← Back to plugin index

Radius Authentication Service

Description
A RADIUS server implementation that provides the authentication scheme defined by a configurable underlying authenticator as RADIUS service.
Type name
RadiusService
Class
com.airlock.iam.servicecontainer.app.application.configuration.radius.RadiusServiceConfig
May be used by
License-Tags
RadiusServer
Properties
Password Settings (passwordSettings)
Description
The password settings. If defined, password change is enabled over the RADIUS interface.
Attributes
Plugin-Link
Optional
Assignable plugins
Enable Password Change (enablePasswordChange)
Description
If enabled, password change is enabled over the RADIUS interface (requires password settings).
Attributes
Boolean
Optional
Default value
false
Port (port)
Description
The port to listen on for the RADIUS service. Typically 1812 or 1645 (older systems) is used.
Attributes
Integer
Mandatory
Interface Ip (interfaceIp)
Description
The IP of the interface the Radius server should listen on. This property is optional. If not present, the Radius service listens on all local interfaces.
Attributes
String
Optional
Example
192.168.1.13
Example
127.0.0.1
Example
localhost
Enforce Message-Authenticator (enforceMessageAuthenticator)
Description
If enabled, all clients must include a valid Message-Authenticator attribute in their requests, otherwise the messages will be discarded.

Note: even when disabled, received requests containing a Message-Authenticator will always be validated. Also, responses from this server will always include the Message-Authenticator attribute.

Warning: when disabled, this server is vulnerable to the BlastRADIUS attack.

Attributes
Boolean
Optional
Default value
true
Shared Secret (sharedSecret)
Description
The shared secret for the Radius service. The shared secret is used to protect sensitive information being sent from the Radius client to the Radius server. Since charsets on the server and the client may differ, use only ASCII characters (and choose a longer secret).
Attributes
String
Mandatory
Sensitive
Example
secret4th1ss3rv3r
Example
s843bdfl03h4
Example
wonttellu
Temporary Locking Settings (temporaryLockingSettings)
Description
Configures the behavior of temporary user locking. Notice that responses are not delayed like in the login app not to trigger UDP retransmissions but any further request falling into the temporary lock timeout will be refused immediately with a special message.
If enabling the Temporary Locking settings, either a linear or an exponential factor must be provided or it will have no effect at all. Additionally, a user persister must be specified which must provide the number of failed logins and the last login attempt.
Attributes
Plugin-Link
Optional
Assignable plugins
User Persister (userPersister)
Description
The user persister used to calculate the temporary locking and to read out roles after a mandatory password change.
Attributes
Plugin-Link
Optional
Assignable plugins
Authorization Settings (authorizationSettings)
Description
Check user authorizations, i.e. check if the user may access the requested service or not. If not configured, no authorization checks are performed.
Attributes
Plugin-Link
Optional
Assignable plugins
Charset For Password (charsetForPassword)
Description
The charset to be used to decode the password. Leave empty to use the JVM default charset.
Attributes
String
Optional
Suggested values
UTF-8, ISO-8859-1
Blocking If Asynchronous (blockingIfAsynchronous)
Description

Certain authenticators support asynchronous authentication requests. That is, instead of a final result like accept or reject, an 'authentication pending' result is returned and the caller (in this case the radius service) must call the authenticator repeatedly to get a final result.

If this flag is enabled, the radius service performs the polling and blocks the response until a final result is available. If the flag is disabled, a response is immediately returned to the radius client, asking for a fake challenge (see property 'asynchronousReplyMessage'). When the challenge is returned (content is ignored), the authenticator is queried again and so on.

Note: If the radius service is blocking, the UDP timeout on the client side must be configured to be at least as long as the authenticator timeout.

Attributes
Boolean
Optional
Default value
true
Authenticator Polling Interval Millis (authenticatorPollingIntervalMillis)
Description
If "Blocking If Asynchronous" is TRUE, how long should the radius service pause between polling the authenticator for a new status.
Attributes
Integer
Optional
Default value
5000
Authenticator Polling Timeout [s] (authenticatorPollingTimeoutSecs)
Description
If "Blocking If Asynchronous" is TRUE, how long should the radius services keep polling the authenticator before returning a failure.
Attributes
Integer
Optional
Default value
60
Airlock 2FA Passcode Fallback (airlock2FAPasscodeFallback)
Description
If Airlock 2FA is used and "Blocking If Asynchronous" is enabled, fall back to Passcode after "Authenticator Polling Timeout [s]". Otherwise, the authentication is cancelled after the timeout.
Attributes
Boolean
Optional
Default value
true
Sso Attribute (ssoAttribute)
Description
If this attribute is set, the RADIUS server includes the plain password credential in an attribute in the RADIUS Access-Accept response when authentication succeeded.
The corresponding RADIUS attribute is used to transport the password to the RADIUS client. (The "Class" attribute has id 25, the "Filter-Id" attribute has id 11). Leave this property empty (or do not define the property) to turn this feature off.

CAUTION: If the feature is used, the password is sent in plaintext to the RADIUS client. This may be a security risk depending on the setup.

Attributes
String
Optional
Allowed values
Class, Filter-Id
Radius Roles Configuration (radiusRolesConfiguration)
Description
Use this property to enable returning of user roles with ACCEPT messages. This enables the Radius client to enforce authorization decisions made by Airlock IAM. If the property is undefined, no roles are returned.
Attributes
Plugin-Link
Optional
Assignable plugins
Log Radius Requests (logRadiusRequests)
Description
If enabled, all RADIUS requests are logged together with the client IP, NAS-Identifier and username. The log is written with INFO level.
Attributes
Boolean
Optional
Default value
false
Session Table Size (sessionTableSize)
Description
Determines the maximum number of open authentication sessions that are kept in the Radius server.

This value should be increased in high-traffic situations if authentication sessions are lost.

Attributes
Integer
Optional
Default value
4096
Retransmission Table Size (retransmissionTableSize)
Description
Determines the maximum number of handled packet that are kept in the Radius server in order to detect retransmissions of packets.

This value should be increased in high-traffic situations when retransmitted packets are not detected and requests are therefore answered twice.

Attributes
Integer
Optional
Default value
1024
Retransmission Interval Millis (retransmissionIntervalMillis)
Description
Determines the maximum number of milliseconds between two identical looking requests such that they are still considered to be the same request (retransmission).

This value should be increased when a Radius client sends retransmissions after more than the indicated time. The value should be lowered if Radius requests are ignored because identical requests are sent within the indicated amount of milliseconds.

Attributes
Long
Optional
Default value
30000
Packet Buffer Size (packetBufferSize)
Description
Determines the maximum size of a received UDP packet in bytes.

This value should be increased if you experience problems because receiving only parts extraodinaryly long Radius packets.

Attributes
Integer
Optional
Default value
8192
Use Rsa Ace Compatibility Mode (useRsaAceCompatibilityMode)
Description
Specifies if the RSA/ACE compatibility mode should be used or not. If set to "TRUE", this server behaves like a RSA/ACE service would (important for some clients to distinguish next-token-mode from new-pin-mode).
When this mode is enabled, only authenticators that return ACE-like responses can be used. It can - for example - be used in combination with challenge-response authenticators.
Attributes
Boolean
Optional
Default value
false
Static Rejected User (staticRejectedUser)
Description

Allows definition of a static test user for external monitoring of the Radius service. All login attempts with the static test user are rejected immediately without generating logfile entries. Even if the log level is set to DEBUG and option "logRadiusRequests" is enabled, requests with the static test user will not be logged.

Note: The static test user name must not coincide with an existing user name. Otherwise, the corresponding user will not be able to log in.

Attributes
String
Optional
Length >= 4
Example
_RejectedUser
Access Accept Reply Message (accessAcceptReplyMessage)
Description
Specifies the reply message sent with an Access-Accept response.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Accept responses.

Attributes
String
Optional
Default value
Login successful.
Example
Authentication successful
Example
Access granted
Access Accept Password Changed Reply Message (accessAcceptPasswordChangedReplyMessage)
Description
Specifies the reply message sent with an Access-Accept response after the password has been changed successfully.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, property "Access Accept Reply Message" will be included in Access-Accept responses.

Attributes
String
Optional
Default value
Login and password change successful.
Example
Authentication after password change successful
Example
Access after password change granted
Access Denied Reply Message (accessDeniedReplyMessage)
Description
Specifies the reply message sent with an Access-Denied response.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Denied responses.

Attributes
String
Optional
Default value
Login failed.
Example
Authentication failed
Example
Access denied
User Locked Reply Message (userLockedReplyMessage)
Description
Specifies the reply message sent with an Access-Denied response because the user account is locked.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, the general access denied message (see separate property) is used.

Attributes
String
Optional
Default value
Your user account is locked.
Example
Account locked.
Example
Your account has been locked for security reasons. Please contact our hotline.
User Temporarily Locked Reply Message (userTemporarilyLockedReplyMessage)
Description
Specifies the reply message sent with an Access-Denied response because the user account is temporarily locked. This only happens if Temporary Locking settings and the user persister are configured.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, the general access denied message (see separate property) is used.

Attributes
String
Optional
Default value
Your user account has been locked temporarily. Please try again in a few minutes.
Example
Account temporarily locked; please try again in a few minutes.
Not Authorized Reply Message (notAuthorizedReplyMessage)
Description
Specifies the reply message sent with an Access-Denied response because the user is not authorized (not enough rights).
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in the responses.

Attributes
String
Optional
Default value
Access denied. Not enough access rights.
Example
Not authorized.
Example
Not enough rights
Next Token Mode Reply Message (nextTokenModeReplyMessage)
Description
Specifies the reply message sent with an Access-Challenge response when in next-token mode.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Challenge responses.

Attributes
String
Optional
Default value
Please wait for the NEXT token and enter it.
Example
Enter next token
Example
Please wait for next token and enter it
New Pin Reply Message (newPinReplyMessage)
Description
Specifies the reply message sent with an Access-Challenge response when in new-pin mode.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Challenge responses.

Attributes
String
Optional
Default value
Please choose a new PIN.
Example
Set new PIN
Example
Please set a new PIN
Pin Accepted Reply Message (pinAcceptedReplyMessage)
Description
Specifies the reply message sent with an Access-Challenge response when in pin-accepted state.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Challenge responses.

Attributes
String
Optional
Default value
PIN accepted. Please wait for the NEXT token and enter it.
Example
PIN Accepted. Enter next token
Example
PIN changed. Please wait for next token and enter it
Token Required Reply Message (tokenRequiredReplyMessage)
Description
Specifies the reply message sent with an Access-Challenge response when a token is required. Use the variable ${LAST_USED_TOKEN} to include the last used token (may be an empty string!).
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Challenge responses.

Attributes
String
Optional
Default value
Please enter next token.
Example
Please enter next token. Last used token: ${LAST_USED_TOKEN}
Example
Enter token
Credential Unassigned Reply Message (credentialUnassignedReplyMessage)
Description
Specifies the reply message sent with an Access-Denied response when a required credential is not assigned to the user. If not set, no reply message will be included in the Access-Denied response.
Attributes
String
Optional
Default value
No authentication token has been assigned to your account.
Example
No token has been assigned to your account. Please contact the hotline.
Index Challenge Reply Message (indexChallengeReplyMessage)
Description
Specifies the reply message sent with an Access-Challenge response when an index challenge is sent. This is the case when the underlying authenticator asks for a specific token and references it by an index. Use the variable ${INDEX} to include the index number in the message.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Challenge responses.

Attributes
String
Optional
Default value
Please enter token at position ${INDEX}.
Example
Please enter token at position ${INDEX}
Example
Enter TAN at index ${INDEX}
Matrix Challenge Reply Message (matrixChallengeReplyMessage)
Description
Specifies the reply message sent with an Access-Challenge response when a matrix challenge is sent. This is the case when the underlying authenticator asks for a specific token and references it by one or more coordinate pairs. Use the variable ${CHALLENGE_COORDINATES} to include the coordinate pair(s) in the message.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Challenge responses.

Attributes
String
Optional
Default value
Please enter token(s) ${CHALLENGE_COORDINATES}.
Example
Please enter tokens ${CHALLENGE_COORDINATES}
Change Password Reply Message (changePasswordReplyMessage)
Description
Specifies the reply message sent with an Access-Challenge response when asking to set a new password.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Challenge responses.

Attributes
String
Optional
Default value
Please choose a new password.
Example
Set a new password:
Example
Your password has expired, please choose a new password:
Confirm Password Reply Message (confirmPasswordReplyMessage)
Description
Specifies the reply message sent with an Access-Challenge response when asking to retype (confirm) the new password.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Challenge responses.

Attributes
String
Optional
Default value
Please enter the new password again for confirmation.
Example
Re-type the new password:
Example
Please re-type the new password to confirm it:
Passwords Do Not Match Reply Message (passwordsDoNotMatchReplyMessage)
Description
Specifies the reply message sent with an Access-Denied response when the new password and its confirmation do not match.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Denied responses.

Attributes
String
Optional
Default value
The passwords do not match. Please login again.
Example
Passwords do not match. Login again.
Example
The new password did not match its confirmation. Please login again.
Password Not Accepted Reply Message (passwordNotAcceptedReplyMessage)
Description
Specifies the reply message sent with an Access-Denied response when the new password could not be accepted because of password policy violations.
Some RADIUS clients (such as keyboard-interactive authentication) may display this to the user. Other clients may make their behavior dependent on this message.

If not set, no reply message will be included in Access-Denied responses.

Attributes
String
Optional
Default value
The new password has not been accepted because it violates the password policy.
Example
Password not accepted.
Example
The new password could not be accepted because it does not meet the requirements for new passwords.
Asynchronous Reply Message (asynchronousReplyMessage)
Description
If property "Blocking If Asynchronous" is FALSE, the service forwards 'authentication pending' results directly to the radius client in form of a challenge response. This is the message that is displayed to the user in that case. The actual reply to the challenge is ignored and the state of the authentication is checked again.
Attributes
String
Optional
Default value
Please proceed authentication on your authentication device and press the login button when finished.
Example
Please proceed authentication on the mobile phone and press the login button when finished.
Username Transformation (usernameTransformers)
Description
Username transformers may transform the name received in a Radius request into the single unique user ID required for the authentication process.
The transformation of a username takes place before the authenticator reads the user from persistency layer. Transfomers can be chained, i.e. a first transformer could normalize the original name, after which the next transformer looks up the normalized name in a database for eventual transformation matches.
In addition to the above description of chaining, a transformer can also signal that it already found the final user ID and that the transformation must stop here.
For further details please refer to the documentation of the username transformer plugins.
Attributes
Plugin-List
Optional
Assignable plugins
Token Selection Choice Message (tokenSelectionChoiceMessage)
Description
Message displayed when the user is required to select a token from the given list.
Attributes
String
Optional
Default value
Please choose:
Example
Please choose:
Use Password As Token (usePasswordAsToken)
Description
Pass on the password to the authenticator as if it is a token code.
Attributes
Boolean
Optional
Default value
false
Accept Modifiers (acceptModifiers)
Description
The accept modifiers may modify the final RADIUS accept packet before it is sent to the client.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: RadiusService
id: RadiusService-xxxxxx
displayName: 
comment: 
properties:
  acceptModifiers:
  accessAcceptPasswordChangedReplyMessage: Login and password change successful.
  accessAcceptReplyMessage: Login successful.
  accessDeniedReplyMessage: Login failed.
  airlock2FAPasscodeFallback: true
  asynchronousReplyMessage: Please proceed authentication on your authentication device and press the login button when finished.
  authenticator:
  authenticatorPollingIntervalMillis: 5000
  authenticatorPollingTimeoutSecs: 60
  authorizationSettings:
  blockingIfAsynchronous: true
  changePasswordReplyMessage: Please choose a new password.
  charsetForPassword:
  confirmPasswordReplyMessage: Please enter the new password again for confirmation.
  credentialUnassignedReplyMessage: No authentication token has been assigned to your account.
  enablePasswordChange: false
  enforceMessageAuthenticator: true
  indexChallengeReplyMessage: Please enter token at position ${INDEX}.
  interfaceIp:
  logRadiusRequests: false
  matrixChallengeReplyMessage: Please enter token(s) ${CHALLENGE_COORDINATES}.
  newPinReplyMessage: Please choose a new PIN.
  nextTokenModeReplyMessage: Please wait for the NEXT token and enter it.
  notAuthorizedReplyMessage: Access denied. Not enough access rights.
  packetBufferSize: 8192
  passwordNotAcceptedReplyMessage: The new password has not been accepted because it violates the password policy.
  passwordSettings:
  passwordsDoNotMatchReplyMessage: The passwords do not match. Please login again.
  pinAcceptedReplyMessage: PIN accepted. Please wait for the NEXT token and enter it.
  port:
  radiusRolesConfiguration:
  retransmissionIntervalMillis: 30000
  retransmissionTableSize: 1024
  sessionTableSize: 4096
  sharedSecret:
  ssoAttribute:
  staticRejectedUser:
  temporaryLockingSettings:
  tokenRequiredReplyMessage: Please enter next token.
  tokenSelectionChoiceMessage: Please choose:
  usePasswordAsToken: false
  useRsaAceCompatibilityMode: false
  userLockedReplyMessage: Your user account is locked.
  userPersister:
  userTemporarilyLockedReplyMessage: Your user account has been locked temporarily. Please try again in a few minutes.
  usernameTransformers: