Initial commit
- update else condition on the line 239 in templates/Deployment - update st-common version from 0.1.10 to 0.1.12 on Chart.yaml file - add gitlab ci/cd pipeline to package the Helm chart into a .tgz. and Publish it to GitLab’s Helm package registry
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
You can copy here your custom .sh, .sql or .sql.gz file so they are executed during the first boot of the image.
|
||||
|
||||
More info in the [freeradius/freeradius-server](https://hub.docker.com/r/freeradius/freeradius-server) repository.
|
||||
@@ -0,0 +1,366 @@
|
||||
# -*- text -*-
|
||||
##
|
||||
## mods-available/sql -- SQL modules
|
||||
##
|
||||
## $Id: cfeac63ea87c30fead8457af6d10f5c3a0f48aef $
|
||||
|
||||
######################################################################
|
||||
#
|
||||
# Configuration for the SQL module
|
||||
#
|
||||
# The database schemas and queries are located in subdirectories:
|
||||
#
|
||||
# sql/<DB>/main/schema.sql Schema
|
||||
# sql/<DB>/main/queries.conf Authorisation and Accounting queries
|
||||
#
|
||||
# Where "DB" is mysql, mssql, oracle, or postgresql.
|
||||
#
|
||||
# The name used to query SQL is sql_user_name, which is set in the file
|
||||
#
|
||||
# raddb/mods-config/sql/main/${dialect}/queries.conf
|
||||
#
|
||||
# If you are using realms, that configuration should be changed to use
|
||||
# the Stripped-User-Name attribute. See the comments around sql_user_name
|
||||
# for more information.
|
||||
#
|
||||
|
||||
sql {
|
||||
#
|
||||
# The dialect of SQL being used.
|
||||
#
|
||||
# Allowed dialects are:
|
||||
#
|
||||
# mssql
|
||||
# mysql
|
||||
# oracle
|
||||
# postgresql
|
||||
# sqlite
|
||||
# mongo
|
||||
#
|
||||
# dialect = "sqlite"
|
||||
dialect = $ENV{FREERADIUS_MODS_SQL_DIALECT}
|
||||
|
||||
#
|
||||
# The driver module used to execute the queries. Since we
|
||||
# don't know which SQL drivers are being used, the default is
|
||||
# "rlm_sql_null", which just logs the queries to disk via the
|
||||
# "logfile" directive, below.
|
||||
#
|
||||
# In order to talk to a real database, delete the next line,
|
||||
# and uncomment the one after it.
|
||||
#
|
||||
# If the dialect is "mssql", then the driver should be set to
|
||||
# one of the following values, depending on your system:
|
||||
#
|
||||
# rlm_sql_db2
|
||||
# rlm_sql_firebird
|
||||
# rlm_sql_freetds
|
||||
# rlm_sql_iodbc
|
||||
# rlm_sql_unixodbc
|
||||
#
|
||||
# driver = "rlm_sql_null"
|
||||
driver = "rlm_sql_${dialect}"
|
||||
|
||||
#
|
||||
# Driver-specific subsections. They will only be loaded and
|
||||
# used if "driver" is something other than "rlm_sql_null".
|
||||
# When a real driver is used, the relevant driver
|
||||
# configuration section is loaded, and all other driver
|
||||
# configuration sections are ignored.
|
||||
#
|
||||
sqlite {
|
||||
# Path to the sqlite database
|
||||
filename = $ENV{FREERADIUS_MODS_SQL_SQLITE_FILENAME}
|
||||
|
||||
# How long to wait for write locks on the database to be released (in ms) before giving up.
|
||||
busy_timeout = $ENV{FREERADIUS_MODS_SQL_SQLITE_BUSY_TIMEOUT}
|
||||
|
||||
# If the file above does not exist and bootstrap is set
|
||||
# a new database file will be created, and the SQL statements
|
||||
# contained within the bootstrap file will be executed.
|
||||
bootstrap = "${modconfdir}/${..:name}/main/sqlite/schema.sql"
|
||||
}
|
||||
|
||||
mysql {
|
||||
# If any of the files below are set, TLS encryption is enabled
|
||||
tls {
|
||||
# ca_file = $ENV{FREERADIUS_MODS_SQL_TLS_CACERT}
|
||||
# ca_path = "/startechnica/freeradius/certs-sql/"
|
||||
# certificate_file = $ENV{FREERADIUS_MODS_SQL_TLS_CERTIFICATE}
|
||||
# private_key_file = $ENV{FREERADIUS_MODS_SQL_TLS_PRIVATEKEY}
|
||||
# cipher = "DHE-RSA-AES256-SHA:AES128-SHA"
|
||||
# cipher = $ENV{FREERADIUS_MODS_SQL_TLS_CIPHER}
|
||||
|
||||
tls_required = $ENV{FREERADIUS_MODS_SQL_TLS_ENABLE}
|
||||
tls_check_cert = no
|
||||
tls_check_cert_cn = no
|
||||
}
|
||||
|
||||
# If yes, (or auto and libmysqlclient reports warnings are
|
||||
# available), will retrieve and log additional warnings from
|
||||
# the server if an error has occured. Defaults to 'auto'
|
||||
warnings = auto
|
||||
}
|
||||
|
||||
postgresql {
|
||||
|
||||
# unlike MySQL, which has a tls{} connection configuration, postgresql
|
||||
# uses its connection parameters - see the radius_db option below in
|
||||
# this file
|
||||
|
||||
# Send application_name to the postgres server
|
||||
# Only supported in PG 9.0 and greater. Defaults to no.
|
||||
send_application_name = yes
|
||||
}
|
||||
|
||||
#
|
||||
# Configuration for Mongo.
|
||||
#
|
||||
# Note that the Mongo driver is experimental. The FreeRADIUS developers
|
||||
# are unable to help with the syntax of the Mongo queries. Please see
|
||||
# the Mongo documentation for that syntax.
|
||||
#
|
||||
# The Mongo driver supports only the following methods:
|
||||
#
|
||||
# aggregate
|
||||
# findAndModify
|
||||
# findOne
|
||||
# insert
|
||||
#
|
||||
# For examples, see the query files:
|
||||
#
|
||||
# raddb/mods-config/sql/main/mongo/queries.conf
|
||||
# raddb/mods-config/sql/main/ippool/queries.conf
|
||||
#
|
||||
# In order to use findAndModify with an aggretation pipleline, make
|
||||
# sure that you are running MongoDB version 4.2 or greater. FreeRADIUS
|
||||
# assumes that the paramaters passed to the methods are supported by the
|
||||
# version of MongoDB which it is connected to.
|
||||
#
|
||||
mongo {
|
||||
#
|
||||
# The application name to use.
|
||||
#
|
||||
appname = "freeradius"
|
||||
|
||||
#
|
||||
# The TLS parameters here map directly to the Mongo TLS configuration
|
||||
#
|
||||
tls {
|
||||
certificate_file = $ENV{FREERADIUS_MODS_SQL_TLS_CERTIFICATE}
|
||||
certificate_password = $ENV{FREERADIUS_MODS_SQL_TLS_PRIVATEKEY}
|
||||
ca_file = $ENV{FREERADIUS_MODS_SQL_TLS_CACERT}
|
||||
ca_dir = /startechnica/freeradius/certs-sql/
|
||||
# crl_file = /path/to/file
|
||||
weak_cert_validation = false
|
||||
allow_invalid_hostname = false
|
||||
}
|
||||
}
|
||||
|
||||
# Connection info:
|
||||
#
|
||||
server = $ENV{FREERADIUS_MODS_SQL_SERVER}
|
||||
port = $ENV{FREERADIUS_MODS_SQL_PORT}
|
||||
login = $ENV{FREERADIUS_MODS_SQL_LOGIN}
|
||||
password = $ENV{FREERADIUS_MODS_SQL_PASSWORD}
|
||||
|
||||
# Connection info for Mongo
|
||||
# Authentication Without SSL
|
||||
# server = "mongodb://USER:PASSWORD@192.16.0.2:PORT/DATABASE?authSource=admin&ssl=false"
|
||||
|
||||
# Authentication With SSL
|
||||
# server = "mongodb://USER:PASSWORD@192.16.0.2:PORT/DATABASE?authSource=admin&ssl=true"
|
||||
|
||||
# Authentication with Certificate
|
||||
# Use this command for retrieve Derived username:
|
||||
# openssl x509 -in mycert.pem -inform PEM -subject -nameopt RFC2253
|
||||
# server = mongodb://<DERIVED USERNAME>@192.168.0.2:PORT/DATABASE?authSource=$external&ssl=true&authMechanism=MONGODB-X509
|
||||
|
||||
# Database table configuration for everything except Oracle
|
||||
radius_db = $ENV{FREERADIUS_MODS_SQL_DB}
|
||||
|
||||
# If you are using Oracle then use this instead
|
||||
# radius_db = "(DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=localhost)(PORT=1521))(CONNECT_DATA=(SID=your_sid)))"
|
||||
|
||||
# If you're using postgresql this can also be used instead of the connection info parameters
|
||||
# radius_db = "dbname=$ENV{FREERADIUS_MODS_SQL_DB} host=$ENV{FREERADIUS_MODS_SQL_SERVER} port=$ENV{FREERADIUS_MODS_SQL_PORT} user=$ENV{FREERADIUS_MODS_SQL_LOGIN} password=$ENV{FREERADIUS_MODS_SQL_PASSWORD}"
|
||||
|
||||
# Postgreql doesn't take tls{} options in its module config like mysql does - if you want to
|
||||
# use SSL connections then use this form of connection info parameter
|
||||
# radius_db = "host=localhost port=5432 dbname=radius user=radius password=raddpass sslmode=verify-full sslcert=/etc/ssl/client.crt sslkey=/etc/ssl/client.key sslrootcert=/etc/ssl/ca.crt"
|
||||
|
||||
# If you want both stop and start records logged to the
|
||||
# same SQL table, leave this as is. If you want them in
|
||||
# different tables, put the start table in acct_table1
|
||||
# and stop table in acct_table2
|
||||
acct_table1 = $ENV{FREERADIUS_MODS_SQL_TABLE_ACCT1}
|
||||
acct_table2 = $ENV{FREERADIUS_MODS_SQL_TABLE_ACCT2}
|
||||
|
||||
# Allow for storing data after authentication
|
||||
postauth_table = $ENV{FREERADIUS_MODS_SQL_TABLE_POSTAUTH}
|
||||
|
||||
# Tables containing 'check' items
|
||||
authcheck_table = $ENV{FREERADIUS_MODS_SQL_TABLE_AUTHCHECK}
|
||||
groupcheck_table = $ENV{FREERADIUS_MODS_SQL_TABLE_GROUPCHECK}
|
||||
|
||||
# Tables containing 'reply' items
|
||||
authreply_table = $ENV{FREERADIUS_MODS_SQL_TABLE_AUTHREPLY}
|
||||
groupreply_table = $ENV{FREERADIUS_MODS_SQL_TABLE_GROUPREPLY}
|
||||
|
||||
# Table to keep group info
|
||||
usergroup_table = $ENV{FREERADIUS_MODS_SQL_TABLE_USERGROUP}
|
||||
|
||||
# If set to 'yes' (default) we read the group tables unless Fall-Through = no in the reply table.
|
||||
# If set to 'no' we do not read the group tables unless Fall-Through = yes in the reply table.
|
||||
# read_groups = yes
|
||||
|
||||
# If set to 'yes' (default) we read profiles unless Fall-Through = no in the groupreply table.
|
||||
# If set to 'no' we do not read profiles unless Fall-Through = yes in the groupreply table.
|
||||
# read_profiles = yes
|
||||
|
||||
# Remove stale session if checkrad does not see a double login
|
||||
delete_stale_sessions = yes
|
||||
|
||||
# Write SQL queries to a logfile. This is potentially useful for tracing
|
||||
# issues with authorization queries. See also "logfile" directives in
|
||||
# mods-config/sql/main/*/queries.conf. You can enable per-section logging
|
||||
# by enabling "logfile" there, or global logging by enabling "logfile" here.
|
||||
#
|
||||
# Per-section logging can be disabled by setting "logfile = ''"
|
||||
# logfile = ${logdir}/sqllog.sql
|
||||
|
||||
# Set the maximum query duration and connection timeout
|
||||
# for rlm_sql_mysql.
|
||||
# query_timeout = 5
|
||||
|
||||
# As of version 3.0, the "pool" section has replaced the
|
||||
# following configuration items:
|
||||
#
|
||||
# num_sql_socks
|
||||
# connect_failure_retry_delay
|
||||
# lifetime
|
||||
# max_queries
|
||||
|
||||
#
|
||||
# The connection pool is new for 3.0, and will be used in many
|
||||
# modules, for all kinds of connection-related activity.
|
||||
#
|
||||
# When the server is not threaded, the connection pool
|
||||
# limits are ignored, and only one connection is used.
|
||||
#
|
||||
# If you want to have multiple SQL modules re-use the same
|
||||
# connection pool, use "pool = name" instead of a "pool"
|
||||
# section. e.g.
|
||||
#
|
||||
# sql sql1 {
|
||||
# ...
|
||||
# pool {
|
||||
# ...
|
||||
# }
|
||||
# }
|
||||
#
|
||||
# # sql2 will use the connection pool from sql1
|
||||
# sql sql2 {
|
||||
# ...
|
||||
# pool = sql1
|
||||
# }
|
||||
#
|
||||
pool {
|
||||
# Connections to create during module instantiation.
|
||||
# If the server cannot create specified number of
|
||||
# connections during instantiation it will exit.
|
||||
# Set to 0 to allow the server to start without the database being available.
|
||||
start = ${thread[pool].start_servers}
|
||||
|
||||
# Minimum number of connections to keep open
|
||||
min = ${thread[pool].min_spare_servers}
|
||||
|
||||
# Maximum number of connections
|
||||
#
|
||||
# If these connections are all in use and a new one
|
||||
# is requested, the request will NOT get a connection.
|
||||
#
|
||||
# Setting 'max' to LESS than the number of threads means
|
||||
# that some threads may starve, and you will see errors
|
||||
# like 'No connections available and at max connection limit'
|
||||
#
|
||||
# Setting 'max' to MORE than the number of threads means
|
||||
# that there are more connections than necessary.
|
||||
max = ${thread[pool].max_servers}
|
||||
|
||||
# Spare connections to be left idle
|
||||
#
|
||||
# NOTE: Idle connections WILL be closed if "idle_timeout"
|
||||
# is set. This should be less than or equal to "max" above.
|
||||
spare = ${thread[pool].max_spare_servers}
|
||||
|
||||
# Number of uses before the connection is closed
|
||||
#
|
||||
# 0 means "infinite"
|
||||
uses = 0
|
||||
|
||||
# The number of seconds to wait after the server tries
|
||||
# to open a connection, and fails. During this time,
|
||||
# no new connections will be opened.
|
||||
retry_delay = 30
|
||||
|
||||
# The lifetime (in seconds) of the connection
|
||||
lifetime = 0
|
||||
|
||||
# idle timeout (in seconds). A connection which is
|
||||
# unused for this length of time will be closed.
|
||||
idle_timeout = 60
|
||||
|
||||
# NOTE: All configuration settings are enforced. If a
|
||||
# connection is closed because of "idle_timeout",
|
||||
# "uses", or "lifetime", then the total number of
|
||||
# connections MAY fall below "min". When that
|
||||
# happens, it will open a new connection. It will
|
||||
# also log a WARNING message.
|
||||
#
|
||||
# The solution is to either lower the "min" connections,
|
||||
# or increase lifetime/idle_timeout.
|
||||
}
|
||||
|
||||
# Set to 'yes' to read radius clients from the database ('nas' table)
|
||||
# Clients will ONLY be read on server startup.
|
||||
#
|
||||
# A client can be link to a virtual server via the SQL
|
||||
# module. This link is done via the following process:
|
||||
#
|
||||
# If there is no listener in a virtual server, SQL clients
|
||||
# are added to the global list for that virtual server.
|
||||
#
|
||||
# If there is a listener, and the first listener does not
|
||||
# have a "clients=..." configuration item, SQL clients are
|
||||
# added to the global list.
|
||||
#
|
||||
# If there is a listener, and the first one does have a
|
||||
# "clients=..." configuration item, SQL clients are added to
|
||||
# that list. The client { ...} ` configured in that list are
|
||||
# also added for that listener.
|
||||
#
|
||||
# The only issue is if you have multiple listeners in a
|
||||
# virtual server, each with a different client list, then
|
||||
# the SQL clients are added only to the first listener.
|
||||
#
|
||||
read_clients = $ENV{FREERADIUS_MODS_SQL_READ_CLIENTS}
|
||||
|
||||
# Table to keep radius client info
|
||||
client_table = $ENV{FREERADIUS_MODS_SQL_TABLE_CLIENT}
|
||||
|
||||
#
|
||||
# The group attribute specific to this instance of rlm_sql
|
||||
#
|
||||
|
||||
# This entry should be used for additional instances (sql foo {})
|
||||
# of the SQL module.
|
||||
# group_attribute = "${.:instance}-SQL-Group"
|
||||
|
||||
# This entry should be used for the default instance (sql {})
|
||||
# of the SQL module.
|
||||
group_attribute = $ENV{FREERADIUS_MODS_SQL_GROUP_ATTRIBUTE}
|
||||
|
||||
# Read database-specific queries
|
||||
$INCLUDE ${modconfdir}/${.:name}/main/${dialect}/queries.conf
|
||||
}
|
||||
@@ -0,0 +1,165 @@
|
||||
###########################################################################
|
||||
# $Id: 41fcccad1c012226d12cc721518fe91e311e55e2 $ #
|
||||
# #
|
||||
# schema.sql rlm_sql - FreeRADIUS SQL Module #
|
||||
# #
|
||||
# Database schema for MySQL rlm_sql module #
|
||||
# #
|
||||
# To load: #
|
||||
# mysql -uroot -prootpass radius < schema.sql #
|
||||
# #
|
||||
# Mike Machado <mike@innercite.com> #
|
||||
###########################################################################
|
||||
|
||||
#
|
||||
# Table structure for table 'radacct'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radacct (
|
||||
radacctid bigint(21) NOT NULL auto_increment,
|
||||
acctsessionid varchar(64) NOT NULL default '',
|
||||
acctuniqueid varchar(32) NOT NULL default '',
|
||||
username varchar(64) NOT NULL default '',
|
||||
realm varchar(64) default '',
|
||||
nasipaddress varchar(15) NOT NULL default '',
|
||||
nasportid varchar(32) default NULL,
|
||||
nasporttype varchar(32) default NULL,
|
||||
acctstarttime datetime NULL default NULL,
|
||||
acctupdatetime datetime NULL default NULL,
|
||||
acctstoptime datetime NULL default NULL,
|
||||
acctinterval int(12) default NULL,
|
||||
acctsessiontime int(12) unsigned default NULL,
|
||||
acctauthentic varchar(32) default NULL,
|
||||
connectinfo_start varchar(128) default NULL,
|
||||
connectinfo_stop varchar(128) default NULL,
|
||||
acctinputoctets bigint(20) default NULL,
|
||||
acctoutputoctets bigint(20) default NULL,
|
||||
calledstationid varchar(50) NOT NULL default '',
|
||||
callingstationid varchar(50) NOT NULL default '',
|
||||
acctterminatecause varchar(32) NOT NULL default '',
|
||||
servicetype varchar(32) default NULL,
|
||||
framedprotocol varchar(32) default NULL,
|
||||
framedipaddress varchar(15) NOT NULL default '',
|
||||
framedipv6address varchar(45) NOT NULL default '',
|
||||
framedipv6prefix varchar(45) NOT NULL default '',
|
||||
framedinterfaceid varchar(44) NOT NULL default '',
|
||||
delegatedipv6prefix varchar(45) NOT NULL default '',
|
||||
class varchar(64) default NULL,
|
||||
PRIMARY KEY (radacctid),
|
||||
UNIQUE KEY acctuniqueid (acctuniqueid),
|
||||
KEY username (username),
|
||||
KEY framedipaddress (framedipaddress),
|
||||
KEY framedipv6address (framedipv6address),
|
||||
KEY framedipv6prefix (framedipv6prefix),
|
||||
KEY framedinterfaceid (framedinterfaceid),
|
||||
KEY delegatedipv6prefix (delegatedipv6prefix),
|
||||
KEY acctsessionid (acctsessionid),
|
||||
KEY acctsessiontime (acctsessiontime),
|
||||
KEY acctstarttime (acctstarttime),
|
||||
KEY acctinterval (acctinterval),
|
||||
KEY acctstoptime (acctstoptime),
|
||||
KEY nasipaddress (nasipaddress),
|
||||
KEY class (class)
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radcheck'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radcheck (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
username varchar(64) NOT NULL default '',
|
||||
attribute varchar(64) NOT NULL default '',
|
||||
op char(2) NOT NULL DEFAULT '==',
|
||||
value varchar(253) NOT NULL default '',
|
||||
PRIMARY KEY (id),
|
||||
KEY username (username(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radgroupcheck'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radgroupcheck (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
groupname varchar(64) NOT NULL default '',
|
||||
attribute varchar(64) NOT NULL default '',
|
||||
op char(2) NOT NULL DEFAULT '==',
|
||||
value varchar(253) NOT NULL default '',
|
||||
PRIMARY KEY (id),
|
||||
KEY groupname (groupname(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radgroupreply'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radgroupreply (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
groupname varchar(64) NOT NULL default '',
|
||||
attribute varchar(64) NOT NULL default '',
|
||||
op char(2) NOT NULL DEFAULT '=',
|
||||
value varchar(253) NOT NULL default '',
|
||||
PRIMARY KEY (id),
|
||||
KEY groupname (groupname(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radreply'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radreply (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
username varchar(64) NOT NULL default '',
|
||||
attribute varchar(64) NOT NULL default '',
|
||||
op char(2) NOT NULL DEFAULT '=',
|
||||
value varchar(253) NOT NULL default '',
|
||||
PRIMARY KEY (id),
|
||||
KEY username (username(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
|
||||
#
|
||||
# Table structure for table 'radusergroup'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS `radusergroup` (
|
||||
id int(11) unsigned NOT NULL auto_increment,
|
||||
username varchar(64) NOT NULL default '',
|
||||
groupname varchar(64) NOT NULL default '',
|
||||
priority int(11) NOT NULL default '1',
|
||||
PRIMARY KEY (id),
|
||||
KEY username (username(32))
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'radpostauth'
|
||||
#
|
||||
# Note: MySQL versions since 5.6.4 support fractional precision timestamps
|
||||
# which we use here. Replace the authdate definition with the following
|
||||
# if your software is too old:
|
||||
#
|
||||
# authdate timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS radpostauth (
|
||||
id int(11) NOT NULL auto_increment,
|
||||
username varchar(64) NOT NULL default '',
|
||||
pass varchar(64) NOT NULL default '',
|
||||
reply varchar(32) NOT NULL default '',
|
||||
authdate timestamp(6) NOT NULL DEFAULT CURRENT_TIMESTAMP(6) ON UPDATE CURRENT_TIMESTAMP(6),
|
||||
class varchar(64) default NULL,
|
||||
PRIMARY KEY (id),
|
||||
KEY username (username),
|
||||
KEY class (class)
|
||||
) ENGINE = INNODB;
|
||||
|
||||
#
|
||||
# Table structure for table 'nas'
|
||||
#
|
||||
CREATE TABLE IF NOT EXISTS nas (
|
||||
id int(10) NOT NULL auto_increment,
|
||||
nasname varchar(128) NOT NULL,
|
||||
shortname varchar(32),
|
||||
type varchar(30) DEFAULT 'other',
|
||||
ports int(5),
|
||||
secret varchar(60) DEFAULT 'secret' NOT NULL,
|
||||
server varchar(64),
|
||||
community varchar(50),
|
||||
description varchar(200) DEFAULT 'RADIUS Client',
|
||||
PRIMARY KEY (id),
|
||||
KEY nasname (nasname)
|
||||
) ENGINE = INNODB;
|
||||
@@ -0,0 +1,41 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# Sample virtual server for receiving a CoA or Disconnect-Request packet.
|
||||
#
|
||||
|
||||
# Listen on the CoA port.
|
||||
#
|
||||
# This uses the normal set of clients, with the same secret as for authentication and accounting.
|
||||
#
|
||||
|
||||
listen {
|
||||
type = coa
|
||||
# ipaddr = $ENV{FREERADIUS_SITES_COA_LISTEN}
|
||||
ipaddr = *
|
||||
port = $ENV{FREERADIUS_SITES_COA_PORT}
|
||||
virtual_server = coa
|
||||
}
|
||||
|
||||
server coa {
|
||||
# When a packet is received, it is processed through the recv-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
|
||||
recv-coa {
|
||||
# CoA && Disconnect packets can be proxied in the same way as authentication or accounting packets.
|
||||
# Just set Proxy-To-Realm, or Home-Server-Pool, and the packets will be proxied.
|
||||
|
||||
# Do proxying based on realms here. You don't need "IPASS" or "ntdomain", as the proxying is based on the Operator-Name attribute. It contains the realm,
|
||||
# and ONLY the realm (prefixed by a '1')
|
||||
suffix
|
||||
|
||||
# Insert your own policies here.
|
||||
ok
|
||||
}
|
||||
|
||||
# When a packet is sent, it is processed through the send-coa section. This applies to *both* CoA-Request and Disconnect-Request packets.
|
||||
send-coa {
|
||||
# Sample module.
|
||||
ok
|
||||
}
|
||||
|
||||
# You can use pre-proxy and post-proxy sections here, too. They will be processed for sending && receiving proxy packets.
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,595 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# This is a virtual server that handles DHCP.
|
||||
#
|
||||
# See raddb/mods-available/dhcp_sqlippool for the IP Pool configuration.
|
||||
#
|
||||
# See raddb/policy.d/dhcp_sqlippool for the "glue" code that allows
|
||||
# the RADIUS based "sqlippool" module to be used for DHCP.
|
||||
#
|
||||
# See raddb/mods-config/sql/ippool/ for the schemas.
|
||||
#
|
||||
# See raddb/sites-available/dhcp for instructions on how to configure
|
||||
# the DHCP server.
|
||||
#
|
||||
# $Id$
|
||||
#
|
||||
######################################################################
|
||||
|
||||
#
|
||||
# The DHCP functionality goes into a virtual server.
|
||||
#
|
||||
server dhcp {
|
||||
|
||||
# Define a DHCP socket.
|
||||
#
|
||||
# The default port below is 6700, so you don't break your network.
|
||||
# If you want it to do real DHCP, change this to 67, and good luck!
|
||||
#
|
||||
# You can also bind the DHCP socket to an interface.
|
||||
# See below, and raddb/radiusd.conf for examples.
|
||||
#
|
||||
# This lets you run *one* DHCP server instance and have it listen on
|
||||
# multiple interfaces, each with a separate policy.
|
||||
#
|
||||
# If you have multiple interfaces, it is a good idea to bind the
|
||||
# listen section to an interface. You will also need one listen
|
||||
# section per interface.
|
||||
#
|
||||
# FreeBSD does *not* support binding sockets to interfaces. Therefore,
|
||||
# if you have multiple interfaces, broadcasts may go out of the wrong
|
||||
# one, or even all interfaces. The solution is to use the "setfib" command.
|
||||
# If you have a network "10.10.0/24" on LAN1, you will need to do:
|
||||
#
|
||||
# Pick any IP on the 10.10.0/24 network
|
||||
# $ setfib 1 route add default 10.10.0.1
|
||||
#
|
||||
# Edit /etc/rc.local, and add a line:
|
||||
# setfib 1 /path/to/radiusd
|
||||
#
|
||||
# The kern must be built with the following options:
|
||||
# options ROUTETABLES=2
|
||||
# or any value larger than 2.
|
||||
#
|
||||
# The other only solution is to update FreeRADIUS to use BPF sockets.
|
||||
#
|
||||
listen {
|
||||
# This is a dhcp socket.
|
||||
type = dhcp
|
||||
|
||||
# IP address to listen on. Will usually be the IP of the
|
||||
# interface, or 0.0.0.0
|
||||
ipaddr = 0.0.0.0
|
||||
|
||||
# source IP address for unicast packets sent by the
|
||||
# DHCP server.
|
||||
#
|
||||
# The source IP for unicast packets is chosen from the first
|
||||
# one of the following items which returns a valid IP
|
||||
# address:
|
||||
#
|
||||
# src_ipaddr
|
||||
# ipaddr
|
||||
# reply:DHCP-Server-IP-Address
|
||||
# reply:DHCP-DHCP-Server-Identifier
|
||||
#
|
||||
src_ipaddr = 127.0.0.1
|
||||
|
||||
# The port should be 67 for a production network. Don't set
|
||||
# it to 67 on a production network unless you really know
|
||||
# what you're doing. Even if nothing is configured below, the
|
||||
# server may still NAK legitimate responses from clients.
|
||||
port = 6700
|
||||
|
||||
# Interface name we are listening on. See comments above.
|
||||
# interface = lo0
|
||||
|
||||
# The DHCP server defaults to allowing broadcast packets.
|
||||
# Set this to "no" only when the server receives *all* packets
|
||||
# from a relay agent. i.e. when *no* clients are on the same
|
||||
# LAN as the DHCP server.
|
||||
#
|
||||
# It's set to "no" here for testing. It will usually want to
|
||||
# be "yes" in production, unless you are only dealing with
|
||||
# relayed packets.
|
||||
broadcast = no
|
||||
|
||||
# On Linux if you're running the server as non-root, you
|
||||
# will need to do:
|
||||
#
|
||||
# setcap cap_net_admin,cap_net_bind_service=eip /path/to/radiusd
|
||||
#
|
||||
# This will allow the server to set ARP table entries
|
||||
# for newly allocated IPs, when run as the "radius" user.
|
||||
#
|
||||
# The above "setcap" command adds the capability to the program,
|
||||
# usually so long as it is run by the "radius" user. Which means
|
||||
# (oddly enough) that it no longer works when run as root!
|
||||
#
|
||||
# When running the server as root in debug mode, you can use:
|
||||
#
|
||||
# capsh --caps="cap_setpcap,cap_setuid,cap_setgid,cap_net_admin,cap_net_bind_service+eip" --keep=1 --user=radius --addamb=cap_net_admin,cap_net_bind_service -- -c "/path/to/radiusd -X"
|
||||
#
|
||||
# Or, simply "sudo" or "su" to the "radius" user, and then run
|
||||
# the server in debug mode.
|
||||
|
||||
# De-duplicate DHCP packets. If clients don't receive
|
||||
# a reply within their timeout, most will re-transmit.
|
||||
# A reply to either packet will satisfy, so de-duplicating
|
||||
# helps manage load on a busy server
|
||||
performance {
|
||||
skip_duplicate_checks = no
|
||||
}
|
||||
}
|
||||
|
||||
# Packets received on the socket will be processed through one
|
||||
# of the following sections, named after the DHCP packet type.
|
||||
# See dictionary.dhcp for the packet types.
|
||||
|
||||
# Return packets will be sent to, in preference order:
|
||||
# DHCP-Gateway-IP-Address
|
||||
# DHCP-Client-IP-Address
|
||||
# DHCP-Your-IP-Address
|
||||
# At least one of these attributes should be set at the end of each
|
||||
# section for a response to be sent.
|
||||
|
||||
# An internal attribute of DHCP-Network-Subnet is set to provide
|
||||
# a basis for determining the network that a client belongs to. This
|
||||
# is a hierarchical assignment based on:
|
||||
#
|
||||
# - DHCP-Relay-Link-Selection
|
||||
# - DHCP-Subnet-Selection-Option
|
||||
# - DHCP-Gateway-IP-Address
|
||||
# - DHCP-Client-IP-Address
|
||||
#
|
||||
# Except for cases where all IP allocation is performed using a mapping from
|
||||
# the device MAC address to a fixed IP address the DHCP configuration will
|
||||
# involve the use of one or more pools.
|
||||
#
|
||||
# Each pool should be composed of a set of equally valid IP addresses for the
|
||||
# devices designated as users of the pool. During IP allocation the choice of
|
||||
# pool is driven by setting the Pool-Name attribute which may either be
|
||||
# specified directly or chosen (usually with the help of the dhcp_network
|
||||
# module) based on the initial value of DHCP-Network-Subnet.
|
||||
#
|
||||
# DHCP-Network-Subnet indicates the network from which the request is
|
||||
# originating. In cases where the originating network alone is insufficent to
|
||||
# define the required IP allocated policy, DHCP-Network-Subnet may be
|
||||
# overridden to force the selection of a particular pool.
|
||||
#
|
||||
# IP addresses belonging to a single pool that is designated for a Layer 2
|
||||
# network containing multiple subnets (a "shared-network" or "multinet"
|
||||
# configuration as defined by some other DHCP servers), will by definition be
|
||||
# members of distinct subnets that require their own DHCP reply parameters. In
|
||||
# this case the dhcp_subnet policy can be used to set the correct
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address options
|
||||
# based on the allocated IP.
|
||||
|
||||
dhcp DHCP-Discover {
|
||||
|
||||
# The DHCP Server Identifier is set here since is returned in OFFERs
|
||||
update control {
|
||||
&DHCP-DHCP-Server-Identifier = 192.0.2.2
|
||||
}
|
||||
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# If clients need to be assigned to a particular network based on
|
||||
# an attribute in the packet rather than the calculated
|
||||
# DHCP-Network-Subnet described above, then call a policy
|
||||
# (defined in policy.d/dhcp) to perform the override
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Do a simple mapping of MAC to assigned IP.
|
||||
#
|
||||
# See below for the definition of the "mac2ip"
|
||||
# module.
|
||||
#
|
||||
#mac2ip
|
||||
|
||||
# Or, allocate IPs from the DHCP pool in SQL. You may need to
|
||||
# set the pool name here if you haven't set it elsewhere.
|
||||
#update control {
|
||||
# &Pool-Name := "local"
|
||||
#}
|
||||
#dhcp_sqlippool
|
||||
|
||||
# If the IP address was not allocated, do something else.
|
||||
# You could call a Perl, Python, or Java script here.
|
||||
#if (notfound) {
|
||||
# ...
|
||||
#}
|
||||
|
||||
# "Shared-networks" may have multiple IP subnets co-existing in a
|
||||
# single Layer 2 network. If the pool for the network contains
|
||||
# addresses from more that one subnet then the setting subnet-specific
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
|
||||
# parameters must be performed after the allocation of the IP address.
|
||||
#
|
||||
# Set any subnet-specific parameters using this policy.
|
||||
#
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this.
|
||||
#
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# As an alternative or complement to configuration files based lookup
|
||||
# for options data you can instead use an SQL database. Example
|
||||
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
|
||||
# will need to be adapted to your requirements.
|
||||
#dhcp_policy_sql
|
||||
|
||||
# Set the type of packet to send in reply.
|
||||
#
|
||||
# The server will look at the DHCP-Message-Type attribute to
|
||||
# determine which type of packet to send in reply. Common
|
||||
# values would be DHCP-Offer, DHCP-Ack or DHCP-NAK. See
|
||||
# dictionary.dhcp for all the possible values.
|
||||
#
|
||||
# DHCP-Do-Not-Respond can be used to tell the server to not
|
||||
# respond.
|
||||
#
|
||||
# In the event that DHCP-Message-Type is not set then the
|
||||
# server will fall back to determining the type of reply
|
||||
# based on the rcode of this section.
|
||||
#
|
||||
#update reply {
|
||||
# DHCP-Message-Type = DHCP-Offer
|
||||
#}
|
||||
#
|
||||
# If DHCP-Message-Type is not set, returning "ok" or
|
||||
# "updated" from this section will respond with a DHCP-Offer
|
||||
# message.
|
||||
#
|
||||
# Other rcodes will tell the server to not return any response.
|
||||
#
|
||||
#ok
|
||||
}
|
||||
|
||||
dhcp DHCP-Request {
|
||||
|
||||
# You must set the DHCP Server Identifier here since this is returned
|
||||
# in ACKs and is used to determine whether a request containing a
|
||||
# "server-ip" field is intended for this server
|
||||
update control {
|
||||
&DHCP-DHCP-Server-Identifier = 192.0.2.2
|
||||
}
|
||||
|
||||
# If the request is not for this server then silently discard it
|
||||
if (&request:DHCP-DHCP-Server-Identifier && \
|
||||
&request:DHCP-DHCP-Server-Identifier != &control:DHCP-DHCP-Server-Identifier) {
|
||||
do_not_respond
|
||||
}
|
||||
|
||||
# Response packet type. See DHCP-Discover section above.
|
||||
#update reply {
|
||||
# &DHCP-Message-Type = DHCP-Ack
|
||||
#}
|
||||
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Do a simple mapping of MAC to assigned IP.
|
||||
#
|
||||
# See below for the definition of the "mac2ip"
|
||||
# module.
|
||||
#
|
||||
#mac2ip
|
||||
|
||||
# Or, allocate IPs from the DHCP pool in SQL. You may need to
|
||||
# set the pool name here if you haven't set it elsewhere.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_request
|
||||
|
||||
# If the IP was not allocated, do something else.
|
||||
# You could call a Perl, Python, or Java script here.
|
||||
#if (notfound) {
|
||||
# ...
|
||||
#}
|
||||
|
||||
# "Shared-networks" may have multiple IP subnets co-existing in a
|
||||
# single Layer 2 network. If the pool for the network contains
|
||||
# addresses from more that one subnet then the setting subnet-specific
|
||||
# DHCP-Subnet-Mask, DHCP-Router-Address and DHCP-Broadcast-Address
|
||||
# parameters must be performed after the allocation of the IP address.
|
||||
#
|
||||
# Set any subnet-specific parameters using this policy.
|
||||
#
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# As an alternative or complement to configuration files based lookup
|
||||
# for options data you can instead use an SQL database. Example
|
||||
# configuration is found in dhcp_policy_sql in policy.d/dhcp which
|
||||
# will need to be adapted to your requirements.
|
||||
#dhcp_policy_sql
|
||||
|
||||
# If DHCP-Message-Type is not set, returning "ok" or
|
||||
# "updated" from this section will respond with a DHCP-Ack
|
||||
# packet.
|
||||
#
|
||||
# "handled" will not return a packet, all other rcodes will
|
||||
# send back a DHCP-NAK.
|
||||
#
|
||||
#ok
|
||||
}
|
||||
|
||||
#
|
||||
# Other DHCP packet types
|
||||
#
|
||||
# There should be a separate section for each DHCP message type.
|
||||
# By default this configuration will ignore them all. Any packet type
|
||||
# not defined here will be responded to with a DHCP-NAK.
|
||||
|
||||
dhcp DHCP-Decline {
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple networks use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Use a policy that set options from data stored in an SQL database
|
||||
#dhcp_policy_sql
|
||||
|
||||
# If using IPs from a DHCP pool in SQL then you may need to set the
|
||||
# pool name here if you haven't set it elsewhere and release the IP.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_decline
|
||||
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Do-Not-Respond
|
||||
}
|
||||
reject
|
||||
}
|
||||
|
||||
#
|
||||
# A dummy config for Inform packets - this should match the
|
||||
# options set in the Request section above, except Inform replies
|
||||
# must not set Your-IP-Address or IP-Address-Lease-Time
|
||||
#
|
||||
dhcp DHCP-Inform {
|
||||
# Call a policy (defined in policy.d/dhcp) to set common reply attributes
|
||||
dhcp_common
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and network options
|
||||
# For multiple networks use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# Use a policy with calls a "files" module of the same name to lookup
|
||||
# subnet options
|
||||
# Enable mods-available/dhcp_files AND uncomment dhcp_subnet in
|
||||
# policy.d/dhcp to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_subnet
|
||||
|
||||
# Use a "files" module to lookup options based on DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_group_options
|
||||
|
||||
# Use a "files" module to lookup host specific options
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_hosts
|
||||
|
||||
# Use a policy that set options from data stored in an SQL database
|
||||
#dhcp_policy_sql
|
||||
|
||||
ok
|
||||
}
|
||||
|
||||
#
|
||||
# For Windows 7 boxes
|
||||
#
|
||||
#dhcp DHCP-Inform {
|
||||
# update reply {
|
||||
# Packet-Dst-Port = 67
|
||||
# DHCP-Message-Type = DHCP-ACK
|
||||
# DHCP-DHCP-Server-Identifier = "%{Packet-Dst-IP-Address}"
|
||||
# DHCP-Site-specific-28 = 0x0a00
|
||||
# }
|
||||
# ok
|
||||
#}
|
||||
|
||||
dhcp DHCP-Release {
|
||||
|
||||
# Use a "passwd" module to set group memberships in DHCP-Group-Name
|
||||
# Enable mods-available/dhcp_passwd to use this
|
||||
#dhcp_group_membership
|
||||
|
||||
# Optionally override the network address based on client attributes
|
||||
# See Discover section
|
||||
#dhcp_override_network
|
||||
|
||||
# Use a "files" module to lookup global and subnet options
|
||||
# For multiple subnets use this in place of dhcp_common
|
||||
# Enable mods-available/dhcp_files to use this
|
||||
# Options are set in mods-config/files/dhcp
|
||||
#dhcp_network
|
||||
|
||||
# If using IPs from a DHCP pool in SQL then you may need to set the
|
||||
# pool name here if you haven't set it elsewhere and release the IP.
|
||||
# update control {
|
||||
# &Pool-Name := "local"
|
||||
# }
|
||||
# dhcp_sqlippool_release
|
||||
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Do-Not-Respond
|
||||
}
|
||||
reject
|
||||
}
|
||||
|
||||
|
||||
dhcp DHCP-Lease-Query {
|
||||
# The thing being queried for is implicit
|
||||
# in the packets.
|
||||
|
||||
# has MAC, asking for IP, etc.
|
||||
if (&DHCP-Client-Hardware-Address) {
|
||||
# look up MAC in database
|
||||
}
|
||||
|
||||
# has IP, asking for MAC, etc.
|
||||
elsif (&DHCP-Your-IP-Address) {
|
||||
# look up IP in database
|
||||
}
|
||||
|
||||
# has host name, asking for IP, MAC, etc.
|
||||
elsif (&DHCP-Client-Identifier) {
|
||||
# look up identifier in database
|
||||
}
|
||||
else {
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unknown
|
||||
}
|
||||
|
||||
ok
|
||||
|
||||
# stop processing
|
||||
return
|
||||
}
|
||||
|
||||
#
|
||||
# We presume that the database lookup returns "notfound"
|
||||
# if it can't find anything.
|
||||
#
|
||||
if (notfound) {
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unknown
|
||||
}
|
||||
ok
|
||||
return
|
||||
}
|
||||
|
||||
#
|
||||
# Add more logic here. Is the lease inactive?
|
||||
# If so, respond with DHCP-Lease-Unassigned.
|
||||
#
|
||||
# Otherwise, respond with DHCP-Lease-Active
|
||||
#
|
||||
|
||||
#
|
||||
# Also be sure to return ALL information about
|
||||
# the lease.
|
||||
#
|
||||
|
||||
#
|
||||
# The reply types are:
|
||||
#
|
||||
# DHCP-Lease-Unknown
|
||||
# DHCP-Lease-Active
|
||||
# DHCP-Lease-Unassigned
|
||||
#
|
||||
update reply {
|
||||
&DHCP-Message-Type = DHCP-Lease-Unassigned
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
######################################################################
|
||||
#
|
||||
# This next section is a sample configuration for the "passwd"
|
||||
# module, that reads flat-text files. It should go into
|
||||
# radiusd.conf, in the "modules" section.
|
||||
#
|
||||
# The file is in the format <mac>,<ip>
|
||||
#
|
||||
# 00:01:02:03:04:05,192.0.2.100
|
||||
# 01:01:02:03:04:05,192.0.2.101
|
||||
# 02:01:02:03:04:05,192.0.2.102
|
||||
#
|
||||
# This lets you perform simple static IP assignment.
|
||||
#
|
||||
# There is a preconfigured "mac2ip" module setup in
|
||||
# mods-available/mac2ip. To use it do:
|
||||
#
|
||||
# # cd raddb/
|
||||
# # ln -s ../mods-available/mac2ip mods-enabled/mac2ip
|
||||
# # mkdir mods-config/passwd
|
||||
#
|
||||
# Then create the file mods-config/passwd/mac2ip with the above
|
||||
# format.
|
||||
#
|
||||
######################################################################
|
||||
|
||||
|
||||
# This is an example only - see mods-available/mac2ip instead; do
|
||||
# not uncomment these lines here.
|
||||
#
|
||||
#passwd mac2ip {
|
||||
# filename = ${confdir}/mac2ip
|
||||
# format = "*DHCP-Client-Hardware-Address:=DHCP-Your-IP-Address"
|
||||
# delimiter = ","
|
||||
#}
|
||||
@@ -0,0 +1,126 @@
|
||||
######################################################################
|
||||
#
|
||||
# This is a virtual server that handles *only* inner tunnel
|
||||
# requests for EAP-TTLS and PEAP types.
|
||||
#
|
||||
######################################################################
|
||||
|
||||
server inner-tunnel {
|
||||
|
||||
listen {
|
||||
ipaddr = 127.0.0.1
|
||||
port = 18120
|
||||
type = auth
|
||||
}
|
||||
|
||||
authorize {
|
||||
filter_username
|
||||
# filter_inner_identity
|
||||
chap
|
||||
mschap
|
||||
# unix
|
||||
# IPASS
|
||||
suffix
|
||||
# ntdomain
|
||||
|
||||
update control {
|
||||
&Proxy-To-Realm := LOCAL
|
||||
}
|
||||
|
||||
eap {
|
||||
ok = return
|
||||
}
|
||||
|
||||
files
|
||||
-sql
|
||||
# smbpasswd
|
||||
-ldap
|
||||
# daily
|
||||
expiration
|
||||
logintime
|
||||
pap
|
||||
}
|
||||
|
||||
authenticate {
|
||||
Auth-Type PAP {
|
||||
pap
|
||||
}
|
||||
|
||||
Auth-Type CHAP {
|
||||
chap
|
||||
}
|
||||
|
||||
Auth-Type MS-CHAP {
|
||||
mschap
|
||||
}
|
||||
|
||||
mschap
|
||||
# pam
|
||||
|
||||
# Auth-Type LDAP {
|
||||
# ldap
|
||||
# }
|
||||
|
||||
eap
|
||||
}
|
||||
|
||||
session {
|
||||
radutmp
|
||||
# sql
|
||||
}
|
||||
|
||||
# Post-Authentication
|
||||
post-auth {
|
||||
# cui-inner
|
||||
|
||||
# update outer.session-state {
|
||||
# User-Name := &User-Name
|
||||
# }
|
||||
|
||||
# reply_log
|
||||
-sql
|
||||
# ldap
|
||||
# moonshot_host_tid
|
||||
# moonshot_realm_tid
|
||||
# moonshot_coi_tid
|
||||
|
||||
if (0) {
|
||||
update reply {
|
||||
User-Name !* ANY
|
||||
Message-Authenticator !* ANY
|
||||
EAP-Message !* ANY
|
||||
Proxy-State !* ANY
|
||||
MS-MPPE-Encryption-Types !* ANY
|
||||
MS-MPPE-Encryption-Policy !* ANY
|
||||
MS-MPPE-Send-Key !* ANY
|
||||
MS-MPPE-Recv-Key !* ANY
|
||||
}
|
||||
|
||||
update {
|
||||
&outer.session-state: += &reply:
|
||||
}
|
||||
}
|
||||
|
||||
Post-Auth-Type REJECT {
|
||||
-sql
|
||||
attr_filter.access_reject
|
||||
|
||||
update outer.session-state {
|
||||
&Module-Failure-Message := &request:Module-Failure-Message
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pre-proxy {
|
||||
# files
|
||||
# attr_filter.pre-proxy
|
||||
# pre_proxy_log
|
||||
}
|
||||
|
||||
post-proxy {
|
||||
# post_proxy_log
|
||||
# attr_filter.post-proxy
|
||||
eap
|
||||
}
|
||||
|
||||
} # inner-tunnel server block
|
||||
@@ -0,0 +1,126 @@
|
||||
# -*- text -*-
|
||||
######################################################################
|
||||
#
|
||||
# A virtual server to handle ONLY Status-Server packets.
|
||||
#
|
||||
# Server statistics can be queried with a properly formatted
|
||||
# Status-Server request. See dictionary.freeradius for comments.
|
||||
#
|
||||
# If radiusd.conf has "status_server = yes", then any client
|
||||
# will be able to send a Status-Server packet to any port
|
||||
# (listen section type "auth", "acct", or "status"), and the
|
||||
# server will respond.
|
||||
#
|
||||
# If radiusd.conf has "status_server = no", then the server will
|
||||
# ignore Status-Server packets to "auth" and "acct" ports. It
|
||||
# will respond only if the Status-Server packet is sent to a
|
||||
# "status" port.
|
||||
#
|
||||
# The server statistics are available ONLY on socket of type
|
||||
# "status". Queries for statistics sent to any other port
|
||||
# are ignored.
|
||||
#
|
||||
# Similarly, a socket of type "status" will not process
|
||||
# authentication or accounting packets. This is for security.
|
||||
#
|
||||
# $Id: e7d4346310b837d56bffe4c991b4e5680742ebc0 $
|
||||
#
|
||||
######################################################################
|
||||
|
||||
server status {
|
||||
listen {
|
||||
# ONLY Status-Server is allowed to this port.
|
||||
# ALL other packets are ignored.
|
||||
type = status
|
||||
|
||||
ipaddr = $ENV{FREERADIUS_SITES_STATUS_LISTEN}
|
||||
port = $ENV{FREERADIUS_SITES_STATUS_PORT}
|
||||
}
|
||||
|
||||
#
|
||||
# We recommend that you list ONLY management clients here.
|
||||
# i.e. NOT your NASes or Access Points, and for an ISP,
|
||||
# DEFINITELY not any RADIUS servers that are proxying packets
|
||||
# to you.
|
||||
#
|
||||
# If you do NOT list a client here, then any client that is
|
||||
# globally defined (i.e. all of them) will be able to query
|
||||
# these statistics.
|
||||
#
|
||||
# Do you really want your partners seeing the internal details
|
||||
# of what your RADIUS server is doing?
|
||||
#
|
||||
client admin {
|
||||
ipaddr = 127.0.0.1
|
||||
secret = $ENV{FREERADIUS_SITES_STATUS_SECRET}
|
||||
}
|
||||
|
||||
# Simple authorize section. The "Autz-Type Status-Server"
|
||||
# section will work here, too. See "raddb/sites-available/default".
|
||||
authorize {
|
||||
ok
|
||||
|
||||
# respond to the Status-Server request.
|
||||
Autz-Type Status-Server {
|
||||
ok
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Statistics can be queried via a number of methods:
|
||||
#
|
||||
# All packets received/sent by the server (1 = auth, 2 = acct)
|
||||
# FreeRADIUS-Statistics-Type = 3
|
||||
#
|
||||
# All packets proxied by the server (4 = proxy-auth, 8 = proxy-acct)
|
||||
# FreeRADIUS-Statistics-Type = 12
|
||||
#
|
||||
# All packets sent && received:
|
||||
# FreeRADIUS-Statistics-Type = 15
|
||||
#
|
||||
# Internal server statistics:
|
||||
# FreeRADIUS-Statistics-Type = 16
|
||||
#
|
||||
# All packets for a particular client (globally defined)
|
||||
# FreeRADIUS-Statistics-Type = 35
|
||||
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
|
||||
#
|
||||
# All packets for a client attached to a "listen" ip/port
|
||||
# FreeRADIUS-Statistics-Type = 35
|
||||
# FreeRADIUS-Stats-Client-IP-Address = 192.0.2.1
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
#
|
||||
# All packets for a "listen" IP/port
|
||||
# FreeRADIUS-Statistics-Type = 67
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 127.0.0.1
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
#
|
||||
# All packets for a home server IP / port
|
||||
# FreeRADIUS-Statistics-Type = 131
|
||||
# FreeRADIUS-Stats-Server-IP-Address = 192.0.2.2
|
||||
# FreeRADIUS-Stats-Server-Port = 1812
|
||||
|
||||
#
|
||||
# You can also get exponentially weighted moving averages of
|
||||
# response times (in usec) of home servers. Just set the config
|
||||
# item "historic_average_window" in a home_server section.
|
||||
#
|
||||
# By default it is zero (don't calculate it). Useful values
|
||||
# are between 100, and 10,000. The server will calculate and
|
||||
# remember the moving average for this window, and for 10 times
|
||||
# that window.
|
||||
#
|
||||
|
||||
#
|
||||
# Some of this could have been simplified. e.g. the proxy-auth and
|
||||
# proxy-acct bits aren't completely necessary. But using them permits
|
||||
# the server to be queried for ALL inbound && outbound packets at once.
|
||||
# This gives a good snapshot of what the server is doing.
|
||||
#
|
||||
# Due to internal limitations, the statistics might not be exactly up
|
||||
# to date. Do not expect all of the numbers to add up perfectly.
|
||||
# The Status-Server packets are also counted in the total requests &&
|
||||
# responses. The responses are counted only AFTER the response has
|
||||
# been sent.
|
||||
#
|
||||
@@ -0,0 +1,603 @@
|
||||
######################################################################
|
||||
#
|
||||
# RADIUS over TLS (radsec)
|
||||
#
|
||||
# When a new client connects, the various TLS parameters for the
|
||||
# connection are available as dynamic expansions, e.g.
|
||||
#
|
||||
# %{listen:TLS-Client-Cert-Common-Name}
|
||||
#
|
||||
# Along with other TLS-Client-Cert-... attributes.
|
||||
# These expansions will only exist if the relevant fields
|
||||
# are in the client certificate. Read the debug output to see
|
||||
# which fields are available. Look for output like the following:
|
||||
#
|
||||
# (0) TLS - Creating attributes from certificate OIDs
|
||||
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "one.example.org"
|
||||
# (0) TLS-Client-Cert-Subject-Alt-Name-Dns := "two.example.org"
|
||||
# ...
|
||||
#
|
||||
# It is also possible to distinguish between connections which have
|
||||
# TLS enables, and ones which do not. The expansion:
|
||||
#
|
||||
# %{listen:tls}
|
||||
#
|
||||
# Will return "yes" if the connection has TLS enabled. It will
|
||||
# return "no" if TLS is not enabled for a particular listen section.
|
||||
#
|
||||
# A number of TLS-Client-Cert-.. attributes holds X509v3 extensions
|
||||
# data, attributes named the way OpenSSL names them. It is possible
|
||||
# to extract data for an extension not known to OpenSSL by defining
|
||||
# a custom string attribute which contains extension OID in it's
|
||||
# name after 'TLS-Client-Cert-' prefix. E.g.:
|
||||
#
|
||||
# ATTRIBUTE TLS-Client-Cert-1.3.6.1.4.1.311.21.7 3002 string
|
||||
#
|
||||
# which will yield something simmilar to:
|
||||
#
|
||||
# (0) eap_tls: TLS - Creating attributes from certificate OIDs
|
||||
# (0) eap_tls: TLS-Client-Cert-1.3.6.1.4.1.311.21.7 += "0x302e06"
|
||||
# ...
|
||||
#
|
||||
######################################################################
|
||||
|
||||
listen {
|
||||
|
||||
# ipaddr = $ENV{FREERADIUS_SITES_TLS_LISTEN}
|
||||
ipaddr = *
|
||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
||||
|
||||
#
|
||||
# TCP and TLS sockets can accept Access-Request and Accounting-Request on the same socket.
|
||||
#
|
||||
# auth = only Access-Request
|
||||
# acct = only Accounting-Request
|
||||
# auth+acct = both
|
||||
# coa = only CoA / Disconnect requests
|
||||
#
|
||||
type = auth+acct
|
||||
|
||||
# For now, only TCP transport is allowed.
|
||||
proto = tcp
|
||||
|
||||
# Send packets to the default virtual server
|
||||
virtual_server = default
|
||||
|
||||
clients = radsec
|
||||
|
||||
# Use the haproxy "PROXY protocol".
|
||||
#
|
||||
# This configuration allows for many FreeRADIUS servers to be behind a haproxy server. The "PROXY protocol" allows haproxy to send the actual client IP to FreeRADIUS.
|
||||
#
|
||||
# This will work ONLY for RadSec (TLS). Both the haproxy AND the RadSec client MUST be listed as allowed RADIUS clients.
|
||||
#
|
||||
# haproxy needs to have "send-proxy" configured for this server. Health checks should be turned off, as haproxy does not support RADIUS health checks.
|
||||
#
|
||||
# The main use of this feature is for scalability. There is no longer any need to have a RADIUS proxy as a load balancer.
|
||||
# haproxy is fast, stable, and supports dynamic reloads!
|
||||
#
|
||||
# The only problem is that many RADIUS clients do not support RadSec. That situation will hopefully change over time.
|
||||
#
|
||||
# proxy_protocol = no
|
||||
|
||||
# When this is set to "yes", new TLS connections are processed through a section called
|
||||
#
|
||||
# Autz-Type New-TLS-Connection {
|
||||
# ...
|
||||
# }
|
||||
#
|
||||
# The request contains TLS client certificate attributes,
|
||||
# and nothing else. The debug output will print which
|
||||
# attributes are available on your system.
|
||||
#
|
||||
# If the section returns "ok" or "updated", then the
|
||||
# connection is accepted. Otherwise the connection is
|
||||
# terminated.
|
||||
#
|
||||
# check_client_connections = yes
|
||||
|
||||
#
|
||||
# Connection limiting for sockets with "proto = tcp".
|
||||
#
|
||||
limit {
|
||||
# Limit the number of simultaneous TCP connections to the socket
|
||||
#
|
||||
# The default is 16.
|
||||
# Setting this to 0 means "no limit"
|
||||
max_connections = 16
|
||||
|
||||
# The per-socket "max_requests" option does not exist.
|
||||
|
||||
# The lifetime, in seconds, of a TCP connection. After this lifetime, the connection will be closed.
|
||||
#
|
||||
# Setting this to 0 means "forever".
|
||||
lifetime = 0
|
||||
|
||||
# The idle timeout, in seconds, of a TCP connection. If no packets have been received over the connection for this time, the connection will be closed.
|
||||
#
|
||||
# Setting this to 0 means "no timeout".
|
||||
# We STRONGLY RECOMMEND that you set an idle timeout.
|
||||
#
|
||||
idle_timeout = 30
|
||||
}
|
||||
|
||||
# This is *exactly* the same configuration as used by the EAP-TLS
|
||||
# module. It's OK for testing, but for production use it's a good
|
||||
# idea to use different server certificates for EAP and for RADIUS
|
||||
# transport.
|
||||
#
|
||||
# If you want only one TLS configuration for multiple sockets,
|
||||
# then we suggest putting "tls { ...}" into radiusd.conf.
|
||||
# The subsection below can then be changed into a reference:
|
||||
#
|
||||
# tls = ${tls}
|
||||
#
|
||||
# Which means "the tls sub-section is not here, but instead is in
|
||||
# the top-level section called 'tls'".
|
||||
#
|
||||
# If you have multiple tls configurations, you can put them into
|
||||
# sub-sections of a top-level "tls" section. There's no need to
|
||||
# call them all "tls". You can then use:
|
||||
#
|
||||
# tls = ${tls.site1}
|
||||
#
|
||||
# to refer to the "site1" sub-section of the "tls" section.
|
||||
#
|
||||
tls {
|
||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
||||
|
||||
# Accept an expired Certificate Revocation List
|
||||
# allow_expired_crl = no
|
||||
|
||||
# If Private key & Certificate are located in
|
||||
# the same file, then private_key_file &
|
||||
# certificate_file must contain the same file
|
||||
# name.
|
||||
#
|
||||
# If ca_file (below) is not used, then the
|
||||
# certificate_file below MUST include not
|
||||
# only the server certificate, but ALSO all
|
||||
# of the CA certificates used to sign the
|
||||
# server certificate.
|
||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
||||
|
||||
|
||||
# Trusted Root CA list
|
||||
#
|
||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
||||
#
|
||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
||||
# In that case, this CA file should contain *one* CA certificate.
|
||||
#
|
||||
# This parameter is used only for EAP-TLS, when you issue client certificates. If you do not use client certificates, and you do not want
|
||||
# to permit EAP-TLS authentication, then delete this configuration item.
|
||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
||||
|
||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
||||
#
|
||||
# openssl dhparam -out certs/dh 1024
|
||||
#
|
||||
# dh_file = ${certdir}/dh
|
||||
|
||||
#
|
||||
# If your system doesn't have /dev/urandom,
|
||||
# you will need to create this file, and
|
||||
# periodically change its contents.
|
||||
#
|
||||
# For security reasons, FreeRADIUS doesn't
|
||||
# write to files in its configuration
|
||||
# directory.
|
||||
#
|
||||
# random_file = /dev/urandom
|
||||
|
||||
#
|
||||
# The default fragment size is 1K.
|
||||
# However, it's possible to send much more data than
|
||||
# that over a TCP connection. The upper limit is 64K.
|
||||
# Setting the fragment size to more than 1K means that
|
||||
# there are fewer round trips when setting up a TLS
|
||||
# connection. But only if the certificates are large.
|
||||
#
|
||||
fragment_size = 8192
|
||||
|
||||
# include_length is a flag which is
|
||||
# by default set to yes If set to
|
||||
# yes, Total Length of the message is
|
||||
# included in EVERY packet we send.
|
||||
# If set to no, Total Length of the
|
||||
# message is included ONLY in the
|
||||
# First packet of a fragment series.
|
||||
#
|
||||
# include_length = yes
|
||||
|
||||
# Check the Certificate Revocation List
|
||||
#
|
||||
# 1) Copy CA certificates and CRLs to same directory.
|
||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
||||
# 'c_rehash' is OpenSSL's command.
|
||||
# 3) uncomment the line below.
|
||||
# 5) Restart radiusd
|
||||
# check_crl = yes
|
||||
ca_path = ${cadir}
|
||||
|
||||
# OpenSSL does not reload contents of ca_path dir over time.
|
||||
# That means that if check_crl is enabled and CRLs are loaded
|
||||
# from ca_path dir, at some point CRLs will expire and
|
||||
# RADIUSd will stop authenticating NASes.
|
||||
# If ca_path_reload_interval is non-zero, it will force OpenSSL
|
||||
# to reload all data from ca_path periodically
|
||||
#
|
||||
# Flush ca_path each hour
|
||||
ca_path_reload_interval = 3600
|
||||
|
||||
#
|
||||
# If check_cert_issuer is set, the value will
|
||||
# be checked against the DN of the issuer in
|
||||
# the client certificate. If the values do not
|
||||
# match, the certificate verification will fail,
|
||||
# rejecting the user.
|
||||
#
|
||||
# This check can be done more generally by checking
|
||||
# the value of the TLS-Client-Cert-Issuer attribute.
|
||||
# This check can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
||||
|
||||
#
|
||||
# If check_cert_cn is set, the value will
|
||||
# be xlat'ed and checked against the CN
|
||||
# in the client certificate. If the values
|
||||
# do not match, the certificate verification
|
||||
# will fail rejecting the user.
|
||||
#
|
||||
# This check is done only if the previous
|
||||
# "check_cert_issuer" is not set, or if
|
||||
# the check succeeds.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Common-Name attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_cn = %{User-Name}
|
||||
#
|
||||
# Set this option to specify the allowed
|
||||
# TLS cipher suites. The format is listed
|
||||
# in "man 1 ciphers".
|
||||
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
|
||||
|
||||
# If enabled, OpenSSL will use server cipher list
|
||||
# (possibly defined by cipher_list option above)
|
||||
# for choosing right cipher suite rather than
|
||||
# using client-specified list which is OpenSSl default
|
||||
# behavior. Having it set to yes is a current best practice
|
||||
# for TLS
|
||||
cipher_server_preference = no
|
||||
|
||||
#
|
||||
# Older TLS versions are deprecated. But for RadSec,
|
||||
# we CAN allow TLS 1.3.
|
||||
#
|
||||
tls_min_version = "1.2"
|
||||
tls_max_version = "1.3"
|
||||
|
||||
#
|
||||
# Session resumption / fast reauthentication cache.
|
||||
#
|
||||
# The cache contains the following information:
|
||||
#
|
||||
# session Id - unique identifier, managed by SSL
|
||||
# User-Name - from the Access-Accept
|
||||
# Stripped-User-Name - from the Access-Request
|
||||
# Cached-Session-Policy - from the Access-Accept
|
||||
#
|
||||
# The "Cached-Session-Policy" is the name of a
|
||||
# policy which should be applied to the cached
|
||||
# session. This policy can be used to assign
|
||||
# VLANs, IP addresses, etc. It serves as a useful
|
||||
# way to re-apply the policy from the original
|
||||
# Access-Accept to the subsequent Access-Accept
|
||||
# for the cached session.
|
||||
#
|
||||
# On session resumption, these attributes are
|
||||
# copied from the cache, and placed into the
|
||||
# reply list.
|
||||
#
|
||||
# You probably also want "use_tunneled_reply = yes" when using fast session resumption.
|
||||
#
|
||||
cache {
|
||||
#
|
||||
# Enable it. The default is "no".
|
||||
# Deleting the entire "cache" subsection
|
||||
# Also disables caching.
|
||||
#
|
||||
#
|
||||
# As of version 3.0.14, the session cache requires the use
|
||||
# of the "name" and "persist_dir" configuration items, below.
|
||||
#
|
||||
# The internal OpenSSL session cache has been permanently
|
||||
# disabled.
|
||||
#
|
||||
# You can disallow resumption for a
|
||||
# particular user by adding the following
|
||||
# attribute to the control item list:
|
||||
#
|
||||
# Allow-Session-Resumption = No
|
||||
#
|
||||
# If "enable = no" below, you CANNOT
|
||||
# enable resumption for just one user
|
||||
# by setting the above attribute to "yes".
|
||||
#
|
||||
enable = no
|
||||
|
||||
#
|
||||
# Lifetime of the cached entries, in hours.
|
||||
# The sessions will be deleted after this
|
||||
# time.
|
||||
#
|
||||
lifetime = 24 # hours
|
||||
|
||||
#
|
||||
# Internal "name" of the session cache.
|
||||
# Used to distinguish which TLS context
|
||||
# sessions belong to.
|
||||
#
|
||||
# The server will generate a random value
|
||||
# if unset. This will change across server
|
||||
# restart so you MUST set the "name" if you
|
||||
# want to persist sessions (see below).
|
||||
#
|
||||
# If you use IPv6, change the "ipaddr" below
|
||||
# to "ipv6addr"
|
||||
#
|
||||
#name = "TLS ${..ipaddr} ${..port} ${..proto}"
|
||||
|
||||
#
|
||||
# Simple directory-based storage of sessions.
|
||||
# Two files per session will be written, the SSL
|
||||
# state and the cached VPs. This will persist session
|
||||
# across server restarts.
|
||||
#
|
||||
# The server will need write perms, and the directory
|
||||
# should be secured from anyone else. You might want
|
||||
# a script to remove old files from here periodically:
|
||||
#
|
||||
# find ${logdir}/tlscache -mtime +2 -exec rm -f {} \;
|
||||
#
|
||||
# This feature REQUIRES "name" option be set above.
|
||||
#
|
||||
#persist_dir = "${logdir}/tlscache"
|
||||
}
|
||||
|
||||
#
|
||||
# Require a client certificate.
|
||||
#
|
||||
require_client_cert = yes
|
||||
|
||||
#
|
||||
# As of version 2.1.10, client certificates can be
|
||||
# validated via an external command. This allows
|
||||
# dynamic CRLs or OCSP to be used.
|
||||
#
|
||||
# This configuration is commented out in the
|
||||
# default configuration. Uncomment it, and configure
|
||||
# the correct paths below to enable it.
|
||||
#
|
||||
verify {
|
||||
# A temporary directory where the client
|
||||
# certificates are stored. This directory
|
||||
# MUST be owned by the UID of the server,
|
||||
# and MUST not be accessible by any other
|
||||
# users. When the server starts, it will do
|
||||
# "chmod go-rwx" on the directory, for
|
||||
# security reasons. The directory MUST
|
||||
# exist when the server starts.
|
||||
#
|
||||
# You should also delete all of the files
|
||||
# in the directory when the server starts.
|
||||
# tmpdir = /tmp/radiusd
|
||||
# tmpdir = /startechnica/freeradius/tmp
|
||||
|
||||
# The command used to verify the client cert.
|
||||
# We recommend using the OpenSSL command-line
|
||||
# tool.
|
||||
#
|
||||
# The ${..ca_path} text is a reference to
|
||||
# the ca_path variable defined above.
|
||||
#
|
||||
# The %{TLS-Client-Cert-Filename} is the name
|
||||
# of the temporary file containing the cert
|
||||
# in PEM format. This file is automatically
|
||||
# deleted by the server when the command
|
||||
# returns.
|
||||
# client = "/path/to/openssl verify -CApath ${..ca_path} %{TLS-Client-Cert-Filename}"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
clients radsec {
|
||||
client 127.0.0.1 {
|
||||
ipaddr = 127.0.0.1
|
||||
|
||||
# Ensure that this client is TLS *only*.
|
||||
proto = tls
|
||||
|
||||
# TCP clients can have any shared secret.
|
||||
# TLS clients MUST have the shared secret set to "radsec". Or, for "proto = tls", you can omit the secret, and it will
|
||||
# automatically be set to "radsec".
|
||||
# secret = radsec
|
||||
secret = $ENV{FREERADIUS_CLIENTS_SECRET}
|
||||
|
||||
# You can also use a "limit" section here.
|
||||
# See raddb/clients.conf for examples.
|
||||
#
|
||||
# Note that BOTH limits are applied. You should therefore set the "listen" limits higher than the ones for each individual
|
||||
# client.
|
||||
}
|
||||
}
|
||||
|
||||
# When a request is proxied to a TLS-enabled home server, the TLS parameters are available via the expansion:
|
||||
#
|
||||
# %{proxy_listen: ... }
|
||||
#
|
||||
# The contents of the expansion are the same as described above with the %{listen: ... } expansion, and have similar meanings. "client" in this case is the proxy (this system)
|
||||
# and "server" is the remote system (home server).
|
||||
#
|
||||
# Note that the %{proxy_listen: ... } parameters are available only AFTER the connection has been made to the home server.
|
||||
home_server tls {
|
||||
ipaddr = 127.0.0.1
|
||||
port = $ENV{FREERADIUS_SITES_TLS_PORT}
|
||||
|
||||
# type can be the same types as for the "listen" section/
|
||||
# e.g. auth, acct, auth+acct, coa
|
||||
type = auth
|
||||
secret = radsec
|
||||
proto = tcp
|
||||
status_check = none
|
||||
|
||||
tls {
|
||||
#
|
||||
# Similarly to HTTP, the client can use Server Name
|
||||
# Indication to inform the RadSec server of which
|
||||
# domain it is requesting. This selection allows
|
||||
# multiple sites to exist at the same IP address.
|
||||
#
|
||||
# For example, and identity provider could host
|
||||
# multiple sites, but present itself with one public
|
||||
# IP address.
|
||||
#
|
||||
# SNI also permits the use of a load balancer such as
|
||||
# haproxy. That load balancer can terminate the TLS
|
||||
# connection, and then use SNI to route the
|
||||
# underlying RADIUS TCP traffic to a particular host.
|
||||
#
|
||||
# Note that "hostname" here is only for SNI, and is NOT
|
||||
# the hostname or IP address we connect to. For that,
|
||||
# see "ipaddr", above.
|
||||
#
|
||||
# hostname = "example.com"
|
||||
|
||||
private_key_password = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_PASSWORD}
|
||||
# private_key_file = ${certdir}/client.pem
|
||||
private_key_file = $ENV{FREERADIUS_SITES_TLS_PRIVKEY_FILE}
|
||||
|
||||
# If Private key & Certificate are located in
|
||||
# the same file, then private_key_file &
|
||||
# certificate_file must contain the same file
|
||||
# name.
|
||||
#
|
||||
# If ca_file (below) is not used, then the
|
||||
# certificate_file below MUST include not
|
||||
# only the server certificate, but ALSO all
|
||||
# of the CA certificates used to sign the
|
||||
# server certificate.
|
||||
# certificate_file = ${certdir}/client.pem
|
||||
certificate_file = $ENV{FREERADIUS_SITES_TLS_CERTIFICATE_FILE}
|
||||
|
||||
# Trusted Root CA list
|
||||
#
|
||||
# ALL of the CA's in this list will be trusted to issue client certificates for authentication.
|
||||
#
|
||||
# In general, you should use self-signed certificates for 802.1x (EAP) authentication.
|
||||
# In that case, this CA file should contain *one* CA certificate.
|
||||
#
|
||||
# This parameter is used only for EAP-TLS,
|
||||
# when you issue client certificates. If you do
|
||||
# not use client certificates, and you do not want
|
||||
# to permit EAP-TLS authentication, then delete
|
||||
# this configuration item.
|
||||
ca_file = $ENV{FREERADIUS_SITES_TLS_CA_FILE}
|
||||
|
||||
#
|
||||
# For TLS-PSK, the key should be specified dynamically, instead of using a hard-coded psk_identity and psk_hexphrase.
|
||||
#
|
||||
# The input to the dynamic expansion will be the PSK
|
||||
# identity supplied by the client, in the
|
||||
# TLS-PSK-Identity attribute. The output of the
|
||||
# expansion should be a hex string, of no more than
|
||||
# 512 characters. The string should not be prefixed
|
||||
# with "0x". e.g. "abcdef" is OK. "0xabcdef" is not.
|
||||
#
|
||||
# psk_query = "%{psksql:select hex(key) from psk_keys where keyid = '%{TLS-PSK-Identity}'}"
|
||||
|
||||
# For DH cipher suites to work, you have to run OpenSSL to create the DH file first:
|
||||
#
|
||||
# openssl dhparam -out certs/dh 1024
|
||||
#
|
||||
dh_file = ${certdir}/dh
|
||||
random_file = /dev/urandom
|
||||
|
||||
#
|
||||
# The default fragment size is 1K.
|
||||
# However, TLS can send 64K of data at once.
|
||||
# It can be useful to set it higher.
|
||||
#
|
||||
fragment_size = 8192
|
||||
|
||||
# include_length is a flag which is
|
||||
# by default set to yes If set to
|
||||
# yes, Total Length of the message is
|
||||
# included in EVERY packet we send.
|
||||
# If set to no, Total Length of the
|
||||
# message is included ONLY in the
|
||||
# First packet of a fragment series.
|
||||
#
|
||||
# include_length = yes
|
||||
|
||||
# Check the Certificate Revocation List
|
||||
#
|
||||
# 1) Copy CA certificates and CRLs to same directory.
|
||||
# 2) Execute 'c_rehash <CA certs&CRLs Directory>'.
|
||||
# 'c_rehash' is OpenSSL's command.
|
||||
# 3) uncomment the line below.
|
||||
# 5) Restart radiusd
|
||||
# check_crl = yes
|
||||
ca_path = ${cadir}
|
||||
|
||||
#
|
||||
# If check_cert_issuer is set, the value will
|
||||
# be checked against the DN of the issuer in
|
||||
# the client certificate. If the values do not
|
||||
# match, the certificate verification will fail,
|
||||
# rejecting the user.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Issuer attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_issuer = "/C=GB/ST=Berkshire/L=Newbury/O=My Company Ltd"
|
||||
|
||||
#
|
||||
# If check_cert_cn is set, the value will
|
||||
# be xlat'ed and checked against the CN
|
||||
# in the client certificate. If the values
|
||||
# do not match, the certificate verification
|
||||
# will fail rejecting the user.
|
||||
#
|
||||
# This check is done only if the previous
|
||||
# "check_cert_issuer" is not set, or if
|
||||
# the check succeeds.
|
||||
#
|
||||
# In 2.1.10 and later, this check can be done
|
||||
# more generally by checking the value of the
|
||||
# TLS-Client-Cert-Common-Name attribute. This check
|
||||
# can be done via any mechanism you choose.
|
||||
#
|
||||
# check_cert_cn = %{User-Name}
|
||||
#
|
||||
# Set this option to specify the allowed TLS cipher suites. The format is listed in "man 1 ciphers".
|
||||
cipher_list = $ENV{FREERADIUS_SITES_TLS_CIPHER}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
home_server_pool tls {
|
||||
type = fail-over
|
||||
home_server = tls
|
||||
}
|
||||
|
||||
realm tls {
|
||||
auth_pool = tls
|
||||
}
|
||||
Reference in New Issue
Block a user