When we have a RADIUS server with a configured accounting port instead of 1813 or not configured at all, CLI always be freezing. pam_radius get accounting port from /etc/services.
Will be good to have the possibility to disable pam radius accounting to prevent this issue.
Description
Description
Details
Details
- Difficulty level
- Unknown (require assessment)
- Version
- 1.3-rolling-202101060217
- Why the issue appeared?
- Will be filled on close
- Is it a breaking change?
- Unspecified (possibly destroys the router)
- Issue type
- Unspecified (please specify)
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Resolved | BUG | None | T3191 PAM RADIUS freezing when accounting does not configured on RADIUS server | ||
Resolved | BUG | Viacheslav | T5554 Disable sudo for PAM RADIUS |
Event Timeline
Comment Actions
Maybe disable sent "accounting messages" by default and enable it as a configuration option explicitly?
Comment Actions
Tested in VyOS 1.4.0-rc1 , VyOS 1.3.5 and VyOS 1.5-rolling-202401030023
The configuration
VyOS 1.4.0-rc1:
set interfaces ethernet eth0 address '10.55.8.241/24' set service ssh set system login radius server 10.55.8.21 key 'testing123' set system login radius server 10.55.8.21 port '1812' set system login radius server 10.55.8.21 timeout '5' set system login radius source-address '10.55.8.241'
VyOS 1.3.5:
set interfaces ethernet eth0 address '10.55.8.242/24' set service ssh set system login radius server 10.55.8.21 key 'testing123' set system login radius server 10.55.8.21 port '1812' set system login radius server 10.55.8.21 timeout '5' set system login radius source-address '10.55.8.242'
VyOS 1.5-rolling-202401030023:
set interfaces ethernet eth0 address '10.55.8.243/24' set service ssh set system login radius server 10.55.8.21 key 'testing123' set system login radius server 10.55.8.21 port '1812' set system login radius server 10.55.8.21 timeout '5' set system login radius source-address '10.55.8.243'
In RADIUS server side server does not listen to port 1813 only 1812
Testing:
Works as expected the CLI does not freeze