Radius server ans NAS keys don't match! ?




Hi,
I am trying to work with Radius on a FreeBSD machine.
When I try radlogin on the client machine , I get the following message from
the server

Ready to process requests.
Service-Type = 0x0000000100000000
User-Name = "xxx"
User-Password = "\240\365\313ħ\255\371\r\203\300.\275ܤ"
NAS-Port = 0x0000000000000000
NAS-IP-Address = 0x0a2a009b00000000
+- entering group authorize
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
rlm_realm: No '@' in User-Name = "xxx", looking up realm NULL
rlm_realm: No such realm "NULL"
++[suffix] returns noop
rlm_eap: No EAP-Message, not doing EAP
++[eap] returns noop
++[unix] returns notfound
users: Matched entry xxx at line 17
++[files] returns ok
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns updated
rad_check_password: Found Auth-Type
auth: type "PAP"
+- entering group PAP
rlm_pap: login attempt with password "?õËħ­ù ?À.½Ü?¤"
rlm_pap: Using clear text password "xxx"
rlm_pap: Passwords don't match
++[pap] returns reject
auth: Failed to validate the user.
Login incorrect (rlm_pap: CLEAR TEXT password check failed):
[kavita/\240\365\313ħ\255\371\r\203\300.\275Ü?¤] (from client hwq5 port 0)
WARNING: Unprintable characters in the password. Double-check the
shared secret on the server and the NAS!
Found Post-Auth-Type Reject
+- entering group REJECT
expand: %{User-Name} -> xxx
attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 1 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 1
Waking up in 4.9 seconds.
Cleaning up request 1 ID 127 with timestamp +24
Ready to process requests.



I have checked the secret key on the server and the client and it is the
same!

Is there any setting to be done in
/radiusclient-ng-0.5.6/etc/servers
apart from
radius_server_ip secret_key

and
/radiusclient-ng/radiusclient.conf

apart from
authserver radius_server_ip:1812

Thank you,
Kavita





--
View this message in context: http://www.nabble.com/Radius-server-ans-NAS-keys-don%27t-match%21---tp19058901p19058901.html
Sent from the freebsd-questions mailing list archive at Nabble.com.

_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • WAP +Radius
    ... Has anyone tried to setup a WAP using Radius to authenticate users? ... added to EAP section? ... Thread 2 handling request 6, ... entering group authenticate for request 6 ...
    (Debian-User)
  • Re: Outlook 2000 Question
    ... PS. Hope you understand my English (I'm not from an English talking ... >>> solely to do with the client machine. ... >>> format? ... >>> request ...
    (microsoft.public.outlook)
  • Re: Certificate Authority web enrollment error
    ... Is the CA machine reachable from the client machine on which the request ... The client machine should be in the same domain as the CA machine or both ... > CCertRequest::Submit The RPC server is unavailable. ... > The Certification Authority Service has not been started. ...
    (microsoft.public.win2000.security)
  • Re: Outlook 2000 Question
    ... >> - the meeting request is being sent in RTF ... >> solely to do with the client machine. ... >>> their email address in contacts) Is outlook set to choose the best ... >> format? ...
    (microsoft.public.outlook)
  • Re: HttpModules - Webservices
    ... eyeball the request/response from a client machine and see if there ... >Thought the solution was an HttpModule hooked into begin request, ... >public void OnBeginRequest ... > catch (Exception ex) ...
    (microsoft.public.dotnet.framework.aspnet)