mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
use radcli as the radius library if found
This commit is contained in:
+18
-9
@@ -188,25 +188,34 @@ AC_ARG_WITH(radius,
|
||||
radius_enabled=no
|
||||
|
||||
if test "$test_for_radius" = yes;then
|
||||
LIBS="$oldlibs -lfreeradius-client"
|
||||
AC_MSG_CHECKING([for freeradius client library])
|
||||
AC_LINK_IFELSE([AC_LANG_PROGRAM([
|
||||
PKG_CHECK_MODULES([RADCLI], [radcli >= 1.2.0], radius_enabled=radcli, radius_enabled=no)
|
||||
|
||||
if test "$radius_enabled" = no;then
|
||||
LIBS="$oldlibs -lfreeradius-client"
|
||||
AC_MSG_CHECKING([for freeradius client library])
|
||||
AC_LINK_IFELSE([AC_LANG_PROGRAM([
|
||||
#include <freeradius-client.h>],[
|
||||
#ifndef PW_MAX_MSG_SIZE
|
||||
#error 1
|
||||
#endif
|
||||
rc_read_config(0);])],
|
||||
[AC_MSG_RESULT(yes)
|
||||
AC_SUBST([FREERADIUS_CLIENT_LIBS], [-lfreeradius-client])
|
||||
AC_SUBST([FREERADIUS_CLIENT_CFLAGS], [])
|
||||
radius_enabled=yes
|
||||
AC_DEFINE([HAVE_RADIUS], 1, [Enable the Radius library])],
|
||||
AC_SUBST([RADCLI_LIBS], [-lfreeradius-client])
|
||||
AC_SUBST([RADCLI_CFLAGS], [])
|
||||
radius_enabled=freeradius-client
|
||||
AC_DEFINE([LEGACY_RADIUS], 1, [Enable the legacy library support])],
|
||||
[AC_MSG_RESULT(no)
|
||||
AC_MSG_WARN([[
|
||||
***
|
||||
*** freeradius-client 1.1.7 or later was not found. Radius support will be disabled.
|
||||
*** radcli 1.2.0 or later was not found. Radius support will be disabled.
|
||||
*** See https://github.com/nmav/radcli
|
||||
*** ]])])
|
||||
LIBS="$oldlibs"
|
||||
LIBS="$oldlibs"
|
||||
fi
|
||||
|
||||
if test "$radius_enabled" != no;then
|
||||
AC_DEFINE([HAVE_RADIUS], 1, [Enable the Radius library])
|
||||
fi
|
||||
fi
|
||||
|
||||
gl_INIT
|
||||
|
||||
+34
-27
@@ -1,49 +1,58 @@
|
||||
============================================
|
||||
Using Radius with ocserv
|
||||
============================================
|
||||
Using Radius with ocserv
|
||||
========================
|
||||
|
||||
For radius support the freeradius-client library is required. The
|
||||
minimum requirement is version 1.1.7 as released at:
|
||||
https://github.com/FreeRADIUS/freeradius-client
|
||||
For radius support the radcli library is required. The
|
||||
minimum requirement is version 1.2.0 as released at:
|
||||
https://github.com/nmav/radcli
|
||||
|
||||
Freeradius-client uses a configuration file to setup the
|
||||
radcli uses a configuration file to setup the
|
||||
server configuration. That is typically found at:
|
||||
/etc/radiusclient/radiusclient.conf
|
||||
and is best to copy the default installed by freeradius-client
|
||||
as radiusclient-ocserv.conf and edit it accordingly.
|
||||
/etc/radcl/radiusclient.conf
|
||||
and is best to copy the default installed as radiusclient-ocserv.conf
|
||||
and edit it accordingly.
|
||||
|
||||
The important options for ocserv usage are the following:
|
||||
dictionary /etc/radiusclient/dictionary
|
||||
servers /etc/radiusclient/servers
|
||||
```
|
||||
dictionary /etc/radcli/dictionary
|
||||
servers /etc/radcli/servers
|
||||
```
|
||||
|
||||
The dictionary should contain at least the attributes shown below,
|
||||
and the servers file should contain the radius server to use.
|
||||
|
||||
============================================
|
||||
Ocserv configuration
|
||||
============================================
|
||||
|
||||
Ocserv configuration
|
||||
====================
|
||||
|
||||
For authentication the following line should be enabled.
|
||||
#auth = "radius[/path/to/radiusclient.conf,groupconfig]"
|
||||
```
|
||||
auth = "radius[config=/etc/radiusclient/radiusclient.conf,groupconfig=true]"
|
||||
```
|
||||
|
||||
Check the ocserv manpage for the meaning of the various options
|
||||
such as groupconfig.
|
||||
|
||||
To enable accounting, set the following option to the time (in
|
||||
To enable accounting, use
|
||||
```
|
||||
acct = "radius[config=/etc/radiusclient/radiusclient.conf]"
|
||||
```
|
||||
|
||||
and modify the following option to the time (in
|
||||
seconds), that accounting information should be reported.
|
||||
#stats-report-time = 360
|
||||
```
|
||||
stats-report-time = 360
|
||||
```
|
||||
|
||||
That value will be overriden by Acct-Interim-Interval if sent
|
||||
by the server.
|
||||
|
||||
============================================
|
||||
Dictionary
|
||||
============================================
|
||||
|
||||
#
|
||||
# Ocserv supports the following radious attributes.
|
||||
#
|
||||
Dictionary
|
||||
==========
|
||||
|
||||
Ocserv supports the following radious attributes.
|
||||
|
||||
```
|
||||
# Standard attributes
|
||||
ATTRIBUTE User-Name 1 string
|
||||
ATTRIBUTE Password 2 string
|
||||
@@ -108,6 +117,4 @@ ATTRIBUTE Route-IPv6-Information 170 ipv6prefix
|
||||
# Experimental Non Protocol Attributes used by Cistron-Radiusd
|
||||
#
|
||||
ATTRIBUTE Group-Name 1030 string
|
||||
|
||||
|
||||
|
||||
```
|
||||
|
||||
+2
-2
@@ -6,7 +6,7 @@ AM_CPPFLAGS = -I$(srcdir)/../gl/ -I$(builddir)/../gl/ \
|
||||
$(LIBPROTOBUF_C_CFLAGS) $(LIBLZ4_CFLAGS) \
|
||||
$(LIBNL3_CFLAGS) $(LIBREADLINE_CFLAGS) \
|
||||
$(LIBTALLOC_CFLAGS) $(LIBDBUS_CFLAGS) \
|
||||
$(LIBKRB5_CFLAGS) $(LIBTASN1_CFLAGS)
|
||||
$(LIBKRB5_CFLAGS) $(LIBTASN1_CFLAGS) $(RADCLI_CFLAGS)
|
||||
|
||||
BUILT_SOURCES = ocpasswd-args.c ocpasswd-args.h \
|
||||
ocserv-args.c ocserv-args.h ipc.pb-c.c ipc.pb-c.h \
|
||||
@@ -101,7 +101,7 @@ ocserv_LDADD = ../gl/libgnu.a $(NEEDED_LIBOPTS) libcmd-ocserv.a
|
||||
ocserv_LDADD += $(LIBGNUTLS_LIBS) $(PAM_LIBS) $(LIBUTIL) \
|
||||
$(LIBSECCOMP) $(LIBWRAP) $(LIBCRYPT) $(NEEDED_HTTP_PARSER_LIBS) \
|
||||
$(LIBPROTOBUF_C_LIBS) $(LIBSYSTEMD) $(LIBTALLOC_LIBS) \
|
||||
$(FREERADIUS_CLIENT_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
|
||||
$(RADCLI_LIBS) $(LIBLZ4_LIBS) $(LIBKRB5_LIBS) \
|
||||
$(LIBTASN1_LIBS)
|
||||
|
||||
|
||||
|
||||
+7
-2
@@ -31,7 +31,12 @@
|
||||
|
||||
#ifdef HAVE_RADIUS
|
||||
|
||||
#include <freeradius-client.h>
|
||||
#ifdef LEGACY_RADIUS
|
||||
# include <freeradius-client.h>
|
||||
#else
|
||||
# include <radcli.h>
|
||||
#endif
|
||||
|
||||
#include <sec-mod-acct.h>
|
||||
#include "auth/radius.h"
|
||||
#include "acct/radius.h"
|
||||
@@ -163,7 +168,7 @@ static void append_acct_standard(rc_handle *rh, const common_auth_info_st *ai, V
|
||||
}
|
||||
}
|
||||
|
||||
#if 0 /* bug in freeradius-client */
|
||||
#ifndef LEGACY_RADIUS /* bug in freeradius-client */
|
||||
if (ai->ipv6[0] != 0) {
|
||||
struct in6_addr in;
|
||||
if (inet_pton(AF_INET6, ai->ipv6, &in) == 1) {
|
||||
|
||||
+6
-1
@@ -32,7 +32,12 @@
|
||||
#ifdef HAVE_RADIUS
|
||||
|
||||
#include "cfg.h"
|
||||
#include <freeradius-client.h>
|
||||
|
||||
#ifdef LEGACY_RADIUS
|
||||
# include <freeradius-client.h>
|
||||
#else
|
||||
# include <radcli.h>
|
||||
#endif
|
||||
|
||||
#define RAD_GROUP_NAME 1030
|
||||
#define RAD_IPV4_DNS1 ((311<<16)|(28))
|
||||
|
||||
Reference in New Issue
Block a user