FreeRADIUS v2.1.12无效Message-Authenticator报错及认证问题求助
Let's walk through your issues step by step—FreeRADIUS v2.1.12 is an older release with specific behavior around authentication that we need to nail down.
First: The "invalid Message-Authenticator" Error
This error almost always traces back to one of two critical mismatches, since v2.1.12 enforces strict validation of the Message-Authenticator attribute (used to block request tampering):
- Mismatched shared secret: Double-check that the
secretin yourradtestcommand (radtest -x selftest password 127.0.0.1 0 secret) exactly matches the secret defined for the127.0.0.1client in/etc/freeradius/clients.conf. FreeRADIUS treats secrets as case-sensitive, and even extra spaces or typos will break validation. - radtest/FreeRADIUS version incompatibility: If your
radtestbinary comes from a newer FreeRADIUS package (v3.x+), it might generate a Message-Authenticator using a format that v2.1.12 doesn't recognize. You'll need to use aradtestversion that matches your server's v2.1.12 release.
Next: Authentication Failure After Switching to "testing123"
When you changed the password to "testing123" and got a rejection, let's verify the fundamentals first:
- Check your
/etc/freeradius/usersentry: It needs to follow v2.1.12's exact syntax for cleartext passwords. The correct entry should look like this:
Make sure you're usingselftest Cleartext-Password := "testing123"Cleartext-Password(hashed variants won't work unless you've configured server-side hashing properly), the:=assignment operator, and that the password is wrapped in double quotes with no typos. - Reconfirm client configuration: Ensure your
clients.confhas a valid entry for localhost:
Again, theclient 127.0.0.1 { secret = secret shortname = localhost nastype = other }secrethere must match what's in yourradtestcommand exactly. - Debug with verbose server logs: Stop the running FreeRADIUS service, then start it in debug mode with
radiusd -X. Run yourradtestcommand again, and scan the debug output line by line—this will tell you exactly why the request was rejected (e.g., password mismatch, client not found, or an unmet condition on the user account).
Quick Reminder for v2.1.12
This is an extremely old release (2012), so it lacks many modern features and has strict parsing rules. Avoid using newer password attributes or syntax that works in v3.x+; stick to v2.x documentation conventions for best results.
内容的提问来源于stack exchange,提问作者my_question

