Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Live login tests

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Live login tests


Chronological Thread 
  • From: Stefan Paetow <Stefan.Paetow AT jisc.ac.uk>
  • To: "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
  • Subject: Re: [[cat-users]] Live login tests
  • Date: Mon, 30 Aug 2021 13:22:53 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=hrYq2vIc+y7Pw7pBNVzLO9YQL4NN2kYOdrWfjs4HeWQ=; b=jLqU+d4Lvf+uX6CBv4QaCz6tVREXzBSyBjhvRZkpINm7jJCJKFS4IdQIMLpy3k1eORJBy+n3pOfXjbJv/dZQVbbV7JokniSsbNqZuntv86l1kP6GDGVzNWK+VsE4EwBLHAAVh+o4ecfNCdp5h0+RAUKhiT8SC9qnGtGTE/8hG2hd4aB285s8uNkcWiYoQrYA5sn7E1nXZpIRFTWNFOGPQk8DZr+74buafTEWlBkFhjO4cy7NGXbVW8leRDwBwBQVxEPNVapGkTjm8CisC/DcmeimRmdWw0Mvb+r7Aao2YOdlseNr8FmTjUVnQw0oF+3vhsV3bVA+BRKHTwvLsEyxMg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=CZyTzOuH+akCFkPoAM5lFaOqvu1fWF9EiTmtqJeeAu+twwxzSZaC2IeHb3ddjIMu0hqMgznVQ8u0jNLutwuqPB0GjiwYFqErSsvwFUkHL1apNHePZi0pSnWe0K0a0BVFVYKB/dUDDZb13JS0Kkqk2ODtNqMGyJWErJEPefiPEkzlbuzMeLCBzkkJqos6MY/XtP2s7mK8RpfOqg27ZB3O5T28e+RTsf6Npy3h9nxuJq+D1a/HZnhoyozftXM/YkizpJ9G0S2LIB+83043M6RGaRGe/Uo2lcPyInDCYRXYYDcEwGRa4lymmf0tCHwNPR6ty+LEZxS6CaCBoHy5POsHqg==
  • Authentication-results: lists.geant.org; dkim=none (message not signed) header.d=none;lists.geant.org; dmarc=none action=none header.from=jisc.ac.uk;

This sounds like a FreeRADIUS issue... maybe it’s file permissions (i.e. that root has access, but the radiusd user does not)?

 

Try to run the server as user radiusd (or on Debian, freerad). It’ll likely show any errors then since FreeRADIUS drops permissions.

 

Also, for FreeRADIUS issues, subscribe to the FreeRADIUS mailing lists at https://freeradius.org/support/

 

Stefan Paetow
Federated Roaming Technical Specialist


t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp AT jabber.dev.ja.net
skype: stefan.paetow.janet

In line with government advice, at Jisc we’re now working from home and our offices are currently closed. Read our statement on coronavirus.


jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under Company No. 5747339, VAT No. GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill, Bristol, BS2 0JA. T 0203 697 5800.

 

 

From: <cat-users-request AT lists.geant.org> on behalf of Johann Hugo <jhugo AT sanren.ac.za>
Reply to: Johann Hugo <jhugo AT sanren.ac.za>
Date: Friday, 27 August 2021 at 09:30
To: "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
Subject: [[cat-users]] Live login tests

 

Hi

 

I have a problem with live login tests to my idp in South Africa. I'm using freeradius-server:3.0.19 with Google ldap in the back end. 

 

Live login's work fine while freeradius runs in debug mode

 

Testing from: eduroamTL dk

Image removed by sender.TTLS-PAP – elapsed time: 4977 ms.

Connected to radius.sanren.ac.za.

Test successful.

 

Server certificate details:

Subject:

emailAddress=radius AT sanren.ac.za,CN=radius.sanren.ac.za,O=CSIR,ST=Gauteng,C=ZA

Issuer:

CN=radius.sanren.ac.za,emailAddress=radius AT sanren.ac.za,O=CSIR,L=Pretoria,ST=Gauteng,C=ZA

Valid from:

Wednesday, 25-Aug-2021 13:15:47 GMT

Valid to:

Tuesday, 28-Nov-2023 13:15:47 GMT

Serial number:

1 (0x1)

SHA1 fingerprint:

48cafdbb59068a72dfe743320e8f23cace948771

Extensions

extendedKeyUsage: TLS Web Server Authentication
crlDistributionPoints: Full Name: URI:http://www.sanren.ac.za/radius_ca.crl
certificatePolicies: Policy: 1.3.6.1.4.1.40808.1.3.2
basicConstraints: CA:FALSE
subjectAltName: DNS:radius.sanren.ac.za, othername:

 

but when I run freeradius without the -X, then live login tests from cat.eduroam.org fails. Local authentications + live login tests from our local federated monitoring system works fine. 

 

CAT error message:

TTLS-PAP – elapsed time: 4524 ms.

Connected to radius.sanren.ac.za.

Test FAILED: the request was rejected. The most likely cause is that you have misspelt the Username and/or the Password.

 

Server certificate details:

Subject:

emailAddress=radius AT sanren.ac.za,CN=radius.sanren.ac.za,O=CSIR,ST=Gauteng,C=ZA

Issuer:

CN=radius.sanren.ac.za,emailAddress=radius AT sanren.ac.za,O=CSIR,L=Pretoria,ST=Gauteng,C=ZA

Valid from:

Wednesday, 25-Aug-2021 13:15:47 GMT

Valid to:

Tuesday, 28-Nov-2023 13:15:47 GMT

Serial number:

1 (0x1)

SHA1 fingerprint:

48cafdbb59068a72dfe743320e8f23cace948771

Extensions

extendedKeyUsage: TLS Web Server Authentication
crlDistributionPoints: Full Name: URI:http://www.sanren.ac.za/radius_ca.crl
certificatePolicies: Policy: 1.3.6.1.4.1.40808.1.3.2
basicConstraints: CA:FALSE
subjectAltName: DNS:radius.sanren.ac.za, othername:

Any ideas where to search for this problem ?

 

Regards

Johann

 

 

To unsubscribe, send this message: mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users




Archive powered by MHonArc 2.6.19.

Top of Page