testing: Config changes for FreeRADIUS 3.0
Also includes some changes for jessie's version of FreeRADIUS 2 (was previously a custom version). Besides the move to a subdir the config files were adapted for 3.0. The rlm_sim_files module was removed with FreeRADIUS 3 and Debian's package of FreeRADIUS 2 does not ship it, so we now replicate it using the files module (via users file, which is actually a symlink to mods-config/files/authorize in the default installation of FreeRADIUS 3). Another approach was tried using rlm_passwd, however, that module does not read binary/hex data, only printable strings, which would require changing the triplets. For 2.x a hack in the site config is necessary to make the attributes available to the EAP-SIM module.
This commit is contained in:
@@ -0,0 +1,5 @@
|
|||||||
|
client moon {
|
||||||
|
ipaddr = 10.1.0.1
|
||||||
|
secret = gv6URkSs
|
||||||
|
require_message_authenticator = yes
|
||||||
|
}
|
||||||
@@ -0,0 +1,99 @@
|
|||||||
|
# radiusd.conf -- FreeRADIUS server configuration file.
|
||||||
|
|
||||||
|
prefix = /usr
|
||||||
|
exec_prefix = /usr
|
||||||
|
sysconfdir = /etc
|
||||||
|
localstatedir = /var
|
||||||
|
sbindir = ${exec_prefix}/sbin
|
||||||
|
logdir = /var/log/freeradius
|
||||||
|
raddbdir = /etc/freeradius/3.0
|
||||||
|
radacctdir = ${logdir}/radacct
|
||||||
|
|
||||||
|
# name of the running server. See also the "-n" command-line option.
|
||||||
|
name = freeradius
|
||||||
|
|
||||||
|
# Location of config and logfiles.
|
||||||
|
confdir = ${raddbdir}
|
||||||
|
modconfdir = ${confdir}/mods-config
|
||||||
|
certdir = ${sysconfdir}/raddb/certs
|
||||||
|
cadir = ${sysconfdir}/raddb/certs
|
||||||
|
run_dir = ${localstatedir}/run/${name}
|
||||||
|
|
||||||
|
# Should likely be ${localstatedir}/lib/radiusd
|
||||||
|
db_dir = ${raddbdir}
|
||||||
|
|
||||||
|
# libdir: Where to find the rlm_* modules.
|
||||||
|
libdir = ${exec_prefix}/lib
|
||||||
|
|
||||||
|
# pidfile: Where to place the PID of the RADIUS server.
|
||||||
|
pidfile = ${run_dir}/${name}.pid
|
||||||
|
|
||||||
|
# correct_escapes: use correct backslash escaping
|
||||||
|
correct_escapes = true
|
||||||
|
|
||||||
|
# max_request_time: The maximum time (in seconds) to handle a request.
|
||||||
|
max_request_time = 30
|
||||||
|
|
||||||
|
# cleanup_delay: The time to wait (in seconds) before cleaning up
|
||||||
|
cleanup_delay = 5
|
||||||
|
|
||||||
|
# max_requests: The maximum number of requests which the server keeps
|
||||||
|
max_requests = 1024
|
||||||
|
|
||||||
|
# hostname_lookups: Log the names of clients or just their IP addresses
|
||||||
|
hostname_lookups = no
|
||||||
|
|
||||||
|
# Logging section
|
||||||
|
log {
|
||||||
|
destination = files
|
||||||
|
colourise = yes
|
||||||
|
file = ${logdir}/radius.log
|
||||||
|
syslog_facility = daemon
|
||||||
|
stripped_names = no
|
||||||
|
auth = yes
|
||||||
|
auth_badpass = yes
|
||||||
|
auth_goodpass = yes
|
||||||
|
}
|
||||||
|
|
||||||
|
# The program to execute to do concurrency checks.
|
||||||
|
checkrad = ${sbindir}/checkrad
|
||||||
|
|
||||||
|
# SECURITY CONFIGURATION
|
||||||
|
security {
|
||||||
|
user = freerad
|
||||||
|
group = freerad
|
||||||
|
allow_core_dumps = no
|
||||||
|
max_attributes = 200
|
||||||
|
reject_delay = 1
|
||||||
|
status_server = yes
|
||||||
|
}
|
||||||
|
|
||||||
|
# PROXY CONFIGURATION
|
||||||
|
proxy_requests = yes
|
||||||
|
$INCLUDE proxy.conf
|
||||||
|
|
||||||
|
# CLIENTS CONFIGURATION
|
||||||
|
$INCLUDE clients.conf
|
||||||
|
|
||||||
|
# THREAD POOL CONFIGURATION
|
||||||
|
thread pool {
|
||||||
|
start_servers = 5
|
||||||
|
max_servers = 32
|
||||||
|
min_spare_servers = 3
|
||||||
|
max_spare_servers = 10
|
||||||
|
max_requests_per_server = 0
|
||||||
|
auto_limit_acct = no
|
||||||
|
}
|
||||||
|
|
||||||
|
# MODULE CONFIGURATION
|
||||||
|
modules {
|
||||||
|
$INCLUDE ${confdir}/mods-enabled/
|
||||||
|
}
|
||||||
|
|
||||||
|
# Policies
|
||||||
|
policy {
|
||||||
|
$INCLUDE policy.d/
|
||||||
|
}
|
||||||
|
|
||||||
|
# Include all enabled virtual hosts
|
||||||
|
$INCLUDE sites-enabled/
|
||||||
@@ -101,8 +101,6 @@ thread pool {
|
|||||||
modules {
|
modules {
|
||||||
$INCLUDE ${confdir}/modules/
|
$INCLUDE ${confdir}/modules/
|
||||||
$INCLUDE eap.conf
|
$INCLUDE eap.conf
|
||||||
$INCLUDE sql.conf
|
|
||||||
$INCLUDE sql/mysql/counter.conf
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# Instantiation
|
# Instantiation
|
||||||
|
|||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = md5
|
||||||
|
md5 {
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
realm strongswan.org {
|
||||||
|
type = radius
|
||||||
|
authhost = LOCAL
|
||||||
|
accthost = LOCAL
|
||||||
|
}
|
||||||
+56
@@ -0,0 +1,56 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
carol Cleartext-Password := "4iChxLT3"
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
realm strongswan.org {
|
||||||
|
type = radius
|
||||||
|
authhost = LOCAL
|
||||||
|
accthost = LOCAL
|
||||||
|
}
|
||||||
+53
@@ -0,0 +1,53 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
pap
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
Auth-Type PAP {
|
||||||
|
pap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
carol Cleartext-Password := "4iChxLT3"
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = sim
|
||||||
|
sim {
|
||||||
|
}
|
||||||
|
}
|
||||||
+58
@@ -0,0 +1,58 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
files
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
|
228060123456002 EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
|
||||||
-3
@@ -1,3 +0,0 @@
|
|||||||
sim_files {
|
|
||||||
simtriplets = "/etc/freeradius/triplets.dat"
|
|
||||||
}
|
|
||||||
+12
-2
@@ -2,13 +2,23 @@ authorize {
|
|||||||
preprocess
|
preprocess
|
||||||
chap
|
chap
|
||||||
mschap
|
mschap
|
||||||
sim_files
|
|
||||||
suffix
|
suffix
|
||||||
|
files
|
||||||
|
update reply {
|
||||||
|
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
|
||||||
|
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
|
||||||
|
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
|
||||||
|
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
|
||||||
|
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
|
||||||
|
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
|
||||||
|
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
|
||||||
|
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
|
||||||
|
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
|
||||||
|
}
|
||||||
eap {
|
eap {
|
||||||
ok = return
|
ok = return
|
||||||
}
|
}
|
||||||
unix
|
unix
|
||||||
files
|
|
||||||
expiration
|
expiration
|
||||||
logintime
|
logintime
|
||||||
pap
|
pap
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
228060123456001,30000000000000000000000000000000,30112233,305566778899AABB
|
|
||||||
228060123456001,31000000000000000000000000000000,31112233,315566778899AABB
|
|
||||||
228060123456001,32000000000000000000000000000000,32112233,325566778899AABB
|
|
||||||
228060123456002,33000000000000000000000000000000,33112233,335566778899AABB
|
|
||||||
228060123456002,34000000000000000000000000000000,34112233,345566778899AABB
|
|
||||||
228060123456002,35000000000000000000000000000000,35112233,355566778899AABB
|
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
|
228060123456002 EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
|
||||||
|
|||||||
@@ -1,7 +1,3 @@
|
|||||||
alice::cat /etc/freeradius/clients.conf
|
|
||||||
alice::cat /etc/freeradius/eap.conf
|
|
||||||
alice::cat /etc/freeradius/proxy.conf
|
|
||||||
alice::cat /etc/freeradius/triplets.dat
|
|
||||||
carol::cat /etc/ipsec.d/triplets.dat
|
carol::cat /etc/ipsec.d/triplets.dat
|
||||||
dave::cat /etc/ipsec.d/triplets.dat
|
dave::cat /etc/ipsec.d/triplets.dat
|
||||||
alice::freeradius
|
alice::freeradius
|
||||||
|
|||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = md5
|
||||||
|
md5 {
|
||||||
|
}
|
||||||
|
}
|
||||||
+58
@@ -0,0 +1,58 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
carol Cleartext-Password := "Ar3etTnp"
|
||||||
|
Framed-IP-Address = 10.3.0.1
|
||||||
|
dave Cleartext-Password := "W7R0g3do"
|
||||||
|
Framed-IP-Address = 10.3.0.2
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = md5
|
||||||
|
md5 {
|
||||||
|
}
|
||||||
|
}
|
||||||
+58
@@ -0,0 +1,58 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
carol Cleartext-Password := "Ar3etTnp"
|
||||||
|
Class = "Research"
|
||||||
|
dave Cleartext-Password := "W7R0g3do"
|
||||||
|
Class = "Accounting"
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = md5
|
||||||
|
md5 {
|
||||||
|
}
|
||||||
|
}
|
||||||
+58
@@ -0,0 +1,58 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
carol Cleartext-Password := "Ar3etTnp"
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = md5
|
||||||
|
md5 {
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
realm strongswan.org {
|
||||||
|
type = radius
|
||||||
|
authhost = LOCAL
|
||||||
|
accthost = LOCAL
|
||||||
|
}
|
||||||
+59
@@ -0,0 +1,59 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
suffix
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
carol Cleartext-Password := "Ar3etTnp"
|
||||||
+21
@@ -0,0 +1,21 @@
|
|||||||
|
eap {
|
||||||
|
md5 {
|
||||||
|
}
|
||||||
|
default_eap_type = peap
|
||||||
|
|
||||||
|
tls-config tls-common {
|
||||||
|
private_key_file = ${certdir}/aaaKey.pem
|
||||||
|
certificate_file = ${certdir}/aaaCert.pem
|
||||||
|
ca_file = ${cadir}/strongswanCert.pem
|
||||||
|
cipher_list = "DEFAULT"
|
||||||
|
dh_file = ${certdir}/dh
|
||||||
|
random_file = ${certdir}/random
|
||||||
|
}
|
||||||
|
|
||||||
|
peap {
|
||||||
|
tls = tls-common
|
||||||
|
default_eap_type = md5
|
||||||
|
use_tunneled_reply = yes
|
||||||
|
virtual_server = "inner-tunnel"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
realm strongswan.org {
|
||||||
|
type = radius
|
||||||
|
authhost = LOCAL
|
||||||
|
accthost = LOCAL
|
||||||
|
}
|
||||||
+59
@@ -0,0 +1,59 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
suffix
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
+38
@@ -0,0 +1,38 @@
|
|||||||
|
server inner-tunnel {
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
filter_username
|
||||||
|
suffix
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
update outer.session-state {
|
||||||
|
&Module-Failure-Message := &request:Module-Failure-Message
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
} # inner-tunnel server block
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
carol Cleartext-Password := "Ar3etTnp"
|
||||||
|
dave Cleartext-Password := "W7R0g3do"
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = sim
|
||||||
|
sim {
|
||||||
|
}
|
||||||
|
}
|
||||||
+58
@@ -0,0 +1,58 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
files
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
sim_files {
|
|
||||||
simtriplets = "/etc/freeradius/triplets.dat"
|
|
||||||
}
|
|
||||||
+12
-1
@@ -1,5 +1,16 @@
|
|||||||
authorize {
|
authorize {
|
||||||
sim_files
|
files
|
||||||
|
update reply {
|
||||||
|
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
|
||||||
|
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
|
||||||
|
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
|
||||||
|
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
|
||||||
|
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
|
||||||
|
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
|
||||||
|
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
|
||||||
|
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
|
||||||
|
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
|
||||||
|
}
|
||||||
eap {
|
eap {
|
||||||
ok = return
|
ok = return
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
228060123456001,30000000000000000000000000000000,30112233,305566778899AABB
|
|
||||||
228060123456001,31000000000000000000000000000000,31112233,315566778899AABB
|
|
||||||
228060123456001,32000000000000000000000000000000,32112233,325566778899AABB
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
moon::iptables-restore < /etc/iptables.rules
|
moon::iptables-restore < /etc/iptables.rules
|
||||||
carol::iptables-restore < /etc/iptables.rules
|
carol::iptables-restore < /etc/iptables.rules
|
||||||
alice::cat /etc/freeradius/triplets.dat
|
|
||||||
carol::cat /etc/ipsec.d/triplets.dat
|
carol::cat /etc/ipsec.d/triplets.dat
|
||||||
alice::freeradius
|
alice::freeradius
|
||||||
moon::ipsec start
|
moon::ipsec start
|
||||||
|
|||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = sim
|
||||||
|
sim {
|
||||||
|
}
|
||||||
|
}
|
||||||
+59
@@ -0,0 +1,59 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
|
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
|
||||||
-3
@@ -1,3 +0,0 @@
|
|||||||
sim_files {
|
|
||||||
simtriplets = "/etc/freeradius/triplets.dat"
|
|
||||||
}
|
|
||||||
+12
-1
@@ -1,6 +1,17 @@
|
|||||||
authorize {
|
authorize {
|
||||||
sim_files
|
files
|
||||||
suffix
|
suffix
|
||||||
|
update reply {
|
||||||
|
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
|
||||||
|
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
|
||||||
|
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
|
||||||
|
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
|
||||||
|
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
|
||||||
|
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
|
||||||
|
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
|
||||||
|
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
|
||||||
|
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
|
||||||
|
}
|
||||||
eap {
|
eap {
|
||||||
ok = return
|
ok = return
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
[email protected],30000000000000000000000000000000,30112233,305566778899AABB
|
|
||||||
[email protected],31000000000000000000000000000000,31112233,315566778899AABB
|
|
||||||
[email protected],32000000000000000000000000000000,32112233,325566778899AABB
|
|
||||||
[email protected],33000000000000000000000000000000,33112233,335566778899AABB
|
|
||||||
[email protected],34000000000000000000000000000000,34112233,345566778899AABB
|
|
||||||
[email protected],35000000000000000000000000000000,35112233,355566778899AABB
|
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
|
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ dave::iptables-restore < /etc/iptables.rules
|
|||||||
moon::rm /etc/ipsec.d/cacerts/*
|
moon::rm /etc/ipsec.d/cacerts/*
|
||||||
carol::rm /etc/ipsec.d/cacerts/*
|
carol::rm /etc/ipsec.d/cacerts/*
|
||||||
dave::rm /etc/ipsec.d/cacerts/*
|
dave::rm /etc/ipsec.d/cacerts/*
|
||||||
alice::cat /etc/freeradius/triplets.dat
|
|
||||||
carol::cat /etc/ipsec.d/triplets.dat
|
carol::cat /etc/ipsec.d/triplets.dat
|
||||||
dave::cat /etc/ipsec.d/triplets.dat
|
dave::cat /etc/ipsec.d/triplets.dat
|
||||||
alice::freeradius
|
alice::freeradius
|
||||||
|
|||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = sim
|
||||||
|
sim {
|
||||||
|
}
|
||||||
|
}
|
||||||
+59
@@ -0,0 +1,59 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
|
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
sim_files {
|
|
||||||
simtriplets = "/etc/freeradius/triplets.dat"
|
|
||||||
}
|
|
||||||
+12
-1
@@ -2,8 +2,19 @@ authorize {
|
|||||||
preprocess
|
preprocess
|
||||||
chap
|
chap
|
||||||
mschap
|
mschap
|
||||||
sim_files
|
files
|
||||||
suffix
|
suffix
|
||||||
|
update reply {
|
||||||
|
EAP-Sim-Rand1 := "%{control:EAP-Sim-Rand1}"
|
||||||
|
EAP-Sim-Rand2 := "%{control:EAP-Sim-Rand2}"
|
||||||
|
EAP-Sim-Rand3 := "%{control:EAP-Sim-Rand3}"
|
||||||
|
EAP-Sim-SRES1 := "%{control:EAP-Sim-SRES1}"
|
||||||
|
EAP-Sim-SRES2 := "%{control:EAP-Sim-SRES2}"
|
||||||
|
EAP-Sim-SRES3 := "%{control:EAP-Sim-SRES3}"
|
||||||
|
EAP-Sim-KC1 := "%{control:EAP-Sim-KC1}"
|
||||||
|
EAP-Sim-KC2 := "%{control:EAP-Sim-KC2}"
|
||||||
|
EAP-Sim-KC3 := "%{control:EAP-Sim-KC3}"
|
||||||
|
}
|
||||||
eap {
|
eap {
|
||||||
ok = return
|
ok = return
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
[email protected],30000000000000000000000000000000,30112233,305566778899AABB
|
|
||||||
[email protected],31000000000000000000000000000000,31112233,315566778899AABB
|
|
||||||
[email protected],32000000000000000000000000000000,32112233,325566778899AABB
|
|
||||||
[email protected],33000000000000000000000000000000,33112233,335566778899AABB
|
|
||||||
[email protected],34000000000000000000000000000000,34112233,345566778899AABB
|
|
||||||
[email protected],35000000000000000000000000000000,35112233,355566778899AABB
|
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
|
[email protected] EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
|
||||||
|
|||||||
@@ -1,10 +1,6 @@
|
|||||||
moon::iptables-restore < /etc/iptables.rules
|
moon::iptables-restore < /etc/iptables.rules
|
||||||
carol::iptables-restore < /etc/iptables.rules
|
carol::iptables-restore < /etc/iptables.rules
|
||||||
dave::iptables-restore < /etc/iptables.rules
|
dave::iptables-restore < /etc/iptables.rules
|
||||||
alice::cat /etc/freeradius/clients.conf
|
|
||||||
alice::cat /etc/freeradius/eap.conf
|
|
||||||
alice::cat /etc/freeradius/proxy.conf
|
|
||||||
alice::cat /etc/freeradius/triplets.dat
|
|
||||||
carol::cat /etc/ipsec.d/triplets.dat
|
carol::cat /etc/ipsec.d/triplets.dat
|
||||||
dave::cat /etc/ipsec.d/triplets.dat
|
dave::cat /etc/ipsec.d/triplets.dat
|
||||||
alice::freeradius
|
alice::freeradius
|
||||||
|
|||||||
+16
@@ -0,0 +1,16 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = tls
|
||||||
|
|
||||||
|
tls-config tls-common {
|
||||||
|
private_key_file = ${certdir}/aaaKey.pem
|
||||||
|
certificate_file = ${certdir}/aaaCert.pem
|
||||||
|
ca_file = ${cadir}/strongswanCert.pem
|
||||||
|
cipher_list = "DEFAULT"
|
||||||
|
dh_file = ${certdir}/dh
|
||||||
|
random_file = ${certdir}/random
|
||||||
|
}
|
||||||
|
|
||||||
|
tls {
|
||||||
|
tls = tls-common
|
||||||
|
}
|
||||||
|
}
|
||||||
+55
@@ -0,0 +1,55 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -9,7 +9,3 @@ charon {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
libtls {
|
|
||||||
suites = TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
|
|
||||||
}
|
|
||||||
|
|||||||
+21
@@ -0,0 +1,21 @@
|
|||||||
|
eap {
|
||||||
|
md5 {
|
||||||
|
}
|
||||||
|
default_eap_type = ttls
|
||||||
|
|
||||||
|
tls-config tls-common {
|
||||||
|
private_key_file = ${certdir}/aaaKey.pem
|
||||||
|
certificate_file = ${certdir}/aaaCert.pem
|
||||||
|
ca_file = ${cadir}/strongswanCert.pem
|
||||||
|
cipher_list = "DEFAULT"
|
||||||
|
dh_file = ${certdir}/dh
|
||||||
|
random_file = ${certdir}/random
|
||||||
|
}
|
||||||
|
|
||||||
|
ttls {
|
||||||
|
tls = tls-common
|
||||||
|
default_eap_type = md5
|
||||||
|
use_tunneled_reply = yes
|
||||||
|
virtual_server = "inner-tunnel"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
realm strongswan.org {
|
||||||
|
type = radius
|
||||||
|
authhost = LOCAL
|
||||||
|
accthost = LOCAL
|
||||||
|
}
|
||||||
+59
@@ -0,0 +1,59 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
suffix
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
+38
@@ -0,0 +1,38 @@
|
|||||||
|
server inner-tunnel {
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
filter_username
|
||||||
|
suffix
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
update outer.session-state {
|
||||||
|
&Module-Failure-Message := &request:Module-Failure-Message
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
} # inner-tunnel server block
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
carol Cleartext-Password := "Ar3etTnp"
|
||||||
|
dave Cleartext-Password := "W7R0g3do"
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = md5
|
||||||
|
md5 {
|
||||||
|
}
|
||||||
|
}
|
||||||
+64
@@ -0,0 +1,64 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = acct
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
files
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
carol Cleartext-Password := "Ar3etTnp"
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
eap {
|
||||||
|
default_eap_type = sim
|
||||||
|
sim {
|
||||||
|
}
|
||||||
|
}
|
||||||
+58
@@ -0,0 +1,58 @@
|
|||||||
|
server default {
|
||||||
|
|
||||||
|
listen {
|
||||||
|
type = auth
|
||||||
|
ipaddr = 10.1.0.10
|
||||||
|
port = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
authorize {
|
||||||
|
preprocess
|
||||||
|
files
|
||||||
|
eap {
|
||||||
|
ok = return
|
||||||
|
}
|
||||||
|
expiration
|
||||||
|
logintime
|
||||||
|
}
|
||||||
|
|
||||||
|
authenticate {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
preacct {
|
||||||
|
preprocess
|
||||||
|
acct_unique
|
||||||
|
suffix
|
||||||
|
files
|
||||||
|
}
|
||||||
|
|
||||||
|
accounting {
|
||||||
|
detail
|
||||||
|
unix
|
||||||
|
radutmp
|
||||||
|
exec
|
||||||
|
attr_filter.accounting_response
|
||||||
|
}
|
||||||
|
|
||||||
|
session {
|
||||||
|
radutmp
|
||||||
|
}
|
||||||
|
|
||||||
|
post-auth {
|
||||||
|
exec
|
||||||
|
Post-Auth-Type REJECT {
|
||||||
|
attr_filter.access_reject
|
||||||
|
eap
|
||||||
|
remove_reply_message_if_eap
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pre-proxy {
|
||||||
|
}
|
||||||
|
|
||||||
|
post-proxy {
|
||||||
|
eap
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
228060123456001 EAP-Type := SIM, EAP-Sim-RAND1 := 0x30000000000000000000000000000000, EAP-Sim-SRES1 := 0x30112233, EAP-Sim-KC1 := 0x305566778899AABB, EAP-Sim-RAND2 := 0x31000000000000000000000000000000, EAP-Sim-SRES2 := 0x31112233, EAP-Sim-KC2 := 0x315566778899AABB, EAP-Sim-RAND3 := 0x32000000000000000000000000000000, EAP-Sim-SRES3 := 0x32112233, EAP-Sim-KC3 := 0x325566778899AABB
|
||||||
|
228060123456002 EAP-Type := SIM, EAP-Sim-RAND1 := 0x33000000000000000000000000000000, EAP-Sim-SRES1 := 0x33112233, EAP-Sim-KC1 := 0x335566778899AABB, EAP-Sim-RAND2 := 0x34000000000000000000000000000000, EAP-Sim-SRES2 := 0x34112233, EAP-Sim-KC2 := 0x345566778899AABB, EAP-Sim-RAND3 := 0x35000000000000000000000000000000, EAP-Sim-SRES3 := 0x35112233, EAP-Sim-KC3 := 0x355566778899AABB
|
||||||
-3
@@ -1,3 +0,0 @@
|
|||||||
sim_files {
|
|
||||||
simtriplets = "/etc/freeradius/triplets.dat"
|
|
||||||
}
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user