iT邦幫忙

0

Freeradius 透過 eap-tls 驗證錯誤

  • 分享至 

  • xImage

各位好,請教一下,
想嘗試透過 freeradius 結合 eap-tls 的驗證機制,
透過 google 大神有找到一篇類似的設定說明
https://www.tp-link.com/us/support/faq/3456/
照著設定以後,freeradius server 雖然沒有跳 錯誤訊息,
但 windows client 並沒有認證成功
在 switch 上面也只有看到 radius access-challenge packets
不知是否有除錯的方向可以參考,
謝謝大家的回覆。
https://ithelp.ithome.com.tw/upload/images/20230704/201471452IdvCM0X7q.png

補充說明:在 freeradius 上開啟 debug mode 後,有發現下列的 error message
(80) eap: ERROR: rlm_eap (EAP): No EAP session matching state
(80) eap: Either EAP-request timed out OR EAP-response to an unknown EAP-request
(80) eap: Failed in handler
(80) [eap] = invalid
(80) } # authenticate = invalid
(80) Failed to authenticate the user

2023/07/05 補充 error message 如下
(35) eap_tls: >>> send TLS 1.2 [length 0002]
(35) eap_tls: ERROR: TLS Alert write:fatal:decode error
[tls: TLS_accept: Error in error
(35) eap_tls: ERROR: Failed in FUNCTION (SSL_read)
(35) eap_tls: ERROR: error:0D07207B:asn1 encoding routines:ASN1_get_object:header too long
(35) eap_tls: ERROR: error:0D068066:asn1 encoding routines:asn1_check_tlen:bad object header
(35) eap_tls: ERROR: error:0D06A03A:asn1 encoding routines:asn1_collect:nested asn1 error
(35) eap_tls: ERROR: error:0D08303A:asn1 encoding routines:asn1_template_noexp_d2i:nested asn1 error
(35) eap_tls: ERROR: error:0D08303A:asn1 encoding routines:asn1_template_noexp_d2i:nested asn1 error
(35) eap_tls: ERROR: error:1417C00D:SSL routines:tls_process_client_certificate:ASN1 lib
(35) eap_tls: ERROR: System call (I/O) error (-1)
(35) eap_tls: ERROR: TLS receive handshake failed during operation
(35) eap_tls: ERROR: [eaptls process] = fail
(35) eap: ERROR: Failed continuing EAP TLS (13) session. EAP sub-module failed
(35) eap: Sending EAP Failure (code 4) ID 18 length 4
(35) eap: Failed in EAP select
(35) [eap] = invalid
(35) } # authenticate = invalid
(35) Failed to authenticate the user
(35) Using Post-Auth-Type Reject

圖片
  直播研討會
圖片
{{ item.channelVendor }} {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友回答

立即登入回答