Re: 12077 error???

2005-09-20 Thread Ben Walding
To me, it looks like your private key file might bea) in the wrong formatb) not contain the private keyOn 9/16/05, Armin Krämer 
[EMAIL PROTECTED] wrote:I build the deb Files out of the source.-Ursprüngliche Nachricht-
Von: [EMAIL PROTECTED][mailto:[EMAIL PROTECTED]
] Im Auftrag von King,MichaelGesendet: Donnerstag, 15. September 2005 16:50An: FreeRadius users mailing listBetreff: RE: 12077 error??? -Original Message- From: 
[EMAIL PROTECTED] Behalf Of Armin Krämer Hi, I set up freeradius with eap-tls and after I generated my certificates with TinnyCA and configured it in eap.conf
 File I get this error message...Does anyone knows what causes this error? Thanks Armin debian:~# freeradius -X -ADid you install FreeRadius via Apt (aptitude) or compile from source?
-List info/subscribe/unsubscribe? Seehttp://www.freeradius.org/list/users.html-List info/subscribe/unsubscribe? See 
http://www.freeradius.org/list/users.html
- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

12077 error???

2005-09-15 Thread Armin Krämer
Hi, I set up freeradius with eap-tls and after I generated my certificates
with TinnyCA and configured it in eap.conf File I get this error
message...Does anyone knows what causes this error?
Thanks Armin

debian:~# freeradius -X -A
Starting - reading configuration files ...
reread_config:  reading radiusd.conf
Config:   including file: /etc/freeradius/proxy.conf
Config:   including file: /etc/freeradius/clients.conf
Config:   including file: /etc/freeradius/snmp.conf
Config:   including file: /etc/freeradius/eap.conf
Config:   including file: /etc/freeradius/sql.conf
 main: prefix = /usr
 main: localstatedir = /var
 main: logdir = /var/log/freeradius
 main: libdir = /usr/lib/freeradius
 main: radacctdir = /var/log/freeradius/radacct
 main: hostname_lookups = no
 main: max_request_time = 30
 main: cleanup_delay = 5
 main: max_requests = 1024
 main: delete_blocked_requests = 0
 main: port = 0
 main: allow_core_dumps = no
 main: log_stripped_names = no
 main: log_file = /var/log/freeradius/radius.log
 main: log_auth = no
 main: log_auth_badpass = no
 main: log_auth_goodpass = no
 main: pidfile = /var/run/freeradius/freeradius.pid
 main: user = freerad
 main: group = freerad
 main: usercollide = no
 main: lower_user = no
 main: lower_pass = no
 main: nospace_user = no
 main: nospace_pass = no
 main: checkrad = /usr/sbin/checkrad
 main: proxy_requests = yes
 proxy: retry_delay = 5
 proxy: retry_count = 3
 proxy: synchronous = no
 proxy: default_fallback = yes
 proxy: dead_time = 120
 proxy: post_proxy_authorize = yes
 proxy: wake_all_if_all_dead = no
 security: max_attributes = 200
 security: reject_delay = 1
 security: status_server = no
 main: debug_level = 0
read_config_files:  reading dictionary
read_config_files:  reading naslist
Using deprecated naslist file.  Support for this will go away soon.
read_config_files:  reading clients
read_config_files:  reading realms
radiusd:  entering modules setup
Module: Library search path is /usr/lib/freeradius
Module: Loaded exec
 exec: wait = yes
 exec: program = (null)
 exec: input_pairs = request
 exec: output_pairs = (null)
 exec: packet_type = (null)
rlm_exec: Wait=yes but no output defined. Did you mean output=none?
Module: Instantiated exec (exec)
Module: Loaded expr
Module: Instantiated expr (expr)
Module: Loaded PAP
 pap: encryption_scheme = crypt
Module: Instantiated pap (pap)
Module: Loaded CHAP
Module: Instantiated chap (chap)
Module: Loaded MS-CHAP
 mschap: use_mppe = yes
 mschap: require_encryption = no
 mschap: require_strong = no
 mschap: with_ntdomain_hack = no
 mschap: passwd = (null)
 mschap: authtype = MS-CHAP
 mschap: ntlm_auth = (null)
Module: Instantiated mschap (mschap)
Module: Loaded System
 unix: cache = no
 unix: passwd = (null)
 unix: shadow = /etc/shadow
 unix: group = (null)
 unix: radwtmp = /var/log/freeradius/radwtmp
 unix: usegroup = no
 unix: cache_reload = 600
Module: Instantiated unix (unix)
Module: Loaded eap
 eap: default_eap_type = tls
 eap: timer_expire = 60
 eap: ignore_unknown_eap_types = no
 eap: cisco_accounting_username_bug = no
rlm_eap: Loaded and initialized type md5
rlm_eap: Loaded and initialized type leap
 gtc: challenge = Password: 
 gtc: auth_type = PAP
rlm_eap: Loaded and initialized type gtc
 tls: rsa_key_exchange = no
 tls: dh_key_exchange = yes
 tls: rsa_key_length = 512
 tls: dh_key_length = 512
 tls: verify_depth = 0
 tls: CA_path = (null)
 tls: pem_file_type = yes
 tls: private_key_file = /etc/freeradius/certs/cert-srv.pem
 tls: certificate_file = /etc/freeradius/certs/cert-srv.pem
 tls: CA_file = /etc/freeradius/certs/cacert.pem
 tls: private_key_password = test
 tls: dh_file = /etc/freeradius/certs/dh
 tls: random_file = /etc/freeradius/certs/random
 tls: fragment_size = 1024
 tls: include_length = yes
 tls: check_crl = no
 tls: check_cert_cn = (null)
12077:error:0906D06C:PEM routines:PEM_read_bio:no start
line:pem_lib.c:637:Expecting: CERTIFICATE
12077:error:06065064:digital envelope routines:EVP_DecryptFinal:bad
decrypt:evp_enc.c:450:
12077:error:0906A065:PEM routines:PEM_do_header:bad decrypt:pem_lib.c:423:
12077:error:140B0009:SSL routines:SSL_CTX_use_PrivateKey_file:PEM
lib:ssl_rsa.c:709:
rlm_eap_tls: Error reading private key file
rlm_eap: Failed to initialize type tls
radiusd.conf[9]: eap: Module instantiation failed.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


RE: 12077 error???

2005-09-15 Thread King, Michael

 -Original Message-
 From: [EMAIL PROTECTED] 
 Behalf Of Armin Krämer
 
 Hi, I set up freeradius with eap-tls and after I generated my 
 certificates with TinnyCA and configured it in eap.conf File 
 I get this error message...Does anyone knows what causes this error?
 Thanks Armin
 
 debian:~# freeradius -X -A

Did you install FreeRadius via Apt (aptitude) or compile from source? 

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


AW: 12077 error???

2005-09-15 Thread Armin Krämer
I build the deb Files out of the source.

-Ursprüngliche Nachricht-
Von: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Im Auftrag von King,
Michael
Gesendet: Donnerstag, 15. September 2005 16:50
An: FreeRadius users mailing list
Betreff: RE: 12077 error???


 -Original Message-
 From: [EMAIL PROTECTED] 
 Behalf Of Armin Krämer
 
 Hi, I set up freeradius with eap-tls and after I generated my 
 certificates with TinnyCA and configured it in eap.conf File 
 I get this error message...Does anyone knows what causes this error?
 Thanks Armin
 
 debian:~# freeradius -X -A

Did you install FreeRadius via Apt (aptitude) or compile from source? 

- 
List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html


- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html