# configurable length of time, entries in the list
# expire, and are deleted.
#
- timer_expire = 60
+ timer_expire = 60
# There are many EAP types, but the server has support
# for only a limited subset. If the server receives
# If another module is NOT configured to handle the
# request, then the request will still end up being
# rejected.
+ #
ignore_unknown_eap_types = no
# Cisco AP1230B firmware 12.2(13)JA1 has a bug. When given
#
# We can work around it by configurably adding an extra
# zero byte.
+ #
cisco_accounting_username_bug = no
- #
# Help prevent DoS attacks by limiting the number of
# sessions that the server is tracking. For simplicity,
# this is taken from the "max_requests" directive in
# radiusd.conf.
+ #
max_sessions = ${max_requests}
- # Supported EAP-types
+ ############################################################
+ #
+ # Supported EAP-types
+ #
+
+
+ # EAP-MD5
#
# We do NOT recommend using EAP-MD5 authentication
# for wireless connections. It is insecure, and does
md5 {
}
+
+ # EAP-pwd -- secure password-based authentication
#
- # EAP-pwd -- secure password-based authentication
- #
-# pwd {
-# group = 19
+ #pwd {
+ # group = 19
- #
-# server_id = theserver@example.com
+ # server_id = theserver@example.com
# This has the same meaning as for TLS.
-# fragment_size = 1020
+ #
+ # fragment_size = 1020
# The virtual server which determines the
# "known good" password for the user.
# section is processed. EAP-PWD requests can be
# distinguished by having a User-Name, but
# no User-Password, CHAP-Password, EAP-Message, etc.
-# virtual_server = "inner-tunnel"
-# }
+ #
+ # virtual_server = "inner-tunnel"
+ #}
- # Cisco LEAP
+
+ # Cisco LEAP
#
# We do not recommend using LEAP in new deployments. See:
# http://www.securiteam.com/tools/5TP012ACKE.html
leap {
}
- # Generic Token Card.
+
+ # EAP-GTC -- Generic Token Card
#
# Currently, this is only permitted inside of EAP-TTLS,
# or EAP-PEAP. The module "challenges" the user with
gtc {
# The default challenge, which many clients
# ignore..
- #challenge = "Password: "
+ #
+ # challenge = "Password: "
# The plain-text response which comes back
# is put into a User-Password attribute,
auth_type = PAP
}
- ## Common TLS configuration for TLS-based EAP types
+
+ # Common TLS configuration for TLS-based EAP types
+ # ------------------------------------------------
#
# See raddb/certs/README for additional comments
# on certificates.
# e.g. using a Verisign cert as a "known CA" means that
# ANYONE who has a certificate signed by them can
# authenticate via EAP-TLS! This is likely not what you want.
+ #
tls-config tls-common {
private_key_password = whatever
private_key_file = ${certdir}/server.pem
# only the server certificate, but ALSO all
# of the CA certificates used to sign the
# server certificate.
+ #
certificate_file = ${certdir}/server.pem
# Trusted Root CA list
#
# When setting "auto_chain = no", the server certificate
# file MUST include the full certificate chain.
+ #
# auto_chain = yes
- #
# If OpenSSL supports TLS-PSK, then we can use a
# fixed PSK identity and (hex) password. As of
# 3.0.18, these can be used at the same time as the
# configured, and the other will have certificates
# configured.
#
-# psk_identity = "test"
-# psk_hexphrase = "036363823"
-
+ # psk_identity = "test"
+ # psk_hexphrase = "036363823"
- #
# Dynamic queries for the PSK. If TLS-PSK is used,
# and psk_query is set, then you MUST NOT use
# psk_identity or psk_hexphrase.
# Note that this query is just an example. You will
# need to customize it for your installation.
#
-# psk_query = "%{sql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
+ # psk_query = "%{sql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
- #
# For DH cipher suites to work, you have to
# run OpenSSL to create the DH file first:
#
- # openssl dhparam -out certs/dh 2048
+ # openssl dhparam -out certs/dh 2048
#
dh_file = ${certdir}/dh
- #
# If your system doesn't have /dev/urandom,
# you will need to create this file, and
# periodically change its contents.
#
# random_file = /dev/urandom
- #
# This can never exceed the size of a RADIUS
# packet (4096 bytes), and is preferably half
# that, to accommodate other attributes in
#
# 1) Copy CA certificates and CRLs to same directory.
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
- # 'c_rehash' is OpenSSL's command.
+ # 'c_rehash' is OpenSSL's command.
# 3) uncomment the lines below.
# 5) Restart radiusd
# check_crl = yes
# Accept an expired Certificate Revocation List
#
-# allow_expired_crl = no
+ # allow_expired_crl = no
- #
# If check_cert_issuer is set, the value will
# be checked against the DN of the issuer in
# the client certificate. If the values do not
#
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
- #
# If check_cert_cn is set, the value will
# be xlat'ed and checked against the CN
# in the client certificate. If the values
# can be done via any mechanism you choose.
#
# check_cert_cn = %{User-Name}
+
+ # Set this option to specify the allowed
+ # TLS cipher suites. The format is listed
+ # in "man 1 ciphers".
#
- # Set this option to specify the allowed
- # TLS cipher suites. The format is listed
- # in "man 1 ciphers".
- #
- # For EAP-FAST, use "ALL:!EXPORT:!eNULL:!SSLv2"
+ # For EAP-FAST, use "ALL:!EXPORT:!eNULL:!SSLv2"
#
cipher_list = "DEFAULT"
- # If enabled, OpenSSL will use server cipher list
- # (possibly defined by cipher_list option above)
- # for choosing right cipher suite rather than
- # using client-specified list which is OpenSSl default
- # behavior. Having it set to yes is a current best practice
- # for TLS
+ # If enabled, OpenSSL will use server cipher list
+ # (possibly defined by cipher_list option above)
+ # for choosing right cipher suite rather than
+ # using client-specified list which is OpenSSl default
+ # behavior. Having it set to yes is a current best practice
+ # for TLS.
+ #
cipher_server_preference = no
- #
# You can selectively disable TLS versions for
# compatability with old client devices.
#
# use these. Instead, set tls_min_version and
# tls_max_version.
#
-# disable_tlsv1_2 = no
-# disable_tlsv1_1 = no
-# disable_tlsv1 = no
+ # disable_tlsv1_2 = no
+ # disable_tlsv1_1 = no
+ # disable_tlsv1 = no
- #
# Set min / max TLS version. Mainly for Debian
# "trusty", which disables older versions of TLS, and
# requires the application to manually enable them.
#
# The values must be in quotes.
#
-# tls_min_version = "1.0"
-# tls_max_version = "1.2"
+ # tls_min_version = "1.0"
+ # tls_max_version = "1.2"
-
- #
# Elliptical cryptography configuration
#
# Only for OpenSSL >= 0.9.8.f
#
ecdh_curve = "prime256v1"
- #
# Session resumption / fast reauthentication
# cache.
#
# The cache contains the following information:
#
- # session Id - unique identifier, managed by SSL
- # User-Name - from the Access-Accept
- # Stripped-User-Name - from the Access-Request
- # Cached-Session-Policy - from the Access-Accept
+ # session Id - unique identifier, managed by SSL
+ # User-Name - from the Access-Accept
+ # Stripped-User-Name - from the Access-Request
+ # Cached-Session-Policy - from the Access-Accept
#
# The "Cached-Session-Policy" is the name of a
# policy which should be applied to the cached
# when using fast session resumption.
#
cache {
- #
# Enable it. The default is "no". Deleting the entire "cache"
# subsection also disables caching.
#
#
enable = no
- #
# Lifetime of the cached entries, in hours. The sessions will be
# deleted/invalidated after this time.
#
lifetime = 24 # hours
- #
# Internal "name" of the session cache. Used to
# distinguish which TLS context sessions belong to.
#
# set the "name" if you want to persist sessions (see
# below).
#
- #name = "EAP module"
+ # name = "EAP module"
- #
# Simple directory-based storage of sessions.
# Two files per session will be written, the SSL
# state and the cached VPs. This will persist session
#
# This feature REQUIRES "name" option be set above.
#
- #persist_dir = "${logdir}/tlscache"
+ # persist_dir = "${logdir}/tlscache"
}
- #
# As of version 2.1.10, client certificates can be
# validated via an external command. This allows
# dynamic CRLs or OCSP to be used.
# If you want to skip verify on OCSP success,
# uncomment this configuration item, and set it
# to "yes".
- # skip_if_ocsp_ok = no
+ #
+ # skip_if_ocsp_ok = no
# A temporary directory where the client
# certificates are stored. This directory
#
# You should also delete all of the files
# in the directory when the server starts.
- # tmpdir = /tmp/radiusd
+ #
+ # tmpdir = /tmp/radiusd
# The command used to verify the client cert.
# We recommend using the OpenSSL command-line
# in PEM format. This file is automatically
# deleted by the server when the command
# returns.
- # client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
+ #
+ # client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
}
- #
# OCSP Configuration
+ #
# Certificates can be verified against an OCSP
# Responder. This makes it possible to immediately
# revoke certificates without the distribution of
# new Certificate Revocation Lists (CRLs).
#
ocsp {
- #
# Enable it. The default is "no".
# Deleting the entire "ocsp" subsection
# also disables ocsp checking
#
enable = no
- #
# The OCSP Responder URL can be automatically
# extracted from the certificate in question.
# To override the OCSP Responder URL set
#
override_cert_url = yes
- #
# If the OCSP Responder address is not extracted from
# the certificate, the URL can be defined here.
#
url = "http://127.0.0.1/ocsp/"
- #
# If the OCSP Responder can not cope with nonce
# in the request, then it can be disabled here.
#
# to disable it in the query here.
# See http://technet.microsoft.com/en-us/library/cc770413%28WS.10%29.aspx
#
- # use_nonce = yes
+ # use_nonce = yes
- #
# Number of seconds before giving up waiting
# for OCSP response. 0 uses system default.
#
- # timeout = 0
+ # timeout = 0
- #
# Normally an error in querying the OCSP
# responder (no response from server, server did
# not understand the request, etc) will result in
# certificates to connect if the OCSP responder
# is not available. Use with caution.
#
- # softfail = no
+ # softfail = no
}
}
- ## EAP-TLS
+
+ # EAP-TLS
#
# As of Version 3.0, the TLS configuration for TLS-based
# EAP types is above in the "tls-config" section.
#
tls {
- # Point to the common TLS configuration
+ # Point to the common TLS configuration
+ #
tls = tls-common
- #
- # As part of checking a client certificate, the EAP-TLS
- # sets some attributes such as TLS-Client-Cert-Common-Name. This
- # virtual server has access to these attributes, and can
- # be used to accept or reject the request.
+ # As part of checking a client certificate, the EAP-TLS
+ # sets some attributes such as TLS-Client-Cert-Common-Name. This
+ # virtual server has access to these attributes, and can
+ # be used to accept or reject the request.
#
# virtual_server = check-eap-tls
}
- ## EAP-TTLS
+ # EAP-TTLS -- Tunneled TLS
#
# The TTLS module implements the EAP-TTLS protocol,
# which can be described as EAP inside of Diameter,
#
copy_request_to_tunnel = no
- #
# As of version 3.0.5, this configuration item
# is deprecated. Instead, you should use
#
- # update outer.session-state {
- # ...
- #
- # }
+ # update outer.session-state {
+ # ...
+ # }
#
# This will cache attributes for the final Access-Accept.
#
#
use_tunneled_reply = no
- #
# The inner tunneled request can be sent
# through a virtual server constructed
# specifically for this purpose.
#
# include_length = yes
+ # Unlike EAP-TLS, EAP-TTLS does not require a client
+ # certificate. However, you can require one by setting the
+ # following option. You can also override this option by
+ # setting
#
- # Unlike EAP-TLS, EAP-TTLS does not require a client
- # certificate. However, you can require one by setting the
- # following option. You can also override this option by
- # setting
+ # EAP-TLS-Require-Client-Cert = Yes
#
- # EAP-TLS-Require-Client-Cert = Yes
+ # in the control items for a request.
#
- # in the control items for a request.
- #
- # Note that the majority of supplicants do not support using a
- # client certificate with EAP-TTLS, so this option is unlikely
- # to be usable for most people.
+ # Note that the majority of supplicants do not support using a
+ # client certificate with EAP-TTLS, so this option is unlikely
+ # to be usable for most people.
#
# require_client_cert = yes
}
- ## EAP-PEAP
+ # EAP-PEAP
#
##################################################
# fail. See the "scripts/xpextensions" file for
# details, and the following page:
#
- # http://support.microsoft.com/kb/814394/en-us
- #
- # For additional Windows XP SP2 issues, see:
- #
- # http://support.microsoft.com/kb/885453/en-us
- #
+ # https://support.microsoft.com/en-us/help/814394/
#
# If is still doesn't work, and you're using Samba,
# you may be encountering a Samba bug. See:
#
##################################################
- #
# The tunneled EAP session needs a default EAP type
# which is separate from the one for the non-tunneled
# EAP module. Inside of the TLS/PEAP tunnel, we
#
copy_request_to_tunnel = no
- #
# As of version 3.0.5, this configuration item
# is deprecated. Instead, you should use
#
- # update outer.session-state {
- # ...
- #
- # }
+ # update outer.session-state {
+ # ...
+ # }
#
# This will cache attributes for the final Access-Accept.
#
#
# proxy_tunneled_request_as_eap = yes
- #
# The inner tunneled request can be sent
# through a virtual server constructed
# specifically for this purpose.
#
virtual_server = "inner-tunnel"
- # This option enables support for MS-SoH
- # see doc/SoH.txt for more info.
- # It is disabled by default.
+ # This option enables support for MS-SoH
+ # see doc/SoH.txt for more info.
+ # It is disabled by default.
#
# soh = yes
- #
- # The SoH reply will be turned into a request which
- # can be sent to a specific virtual server:
+ # The SoH reply will be turned into a request which
+ # can be sent to a specific virtual server:
#
# soh_virtual_server = "soh-server"
+ # Unlike EAP-TLS, PEAP does not require a client certificate.
+ # However, you can require one by setting the following
+ # option. You can also override this option by setting
#
- # Unlike EAP-TLS, PEAP does not require a client certificate.
- # However, you can require one by setting the following
- # option. You can also override this option by setting
+ # EAP-TLS-Require-Client-Cert = Yes
#
- # EAP-TLS-Require-Client-Cert = Yes
+ # in the control items for a request.
#
- # in the control items for a request.
- #
- # Note that the majority of supplicants do not support using a
- # client certificate with PEAP, so this option is unlikely to
- # be usable for most people.
+ # Note that the majority of supplicants do not support using a
+ # client certificate with PEAP, so this option is unlikely to
+ # be usable for most people.
#
# require_client_cert = yes
}
- #
- # This takes no configuration.
+
+ # EAP-MSCHAPv2
#
# Note that it is the EAP MS-CHAPv2 sub-module, not
# the main 'mschap' module.
# but *may* also cause other clients to stop
# working.
#
-# send_error = no
+ # send_error = no
# Server identifier to send back in the challenge.
# This should generally be the host name of the
# RADIUS server. Or, some information to uniquely
# identify it.
-# identity = "FreeRADIUS"
+ #
+ # identity = "FreeRADIUS"
}
- ## EAP-FAST
+
+ # EAP-FAST
#
# The FAST module implements the EAP-FAST protocol
#
-# fast {
- # Point to the common TLS configuration
+ #fast {
+ # Point to the common TLS configuration
#
-# tls = tls-common
+ # tls = tls-common
- #
# If 'cipher_list' is set here, it will over-ride the
# 'cipher_list' configuration from the 'tls-common'
# configuration. The EAP-FAST module has it's own
# Note - for OpenSSL 1.1.0 and above you may need
# to add ":@SECLEVEL=0"
#
-# cipher_list = "ALL:!EXPORT:!eNULL:!SSLv2"
+ # cipher_list = "ALL:!EXPORT:!eNULL:!SSLv2"
- # PAC lifetime in seconds (default: seven days)
+ # PAC lifetime in seconds (default: seven days)
#
-# pac_lifetime = 604800
+ # pac_lifetime = 604800
- # Authority ID of the server
+ # Authority ID of the server
#
- # if you are running a cluster of RADIUS servers, you should make
- # the value chosen here (and for "pac_opaque_key") the same on all
- # your RADIUS servers. This value should be unique to your
- # installation. We suggest using a domain name.
+ # If you are running a cluster of RADIUS servers, you should make
+ # the value chosen here (and for "pac_opaque_key") the same on all
+ # your RADIUS servers. This value should be unique to your
+ # installation. We suggest using a domain name.
#
-# authority_identity = "1234"
+ # authority_identity = "1234"
- # PAC Opaque encryption key (must be exactly 32 bytes in size)
+ # PAC Opaque encryption key (must be exactly 32 bytes in size)
#
- # This value MUST be secret, and MUST be generated using
- # a secure method, such as via 'openssl rand -hex 32'
+ # This value MUST be secret, and MUST be generated using
+ # a secure method, such as via 'openssl rand -hex 32'
#
-# pac_opaque_key = "0123456789abcdef0123456789ABCDEF"
+ # pac_opaque_key = "0123456789abcdef0123456789ABCDEF"
- # Same as for TTLS, PEAP, etc.
+ # Same as for TTLS, PEAP, etc.
#
-# virtual_server = inner-tunnel
-# }
+ # virtual_server = inner-tunnel
+ #}
}