Столкнулся с проблемой при настройке freeradius2, пару дней за гуглом результатов не принесли, так как все тексты ссылаются на БД идущую с радиусом.Имеется собственная БД с login и pass
к примеру: id, login, pass, name, tariff, tel, emailв какой вид мне необходимо привести dialup.conf?
сейчас:
authorize_check_query = "select id, login as username, pass as attribute, '', 'qwe' from users where login='%{User-Name}';"
authorize_reply_query = "select id, login as username, pass as attribute, '', 'qwe' from users where login='%{User-Name}';"лог:
rad_recv: Access-Request packet from host 127.0.0.1 port 15904, id=60, length=55
User-Name = "qwe"
User-Password = "qwe"
NAS-IP-Address = 95.23.45.4
NAS-Port = 1812
# Executing section authorize from file /usr/local/etc/raddb/sites-enabled/default
+- entering group authorize {...}
++[preprocess] returns ok
++[chap] returns noop
++[mschap] returns noop
++[digest] returns noop
[suffix] No '@' in User-Name = "qwe", looking up realm NULL
[suffix] No such realm "NULL"
++[suffix] returns noop
[eap] No EAP-Message, not doing EAP
++[eap] returns noop
++[files] returns noop
[sql] expand: %{User-Name} -> qwe
[sql] sql_set_user escaped user --> 'qwe'
rlm_sql (sql): Reserving sql socket id: 4
[sql] expand: select id, login as username, pass as attribute, '', 'qwe' from users where login='%{User-Name}'; -> select id, login as username, pass as attribute, '', 'qwe' from users where login='qwe';
rlm_sql: Invalid operator "qwe" for attribute qwe
rlm_sql (sql): Error getting data from database
[sql] SQL query error; rejecting user
rlm_sql (sql): Released sql socket id: 4
++[sql] returns fail
Invalid user: [qwe/qwe] (from client localhost port 1812)
Using Post-Auth-Type Reject
# Executing group from file /usr/local/etc/raddb/sites-enabled/default
+- entering group REJECT {...}
[sql] expand: %{User-Name} -> qwe
[sql] sql_set_user escaped user --> 'qwe'
++[sql] returns noop
[attr_filter.access_reject] expand: %{User-Name} -> qwe
attr_filter: Matched entry DEFAULT at line 11
++[attr_filter.access_reject] returns updated
Delaying reject of request 0 for 1 seconds
Going to the next request
Waking up in 0.9 seconds.
Sending delayed reject for request 0
Sending Access-Reject of id 60 to 127.0.0.1 port 15904
Waking up in 4.9 seconds.
Cleaning up request 0 ID 60 with timestamp +5
Ready to process requests.
Как-то так:authorize_check_query = "select id, login as username, 'Crypt-Password' as attribute, pass as value, ':=' as op from users where login='%{User-Name}' order by id"
authorize_reply_query = "select id, login as username, 'Crypt-Password' as attribute, pass as value, ':=' as op from users where login='%{User-Name}' order by id"
> Как-то так:
> authorize_check_query = "select id, login as username, 'Crypt-Password' as attribute,
> pass as value, ':=' as op from users where login='%{User-Name}' order
> by id"
> authorize_reply_query = "select id, login as username, 'Crypt-Password' as attribute,
> pass as value, ':=' as op from users where login='%{User-Name}' order
> by id"Спасибо большое, время 5 утра я все туплю, подскажите куда копать, теперь выскакивает:
++[sql] returns ok
++[expiration] returns noop
++[logintime] returns noop
++[pap] returns updated
Found Auth-Type = PAP
# Executing group from file /usr/local/etc/raddb/sites-enabled/default
+- entering group PAP {...}
[pap] login attempt with password "qwe"
[pap] Using CRYPT password "qwe"
[pap] Passwords don't match
++[pap] returns reject
Failed to authenticate the user.
Login incorrect (rlm_pap: CRYPT password check failed): [qwe/qwe] (from client localhost port 1812)
Using Post-Auth-Type Reject
# Executing group from file /usr/local/etc/raddb/sites-enabled/default
+- entering group REJECT {...}
++[sql] returns noop
сменил Crypt-Password на Cleartext-Password, еще раз спасибо