Initial commit
- update else condition on the line 239 in templates/Deployment - update st-common version from 0.1.10 to 0.1.12 on Chart.yaml file - add gitlab ci/cd pipeline to package the Helm chart into a .tgz. and Publish it to GitLab’s Helm package registry
This commit is contained in:
@@ -0,0 +1,41 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# Sample virtual server for receiving a CoA or Disconnect-Request packet.
|
||||
#
|
||||
|
||||
# Listen on the CoA port.
|
||||
#
|
||||
# This uses the normal set of clients, with the same secret as for authentication and accounting.
|
||||
#
|
||||
|
||||
listen {
|
||||
type = coa
|
||||
# ipaddr = $ENV{FREERADIUS_SITES_COA_LISTEN}
|
||||
ipaddr = *
|
||||
port = $ENV{FREERADIUS_SITES_COA_PORT}
|
||||
virtual_server = coa
|
||||
}
|
||||
|
||||
server coa {
|
||||
# When a packet is received, it is processed through the recv-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
|
||||
recv-coa {
|
||||
# CoA && Disconnect packets can be proxied in the same way as authentication or accounting packets.
|
||||
# Just set Proxy-To-Realm, or Home-Server-Pool, and the packets will be proxied.
|
||||
|
||||
# Do proxying based on realms here. You don't need "IPASS" or "ntdomain", as the proxying is based on the Operator-Name attribute. It contains the realm,
|
||||
# and ONLY the realm (prefixed by a '1')
|
||||
suffix
|
||||
|
||||
# Insert your own policies here.
|
||||
ok
|
||||
}
|
||||
|
||||
# When a packet is sent, it is processed through the send-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
|
||||
send-coa {
|
||||
# Sample module.
|
||||
ok
|
||||
}
|
||||
|
||||
# You can use pre-proxy and post-proxy sections here, too. They will be processed for sending && receiving proxy packets.
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,595 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# This is a virtual server that handles DHCP.
|
||||
#
|
||||
# See raddb/mods-available/dhcp_sqlippool for the IP Pool configuration.
|
||||
#
|
||||
# See raddb/policy.d/dhcp_sqlippool for the "glue" code that allows
|
||||
# the RADIUS based "sqlippool" module to be used for DHCP.
|
||||
#
|
||||
# See raddb/mods-config/sql/ippool/ for the schemas.
|
||||
#
|
||||
# See raddb/sites-available/dhcp for instructions on how to configure
|
||||
# the DHCP server.
|
||||
#
|
||||
# $Id$
|
||||
#
|
||||
######################################################################
|
||||
|
||||
#
|
||||
# The DHCP functionality goes into a virtual server.
|
||||
#
|
||||
server dhcp {
|
||||
|
||||
# Define a DHCP socket.
|
||||
#
|
||||
# The default port below is 6700, so you don't break your network.
|
||||
# If you want it to do real DHCP, change this to 67, and good luck!
|
||||
#
|
||||
# You can also bind the DHCP socket to an interface.
|
||||
# See below, and raddb/radiusd.conf for examples.
|
||||
#
|
||||
# This lets you run *one* DHCP server instance and have it listen on
|
||||
# multiple interfaces, each with a separate policy.
|
||||
#
|
||||
# If you have multiple interfaces, it is a good idea to bind the
|
||||
# listen section to an interface. You will also need one listen
|
||||
# section per interface.
|
||||
#
|
||||
# FreeBSD does *not* support binding sockets to interfaces. Therefore,
|
||||
# if you have multiple interfaces, broadcasts may go out of the wrong
|
||||
# one, or even all interfaces. The solution is to use the "setfib" command.
|
||||
# If you have a network "10.10.0/24" on LAN1, you will need to do:
|
||||
#
|
||||
# Pick any IP on the 10.10.0/24 network
|
||||
# $ setfib 1 route add default 10.10.0.1
|
||||
#
|
||||
# Edit /etc/rc.local, and add a line:
|
||||
# setfib 1 /path/to/radiusd
|
||||
#
|
||||
# The kern must be built with the following options:
|
||||
# options ROUTETABLES=2
|
||||
# or any value larger than 2.
|
||||
#
|
||||
# The other only solution is to update FreeRADIUS to use BPF sockets.
|
||||
#
|
||||
listen {
|
||||
# This is a dhcp socket.
|
||||
type = dhcp
|
||||
|
||||
# IP address to listen on. Will usually be the IP of the
|
||||
# interface, or 0.0.0.0
|
||||
ipaddr = 0.0.0.0
|
||||
|
||||
# source IP address for unicast packets sent by the
|
||||
# DHCP server.
|
||||
#
|
||||
# The source IP for unicast packets is chosen from the first
|
||||
# one of the following items which returns a valid IP
|
||||
# address:
|
||||
#
|
||||
# src_ipaddr
|
||||
# ipaddr
|
||||
# reply:DHCP-Server-IP-Address
|
||||
# reply:DHCP-DHCP-Server-Identifier
|
||||
#
|
||||
src_ipaddr = 127.0.0.1
|
||||
|
||||
# The port should be 67 for a production network. Don't set
|
||||
# it to 67 on a production network unless you really know
|
||||
# what you're doing. Even if nothing is configured below, the
|
||||
# server may still NAK legitimate responses from clients.
|
||||
port = 6700
|
||||
|
||||
# Interface name we are listening on. See comments above.
|
||||
# interface = lo0
|
||||
|
||||
# The DHCP server defaults to allowing broadcast packets.
|
||||
# Set this to "no" only when the server receives *all* packets
|
||||
# from a relay agent. i.e. when *no* clients are on the same
|
||||
# LAN as the DHCP server.
|
||||
#
|
||||
# It's set to "no" here for testing. It will usually want to
|
||||
# be "yes" in production, unless you are only dealing with
|
||||
# relayed packets.
|
||||
broadcast = no
|
||||
|
||||
# On Linux if you're running the server as non-root, you
|
||||
# will need to do:
|
||||
#
|
||||
# setcap cap_net_admin,cap_net_bind_service=eip /path/to/radiusd
|
||||
#
|
||||
# This will allow the server to set ARP table entries
|
||||
# for newly allocated IPs, when run as the "radius" user.
|
||||
#
|
||||
# The above "setcap" command adds the capability to the program,
|
||||
# usually so long as it is run by the "radius" user. Which means
|
||||
# (oddly enough) that it no longer works when run as root!
|
||||
#
|
||||
# When running the server as root in debug mode, you can use:
|
||||
#
|
||||
# capsh --caps="cap_setpcap,cap_setuid,cap_setgid,cap_net_admin,cap_net_bind_service+eip" --keep=1 --user=radius --addamb=cap_net_admin,cap_net_bind_service -- -c "/path/to/radiusd -X"
|
||||
#
|
||||
# Or, simply "sudo" or "su" to the "radius" user, and then run
|
||||
# the server in debug mode.
|
||||
|
||||
# De-duplicate DHCP packets. If clients don't receive
|
||||
# a reply within their timeout, most will re-transmit.
|
||||
# A reply to either packet will satisfy, so de-duplicating
|
||||
# helps manage load on a busy server
|
||||
performance {
|
||||
skip_duplicate_checks = no
|
||||
}
|
||||
}
|
||||
|
||||
# Packets received on the socket will be processed through one
|
||||
# of the following sections, named after the DHCP packet type.
|
||||
# See dictionary.dhcp for the packet types.
|
||||
|
||||
# Return packets will be sent to, in preference order:
|
||||
# DHCP-Gateway-IP-Address
|
||||
# DHCP-Client-IP-Address
|
||||
# DHCP-Your-IP-Address
|
||||
# At least one of these attributes should be set at the end of each
|
||||
# section for a response to be sent.
|
||||
|
||||
# An internal attribute of DHCP-Network-Subnet is set to provide
|
||||
# a basis for determining the network that a client belongs to. This
|
||||
# is a hierarchical assignment based on:
|
||||
#
|
||||
# - DHCP-Relay-Link-Selection
|
||||
# - DHCP-Subnet-Selection-Option
|
||||
# - DHCP-Gateway-IP-Address
|
||||
# - DHCP-Client-IP-Address
|
||||
#
|
||||
# Except for cases where all IP allocation is performed using a mapping from
|
||||
# the device MAC address to a fixed IP address the DHCP configuration will
|
||||
# involve the use of one or more pools.
|
||||
#
|
||||
# Each pool should be composed of a set of equally valid IP addresses for the
|
||||
# devices designated as users of the pool. During IP allocation the choice of
|
||||
# pool is driven by setting the Pool-Name attribute which may either be
|
||||
# specified directly or chosen (usually with the help of the dhcp_network
|
||||
# module) based on the initial value of DHCP-Network-Subnet.
|
||||
#
|
||||
# DHCP-Network-Subnet indicates the network from which the request is
|
||||
# originating. In cases where the originating network alone is insufficent to
|
||||
# define the required IP allocated policy, DHCP-Network-Subnet may be
|
||||
# overridden to force the selection of a particular pool.
|
||||
#
|
||||
# IP addresses belonging to a single pool that is designated for a Layer 2
|
||||
# network containing multiple subnets (a "shared-network" or "multinet"
|
||||
# configuration as defined by some other DHCP servers), will by definition be
|
||||
# members of distinct subnets that require their own DHCP reply parameters. In
|
||||
# this case the dhcp_subnet policy can be used to set the correct
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address options
|
||||
# based on the allocated IP.
|
||||
|
||||
dhcp DHCP-Discover {
|
||||
|
||||
# The DHCP Server Identifier is set here since is returned in OFFERs
|
||||
update control {
|
||||
&DHCP-DHCP-Server-Identifier = 192.0.2.2
|
||||
}
|
||||
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# If clients need to be assigned to a particular network based on
|
||||
# an attribute in the packet rather than the calculated
|
||||
# DHCP-Network-Subnet described above, then call a policy
|
||||
# (defined in policy.d/dhcp) to perform the override
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Do a simple mapping of MAC to assigned IP.
|
||||
#
|
||||
# See below for the definition of the "mac2ip"
|
||||
# module.
|
||||
#
|
||||
#mac2ip
|
||||
|
||||
# Or, allocate IPs from the DHCP pool in SQL. You may need to
|
||||
# set the pool name here if you haven't set it elsewhere.
|
||||
#update control {
|
||||
# &Pool-Name := "local"
|
||||
#}
|
||||
#dhcp_sqlippool
|
||||
|
||||
# If the IP address was not allocated, do something else.
|
||||
# You could call a Perl, Python, or Java script here.
|
||||
#if (notfound) {
|
||||
# ...
|
||||
#}
|
||||
|
||||
# "Shared-networks" may have multiple IP subnets co-existing in a
|
||||
# single Layer 2 network. If the pool for the network contains
|
||||
# addresses from more that one subnet then the setting subnet-specific
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
|
||||
# parameters must be performed after the allocation of the IP address.
|
||||
#
|
||||
# Set any subnet-specific parameters using this policy.
|
||||
#
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this.
|
||||
#
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# As an alternative or complement to configuration files based lookup
|
||||
# for options data you can instead use an SQL database. Example
|
||||
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
|
||||
# will need to be adapted to your requirements.
|
||||
#dhcp_policy_sql
|
||||
|
||||
# Set the type of packet to send in reply.
|
||||
#
|
||||
# The server will look at the DHCP-Message-Type attribute to
|
||||
# determine which type of packet to send in reply. Common
|
||||
# values would be DHCP-Offer, DHCP-Ack or DHCP-NAK. See
|
||||
# dictionary.dhcp for all the possible values.
|
||||
#
|
||||
# DHCP-Do-Not-Respond can be used to tell the server to not
|
||||
# respond.
|
||||
#
|
||||
# In the event that DHCP-Message-Type is not set then the
|
||||
# server will fall back to determining the type of reply
|
||||
# based on the rcode of this section.
|
||||
#
|
||||
#update reply {
|
||||
# DHCP-Message-Type = DHCP-Offer
|
||||
#}
|
||||
#
|
||||
# If DHCP-Message-Type is not set, returning "ok" or
|
||||
# "updated" from this section will respond with a DHCP-Offer
|
||||
# message.
|
||||
#
|
||||
# Other rcodes will tell the server to not return any response.
|
||||
#
|
||||
#ok
|
||||
}
|
||||
|
||||
dhcp DHCP-Request {
|
||||
|
||||
# You must set the DHCP Server Identifier here since this is returned
|
||||
# in ACKs and is used to determine whether a request containing a
|
||||
# "server-ip" field is intended for this server
|
||||
update control {
|
||||
&DHCP-DHCP-Server-Identifier = 192.0.2.2
|
||||
}
|
||||
|
||||
# If the request is not for this server then silently discard it
|
||||
if (&request:DHCP-DHCP-Server-Identifier && \
|
||||
&request:DHCP-DHCP-Server-Identifier != &control:DHCP-DHCP-Server-Identifier) {
|
||||
do_not_respond
|
||||
}
|
||||
|
||||
# Response packet type. See DHCP-Discover section above.
|
||||
#update reply {
|
||||
# &DHCP-Message-Type = DHCP-Ack
|
||||
#}
|
||||
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Do a simple mapping of MAC to assigned IP.
|
||||
#
|
||||
# See below for the definition of the "mac2ip"
|
||||
# module.
|
||||
#
|
||||
#mac2ip
|
||||
|
||||
# Or, allocate IPs from the DHCP pool in SQL. You may need to
|
||||
# set the pool name here if you haven't set it elsewhere.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_request
|
||||
|
||||
# If the IP was not allocated, do something else.
|
||||
# You could call a Perl, Python, or Java script here.
|
||||
#if (notfound) {
|
||||
# ...
|
||||
#}
|
||||
|
||||
# "Shared-networks" may have multiple IP subnets co-existing in a
|
||||
# single Layer 2 network. If the pool for the network contains
|
||||
# addresses from more that one subnet then the setting subnet-specific
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
|
||||
# parameters must be performed after the allocation of the IP address.
|
||||
#
|
||||
# Set any subnet-specific parameters using this policy.
|
||||
#
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# As an alternative or complement to configuration files based lookup
|
||||
# for options data you can instead use an SQL database. Example
|
||||
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
|
||||
# will need to be adapted to your requirements.
|
||||
#dhcp_policy_sql
|
||||
|
||||
# If DHCP-Message-Type is not set, returning "ok" or
|
||||
# "updated" from this section will respond with a DHCP-Ack
|
||||
# packet.
|
||||
#
|
||||
# "handled" will not return a packet, all other rcodes will
|
||||
# send back a DHCP-NAK.
|
||||
#
|
||||
#ok
|
||||
}
|
||||
|
||||
#
|
||||
# Other DHCP packet types
|
||||
#
|
||||
# There should be a separate section for each DHCP message type.
|
||||
# By default this configuration will ignore them all. Any packet type
|
||||
# not defined here will be responded to with a DHCP-NAK.
|
||||
|
||||
dhcp DHCP-Decline {
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple networks use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Use a policy that set options from data stored in an SQL database
|
||||
#dhcp_policy_sql
|
||||
|
||||
# If using IPs from a DHCP pool in SQL then you may need to set the
|
||||
# pool name here if you haven't set it elsewhere and release the IP.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_decline
|
||||
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Do-Not-Respond
|
||||
}
|
||||
reject
|
||||
}
|
||||
|
||||
#
|
||||
# A dummy config for Inform packets - this should match the
|
||||
# options set in the Request section above, except Inform replies
|
||||
# must not set Your-IP-Address or IP-Address-Lease-Time
|
||||
#
|
||||
dhcp DHCP-Inform {
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and network options
|
||||
# For multiple networks use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Use a policy with calls a "files" module of the same name to lookup
|
||||
# subnet options
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# Use a policy that set options from data stored in an SQL database
|
||||
#dhcp_policy_sql
|
||||
|
||||
ok
|
||||
}
|
||||
|
||||
#
|
||||
# For Windows 7 boxes
|
||||
#
|
||||
#dhcp DHCP-Inform {
|
||||
# update reply {
|
||||
# Packet-Dst-Port = 67
|
||||
# DHCP-Message-Type = DHCP-ACK
|
||||
# DHCP-DHCP-Server-Identifier = "%{Packet-Dst-IP-Address}"
|
||||
# DHCP-Site-specific-28 = 0x0a00
|
||||
# }
|
||||
# ok
|
||||
#}
|
||||
|
||||
dhcp DHCP-Release {
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# If using IPs from a DHCP pool in SQL then you may need to set the
|
||||
# pool name here if you haven't set it elsewhere and release the IP.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_release
|
||||
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Do-Not-Respond
|
||||
}
|
||||
reject
|
||||
}
|
||||
|
||||
|
||||
dhcp DHCP-Lease-Query {
|
||||
# The thing being queried for is implicit
|
||||
# in the packets.
|
||||
|
||||
# has MAC, asking for IP, etc.
|
||||
if (&DHCP-Client-Hardware-Address) {
|
||||
# look up MAC in database
|
||||
}
|
||||
|
||||
# has IP, asking for MAC, etc.
|
||||
elsif (&DHCP-Your-IP-Address) {
|
||||
# look up IP in database
|
||||
}
|
||||
|
||||
# has host name, asking for IP, MAC, etc.
|
||||
elsif (&DHCP-Client-Identifier) {
|
||||
# look up identifier in database
|
||||
}
|
||||
else {
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unknown
|
||||
}
|
||||
|
||||
ok
|
||||
|
||||
# stop processing
|
||||
return
|
||||
}
|
||||
|
||||
#
|
||||
# We presume that the database lookup returns "notfound"
|
||||
# if it can't find anything.
|
||||
#
|
||||
if (notfound) {
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unknown
|
||||
}
|
||||
ok
|
||||
return
|
||||
}
|
||||
|
||||
#
|
||||
# Add more logic here. Is the lease inactive?
|
||||
# If so, respond with DHCP-Lease-Unassigned.
|
||||
#
|
||||
# Otherwise, respond with DHCP-Lease-Active
|
||||
#
|
||||
|
||||
#
|
||||
# Also be sure to return ALL information about
|
||||
# the lease.
|
||||
#
|
||||
|
||||
#
|
||||
# The reply types are:
|
||||
#
|
||||
# DHCP-Lease-Unknown
|
||||
# DHCP-Lease-Active
|
||||
# DHCP-Lease-Unassigned
|
||||
#
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unassigned
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
######################################################################
|
||||
#
|
||||
# This next section is a sample configuration for the "passwd"
|
||||
# module, that reads flat-text files. It should go into
|
||||
# radiusd.conf, in the "modules" section.
|
||||
#
|
||||
# The file is in the format <mac>,<ip>
|
||||
#
|
||||
# 00:01:02:03:04:05,192.0.2.100
|
||||
# 01:01:02:03:04:05,192.0.2.101
|
||||
# 02:01:02:03:04:05,192.0.2.102
|
||||
#
|
||||
# This lets you perform simple static IP assignment.
|
||||
#
|
||||
# There is a preconfigured "mac2ip" module setup in
|
||||
# mods-available/mac2ip. To use it do:
|
||||
#
|
||||
# # cd raddb/
|
||||
# # ln -s ../mods-available/mac2ip mods-enabled/mac2ip
|
||||
# # mkdir mods-config/passwd
|
||||
#
|
||||
# Then create the file mods-config/passwd/mac2ip with the above
|
||||
# format.
|
||||
#
|
||||
######################################################################
|
||||
|
||||
|
||||
# This is an example only - see mods-available/mac2ip instead; do
|
||||
# not uncomment these lines here.
|
||||
#
|
||||
#passwd mac2ip {
|
||||
# filename = ${confdir}/mac2ip
|
||||
# format = "*DHCP-Client-Hardware-Address:=DHCP-Your-IP-Address"
|
||||
# delimiter = ","
|
||||
#}
|
||||
@@ -0,0 +1,126 @@
|
||||
######################################################################
|
||||
#
|
||||
# This is a virtual server that handles *only* inner tunnel
|
||||
# requests for EAP-TTLS and PEAP types.
|
||||
#
|
||||
######################################################################
|
||||
|
||||
server inner-tunnel {
|
||||
|
||||
listen {
|
||||
ipaddr = 127.0.0.1
|
||||
port = 18120
|
||||
type = auth
|
||||
}
|
||||
|
||||
authorize {
|
||||
filter_username
|
||||
# filter_inner_identity
|
||||
chap
|
||||
mschap
|
||||
# unix
|
||||
# IPASS
|
||||
suffix
|
||||
# ntdomain
|
||||
|
||||
update control {
|
||||
&Proxy-To-Realm := LOCAL
|
||||
}
|
||||
|
||||
eap {
|
||||
ok = return
|
||||
}
|
||||
|
||||
files
|
||||
-sql
|
||||
# smbpasswd
|
||||
-ldap
|
||||
# daily
|
||||
expiration
|
||||
logintime
|
||||
pap
|
||||
}
|
||||
|
||||
authenticate {
|
||||
Auth-Type PAP {
|
||||
pap
|
||||
}
|
||||
|
||||
Auth-Type CHAP {
|
||||
chap
|
||||
}
|
||||
|
||||
Auth-Type MS-CHAP {
|
||||
mschap
|
||||
}
|
||||
|
||||
mschap
|
||||
# pam
|
||||
|
||||
# Auth-Type LDAP {
|
||||
# ldap
|
||||
# }
|
||||
|
||||
eap
|
||||
}
|
||||
|
||||
session {
|
||||
radutmp
|
||||
# sql
|
||||
}
|
||||
|
||||
# Post-Authentication
|
||||
post-auth {
|
||||
# cui-inner
|
||||
|
||||
# update outer.session-state {
|
||||
# User-Name := &User-Name
|
||||
# }
|
||||
|
||||
# reply_log
|
||||
-sql
|
||||
# ldap
|
||||
# moonshot_host_tid
|
||||
# moonshot_realm_tid
|
||||
# moonshot_coi_tid
|
||||
|
||||
if (0) {
|
||||
update reply {
|
||||
User-Name !* ANY
|
||||
Message-Authenticator !* ANY
|
||||
EAP-Message !* ANY
|
||||
Proxy-State !* ANY
|
||||
MS-MPPE-Encryption-Types !* ANY
|
||||
MS-MPPE-Encryption-Policy !* ANY
|
||||
MS-MPPE-Send-Key !* ANY
|
||||
MS-MPPE-Recv-Key !* ANY
|
||||
}
|
||||
|
||||
update {
|
||||
&outer.session-state: += &reply:
|
||||
}
|
||||
}
|
||||
|
||||
Post-Auth-Type REJECT {
|
||||
-sql
|
||||
attr_filter.access_reject
|
||||
|
||||
update outer.session-state {
|
||||
&Module-Failure-Message := &request:Module-Failure-Message
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pre-proxy {
|
||||
# files
|
||||
# attr_filter.pre-proxy
|
||||
# pre_proxy_log
|
||||
}
|
||||
|
||||
post-proxy {
|
||||
# post_proxy_log
|
||||
# attr_filter.post-proxy
|
||||
eap
|
||||
}
|
||||
|
||||
} # inner-tunnel server block
|
||||
@@ -0,0 +1,126 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# A virtual server to handle ONLY Status-Server packets.
|
||||
#
|
||||
# Server statistics can be queried with a properly formatted
|
||||
# Status-Server request. See dictionary.freeradius for comments.
|
||||
#
|
||||
# If radiusd.conf has "status_server = yes", then any client
|
||||
# will be able to send a Status-Server packet to any port
|
||||
# (listen section type "auth", "acct", or "status"), and the
|
||||
# server will respond.
|
||||
#
|
||||
# If radiusd.conf has "status_server = no", then the server will
|
||||
# ignore Status-Server packets to "auth" and "acct" ports. It
|
||||
# will respond only if the Status-Server packet is sent to a
|
||||
# "status" port.
|
||||
#
|
||||
# The server statistics are available ONLY on socket of type
|
||||
# "status". Queries for statistics sent to any other port
|
||||
# are ignored.
|
||||
#
|
||||
# Similarly, a socket of type "status" will not process
|
||||
# authentication or accounting packets. This is for security.
|
||||
#
|
||||
# $Id: e7d4346310b837d56bffe4c991b4e5680742ebc0 $
|
||||
#
|
||||
######################################################################
|
||||
|
||||
server status {
|
||||
listen {
|
||||
# ONLY Status-Server is allowed to this port.
|
||||
# ALL other packets are ignored.
|
||||
type = status
|
||||
|
||||
ipaddr = $ENV{FREERADIUS_SITES_STATUS_LISTEN}
|
||||
port = $ENV{FREERADIUS_SITES_STATUS_PORT}
|
||||
}
|
||||
|
||||
#
|
||||
# We recommend that you list ONLY management clients here.
|
||||
# i.e. NOT your NASes or Access Points, and for an ISP,
|
||||
# DEFINITELY not any RADIUS servers that are proxying packets
|
||||
# to you.
|
||||
#
|
||||
# If you do NOT list a client here, then any client that is
|
||||
# globally defined (i.e. all of them) will be able to query
|
||||
# these statistics.
|
||||
#
|
||||
# Do you really want your partners seeing the internal details
|
||||
# of what your RADIUS server is doing?
|
||||
#
|
||||
client admin {
|
||||
ipaddr = 127.0.0.1
|
||||
secret = $ENV{FREERADIUS_SITES_STATUS_SECRET}
|
||||
}
|
||||
|
||||
# Simple authorize section. The "Autz-Type Status-Server"
|
||||
# section will work here, too. See "raddb/sites-available/default".
|
||||
authorize {
|
||||
ok
|
||||
|
||||
# respond to the Status-Server request.
|
||||
Autz-Type Status-Server {
|
||||
ok
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Statistics can be queried via a number of methods:
|
||||
#
|
||||
# All packets received/sent by the server (1 = auth, 2 = acct)
|
||||
# FreeRADIUS-Statistics-Type = 3
|
||||
#
|
||||
# All packets proxied by the server (4 = proxy-auth, 8 = proxy-acct)
|
||||
# FreeRADIUS-Statistics-Type = 12
|
||||
#
|
||||
# All packets sent && received:
|
||||
# FreeRADIUS-Statistics-Type = 15
|
||||
#
|
||||
# Internal server statistics:
|
||||
# FreeRADIUS-Statistics-Type = 16
|
||||
#
|
||||
# All packets for a particular client (globally defined)
|
||||
# FreeRADIUS-Statistics-Type = 35
|
||||
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
|
||||
#
|
||||
# All packets for a client attached to a "listen" ip/port
|
||||
# FreeRADIUS-Statistics-Type = 35
|
||||
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
#
|
||||
# All packets for a "listen" IP/port
|
||||
# FreeRADIUS-Statistics-Type = 67
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
#
|
||||
# All packets for a home server IP / port
|
||||
# FreeRADIUS-Statistics-Type = 131
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 192.0.2.2
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
|
||||
#
|
||||
# You can also get exponentially weighted moving averages of
|
||||
# response times (in usec) of home servers. Just set the config
|
||||
# item "historic_average_window" in a home_server section.
|
||||
#
|
||||
# By default it is zero (don't calculate it). Useful values
|
||||
# are between 100, and 10,000. The server will calculate and
|
||||
# remember the moving average for this window, and for 10 times
|
||||
# that window.
|
||||
#
|
||||
|
||||
#
|
||||
# Some of this could have been simplified. e.g. the proxy-auth and
|
||||
# proxy-acct bits aren't completely necessary. But using them permits
|
||||
# the server to be queried for ALL inbound && outbound packets at once.
|
||||
# This gives a good snapshot of what the server is doing.
|
||||
#
|
||||
# Due to internal limitations, the statistics might not be exactly up
|
||||
# to date. Do not expect all of the numbers to add up perfectly.
|
||||
# The Status-Server packets are also counted in the total requests &&
|
||||
# responses. The responses are counted only AFTER the response has
|
||||
# been sent.
|
||||
#
|
||||
@@ -0,0 +1,603 @@
|
||||
######################################################################
|
||||
#
|
||||
# RADIUS over TLS (radsec)
|
||||
#
|
||||
# When a new client connects, the various TLS parameters for the
|
||||
# connection are available as dynamic expansions, e.g.
|
||||
#
|
||||
# %{listen:TLS-Client-Cert-Common-Name}
|
||||
#
|
||||
# Along with other TLS-Client-Cert-... attributes.
|
||||
# These expansions will only exist if the relevant fields
|
||||
# are in the client certificate. Read the debug output to see
|
||||
# which fields are available. Look for output like the following:
|
||||
#
|
||||
# (0) TLS - Creating attributes from certificate OIDs
|
||||
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "one.example.org"
|
||||
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "two.example.org"
|
||||
# ...
|
||||
#
|
||||
# It is also possible to distinguish between connections which have
|
||||
# TLS enables, and ones which do not. The expansion:
|
||||
#
|
||||
# %{listen:tls}
|
||||
#
|
||||
# Will return "yes" if the connection has TLS enabled. It will
|
||||
# return "no" if TLS is not enabled for a particular listen section.
|
||||
#
|
||||
# A number of TLS-Client-Cert-.. attributes holds X509v3 extensions
|
||||
# data, attributes named the way OpenSSL names them. It is possible
|
||||
# to extract data for an extension not known to OpenSSL by defining
|
||||
# a custom string attribute which contains extension OID in it's
|
||||
# name after 'TLS-Client-Cert-' prefix. E.g.:
|
||||
#
|
||||
# ATTRIBUTE TLS-Client-Cert-1.3.6.1.4.1.311.21.7 3002 string
|
||||
#
|
||||
# which will yield something simmilar to:
|
||||
#
|
||||
# (0) eap_tls: TLS - Creating attributes from certificate OIDs
|
||||
# (0) eap_tls: TLS-Client-Cert-1.3.6.1.4.1.311.21.7 += "0x302e06"
|
||||
# ...
|
||||
#
|
||||
######################################################################
|
||||
|
||||
listen {
|
||||
|
||||
# ipaddr = $ENV{FREERADIUS_SITES_TLS_LISTEN}
|
||||
ipaddr = *
|
||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
||||
|
||||
#
|
||||
# TCP and TLS sockets can accept Access-Request and Accounting-Request on the same socket.
|
||||
#
|
||||
# auth = only Access-Request
|
||||
# acct = only Accounting-Request
|
||||
# auth+acct = both
|
||||
# coa = only CoA / Disconnect requests
|
||||
#
|
||||
type = auth+acct
|
||||
|
||||
# For now, only TCP transport is allowed.
|
||||
proto = tcp
|
||||
|
||||
# Send packets to the default virtual server
|
||||
virtual_server = default
|
||||
|
||||
clients = radsec
|
||||
|
||||
# Use the haproxy "PROXY protocol".
|
||||
#
|
||||
# This configuration allows for many FreeRADIUS servers to be behind a haproxy server. The "PROXY protocol" allows haproxy to send the actual client IP to FreeRADIUS.
|
||||
#
|
||||
# This will work ONLY for RadSec (TLS). Both the haproxy AND the RadSec client MUST be listed as allowed RADIUS clients.
|
||||
#
|
||||
# haproxy needs to have "send-proxy" configured for this server. Health checks should be turned off, as haproxy does not support RADIUS health checks.
|
||||
#
|
||||
# The main use of this feature is for scalability. There is no longer any need to have a RADIUS proxy as a load balancer.
|
||||
# haproxy is fast, stable, and supports dynamic reloads!
|
||||
#
|
||||
# The only problem is that many RADIUS clients do not support RadSec. That situation will hopefully change over time.
|
||||
#
|
||||
# proxy_protocol = no
|
||||
|
||||
# When this is set to "yes", new TLS connections are processed through a section called
|
||||
#
|
||||
# Autz-Type New-TLS-Connection {
|
||||
# ...
|
||||
# }
|
||||
#
|
||||
# The request contains TLS client certificate attributes,
|
||||
# and nothing else. The debug output will print which
|
||||
# attributes are available on your system.
|
||||
#
|
||||
# If the section returns "ok" or "updated", then the
|
||||
# connection is accepted. Otherwise the connection is
|
||||
# terminated.
|
||||
#
|
||||
# check_client_connections = yes
|
||||
|
||||
#
|
||||
# Connection limiting for sockets with "proto = tcp".
|
||||
#
|
||||
limit {
|
||||
# Limit the number of simultaneous TCP connections to the socket
|
||||
#
|
||||
# The default is 16.
|
||||
# Setting this to 0 means "no limit"
|
||||
max_connections = 16
|
||||
|
||||
# The per-socket "max_requests" option does not exist.
|
||||
|
||||
# The lifetime, in seconds, of a TCP connection. After this lifetime, the connection will be closed.
|
||||
#
|
||||
# Setting this to 0 means "forever".
|
||||
lifetime = 0
|
||||
|
||||
# The idle timeout, in seconds, of a TCP connection. If no packets have been received over the connection for this time, the connection will be closed.
|
||||
#
|
||||
# Setting this to 0 means "no timeout".
|
||||
# We STRONGLY RECOMMEND that you set an idle timeout.
|
||||
#
|
||||
idle_timeout = 30
|
||||
}
|
||||
|
||||
# This is *exactly* the same configuration as used by the EAP-TLS
|
||||
# module. It's OK for testing, but for production use it's a good
|
||||
# idea to use different server certificates for EAP and for RADIUS
|
||||
# transport.
|
||||
#
|
||||
# If you want only one TLS configuration for multiple sockets,
|
||||
# then we suggest putting "tls { ...}" into radiusd.conf.
|
||||
# The subsection below can then be changed into a reference:
|
||||
#
|
||||
# tls = ${tls}
|
||||
#
|
||||
# Which means "the tls sub-section is not here, but instead is in
|
||||
# the top-level section called 'tls'".
|
||||
#
|
||||
# If you have multiple tls configurations, you can put them into
|
||||
# sub-sections of a top-level "tls" section. There's no need to
|
||||
# call them all "tls". You can then use:
|
||||
#
|
||||
# tls = ${tls.site1}
|
||||
#
|
||||
# to refer to the "site1" sub-section of the "tls" section.
|
||||
#
|
||||
tls {
|
||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
||||
|
||||
# Accept an expired Certificate Revocation List
|
||||
# allow_expired_crl = no
|
||||
|
||||
# If Private key & Certificate are located in
|
||||
# the same file, then private_key_file &
|
||||
# certificate_file must contain the same file
|
||||
# name.
|
||||
#
|
||||
# If ca_file (below) is not used, then the
|
||||
# certificate_file below MUST include not
|
||||
# only the server certificate, but ALSO all
|
||||
# of the CA certificates used to sign the
|
||||
# server certificate.
|
||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
||||
|
||||
|
||||
# Trusted Root CA list
|
||||
#
|
||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
||||
#
|
||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
||||
# In that case, this CA file should contain *one* CA certificate.
|
||||
#
|
||||
# This parameter is used only for EAP-TLS, when you issue client certificates. If you do not use client certificates, and you do not want
|
||||
# to permit EAP-TLS authentication, then delete this configuration item.
|
||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
||||
|
||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
||||
#
|
||||
# openssl dhparam -out certs/dh 1024
|
||||
#
|
||||
# dh_file = ${certdir}/dh
|
||||
|
||||
#
|
||||
# If your system doesn't have /dev/urandom,
|
||||
# you will need to create this file, and
|
||||
# periodically change its contents.
|
||||
#
|
||||
# For security reasons, FreeRADIUS doesn't
|
||||
# write to files in its configuration
|
||||
# directory.
|
||||
#
|
||||
# random_file = /dev/urandom
|
||||
|
||||
#
|
||||
# The default fragment size is 1K.
|
||||
# However, it's possible to send much more data than
|
||||
# that over a TCP connection. The upper limit is 64K.
|
||||
# Setting the fragment size to more than 1K means that
|
||||
# there are fewer round trips when setting up a TLS
|
||||
# connection. But only if the certificates are large.
|
||||
#
|
||||
fragment_size = 8192
|
||||
|
||||
# include_length is a flag which is
|
||||
# by default set to yes If set to
|
||||
# yes, Total Length of the message is
|
||||
# included in EVERY packet we send.
|
||||
# If set to no, Total Length of the
|
||||
# message is included ONLY in the
|
||||
# First packet of a fragment series.
|
||||
#
|
||||
# include_length = yes
|
||||
|
||||
# Check the Certificate Revocation List
|
||||
#
|
||||
# 1) Copy CA certificates and CRLs to same directory.
|
||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
||||
# 'c_rehash' is OpenSSL's command.
|
||||
# 3) uncomment the line below.
|
||||
# 5) Restart radiusd
|
||||
# check_crl = yes
|
||||
ca_path = ${cadir}
|
||||
|
||||
# OpenSSL does not reload contents of ca_path dir over time.
|
||||
# That means that if check_crl is enabled and CRLs are loaded
|
||||
# from ca_path dir, at some point CRLs will expire and
|
||||
# RADIUSd will stop authenticating NASes.
|
||||
# If ca_path_reload_interval is non-zero, it will force OpenSSL
|
||||
# to reload all data from ca_path periodically
|
||||
#
|
||||
# Flush ca_path each hour
|
||||
ca_path_reload_interval = 3600
|
||||
|
||||
#
|
||||
# If check_cert_issuer is set, the value will
|
||||
# be checked against the DN of the issuer in
|
||||
# the client certificate. If the values do not
|
||||
# match, the certificate verification will fail,
|
||||
# rejecting the user.
|
||||
#
|
||||
# This check can be done more generally by checking
|
||||
# the value of the TLS-Client-Cert-Issuer attribute.
|
||||
# This check can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
||||
|
||||
#
|
||||
# If check_cert_cn is set, the value will
|
||||
# be xlat'ed and checked against the CN
|
||||
# in the client certificate. If the values
|
||||
# do not match, the certificate verification
|
||||
# will fail rejecting the user.
|
||||
#
|
||||
# This check is done only if the previous
|
||||
# "check_cert_issuer" is not set, or if
|
||||
# the check succeeds.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Common-Name attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_cn = %{User-Name}
|
||||
#
|
||||
# Set this option to specify the allowed
|
||||
# TLS cipher suites. The format is listed
|
||||
# in "man 1 ciphers".
|
||||
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
|
||||
|
||||
# If enabled, OpenSSL will use server cipher list
|
||||
# (possibly defined by cipher_list option above)
|
||||
# for choosing right cipher suite rather than
|
||||
# using client-specified list which is OpenSSl default
|
||||
# behavior. Having it set to yes is a current best practice
|
||||
# for TLS
|
||||
cipher_server_preference = no
|
||||
|
||||
#
|
||||
# Older TLS versions are deprecated. But for RadSec,
|
||||
# we CAN allow TLS 1.3.
|
||||
#
|
||||
tls_min_version = "1.2"
|
||||
tls_max_version = "1.3"
|
||||
|
||||
#
|
||||
# Session resumption / fast reauthentication cache.
|
||||
#
|
||||
# The cache contains the following information:
|
||||
#
|
||||
# session Id - unique identifier, managed by SSL
|
||||
# User-Name - from the Access-Accept
|
||||
# Stripped-User-Name - from the Access-Request
|
||||
# Cached-Session-Policy - from the Access-Accept
|
||||
#
|
||||
# The "Cached-Session-Policy" is the name of a
|
||||
# policy which should be applied to the cached
|
||||
# session. This policy can be used to assign
|
||||
# VLANs, IP addresses, etc. It serves as a useful
|
||||
# way to re-apply the policy from the original
|
||||
# Access-Accept to the subsequent Access-Accept
|
||||
# for the cached session.
|
||||
#
|
||||
# On session resumption, these attributes are
|
||||
# copied from the cache, and placed into the
|
||||
# reply list.
|
||||
#
|
||||
# You probably also want "use_tunneled_reply = yes" when using fast session resumption.
|
||||
#
|
||||
cache {
|
||||
#
|
||||
# Enable it. The default is "no".
|
||||
# Deleting the entire "cache" subsection
|
||||
# Also disables caching.
|
||||
#
|
||||
#
|
||||
# As of version 3.0.14, the session cache requires the use
|
||||
# of the "name" and "persist_dir" configuration items, below.
|
||||
#
|
||||
# The internal OpenSSL session cache has been permanently
|
||||
# disabled.
|
||||
#
|
||||
# You can disallow resumption for a
|
||||
# particular user by adding the following
|
||||
# attribute to the control item list:
|
||||
#
|
||||
# Allow-Session-Resumption = No
|
||||
#
|
||||
# If "enable = no" below, you CANNOT
|
||||
# enable resumption for just one user
|
||||
# by setting the above attribute to "yes".
|
||||
#
|
||||
enable = no
|
||||
|
||||
#
|
||||
# Lifetime of the cached entries, in hours.
|
||||
# The sessions will be deleted after this
|
||||
# time.
|
||||
#
|
||||
lifetime = 24 # hours
|
||||
|
||||
#
|
||||
# Internal "name" of the session cache.
|
||||
# Used to distinguish which TLS context
|
||||
# sessions belong to.
|
||||
#
|
||||
# The server will generate a random value
|
||||
# if unset. This will change across server
|
||||
# restart so you MUST set the "name" if you
|
||||
# want to persist sessions (see below).
|
||||
#
|
||||
# If you use IPv6, change the "ipaddr" below
|
||||
# to "ipv6addr"
|
||||
#
|
||||
#name = "TLS ${..ipaddr} ${..port} ${..proto}"
|
||||
|
||||
#
|
||||
# Simple directory-based storage of sessions.
|
||||
# Two files per session will be written, the SSL
|
||||
# state and the cached VPs. This will persist session
|
||||
# across server restarts.
|
||||
#
|
||||
# The server will need write perms, and the directory
|
||||
# should be secured from anyone else. You might want
|
||||
# a script to remove old files from here periodically:
|
||||
#
|
||||
# find ${logdir}/tlscache -mtime +2 -exec rm -f {} \;
|
||||
#
|
||||
# This feature REQUIRES "name" option be set above.
|
||||
#
|
||||
#persist_dir = "${logdir}/tlscache"
|
||||
}
|
||||
|
||||
#
|
||||
# Require a client certificate.
|
||||
#
|
||||
require_client_cert = yes
|
||||
|
||||
#
|
||||
# As of version 2.1.10, client certificates can be
|
||||
# validated via an external command. This allows
|
||||
# dynamic CRLs or OCSP to be used.
|
||||
#
|
||||
# This configuration is commented out in the
|
||||
# default configuration. Uncomment it, and configure
|
||||
# the correct paths below to enable it.
|
||||
#
|
||||
verify {
|
||||
# A temporary directory where the client
|
||||
# certificates are stored. This directory
|
||||
# MUST be owned by the UID of the server,
|
||||
# and MUST not be accessible by any other
|
||||
# users. When the server starts, it will do
|
||||
# "chmod go-rwx" on the directory, for
|
||||
# security reasons. The directory MUST
|
||||
# exist when the server starts.
|
||||
#
|
||||
# You should also delete all of the files
|
||||
# in the directory when the server starts.
|
||||
# tmpdir = /tmp/radiusd
|
||||
# tmpdir = /startechnica/freeradius/tmp
|
||||
|
||||
# The command used to verify the client cert.
|
||||
# We recommend using the OpenSSL command-line
|
||||
# tool.
|
||||
#
|
||||
# The ${..ca_path} text is a reference to
|
||||
# the ca_path variable defined above.
|
||||
#
|
||||
# The %{TLS-Client-Cert-Filename} is the name
|
||||
# of the temporary file containing the cert
|
||||
# in PEM format. This file is automatically
|
||||
# deleted by the server when the command
|
||||
# returns.
|
||||
# client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
clients radsec {
|
||||
client 127.0.0.1 {
|
||||
ipaddr = 127.0.0.1
|
||||
|
||||
# Ensure that this client is TLS *only*.
|
||||
proto = tls
|
||||
|
||||
# TCP clients can have any shared secret.
|
||||
# TLS clients MUST have the shared secret set to "radsec". Or, for "proto = tls", you can omit the secret, and it will
|
||||
# automatically be set to "radsec".
|
||||
# secret = radsec
|
||||
secret = $ENV{FREERADIUS_CLIENTS_SECRET}
|
||||
|
||||
# You can also use a "limit" section here.
|
||||
# See raddb/clients.conf for examples.
|
||||
#
|
||||
# Note that BOTH limits are applied. You should therefore set the "listen" limits higher than the ones for each individual
|
||||
# client.
|
||||
}
|
||||
}
|
||||
|
||||
# When a request is proxied to a TLS-enabled home server, the TLS parameters are available via the expansion:
|
||||
#
|
||||
# %{proxy_listen: ... }
|
||||
#
|
||||
# The contents of the expansion are the same as described above with the %{listen: ... } expansion, and have similar meanings. "client" in this case is the proxy (this system)
|
||||
# and "server" is the remote system (home server).
|
||||
#
|
||||
# Note that the %{proxy_listen: ... } parameters are available only AFTER the connection has been made to the home server.
|
||||
home_server tls {
|
||||
ipaddr = 127.0.0.1
|
||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
||||
|
||||
# type can be the same types as for the "listen" section/
|
||||
# e.g. auth, acct, auth+acct, coa
|
||||
type = auth
|
||||
secret = radsec
|
||||
proto = tcp
|
||||
status_check = none
|
||||
|
||||
tls {
|
||||
#
|
||||
# Similarly to HTTP, the client can use Server Name
|
||||
# Indication to inform the RadSec server of which
|
||||
# domain it is requesting. This selection allows
|
||||
# multiple sites to exist at the same IP address.
|
||||
#
|
||||
# For example, and identity provider could host
|
||||
# multiple sites, but present itself with one public
|
||||
# IP address.
|
||||
#
|
||||
# SNI also permits the use of a load balancer such as
|
||||
# haproxy. That load balancer can terminate the TLS
|
||||
# connection, and then use SNI to route the
|
||||
# underlying RADIUS TCP traffic to a particular host.
|
||||
#
|
||||
# Note that "hostname" here is only for SNI, and is NOT
|
||||
# the hostname or IP address we connect to. For that,
|
||||
# see "ipaddr", above.
|
||||
#
|
||||
# hostname = "example.com"
|
||||
|
||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
||||
# private_key_file = ${certdir}/client.pem
|
||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
||||
|
||||
# If Private key & Certificate are located in
|
||||
# the same file, then private_key_file &
|
||||
# certificate_file must contain the same file
|
||||
# name.
|
||||
#
|
||||
# If ca_file (below) is not used, then the
|
||||
# certificate_file below MUST include not
|
||||
# only the server certificate, but ALSO all
|
||||
# of the CA certificates used to sign the
|
||||
# server certificate.
|
||||
# certificate_file = ${certdir}/client.pem
|
||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
||||
|
||||
# Trusted Root CA list
|
||||
#
|
||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
||||
#
|
||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
||||
# In that case, this CA file should contain *one* CA certificate.
|
||||
#
|
||||
# This parameter is used only for EAP-TLS,
|
||||
# when you issue client certificates. If you do
|
||||
# not use client certificates, and you do not want
|
||||
# to permit EAP-TLS authentication, then delete
|
||||
# this configuration item.
|
||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
||||
|
||||
#
|
||||
# For TLS-PSK, the key should be specified dynamically, instead of using a hard-coded psk_identity and psk_hexphrase.
|
||||
#
|
||||
# The input to the dynamic expansion will be the PSK
|
||||
# identity supplied by the client, in the
|
||||
# TLS-PSK-Identity attribute. The output of the
|
||||
# expansion should be a hex string, of no more than
|
||||
# 512 characters. The string should not be prefixed
|
||||
# with "0x". e.g. "abcdef" is OK. "0xabcdef" is not.
|
||||
#
|
||||
# psk_query = "%{psksql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
|
||||
|
||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
||||
#
|
||||
# openssl dhparam -out certs/dh 1024
|
||||
#
|
||||
dh_file = ${certdir}/dh
|
||||
random_file = /dev/urandom
|
||||
|
||||
#
|
||||
# The default fragment size is 1K.
|
||||
# However, TLS can send 64K of data at once.
|
||||
# It can be useful to set it higher.
|
||||
#
|
||||
fragment_size = 8192
|
||||
|
||||
# include_length is a flag which is
|
||||
# by default set to yes If set to
|
||||
# yes, Total Length of the message is
|
||||
# included in EVERY packet we send.
|
||||
# If set to no, Total Length of the
|
||||
# message is included ONLY in the
|
||||
# First packet of a fragment series.
|
||||
#
|
||||
# include_length = yes
|
||||
|
||||
# Check the Certificate Revocation List
|
||||
#
|
||||
# 1) Copy CA certificates and CRLs to same directory.
|
||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
||||
# 'c_rehash' is OpenSSL's command.
|
||||
# 3) uncomment the line below.
|
||||
# 5) Restart radiusd
|
||||
# check_crl = yes
|
||||
ca_path = ${cadir}
|
||||
|
||||
#
|
||||
# If check_cert_issuer is set, the value will
|
||||
# be checked against the DN of the issuer in
|
||||
# the client certificate. If the values do not
|
||||
# match, the certificate verification will fail,
|
||||
# rejecting the user.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Issuer attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
||||
|
||||
#
|
||||
# If check_cert_cn is set, the value will
|
||||
# be xlat'ed and checked against the CN
|
||||
# in the client certificate. If the values
|
||||
# do not match, the certificate verification
|
||||
# will fail rejecting the user.
|
||||
#
|
||||
# This check is done only if the previous
|
||||
# "check_cert_issuer" is not set, or if
|
||||
# the check succeeds.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Common-Name attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_cn = %{User-Name}
|
||||
#
|
||||
# Set this option to specify the allowed TLS cipher suites. The format is listed in "man 1 ciphers".
|
||||
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
home_server_pool tls {
|
||||
type = fail-over
|
||||
home_server = tls
|
||||
}
|
||||
|
||||
realm tls {
|
||||
auth_pool = tls
|
||||
}
|
||||
Reference in New Issue
Block a user