OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • 22.7 Legacy Series »
  • freeradius: EAP-TLS broken since update
« previous next »
  • Print
Pages: [1]

Author Topic: freeradius: EAP-TLS broken since update  (Read 432 times)

senser8912

  • Newbie
  • *
  • Posts: 10
  • Karma: 0
    • View Profile
freeradius: EAP-TLS broken since update
« on: November 20, 2022, 06:56:10 am »
Hello,

I already posted in the german part of this forum (https://forum.opnsense.org/index.php?topic=31124.0).
Since my update to 22.7.8, which included an update of freeradius to version 3.2.1 I'm facing problems with my wifi-clients.
They simply won't connect anymore, the radius-log is showing the error, that you can see below.
I tried reinstalling the freeradius-package, deleting the raddb-folder etc. None of which has worked so far.

Code: [Select]
Auth: (25) Login incorrect (eap: Failed continuing EAP TLS (13) session. EAP sub-module failed): [USERNAME/<via Auth-Type = eap>] (from client ACCESSPOINT port 0 cli XX-XX-XX-XX-XX-XX)

Auth: (25) Login incorrect: [USERNAME/<via Auth-Type = Reject>] (from client ACCESSPOINT port 0 cli XX-XX-XX-XX-XX-XX via TLS tunnel)
Logged

senser8912

  • Newbie
  • *
  • Posts: 10
  • Karma: 0
    • View Profile
Re: freeradius: EAP-TLS broken since update
« Reply #1 on: November 20, 2022, 04:03:06 pm »
I found a very unsatisfying solution: The config-parameter "Check TLS Common-Name" was suddenly causing these problems.
If I uncheck this box everything works just fine.
But: Now everyone with a valid certificate could log in as any other user...

Is this a bug?
Cause it worked just fine before the update and of course the common-names and usernames are identical.
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6332
  • Karma: 435
    • View Profile
Re: freeradius: EAP-TLS broken since update
« Reply #2 on: November 22, 2022, 06:55:39 pm »
Can you try to revert:

https://forum.opnsense.org/index.php?topic=31124.msg150219#msg150219
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

senser8912

  • Newbie
  • *
  • Posts: 10
  • Karma: 0
    • View Profile
Re: freeradius: EAP-TLS broken since update
« Reply #3 on: November 25, 2022, 09:37:27 am »
Hi mimugmail,

thanks for your help, reverting helped indeed!

Code: [Select]
opnsense-revert -r 22.7.3 freeradius3

But this is obviously a software bug?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6332
  • Karma: 435
    • View Profile
Re: freeradius: EAP-TLS broken since update
« Reply #4 on: November 25, 2022, 12:13:24 pm »
Quote from: senser8912 on November 25, 2022, 09:37:27 am
Hi mimugmail,

thanks for your help, reverting helped indeed!

Code: [Select]
opnsense-revert -r 22.7.3 freeradius3

But this is obviously a software bug?

A bug of FreeRadius where OPN is not responsible of.
Can you also revert to 22.7.7 and check again?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • 22.7 Legacy Series »
  • freeradius: EAP-TLS broken since update
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2