radiusclient.conf 3.2 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091
  1. # General settings
  2. # specify which authentication comes first respectively which
  3. # authentication is used. possible values are: "radius" and "local".
  4. # if you specify "radius,local" then the RADIUS server is asked
  5. # first then the local one. if only one keyword is specified only
  6. # this server is asked.
  7. auth_order radius,local
  8. # maximum login tries a user has
  9. login_tries 2
  10. # timeout for all login tries
  11. # if this time is exceeded the user is kicked out
  12. login_timeout 5
  13. # name of the nologin file which when it exists disables logins.
  14. # it may be extended by the ttyname which will result in
  15. # a terminal specific lock (e.g. /etc/nologin.ttyS2 will disable
  16. # logins on /dev/ttyS2)
  17. nologin /etc/nologin
  18. # name of the issue file. it's only display when no username is passed
  19. # on the radlogin command line
  20. issue /etc/radiusclient/issue
  21. # RADIUS settings
  22. # RADIUS server to use for authentication requests. this config
  23. # item can appear more then one time. if multiple servers are
  24. # defined they are tried in a round robin fashion if one
  25. # server is not answering.
  26. # optionally you can specify a the port number on which is remote
  27. # RADIUS listens separated by a colon from the hostname. if
  28. # no port is specified /etc/services is consulted of the radius
  29. # service. if this fails also a compiled in default is used.
  30. # For IPv6 addresses use the '[IPv6]:port:secret' format, or
  31. # simply '[IPv6]'.
  32. authserver 192.168.1.10
  33. # RADIUS server to use for accounting requests. All that I
  34. # said for authserver applies, too.
  35. #
  36. acctserver 192.168.1.10
  37. # file holding shared secrets used for the communication
  38. # between the RADIUS client and server
  39. servers /etc/radiusclient/servers
  40. # dictionary of allowed attributes and values
  41. # just like in the normal RADIUS distributions
  42. dictionary /etc/radiusclient/dictionary
  43. # program to call for a RADIUS authenticated login
  44. login_radius /sbin/login.radius
  45. # file which specifies mapping between ttyname and NAS-Port attribute
  46. mapfile /etc/radiusclient/port-id-map
  47. # default authentication realm to append to all usernames if no
  48. # realm was explicitly specified by the user
  49. # the radiusd directly form Livingston doesn't use any realms, so leave
  50. # it blank then
  51. default_realm
  52. # time to wait for a reply from the RADIUS server
  53. radius_timeout 3
  54. # resend request this many times before trying the next server
  55. radius_retries 2
  56. # The length of time in seconds that we skip a nonresponsive RADIUS
  57. # server for transaction requests. Server(s) being in the "dead" state
  58. # are tried only after all other non-dead servers have been tried and
  59. # failed or timeouted. The deadtime interval starts when the server
  60. # does not respond to an authentication/accounting request transmissions.
  61. # When the interval expires, the "dead" server would be re-tried again,
  62. # and if it's still down then it will be considered "dead" for another
  63. # such interval and so on. This option is no-op if there is only one
  64. # server in the list. Set to 0 in order to disable the feature.
  65. radius_deadtime 0
  66. # local address from which radius packets have to be sent
  67. bindaddr *
  68. # LOCAL settings
  69. # program to execute for local login
  70. # it must support the -f flag for preauthenticated login
  71. login_local /bin/login