LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking > Linux - Wireless Networking
User Name
Password
Linux - Wireless Networking This forum is for the discussion of wireless networking in Linux.

Notices


Reply
  Search this Thread
Old 03-26-2008, 05:26 AM   #1
saman
Member
 
Registered: Oct 2007
Posts: 49

Rep: Reputation: 13
WPA-Radius authentication errors


Hi Everybody,

Here I have problem and would like to ask for help.
Recently I try to implement freeradius with EAP-TLS.
I copied root.der and cert-clt.p12 and installed into Windows Xp.
Everything was fine until I tried to connect from Windows Xp and
I got an error saying "Authentication failed" then "Acquire network address". I

before using "WPA - Radius", I test it with WEP and it's connected.

Appreciate if anyone can help me solve this.
 
Old 03-26-2008, 06:40 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well what's the radius server say about that attempt?
 
Old 03-27-2008, 11:26 PM   #3
saman
Member
 
Registered: Oct 2007
Posts: 49

Original Poster
Rep: Reputation: 13
[QUOTE=acid_kewpie;3100851]well what's the radius server say about that attempt?

Thanks for response. Where can I check the server output?
 
Old 03-27-2008, 11:53 PM   #4
2Gnu
Senior Member
 
Registered: Jan 2002
Location: Southern California
Distribution: Slackware
Posts: 1,880

Rep: Reputation: 51
Run the service in debug mode to see a lot of detail about what's going on:

radiusd -X

http://www.freeradius.org/radiusd/INSTALL
 
Old 03-29-2008, 05:57 AM   #5
saman
Member
 
Registered: Oct 2007
Posts: 49

Original Poster
Rep: Reputation: 13
radiusd -X

Here the output

Processing the authorize section of radiusd.conf
modcall: entering group authorize for request 14
modcall[authorize]: module "preprocess" returns ok for request 14
modcall[authorize]: module "chap" returns noop for request 14
modcall[authorize]: module "mschap" returns noop for request 14
rlm_realm: No '@' in User-Name = "peter", looking up realm NULL
rlm_realm: No such realm "NULL"
modcall[authorize]: module "suffix" returns noop for request 14
rlm_eap: EAP packet type response id 1 length 23
rlm_eap: No EAP Start, assuming it's an on-going EAP conversation
modcall[authorize]: module "eap" returns updated for request 14
users: Matched entry DEFAULT at line 153

modcall[authorize]: module "files" returns ok for request 14
rlm_pap: WARNING! No "known good" password found for the user. Authentication may fail because of this.

modcall[authorize]: module "pap" returns noop for request 14
modcall: leaving group authorize (returns updated) for request 14
rad_check_password: Found Auth-Type EAP
auth: type "EAP"
Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 14
rlm_eap: EAP Identity
rlm_eap: processing type tls
rlm_eap_tls: Requiring client certificate
rlm_eap_tls: Initiate
rlm_eap_tls: Start returned 1
modcall[authenticate]: module "eap" returns handled for request 14
modcall: leaving group authenticate (returns handled) for request 14
Sending Access-Challenge of id 4 to 192.168.0.206 port 1024
EAP-Message = 0x010200060d20
Message-Authenticator = 0x00000000000000000000000000000000
State = 0x10078c1f070f3b1fd82eab98a5dbdd37
Finished request 14
Going to the next request
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Cleaning up request 13 ID 3 with timestamp 47ee1d76
Waking up in 5 seconds...
--- Walking the entire request list ---
Cleaning up request 14 ID 4 with timestamp 47ee1d7b
  1. Is it because the password hence it's not connected?
  2. Where to set the password and user name? (for example above "peter" to "joe")
  3. Should I run CA.all everytime got new user to generate root.der or cert-clt.p12 for each username?
  4. Openssl pkcs12 or Openssl req -new -x509 is for what?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
radius mac authentication sholah Linux - Server 9 12-05-2011 02:04 AM
WPA enterprise radius authentication certificate problems Geneset Linux - Wireless Networking 0 10-02-2007 06:10 PM
Wireless + Chillispot + Radius + WPA gurl4sh25 Linux - Wireless Networking 2 06-21-2007 07:12 AM
Ldap Radius Authentication tmolise Linux - Software 0 11-01-2006 10:49 AM
User authentication through radius tiger3090 Linux - Networking 1 09-08-2005 04:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking > Linux - Wireless Networking

All times are GMT -5. The time now is 06:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration