected],33000000000000000000000000000000,33112233,335566778899AABB
[email protected],34000000000000000000000000000000,34112233,345566778899AABB
[email protected],35000000000000000000000000000000,35112233,355566778899AABB
@@ -0,0 +1,2 @@
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
@@ -7,7 +7,6 @@ dave::iptables-restore < /etc/iptables.rules
moon::rm /etc/ipsec.d/cacerts/*
carol::rm /etc/ipsec.d/cacerts/*
dave::rm /etc/ipsec.d/cacerts/*
alice::cat /etc/freeradius/triplets.dat
carol::cat /etc/ipsec.d/triplets.dat
dave::cat /etc/ipsec.d/triplets.dat
alice::freeradius
@@ -0,0 +1,5 @@
eap {
default_eap_type = sim
sim {
}
}
@@ -0,0 +1,59 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
suffix
files
eap {
ok = return
}
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1,2 @@
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
@@ -1,3 +0,0 @@
sim_files {
simtriplets = "/etc/freeradius/triplets.dat"
}
@@ -2,8 +2,19 @@ authorize {
preprocess
chap
mschap
sim_files
files
suffix
update reply {
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
}
eap {
ok = return
}
@@ -1,6 +0,0 @@
[email protected],30000000000000000000000000000000,30112233,305566778899AABB
[email protected],31000000000000000000000000000000,31112233,315566778899AABB
[email protected],32000000000000000000000000000000,32112233,325566778899AABB
[email protected],33000000000000000000000000000000,33112233,335566778899AABB
[email protected],34000000000000000000000000000000,34112233,345566778899AABB
[email protected],35000000000000000000000000000000,35112233,355566778899AABB
@@ -0,0 +1,2 @@
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
@@ -1,10 +1,6 @@
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
alice::cat /etc/freeradius/clients.conf
alice::cat /etc/freeradius/eap.conf
alice::cat /etc/freeradius/proxy.conf
alice::cat /etc/freeradius/triplets.dat
carol::cat /etc/ipsec.d/triplets.dat
dave::cat /etc/ipsec.d/triplets.dat
alice::freeradius
@@ -0,0 +1,16 @@
eap {
default_eap_type = tls
tls-config tls-common {
private_key_file = ${certdir}/aaaKey.pem
certificate_file = ${certdir}/aaaCert.pem
ca_file = ${cadir}/strongswanCert.pem
cipher_list = "DEFAULT"
dh_file = ${certdir}/dh
random_file = ${certdir}/random
}
tls {
tls = tls-common
}
}
@@ -0,0 +1,55 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
eap {
ok = return
}
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -9,7 +9,3 @@ charon {
}
}
}
libtls {
suites = TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
}
@@ -0,0 +1,21 @@
eap {
md5 {
}
default_eap_type = ttls
tls-config tls-common {
private_key_file = ${certdir}/aaaKey.pem
certificate_file = ${certdir}/aaaCert.pem
ca_file = ${cadir}/strongswanCert.pem
cipher_list = "DEFAULT"
dh_file = ${certdir}/dh
random_file = ${certdir}/random
}
ttls {
tls = tls-common
default_eap_type = md5
use_tunneled_reply = yes
virtual_server = "inner-tunnel"
}
}
@@ -0,0 +1,5 @@
realm strongswan.org {
type = radius
authhost = LOCAL
accthost = LOCAL
}
@@ -0,0 +1,59 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
suffix
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1,38 @@
server inner-tunnel {
authorize {
filter_username
suffix
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
session {
radutmp
}
post-auth {
Post-Auth-Type REJECT {
attr_filter.access_reject
update outer.session-state {
&Module-Failure-Message := &request:Module-Failure-Message
}
}
}
pre-proxy {
}
post-proxy {
eap
}
} # inner-tunnel server block
@@ -0,0 +1,2 @@
carol Cleartext-Password := "Ar3etTnp"
dave Cleartext-Password := "W7R0g3do"
@@ -0,0 +1,5 @@
eap {
default_eap_type = md5
md5 {
}
}
@@ -0,0 +1,64 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
listen {
type = acct
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
eap {
ok = return
}
files
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1 @@
carol Cleartext-Password := "Ar3etTnp"
@@ -0,0 +1,5 @@
eap {
default_eap_type = sim
sim {
}
}
@@ -0,0 +1,58 @@
server default {
listen {
type = auth
ipaddr = 10.1.0.10
port = 0
}
authorize {
preprocess
files
eap {
ok = return
}
expiration
logintime
}
authenticate {
eap
}
preacct {
preprocess
acct_unique
suffix
files
}
accounting {
detail
unix
radutmp
exec
attr_filter.accounting_response
}
session {
radutmp
}
post-auth {
exec
Post-Auth-Type REJECT {
attr_filter.access_reject
eap
remove_reply_message_if_eap
}
}
pre-proxy {
}
post-proxy {
eap
}
}
@@ -0,0 +1,2 @@
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
228060123456002 EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
@@ -1,3 +0,0 @@
sim_files {
simtriplets = "/etc/freeradius/triplets.dat"
}
@@ -2,8 +2,19 @@ authorize {
preprocess
chap
mschap
sim_files
files
suffix
update reply {
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
}
eap {
ok = return
}
@@ -1,6 +0,0 @@
228060123456001,30000000000000000000000000000000,30112233,305566778899AABB
228060123456001,31000000000000000000000000000000,31112233,315566778899AABB
228060123456001,32000000000000000000000000000000,32112233,325566778899AABB
228060123456002,33000000000000000000000000000000,33112233,335566778899AABB
228060123456002,34000000000000000000000000000000,34112233,345566778899AABB
228060123456002,35000000000000000000000000000000,35112233,355566778899AABB
@@ -0,0 +1,2 @@
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
228060123456002 EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB

Some files were not shown because too many files have changed in this diff Show More