Setup FreeRADIUS for 802.1x PEAP/MSCHAPv2 Auth against OpenLDAP

Intro
You guessed correctly. This is yet another article on how to setup FreeRADIUS to do 802.1x authentication. Why am I doing another when there are a plethora of other such guides out there? Well, the others I found lacking. When I set this up a few years ago, I remember having at least 10 different HowTo's/Guides/FAQs open.

Recently in my studies I needed to debug something with FreeRADIUS (was not working with Dynamic VLAN assignment), and I got thinking: Where exactly does FreeRADIUS kick over authentication to LDAP? Since I couldn't recall, I figured I would make up a guide, and redo the configuration to better understand it.

This was also expedited by user in the #freeradius FreeNode channel looking to do the same, but as I as posting configs, it wasn't helping.

This will get you to a place where you can do User and MAC address authentication, and Dynamic VLAN Assignment (or 802.1x VLAN assignment) So, without further ado, I give you my guide on setting up FreeRADIUS, pulling authentication information from an LDAP backend.

What does this page assume?

 * You have a working OpenLDAP setup.
 * The FreeRADIUS machine does need /etc/openldap/ldap.conf configured correctly, at least if you are doing TLS for LDAP.
 * There's a few good guides out there, and this isn't terribly difficult. I may come up with something later, in which case I'll link to it at that time.
 * Passwords are stored in plain text
 * My LDAP tree is setup as such:
 * ou=Wireless,ou=Services,dc=domain,dc=com -- Where the RADIUS settings are stored (I originally set this up for Wireless, hence the name)
 * ou=Machines,ou=Wireless -- Where Machine MAC addresses are stored, with uid=001122334455, and password of the same
 * ou=Users,ou=Wireless -- Where users are stored. Note, the passwords here are in plain-text, so it needs protected via LDAP ACLs
 * I highly suggest Apache Directory Studio to manage the LDAP Database, if you don't already have something graphical.


 * You have configured your end devices (or will once FreeRADIUS is setup).
 * In my case, my wireless AP is a Cisco AP-1242AG, and the LAN switches I have tested this on are: 2950-24T, 2950G-48, 3750-48PS, 3550-24-PWR. The configuration for these devices is fairly simple and well documented on Cisco's website. Using another manufacture shouldn't be much different, as RADIUS/EAP is standards based.
 * You have Server SSL Certs. I won't go in to this much, as SSL is it's own beast, but I got my wildcard certs from CACert. I do recommend them, especially if you can get assured. You can also setup your own CA for SSL Certs ( I think this is recommended by FreeRADIUS).

My testing environment

 * Linux, Distro: Gentoo Hardened, AMD64 Stable (Note: SELinux was disabled on this machine)
 * While some stuff may be Gentoo specific, the basics of the files in the /etc/raddb (FreeRADIUS's config directory on Gentoo) should be the same across the board
 * freeradius-2.1.11-r1 was emerged with the following USE line:
 * USE="ldap mysql pam snmp ssl threads udpfromto -bindist -debug -edirectory (-firebird) -frascend -frxp -kerberos -postgres" Adjust as needed, but you will need at least 'ldap' and 'ssl'.
 * You can do this with: echo "net-dialup/freeradius ldap mysql pam snmp ssl threads udpfromt" >> /etc/portage/package.use/freeradius
 * SSL Cert from CACert (needs to be known who the CA is when configuring it). This is needed for the EAP stuff, not just TLS to LDAP (it's actually not used there).

The Files

 * All files are referenced from /etc/raddb/

clients.conf

 * Only modification here was adding the client stanza at the bottom. In my case, I did one stanza to cover most of my devices. If you want more fine-grain control, you can specify each one as a /32. This is for the device that you are connecting to (e.g. AP, Switch, etc).

eap.conf

 * Under EAP {}:
 * default_eap_type = peap
 * Under TLS {}:
 * This section says not to use a known CA, but this is where I use my cert from CACert, so known or not is up for debate.
 * pem_file_type = yes -- This is an addition
 * certdir = /etc/ssl/ _wildcard -- This is where I store the wildcard cert mentioned above
 * cadir = /etc/ssl/certs -- since CACert is included in the system CAs
 * #private_key_password = whatever -- Commented this out, as my privkey has no password (a pain with Apache)
 * private_key_file = ${certdir}/ _wildcard.key
 * certificate_file = ${certdir}/ _wildcard.crt
 * CA_file = ${cadir}/cacert.org.pem
 * #CA_path = ${cadir} -- Commented out, maybe this is fine?
 * Under peap {}:
 * use_tunneled_reply = yes -- This is only needed for Dynamic VLAN Assignment. For straight Auth, you don't need to change this

ldap.attrmap

 * checkItem      Cleartext-Password                   userPassword  -- Added at bottom
 * I haven't tried to modify this to include the normal hashed password used for system authentication, which requires bouncing through something like ntlm_auth. So, for now, as explained above, I store the password in plaintest, in a ACL protected OU.

modules/ldap

 * Under ldap {}:
 * server = "server.domain.com" -- set to your LDAP Server
 * identity = "cn=radius,ou=virtual,ou=users,dc=domain,dc=com" -- Set to your RADIUS LDAP user, or some other user that can access the stuff in your OU below
 * password = "MyradiusUserPassword"
 * basedn = "ou=Wireless,ou=Services,dc=domain,dc=com" -- The OU where your RADIUS stuff is stored. I explained this above for my layout.
 * #filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})" -- Commented, as everything under the DN above is RADIUS, so I don't need to filter.
 * Under tls {}:
 * start_tls = yes -- My LDAP Server is setup for TLS, and I prefer to use it in all instances connecting to it.
 * cacertdir = /etc/ssl/certs -- Uncomment, letting it use the system root CAs.
 * require_cert  = "demand" -- Uncomment
 * Remember if you configure TLS to also setup /etc/openldap/ldap.conf too (basic configuration if you have a machine authing against LDAP)
 * access_attr_used_for_allow = yes -- Uncomment
 * set_auth_type = no -- Uncommented and changed

modules/mschap

 * Under mschap {}:
 * authtype = MS-CHAP -- Addition
 * use_mppe = yes -- Uncommented and changed
 * require_encryption = yes -- Uncommented
 * require_strong = yes -- Uncommented
 * with_ntdomain_hack = yes -- Uncommented and changed


 * Note: sites-enabled only had the default files symlinked inside (control-socket, default, inner-tunnel)

sites-enabled/default

 * Under authorize {}:
 * #chap -- Commented
 * #digest -- Commented
 * #suffix -- Commented
 * ntdomain -- Uncommented
 * ldap -- Uncommented
 * #pap -- Commented
 * Under authenticate {}:
 * #Auth-Type CHAP {} -- Section commented
 * #digest -- Commented
 * #unix -- Commented

sites-enabled/inner-tunnel

 * Under server inner-tunnel {}:
 * #listen {} -- Commented listen block
 * Under authorize {}:
 * unix -- Uncommented - Old?
 * #suffix -- Commented
 * ntdomain -- Uncommented
 * ldap -- Uncommented

Caveats

 * Passwords need to be stored in plain text in the LDAP DB. You can limit in OpenLDAP who can do what with ACLs, and I did it in this case. I may write up about this later, but it isn't fully applicable here, as it's more of an OpenLDAP configuration then a FreeRADIUS configuration.
 * As such, I highly recommend doing TLS on LDAP, since otherwise you might end up with passwords going over the wire in clear-text.
 * I know some of the stuff in LDAP isn't fully clear, or some of the more advanced stuff like VLAN assignment. I'll try to clear these up later, but for right now, this should get you up and going.

Resources used

 * Sadly I set the majority of this up a long time ago, but I do seem to have some bookmarks, so I'll throw some of them here. Otherwise, I only used one recently from the FreeRADIUS mailing list.
 * http://vuksan.com/linux/dot1x/802-1x-LDAP.html -- Decent guide, also covers setting up OpenLDAP and it's ACLs, and device setup.
 * http://tldp.org/HOWTO/html_single/8021X-HOWTO/#confradius
 * The FreeRADIUS Wiki
 * http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg48720.html -- Email thread bookmarked.
 * http://lists.freeradius.org/pipermail/freeradius-users/2012-January/058185.html -- This thread, specially this post to get the Dynamic VLAN assignment working.

Fin
I am available on IRC if you have any questions or comments; irc.freenode.net, my Nickname is Sedorox. Sometimes I am in the #freeradius channel, sometimes not, but I am usually connected.