You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

FreeRADIUS v2.1.12无效Message-Authenticator报错及认证问题求助

Troubleshooting FreeRADIUS v2.1.12 "invalid Message-Authenticator" & Authentication Failures

Let's walk through your issues step by step—FreeRADIUS v2.1.12 is an older release with specific behavior around authentication that we need to nail down.

First: The "invalid Message-Authenticator" Error

This error almost always traces back to one of two critical mismatches, since v2.1.12 enforces strict validation of the Message-Authenticator attribute (used to block request tampering):

  • Mismatched shared secret: Double-check that the secret in your radtest command (radtest -x selftest password 127.0.0.1 0 secret) exactly matches the secret defined for the 127.0.0.1 client in /etc/freeradius/clients.conf. FreeRADIUS treats secrets as case-sensitive, and even extra spaces or typos will break validation.
  • radtest/FreeRADIUS version incompatibility: If your radtest binary comes from a newer FreeRADIUS package (v3.x+), it might generate a Message-Authenticator using a format that v2.1.12 doesn't recognize. You'll need to use a radtest version that matches your server's v2.1.12 release.

Next: Authentication Failure After Switching to "testing123"

When you changed the password to "testing123" and got a rejection, let's verify the fundamentals first:

  1. Check your /etc/freeradius/users entry: It needs to follow v2.1.12's exact syntax for cleartext passwords. The correct entry should look like this:
    selftest    Cleartext-Password := "testing123"
    
    Make sure you're using Cleartext-Password (hashed variants won't work unless you've configured server-side hashing properly), the := assignment operator, and that the password is wrapped in double quotes with no typos.
  2. Reconfirm client configuration: Ensure your clients.conf has a valid entry for localhost:
    client 127.0.0.1 {
        secret = secret
        shortname = localhost
        nastype = other
    }
    
    Again, the secret here must match what's in your radtest command exactly.
  3. Debug with verbose server logs: Stop the running FreeRADIUS service, then start it in debug mode with radiusd -X. Run your radtest command again, and scan the debug output line by line—this will tell you exactly why the request was rejected (e.g., password mismatch, client not found, or an unmet condition on the user account).

Quick Reminder for v2.1.12

This is an extremely old release (2012), so it lacks many modern features and has strict parsing rules. Avoid using newer password attributes or syntax that works in v3.x+; stick to v2.x documentation conventions for best results.

内容的提问来源于stack exchange,提问作者my_question

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:32:13