Radius Authentication Service
passwordSettings) enablePasswordChange) port) interfaceIp) enforceMessageAuthenticator) Note: even when disabled, received requests containing a Message-Authenticator will always be validated. Also, responses from this server will always include the Message-Authenticator attribute.
Warning: when disabled, this server is vulnerable to the BlastRADIUS attack.
sharedSecret) authenticator) temporaryLockingSettings) If enabling the Temporary Locking settings, either a linear or an exponential factor must be provided or it will have no effect at all. Additionally, a user persister must be specified which must provide the number of failed logins and the last login attempt.
userPersister) authorizationSettings) charsetForPassword) blockingIfAsynchronous) Certain authenticators support asynchronous authentication requests. That is, instead of a final result like accept or reject, an 'authentication pending' result is returned and the caller (in this case the radius service) must call the authenticator repeatedly to get a final result.
If this flag is enabled, the radius service performs the polling and blocks the response until a final result is available. If the flag is disabled, a response is immediately returned to the radius client, asking for a fake challenge (see property 'asynchronousReplyMessage'). When the challenge is returned (content is ignored), the authenticator is queried again and so on.
Note: If the radius service is blocking, the UDP timeout on the client side must be configured to be at least as long as the authenticator timeout.
authenticatorPollingIntervalMillis) authenticatorPollingTimeoutSecs) airlock2FAPasscodeFallback) ssoAttribute) The corresponding RADIUS attribute is used to transport the password to the RADIUS client. (The "Class" attribute has id 25, the "Filter-Id" attribute has id 11). Leave this property empty (or do not define the property) to turn this feature off.
CAUTION: If the feature is used, the password is sent in plaintext to the RADIUS client. This may be a security risk depending on the setup.
radiusRolesConfiguration) logRadiusRequests) sessionTableSize) This value should be increased in high-traffic situations if authentication sessions are lost.
retransmissionTableSize) This value should be increased in high-traffic situations when retransmitted packets are not detected and requests are therefore answered twice.
retransmissionIntervalMillis) This value should be increased when a Radius client sends retransmissions after more than the indicated time. The value should be lowered if Radius requests are ignored because identical requests are sent within the indicated amount of milliseconds.
packetBufferSize) This value should be increased if you experience problems because receiving only parts extraodinaryly long Radius packets.
useRsaAceCompatibilityMode) When this mode is enabled, only authenticators that return ACE-like responses can be used. It can - for example - be used in combination with challenge-response authenticators.
staticRejectedUser) Allows definition of a static test user for external monitoring of the Radius service. All login attempts with the static test user are rejected immediately without generating logfile entries. Even if the log level is set to DEBUG and option "logRadiusRequests" is enabled, requests with the static test user will not be logged.
Note: The static test user name must not coincide with an existing user name. Otherwise, the corresponding user will not be able to log in.
accessAcceptReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Accept responses.
accessAcceptPasswordChangedReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, property "Access Accept Reply Message" will be included in Access-Accept responses.
accessDeniedReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Denied responses.
userLockedReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, the general access denied message (see separate property) is used.
userTemporarilyLockedReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, the general access denied message (see separate property) is used.
notAuthorizedReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in the responses.
nextTokenModeReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Challenge responses.
newPinReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Challenge responses.
pinAcceptedReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Challenge responses.
tokenRequiredReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Challenge responses.
credentialUnassignedReplyMessage) indexChallengeReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Challenge responses.
matrixChallengeReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Challenge responses.
changePasswordReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Challenge responses.
confirmPasswordReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Challenge responses.
passwordsDoNotMatchReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Denied responses.
passwordNotAcceptedReplyMessage) Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.
If not set, no reply message will be included in Access-Denied responses.
asynchronousReplyMessage) usernameTransformers) The transformation of a username takes place before the authenticator reads the user from persistency layer. Transfomers can be chained, i.e. a first transformer could normalize the original name, after which the next transformer looks up the normalized name in a database for eventual transformation matches.
In addition to the above description of chaining, a transformer can also signal that it already found the final user ID and that the transformation must stop here.
For further details please refer to the documentation of the username transformer plugins.
tokenSelectionChoiceMessage) usePasswordAsToken) acceptModifiers)
type: RadiusService
id: RadiusService-xxxxxx
displayName:
comment:
properties:
acceptModifiers:
accessAcceptPasswordChangedReplyMessage: Login and password change successful.
accessAcceptReplyMessage: Login successful.
accessDeniedReplyMessage: Login failed.
airlock2FAPasscodeFallback: true
asynchronousReplyMessage: Please proceed authentication on your authentication device and press the login button when finished.
authenticator:
authenticatorPollingIntervalMillis: 5000
authenticatorPollingTimeoutSecs: 60
authorizationSettings:
blockingIfAsynchronous: true
changePasswordReplyMessage: Please choose a new password.
charsetForPassword:
confirmPasswordReplyMessage: Please enter the new password again for confirmation.
credentialUnassignedReplyMessage: No authentication token has been assigned to your account.
enablePasswordChange: false
enforceMessageAuthenticator: true
indexChallengeReplyMessage: Please enter token at position ${INDEX}.
interfaceIp:
logRadiusRequests: false
matrixChallengeReplyMessage: Please enter token(s) ${CHALLENGE_COORDINATES}.
newPinReplyMessage: Please choose a new PIN.
nextTokenModeReplyMessage: Please wait for the NEXT token and enter it.
notAuthorizedReplyMessage: Access denied. Not enough access rights.
packetBufferSize: 8192
passwordNotAcceptedReplyMessage: The new password has not been accepted because it violates the password policy.
passwordSettings:
passwordsDoNotMatchReplyMessage: The passwords do not match. Please login again.
pinAcceptedReplyMessage: PIN accepted. Please wait for the NEXT token and enter it.
port:
radiusRolesConfiguration:
retransmissionIntervalMillis: 30000
retransmissionTableSize: 1024
sessionTableSize: 4096
sharedSecret:
ssoAttribute:
staticRejectedUser:
temporaryLockingSettings:
tokenRequiredReplyMessage: Please enter next token.
tokenSelectionChoiceMessage: Please choose:
usePasswordAsToken: false
useRsaAceCompatibilityMode: false
userLockedReplyMessage: Your user account is locked.
userPersister:
userTemporarilyLockedReplyMessage: Your user account has been locked temporarily. Please try again in a few minutes.
usernameTransformers: