]> git.ipfire.org Git - thirdparty/freeradius-server.git/commitdiff
Remove rlm_realm and rlm_preprocess
authorArran Cudbard-Bell <a.cudbardb@freeradius.org>
Sat, 1 Jul 2017 01:10:46 +0000 (21:10 -0400)
committerArran Cudbard-Bell <a.cudbardb@freeradius.org>
Sat, 1 Jul 2017 01:10:46 +0000 (21:10 -0400)
Both were duplicative of behaviour in unlang

37 files changed:
debian/freeradius-config.postinst
debian/freeradius.postinst
debian/freeradius.prerm
debian/patches/disable-dhcp-bydefault.diff
doc/configuration/acct_type.rst [deleted file]
doc/configuration/autz_type.rst [deleted file]
doc/configuration/configurable_failover.rst
doc/configuration/post_auth_type [deleted file]
doc/configuration/session_type [deleted file]
doc/configuration/simultaneous_use [deleted file]
doc/modules/ldap_howto.rst
doc/modules/rlm_soh
raddb/all.mk
raddb/mods-available/preprocess [deleted file]
raddb/mods-config/preprocess/hints [deleted file]
raddb/mods-config/preprocess/huntgroups [deleted file]
raddb/sites-available/abfab-tr-idp
raddb/sites-available/buffered-sql
raddb/sites-available/coa
raddb/sites-available/copy-acct-to-home-server
raddb/sites-available/decoupled-accounting
raddb/sites-available/default
raddb/sites-available/inner-tunnel
redhat/freeradius.spec
src/modules/rlm_mruby/rlm_mruby.c
src/modules/rlm_preprocess/README.md [deleted file]
src/modules/rlm_preprocess/all.mk [deleted file]
src/modules/rlm_preprocess/rlm_preprocess.c [deleted file]
src/modules/rlm_rest/rlm_rest.c
src/modules/stable
src/tests/modules/preprocess/all.mk [deleted file]
src/tests/modules/preprocess/hints [deleted file]
src/tests/modules/preprocess/huntgroups [deleted file]
src/tests/modules/preprocess/module.conf [deleted file]
src/tests/modules/preprocess/xlat.attrs [deleted file]
src/tests/modules/preprocess/xlat.unlang [deleted file]
src/tests/vectors/eapsim-03/radiusd-example.txt [deleted file]

index dcc03e7e4a18d29c590cf4c21f388c34490e096c..aa53a9614f67686e7a67b853d9326cd6d6b4ec63 100644 (file)
@@ -26,7 +26,7 @@ case "$1" in
           for mod in always attr_filter cache_eap chap \
               detail detail.log digest dynamic_clients eap \
               eap_inner echo exec expiration expr files linelog logintime \
-              mschap ntlm_auth pap passwd preprocess radutmp realm \
+              mschap ntlm_auth pap passwd radutmp realm \
               replicate soh sradutmp unix unpack utf8 ; do
             if test ! -h /etc/freeradius/mods-enabled/$mod && \
                test ! -e /etc/freeradius/mods-enabled/$mod; then
index 125842fd822837509693d738456d4b440f520714..ea911385264f18f62ac9c62079205b344a144767 100644 (file)
@@ -28,8 +28,6 @@ case "$1" in
 
           for file in /etc/freeradius/mods-config/files/pre-proxy \
             /etc/freeradius/mods-config/files/accounting \
-            /etc/freeradius/mods-config/preprocess/huntgroups \
-            /etc/freeradius/mods-config/preprocess/hints \
             /etc/freeradius/experimental.conf \
             /etc/freeradius/clients.conf
           do
index be61e55a6785cd9ac411d1fefb012fd54ced8618..e77702d2ec4f4815141c3d8fde06f6344fe551df 100644 (file)
@@ -11,8 +11,6 @@ case "$1" in
        fi
 
         for file in /etc/freeradius/mods-config/files/pre-proxy \
-          /etc/freeradius/mods-config/preprocess/huntgroups \
-          /etc/freeradius/mods-config/preprocess/hints \
           /etc/freeradius/mods-config/files/accounting \
           /etc/freeradius/experimental.conf \
           /etc/freeradius/clients.conf
index 071bc615c3c38f5a460b2a3bd104c9d4a315cfcb..642265844a95fb03d00a7436a623653903175dab 100644 (file)
@@ -5,10 +5,10 @@ Index: freeradius-server/raddb/all.mk
 +++ freeradius-server/raddb/all.mk
 @@ -8,7 +8,7 @@ DEFAULT_SITES :=       default inner-tunnel
  LOCAL_SITES :=                $(addprefix raddb/sites-enabled/,$(DEFAULT_SITES))
+
  DEFAULT_MODULES :=    always attr_filter cache_eap chap client \
 -                      detail detail.log digest dhcp eap \
 +                      detail detail.log digest eap \
                        eap_inner echo exec expiration expr files linelog logintime \
-                       mschap ntlm_auth pap passwd preprocess radutmp realm \
+                       mschap ntlm_auth pap passwd radutmp realm \
                        replicate soh sradutmp unix unpack utf8
diff --git a/doc/configuration/acct_type.rst b/doc/configuration/acct_type.rst
deleted file mode 100644 (file)
index 0c88824..0000000
+++ /dev/null
@@ -1,71 +0,0 @@
-Acct-Type
-=========
-
-FreeRADIUS supports the Acct-Type attribute to select between
-accounting methods based on arbitrary attribute/value pairs contained
-in an accounting packet. Its use follows the same general configuration
-syntax as Auth-Type and Autz-Type. The main difference in configuration
-between Acct-Type and Auth/Autz-Type lies in where the Acct-Type
-method is assigned. With Auth/Autz-Type, the method is typically
-assigned in the 'users' file. The 'users' file, naturally, is not
-processed during the handling of the process Accounting-Request {} section. However,
-part of the default files {} module is the 'acct_users' file, which
-serves the same purpose as the 'users' file, but applies to accounting
-packets.
-
-For example, a server administrator is responsible for handling the
-accounting data for two different realms, foo.com and bar.com, and
-wishes to use different instances of the SQL module for each. In
-addition, there is one RADIUS client sending accounting data that is
-to be logged only to a specific detail file. Everything else should
-use a third SQL instance.
-
-The acct_users file would look something like this::
-
-  DEFAULT Realm == "foo.com", Acct-Type := "SQLFOO"
-
-  DEFAULT Realm == "bar.com", Acct-Type := "SQLBAR"
-
-  DEFAULT Client-IP-Address == "10.0.0.1", Acct-Type := "OTHERNAS"
-
-And in radiusd.conf::
-
-  $INCLUDE  ${confdir}/sql0.conf # Instance named 'sql0'.
-  $INCLUDE  ${confdir}/sql1.conf # Instance named 'sql1'.
-  $INCLUDE  ${confdir}/sql2.conf # Instance named 'sql2'.
-
-  detail othernas {
-        filename = ${radacctdir}/10.0.0.1/detail-%Y%m%d
-  }
-
-  recv Accounting-Request {
-        suffix # Add the Realm A/V pair.
-        files  # Add the Acct-Type A/V pair based on the Realm A/V pair.
-  }
-
-  process Accounting-Request {
-
-        # If Acct-Type is SQLFOO use the 'sql1' instance of the SQL module.
-
-        Acct-Type SQLFOO {
-                sql1
-        }
-
-        # If Acct-Type is SQLBAR, use the 'sql2' instance of the SQL module.
-
-        Acct-Type SQLBAR {
-                sql2
-        }
-
-        # If Acct-Type is OTHERNAS, use the 'othernas' instance of the detail
-        # module
-
-        Acct-Type OTHERNAS {
-                othernas
-        }
-
-        # If we've made it this far, we haven't matched an Acct-Type, so use
-        # the sql0 instance.
-
-        sql0
-  }
diff --git a/doc/configuration/autz_type.rst b/doc/configuration/autz_type.rst
deleted file mode 100644 (file)
index 0b37968..0000000
+++ /dev/null
@@ -1,88 +0,0 @@
-Autz-Type
-=========
-
-Like Auth-Type for authentication method selection freeradius also
-supports the Autz-Type to select between authorization methods.  The only
-problem is that authorization is the first thing to be called when an
-authentication request is handled.  As a result we first have to call the
-authorize section without checking for Autz-Type. After that we check for
-Autz-Type and if it exists we call the corresponding subsection in the
-authorize section.  In other words the authorize section in radiusd.conf
-should look like this::
-
- authorize{
-         suffix
-         preprocess
-         # whatever other authorize modules here
-         Autz-Type Ldap{
-                 ldap
-         }
-         Autz-Type SQL{
-                 sql
-         }
-         files
- }
-
-What happens is that the first time the authorize section is examined the
-suffix, preprocess and files modules are executed.  If Autz-Type is set
-after that the server core checks for any matching Autz-Type subsection.
-If one is found it is called.  The users file should look something
-like this::
-
-  DEFAULT        Called-Station-Id == "123456789", Autz-Type := Ldap
-
-  DEFAULT Realm == "other.company.com", Autz-Type := SQL
-
-Autz-Type could also be used to select between multiple instances of
-a module (ie sql or ldap) which have been configured differently.  For
-example based on the user realm different ldap servers (belonging to
-different companies) could be queried.  If Auth-Type was also set then we
-could do both Authentication and Authorization with the user databases
-belonging to other companies.  In detail:
-
-radiusd.conf::
-
-  authenticate{
-         Auth-Type customer1{
-                 ldap1
-         }
-         Auth-Type customer2{
-                 ldap2
-         }
-  }
-
-  authorize{
-         preprocess
-         suffix
-         Autz-Type customer1{
-                 ldap1
-         }
-         Autz-Type customer2{
-                 ldap2
-         }
-         files
-  }
-
-The users file::
-
-  DEFAULT Realm == "customer1", Autz-Type := customer1, Auth-Type := customer1
-
-  DEFAULT Realm == "customer2", Autz-Type := customer2, Auth-Type := customer2
-
-
-Apart from Autz-Type the server also supports the use of
-Acct-Type, Session-Type and Post-Auth-Type for the corresponding sections.
-The corresponding section names in the radiusd.conf file are the same.  So for example:
-
-users file::
-
-  DEFAULT Called-Station-Id == "236473", Session-Type := SQL
-
-radiusd.conf::
-
- session {
-         radutmp
-         Session-Type SQL {
-                 sql
-         }
- }
index 10fca7461c8a1a0ff42b603f3e8b40f5ae3bd3c2..3e302c157b1de8a7bd0f25c0a14aed94be536eff 100644 (file)
@@ -8,14 +8,12 @@ Before configurable module failover, we had this kind of entry in
 
   #---
   recv Access-Request {
-    preprocess
     files
   }
   #---
 
 This entry instructed the ``authorize`` section to first process the
-request through the ``preprocess`` module, and if that returned success,
-to process it through ``files`` module.  If that sequence returned
+request through the ``files`` module.  If that sequence returned
 success, then the ``authorize`` stage itself would then return success.
 Processing was strictly linear and if one module failed, the whole
 section would fail immediately.
@@ -267,7 +265,7 @@ radiusd.conf are functions. There are two kinds of MODCALLABLEs: GROUPs and
 SINGLEs.
 
 A SINGLE is a reference to a module instance that was set up in the modules{}
-section of radiusd.conf, like ``preprocess`` or ``sql1``. When a SINGLE is
+section of radiusd.conf, like ``sql1``. When a SINGLE is
 called, the corresponding function in the rlm is invoked, and whichever
 RLM_MODULE_* it returns becomes the RESULT of the SINGLE.
 
diff --git a/doc/configuration/post_auth_type b/doc/configuration/post_auth_type
deleted file mode 100644 (file)
index 7492324..0000000
+++ /dev/null
@@ -1,44 +0,0 @@
-This is now called Post-Auth-Type, for consistency.
-
-O.INTRODUCTION
-
-  Post-Auth-Type is used to select between groupings of
-  modules in the post-auth stanza using arbitrary attributes.
-  It is functionally identical to Acct-Type, apart from
-  the name of the attribute and its dealing with rejected
-  requests.. This means that (unlike Autz-Type) the attribute
-  must be set before the stanza is run. Changes to
-  Post-Auth-Type during post-auth will have no effect.
-
-1.HOW IT WORKS
-
-  If a request has been rejected, the value of Post-Auth-Type
-  is overwritten with REJECT automatically, so anonymous
-  modules outside the REJECT substanza will not be run, only
-  modules within the appropriate substanza will be run.
-
-2.EXAMPLES
-
-  In the example below, when a request has been rejected, the
-  module my_ippool will not be run, only the module my_detail
-  will be run.
-  If the request is not rejected, the my_ippool module will be
-  run, but not the my_detail module
-
-  post-auth {
-      my_ippool
-      Post-Auth-Type REJECT {
-          my_detail
-      }
-  }
-
-  In the following example, 2 different sql modules are used
-  to store accepted requests and rejected requests.
-
-  post-auth {
-      my_sql_accept
-      Post-Auth-Type REJECT {
-          my_sql_reject
-      }
-  }
-
diff --git a/doc/configuration/session_type b/doc/configuration/session_type
deleted file mode 100644 (file)
index 9efcd7c..0000000
+++ /dev/null
@@ -1,10 +0,0 @@
-Session-Type is used to select between groupings of
-modules in the session stanza using arbitrary attributes.
-It is functionally identical to Acct-Type, apart from
-the name of the attribute. This means that (unlike
-Autz-Type) the attribute must be set before the stanza
-is run. Changes to Session-Type during session will
-have no effect.
-
-This allows Simultaneous-Use checking behaviour to be very flexible.
-
diff --git a/doc/configuration/simultaneous_use b/doc/configuration/simultaneous_use
deleted file mode 100644 (file)
index 5639738..0000000
+++ /dev/null
@@ -1,173 +0,0 @@
-
-       FreeRADIUS server and the Simultaneous-Use parameter.
-
-
-0. INTRODUCTION
-
-  Lots of people want to limit the number of times one user account can
-  login, usually to one. This is hard to do with the radius protocol;
-  the nature of the accounting stuff is such that the idea the radius server
-  has about the list of logged-in users might be different from the idea
-  the terminal server has about it.
-
-  However, most terminal servers have an alternative way to get a list
-  of logged-in users. Most support some way through telnet, some have
-  a finger-daemon builtin and a lot of them support SNMP. So if the
-  radius server thinks that someone is trying to login a second time,
-  it is possible to check on the terminal server itself if the first
-  login is indeed still active.  Only then access is denied for the
-  second login.
-
-
-1. PREREQUISITES
-
-  You need to have perl installed.
-
-  For SNMP checks, you have 2 options. You can use the `snmpget' program
-  from the cmu-snmp tools. You can probably get precompiled ones,
-  maybe even packaged for your system (Debian/Linux, Redhat/Linux, FreeBSD
-  ports collection etc). The source code is at
-  http://www.net.cmu.edu/projects/snmp/snmpapps/. The Linux-specific
-  version of this is at http://www.gaertner.de/snmp/
-
-  The other option is to install the SNMP_Session and BER modules that
-  for example the well known `mrtg' package uses. This is recommended.
-  In that case you need no external snmpget program, checkrad will
-  speak SNMP directly. See http://www.switch.ch/misc/leinen/snmp/perl/
-
-  The checkroutine for USR/3Com Total Control racks uses the Net::Telnet
-  module from CPAN, at least version 3.00. If you need that, obtain it from
-  your local CPAN mirror (or see http://www.perl.com/CPAN/). The checkrad.pl
-  perl script will autodetect if that module is installed.
-
-2. USAGE.
-
-  It works by adding the `check' parameter "Simultaneous-Use" to the entry
-  for a users or DEFAULT in /etc/raddb/users. It should be at least one;
-  it defines the maximum number of users logged in with the same account name.
-  For example:
-
-  #
-  # Simultaneous use restrictions.
-  #
-  DEFAULT Group == "staff", Simultaneous-Use := 4
-          Fall-Through = 1
-  DEFAULT Group == "business", Simultaneous-Use := 2
-          Fall-Through = 1
-  DEFAULT Simultaneous-Use := 1
-          Fall-Through = 1
-
-
-  NOTE!!! The "Simultaneous-Use" parameter is in the "check" A/V pairs,
-          and not in the Reply A/V pairs (it _is_ a check).
-
-  For SQL, after creating and populating your schema, you should
-  execute the following statement (for MySQL, others may vary):
-
-  INSERT INTO radgroupcheck (GroupName, Attribute, op, Value) values("dialup", "Simultaneous-Use", ":=", "1");
-
-  Once that is done, your users should be limited to only one login at a time.
-
-3. IMPLEMENTATION
-
-  The server keeps a list of logged-in users in the /var/log/radutmp file.
-  This is also called "the session database". When you execute "radwho",
-  all that radwho really does is list the entries in this file in a pretty
-  format. Only when someone tries to login who _already_ has an active
-  session according to the radutmp file, the server executes the perl
-  script /usr/local/sbin/checkrad (or /usr/sbin/checkrad, it checks for
-  the presence of both and in that order). This script queries the terminal
-  server to see if the user indeed already has an active session.
-
-  The script uses SNMP for Livingston Portmasters and Ciscos, finger for
-  Portslave, Computone and Ascend, and Net::Telnet for USR/3Com TC.
-
-  Since the script has been witten in perl, it's easy to adjust for
-  any type of terminal server. There are implementations in the script for
-  checks using SNMP, finger, and telnet, so it should be easy to add
-  your own check routine if your terminal server is not supported yet.
-
-  You can find the script in the file src/checkrad.pl.
-
-  You need to set the correct type in the file /etc/raddb/naslist so that
-  checkrad KNOWS how it should interrogate the terminal server. At this
-  time you can define the following types:
-
-  type        Vendor      Uses method     needs               Need naspasswd
-  ====        ======      ===========     =====               ==============
-  ascend      Lucent      SNMP            SNMP                No
-  bay         Nortel      finger          finger command      No
-  cisco       Cisco       SNMP            SNMP                Optional  [1]
-  computone   Computone   finger          finger command      No
-  cvx         Nortel      SNMP            SNMP                No
-  digitro     Digitro     rusers          rusers command      No
-  livingston  Livingston  SNMP            SNMP                No       [2]
-  max40xx     Lucent      finger          finger command      No
-  netserver   USR/3com    telnet          CPAN Net::Telnet    Yes
-  pathras     Cyclades    telnet          CPAN Net::Telnet    Yes
-  patton      Patton      SNMP            SNMP                No
-  portslave   ?           finger          finger command      No
-  pr3000      Cyclades    SNMP            snmpwalk command    No
-  pr4000      Cyclades    SNMP            snmpwalk command    No
-  tc          USR/3com    telnet          CPAN Net::Telnet    Yes
-  usrhyper    USR/3com    SNMP            SNMP                No       [3]
-  versanet    VersaNet    SNMP            SNMP                No
-
-  other       none        N/A             -                   No
-
-  [1] In naspasswd file: set username to SNMP, password is community.
-  [2] Needs at least ComOS 3.5, SNMP enabled.
-  [3] Set "Reported Port Density" to 256 (default)
-
-  "other" means "don't bother checking, I believe what radutmp says".
-  This really is not recommended, if a user has a "stuck" entry in the
-  session database she will not be able to login again - hence the
-  extra check that "checkrad" does.
-
-4. IF IT DOESN'T WORK
-
-  Note that you need to add the Simultaneous-Use parameter to the
-  check item (first line), not the reply item, using the ':=' operator.
-
-  You can edit the `checkrad' perl script and turn on debugging. Then
-  watch the debug file. The `radius.log' file also gives some hints.
-
-  You can also run the "checkrad" script manually, use the "-d"
-  switch to get debug output on standard output instead of in the log.
-
-  See also:
-
-       http://wrath.geoweb.ge/simult.html
-
-  which has a good discussion of the use of Simultaneous-Use.
-
-
-5. CAVEATS
-
-  This solution checks the radutmp file. This file is kept up-to-date from
-  the Accounting records the NAS sends. Since some NASes delay these records
-  for quite some time, it is possible to get a double login by logging in
-  twice at _exactly_ the same time (plus or minus the mentioned delay time),
-  since neither of the logins are registered yet.
-
-  The solution would be to create a small 1-minute cache of Authentication
-  records, that is also checked for double login attempts. Perhaps in the
-  next version.
-
-  When implementing this one thing was considered the most important: when
-  trying to detect double logins, we always try to err on the safe side. So
-  in rare cases, a double login is possible but we try never to limit access
-  for a legitimate login.
-
-6. PROBLEMS WITH DROPPED CONNECTIONS
-
-  Our PM3, with 2 ISDN-30 lines coming into it, had the habit of sometimes
-  dropping connections. In a few cases, the portmaster thought the session was
-  still alive so if the user tried to login again, he or she was denied access.
-  In our case, this problem was caused by a bad PRI line from the phone
-  company.
-
-  We tried to compensate this by setting the Idle-Timeout to 15 minutes. That
-  way, even if a user did get locked out the portmaster would clear the rogue
-  session within 15 minutes and the user could login again.
-
index 0065ce6a3f45e097ea59a3277483a84275096dbf..2b8c255fd4e43b898366a031987a01d46c83e061 100644 (file)
@@ -978,9 +978,8 @@ The first thing that is done is authorization of the user.  The radius server
 will process the modules in the order specified in the authorization section of
 radiusd.conf.  Currently, they are in the following order.
 
-1) preprocess
-2) files
-3) ldap
+1) files
+2) ldap
 
 The first module will be preprocess.  This will first check the huntgroups of
 the user coming in.  The huntgroups are defined in the file huntgroups and they
index 9a2fe02819df12c699e91039814eada7e2fcbe6a..fbda4296925d6b80bae272491f3454768c7c5fa5 100644 (file)
@@ -73,7 +73,6 @@ case presumably FreeRadius. To take advantage of this you will need to add
 the "soh" module to the "authorize" section of your virtual server, like so:
 
 server tsgateway {
-  preprocess
   soh
   if () {
     ... policy goes here
index ce8acbd6b20eb50ae7f53a63b7e033bf1c584f10..b65bdf2fef9b3c12732803537a56d5d5f9ffef8d 100644 (file)
@@ -10,7 +10,7 @@ LOCAL_SITES :=                $(addprefix raddb/sites-enabled/,$(DEFAULT_SITES))
 DEFAULT_MODULES :=     always attr_filter cache_eap chap client \
                        detail detail.log digest dhcpv4 eap \
                        eap_inner echo exec expiration expr files linelog logintime \
-                       mschap ntlm_auth pam pap passwd preprocess radutmp \
+                       mschap ntlm_auth pam pap passwd radutmp \
                        soh sradutmp unix unpack utf8
 
 LOCAL_MODULES :=       $(addprefix raddb/mods-enabled/,$(DEFAULT_MODULES))
diff --git a/raddb/mods-available/preprocess b/raddb/mods-available/preprocess
deleted file mode 100644 (file)
index 8baec79..0000000
+++ /dev/null
@@ -1,62 +0,0 @@
-# -*- text -*-
-#
-#  $Id$
-
-# Preprocess the incoming RADIUS request, before handing it off
-# to other modules.
-#
-#  This module processes the 'huntgroups' and 'hints' files.
-#  In addition, it re-writes some weird attributes created
-#  by some NAS, and converts the attributes into a form which
-#  is a little more standard.
-#
-preprocess {
-       # Search for files in a subdirectory of mods-config which
-       # matches this instance of the preprocess module.
-       moddir = ${modconfdir}/${.:instance}
-
-       huntgroups = ${moddir}/huntgroups
-       hints = ${moddir}/hints
-
-       # This hack changes Ascend's weird port numbering
-       # to standard 0-??? port numbers so that the "+" works
-       # for IP address assignments.
-       with_ascend_hack = no
-       ascend_channels_per_line = 23
-
-       # Windows NT machines often authenticate themselves as
-       # NT_DOMAIN\username
-       #
-       # If this is set to 'yes', then the NT_DOMAIN portion
-       # of the user-name is silently discarded.
-       #
-       # This configuration entry SHOULD NOT be used.
-       # See the "realms" module for a better way to handle
-       # NT domains.
-       with_ntdomain_hack = no
-
-       # Specialix Jetstream 8500 24 port access server.
-       #
-       # If the user name is 10 characters or longer, a "/"
-       # and the excess characters after the 10th are
-       # appended to the user name.
-       #
-       # If you're not running that NAS, you don't need
-       # this hack.
-       with_specialix_jetstream_hack = no
-
-       # Cisco (and Quintum in Cisco mode) sends it's VSA attributes
-       # with the attribute name *again* in the string, like:
-       #
-       #   H323-Attribute = "h323-attribute=value".
-       #
-       # If this configuration item is set to 'yes', then
-       # the redundant data in the the attribute text is stripped
-       # out.  The result is:
-       #
-       #  H323-Attribute = "value"
-       #
-       # If you're not running a Cisco or Quintum NAS, you don't
-       # need this hack.
-       with_cisco_vsa_hack = no
-}
diff --git a/raddb/mods-config/preprocess/hints b/raddb/mods-config/preprocess/hints
deleted file mode 100644 (file)
index f92ffb9..0000000
+++ /dev/null
@@ -1,77 +0,0 @@
-# hints
-#
-#      The hints file.   This file is used to match
-#      a request, and then add attributes to it.  This
-#      process allows a user to login as "bob.ppp" (for example),
-#      and receive a PPP connection, even if the NAS doesn't
-#      ask for PPP.  The "hints" file is used to match the
-#      ".ppp" portion of the username, and to add a set of
-#      "user requested PPP" attributes to the request.
-#
-#      Matching can take place with the the Prefix and Suffix
-#      attributes, just like in the "users" file.
-#      These attributes operate ONLY on the username, though.
-#
-#      Note that the attributes that are set for each
-#      entry are _NOT_ passed back to the terminal server.
-#      Instead they are added to the information that has
-#      been _SENT_ by the terminal server.
-#
-#      This extra information can be used in the users file to
-#      match on. Usually this is done in the DEFAULT entries,
-#      of which there can be more than one.
-#
-#      In addition a matching entry can transform a username
-#      for authentication purposes if the "Strip-User-Name"
-#      variable is set to Yes in an entry (default is Yes).
-#
-#      A special non-protocol name-value pair called "Hint"
-#      can be set to match on in the "users" file.
-#
-#      The following is how most ISPs want to set this up.
-#
-# Version:     $Id$
-#
-
-
-DEFAULT        Suffix == ".ppp", Strip-User-Name = Yes
-       Hint = "PPP",
-       Service-Type = Framed-User,
-       Framed-Protocol = PPP
-
-DEFAULT        Suffix == ".slip", Strip-User-Name = Yes
-       Hint = "SLIP",
-       Service-Type = Framed-User,
-       Framed-Protocol = SLIP
-
-DEFAULT        Suffix == ".cslip", Strip-User-Name = Yes
-       Hint = "CSLIP",
-       Service-Type = Framed-User,
-       Framed-Protocol = SLIP,
-       Framed-Compression = Van-Jacobson-TCP-IP
-
-######################################################################
-#
-#      These entries are old, and commented out by default.
-#      They confuse too many people when "Peter" logs in, and the
-#      server thinks that the user "eter" is asking for PPP.
-#
-#DEFAULT       Prefix == "U", Strip-User-Name = No
-#      Hint = "UUCP"
-
-#DEFAULT       Prefix == "P", Strip-User-Name = Yes
-#      Hint = "PPP",
-#      Service-Type = Framed-User,
-#      Framed-Protocol = PPP
-
-#DEFAULT       Prefix == "S", Strip-User-Name = Yes
-#      Hint = "SLIP",
-#      Service-Type = Framed-User,
-#      Framed-Protocol = SLIP
-
-#DEFAULT       Prefix == "C", Strip-User-Name = Yes
-#      Hint = "CSLIP",
-#      Service-Type = Framed-User,
-#      Framed-Protocol = SLIP,
-#      Framed-Compression = Van-Jacobson-TCP-IP
-
diff --git a/raddb/mods-config/preprocess/huntgroups b/raddb/mods-config/preprocess/huntgroups
deleted file mode 100644 (file)
index a937c8b..0000000
+++ /dev/null
@@ -1,46 +0,0 @@
-#
-# huntgroups   This file defines the `huntgroups' that you have. A
-#              huntgroup is defined by specifying the IP address of
-#              the NAS and possibly a port range. Port can be identified
-#              as just one port, or a range (from-to), and multiple ports
-#              or ranges of ports must be separated by a comma. For
-#              example: 1,2,3-8
-#
-#              Matching is done while RADIUS scans the user file; if it
-#              includes the selection criterium "Huntgroup-Name == XXX"
-#              the huntgroup is looked up in this file to see if it
-#              matches. There can be multiple definitions of the same
-#              huntgroup; the first one that matches will be used.
-#
-#              This file can also be used to define restricted access
-#              to certain huntgroups. The second and following lines
-#              define the access restrictions (based on username and
-#              UNIX usergroup) for the huntgroup.
-#
-
-#
-# Our POP in Alphen a/d Rijn has 3 terminal servers. Create a Huntgroup-Name
-# called Alphen that matches on all three terminal servers.
-#
-#alphen                NAS-IP-Address == 192.0.2.5
-#alphen                NAS-IP-Address == 192.0.2.6
-#alphen                NAS-IP-Address == 192.0.2.7
-
-#
-# The POP in Delft consists of only one terminal server.
-#
-#delft         NAS-IP-Address == 198.51.100.5
-
-#
-# Ports 0-7 on the first terminal server in Alphen are connected to
-# a huntgroup that is for business users only. Note that only one
-# of the username or groupname has to match to get access (OR/OR).
-#
-# Note that this huntgroup is a subset of the "alphen" huntgroup.
-#
-#business      NAS-IP-Address == 198.51.100.5, NAS-Port-Id == 0-7
-#              User-Name = rogerl,
-#              User-Name = henks,
-#              Group = business,
-#              Group = staff
-
index 0ff154a3863987702d0702f52d6200b164686274..91b816580a34a0244166f745c6545d1385a248e8 100644 (file)
@@ -15,7 +15,6 @@ recv Access-Request {
         psk_authorize
        abfab_client_check
        filter_username
-       preprocess
 
        #  If you intend to use CUI and you require that the Operator-Name
        #  be set for CUI generation and you want to generate CUI also
@@ -29,10 +28,6 @@ recv Access-Request {
        #  cui below and set "add_cui = yes" for these clients in clients.conf
 #      cui
 
-       suffix {
-               updated = 1
-               noop = reject
-        }
        eap {
                ok = return
        }
index 411b6ba74944932b7cf269ce7b029318579379d1..8736e91df240a0c4e920576a77604520697069ef 100644 (file)
@@ -127,8 +127,6 @@ server buffered-sql {
        #  Pre-accounting.  Decide which accounting type to use.
        #
        recv Accounting-Request {
-               preprocess
-
                #
                #  Ensure that we have a semi-unique identifier for every
                #  request, and many NAS boxes are broken.
index c10f88e81bf01b8e9b066105b037df21d444eb92..3cd80c9d334f053a8633a6615cd89ed54ae555e9 100644 (file)
@@ -21,17 +21,6 @@ server coa {
        #  recv-coa section.  This applies to *both* CoA-Request and
        #  Disconnect-Request packets.
        recv-coa {
-               #  CoA && Disconnect packets can be proxied in the same
-               #  way as authentication or accounting packets.
-               #  Just set Proxy-To-Realm, or Home-Server-Pool, and the
-               #  packets will be proxied.
-
-               #  Do proxying based on realms here.  You don't need
-               #  "IPASS" or "ntdomain", as the proxying is based on
-               #  the Operator-Name attribute.  It contains the realm,
-               #  and ONLY the realm (prefixed by a '1')
-               suffix
-
                #  Insert your own policies here.
                ok
        }
index fe4cb7ea0aa806db00c2135f350ce6840b0623d7..821a4a04c28a188e8e554f9f9aa46ec6bcd0dada 100644 (file)
@@ -114,21 +114,6 @@ server copy-acct-to-home-server {
        #  Pre-accounting.  Decide which accounting type to use.
        #
        recv Accounting-Request {
-               preprocess
-
-               # Since we're just proxying, we don't need acct_unique.
-
-               #
-               #  Look for IPASS-style 'realm/', and if not found, look for
-               #  '@realm', and decide whether or not to proxy, based on
-               #  that.
-               #
-               #  Accounting requests are generally proxied to the same
-               #  home server as authentication requests.
-       #       IPASS
-               suffix
-       #       ntdomain
-
                #
                #  Read the 'acct_users' file.  This isn't always
                #  necessary, and can be deleted if you do not use it.
index f13fd0e94b724107e2609578403b49a146a12158..4122dc67d7f1f830be02a1fa74d5ff8a4674c60c 100644 (file)
@@ -55,24 +55,11 @@ server read-detail.example.com {
 #  Pre-accounting.  Decide which accounting type to use.
 #
 recv Accounting-Request {
-       preprocess
-
        #
        #  Ensure that we have a semi-unique identifier for every
        #  request, and many NAS boxes are broken.
        acct_unique
 
-       #
-       #  Look for IPASS-style 'realm/', and if not found, look for
-       #  '@realm', and decide whether or not to proxy, based on
-       #  that.
-       #
-       #  Accounting requests are generally proxied to the same
-       #  home server as authentication requests.
-#      IPASS
-       suffix
-#      ntdomain
-
        #
        #  Read the 'acct_users' file
        files
index 1ef92da4e97beff4fef273b6f17d22ddca94b238..232d5a92df129b5e8ebf05a745888056b6ba8f9d 100644 (file)
@@ -77,10 +77,7 @@ server default {
 #  virtual server.
 #
 #  The order of the realm modules will determine the order that
-#  we try to find a matching realm.
-#
-#  Make *sure* that 'preprocess' comes before any realm if you
-#  need to setup hints for the remote radius server
+#  we try to find a matching realm
 recv Access-Request {
        #
        #  Take a User-Name, and perform some checks on it, for spaces and other
@@ -101,15 +98,6 @@ recv Access-Request {
        #
 #      filter_password
 
-       #
-       #  The preprocess module takes care of sanitizing some bizarre
-       #  attributes in the request, and turning them into attributes
-       #  which are more standard.
-       #
-       #  It takes care of processing the 'raddb/mods-config/preprocess/hints' 
-       #  and the 'raddb/mods-config/preprocess/huntgroups' files.
-       preprocess
-
        #  If you intend to use CUI and you require that the Operator-Name
        #  be set for CUI generation and you want to generate CUI also
        #  for your local clients then uncomment the operator-name
@@ -494,8 +482,6 @@ send Access-Reject {
 #  Pre-accounting.  Decide which accounting type to use.
 #
 recv Accounting-Request {
-       preprocess
-
        #
        #  Merge Acct-[Input|Output]-Gigawords and Acct-[Input-Output]-Octets
        #  into a single 64bit counter Acct-[Input|Output]-Octets64.
index 84e9ae6ef8e964f76fdf7e386c2d42db2cd7a705..cca3f8828b286e18a3e4c7846a2d2162531a5fe9 100644 (file)
@@ -42,14 +42,9 @@ listen {
        }
 }
 
-#  Authorization. First preprocess (hints and huntgroups files),
-#  then realms, and finally look in the "users" file.
 #
-#  The order of the realm modules will determine the order that
-#  we try to find a matching realm.
+#  Authorization
 #
-#  Make *sure* that 'preprocess' comes before any realm if you
-#  need to setup hints for the remote radius server
 recv Access-Request {
        #
        #  Take a User-Name, and perform some checks on it, for spaces and other
index ac4047d1c5a87e5c7461d58a445f3f1462c923db..940fbfff698784b4cb798791eec7013ea1709b39 100644 (file)
@@ -678,7 +678,6 @@ fi
 %{_libdir}/freeradius/rlm_pam.so
 %{_libdir}/freeradius/rlm_pap.so
 %{_libdir}/freeradius/rlm_passwd.so
-%{_libdir}/freeradius/rlm_preprocess.so
 %{_libdir}/freeradius/rlm_radius_client.so
 %{_libdir}/freeradius/rlm_radutmp.so
 %{_libdir}/freeradius/rlm_soh.so
@@ -704,8 +703,6 @@ fi
 #%attr(640,root,radiusd) %config(noreplace) /etc/raddb/filter/*
 %attr(644,root,radiusd) %config(noreplace) /etc/raddb/dictionary
 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/clients.conf
-%config(noreplace) /etc/raddb/hints
-%config(noreplace) /etc/raddb/huntgroups
 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/panic.gdb
 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/README.md
 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/radiusd.conf
@@ -735,8 +732,6 @@ fi
 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/mods-config/lua/*
 %dir %attr(750,root,radiusd) /etc/raddb/mods-config/perl
 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/mods-config/perl/*
-%dir %attr(750,root,radiusd) /etc/raddb/mods-config/preprocess
-%attr(640,root,radiusd) %config(noreplace) /etc/raddb/mods-config/preprocess/*
 %dir %attr(750,root,radiusd) /etc/raddb/mods-config/python
 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/mods-config/python/*
 %dir %attr(750,root,radiusd) /etc/raddb/mods-enabled
index 16ce85ae739878848beead6135c3c612fd04f83b..a95868bda3e2e80d350b4da03cab8b9773e55762 100644 (file)
@@ -484,7 +484,6 @@ RLM_MRUBY_FUNC(post_auth)
 #ifdef WITH_ACCOUNTING
 RLM_MRUBY_FUNC(preacct)
 RLM_MRUBY_FUNC(accounting)
-RLM_MRUBY_FUNC(session)
 #endif
 #ifdef WITH_PROXY
 RLM_MRUBY_FUNC(pre_proxy)
@@ -534,7 +533,6 @@ rad_module_t rlm_mruby = {
 #ifdef WITH_ACCOUNTING
                [MOD_PREACCT]           = mod_preacct,
                [MOD_ACCOUNTING]        = mod_accounting,
-               [MOD_SESSION]           = mod_session,
 #endif
 #ifdef WITH_PROXY
                [MOD_PRE_PROXY]         = mod_pre_proxy,
diff --git a/src/modules/rlm_preprocess/README.md b/src/modules/rlm_preprocess/README.md
deleted file mode 100644 (file)
index c3e2441..0000000
+++ /dev/null
@@ -1,14 +0,0 @@
-# rlm_preprocess
-## Metadata
-<dl>
-  <dt>category</dt><dd>policy</dd>
-</dl>
-
-## Summary
-Preprocesses the incoming request before handing it off to other modules.
-
-Supports the legacy huntgroups and hints files. In addition, it re-writes some unusual attributes created by some
-NASes and converts the attributes into a form that is a little more standard.
-
-This module is mostly deprecated in favour of unlang, but is kept in current distributions to provide backwards
-compatibility.
diff --git a/src/modules/rlm_preprocess/all.mk b/src/modules/rlm_preprocess/all.mk
deleted file mode 100644 (file)
index 6b18994..0000000
+++ /dev/null
@@ -1,2 +0,0 @@
-TARGET         := rlm_preprocess.a
-SOURCES                := rlm_preprocess.c
diff --git a/src/modules/rlm_preprocess/rlm_preprocess.c b/src/modules/rlm_preprocess/rlm_preprocess.c
deleted file mode 100644 (file)
index 0eebe75..0000000
+++ /dev/null
@@ -1,697 +0,0 @@
-/*
- *   This program is is free software; you can redistribute it and/or modify
- *   it under the terms of the GNU General Public License as published by
- *   the Free Software Foundation; either version 2 of the License, or (at
- *   your option) any later version.
- *
- *   This program is distributed in the hope that it will be useful,
- *   but WITHOUT ANY WARRANTY; without even the implied warranty of
- *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
- *   GNU General Public License for more details.
- *
- *   You should have received a copy of the GNU General Public License
- *   along with this program; if not, write to the Free Software
- *   Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
- */
-
-/**
- * $Id$
- * @file rlm_preprocess.c
- * @brief Fixes up requests, and processes huntgroups/hints files.
- *
- * @copyright 2000,2006  The FreeRADIUS server project
- * @copyright 2000  Alan DeKok <aland@ox.org>
- */
-RCSID("$Id$")
-
-#define LOG_PREFIX "rlm_preprocess - "
-
-#include <freeradius-devel/radiusd.h>
-#include <freeradius-devel/modules.h>
-#include <freeradius-devel/rad_assert.h>
-
-#include <ctype.h>
-
-typedef struct rlm_preprocess_t {
-       char const      *huntgroup_file;
-       char const      *hints_file;
-       PAIR_LIST       *huntgroups;
-       PAIR_LIST       *hints;
-       bool            with_ascend_hack;
-       uint32_t        ascend_channels_per_line;
-       bool            with_ntdomain_hack;
-       bool            with_specialix_jetstream_hack;
-       bool            with_cisco_vsa_hack;
-       bool            with_alvarion_vsa_hack;
-} rlm_preprocess_t;
-
-static const CONF_PARSER module_config[] = {
-       { FR_CONF_OFFSET("huntgroups", FR_TYPE_FILE_INPUT, rlm_preprocess_t, huntgroup_file) },
-       { FR_CONF_OFFSET("hints", FR_TYPE_FILE_INPUT, rlm_preprocess_t, hints_file) },
-       { FR_CONF_OFFSET("with_ascend_hack", FR_TYPE_BOOL, rlm_preprocess_t, with_ascend_hack), .dflt = "no" },
-       { FR_CONF_OFFSET("ascend_channels_per_line", FR_TYPE_UINT32, rlm_preprocess_t, ascend_channels_per_line), .dflt = "23" },
-
-       { FR_CONF_OFFSET("with_ntdomain_hack", FR_TYPE_BOOL, rlm_preprocess_t, with_ntdomain_hack), .dflt = "no" },
-       { FR_CONF_OFFSET("with_specialix_jetstream_hack", FR_TYPE_BOOL, rlm_preprocess_t, with_specialix_jetstream_hack), .dflt = "no" },
-       { FR_CONF_OFFSET("with_cisco_vsa_hack", FR_TYPE_BOOL, rlm_preprocess_t, with_cisco_vsa_hack), .dflt = "no" },
-       { FR_CONF_OFFSET("with_alvarion_vsa_hack", FR_TYPE_BOOL, rlm_preprocess_t, with_alvarion_vsa_hack), .dflt = "no" },
-
-       CONF_PARSER_TERMINATOR
-};
-
-/*
- *     See if a VALUE_PAIR list contains Fall-Through = Yes
- */
-static int fall_through(VALUE_PAIR *vp)
-{
-       VALUE_PAIR *tmp;
-       tmp = fr_pair_find_by_num(vp, 0, FR_FALL_THROUGH, TAG_ANY);
-
-       return tmp ? tmp->vp_uint32 : 0;
-}
-
-/*
- *     This hack changes Ascend's weird port numberings
- *     to standard 0-??? port numbers so that the "+" works
- *     for IP address assignments.
- */
-static void ascend_nasport_hack(VALUE_PAIR *nas_port, int channels_per_line)
-{
-       int service;
-       int line;
-       int channel;
-
-       if (!nas_port) {
-               return;
-       }
-
-       if (nas_port->vp_uint32 > 9999) {
-               service = nas_port->vp_uint32/10000; /* 1=digital 2=analog */
-               line = (nas_port->vp_uint32 - (10000 * service)) / 100;
-               channel = nas_port->vp_uint32 - ((10000 * service) + (100 * line));
-               nas_port->vp_uint32 = (channel - 1) + ((line - 1) * channels_per_line);
-       }
-}
-
-/*
- *     This hack strips out Cisco's VSA duplicities in lines
- *     (Cisco not implemented VSA's in standard way.
- *
- *     Cisco sends it's VSA attributes with the attribute name *again*
- *     in the string, like:  H323-Attribute = "h323-attribute=value".
- *     This sort of behaviour is nonsense.
- */
-static void cisco_vsa_hack(REQUEST *request)
-{
-       int             vendorcode;
-       char            *ptr;
-       char            newattr[FR_MAX_STRING_LEN];
-       VALUE_PAIR      *vp;
-       vp_cursor_t     cursor;
-       for (vp = fr_pair_cursor_init(&cursor, &request->packet->vps);
-            vp;
-            vp = fr_pair_cursor_next(&cursor)) {
-               vendorcode = vp->da->vendor;
-               if (!((vendorcode == 9) || (vendorcode == 6618))) {
-                       continue; /* not a Cisco or Quintum VSA, continue */
-               }
-
-               if (vp->vp_type != FR_TYPE_STRING) continue;
-
-               /*
-                *  No weird packing.  Ignore it.
-                */
-               ptr = strchr(vp->vp_strvalue, '='); /* find an '=' */
-               if (!ptr) {
-                       continue;
-               }
-
-               /*
-                *      Cisco-AVPair's get packed as:
-                *
-                *      Cisco-AVPair = "h323-foo-bar = baz"
-                *      Cisco-AVPair = "h323-foo-bar=baz"
-                *
-                *      which makes sense only if you're a lunatic.
-                *      This code looks for the attribute named inside
-                *      of the string, and if it exists, adds it as a new
-                *      attribute.
-                */
-               if (vp->da->attr == 1) {
-                       char const *p;
-
-                       p = vp->vp_strvalue;
-                       gettoken(&p, newattr, sizeof(newattr), false);
-
-                       if (fr_dict_attr_by_name(NULL, newattr) != NULL) {
-                               pair_make_request(newattr, ptr + 1, T_OP_EQ);
-                       }
-               } else {        /* h322-foo-bar = "h323-foo-bar = baz" */
-                       /*
-                        *      We strip out the duplicity from the
-                        *      value field, we use only the value on
-                        *      the right side of the '=' character.
-                        */
-                       fr_pair_value_strcpy(vp, ptr + 1);
-               }
-       }
-}
-
-
-/*
- *     Don't even ask what this is doing...
- */
-static void alvarion_vsa_hack(VALUE_PAIR *vp)
-{
-       int number = 1;
-       vp_cursor_t cursor;
-
-       for (vp = fr_pair_cursor_init(&cursor, &vp);
-            vp;
-            vp = fr_pair_cursor_next(&cursor)) {
-               fr_dict_attr_t const *da;
-
-               if (vp->da->vendor != 12394) continue;
-
-               if (vp->vp_type != FR_TYPE_STRING) continue;
-
-               da = fr_dict_attr_by_num(NULL, 12394, number);
-               if (!da) continue;
-
-               vp->da = da;
-
-               number++;
-       }
-}
-
-/*
- *     Cablelabs magic, taken from:
- *
- * http://www.cablelabs.com/packetcable/downloads/specs/PKT-SP-EM-I12-05812.pdf
- *
- *     Sample data is:
- *
- *     0x0001d2d2026d30310000000000003030
- *       3130303030000e812333000100033031
- *       00000000000030303130303030000000
- *       00063230313230313331303630323231
- *       2e3633390000000081000500
- */
-
-typedef struct cl_timezone_t {
-       uint8_t         dst;
-       uint8_t         sign;
-       uint8_t         hh[2];
-       uint8_t         mm[2];
-       uint8_t         ss[2];
-} cl_timezone_t;
-
-typedef struct cl_bcid_t {
-       uint32_t        timestamp;
-       uint8_t         element_id[8];
-       cl_timezone_t   timezone;
-       uint32_t        event_counter;
-} cl_bcid_t;
-
-typedef struct cl_em_hdr_t {
-       uint16_t        version;
-       cl_bcid_t       bcid;
-       uint16_t        message_type;
-       uint16_t        element_type;
-       uint8_t         element_id[8];
-       cl_timezone_t   time_zone;
-       uint32_t        sequence_number;
-       uint8_t         event_time[18];
-       uint8_t         status[4];
-       uint8_t         priority;
-       uint16_t        attr_count; /* of normal Cablelabs VSAs */
-       uint8_t         event_object;
-} cl_em_hdr_t;
-
-/*
- *     Mangle username if needed, IN PLACE.
- */
-static void rad_mangle(rlm_preprocess_t const *inst, REQUEST *request)
-{
-       int             num_proxy_state;
-       VALUE_PAIR      *namepair;
-       VALUE_PAIR      *request_pairs;
-       VALUE_PAIR      *tmp;
-       vp_cursor_t     cursor;
-
-       /*
-        *      Get the username from the request
-        *      If it isn't there, then we can't mangle the request.
-        */
-       request_pairs = request->packet->vps;
-       namepair = fr_pair_find_by_num(request_pairs, 0, FR_USER_NAME, TAG_ANY);
-       if (!namepair || (namepair->vp_length == 0)) {
-               return;
-       }
-
-       if (inst->with_ntdomain_hack) {
-               char *ptr;
-               char newname[FR_MAX_STRING_LEN];
-
-               /*
-                *      Windows NT machines often authenticate themselves as
-                *      NT_DOMAIN\username. Try to be smart about this.
-                *
-                *      FIXME: should we handle this as a REALM ?
-                */
-               if ((ptr = strchr(namepair->vp_strvalue, '\\')) != NULL) {
-                       strlcpy(newname, ptr + 1, sizeof(newname));
-                       /* Same size */
-                       fr_pair_value_strcpy(namepair, newname);
-               }
-       }
-
-       if (inst->with_specialix_jetstream_hack) {
-               /*
-                *      Specialix Jetstream 8500 24 port access server.
-                *      If the user name is 10 characters or longer, a "/"
-                *      and the excess characters after the 10th are
-                *      appended to the user name.
-                *
-                *      Reported by Lucas Heise <root@laonet.net>
-                */
-               if ((strlen(namepair->vp_strvalue) > 10) &&
-                   (namepair->vp_strvalue[10] == '/')) {
-                       fr_pair_value_strcpy(namepair, namepair->vp_strvalue + 11);
-               }
-       }
-
-       /*
-        *      Small check: if Framed-Protocol present but Service-Type
-        *      is missing, add Service-Type = Framed-User.
-        */
-       if (fr_pair_find_by_num(request_pairs, 0, FR_FRAMED_PROTOCOL, TAG_ANY) != NULL &&
-           fr_pair_find_by_num(request_pairs, 0, FR_SERVICE_TYPE, TAG_ANY) == NULL) {
-               tmp = radius_pair_create(request->packet, &request->packet->vps, FR_SERVICE_TYPE, 0);
-               tmp->vp_uint32 = FR_FRAMED_USER;
-       }
-
-       num_proxy_state = 0;
-       for (tmp = fr_pair_cursor_init(&cursor, &request->packet->vps);
-            tmp;
-            tmp = fr_pair_cursor_next(&cursor)) {
-               if (tmp->da->vendor != 0) {
-                       continue;
-               }
-
-               if (tmp->da->attr != FR_PROXY_STATE) {
-                       continue;
-               }
-
-               num_proxy_state++;
-       }
-
-       if (num_proxy_state > 10) {
-               RWDEBUG("There are more than 10 Proxy-State attributes in the request");
-               RWDEBUG("You have likely configured an infinite proxy loop");
-       }
-}
-
-/*
- *     Compare the request with the "reply" part in the
- *     huntgroup, which normally only contains username or group.
- *     At least one of the "reply" items has to match.
- */
-static int hunt_paircmp(REQUEST *req, VALUE_PAIR *request, VALUE_PAIR *check)
-{
-       vp_cursor_t     cursor;
-       VALUE_PAIR      *check_item;
-       VALUE_PAIR      *tmp;
-       int             result = -1;
-
-       if (!check) return 0;
-
-       for (check_item = fr_pair_cursor_init(&cursor, &check);
-            check_item && (result != 0);
-            check_item = fr_pair_cursor_next(&cursor)) {
-               /* FIXME: fr_pair_list_copy should be removed once VALUE_PAIRs are no longer in linked lists */
-               tmp = fr_pair_copy(request, check_item);
-               tmp->op = check_item->op;
-               result = paircompare(req, request, tmp, NULL);
-               fr_pair_list_free(&tmp);
-       }
-
-       return result;
-}
-
-
-/*
- *     Add hints to the info sent by the terminal server
- *     based on the pattern of the username, and other attributes.
- */
-static int hints_setup(PAIR_LIST *hints, REQUEST *request)
-{
-       char const      *name;
-       VALUE_PAIR      *add;
-       VALUE_PAIR      *tmp;
-       PAIR_LIST       *i;
-       VALUE_PAIR      *request_pairs;
-       int             updated = 0, ft;
-
-       request_pairs = request->packet->vps;
-
-       if (!hints || !request_pairs)
-               return RLM_MODULE_NOOP;
-
-       /*
-        *      Check for valid input, zero length names not permitted
-        */
-       name = (tmp = fr_pair_find_by_num(request_pairs, 0, FR_USER_NAME, TAG_ANY)) ?
-               tmp->vp_strvalue : NULL;
-       if (!name || name[0] == 0) {
-               /*
-                *      No name, nothing to do.
-                */
-               return RLM_MODULE_NOOP;
-       }
-
-       for (i = hints; i; i = i->next) {
-               /*
-                *      Use "paircompare", which is a little more general...
-                */
-               if (((strcmp(i->name, "DEFAULT") == 0) || (strcmp(i->name, name) == 0)) &&
-                   (paircompare(request, request_pairs, i->check, NULL) == 0)) {
-                       RDEBUG2("hints: Matched %s at %d", i->name, i->lineno);
-                       /*
-                        *      Now add all attributes to the request list,
-                        *      except FR_STRIP_USER_NAME and FR_FALL_THROUGH
-                        *      and xlat them.
-                        */
-                       add = fr_pair_list_copy(request->packet, i->reply);
-                       ft = fall_through(add);
-
-                       fr_pair_delete_by_num(&add, 0, FR_STRIP_USER_NAME, TAG_ANY);
-                       fr_pair_delete_by_num(&add, 0, FR_FALL_THROUGH, TAG_ANY);
-                       radius_pairmove(request, &request->packet->vps, add, true);
-
-                       updated = 1;
-                       if (!ft) {
-                               break;
-                       }
-               }
-       }
-
-       if (updated == 0) {
-               return RLM_MODULE_NOOP;
-       }
-
-       return RLM_MODULE_UPDATED;
-}
-
-/*
- *     See if we have access to the huntgroup.
- */
-static int huntgroup_access(REQUEST *request, PAIR_LIST *huntgroups)
-{
-       PAIR_LIST       *i;
-       int             r = RLM_MODULE_OK;
-       VALUE_PAIR      *request_pairs = request->packet->vps;
-
-       /*
-        *      We're not controlling access by huntgroups:
-        *      Allow them in.
-        */
-       if (!huntgroups) {
-               return RLM_MODULE_OK;
-       }
-
-       for (i = huntgroups; i; i = i->next) {
-               /*
-                *      See if this entry matches.
-                */
-               if (paircompare(request, request_pairs, i->check, NULL) != 0) {
-                       continue;
-               }
-
-               /*
-                *      Now check for access.
-                */
-               r = RLM_MODULE_REJECT;
-               if (hunt_paircmp(request, request_pairs, i->reply) == 0) {
-                       VALUE_PAIR *vp;
-
-                       /*
-                        *  We've matched the huntgroup, so add it in
-                        *  to the list of request pairs.
-                        */
-                       vp = fr_pair_find_by_num(request_pairs, 0, FR_HUNTGROUP_NAME, TAG_ANY);
-                       if (!vp) {
-                               vp = radius_pair_create(request->packet, &request->packet->vps, FR_HUNTGROUP_NAME, 0);
-                               fr_pair_value_strcpy(vp, i->name);
-                       }
-                       r = RLM_MODULE_OK;
-               }
-               break;
-       }
-
-       return r;
-}
-
-/*
- *     If the NAS wasn't smart enought to add a NAS-IP-Address
- *     to the request, then add it ourselves.
- */
-static int add_nas_attr(REQUEST *request)
-{
-       VALUE_PAIR *nas;
-
-       switch (request->packet->src_ipaddr.af) {
-       case AF_INET:
-               nas = fr_pair_find_by_num(request->packet->vps, 0, FR_NAS_IP_ADDRESS, TAG_ANY);
-               if (!nas) {
-                       nas = radius_pair_create(request->packet, &request->packet->vps, FR_NAS_IP_ADDRESS, 0);
-                       nas->vp_ip = request->packet->src_ipaddr;
-               }
-               break;
-
-       case AF_INET6:
-               nas = fr_pair_find_by_num(request->packet->vps, 0, FR_NAS_IPV6_ADDRESS, TAG_ANY);
-               if (!nas) {
-                       nas = radius_pair_create(request->packet, &request->packet->vps, FR_NAS_IPV6_ADDRESS, 0);
-                       nas->vp_ip = request->packet->src_ipaddr;
-               }
-               break;
-
-       default:
-               ERROR("Unknown address family for packet");
-               return -1;
-       }
-
-       return 0;
-}
-
-
-/*
- *     Initialize.
- */
-static int mod_instantiate(void *instance, UNUSED CONF_SECTION *conf)
-{
-       int ret;
-       rlm_preprocess_t *inst = instance;
-
-       /*
-        *      Read the huntgroups file.
-        */
-       if (inst->huntgroup_file) {
-               ret = pairlist_read(inst, inst->huntgroup_file, &(inst->huntgroups), 0);
-               if (ret < 0) {
-                       ERROR("Error reading %s", inst->huntgroup_file);
-
-                       return -1;
-               }
-       }
-
-       /*
-        *      Read the hints file.
-        */
-       if (inst->hints_file) {
-               ret = pairlist_read(inst, inst->hints_file, &(inst->hints), 0);
-               if (ret < 0) {
-                       ERROR("Error reading %s", inst->hints_file);
-
-                       return -1;
-               }
-       }
-
-       return 0;
-}
-
-/*
- *     Preprocess a request.
- */
-static rlm_rcode_t CC_HINT(nonnull) mod_authorize(void *instance, UNUSED void *thread, REQUEST *request)
-{
-       int r;
-       rlm_preprocess_t const *inst = instance;
-
-       VALUE_PAIR *vp;
-
-       /*
-        *      Mangle the username, to get rid of stupid implementation
-        *      bugs.
-        */
-       rad_mangle(inst, request);
-
-       if (inst->with_ascend_hack) {
-               /*
-                *      If we're using Ascend systems, hack the NAS-Port-Id
-                *      in place, to go from Ascend's weird values to something
-                *      approaching rationality.
-                */
-               ascend_nasport_hack(fr_pair_find_by_num(request->packet->vps, 0, FR_NAS_PORT, TAG_ANY),
-                                   inst->ascend_channels_per_line);
-       }
-
-       if (inst->with_cisco_vsa_hack) {
-               /*
-                *      We need to run this hack because the h323-conf-id
-                *      attribute should be used.
-                */
-               cisco_vsa_hack(request);
-       }
-
-       if (inst->with_alvarion_vsa_hack) {
-               /*
-                *      We need to run this hack because the Alvarion
-                *      people are crazy.
-                */
-               alvarion_vsa_hack(request->packet->vps);
-       }
-
-       /*
-        *      Add an event timestamp. Means Event-Timestamp can be used
-        *      consistently instead of one letter expansions.
-        */
-       vp = fr_pair_find_by_num(request->packet->vps, 0, FR_EVENT_TIMESTAMP, TAG_ANY);
-       if (!vp) {
-               vp = radius_pair_create(request->packet, &request->packet->vps, FR_EVENT_TIMESTAMP, 0);
-               vp->vp_date = request->packet->timestamp.tv_sec;
-       }
-
-       /*
-        *      Note that we add the Request-Src-IP-Address to the request
-        *      structure BEFORE checking huntgroup access.  This allows
-        *      the Request-Src-IP-Address to be used for huntgroup
-        *      comparisons.
-        */
-       if (add_nas_attr(request) < 0) {
-               return RLM_MODULE_FAIL;
-       }
-
-       hints_setup(inst->hints, request);
-
-       /*
-        *      If there is a FR_CHAP_PASSWORD attribute but there
-        *      is FR_CHAP_CHALLENGE we need to add it so that other
-        *      modules can use it as a normal attribute.
-        */
-       if (fr_pair_find_by_num(request->packet->vps, 0, FR_CHAP_PASSWORD, TAG_ANY) &&
-           fr_pair_find_by_num(request->packet->vps, 0, FR_CHAP_CHALLENGE, TAG_ANY) == NULL) {
-               vp = radius_pair_create(request->packet, &request->packet->vps, FR_CHAP_CHALLENGE, 0);
-               fr_pair_value_memcpy(vp, request->packet->vector, AUTH_VECTOR_LEN);
-       }
-
-       if ((r = huntgroup_access(request, inst->huntgroups)) != RLM_MODULE_OK) {
-               char buf[1024];
-               RIDEBUG("No huntgroup access: [%s] (%s)",
-                       request->username ? request->username->vp_strvalue : "<NO User-Name>",
-                       auth_name(buf, sizeof(buf), request, 1));
-
-               return r;
-       }
-
-       return RLM_MODULE_OK; /* Meaning: try next authorization module */
-}
-
-/*
- *     Preprocess a request before accounting
- */
-static rlm_rcode_t CC_HINT(nonnull) mod_preaccounting(void *instance, UNUSED void *thread, REQUEST *request)
-{
-       int r;
-       VALUE_PAIR *vp;
-       rlm_preprocess_t const *inst = instance;
-
-       /*
-        *  Ensure that we have the SAME user name for both
-        *  authentication && accounting.
-        */
-       rad_mangle(inst, request);
-
-       if (inst->with_cisco_vsa_hack) {
-               /*
-                *      We need to run this hack because the h323-conf-id
-                *      attribute should be used.
-                */
-               cisco_vsa_hack(request);
-       }
-
-       if (inst->with_alvarion_vsa_hack) {
-               /*
-                *      We need to run this hack because the Alvarion
-                *      people are crazy.
-                */
-               alvarion_vsa_hack(request->packet->vps);
-       }
-
-       /*
-        *  Ensure that we log the NAS IP Address in the packet.
-        */
-       if (add_nas_attr(request) < 0) {
-               return RLM_MODULE_FAIL;
-       }
-
-       hints_setup(inst->hints, request);
-
-       /*
-        *      Add an event timestamp.  This means that the rest of
-        *      the server can use it, rather than various error-prone
-        *      manual calculations.
-        */
-       vp = fr_pair_find_by_num(request->packet->vps, 0, FR_EVENT_TIMESTAMP, TAG_ANY);
-       if (!vp) {
-               VALUE_PAIR *delay;
-
-               vp = radius_pair_create(request->packet, &request->packet->vps, FR_EVENT_TIMESTAMP, 0);
-               vp->vp_date = request->packet->timestamp.tv_sec;
-
-               delay = fr_pair_find_by_num(request->packet->vps, 0, FR_ACCT_DELAY_TIME, TAG_ANY);
-               if (delay) {
-                       if ((delay->vp_uint32 >= vp->vp_date) || (delay->vp_uint32 == UINT32_MAX)) {
-                               RWARN("Ignoring invalid Acct-Delay-time of %u seconds", delay->vp_uint32);
-                       } else {
-                               vp->vp_date -= delay->vp_uint32;
-                       }
-               }
-       }
-
-       if ((r = huntgroup_access(request, inst->huntgroups)) != RLM_MODULE_OK) {
-               char buf[1024];
-               RIDEBUG("No huntgroup access: [%s] (%s)",
-                       request->username ? request->username->vp_strvalue : "<NO User-Name>",
-                       auth_name(buf, sizeof(buf), request, 1));
-               return r;
-       }
-
-       return r;
-}
-
-/* globally exported name */
-extern rad_module_t rlm_preprocess;
-rad_module_t rlm_preprocess = {
-       .magic          = RLM_MODULE_INIT,
-       .name           = "preprocess",
-       .inst_size      = sizeof(rlm_preprocess_t),
-       .config         = module_config,
-       .instantiate    = mod_instantiate,
-       .methods = {
-               [MOD_AUTHORIZE]         = mod_authorize,
-               [MOD_PREACCT]           = mod_preaccounting
-       },
-};
-
index b4ada56236c21fac43a347e88660fb49a2daa229..6fd7dde0fa144fd2c33766587660327485714e85 100644 (file)
@@ -967,10 +967,6 @@ static int mod_instantiate(void *instance, CONF_SECTION *conf)
                                   section_type_value[MOD_AUTHENTICATE].section) < 0) ||
                (parse_sub_section(inst, conf, section_config, &inst->accounting,
                                   section_type_value[MOD_ACCOUNTING].section) < 0) ||
-
-/* @todo add behaviour for checksimul */
-/*             (parse_sub_section(conf, section_config, &inst->checksimul,
-                                  section_type_value[MOD_SESSION].section) < 0) || */
                (parse_sub_section(inst, conf, section_config, &inst->post_auth,
                                   section_type_value[MOD_POST_AUTH].section) < 0))
        {
index adc78756c1b472088a35935235c1deaf9cf50701..27b7246b9acf04d3f5436145011bdc97e52f43a4 100644 (file)
@@ -22,7 +22,6 @@ rlm_pam
 rlm_pap
 rlm_passwd
 rlm_perl
-rlm_preprocess
 rlm_python
 rlm_radutmp
 rlm_redis
diff --git a/src/tests/modules/preprocess/all.mk b/src/tests/modules/preprocess/all.mk
deleted file mode 100644 (file)
index 5cfad60..0000000
+++ /dev/null
@@ -1,3 +0,0 @@
-#
-#  Test the "preprocess" module
-#
diff --git a/src/tests/modules/preprocess/hints b/src/tests/modules/preprocess/hints
deleted file mode 100644 (file)
index 14ceafc..0000000
+++ /dev/null
@@ -1,2 +0,0 @@
-DEFAULT
-       Calling-Station-Id := "%{User-Name}@%{NAS-IP-Address}"
diff --git a/src/tests/modules/preprocess/huntgroups b/src/tests/modules/preprocess/huntgroups
deleted file mode 100644 (file)
index e69de29..0000000
diff --git a/src/tests/modules/preprocess/module.conf b/src/tests/modules/preprocess/module.conf
deleted file mode 100644 (file)
index 7c51fa6..0000000
+++ /dev/null
@@ -1,4 +0,0 @@
-preprocess {
-       hints = $ENV{MODULE_TEST_DIR}/hints
-       huntgroups = $ENV{MODULE_TEST_DIR}/huntgroups
-}
diff --git a/src/tests/modules/preprocess/xlat.attrs b/src/tests/modules/preprocess/xlat.attrs
deleted file mode 100644 (file)
index e7170d1..0000000
+++ /dev/null
@@ -1,12 +0,0 @@
-#
-#  Input packet
-#
-User-Name = "bob"
-User-Password = "bob"
-NAS-IP-Address = 127.0.0.1
-
-#
-#  Expected answer
-#
-Response-Packet-Type == Access-Accept
-Filter-Id == 'success'
diff --git a/src/tests/modules/preprocess/xlat.unlang b/src/tests/modules/preprocess/xlat.unlang
deleted file mode 100644 (file)
index da53982..0000000
+++ /dev/null
@@ -1,14 +0,0 @@
-#
-#  Run the preprocess module
-#
-preprocess
-
-if (Calling-Station-Id == "bob@127.0.0.1") {
-       update reply {
-               Filter-Id := "success"
-       }
-}
-
-update control {
-       Cleartext-Password := "%{User-Name}"
-}
diff --git a/src/tests/vectors/eapsim-03/radiusd-example.txt b/src/tests/vectors/eapsim-03/radiusd-example.txt
deleted file mode 100644 (file)
index 5de3c1a..0000000
+++ /dev/null
@@ -1,1486 +0,0 @@
-##
-## radiusd.conf        -- FreeRADIUS server configuration file.
-##
-##     http://www.freeradius.org/
-##     $Id$
-##
-
-# This is the radiusd.conf file used for testing EAP-SIM stuff.
-#
-#
-
-#      The location of other config files and
-#      logfiles are declared in this file
-#
-#      Also general configuration for modules can be done
-#      in this file, it is exported through the API to
-#      modules that ask for it.
-#
-#      The configuration variables defined here are of the form ${foo}
-#      They are local to this file, and do not change from request to
-#      request.
-#
-#      The per-request variables are of the form %{Attribute-Name}, and
-#      are taken from the values of the attribute in the incoming
-#      request.  See 'doc/configuration/variables.rst' for more information.
-
-prefix = /elros/mcr/root
-exec_prefix = ${prefix}
-sysconfdir = ${prefix}/etc
-localstatedir = ${prefix}/var
-sbindir = ${exec_prefix}/sbin
-logdir = ${localstatedir}/log/radius
-raddbdir = ${sysconfdir}/raddb
-radacctdir = ${logdir}/radacct
-
-#  Location of config and logfiles.
-confdir = ${raddbdir}
-run_dir = ${localstatedir}/run/radiusd
-
-#
-#  The logging messages for the server are appended to the
-#  tail of this file.
-#
-log_file = ${logdir}/radius.log
-
-#
-# libdir: Where to find the rlm_* modules.
-#
-#   This should be automatically set at configuration time.
-#
-#   If the server builds and installs, but fails at execution time
-#   with an 'undefined symbol' error, then you can use the libdir
-#   directive to work around the problem.
-#
-#   The cause is usually that a library has been installed on your
-#   system in a place where the dynamic linker CANNOT find it.  When
-#   executing as root (or another user), your personal environment MAY
-#   be set up to allow the dynamic linker to find the library.  When
-#   executing as a daemon, FreeRADIUS MAY NOT have the same
-#   personalized configuration.
-#
-#   To work around the problem, find out which library contains that symbol,
-#   and add the directory containing that library to the end of 'libdir',
-#   with a colon separating the directory names.  NO spaces are allowed.
-#
-#   e.g. libdir = /usr/local/lib:/opt/package/lib
-#
-#   You can also try setting the LD_LIBRARY_PATH environment variable
-#   in a script which starts the server.
-#
-#   If that does not work, then you can re-configure and re-build the
-#   server to NOT use shared libraries, via:
-#
-#      ./configure --disable-shared
-#      make
-#      make install
-#
-libdir = ${exec_prefix}/lib
-
-#  pidfile: Where to place the PID of the RADIUS server.
-#
-#  The server may be signalled while it's running by using this
-#  file.
-#
-#  This file is written when ONLY running in daemon mode.
-#
-#  e.g.:  kill -HUP `cat /var/run/radiusd/radiusd.pid`
-#
-pidfile = ${run_dir}/radiusd.pid
-
-
-# user/group: The name (or #number) of the user/group to run radiusd as.
-#
-#   If these are commented out, the server will run as the user/group
-#   that started it.  In order to change to a different user/group, you
-#   MUST be root ( or have root privleges ) to start the server.
-#
-#   We STRONGLY recommend that you run the server with as few permissions
-#   as possible.  That is, if you're not using shadow passwords, the
-#   user and group items below should be set to 'nobody'.
-#
-#    On SCO (ODT 3) use "user = nouser" and "group = nogroup".
-#
-#  NOTE that some kernels refuse to setgid(group) when the value of
-#  (unsigned)group is above 60000; don't use group nobody on these systems!
-#
-#  On systems with shadow passwords, you might have to set 'group = shadow'
-#  for the server to be able to read the shadow password file.  If you can
-#  authenticate users while in debug mode, but not in daemon mode, it may be
-#  that the debugging mode server is running as a user that can read the
-#  shadow info, and the user listed below can not.
-#
-#user = nobody
-#group = nobody
-
-#  max_request_time: The maximum time (in seconds) to handle a request.
-#
-#  Requests which take more time than this to process may be killed, and
-#  a REJECT message is returned.
-#
-#  WARNING: If you notice that requests take a long time to be handled,
-#  then this MAY INDICATE a bug in the server, in one of the modules
-#  used to handle a request, OR in your local configuration.
-#
-#  This problem is most often seen when using an SQL database.  If it takes
-#  more than a second or two to receive an answer from the SQL database,
-#  then it probably means that you haven't indexed the database.  See your
-#  SQL server documentation for more information.
-#
-#  Useful range of values: 5 to 120
-#
-max_request_time = 30
-
-#  cleanup_delay: The time to wait (in seconds) before cleaning up
-#  a reply which was sent to the NAS.
-#
-#  The RADIUS request is normally cached internally for a short period
-#  of time, after the reply is sent to the NAS.  The reply packet may be
-#  lost in the network, and the NAS will not see it.  The NAS will then
-#  re-send the request, and the server will respond quickly with the
-#  cached reply.
-#
-#  If this value is set too low, then duplicate requests from the NAS
-#  MAY NOT be detected, and will instead be handled as separate requests.
-#
-#  If this value is set too high, then the server will cache too many
-#  requests, and some new requests may get blocked.  (See 'max_requests'.)
-#
-#  Useful range of values: 2 to 10
-#
-cleanup_delay = 5
-
-#  max_requests: The maximum number of requests which the server keeps
-#  track of.  This should be 256 multiplied by the number of clients.
-#  e.g. With 4 clients, this number should be 1024.
-#
-#  If this number is too low, then when the server becomes busy,
-#  it will not respond to any new requests, until the 'cleanup_delay'
-#  time has passed, and it has removed the old requests.
-#
-#  If this number is set too high, then the server will use a bit more
-#  memory for no real benefit.
-#
-#  If you aren't sure what it should be set to, it's better to set it
-#  too high than too low.  Setting it to 1000 per client is probably
-#  the highest it should be.
-#
-#  Useful range of values: 256 to infinity
-#
-max_requests = 1024
-
-#  bind_address:  Make the server listen on a particular IP address, and
-#  send replies out from that address.  This directive is most useful
-#  for machines with multiple IP addresses on one interface.
-#
-#  It can either contain "*", or an IP address, or a fully qualified
-#  Internet domain name.  The default is "*"
-#
-bind_address = *
-
-#  port: Allows you to bind FreeRADIUS to a specific port.
-#
-#  The default port that most NAS boxes use is 1645, which is historical.
-#  RFC 2138 defines 1812 to be the new port.  Many new servers and
-#  NAS boxes use 1812, which can create interoperability problems.
-#
-#  The port is defined here to be 0 so that the server will pick up
-#  the machine's local configuration for the radius port, as defined
-#  in /etc/services.
-#
-#  If you want to use the default RADIUS port as defined on your server,
-#  (usually through 'grep radius /etc/services') set this to 0 (zero).
-#
-#  A port given on the command-line via '-p' over-rides this one.
-#
-port = 0
-
-#  hostname_lookups: Log the names of clients or just their IP addresses
-#  e.g., www.freeradius.org (on) or 206.47.27.232 (off).
-#
-#  The default is 'off' because it would be overall better for the net
-#  if people had to knowingly turn this feature on, since enabling it
-#  means that each client request will result in AT LEAST one lookup
-#  request to the nameserver.   Enabling hostname_lookups will also
-#  mean that your server may stop randomly for 30 seconds from time
-#  to time, if the DNS requests take too long.
-#
-#  Turning hostname lookups off also means that the server won't block
-#  for 30 seconds, if it sees an IP address which has no name associated
-#  with it.
-#
-#  allowed values: {no, yes}
-#
-hostname_lookups = no
-
-#  Core dumps are a bad thing.  This should only be set to 'yes'
-#  if you're debugging a problem with the server.
-#
-#  allowed values: {no, yes}
-#
-allow_core_dumps = yes
-
-#  Log the full User-Name attribute, as it was found in the request.
-#
-# allowed values: {no, yes}
-#
-log_stripped_names = no
-
-#  Log authentication requests to the log file.
-#
-#  allowed values: {no, yes}
-#
-log_auth = no
-
-#  Log passwords with the authentication requests.
-#  log_auth_badpass  - logs password if it's rejected
-#  log_auth_goodpass - logs password if it's correct
-#
-#  allowed values: {no, yes}
-#
-log_auth_badpass = no
-log_auth_goodpass = no
-
-# usercollide:  Turn "username collision" code on and off.  See the
-# "doc/duplicate-users" file
-#
-usercollide = no
-
-# lower_user / lower_pass:
-# Lower case the username/password "before" or "after"
-# attempting to authenticate.
-#
-#  If "before", the server will first modify the request and then try
-#  to auth the user.  If "after", the server will first auth using the
-#  values provided by the user.  If that fails it will reprocess the
-#  request after modifying it as you specify below.
-#
-#  This is as close as we can get to case insensitivity.  It is the
-#  admin's job to ensure that the username on the auth db side is
-#  *also* lowercase to make this work
-#
-# Default is 'no' (don't lowercase values)
-# Valid values = "before" / "after" / "no"
-#
-lower_user = no
-lower_pass = no
-
-# nospace_user / nospace_pass:
-#
-#  Some users like to enter spaces in their username or password
-#  incorrectly.  To save yourself the tech support call, you can
-#  eliminate those spaces here:
-#
-# Default is 'no' (don't remove spaces)
-# Valid values = "before" / "after" / "no" (explanation above)
-#
-nospace_user = no
-nospace_pass = no
-
-#  The program to execute to do concurrency checks.
-checkrad = ${sbindir}/checkrad
-
-# SECURITY CONFIGURATION
-#
-#  There may be multiple methods of attacking on the server.  This
-#  section holds the configuration items which minimize the impact
-#  of those attacks
-#
-security {
-       #
-       #  max_attributes: The maximum number of attributes
-       #  permitted in a RADIUS packet.  Packets which have MORE
-       #  than this number of attributes in them will be dropped.
-       #
-       #  If this number is set too low, then no RADIUS packets
-       #  will be accepted.
-       #
-       #  If this number is set too high, then an attacker may be
-       #  able to send a small number of packets which will cause
-       #  the server to use all available memory on the machine.
-       #
-       #  Setting this number to 0 means "allow any number of attributes"
-       max_attributes = 200
-
-       #
-       #  reject_delay: When sending an Access-Reject, it can be
-       #  delayed for a few seconds.  This may help slow down a DoS
-       #  attack.  It also helps to slow down people trying to brute-force
-       #  crack a users password.
-       #
-       #  Setting this number to 0 means "send rejects immediately"
-       #
-       #  If this number is set higher than 'cleanup_delay', then the
-       #  rejects will be sent at 'cleanup_delay' time, when the request
-       #  is deleted from the internal cache of requests.
-       #
-       #  Useful ranges: 1 to 5
-       reject_delay = 1
-
-       #
-       #  status_server: Whether or not the server will respond
-       #  to Status-Server requests.
-       #
-       #  Normally this should be set to "no", because they're useless.
-       #  See: http://www.freeradius.org/rfc/rfc2865.html#Keep-Alives
-       #
-       #  However, certain NAS boxes may require them.
-       #
-       #  When sent a Status-Server message, the server responds with
-       #  and Access-Accept packet, containing a Reply-Message attribute,
-       #  which is a string describing how long the server has been
-       #  running.
-       #
-       status_server = no
-}
-
-# CLIENTS CONFIGURATION
-#
-#  Client configuration is defined in "clients.conf".
-#
-
-#  The 'clients.conf' file contains all of the information from the old
-#  'clients' and 'naslist' configuration files.  We recommend that you
-#  do NOT use 'client's or 'naslist', although they are still
-#  supported.
-#
-#  Anything listed in 'clients.conf' will take precedence over the
-#  information from the old-style configuration files.
-#
-$INCLUDE  ${confdir}/clients.conf
-
-
-# SNMP CONFIGURATION
-#
-#  Snmp configuration is only valid if SNMP support was enabled
-#  at compile time.
-#
-#  To enable SNMP querying of the server, set the value of the
-#  'snmp' attribute to 'yes'
-#
-snmp   = no
-$INCLUDE  ${confdir}/snmp.conf
-
-
-# THREAD POOL CONFIGURATION
-#
-#  The thread pool is a long-lived group of threads which
-#  take turns (round-robin) handling any incoming requests.
-#
-#  You probably want to have a few spare threads around,
-#  so that high-load situations can be handled immediately.  If you
-#  don't have any spare threads, then the request handling will
-#  be delayed while a new thread is created, and added to the pool.
-#
-#  You probably don't want too many spare threads around,
-#  otherwise they'll be sitting there taking up resources, and
-#  not doing anything productive.
-#
-#  The numbers given below should be adequate for most situations.
-#
-thread pool {
-       #  Number of servers to start initially --- should be a reasonable
-       #  ballpark figure.
-       start_servers = 5
-
-       #  Limit on the total number of servers running.
-       #
-       #  If this limit is ever reached, clients will be LOCKED OUT, so it
-       #  should NOT BE SET TOO LOW.  It is intended mainly as a brake to
-       #  keep a runaway server from taking the system with it as it spirals
-       #  down...
-       #
-       #  You may find that the server is regularly reaching the
-       #  'max_servers' number of threads, and that increasing
-       #  'max_servers' doesn't seem to make much difference.
-       #
-       #  If this is the case, then the problem is MOST LIKELY that
-       #  your back-end databases are taking too long to respond, and
-       #  are preventing the server from responding in a timely manner.
-       #
-       #  The solution is NOT do keep increasing the 'max_servers'
-       #  value, but instead to fix the underlying cause of the
-       #  problem: slow database, or 'hostname_lookups=yes'.
-       #
-       #  For more information, see 'max_request_time', above.
-       #
-       max_servers = 32
-
-       #  Server-pool size regulation.  Rather than making you guess
-       #  how many servers you need, FreeRADIUS dynamically adapts to
-       #  the load it sees, that is, it tries to maintain enough
-       #  servers to handle the current load, plus a few spare
-       #  servers to handle transient load spikes.
-       #
-       #  It does this by periodically checking how many servers are
-       #  waiting for a request.  If there are fewer than
-       #  min_spare_servers, it creates a new spare.  If there are
-       #  more than max_spare_servers, some of the spares die off.
-       #  The default values are probably OK for most sites.
-       #
-       min_spare_servers = 3
-       max_spare_servers = 10
-
-       #  There may be memory leaks or resource allocation problems with
-       #  the server.  If so, set this value to 300 or so, so that the
-       #  resources will be cleaned up periodically.
-       #
-       #  This should only be necessary if there are serious bugs in the
-       #  server which have not yet been fixed.
-       #
-       #  '0' is a special value meaning 'infinity', or 'the servers never
-       #  exit'
-       max_requests_per_server = 0
-}
-
-# MODULE CONFIGURATION
-#
-#  The names and configuration of each module is located in this section.
-#
-#  After the modules are defined here, they may be referred to by name,
-#  in other sections of this configuration file.
-#
-modules {
-       #
-       #  Each module has a configuration as follows:
-       #
-       #       name [ instance ] {
-       #               config_item = value
-       #               ...
-       #       }
-       #
-       #  The 'name' is used to load the 'rlm_name' library
-       #  which implements the functionality of the module.
-       #
-       #  The 'instance' is optional.  To have two different instances
-       #  of a module, it first must be referred to by 'name'.
-       #  The different copies of the module are then created by
-       #  inventing two 'instance' names, e.g. 'instance1' and 'instance2'
-       #
-       #  The instance names can then be used in later configuration
-       #  INSTEAD of the original 'name'.  See the 'radutmp' configuration
-       #  below for an example.
-       #
-
-       # PAP module to authenticate users based on their stored password
-       #
-       #  Supports multiple encryption schemes
-       #  clear: Clear text
-       #  crypt: Unix crypt
-       #    md5: MD5 ecnryption
-       #   sha1: SHA1 encryption.
-       #  DEFAULT: crypt
-       pap {
-               encryption_scheme = crypt
-       }
-
-       # CHAP module
-       #
-       #  To authenticate requests containing a CHAP-Password attribute.
-       #
-       chap {
-               authtype = CHAP
-       }
-
-       # Pluggable Authentication Modules
-       #
-       #  For Linux, see:
-       #       http://www.kernel.org/pub/linux/libs/pam/index.html
-       #
-       pam {
-               #
-               #  The name to use for PAM authentication.
-               #  PAM looks in /etc/pam.d/${pam_auth_name}
-               #  for it's configuration.  See 'redhat/radiusd-pam'
-               #  for a sample PAM configuration file.
-               #
-               #  Note that any Pam-Auth attribute set in the 'authorize'
-               #  section will over-ride this one.
-               #
-               pam_auth = radiusd
-       }
-
-       # Unix /etc/passwd style authentication
-       #
-       unix {
-               #
-               #  Cache /etc/passwd, /etc/shadow, and /etc/group
-               #
-               #  The default is to NOT cache them.
-               #
-               #  For FreeBSD, you do NOT want to enable the cache,
-               #  as it's password lookups are done via a database, so
-               #  set this value to 'no'.
-               #
-               #  Some systems (e.g. RedHat Linux with pam_pwbd) can
-               #  take *seconds* to check a password, from a passwd
-               #  file containing 1000's of entries.  For those systems,
-               #  you should set the cache value to 'yes', and set
-               #  the locations of the 'passwd', 'shadow', and 'group'
-               #  files, below.
-               #
-               # allowed values: {no, yes}
-               cache = no
-
-               # Reload the cache every 600 seconds (10mins). 0 to disable.
-               cache_reload = 600
-
-               #
-               #  Define the locations of the normal passwd, shadow, and
-               #  group files.
-               #
-               #  'shadow' is commented out by default, because not all
-               #  systems have shadow passwords.
-               #
-               #  To force the module to use the system password functions,
-               #  instead of reading the files, leave the following entries
-               #  commented out.
-               #
-               #  This is required for some systems, like FreeBSD,
-               #  and Mac OSX.
-               #
-               #       passwd = /etc/passwd
-               #       shadow = /etc/shadow
-               #       group = /etc/group
-
-
-               #
-               #  Where the 'wtmp' file is located.
-               #  This should be moved to it's own module soon.
-               #
-               #  The only use for 'radlast'.  If you don't use
-               #  'radlast', then you can comment out this item.
-               #
-               radwtmp = ${logdir}/radwtmp
-       }
-
-       #  Extensible Authentication Protocol
-       #
-       #  For all EAP related authentications
-       eap {
-               #  Invoke the default supported EAP type when
-               #  EAP-Identity response is received.
-               #
-               #  The incoming EAP messages MAY NOT specify which EAP
-               #  type they will be using, so it MUST be set here.
-               #
-               #  For now, only one default EAP type may be used at a time.
-               #
-               default_eap_type = md5
-
-               # Default expiry time to clean the EAP list,
-               # It is maintained to correlate the
-               # EAP-response for each EAP-request sent.
-               timer_expire     = 60
-
-               # Supported EAP-types
-               md5 {
-               }
-
-               sim {
-               }
-
-               # Cisco LEAP
-               #
-               #  Cisco LEAP uses the MS-CHAP algorithm (but not
-               #  the MS-CHAP attributes) to perform it's authentication.
-               #
-               #  As a result, LEAP *requires* access to the plain-text
-               #  User-Password, or the NT-Password attributes.
-               #  'System' authentication is impossible with LEAP.
-               #
-               leap {
-               }
-
-               ## EAP-TLS is highly experimental EAP-Type at the moment.
-               #       Please give feedback on the mailing list.
-               #tls {
-               #       private_key_password = password
-               #       private_key_file = /path/filename
-
-               #       If Private key & Certificate are located in the
-               #       same file, then private_key_file & certificate_file
-               #       must contain the same file name.
-               #       certificate_file = /path/filename
-
-               #       Trusted Root CA list
-                       #ca_file = /path/filename
-
-               #       dh_file = /path/filename
-                       #random_file = /path/filename
-               #
-               #       This can never exceed MAX_RADIUS_LEN (4096)
-               #       preferably half the MAX_RADIUS_LEN, to
-               #       accomodate other attributes in RADIUS packet.
-               #       On most APs the MAX packet length is configured
-               #       between 1500 - 1600. In these cases, fragment
-               #       size should be <= 1024.
-               #
-               #               fragment_size = 1024
-
-               #       include_length is a flag which is by default set to yes
-               #       If set to yes, Total Length of the message is included
-               #       in EVERY packet we send.
-               #       If set to no, Total Length of the message is included
-               #       ONLY in the First packet of a fragment series.
-               #
-               #               include_length = yes
-               #}
-       }
-
-       # Microsoft CHAP authentication
-       #
-       #  This module supports MS-CHAP and MS-CHAPv2 authentication.
-       #  It also enforces the SMB-Account-Ctrl attribute.
-       #
-       mschap {
-               #
-               #  As of 0.9, the mschap module does NOT support
-               #  reading from /etc/smbpasswd.
-               #
-               #  If you are using /etc/smbpasswd, see the 'passwd'
-               #  module for an example of how to use /etc/smbpasswd
-
-               # authtype value, if present, will be used
-               # to overwrite (or add) Auth-Type during
-               # authorization. Normally should be MS-CHAP
-               authtype = MS-CHAP
-
-               # if use_mppe is not set to no mschap will
-               # add MS-CHAP-MPPE-Keys for MS-CHAPv1 and
-               # MS-MPPE-Recv-Key/MS-MPPE-Send-Key for MS-CHAPv2
-               #       use_mppe = no
-
-               # if mppe is enabled require_encryption makes
-               # encryption moderate
-               #       require_encryption = yes
-
-               # require_strong always requires 128 bit key
-               # encryption
-               #       require_strong = yes
-       }
-
-       # Lightweight Directory Access Protocol (LDAP)
-       #
-       #  This module definition allows you to use LDAP for
-       #  authorization and authentication (Auth-Type := LDAP)
-       #
-       #  See doc/rlm_ldap for description of configuration options
-       #  and sample authorize{} and authenticate{} blocks
-       ldap {
-               server = "ldap.your.domain"
-               # identity = "cn=admin,o=My Org,c=UA"
-               # password = mypass
-               basedn = "o=My Org,c=UA"
-               filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
-
-               # set this to 'yes' to use TLS encrypted connections
-               # to the LDAP database by using the StartTLS extended
-               # operation.
-               # The StartTLS operation is supposed to be used with normal
-               # ldap connections instead of using ldaps (port 636) connections
-               start_tls = no
-
-               # default_profile = "cn=radprofile,ou=dialup,o=My Org,c=UA"
-               # profile_attribute = "radiusProfileDn"
-               access_attr = "dialupAccess"
-
-               # Mapping of RADIUS dictionary attributes to LDAP
-               # directory attributes.
-               dictionary_mapping = ${raddbdir}/ldap.attrmap
-
-               ldap_connections_number = 5
-               # password_header = "{clear}"
-               # password_attribute = userPassword
-               # groupname_attribute = cn
-               # groupmembership_filter = "(|(&(objectClass=GroupOfNames)(member=%{Ldap-UserDn}))(&(objectClass=GroupOfUniqueNames)(uniquemember=%{Ldap-UserDn})))"
-               # groupmembership_attribute = radiusGroupName
-               timeout = 4
-               timelimit = 3
-               net_timeout = 1
-               # compare_check_items = yes
-               # access_attr_used_for_allow = yes
-       }
-
-       # passwd module allows to do authorization via any passwd-like
-       # file and to extract any attributes from these modules
-       #
-       # parameters are:
-       #   filename - path to filename
-       #   format - format for filename record. This parameters
-       #            correlates record in the passwd file and RADIUS
-       #            attributes.
-       #
-       #            Field marked as '*' is key field. That is, the parameter
-       #            with this name from the request is used to search for
-       #            the record from passwd file
-       #            Attribute marked as '=' is added to reply_items instead
-       #            of default configure_items
-       #            Attribute marked as '~' is added to request_items
-       #
-       #            Field marked as ',' may contain a comma separated list
-       #            of attributes.
-       #   authtype - if record found this Auth-Type is used to authenticate
-       #            user
-       #   hash_size - hashtable size. If 0 or not specified records are not
-       #            stored in memory and file is red on every request.
-       #   allow_multiple_keys - if few records for every key are allowed
-       #   ignore_nislike - ignore NIS-related records
-       #   delimiter - symbol to use as a field separator in passwd file,
-       #            for format ':' symbol is always used. '\0', '\n' are
-       #            not allowed
-       #
-
-       #  An example configuration for using /etc/smbpasswd.
-       #
-       #passwd etc_smbpasswd {
-       #       filename = /etc/smbpasswd
-       #       format = "*User-Name::LM-Password:NT-Password:SMB-Account-CTRL-TEXT::"
-       #       authtype = MS-CHAP
-       #       hash_size = 100
-       #       ignore_nislike = no
-       #       allow_multiple_keys = no
-       #}
-
-       #  Similar configuration, for the /etc/group file. Adds a Group-Name
-       #  attribute for every group that the user is member of.
-       #
-       #passwd etc_group {
-       #       filename = /etc/group
-       #       format = "=Group-Name:::*,User-Name"
-       #       hash_size = 50
-       #       ignore_nislike = yes
-       #       allow_multiple_keys = yes
-       #       delimiter = ":"
-       #}
-
-       # Realm module, for proxying.
-       #
-       #  You can have multiple instances of the realm module to
-       #  support multiple realm syntaxs at the same time.  The
-       #  search order is defined the order in the authorize and
-       #  preacct blocks after the module config block.
-       #
-       #  Two config options:
-       #       format     -  must be 'prefix' or 'suffix'
-       #       delimiter  -  must be a single character
-
-       #  'realm/username'
-       #
-       #  Using this entry, IPASS users have their realm set to "IPASS".
-       realm realmslash {
-               format = prefix
-               delimiter = "/"
-       }
-
-       #  'username@realm'
-       #
-       realm suffix {
-               format = suffix
-               delimiter = "@"
-       }
-
-       #  'username%realm'
-       #
-       realm realmpercent {
-               format = suffix
-               delimiter = "%"
-       }
-
-       # Preprocess the incoming RADIUS request, before handing it off
-       # to other modules.
-       #
-       #  This module processes the 'huntgroups' and 'hints' files.
-       #  In addition, it re-writes some weird attributes created
-       #  by some NASes, and converts the attributes into a form which
-       #  is a little more standard.
-       #
-       preprocess {
-               huntgroups = ${confdir}/huntgroups
-               hints = ${confdir}/hints
-
-               # This hack changes Ascend's weird port numberings
-               # to standard 0-??? port numbers so that the "+" works
-               # for IP address assignments.
-               with_ascend_hack = no
-               ascend_channels_per_line = 23
-
-               # Windows NT machines often authenticate themselves as
-               # NT_DOMAIN\username
-               #
-               # If this is set to 'yes', then the NT_DOMAIN portion
-               # of the user-name is silently discarded.
-               with_ntdomain_hack = no
-
-               # Specialix Jetstream 8500 24 port access server.
-               #
-               # If the user name is 10 characters or longer, a "/"
-               # and the excess characters after the 10th are
-               # appended to the user name.
-               #
-               # If you're not running that NAS, you don't need
-               # this hack.
-               with_specialix_jetstream_hack = no
-
-               # Cisco sends it's VSA attributes with the attribute
-               # name *again* in the string, like:
-               #
-               #   H323-Attribute = "h323-attribute=value".
-               #
-               # If this configuration item is set to 'yes', then
-               # the redundant data in the the attribute text is stripped
-               # out.  The result is:
-               #
-               #  H323-Attribute = "value"
-               #
-               # If you're not running a Cisco NAS, you don't need
-               # this hack.
-               with_cisco_vsa_hack = no
-       }
-
-       # Livingston-style 'users' file
-       #
-       files {
-               usersfile = ${confdir}/users
-               acctusersfile = ${confdir}/acct_users
-
-               #  If you want to use the old Cistron 'users' file
-               #  with FreeRADIUS, you should change the next line
-               #  to 'compat = cistron'.  You can the copy your 'users'
-               #  file from Cistron.
-               compat = no
-       }
-
-       # Write a detailed log of all accounting records received.
-       #
-       detail {
-               #  Note that we do NOT use NAS-IP-Address here, as
-               #  that attribute MAY BE from the originating NAS, and
-               #  NOT from the proxy which actually sent us the
-               #  request.  The Client-IP-Address attribute is ALWAYS
-               #  the address of the client which sent us the
-               #  request.
-               #
-               #  The following line creates a new detail file for
-               #  every radius client (by IP address or hostname).
-               #  In addition, a new detail file is created every
-               #  day, so that the detail file doesn't have to go
-               #  through a 'log rotation'
-               #
-               #  If your detail files are large, you may also want
-               #  to add a ':%H' (see doc/configuration/variables.rst) to the end
-               #  of it, to create a new detail file every hour, e.g.:
-               #
-               #   ..../detail-%Y%m%d:%H
-               #
-               #  This will create a new detail file for every hour.
-               #
-               detailfile = ${radacctdir}/%{Client-IP-Address}/detail-%Y%m%d
-
-               #
-               #  The Unix-style permissions on the 'detail' file.
-               #
-               #  The detail file often contains secret or private
-               #  information about users.  So by keeping the file
-               #  permissions restrictive, we can prevent unwanted
-               #  people from seeing that information.
-               detailperm = 0600
-       }
-
-       #  Include another file that has the SQL-related configuration.
-       #  This is another file only because it tends to be big.
-       #
-       #  The following configuration file is for use with MySQL.
-       #
-       #  For Postgresql, use:         ${confdir}/postgresql.conf
-       #  For MS-SQL, use:             ${confdir}/mssql.conf
-       #  For Oracle, use:             ${confdir}/oraclesql.conf
-       #
-       $INCLUDE  ${confdir}/sql.conf
-
-       #  Write a 'utmp' style file, of which users are currently
-       #  logged in, and where they've logged in from.
-       #
-       #  This file is used mainly for Simultaneous-Use checking,
-       #  and also 'radwho', to see who's currently logged in.
-       #
-       radutmp {
-               #  Where the file is stored.  It's not a log file,
-               #  so it doesn't need rotating.
-               #
-               filename = ${logdir}/radutmp
-
-               #  The field in the packet to key on for the
-               #  'user' name,  If you have other fields which you want
-               #  to use to key on to control Simultaneous-Use,
-               #  then you can use them here.
-               #
-               #  Note, however, that the size of the field in the
-               #  'utmp' data structure is small, around 32
-               #  characters, so that will limit the possible choices
-               #  of keys.
-               #
-               username = %{User-Name}
-
-               #  Whether or not we want to treat "user" the same
-               #  as "USER", or "User".  Some systems have problems
-               #  with case sensitivity, so this should be set to
-               #  'no' to enable the comparisons of the key attribute
-               #  to be case insensitive.
-               #
-               case_sensitive = yes
-
-               #  Accounting information may be lost, so the user MAY
-               #  have logged off of the NAS, but we haven't noticed.
-               #  If so, we can verify this information with the NAS,
-               #
-               #  If we want to believe the 'utmp' file, then this
-               #  configuration entry can be set to 'no'.
-               #
-               check_with_nas = yes
-
-               # Set the file permissions, as the contents of this file
-               # are usually private.
-               perm = 0600
-
-               caller_id = "yes"
-       }
-
-       # "Safe" radutmp - does not contain caller ID, so it can be
-       # world-readable, and radwho can work for normal users, without
-       # exposing any information that isn't already exposed by who(1).
-       #
-       # This is another 'instance' of the radutmp module, but it is given
-       # then name "sradutmp" to identify it later in the "accounting"
-       # section.
-       radutmp sradutmp {
-               filename = ${logdir}/sradutmp
-               perm = 0644
-               caller_id = "no"
-       }
-
-       # attr_filter - filters the attributes received in replies from
-       # proxied servers, to make sure we send back to our RADIUS client
-       # only allowed attributes.
-       attr_filter {
-               attrsfile = ${confdir}/attrs
-       }
-
-       #  counter module:
-       #  This module takes an attribute (count_attribute).
-       #  It also takes a key, and creates a counter for each unique
-       #  key.  The count is incremented when accounting packets are
-       #  received by the server.  The value of the increment depends
-       #  on the attribute type.
-       #  If the attribute is Acct-Session-Time or of an integer type we add the
-       #  value of the attribute. If it is anything else we increase the
-       #  counter by one.
-       #
-       #  The 'reset' parameter defines when the counters are all reset to
-       #  zero.  It can be hourly, daily, weekly, monthly or never.
-       #
-       #  hourly: Reset on 00:00 of every hour
-       #  daily: Reset on 00:00:00 every day
-       #  weekly: Reset on 00:00:00 on sunday
-       #  monthly: Reset on 00:00:00 of the first day of each month
-       #
-       #  It can also be user defined. It should be of the form:
-       #  num[hdwm] where:
-       #  h: hours, d: days, w: weeks, m: months
-       #  If the letter is ommited days will be assumed. In example:
-       #  reset = 10h (reset every 10 hours)
-       #  reset = 12  (reset every 12 days)
-       #
-       #
-       #  The check_name attribute defines an attribute which will be
-       #  registered by the counter module and can be used to set the
-       #  maximum allowed value for the counter after which the user
-       #  is rejected.
-       #  Something like:
-       #
-       #  DEFAULT Max-Daily-Session := 36000
-       #          Fall-Through = 1
-       #
-       #  You should add the counter module in the instantiate
-       #  section so that it registers check_name before the files
-       #  module reads the users file.
-       #
-       #  If check_name is set and the user is to be rejected then we
-       #  send back a Reply-Message and we log a Failure-Message in
-       #  the radius.log
-       #  If the count attribute is Acct-Session-Time then on each login
-       #  we send back the remaining online time as a Session-Timeout attribute
-       #
-       #  The counter-name can also be used instead of using the check_name
-       #  like below:
-       #
-       #  DEFAULT  Daily-Session-Time > 3600, Auth-Type = Reject
-       #      Reply-Message = "You've used up more than one hour today"
-       #
-       #  The allowed-servicetype attribute can be used to only take
-       #  into account specific sessions. For example if a user first
-       #  logs in through a login menu and then selects ppp there will
-       #  be two sessions. One for Login-User and one for Framed-User
-       #  service type. We only need to take into account the second one.
-       #
-       #  The module should be added in the instantiate, authorize and
-       #  accounting sections.  Make sure that in the authorize
-       #  section it comes after any module which sets the
-       #  'check_name' attribute.
-       #
-       counter daily {
-               filename = ${raddbdir}/db.daily
-               key = User-Name
-               count_attribute = Acct-Session-Time
-               reset = daily
-               counter_name = Daily-Session-Time
-               check_name = Max-Daily-Session
-               allowed_service_type = Framed-User
-               cache_size = 5000
-       }
-
-       # The "always" module is here for debugging purposes. Each
-       # instance simply returns the same result, always, without
-       # doing anything.
-       always fail {
-               rcode = fail
-       }
-       always reject {
-               rcode = reject
-       }
-       always ok {
-               rcode = ok
-               simulcount = 0
-               mpp = no
-       }
-
-       #
-       #  The 'expression' module currently has no configuration.
-       expr {
-       }
-
-       #
-       #  The 'digest' module currently has no configuration.
-       #
-       #  "Digest" authentication against a Cisco SIP server.
-       #  See 'doc/rfc/draft-sterman-aaa-sip-00.txt' for details
-       #  on performing digest authentication for Cisco SIP servers.
-       #
-       digest {
-       }
-
-       #
-       #  Execute external programs
-       #
-       #  The first example is useful only for 'xlat'.  To use it,
-       #  put 'exec' into the 'instantiate' section.  You can then
-       #  do dynamic translation of attributes like:
-       #
-       #  Attribute-Name = `{%exec:/path/to/program args}`
-       #
-       #  The value of the attribute will be replaced with the output
-       #  of the program which is executed.  Due to RADIUS protocol
-       #  limitations, any output over 253 bytes will be ignored.
-       #
-       #  The RADIUS attributes from the user request will be placed
-       #  into environment variables of the executed program, as
-       #  described in 'doc/configuration/variables.rst'
-       #
-       exec {
-               wait = yes
-               input_pairs = request
-       }
-
-       #
-       #  This is a more general example of the execute module.
-       #
-       #  If you wish to execute an external program in more than
-       #  one section (e.g. 'authorize', 'pre_proxy', etc), then it
-       #  is probably best to define a different instance of the
-       #  'exec' module for every section.
-       #
-       exec echo {
-               #
-               #  Wait for the program to finish.
-               #
-               #  If we do NOT wait, then the program is "fire and
-               #  forget", and any output attributes from it are ignored.
-               #
-               #  If we are looking for the program to output
-               #  attributes, and want to add those attributes to the
-               #  request, then we MUST wait for the program to
-               #  finish, and therefore set 'wait=yes'
-               #
-               # allowed values: {no, yes}
-               wait = yes
-
-               #
-               #  The name of the program to execute, and it's
-               #  arguments.  Dynamic translation is done on this
-               #  field, so things like the following example will
-               #  work.
-               #
-               program = "/bin/echo %{User-Name}"
-
-               #
-               #  The attributes which are placed into the
-               #  environment variables for the program.
-               #
-               #  Allowed values are:
-               #
-               #       request         attributes from the request
-               #       reply           attributes from the reply
-               #       proxy-request   attributes from the proxy request
-               #       proxy-reply     attributes from the proxy reply
-               #
-               #  Note that some attributes may not exist at some
-               #  stages.  e.g. There may be no proxy-reply
-               #  attributes if this module is used in the
-               #  'authorize' section.
-               #
-               input_pairs = request
-
-               #
-               #  Where to place the output attributes (if any) from
-               #  the executed program.  The values allowed, and the
-               #  restrictions as to availability, are the same as
-               #  for the input_pairs.
-               #
-               output_pairs = reply
-
-               #
-               #  When to execute the program.  If the packet
-               #  type does NOT match what's listed here, then
-               #  the module does NOT execute the program.
-               #
-               #  For a list of allowed packet types, see
-               #  the 'dictionary' file, and look for VALUEs
-               #  of the Packet-Type attribute.
-               #
-               #  By default, the module executes on ANY packet.
-               #  Un-comment out the following line to tell the
-               #  module to execute only if an Access-Accept is
-               #  being sent to the NAS.
-               #
-               #packet_type = Access-Accept
-       }
-
-       #  Do server side ip pool management. Should be added in post-auth and
-       #  accounting sections.
-       #
-       #  The module also requires the existence of the Pool-Name
-       #  attribute. That way the administrator can add the Pool-Name
-       #  attribute in the user profiles and use different pools
-       #  for different users. The Pool-Name attribute is a *check* item not
-       #  a reply item.
-       #
-       # Example:
-       # radiusd.conf: ippool students { [...] }
-       # users file  : DEFAULT Group == students, Pool-Name := "students"
-       #
-       # ********* IF YOU CHANGE THE RANGE PARAMETERS YOU MUST THEN ERASE THE DB FILES *******
-       #
-       ippool main_pool {
-
-               #  range-start,range-stop: The start and end ip
-               #  addresses for the ip pool
-               range-start = 192.0.2.1
-               range-stop = 192.0.2.254
-
-               #  netmask: The network mask used for the ip's
-               netmask = 255.255.255.0
-
-               #  cache_size: The gdbm cache size for the db
-               #  files. Should be equal to the number of ip's
-               #  available in the ip pool
-               cache_size = 800
-
-               # session-db: The main db file used to allocate ip's to clients
-               session-db = ${raddbdir}/db.ippool
-
-               # ip-index: Helper db index file used in multilink
-               ip-index = ${raddbdir}/db.ipindex
-
-               # override: Will this ippool override a Framed-IP-Address already set
-               override = no
-       }
-
-       # ANSI X9.9 token support.  Not included by default.
-       # $INCLUDE  ${confdir}/x99.conf
-
-}
-
-# Instantiation
-#
-#  This section orders the loading of the modules.  Modules
-#  listed here will get loaded BEFORE the later sections like
-#  authorize, authenticate, etc. get examined.
-#
-#  This section is not strictly needed.  When a section like
-#  authorize refers to a module, it's automatically loaded and
-#  initialized.  However, some modules may not be listed in any
-#  of the following sections, so they can be listed here.
-#
-#  Also, listing modules here ensures that you have control over
-#  the order in which they are initalized.  If one module needs
-#  something defined by another module, you can list them in order
-#  here, and ensure that the configuration will be OK.
-#
-instantiate {
-       #
-       #  The expression module doesn't do authorization,
-       #  authentication, or accounting.  It only does dynamic
-       #  translation, of the form:
-       #
-       #       Session-Timeout = `%{expr:2 + 3}`
-       #
-       #  So the module needs to be instantiated, but CANNOT be
-       #  listed in any other section.  See 'doc/rlm_expr' for
-       #  more information.
-       #
-       expr
-
-       #
-       # We add the counter module here so that it registers
-       # the check_name attribute before any module which sets
-       # it
-#      daily
-}
-
-#  Authorization. First preprocess (hints and huntgroups files),
-#  then realms, and finally look in the "users" file.
-#
-#  The order of the realm modules will determine the order that
-#  we try to find a matching realm.
-#
-#  Make *sure* that 'preprocess' comes before any realm if you
-#  need to setup hints for the remote radius server
-recv Access-Request {
-       #
-       #  The preprocess module takes care of sanitizing some bizarre
-       #  attributes in the request, and turning them into attributes
-       #  which are more standard.
-       #
-       #  It takes care of processing the 'raddb/hints' and the
-       #  'raddb/huntgroups' files.
-       #
-       #  It also adds a Client-IP-Address attribute to the request.
-       preprocess
-
-       #
-       #  The chap module will set 'Auth-Type := CHAP' if we are
-       #  handling a CHAP request and Auth-Type has not already been set
-       chap
-
-#      attr_filter
-
-       #
-       #  This module takes care of EAP-MD5, EAP-TLS, and EAP-LEAP
-       #  authentication.
-       eap
-
-       #
-       #  If you have a Cisco SIP server authenticating against
-       #  FreeRADIUS, uncomment the following line.
-       # digest
-
-       #
-       #  Look for IPASS style 'realm/', and if not found, look for
-       #  '@realm', and decide whether or not to proxy, based on
-       #  that.
-#      realmslash
-       suffix
-
-       #
-       #  Read the 'users' file
-       files
-
-       #
-       #  If you are using /etc/smbpasswd, and are also doing
-       #  mschap authentication, the un-comment this line, and
-       #  configure the 'etc_smbpasswd' module, above.
-#      etc_smbpasswd
-
-       #
-       #  If the users are logging in with an MS-CHAP-Challenge
-       #  attribute for authentication, the mschap module will find
-       #  the MS-CHAP-Challenge attribute, and add 'Auth-Type := MS-CHAP'
-       #  to the request, which will cause the server to then use
-       #  the mschap module for authentication.
-       mschap
-
-
-# The ldap module will set Auth-Type to LDAP if it has not already been set
-#      ldap
-#      daily
-}
-
-
-# Authentication.
-#
-#  This section lists which modules are available for authentication.
-#  Note that it does NOT mean 'try each module in order'.  It means
-#  that you have to have a module from the 'authorize' section add
-#  a configuration attribute 'Auth-Type := FOO'.  That authentication type
-#  is then used to pick the appropriate module from the list below.
-#
-#  The default Auth-Type is Local.  That is, whatever is not included inside
-# an authtype section will be called only if Auth-Type is set to Local.
-#
-# So you should do the following:
-# - Set Auth-Type to an appropriate value in the authorize modules above.
-#   For example, the chap module will set Auth-Type to CHAP, ldap to LDAP, etc.
-# - After that create corresponding authtype sections in the
-#   authenticate section below and call the appropriate modules.
-process Access-Request {
-       #
-       #  PAP authentication, when a back-end database listed
-       #  in the 'authorize' section supplies a password.  The
-       #  password can be clear-text, or encrypted.
-       Auth-Type PAP {
-               pap
-       }
-
-       #
-       #  Most people want CHAP authentication
-       #  A back-end database listed in the 'authorize' section
-       #  MUST supply a CLEAR TEXT password.  Encrypted passwords
-       #  won't work.
-       Auth-Type CHAP {
-               chap
-       }
-
-       #
-       #  MSCHAP authentication.
-       Auth-Type MS-CHAP {
-               mschap
-       }
-
-       #
-       #  If you have a Cisco SIP server authenticating against
-       #  FreeRADIUS, uncomment the following line.
-       # digest
-
-       #
-       #  Pluggable Authentication Modules.
-#      pam
-
-       #
-       #  See 'man getpwent' for information on how the 'unix'
-       #  module checks the users password.  Note that packets
-       #  containing CHAP-Password attributes CANNOT be authenticated
-       #  against /etc/passwd!  See the FAQ for details.
-       #
-       unix
-
-       # Uncomment it if you want to use ldap for authentication
-#      Auth-Type LDAP {
-#              ldap
-#      }
-
-
-       #
-       #  Allow EAP authentication.
-       eap
-}
-
-
-#
-#  Pre-accounting.  Decide which accounting type to use.
-#
-recv Accounting-Request {
-       preprocess
-
-       #
-       #  Look for IPASS-style 'realm/', and if not found, look for
-       #  '@realm', and decide whether or not to proxy, based on
-       #  that.
-       #
-       #  Accounting requests are generally proxied to the same
-       #  home server as authentication requests.
-#      realmslash
-       suffix
-
-       #
-       #  Read the 'acct_users' file
-       files
-}
-
-#
-#  Accounting.  Log the accounting data.
-#
-process Accounting-Request {
-       #
-       #  Ensure that we have a semi-unique identifier for every
-       #  request, and many NAS boxes are broken.
-       acct_unique
-
-       #
-       #  Create a 'detail'ed log of the packets.
-       #  Note that accounting requests which are proxied
-       #  are also logged in the detail file.
-       detail
-#      daily
-
-       unix            # wtmp file
-
-       #
-       #  For Simultaneous-Use tracking.
-       #
-       #  Due to packet losses in the network, the data here
-       #  may be incorrect.  There's little we can do about it.
-       radutmp
-#      sradutmp
-
-       #  Return an address to the IP Pool when we see a stop record.
-#      main_pool
-}
-
-
-#  Session database, used for checking Simultaneous-Use. Either the radutmp
-#  or rlm_sql module can handle this.
-#  The rlm_sql module is *much* faster
-session {
-       radutmp
-#      sql
-}
-
-
-#  Post-Authentication
-#  Once we KNOW that the user has been authenticated, there are
-#  additional steps we can take.
-post-auth {
-       #  Get an address from the IP Pool.
-#      main_pool
-}
-
-#
-#  When the server decides to proxy a request to a home server,
-#  the proxied request is first passed through the pre-proxy
-#  stage.  This stage can re-write the request, or decide to
-#  cancel the proxy.
-#
-#  Only a few modules currently have this method.
-#
-pre-proxy {
-}
-
-#
-#  When the server receives a reply to a request it proxied
-#  to a home server, the request may be massaged here, in the
-#  post-proxy stage.
-#
-post-proxy {
-       #
-       #  If you are proxing LEAP, you MUST configure the EAP
-       #  module, and you MUST list it here, in the post-proxy
-       #  stage.
-       #
-       #  You MUST also use the 'nostrip' option in the 'realm'
-       #  configuration.  Otherwise, the User-Name attribute
-       #  in the proxied request will not match the user name
-       #  hidden inside of the EAP packet, and the end server will
-       #  reject the EAP request.
-       #
-       eap
-}