use radcli as the radius library if found

This commit is contained in:
Nikos Mavrogiannopoulos
2015-06-05 22:36:02 +02:00
parent 16ea4a059f
commit 2bce9455a0
5 changed files with 67 additions and 41 deletions
+14 -5
View File
@@ -188,6 +188,9 @@ AC_ARG_WITH(radius,
radius_enabled=no
if test "$test_for_radius" = yes;then
PKG_CHECK_MODULES([RADCLI], [radcli >= 1.2.0], radius_enabled=radcli, radius_enabled=no)
if test "$radius_enabled" = no;then
LIBS="$oldlibs -lfreeradius-client"
AC_MSG_CHECKING([for freeradius client library])
AC_LINK_IFELSE([AC_LANG_PROGRAM([
@@ -197,18 +200,24 @@ AC_LINK_IFELSE([AC_LANG_PROGRAM([
#endif
rc_read_config(0);])],
[AC_MSG_RESULT(yes)
AC_SUBST([FREERADIUS_CLIENT_LIBS], [-lfreeradius-client])
AC_SUBST([FREERADIUS_CLIENT_CFLAGS], [])
radius_enabled=yes
AC_DEFINE([HAVE_RADIUS], 1, [Enable the Radius library])],
AC_SUBST([RADCLI_LIBS], [-lfreeradius-client])
AC_SUBST([RADCLI_CFLAGS], [])
radius_enabled=freeradius-client
AC_DEFINE([LEGACY_RADIUS], 1, [Enable the legacy library support])],
[AC_MSG_RESULT(no)
AC_MSG_WARN([[
***
*** freeradius-client 1.1.7 or later was not found. Radius support will be disabled.
*** radcli 1.2.0 or later was not found. Radius support will be disabled.
*** See https://github.com/nmav/radcli
*** ]])])
LIBS="$oldlibs"
fi
if test "$radius_enabled" != no;then
AC_DEFINE([HAVE_RADIUS], 1, [Enable the Radius library])
fi
fi
gl_INIT
AC_LIB_HAVE_LINKFLAGS(crypt,, [#define _XOPEN_SOURCE
+31 -24
View File
@@ -1,49 +1,58 @@
============================================
Using Radius with ocserv
============================================
========================
For radius support the freeradius-client library is required. The
minimum requirement is version 1.1.7 as released at:
https://github.com/FreeRADIUS/freeradius-client
For radius support the radcli library is required. The
minimum requirement is version 1.2.0 as released at:
https://github.com/nmav/radcli
Freeradius-client uses a configuration file to setup the
radcli uses a configuration file to setup the
server configuration. That is typically found at:
/etc/radiusclient/radiusclient.conf
and is best to copy the default installed by freeradius-client
as radiusclient-ocserv.conf and edit it accordingly.
/etc/radcl/radiusclient.conf
and is best to copy the default installed as radiusclient-ocserv.conf
and edit it accordingly.
The important options for ocserv usage are the following:
dictionary /etc/radiusclient/dictionary
servers /etc/radiusclient/servers
```
dictionary /etc/radcli/dictionary
servers /etc/radcli/servers
```
The dictionary should contain at least the attributes shown below,
and the servers file should contain the radius server to use.
============================================
Ocserv configuration
============================================
====================
For authentication the following line should be enabled.
#auth = "radius[/path/to/radiusclient.conf,groupconfig]"
```
auth = "radius[config=/etc/radiusclient/radiusclient.conf,groupconfig=true]"
```
Check the ocserv manpage for the meaning of the various options
such as groupconfig.
To enable accounting, set the following option to the time (in
To enable accounting, use
```
acct = "radius[config=/etc/radiusclient/radiusclient.conf]"
```
and modify the following option to the time (in
seconds), that accounting information should be reported.
#stats-report-time = 360
```
stats-report-time = 360
```
That value will be overriden by Acct-Interim-Interval if sent
by the server.
============================================
Dictionary
============================================
==========
#
# Ocserv supports the following radious attributes.
#
Ocserv supports the following radious attributes.
```
# Standard attributes
ATTRIBUTE User-Name 1 string
ATTRIBUTE Password 2 string
@@ -108,6 +117,4 @@ ATTRIBUTE Route-IPv6-Information 170 ipv6prefix
# Experimental Non Protocol Attributes used by Cistron-Radiusd
#
ATTRIBUTE Group-Name 1030 string
```
+2 -2
View File
@@ -6,7 +6,7 @@ AM_CPPFLAGS = -I$(srcdir)/../gl/ -I$(builddir)/../gl/ \
$(LIBPROTOBUF_C_CFLAGS) $(LIBLZ4_CFLAGS) \
$(LIBNL3_CFLAGS) $(LIBREADLINE_CFLAGS) \
$(LIBTALLOC_CFLAGS) $(LIBDBUS_CFLAGS) \
$(LIBKRB5_CFLAGS) $(LIBTASN1_CFLAGS)
$(LIBKRB5_CFLAGS) $(LIBTASN1_CFLAGS) $(RADCLI_CFLAGS)
BUILT_SOURCES = ocpasswd-args.c ocpasswd-args.h \
ocserv-args.c ocserv-args.h ipc.pb-c.c ipc.pb-c.h \
@@ -101,7 +101,7 @@ ocserv_LDADD = ../gl/libgnu.a $(NEEDED_LIBOPTS) libcmd-ocserv.a
ocserv_LDADD += $(LIBGNUTLS_LIBS) $(PAM_LIBS) $(LIBUTIL) \
$(LIBSECCOMP) $(LIBWRAP) $(LIBCRYPT) $(NEEDED_HTTP_PARSER_LIBS) \
$(LIBPROTOBUF_C_LIBS) $(LIBSYSTEMD) $(LIBTALLOC_LIBS) \
$(FREERADIUS_CLIENT_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
$(RADCLI_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
$(LIBTASN1_LIBS)
+6 -1
View File
@@ -31,7 +31,12 @@
#ifdef HAVE_RADIUS
#ifdef LEGACY_RADIUS
# include <freeradius-client.h>
#else
# include <radcli.h>
#endif
#include <sec-mod-acct.h>
#include "auth/radius.h"
#include "acct/radius.h"
@@ -163,7 +168,7 @@ static void append_acct_standard(rc_handle *rh, const common_auth_info_st *ai, V
}
}
#if 0 /* bug in freeradius-client */
#ifndef LEGACY_RADIUS /* bug in freeradius-client */
if (ai->ipv6[0] != 0) {
struct in6_addr in;
if (inet_pton(AF_INET6, ai->ipv6, &in) == 1) {
+5
View File
@@ -32,7 +32,12 @@
#ifdef HAVE_RADIUS
#include "cfg.h"
#ifdef LEGACY_RADIUS
# include <freeradius-client.h>
#else
# include <radcli.h>
#endif
#define RAD_GROUP_NAME 1030
#define RAD_IPV4_DNS1 ((311<<16)|(28))