testing: Config changes for FreeRADIUS 3.0
Also includes some changes for jessie's version of FreeRADIUS 2 (was previously a custom version). Besides the move to a subdir the config files were adapted for 3.0. The rlm_sim_files module was removed with FreeRADIUS 3 and Debian's package of FreeRADIUS 2 does not ship it, so we now replicate it using the files module (via users file, which is actually a symlink to mods-config/files/authorize in the default installation of FreeRADIUS 3). Another approach was tried using rlm_passwd, however, that module does not read binary/hex data, only printable strings, which would require changing the triplets. For 2.x a hack in the site config is necessary to make the attributes available to the EAP-SIM module.
This commit is contained in:
+16
@@ -0,0 +1,16 @@
|
||||
eap {
|
||||
default_eap_type = tls
|
||||
|
||||
tls-config tls-common {
|
||||
private_key_file = ${certdir}/aaaKey.pem
|
||||
certificate_file = ${certdir}/aaaCert.pem
|
||||
ca_file = ${cadir}/strongswanCert.pem
|
||||
cipher_list = "DEFAULT"
|
||||
dh_file = ${certdir}/dh
|
||||
random_file = ${certdir}/random
|
||||
}
|
||||
|
||||
tls {
|
||||
tls = tls-common
|
||||
}
|
||||
}
|
||||
+55
@@ -0,0 +1,55 @@
|
||||
server default {
|
||||
|
||||
listen {
|
||||
type = auth
|
||||
ipaddr = 10.1.0.10
|
||||
port = 0
|
||||
}
|
||||
|
||||
authorize {
|
||||
preprocess
|
||||
eap {
|
||||
ok = return
|
||||
}
|
||||
expiration
|
||||
logintime
|
||||
}
|
||||
|
||||
authenticate {
|
||||
eap
|
||||
}
|
||||
|
||||
preacct {
|
||||
preprocess
|
||||
acct_unique
|
||||
}
|
||||
|
||||
accounting {
|
||||
detail
|
||||
unix
|
||||
radutmp
|
||||
exec
|
||||
attr_filter.accounting_response
|
||||
}
|
||||
|
||||
session {
|
||||
radutmp
|
||||
}
|
||||
|
||||
post-auth {
|
||||
exec
|
||||
Post-Auth-Type REJECT {
|
||||
attr_filter.access_reject
|
||||
eap
|
||||
remove_reply_message_if_eap
|
||||
}
|
||||
}
|
||||
|
||||
pre-proxy {
|
||||
}
|
||||
|
||||
post-proxy {
|
||||
eap
|
||||
}
|
||||
|
||||
}
|
||||
@@ -9,7 +9,3 @@ charon {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
libtls {
|
||||
suites = TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user