Freeradius: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
 
(10 dazwischenliegende Versionen von 3 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:
−
=clients.conf=
+
=installation=
−
<pre>
+
*apt-get install freeradius freeradius-ldap
−
cat /etc/freeradius/clients.conf
+
*[[freeradius erklärt]]
−
client localhost {
+
*[[freeradius 3.x]]
−
ipaddr = 127.0.0.1
+
*[[freeradius switch mac authentication bypass]]
−
secret = secretkey
+
*[[freeradius leap]]
−
nastype    = other
+
*[[freeradius peap]]
−
}
+
*[[freeradius ldap]]
−
client 192.168.0.0/16 {
 
−
secret = secretkey
 
−
nastype = other
 
−
}
 
−
client 10.0.0.0/8 {
 
−
secret = secretkey
 
−
nastype = other
 
−
}
 
−
</pre>
 
−
 
 
−
=radiusd.conf=
 
−
<pre>
 
−
cat  /etc/freeradius/radiusd.conf
 
−
prefix = /usr
 
−
exec_prefix = /usr
 
−
sysconfdir = /etc
 
−
localstatedir = /var
 
−
sbindir = ${exec_prefix}/sbin
 
−
logdir = /var/log/freeradius
 
−
raddbdir = /etc/freeradius
 
−
radacctdir = ${logdir}/radacct
 
−
name = freeradius
 
−
confdir = ${raddbdir}
 
−
run_dir = ${localstatedir}/run/${name}
 
−
db_dir = ${raddbdir}
 
−
libdir = /usr/lib/freeradius
 
−
pidfile = ${run_dir}/${name}.pid
 
−
user = freerad
 
−
group = freerad
 
−
max_request_time = 30
 
−
cleanup_delay = 5
 
−
max_requests = 1024
 
−
listen {
 
−
type = auth
 
−
ipaddr = *
 
−
port = 0
 
−
}
 
−
listen {
 
−
ipaddr = *
 
−
port = 0
 
−
type = acct
 
−
}
 
−
hostname_lookups = no
 
−
allow_core_dumps = no
 
−
regular_expressions    = yes
 
−
extended_expressions    = yes
 
−
log {
 
−
destination = files
 
−
file = ${logdir}/radius.log
 
−
syslog_facility = daemon
 
−
stripped_names = no
 
−
auth = no
 
−
auth_badpass = no
 
−
auth_goodpass = no
 
−
}
 
−
checkrad = ${sbindir}/checkrad
 
−
security {
 
−
max_attributes = 200
 
−
reject_delay = 1
 
−
status_server = yes
 
−
}
 
−
proxy_requests  = yes
 
−
$INCLUDE proxy.conf
 
−
$INCLUDE clients.conf
 
−
thread pool {
 
−
start_servers = 5
 
−
max_servers = 32
 
−
min_spare_servers = 3
 
−
max_spare_servers = 10
 
−
max_requests_per_server = 0
 
−
}
 
−
modules {
 
−
$INCLUDE ${confdir}/modules/
 
−
}
 
−
instantiate {
 
−
exec
 
−
expr
 
−
expiration
 
−
logintime
 
−
}
 
−
$INCLUDE policy.conf
 
−
$INCLUDE sites-enabled/
 
−
</pre>
 
−
=ldap=
 
−
<pre>
 
−
cat /etc/freeradius/modules/ldap
 
−
ldap {
 
−
server = "thor.tuxmen.de"
 
−
port = "636"
 
−
basedn = "dc=xinux,dc=de"
 
−
filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
 
−
ldap_connections_number = 5
 
−
timeout = 4
 
−
timelimit = 3
 
−
net_timeout = 1
 
−
dictionary_mapping = ${confdir}/ldap.attrmap
 
−
edir_account_policy_check = no
 
−
set_auth_type = yes
 
−
}
 
−
</pre>
 
−
 
 
−
=default=
 
−
<pre>
 
−
cat /etc/freeradius/sites-enabled/default
 
−
authorize {
 
−
ldap
 
−
}
 
−
authenticate {
 
−
Auth-Type LDAP {
 
−
ldap
 
−
}
 
−
}
 
−
preacct {
 
−
}
 
−
accounting {
 
−
}
 
−
session {
 
−
radutmp
 
−
}
 
−
post-auth {
 
−
exec
 
−
Post-Auth-Type REJECT {
 
−
attr_filter.access_reject
 
−
}
 
−
}
 
−
pre-proxy {
 
−
}
 
−
post-proxy {
 
−
}
 
−
</pre>
 
−
 
 
−
=inner-tunnel=
 
−
<pre>
 
−
server inner-tunnel {
 
−
authorize {
 
−
ldap
 
−
}
 
−
authenticate {
 
−
Auth-Type LDAP {
 
−
ldap
 
−
}
 
−
}
 
−
session {
 
−
radutmp
 
−
}
 
−
post-auth {
 
−
Post-Auth-Type REJECT {
 
−
attr_filter.access_reject
 
−
}
 
−
}
 
−
pre-proxy {
 
−
}
 
−
post-proxy {
 
−
}
 
−
}
 
−
</pre>
 
  
 
=links=
 
=links=
Zeile 168: Zeile 12:
 
*http://paulgporter.net/2013/07/14/freeradius-ldaps/
 
*http://paulgporter.net/2013/07/14/freeradius-ldaps/
 
*http://ubuntuforums.org/showthread.php?t=1976883
 
*http://ubuntuforums.org/showthread.php?t=1976883
 +
*https://kupschke.net/2013/10/11/freeradius-mit-eap-peap-und-ldap-zur-sicheren-wlan-authentifizierung/

Aktuelle Version vom 5. Dezember 2018, 11:22 Uhr