use radcli as the radius library if found

This commit is contained in:
Nikos Mavrogiannopoulos
2015-06-05 22:36:02 +02:00
parent 16ea4a059f
commit 2bce9455a0
5 changed files with 67 additions and 41 deletions
+18 -9
View File
@@ -188,25 +188,34 @@ AC_ARG_WITH(radius,
radius_enabled=no radius_enabled=no
if test "$test_for_radius" = yes;then if test "$test_for_radius" = yes;then
LIBS="$oldlibs -lfreeradius-client" PKG_CHECK_MODULES([RADCLI], [radcli >= 1.2.0], radius_enabled=radcli, radius_enabled=no)
AC_MSG_CHECKING([for freeradius client library])
AC_LINK_IFELSE([AC_LANG_PROGRAM([ if test "$radius_enabled" = no;then
LIBS="$oldlibs -lfreeradius-client"
AC_MSG_CHECKING([for freeradius client library])
AC_LINK_IFELSE([AC_LANG_PROGRAM([
#include <freeradius-client.h>],[ #include <freeradius-client.h>],[
#ifndef PW_MAX_MSG_SIZE #ifndef PW_MAX_MSG_SIZE
#error 1 #error 1
#endif #endif
rc_read_config(0);])], rc_read_config(0);])],
[AC_MSG_RESULT(yes) [AC_MSG_RESULT(yes)
AC_SUBST([FREERADIUS_CLIENT_LIBS], [-lfreeradius-client]) AC_SUBST([RADCLI_LIBS], [-lfreeradius-client])
AC_SUBST([FREERADIUS_CLIENT_CFLAGS], []) AC_SUBST([RADCLI_CFLAGS], [])
radius_enabled=yes radius_enabled=freeradius-client
AC_DEFINE([HAVE_RADIUS], 1, [Enable the Radius library])], AC_DEFINE([LEGACY_RADIUS], 1, [Enable the legacy library support])],
[AC_MSG_RESULT(no) [AC_MSG_RESULT(no)
AC_MSG_WARN([[ AC_MSG_WARN([[
*** ***
*** freeradius-client 1.1.7 or later was not found. Radius support will be disabled. *** radcli 1.2.0 or later was not found. Radius support will be disabled.
*** See https://github.com/nmav/radcli
*** ]])]) *** ]])])
LIBS="$oldlibs" LIBS="$oldlibs"
fi
if test "$radius_enabled" != no;then
AC_DEFINE([HAVE_RADIUS], 1, [Enable the Radius library])
fi
fi fi
gl_INIT gl_INIT
+34 -27
View File
@@ -1,49 +1,58 @@
============================================ Using Radius with ocserv
Using Radius with ocserv ========================
============================================
For radius support the freeradius-client library is required. The For radius support the radcli library is required. The
minimum requirement is version 1.1.7 as released at: minimum requirement is version 1.2.0 as released at:
https://github.com/FreeRADIUS/freeradius-client https://github.com/nmav/radcli
Freeradius-client uses a configuration file to setup the radcli uses a configuration file to setup the
server configuration. That is typically found at: server configuration. That is typically found at:
/etc/radiusclient/radiusclient.conf /etc/radcl/radiusclient.conf
and is best to copy the default installed by freeradius-client and is best to copy the default installed as radiusclient-ocserv.conf
as radiusclient-ocserv.conf and edit it accordingly. and edit it accordingly.
The important options for ocserv usage are the following: The important options for ocserv usage are the following:
dictionary /etc/radiusclient/dictionary ```
servers /etc/radiusclient/servers dictionary /etc/radcli/dictionary
servers /etc/radcli/servers
```
The dictionary should contain at least the attributes shown below, The dictionary should contain at least the attributes shown below,
and the servers file should contain the radius server to use. and the servers file should contain the radius server to use.
============================================
Ocserv configuration Ocserv configuration
============================================ ====================
For authentication the following line should be enabled. For authentication the following line should be enabled.
#auth = "radius[/path/to/radiusclient.conf,groupconfig]" ```
auth = "radius[config=/etc/radiusclient/radiusclient.conf,groupconfig=true]"
```
Check the ocserv manpage for the meaning of the various options Check the ocserv manpage for the meaning of the various options
such as groupconfig. such as groupconfig.
To enable accounting, set the following option to the time (in To enable accounting, use
```
acct = "radius[config=/etc/radiusclient/radiusclient.conf]"
```
and modify the following option to the time (in
seconds), that accounting information should be reported. seconds), that accounting information should be reported.
#stats-report-time = 360 ```
stats-report-time = 360
```
That value will be overriden by Acct-Interim-Interval if sent That value will be overriden by Acct-Interim-Interval if sent
by the server. by the server.
============================================
Dictionary
============================================
# Dictionary
# Ocserv supports the following radious attributes. ==========
#
Ocserv supports the following radious attributes.
```
# Standard attributes # Standard attributes
ATTRIBUTE User-Name 1 string ATTRIBUTE User-Name 1 string
ATTRIBUTE Password 2 string ATTRIBUTE Password 2 string
@@ -108,6 +117,4 @@ ATTRIBUTE Route-IPv6-Information 170 ipv6prefix
# Experimental Non Protocol Attributes used by Cistron-Radiusd # Experimental Non Protocol Attributes used by Cistron-Radiusd
# #
ATTRIBUTE Group-Name 1030 string ATTRIBUTE Group-Name 1030 string
```
+2 -2
View File
@@ -6,7 +6,7 @@ AM_CPPFLAGS = -I$(srcdir)/../gl/ -I$(builddir)/../gl/ \
$(LIBPROTOBUF_C_CFLAGS) $(LIBLZ4_CFLAGS) \ $(LIBPROTOBUF_C_CFLAGS) $(LIBLZ4_CFLAGS) \
$(LIBNL3_CFLAGS) $(LIBREADLINE_CFLAGS) \ $(LIBNL3_CFLAGS) $(LIBREADLINE_CFLAGS) \
$(LIBTALLOC_CFLAGS) $(LIBDBUS_CFLAGS) \ $(LIBTALLOC_CFLAGS) $(LIBDBUS_CFLAGS) \
$(LIBKRB5_CFLAGS) $(LIBTASN1_CFLAGS) $(LIBKRB5_CFLAGS) $(LIBTASN1_CFLAGS) $(RADCLI_CFLAGS)
BUILT_SOURCES = ocpasswd-args.c ocpasswd-args.h \ BUILT_SOURCES = ocpasswd-args.c ocpasswd-args.h \
ocserv-args.c ocserv-args.h ipc.pb-c.c ipc.pb-c.h \ ocserv-args.c ocserv-args.h ipc.pb-c.c ipc.pb-c.h \
@@ -101,7 +101,7 @@ ocserv_LDADD = ../gl/libgnu.a $(NEEDED_LIBOPTS) libcmd-ocserv.a
ocserv_LDADD += $(LIBGNUTLS_LIBS) $(PAM_LIBS) $(LIBUTIL) \ ocserv_LDADD += $(LIBGNUTLS_LIBS) $(PAM_LIBS) $(LIBUTIL) \
$(LIBSECCOMP) $(LIBWRAP) $(LIBCRYPT) $(NEEDED_HTTP_PARSER_LIBS) \ $(LIBSECCOMP) $(LIBWRAP) $(LIBCRYPT) $(NEEDED_HTTP_PARSER_LIBS) \
$(LIBPROTOBUF_C_LIBS) $(LIBSYSTEMD) $(LIBTALLOC_LIBS) \ $(LIBPROTOBUF_C_LIBS) $(LIBSYSTEMD) $(LIBTALLOC_LIBS) \
$(FREERADIUS_CLIENT_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \ $(RADCLI_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
$(LIBTASN1_LIBS) $(LIBTASN1_LIBS)
+7 -2
View File
@@ -31,7 +31,12 @@
#ifdef HAVE_RADIUS #ifdef HAVE_RADIUS
#include <freeradius-client.h> #ifdef LEGACY_RADIUS
# include <freeradius-client.h>
#else
# include <radcli.h>
#endif
#include <sec-mod-acct.h> #include <sec-mod-acct.h>
#include "auth/radius.h" #include "auth/radius.h"
#include "acct/radius.h" #include "acct/radius.h"
@@ -163,7 +168,7 @@ static void append_acct_standard(rc_handle *rh, const common_auth_info_st *ai, V
} }
} }
#if 0 /* bug in freeradius-client */ #ifndef LEGACY_RADIUS /* bug in freeradius-client */
if (ai->ipv6[0] != 0) { if (ai->ipv6[0] != 0) {
struct in6_addr in; struct in6_addr in;
if (inet_pton(AF_INET6, ai->ipv6, &in) == 1) { if (inet_pton(AF_INET6, ai->ipv6, &in) == 1) {
+6 -1
View File
@@ -32,7 +32,12 @@
#ifdef HAVE_RADIUS #ifdef HAVE_RADIUS
#include "cfg.h" #include "cfg.h"
#include <freeradius-client.h>
#ifdef LEGACY_RADIUS
# include <freeradius-client.h>
#else
# include <radcli.h>
#endif
#define RAD_GROUP_NAME 1030 #define RAD_GROUP_NAME 1030
#define RAD_IPV4_DNS1 ((311<<16)|(28)) #define RAD_IPV4_DNS1 ((311<<16)|(28))