mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
use radcli as the radius library if found
This commit is contained in:
+14
-5
@@ -188,6 +188,9 @@ AC_ARG_WITH(radius,
|
|||||||
radius_enabled=no
|
radius_enabled=no
|
||||||
|
|
||||||
if test "$test_for_radius" = yes;then
|
if test "$test_for_radius" = yes;then
|
||||||
|
PKG_CHECK_MODULES([RADCLI], [radcli >= 1.2.0], radius_enabled=radcli, radius_enabled=no)
|
||||||
|
|
||||||
|
if test "$radius_enabled" = no;then
|
||||||
LIBS="$oldlibs -lfreeradius-client"
|
LIBS="$oldlibs -lfreeradius-client"
|
||||||
AC_MSG_CHECKING([for freeradius client library])
|
AC_MSG_CHECKING([for freeradius client library])
|
||||||
AC_LINK_IFELSE([AC_LANG_PROGRAM([
|
AC_LINK_IFELSE([AC_LANG_PROGRAM([
|
||||||
@@ -197,18 +200,24 @@ AC_LINK_IFELSE([AC_LANG_PROGRAM([
|
|||||||
#endif
|
#endif
|
||||||
rc_read_config(0);])],
|
rc_read_config(0);])],
|
||||||
[AC_MSG_RESULT(yes)
|
[AC_MSG_RESULT(yes)
|
||||||
AC_SUBST([FREERADIUS_CLIENT_LIBS], [-lfreeradius-client])
|
AC_SUBST([RADCLI_LIBS], [-lfreeradius-client])
|
||||||
AC_SUBST([FREERADIUS_CLIENT_CFLAGS], [])
|
AC_SUBST([RADCLI_CFLAGS], [])
|
||||||
radius_enabled=yes
|
radius_enabled=freeradius-client
|
||||||
AC_DEFINE([HAVE_RADIUS], 1, [Enable the Radius library])],
|
AC_DEFINE([LEGACY_RADIUS], 1, [Enable the legacy library support])],
|
||||||
[AC_MSG_RESULT(no)
|
[AC_MSG_RESULT(no)
|
||||||
AC_MSG_WARN([[
|
AC_MSG_WARN([[
|
||||||
***
|
***
|
||||||
*** freeradius-client 1.1.7 or later was not found. Radius support will be disabled.
|
*** radcli 1.2.0 or later was not found. Radius support will be disabled.
|
||||||
|
*** See https://github.com/nmav/radcli
|
||||||
*** ]])])
|
*** ]])])
|
||||||
LIBS="$oldlibs"
|
LIBS="$oldlibs"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if test "$radius_enabled" != no;then
|
||||||
|
AC_DEFINE([HAVE_RADIUS], 1, [Enable the Radius library])
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
gl_INIT
|
gl_INIT
|
||||||
|
|
||||||
AC_LIB_HAVE_LINKFLAGS(crypt,, [#define _XOPEN_SOURCE
|
AC_LIB_HAVE_LINKFLAGS(crypt,, [#define _XOPEN_SOURCE
|
||||||
|
|||||||
+31
-24
@@ -1,49 +1,58 @@
|
|||||||
============================================
|
|
||||||
Using Radius with ocserv
|
Using Radius with ocserv
|
||||||
============================================
|
========================
|
||||||
|
|
||||||
For radius support the freeradius-client library is required. The
|
For radius support the radcli library is required. The
|
||||||
minimum requirement is version 1.1.7 as released at:
|
minimum requirement is version 1.2.0 as released at:
|
||||||
https://github.com/FreeRADIUS/freeradius-client
|
https://github.com/nmav/radcli
|
||||||
|
|
||||||
Freeradius-client uses a configuration file to setup the
|
radcli uses a configuration file to setup the
|
||||||
server configuration. That is typically found at:
|
server configuration. That is typically found at:
|
||||||
/etc/radiusclient/radiusclient.conf
|
/etc/radcl/radiusclient.conf
|
||||||
and is best to copy the default installed by freeradius-client
|
and is best to copy the default installed as radiusclient-ocserv.conf
|
||||||
as radiusclient-ocserv.conf and edit it accordingly.
|
and edit it accordingly.
|
||||||
|
|
||||||
The important options for ocserv usage are the following:
|
The important options for ocserv usage are the following:
|
||||||
dictionary /etc/radiusclient/dictionary
|
```
|
||||||
servers /etc/radiusclient/servers
|
dictionary /etc/radcli/dictionary
|
||||||
|
servers /etc/radcli/servers
|
||||||
|
```
|
||||||
|
|
||||||
The dictionary should contain at least the attributes shown below,
|
The dictionary should contain at least the attributes shown below,
|
||||||
and the servers file should contain the radius server to use.
|
and the servers file should contain the radius server to use.
|
||||||
|
|
||||||
============================================
|
|
||||||
Ocserv configuration
|
Ocserv configuration
|
||||||
============================================
|
====================
|
||||||
|
|
||||||
For authentication the following line should be enabled.
|
For authentication the following line should be enabled.
|
||||||
#auth = "radius[/path/to/radiusclient.conf,groupconfig]"
|
```
|
||||||
|
auth = "radius[config=/etc/radiusclient/radiusclient.conf,groupconfig=true]"
|
||||||
|
```
|
||||||
|
|
||||||
Check the ocserv manpage for the meaning of the various options
|
Check the ocserv manpage for the meaning of the various options
|
||||||
such as groupconfig.
|
such as groupconfig.
|
||||||
|
|
||||||
To enable accounting, set the following option to the time (in
|
To enable accounting, use
|
||||||
|
```
|
||||||
|
acct = "radius[config=/etc/radiusclient/radiusclient.conf]"
|
||||||
|
```
|
||||||
|
|
||||||
|
and modify the following option to the time (in
|
||||||
seconds), that accounting information should be reported.
|
seconds), that accounting information should be reported.
|
||||||
#stats-report-time = 360
|
```
|
||||||
|
stats-report-time = 360
|
||||||
|
```
|
||||||
|
|
||||||
That value will be overriden by Acct-Interim-Interval if sent
|
That value will be overriden by Acct-Interim-Interval if sent
|
||||||
by the server.
|
by the server.
|
||||||
|
|
||||||
============================================
|
|
||||||
Dictionary
|
Dictionary
|
||||||
============================================
|
==========
|
||||||
|
|
||||||
#
|
Ocserv supports the following radious attributes.
|
||||||
# Ocserv supports the following radious attributes.
|
|
||||||
#
|
|
||||||
|
|
||||||
|
```
|
||||||
# Standard attributes
|
# Standard attributes
|
||||||
ATTRIBUTE User-Name 1 string
|
ATTRIBUTE User-Name 1 string
|
||||||
ATTRIBUTE Password 2 string
|
ATTRIBUTE Password 2 string
|
||||||
@@ -108,6 +117,4 @@ ATTRIBUTE Route-IPv6-Information 170 ipv6prefix
|
|||||||
# Experimental Non Protocol Attributes used by Cistron-Radiusd
|
# Experimental Non Protocol Attributes used by Cistron-Radiusd
|
||||||
#
|
#
|
||||||
ATTRIBUTE Group-Name 1030 string
|
ATTRIBUTE Group-Name 1030 string
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -6,7 +6,7 @@ AM_CPPFLAGS = -I$(srcdir)/../gl/ -I$(builddir)/../gl/ \
|
|||||||
$(LIBPROTOBUF_C_CFLAGS) $(LIBLZ4_CFLAGS) \
|
$(LIBPROTOBUF_C_CFLAGS) $(LIBLZ4_CFLAGS) \
|
||||||
$(LIBNL3_CFLAGS) $(LIBREADLINE_CFLAGS) \
|
$(LIBNL3_CFLAGS) $(LIBREADLINE_CFLAGS) \
|
||||||
$(LIBTALLOC_CFLAGS) $(LIBDBUS_CFLAGS) \
|
$(LIBTALLOC_CFLAGS) $(LIBDBUS_CFLAGS) \
|
||||||
$(LIBKRB5_CFLAGS) $(LIBTASN1_CFLAGS)
|
$(LIBKRB5_CFLAGS) $(LIBTASN1_CFLAGS) $(RADCLI_CFLAGS)
|
||||||
|
|
||||||
BUILT_SOURCES = ocpasswd-args.c ocpasswd-args.h \
|
BUILT_SOURCES = ocpasswd-args.c ocpasswd-args.h \
|
||||||
ocserv-args.c ocserv-args.h ipc.pb-c.c ipc.pb-c.h \
|
ocserv-args.c ocserv-args.h ipc.pb-c.c ipc.pb-c.h \
|
||||||
@@ -101,7 +101,7 @@ ocserv_LDADD = ../gl/libgnu.a $(NEEDED_LIBOPTS) libcmd-ocserv.a
|
|||||||
ocserv_LDADD += $(LIBGNUTLS_LIBS) $(PAM_LIBS) $(LIBUTIL) \
|
ocserv_LDADD += $(LIBGNUTLS_LIBS) $(PAM_LIBS) $(LIBUTIL) \
|
||||||
$(LIBSECCOMP) $(LIBWRAP) $(LIBCRYPT) $(NEEDED_HTTP_PARSER_LIBS) \
|
$(LIBSECCOMP) $(LIBWRAP) $(LIBCRYPT) $(NEEDED_HTTP_PARSER_LIBS) \
|
||||||
$(LIBPROTOBUF_C_LIBS) $(LIBSYSTEMD) $(LIBTALLOC_LIBS) \
|
$(LIBPROTOBUF_C_LIBS) $(LIBSYSTEMD) $(LIBTALLOC_LIBS) \
|
||||||
$(FREERADIUS_CLIENT_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
|
$(RADCLI_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
|
||||||
$(LIBTASN1_LIBS)
|
$(LIBTASN1_LIBS)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+6
-1
@@ -31,7 +31,12 @@
|
|||||||
|
|
||||||
#ifdef HAVE_RADIUS
|
#ifdef HAVE_RADIUS
|
||||||
|
|
||||||
|
#ifdef LEGACY_RADIUS
|
||||||
# include <freeradius-client.h>
|
# include <freeradius-client.h>
|
||||||
|
#else
|
||||||
|
# include <radcli.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
#include <sec-mod-acct.h>
|
#include <sec-mod-acct.h>
|
||||||
#include "auth/radius.h"
|
#include "auth/radius.h"
|
||||||
#include "acct/radius.h"
|
#include "acct/radius.h"
|
||||||
@@ -163,7 +168,7 @@ static void append_acct_standard(rc_handle *rh, const common_auth_info_st *ai, V
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#if 0 /* bug in freeradius-client */
|
#ifndef LEGACY_RADIUS /* bug in freeradius-client */
|
||||||
if (ai->ipv6[0] != 0) {
|
if (ai->ipv6[0] != 0) {
|
||||||
struct in6_addr in;
|
struct in6_addr in;
|
||||||
if (inet_pton(AF_INET6, ai->ipv6, &in) == 1) {
|
if (inet_pton(AF_INET6, ai->ipv6, &in) == 1) {
|
||||||
|
|||||||
@@ -32,7 +32,12 @@
|
|||||||
#ifdef HAVE_RADIUS
|
#ifdef HAVE_RADIUS
|
||||||
|
|
||||||
#include "cfg.h"
|
#include "cfg.h"
|
||||||
|
|
||||||
|
#ifdef LEGACY_RADIUS
|
||||||
# include <freeradius-client.h>
|
# include <freeradius-client.h>
|
||||||
|
#else
|
||||||
|
# include <radcli.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
#define RAD_GROUP_NAME 1030
|
#define RAD_GROUP_NAME 1030
|
||||||
#define RAD_IPV4_DNS1 ((311<<16)|(28))
|
#define RAD_IPV4_DNS1 ((311<<16)|(28))
|
||||||
|
|||||||
Reference in New Issue
Block a user