]> git.ipfire.org Git - thirdparty/freeradius-server.git/commitdiff
consistent formatting
authorMatthew Newton <matthew-git@newtoncomputing.co.uk>
Fri, 18 Jan 2019 23:14:08 +0000 (23:14 +0000)
committerMatthew Newton <matthew-git@newtoncomputing.co.uk>
Fri, 18 Jan 2019 23:14:08 +0000 (23:14 +0000)
raddb/mods-available/eap

index 2500e56b32c3536273dce1f504573095b03271d2..748fb9f302bebe629d52a47821f9e24088373372 100644 (file)
@@ -31,7 +31,7 @@ eap {
        #  configurable length of time, entries in the list
        #  expire, and are deleted.
        #
-       timer_expire     = 60
+       timer_expire = 60
 
        #  There are many EAP types, but the server has support
        #  for only a limited subset.  If the server receives
@@ -45,6 +45,7 @@ eap {
        #  If another module is NOT configured to handle the
        #  request, then the request will still end up being
        #  rejected.
+       #
        ignore_unknown_eap_types = no
 
        # Cisco AP1230B firmware 12.2(13)JA1 has a bug.  When given
@@ -53,17 +54,24 @@ eap {
        #
        # We can work around it by configurably adding an extra
        # zero byte.
+       #
        cisco_accounting_username_bug = no
 
-       #
        #  Help prevent DoS attacks by limiting the number of
        #  sessions that the server is tracking.  For simplicity,
        #  this is taken from the "max_requests" directive in
        #  radiusd.conf.
+       #
        max_sessions = ${max_requests}
 
-       # Supported EAP-types
 
+       ############################################################
+       #
+       #  Supported EAP-types
+       #
+
+
+       #  EAP-MD5
        #
        #  We do NOT recommend using EAP-MD5 authentication
        #  for wireless connections.  It is insecure, and does
@@ -72,17 +80,17 @@ eap {
        md5 {
        }
 
+
+       #  EAP-pwd -- secure password-based authentication
        #
-       # EAP-pwd -- secure password-based authentication
-       #
-#      pwd {
-#              group = 19
+       #pwd {
+       #       group = 19
 
-               #
-#              server_id = theserver@example.com
+       #       server_id = theserver@example.com
 
                #  This has the same meaning as for TLS.
-#              fragment_size = 1020
+               #
+       #       fragment_size = 1020
 
                # The virtual server which determines the
                # "known good" password for the user.
@@ -90,10 +98,12 @@ eap {
                # section is processed.  EAP-PWD requests can be
                # distinguished by having a User-Name, but
                # no User-Password, CHAP-Password, EAP-Message, etc.
-#              virtual_server = "inner-tunnel"
-#      }
+               #
+       #       virtual_server = "inner-tunnel"
+       #}
 
-       # Cisco LEAP
+
+       #  Cisco LEAP
        #
        #  We do not recommend using LEAP in new deployments.  See:
        #  http://www.securiteam.com/tools/5TP012ACKE.html
@@ -108,7 +118,8 @@ eap {
        leap {
        }
 
-       #  Generic Token Card.
+
+       #  EAP-GTC -- Generic Token Card
        #
        #  Currently, this is only permitted inside of EAP-TTLS,
        #  or EAP-PEAP.  The module "challenges" the user with
@@ -122,7 +133,8 @@ eap {
        gtc {
                #  The default challenge, which many clients
                #  ignore..
-               #challenge = "Password: "
+               #
+       #       challenge = "Password: "
 
                #  The plain-text response which comes back
                #  is put into a User-Password attribute,
@@ -139,7 +151,9 @@ eap {
                auth_type = PAP
        }
 
-       ## Common TLS configuration for TLS-based EAP types
+
+       #  Common TLS configuration for TLS-based EAP types
+       #  ------------------------------------------------
        #
        #  See raddb/certs/README for additional comments
        #  on certificates.
@@ -165,6 +179,7 @@ eap {
        #  e.g. using a Verisign cert as a "known CA" means that
        #  ANYONE who has a certificate signed by them can
        #  authenticate via EAP-TLS!  This is likely not what you want.
+       #
        tls-config tls-common {
                private_key_password = whatever
                private_key_file = ${certdir}/server.pem
@@ -179,6 +194,7 @@ eap {
                #  only the server certificate, but ALSO all
                #  of the CA certificates used to sign the
                #  server certificate.
+               #
                certificate_file = ${certdir}/server.pem
 
                #  Trusted Root CA list
@@ -200,9 +216,9 @@ eap {
                #
                #  When setting "auto_chain = no", the server certificate
                #  file MUST include the full certificate chain.
+               #
        #       auto_chain = yes
 
-               #
                #  If OpenSSL supports TLS-PSK, then we can use a
                #  fixed PSK identity and (hex) password.  As of
                #  3.0.18, these can be used at the same time as the
@@ -218,11 +234,9 @@ eap {
                #  configured, and the other will have certificates
                #  configured.
                #
-#              psk_identity = "test"
-#              psk_hexphrase = "036363823"
-
+       #       psk_identity = "test"
+       #       psk_hexphrase = "036363823"
 
-               #
                #  Dynamic queries for the PSK.  If TLS-PSK is used,
                #  and psk_query is set, then you MUST NOT use
                #  psk_identity or psk_hexphrase.
@@ -236,17 +250,15 @@ eap {
                #  Note that this query is just an example.  You will
                #  need to customize it for your installation.
                #
-#              psk_query = "%{sql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
+       #       psk_query = "%{sql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
 
-               #
                #  For DH cipher suites to work, you have to
                #  run OpenSSL to create the DH file first:
                #
-               #       openssl dhparam -out certs/dh 2048
+               #    openssl dhparam -out certs/dh 2048
                #
                dh_file = ${certdir}/dh
 
-               #
                #  If your system doesn't have /dev/urandom,
                #  you will need to create this file, and
                #  periodically change its contents.
@@ -257,7 +269,6 @@ eap {
                #
        #       random_file = /dev/urandom
 
-               #
                #  This can never exceed the size of a RADIUS
                #  packet (4096 bytes), and is preferably half
                #  that, to accommodate other attributes in
@@ -283,7 +294,7 @@ eap {
                #
                #  1) Copy CA certificates and CRLs to same directory.
                #  2) Execute 'c_rehash <CA certs&CRLs Directory>'.
-               #    'c_rehash' is OpenSSL's command.
+               #     'c_rehash' is OpenSSL's command.
                #  3) uncomment the lines below.
                #  5) Restart radiusd
        #       check_crl = yes
@@ -295,9 +306,8 @@ eap {
 
                # Accept an expired Certificate Revocation List
                #
-#              allow_expired_crl = no
+       #       allow_expired_crl = no
 
-               #
                #  If check_cert_issuer is set, the value will
                #  be checked against the DN of the issuer in
                #  the client certificate.  If the values do not
@@ -311,7 +321,6 @@ eap {
                #
        #       check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
 
-               #
                #  If check_cert_cn is set, the value will
                #  be xlat'ed and checked against the CN
                #  in the client certificate.  If the values
@@ -328,24 +337,24 @@ eap {
                #  can be done via any mechanism you choose.
                #
        #       check_cert_cn = %{User-Name}
+
+               #  Set this option to specify the allowed
+               #  TLS cipher suites.  The format is listed
+               #  in "man 1 ciphers".
                #
-               # Set this option to specify the allowed
-               # TLS cipher suites.  The format is listed
-               # in "man 1 ciphers".
-               #
-               # For EAP-FAST, use "ALL:!EXPORT:!eNULL:!SSLv2"
+               #  For EAP-FAST, use "ALL:!EXPORT:!eNULL:!SSLv2"
                #
                cipher_list = "DEFAULT"
 
-               # If enabled, OpenSSL will use server cipher list
-               # (possibly defined by cipher_list option above)
-               # for choosing right cipher suite rather than
-               # using client-specified list which is OpenSSl default
-               # behavior. Having it set to yes is a current best practice
-               # for TLS
+               #  If enabled, OpenSSL will use server cipher list
+               #  (possibly defined by cipher_list option above)
+               #  for choosing right cipher suite rather than
+               #  using client-specified list which is OpenSSl default
+               #  behavior. Having it set to yes is a current best practice
+               #  for TLS.
+               #
                cipher_server_preference = no
 
-               #
                #  You can selectively disable TLS versions for
                #  compatability with old client devices.
                #
@@ -353,11 +362,10 @@ eap {
                #  use these.  Instead, set tls_min_version and
                #  tls_max_version.
                #
-#              disable_tlsv1_2 = no
-#              disable_tlsv1_1 = no
-#              disable_tlsv1 = no
+       #       disable_tlsv1_2 = no
+       #       disable_tlsv1_1 = no
+       #       disable_tlsv1 = no
 
-               #
                #  Set min / max TLS version.  Mainly for Debian
                #  "trusty", which disables older versions of TLS, and
                #  requires the application to manually enable them.
@@ -370,27 +378,24 @@ eap {
                #
                #  The values must be in quotes.
                #
-#              tls_min_version = "1.0"
-#              tls_max_version = "1.2"
+       #       tls_min_version = "1.0"
+       #       tls_max_version = "1.2"
 
-
-               #
                #  Elliptical cryptography configuration
                #
                #  Only for OpenSSL >= 0.9.8.f
                #
                ecdh_curve = "prime256v1"
 
-               #
                #  Session resumption / fast reauthentication
                #  cache.
                #
                #  The cache contains the following information:
                #
-               #  session Id - unique identifier, managed by SSL
-               #  User-Name  - from the Access-Accept
-               #  Stripped-User-Name - from the Access-Request
-               #  Cached-Session-Policy - from the Access-Accept
+               #   session Id - unique identifier, managed by SSL
+               #   User-Name  - from the Access-Accept
+               #   Stripped-User-Name - from the Access-Request
+               #   Cached-Session-Policy - from the Access-Accept
                #
                #  The "Cached-Session-Policy" is the name of a
                #  policy which should be applied to the cached
@@ -408,7 +413,6 @@ eap {
                #  when using fast session resumption.
                #
                cache {
-                       #
                        #  Enable it.  The default is "no". Deleting the entire "cache"
                        #  subsection also disables caching.
                        #
@@ -428,13 +432,11 @@ eap {
                        #
                        enable = no
 
-                       #
                        #  Lifetime of the cached entries, in hours. The sessions will be
                        #  deleted/invalidated after this time.
                        #
                        lifetime = 24 # hours
 
-                       #
                        #  Internal "name" of the session cache. Used to
                        #  distinguish which TLS context sessions belong to.
                        #
@@ -443,9 +445,8 @@ eap {
                        #  set the "name" if you want to persist sessions (see
                        #  below).
                        #
-                       #name = "EAP module"
+               #       name = "EAP module"
 
-                       #
                        #  Simple directory-based storage of sessions.
                        #  Two files per session will be written, the SSL
                        #  state and the cached VPs. This will persist session
@@ -464,10 +465,9 @@ eap {
                        #
                        #  This feature REQUIRES "name" option be set above.
                        #
-                       #persist_dir = "${logdir}/tlscache"
+               #       persist_dir = "${logdir}/tlscache"
                }
 
-               #
                #  As of version 2.1.10, client certificates can be
                #  validated via an external command.  This allows
                #  dynamic CRLs or OCSP to be used.
@@ -489,7 +489,8 @@ eap {
                        #  If you want to skip verify on OCSP success,
                        #  uncomment this configuration item, and set it
                        #  to "yes".
-       #               skip_if_ocsp_ok = no
+                       #
+               #       skip_if_ocsp_ok = no
 
                        #  A temporary directory where the client
                        #  certificates are stored.  This directory
@@ -502,7 +503,8 @@ eap {
                        #
                        #  You should also delete all of the files
                        #  in the directory when the server starts.
-       #               tmpdir = /tmp/radiusd
+                       #
+               #       tmpdir = /tmp/radiusd
 
                        #  The command used to verify the client cert.
                        #  We recommend using the OpenSSL command-line
@@ -516,25 +518,24 @@ eap {
                        #  in PEM format.  This file is automatically
                        #  deleted by the server when the command
                        #  returns.
-       #               client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
+                       #
+               #       client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
                }
 
-               #
                #  OCSP Configuration
+               #
                #  Certificates can be verified against an OCSP
                #  Responder. This makes it possible to immediately
                #  revoke certificates without the distribution of
                #  new Certificate Revocation Lists (CRLs).
                #
                ocsp {
-                       #
                        #  Enable it.  The default is "no".
                        #  Deleting the entire "ocsp" subsection
                        #  also disables ocsp checking
                        #
                        enable = no
 
-                       #
                        #  The OCSP Responder URL can be automatically
                        #  extracted from the certificate in question.
                        #  To override the OCSP Responder URL set
@@ -542,13 +543,11 @@ eap {
                        #
                        override_cert_url = yes
 
-                       #
                        #  If the OCSP Responder address is not extracted from
                        #  the certificate, the URL can be defined here.
                        #
                        url = "http://127.0.0.1/ocsp/"
 
-                       #
                        # If the OCSP Responder can not cope with nonce
                        # in the request, then it can be disabled here.
                        #
@@ -562,15 +561,13 @@ eap {
                        # to disable it in the query here.
                        # See http://technet.microsoft.com/en-us/library/cc770413%28WS.10%29.aspx
                        #
-                       # use_nonce = yes
+               #       use_nonce = yes
 
-                       #
                        # Number of seconds before giving up waiting
                        # for OCSP response. 0 uses system default.
                        #
-                       # timeout = 0
+               #       timeout = 0
 
-                       #
                        # Normally an error in querying the OCSP
                        # responder (no response from server, server did
                        # not understand the request, etc) will result in
@@ -584,30 +581,31 @@ eap {
                        # certificates to connect if the OCSP responder
                        # is not available. Use with caution.
                        #
-                       # softfail = no
+               #       softfail = no
                }
        }
 
-       ## EAP-TLS
+
+       #  EAP-TLS
        #
        #  As of Version 3.0, the TLS configuration for TLS-based
        #  EAP types is above in the "tls-config" section.
        #
        tls {
-               # Point to the common TLS configuration
+               #  Point to the common TLS configuration
+               #
                tls = tls-common
 
-               #
-               # As part of checking a client certificate, the EAP-TLS
-               # sets some attributes such as TLS-Client-Cert-Common-Name. This
-               # virtual server has access to these attributes, and can
-               # be used to accept or reject the request.
+               #  As part of checking a client certificate, the EAP-TLS
+               #  sets some attributes such as TLS-Client-Cert-Common-Name. This
+               #  virtual server has access to these attributes, and can
+               #  be used to accept or reject the request.
                #
        #       virtual_server = check-eap-tls
        }
 
 
-       ## EAP-TTLS
+       #  EAP-TTLS -- Tunneled TLS
        #
        #  The TTLS module implements the EAP-TTLS protocol,
        #  which can be described as EAP inside of Diameter,
@@ -652,14 +650,12 @@ eap {
                #
                copy_request_to_tunnel = no
 
-               #
                #  As of version 3.0.5, this configuration item
                #  is deprecated.  Instead, you should use
                #
-               #       update outer.session-state {
-               #               ...
-               #
-               #       }
+               #    update outer.session-state {
+               #      ...
+               #    }
                #
                #  This will cache attributes for the final Access-Accept.
                #
@@ -675,7 +671,6 @@ eap {
                #
                use_tunneled_reply = no
 
-               #
                #  The inner tunneled request can be sent
                #  through a virtual server constructed
                #  specifically for this purpose.
@@ -690,25 +685,24 @@ eap {
                #
        #       include_length = yes
 
+               #  Unlike EAP-TLS, EAP-TTLS does not require a client
+               #  certificate. However, you can require one by setting the
+               #  following option. You can also override this option by
+               #  setting
                #
-               # Unlike EAP-TLS, EAP-TTLS does not require a client
-               # certificate. However, you can require one by setting the
-               # following option. You can also override this option by
-               # setting
+               #    EAP-TLS-Require-Client-Cert = Yes
                #
-               #       EAP-TLS-Require-Client-Cert = Yes
+               #  in the control items for a request.
                #
-               # in the control items for a request.
-               #
-               # Note that the majority of supplicants do not support using a
-               # client certificate with EAP-TTLS, so this option is unlikely
-               # to be usable for most people.
+               #  Note that the majority of supplicants do not support using a
+               #  client certificate with EAP-TTLS, so this option is unlikely
+               #  to be usable for most people.
                #
        #       require_client_cert = yes
        }
 
 
-       ## EAP-PEAP
+       #  EAP-PEAP
        #
 
        ##################################################
@@ -728,12 +722,7 @@ eap {
        #  fail.  See the "scripts/xpextensions" file for
        #  details, and the following page:
        #
-       #       http://support.microsoft.com/kb/814394/en-us
-       #
-       #  For additional Windows XP SP2 issues, see:
-       #
-       #       http://support.microsoft.com/kb/885453/en-us
-       #
+       #       https://support.microsoft.com/en-us/help/814394/
        #
        #  If is still doesn't work, and you're using Samba,
        #  you may be encountering a Samba bug.  See:
@@ -745,7 +734,6 @@ eap {
        #
        ##################################################
 
-       #
        #  The tunneled EAP session needs a default EAP type
        #  which is separate from the one for the non-tunneled
        #  EAP module.  Inside of the TLS/PEAP tunnel, we
@@ -777,14 +765,12 @@ eap {
                #
                copy_request_to_tunnel = no
 
-               #
                #  As of version 3.0.5, this configuration item
                #  is deprecated.  Instead, you should use
                #
-               #       update outer.session-state {
-               #               ...
-               #
-               #       }
+               #    update outer.session-state {
+               #      ...
+               #    }
                #
                #  This will cache attributes for the final Access-Accept.
                #
@@ -797,7 +783,6 @@ eap {
                #
        #       proxy_tunneled_request_as_eap = yes
 
-               #
                #  The inner tunneled request can be sent
                #  through a virtual server constructed
                #  specifically for this purpose.
@@ -806,36 +791,34 @@ eap {
                #
                virtual_server = "inner-tunnel"
 
-               # This option enables support for MS-SoH
-               # see doc/SoH.txt for more info.
-               # It is disabled by default.
+               #  This option enables support for MS-SoH
+               #  see doc/SoH.txt for more info.
+               #  It is disabled by default.
                #
        #       soh = yes
 
-               #
-               # The SoH reply will be turned into a request which
-               # can be sent to a specific virtual server:
+               #  The SoH reply will be turned into a request which
+               #  can be sent to a specific virtual server:
                #
        #       soh_virtual_server = "soh-server"
 
+               #  Unlike EAP-TLS, PEAP does not require a client certificate.
+               #  However, you can require one by setting the following
+               #  option. You can also override this option by setting
                #
-               # Unlike EAP-TLS, PEAP does not require a client certificate.
-               # However, you can require one by setting the following
-               # option. You can also override this option by setting
+               #    EAP-TLS-Require-Client-Cert = Yes
                #
-               #       EAP-TLS-Require-Client-Cert = Yes
+               #  in the control items for a request.
                #
-               # in the control items for a request.
-               #
-               # Note that the majority of supplicants do not support using a
-               # client certificate with PEAP, so this option is unlikely to
-               # be usable for most people.
+               #  Note that the majority of supplicants do not support using a
+               #  client certificate with PEAP, so this option is unlikely to
+               #  be usable for most people.
                #
        #       require_client_cert = yes
        }
 
-       #
-       #  This takes no configuration.
+
+       #  EAP-MSCHAPv2
        #
        #  Note that it is the EAP MS-CHAPv2 sub-module, not
        #  the main 'mschap' module.
@@ -865,25 +848,26 @@ eap {
                #  but *may* also cause other clients to stop
                #  working.
                #
-#              send_error = no
+       #       send_error = no
 
                #  Server identifier to send back in the challenge.
                #  This should generally be the host name of the
                #  RADIUS server.  Or, some information to uniquely
                #  identify it.
-#              identity = "FreeRADIUS"
+               #
+       #       identity = "FreeRADIUS"
        }
 
-       ## EAP-FAST
+
+       #  EAP-FAST
        #
        #  The FAST module implements the EAP-FAST protocol
        #
-#      fast {
-               # Point to the common TLS configuration
+       #fast {
+               #  Point to the common TLS configuration
                #
-#              tls = tls-common
+       #       tls = tls-common
 
-               #
                #  If 'cipher_list' is set here, it will over-ride the
                #  'cipher_list' configuration from the 'tls-common'
                #  configuration.  The EAP-FAST module has it's own
@@ -899,30 +883,30 @@ eap {
                #  Note - for OpenSSL 1.1.0 and above you may need
                #  to add ":@SECLEVEL=0"
                #
-#              cipher_list = "ALL:!EXPORT:!eNULL:!SSLv2"
+       #       cipher_list = "ALL:!EXPORT:!eNULL:!SSLv2"
 
-               # PAC lifetime in seconds (default: seven days)
+               #  PAC lifetime in seconds (default: seven days)
                #
-#              pac_lifetime = 604800
+       #       pac_lifetime = 604800
 
-               # Authority ID of the server
+               #  Authority ID of the server
                #
-               # if you are running a cluster of RADIUS servers, you should make
-               # the value chosen here (and for "pac_opaque_key") the same on all
-               # your RADIUS servers.  This value should be unique to your
-               # installation.  We suggest using a domain name.
+               #  If you are running a cluster of RADIUS servers, you should make
+               #  the value chosen here (and for "pac_opaque_key") the same on all
+               #  your RADIUS servers.  This value should be unique to your
+               #  installation.  We suggest using a domain name.
                #
-#              authority_identity = "1234"
+       #       authority_identity = "1234"
 
-               # PAC Opaque encryption key (must be exactly 32 bytes in size)
+               #  PAC Opaque encryption key (must be exactly 32 bytes in size)
                #
-               # This value MUST be secret, and MUST be generated using
-               # a secure method, such as via 'openssl rand -hex 32'
+               #  This value MUST be secret, and MUST be generated using
+               #  a secure method, such as via 'openssl rand -hex 32'
                #
-#              pac_opaque_key = "0123456789abcdef0123456789ABCDEF"
+       #       pac_opaque_key = "0123456789abcdef0123456789ABCDEF"
 
-               # Same as for TTLS, PEAP, etc.
+               #  Same as for TTLS, PEAP, etc.
                #
-#              virtual_server = inner-tunnel
-#      }
+       #       virtual_server = inner-tunnel
+       #}
 }