[Serusers] FreeRadius MD5 Problem
Heimo Hetl
trashcan at hetl.net
Sun Apr 30 16:17:56 CEST 2006
I had exactly the same problem with SER 0.9.6 and radiusclient-ng
0.5.2 on FreeBSD/Sparc64. I read all the problem reports I found on
Google - they all led to the suggestion that my shared secrets
between radiusclient and FreeRadius mismatch. However, I double-
checked the entries - I also set them to some very simple values, all
to no avail.
So I cloned the Sparc64 setup to an i386 machine using the exact same
releases of FreeBSD, SER and radiusclient-ng. I scp'ed all the config
files from the Spacr box to the i386...
and presto, it works like a charm. So maybe it really is a problem
with calculation of MD5 on 64bit architectures.
cheers
Heimo
(sorry, I don't know how to debug the source myself, but if I can be
of any help leading to a fix, please let me know!)
Am 09.03.2006 um 23:36 schrieb Jan Janak:
> Do you have the same shared secret configured in the client library
> and server ?
>
> Jan.
>
> Edson wrote:
>> I'm facing some really weird problem. Let's try to explain, but
>> first my
>> config (basically):
>>
>> OpenSUSE 10.0
>> FreeRadius 1.0.4-4
>> RadiusClient-NG 0.5.2
>> SER 0.9.6
>> MySQL 5.0.18
>>
>> THE GOALs: upgrade from SER 0.8.4 to 0.9.6; MySQL from 4.0 to 5.0.
>>
>> THE SCENE: FreeRadius, using MySQL as back-end, as SER. SER
>> configured to
>> consult Radius and make account on both places (Radius and MySQL).
>> I have
>> this same configuration running and OK, but on an old version of
>> SER (0.8.4)
>> + MySQL 4.0 + RadiusClient-NG 0.5.0. MySQL is running OK and
>> responding to
>> all queries, as expected.
>>
>> THE PROBLEM: with the upgrade the RadiusClient-NG is reporting
>> that the
>> digest (MD5) returned by the Radius server isn't correct. If I
>> tweak the
>> code of sendserver.c (radiusclient-ng-0.5.2/lib/sendserver.c) to
>> compile it
>> with DEBUG displays, it shows me that different digests. One that
>> comes from
>> FreeRadius and another calculated.
>>
>> So now I stuck... I can not go on with the upgrade 'til I find a
>> solution to
>> this issue. Not using Radius is not a possibility.
>>
>> Did anybody cross this problem and find a solution?
>>
>> Edson.
>>
>> _______________________________________________
>> Serusers mailing list
>> serusers at lists.iptel.org
>> http://lists.iptel.org/mailman/listinfo/serusers
>>
>
> _______________________________________________
> Serusers mailing list
> serusers at lists.iptel.org
> http://lists.iptel.org/mailman/listinfo/serusers
>
>
More information about the sr-users
mailing list