Hi,
My newly installed moonshot RP at STFC can't join trust router. I checked
both TCP ports 2083 and 12309 are open in site firewall and also on host.
Ist terminal: as root:
# radiusd -fxx -l stdout
2nd terminal: as root:
# ids 130.246.143.29 [log in to unmask] moonshot-rp.esc.rl.ac.uk /var/lib/trust_router/keys
tids_listen: TID Server listening on port 12309
3rd terminal:
[root@moonshot-rp ~]# su --shell /bin/bash radiusd
bash-4.1$ unset DISPLAY
bash-4.1$ moonshot-webp -f /tmp/credentials-stfc.xml
bash-4.1$ tidc tr1.moonshot.ja.net moonshot-rp.esc.rl.ac.uk apc.moonshot.ja.net apc.moonshot.ja.net
TIDC Client:
Server = tr1.moonshot.ja.net, rp_realm = moonshot-rp.esc.rl.ac.uk, target_realm = apc.moonshot.ja.net, community = apc.moonshot.ja.net
Warning: dh_check failed with 8: the g value is not a generator
tidc_open_connection: Opening GSS connection to tr1.moonshot.ja.net:12309.gss_connect: Connecting to host 'tr1.moonshot.ja.net' on port 12309
CTRL-EVENT-EAP-STARTED EAP authentication started
CTRL-EVENT-EAP-PROPOSED-METHOD vendor=0 method=21
CTRL-EVENT-EAP-METHOD EAP vendor 0 method 21 (TTLS) selected
CTRL-EVENT-EAP-PEER-CERT depth=1 subject='/C=GB/ST=Oxfordshire/L=Harwell/O=Jisc Collections and Janet [log in to unmask] Workshop CA'
CTRL-EVENT-EAP-PEER-CERT depth=1 subject='/C=GB/ST=Oxfordshire/L=Harwell/O=Jisc Collections and Janet [log in to unmask] Workshop CA'
CTRL-EVENT-EAP-PEER-CERT depth=0 subject='/C=GB/ST=Oxfordshire/O=Jisc Collections and Janet Ltd./CN=Moonshot Workshop [log in to unmask]
CTRL-EVENT-EAP-SUCCESS EAP authentication completed successfully
tidc_fwd_request: Sending TID request:
{"msg_type": "tid_request", "msg_body": {"community": "apc.moonshot.ja.net", "target_realm": "apc.moonshot.ja.net", "rp_realm": "moonshot-rp.esc.rl.ac.uk", "dh_info": {"dh_p": "long hex here", "dh_g": "02", "dh_pub_key": "long hex here"}}}
tidc_fwd_request: Response Received (208 bytes).
{"msg_type": "tid_response", "msg_body": {"target_realm": "apc.moonshot.ja.net", "result": "error", "err_msg": "RP Realm filter error", "rp_realm": "moonshot-rp.esc.rl.ac.uk", "comm": "apc.moonshot.ja.net"}}
tr_msg_decode_tidresp(): Error! result = error.
Response received! Realm = apc.moonshot.ja.net, Community = apc.moonshot.ja.net.
tidc_resp_handler: Response is an error.
bash-4.1$
Suleman Tariq
Research Infrastructure Group
Scientific Computing Department
Science and Technology Facilities Council
Rutherford Appleton Laboratory
Harwell Oxford
Oxfordshire
OX11 0QX
web: http://www.stfc.ac.uk
Email: [log in to unmask]
Tele: +44 (0) 1235 77 8347
|