dictionary.freeradius.internal 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830
  1. # -*- text -*-
  2. # Copyright (C) 2011 The FreeRADIUS Server project and contributors
  3. #
  4. # Non Protocol Attributes used by FreeRADIUS
  5. #
  6. # $Id: b830d56623fc3aad78122fa6af04ce66416123b6 $
  7. #
  8. # The attributes number ranges are allocates as follows:
  9. #
  10. # Range: 500-999
  11. # server-side attributes which can go in a reply list
  12. # These attributes CAN go in the reply item list.
  13. ATTRIBUTE Fall-Through 500 integer
  14. ATTRIBUTE Relax-Filter 501 integer
  15. ATTRIBUTE Exec-Program 502 string
  16. ATTRIBUTE Exec-Program-Wait 503 string
  17. # These attributes CANNOT go in the reply item list.
  18. #
  19. # Range: 1000+
  20. # Attributes which cannot go in a reply list.
  21. #
  22. #
  23. # Range: 1000-1199
  24. # Miscellaneous server attributes.
  25. #
  26. #
  27. # Non-Protocol Attributes
  28. # These attributes are used internally by the server
  29. #
  30. ATTRIBUTE Auth-Type 1000 integer
  31. ATTRIBUTE Menu 1001 string
  32. ATTRIBUTE Termination-Menu 1002 string
  33. ATTRIBUTE Prefix 1003 string
  34. ATTRIBUTE Suffix 1004 string
  35. ATTRIBUTE Group 1005 string
  36. ATTRIBUTE Crypt-Password 1006 string
  37. ATTRIBUTE Connect-Rate 1007 integer
  38. ATTRIBUTE Add-Prefix 1008 string
  39. ATTRIBUTE Add-Suffix 1009 string
  40. ATTRIBUTE Expiration 1010 date
  41. ATTRIBUTE Autz-Type 1011 integer
  42. ATTRIBUTE Acct-Type 1012 integer
  43. ATTRIBUTE Session-Type 1013 integer
  44. ATTRIBUTE Post-Auth-Type 1014 integer
  45. ATTRIBUTE Pre-Proxy-Type 1015 integer
  46. ATTRIBUTE Post-Proxy-Type 1016 integer
  47. ATTRIBUTE Pre-Acct-Type 1017 integer
  48. #
  49. # This is the EAP type of authentication, which is set
  50. # by the EAP module, for informational purposes only.
  51. #
  52. ATTRIBUTE EAP-Type 1018 integer
  53. ATTRIBUTE EAP-TLS-Require-Client-Cert 1019 integer
  54. ATTRIBUTE EAP-Id 1020 integer
  55. ATTRIBUTE EAP-Code 1021 integer
  56. ATTRIBUTE EAP-MD5-Password 1022 string
  57. ATTRIBUTE PEAP-Version 1023 integer
  58. ATTRIBUTE Client-Shortname 1024 string virtual
  59. ATTRIBUTE Load-Balance-Key 1025 string
  60. ATTRIBUTE Raw-Attribute 1026 octets
  61. ATTRIBUTE TNC-VLAN-Access 1027 string
  62. ATTRIBUTE TNC-VLAN-Isolate 1028 string
  63. ATTRIBUTE User-Category 1029 string
  64. ATTRIBUTE Group-Name 1030 string
  65. ATTRIBUTE Huntgroup-Name 1031 string
  66. ATTRIBUTE Simultaneous-Use 1034 integer
  67. ATTRIBUTE Strip-User-Name 1035 integer
  68. ATTRIBUTE Hint 1040 string
  69. ATTRIBUTE Pam-Auth 1041 string
  70. ATTRIBUTE Login-Time 1042 string
  71. ATTRIBUTE Stripped-User-Name 1043 string
  72. ATTRIBUTE Current-Time 1044 string
  73. ATTRIBUTE Realm 1045 string
  74. ATTRIBUTE No-Such-Attribute 1046 string
  75. ATTRIBUTE Packet-Type 1047 integer virtual
  76. ATTRIBUTE Proxy-To-Realm 1048 string
  77. ATTRIBUTE Replicate-To-Realm 1049 string
  78. ATTRIBUTE Acct-Session-Start-Time 1050 date
  79. ATTRIBUTE Acct-Unique-Session-Id 1051 string
  80. ATTRIBUTE Client-IP-Address 1052 ipaddr virtual
  81. ATTRIBUTE Ldap-UserDn 1053 string
  82. ATTRIBUTE NS-MTA-MD5-Password 1054 string
  83. ATTRIBUTE SQL-User-Name 1055 string
  84. ATTRIBUTE LM-Password 1057 octets
  85. ATTRIBUTE NT-Password 1058 octets
  86. ATTRIBUTE SMB-Account-CTRL 1059 integer
  87. ATTRIBUTE SMB-Account-CTRL-TEXT 1061 string
  88. ATTRIBUTE User-Profile 1062 string
  89. ATTRIBUTE Digest-Realm 1063 string
  90. ATTRIBUTE Digest-Nonce 1064 string
  91. ATTRIBUTE Digest-Method 1065 string
  92. ATTRIBUTE Digest-URI 1066 string
  93. ATTRIBUTE Digest-QOP 1067 string
  94. ATTRIBUTE Digest-Algorithm 1068 string
  95. ATTRIBUTE Digest-Body-Digest 1069 string
  96. ATTRIBUTE Digest-CNonce 1070 string
  97. ATTRIBUTE Digest-Nonce-Count 1071 string
  98. ATTRIBUTE Digest-User-Name 1072 string
  99. ATTRIBUTE Pool-Name 1073 string
  100. ATTRIBUTE Ldap-Group 1074 string
  101. ATTRIBUTE Module-Success-Message 1075 string
  102. ATTRIBUTE Module-Failure-Message 1076 string
  103. # X99-Fast 1077 integer
  104. ATTRIBUTE Rewrite-Rule 1078 string
  105. ATTRIBUTE Sql-Group 1079 string
  106. ATTRIBUTE Response-Packet-Type 1080 integer virtual
  107. ATTRIBUTE Digest-HA1 1081 string
  108. ATTRIBUTE MS-CHAP-Use-NTLM-Auth 1082 integer
  109. ATTRIBUTE NTLM-User-Name 1083 string
  110. ATTRIBUTE MS-CHAP-User-Name 1083 string
  111. ATTRIBUTE Packet-Src-IP-Address 1084 ipaddr virtual
  112. ATTRIBUTE Packet-Dst-IP-Address 1085 ipaddr virtual
  113. ATTRIBUTE Packet-Src-Port 1086 integer virtual
  114. ATTRIBUTE Packet-Dst-Port 1087 integer virtual
  115. ATTRIBUTE Packet-Authentication-Vector 1088 octets virtual
  116. ATTRIBUTE Time-Of-Day 1089 string
  117. ATTRIBUTE Request-Processing-Stage 1090 string virtual
  118. ATTRIBUTE SHA2-Password 1092 octets
  119. ATTRIBUTE SHA-Password 1093 octets
  120. ATTRIBUTE SSHA-Password 1094 octets
  121. ATTRIBUTE SHA1-Password 1093 octets
  122. ATTRIBUTE SSHA1-Password 1094 octets
  123. ATTRIBUTE MD5-Password 1095 octets
  124. ATTRIBUTE SMD5-Password 1096 octets
  125. ATTRIBUTE Packet-Src-IPv6-Address 1097 ipv6addr virtual
  126. ATTRIBUTE Packet-Dst-IPv6-Address 1098 ipv6addr virtual
  127. ATTRIBUTE Virtual-Server 1099 string virtual
  128. ATTRIBUTE Cleartext-Password 1100 string
  129. ATTRIBUTE Password-With-Header 1101 string
  130. ATTRIBUTE Inner-Tunnel-User-Name 1102 string
  131. #
  132. # EAP-IKEv2 is experimental.
  133. #
  134. ATTRIBUTE EAP-IKEv2-IDType 1103 integer
  135. VALUE EAP-IKEv2-IDType IPV4_ADDR 1
  136. VALUE EAP-IKEv2-IDType FQDN 2
  137. VALUE EAP-IKEv2-IDType RFC822_ADDR 3
  138. VALUE EAP-IKEv2-IDType IPV6_ADDR 5
  139. VALUE EAP-IKEv2-IDType DER_ASN1_DN 9
  140. VALUE EAP-IKEv2-IDType DER_ASN1_GN 10
  141. VALUE EAP-IKEv2-IDType KEY_ID 11
  142. ATTRIBUTE EAP-IKEv2-ID 1104 string
  143. ATTRIBUTE EAP-IKEv2-Secret 1105 string
  144. ATTRIBUTE EAP-IKEv2-AuthType 1106 integer
  145. VALUE EAP-IKEv2-AuthType none 0
  146. VALUE EAP-IKEv2-AuthType secret 1
  147. VALUE EAP-IKEv2-AuthType cert 2
  148. VALUE EAP-IKEv2-AuthType both 3
  149. ATTRIBUTE Send-Disconnect-Request 1107 integer
  150. ATTRIBUTE Send-CoA-Request 1107 integer
  151. VALUE Send-CoA-Request No 0
  152. VALUE Send-CoA-Request Yes 1
  153. ATTRIBUTE Module-Return-Code 1108 integer virtual
  154. VALUE Module-Return-Code reject 0
  155. VALUE Module-Return-Code fail 1
  156. VALUE Module-Return-Code ok 2
  157. VALUE Module-Return-Code handled 3
  158. VALUE Module-Return-Code invalid 4
  159. VALUE Module-Return-Code userlock 5
  160. VALUE Module-Return-Code notfound 6
  161. VALUE Module-Return-Code noop 7
  162. VALUE Module-Return-Code updated 8
  163. ATTRIBUTE Packet-Original-Timestamp 1109 date
  164. ATTRIBUTE SQL-Table-Name 1110 string
  165. ATTRIBUTE Home-Server-Pool 1111 string
  166. ATTRIBUTE FreeRADIUS-Client-IP-Address 1120 ipaddr
  167. ATTRIBUTE FreeRADIUS-Client-IPv6-Address 1121 ipv6addr
  168. # The rest of the FreeRADIUS-Client-* attributes are at 1150...
  169. ATTRIBUTE FreeRADIUS-Client-Require-MA 1122 integer
  170. VALUE FreeRADIUS-Client-Require-MA no 0
  171. VALUE FreeRADIUS-Client-Require-MA yes 1
  172. ATTRIBUTE FreeRADIUS-Client-Secret 1123 string
  173. ATTRIBUTE FreeRADIUS-Client-Shortname 1124 string
  174. ATTRIBUTE FreeRADIUS-Client-NAS-Type 1125 string
  175. ATTRIBUTE FreeRADIUS-Client-Virtual-Server 1126 string
  176. # For session resumption
  177. ATTRIBUTE Allow-Session-Resumption 1127 integer
  178. VALUE Allow-Session-Resumption no 0
  179. VALUE Allow-Session-Resumption yes 1
  180. ATTRIBUTE EAP-Session-Resumed 1128 integer
  181. VALUE EAP-Session-Resumed no 0
  182. VALUE EAP-Session-Resumed yes 1
  183. #
  184. # Expose EAP keys in the reply.
  185. #
  186. ATTRIBUTE EAP-MSK 1129 octets
  187. ATTRIBUTE EAP-EMSK 1130 octets
  188. #
  189. # For send/recv CoA packets (like Auth-Type, Acct-Type, etc.)
  190. #
  191. ATTRIBUTE Recv-CoA-Type 1131 integer
  192. ATTRIBUTE Send-CoA-Type 1132 integer
  193. ATTRIBUTE MS-CHAP-Password 1133 string
  194. ATTRIBUTE Packet-Transmit-Counter 1134 integer
  195. ATTRIBUTE Cached-Session-Policy 1135 string
  196. ATTRIBUTE MS-CHAP-New-Cleartext-Password 1136 string
  197. ATTRIBUTE MS-CHAP-New-NT-Password 1137 octets
  198. # For default policies
  199. ATTRIBUTE Stripped-User-Domain 1138 string
  200. ATTRIBUTE Called-Station-SSID 1139 string
  201. VALUE Cache-Status-Only no 0
  202. VALUE Cache-Status-Only yes 1
  203. VALUE Cache-Merge no 0
  204. VALUE Cache-Merge yes 1
  205. VALUE Cache-Read-Only no 0
  206. VALUE Cache-Read-Only yes 1
  207. ATTRIBUTE OTP-Challenge 1145 string
  208. ATTRIBUTE EAP-Session-Id 1146 octets
  209. ATTRIBUTE Chbind-Response-Code 1147 integer
  210. ATTRIBUTE Chbind-Response-Code 1147 integer
  211. VALUE Chbind-Response-Code success 2
  212. VALUE Chbind-Response-Code failure 3
  213. #
  214. # Server-side "listen type = foo"
  215. #
  216. ATTRIBUTE Listen-Socket-Type 1147 integer
  217. VALUE Listen-Socket-Type none 0
  218. VALUE Listen-Socket-Type status 0
  219. VALUE Listen-Socket-Type proxy 1
  220. VALUE Listen-Socket-Type auth 2
  221. VALUE Listen-Socket-Type auth+acct 2
  222. VALUE Listen-Socket-Type acct 3
  223. VALUE Listen-Socket-Type detail 4
  224. VALUE Listen-Socket-Type vmps 5
  225. VALUE Listen-Socket-Type dhcp 6
  226. VALUE Listen-Socket-Type control 7
  227. VALUE Listen-Socket-Type coa 8
  228. ATTRIBUTE Acct-Input-Octets64 1148 integer64
  229. ATTRIBUTE Acct-Output-Octets64 1149 integer64
  230. ATTRIBUTE FreeRADIUS-Client-IP-Prefix 1150 ipv4prefix
  231. ATTRIBUTE FreeRADIUS-Client-IPv6-Prefix 1151 ipv6prefix
  232. ATTRIBUTE FreeRADIUS-Response-Delay 1152 integer
  233. ATTRIBUTE FreeRADIUS-Client-Src-IP-Address 1153 ipaddr
  234. ATTRIBUTE FreeRADIUS-Client-Src-IPv6-Address 1154 ipv6addr
  235. ATTRIBUTE FreeRADIUS-Response-Delay-USec 1155 integer
  236. ATTRIBUTE REST-HTTP-Header 1160 string
  237. ATTRIBUTE REST-HTTP-Body 1161 string
  238. ATTRIBUTE Cache-Expires 1170 date
  239. ATTRIBUTE Cache-Created 1171 date
  240. ATTRIBUTE Cache-TTL 1172 signed
  241. ATTRIBUTE Cache-Status-Only 1173 integer
  242. ATTRIBUTE Cache-Merge 1174 integer
  243. ATTRIBUTE Cache-Entry-Hits 1175 integer
  244. ATTRIBUTE Cache-Read-Only 1176 integer
  245. #
  246. # Range: 1200-1279
  247. # EAP-SIM (and other EAP type) weirdness.
  248. #
  249. # For EAP-SIM, some attribute definitions for database interface
  250. #
  251. ATTRIBUTE EAP-Sim-Subtype 1200 integer
  252. ATTRIBUTE EAP-Sim-Rand1 1201 octets
  253. ATTRIBUTE EAP-Sim-Rand2 1202 octets
  254. ATTRIBUTE EAP-Sim-Rand3 1203 octets
  255. ATTRIBUTE EAP-Sim-SRES1 1204 octets
  256. ATTRIBUTE EAP-Sim-SRES2 1205 octets
  257. ATTRIBUTE EAP-Sim-SRES3 1206 octets
  258. VALUE EAP-Sim-Subtype Start 10
  259. VALUE EAP-Sim-Subtype Challenge 11
  260. VALUE EAP-Sim-Subtype Notification 12
  261. VALUE EAP-Sim-Subtype Re-authentication 13
  262. # this attribute is used internally by the client code.
  263. ATTRIBUTE EAP-Sim-State 1207 integer
  264. ATTRIBUTE EAP-Sim-IMSI 1208 string
  265. ATTRIBUTE EAP-Sim-HMAC 1209 string
  266. ATTRIBUTE EAP-Sim-KEY 1210 octets
  267. ATTRIBUTE EAP-Sim-EXTRA 1211 octets
  268. ATTRIBUTE EAP-Sim-Kc1 1212 octets
  269. ATTRIBUTE EAP-Sim-Kc2 1213 octets
  270. ATTRIBUTE EAP-Sim-Kc3 1214 octets
  271. ATTRIBUTE EAP-Sim-Ki 1215 octets
  272. ATTRIBUTE EAP-Sim-Algo-Version 1216 integer
  273. #
  274. # Range: 1280 - 1535
  275. # EAP-type specific attributes
  276. #
  277. # These are used mostly for radeapclient, and aren't
  278. # that useful for anyone else.
  279. #
  280. # egrep VALUE dictionary.freeradius.internal | grep EAP-Type | awk '{print "ATTRIBUTE EAP-Type-" $3 " " 1280+$4 " octets"}' > foo;./format.pl foo
  281. #
  282. ATTRIBUTE EAP-Type-Base 1280 octets
  283. ATTRIBUTE EAP-Type-VALUE 1280 octets
  284. ATTRIBUTE EAP-Type-None 1280 octets
  285. ATTRIBUTE EAP-Type-Identity 1281 octets
  286. ATTRIBUTE EAP-Type-Notification 1282 octets
  287. ATTRIBUTE EAP-Type-NAK 1283 octets
  288. ATTRIBUTE EAP-Type-MD5-Challenge 1284 octets
  289. ATTRIBUTE EAP-Type-One-Time-Password 1285 octets
  290. ATTRIBUTE EAP-Type-Generic-Token-Card 1286 octets
  291. ATTRIBUTE EAP-Type-RSA-Public-Key 1289 octets
  292. ATTRIBUTE EAP-Type-DSS-Unilateral 1290 octets
  293. ATTRIBUTE EAP-Type-KEA 1291 octets
  294. ATTRIBUTE EAP-Type-KEA-Validate 1292 octets
  295. ATTRIBUTE EAP-Type-EAP-TLS 1293 octets
  296. ATTRIBUTE EAP-Type-Defender-Token 1294 octets
  297. ATTRIBUTE EAP-Type-RSA-SecurID-EAP 1295 octets
  298. ATTRIBUTE EAP-Type-Arcot-Systems-EAP 1296 octets
  299. ATTRIBUTE EAP-Type-Cisco-LEAP 1297 octets
  300. ATTRIBUTE EAP-Type-Nokia-IP-Smart-Card 1298 octets
  301. ATTRIBUTE EAP-Type-SIM 1298 octets
  302. ATTRIBUTE EAP-Type-SRP-SHA1 1299 octets
  303. ATTRIBUTE EAP-Type-EAP-TTLS 1301 octets
  304. ATTRIBUTE EAP-Type-Remote-Access-Service 1302 octets
  305. ATTRIBUTE EAP-Type-AKA 1303 octets
  306. ATTRIBUTE EAP-Type-EAP-3Com-Wireless 1304 octets
  307. ATTRIBUTE EAP-Type-PEAP 1305 octets
  308. ATTRIBUTE EAP-Type-MS-EAP-Authentication 1306 octets
  309. ATTRIBUTE EAP-Type-MAKE 1307 octets
  310. ATTRIBUTE EAP-Type-CRYPTOCard 1308 octets
  311. ATTRIBUTE EAP-Type-EAP-MSCHAP-V2 1309 octets
  312. ATTRIBUTE EAP-Type-DynamID 1310 octets
  313. ATTRIBUTE EAP-Type-Rob-EAP 1311 octets
  314. ATTRIBUTE EAP-Type-SecurID-EAP 1312 octets
  315. ATTRIBUTE EAP-Type-MS-Authentication-TLV 1313 octets
  316. ATTRIBUTE EAP-Type-SentriNET 1314 octets
  317. ATTRIBUTE EAP-Type-EAP-Actiontec-Wireless 1315 octets
  318. ATTRIBUTE EAP-Type-Cogent-Biomentric-EAP 1316 octets
  319. ATTRIBUTE EAP-Type-AirFortress-EAP 1317 octets
  320. ATTRIBUTE EAP-Type-EAP-HTTP-Digest 1318 octets
  321. ATTRIBUTE EAP-Type-SecuriSuite-EAP 1319 octets
  322. ATTRIBUTE EAP-Type-DeviceConnect-EAP 1320 octets
  323. ATTRIBUTE EAP-Type-EAP-SPEKE 1321 octets
  324. ATTRIBUTE EAP-Type-EAP-MOBAC 1322 octets
  325. ATTRIBUTE EAP-Type-EAP-FAST 1323 octets
  326. ATTRIBUTE EAP-Type-Zonelabs 1324 octets
  327. ATTRIBUTE EAP-Type-EAP-Link 1325 octets
  328. ATTRIBUTE EAP-Type-EAP-PAX 1326 octets
  329. ATTRIBUTE EAP-Type-EAP-PSK 1327 octets
  330. ATTRIBUTE EAP-Type-EAP-SAKE 1328 octets
  331. ATTRIBUTE EAP-Type-EAP-IKEv2 1329 octets
  332. ATTRIBUTE EAP-Type-EAP-AKA2 1330 octets
  333. ATTRIBUTE EAP-Type-EAP-GPSK 1331 octets
  334. ATTRIBUTE EAP-Type-EAP-PWD 1332 octets
  335. ATTRIBUTE EAP-Type-EAP-EVEv1 1333 octets
  336. ATTRIBUTE EAP-Type-Microsoft-MS-CHAPv2 1306 octets
  337. ATTRIBUTE EAP-Type-Cisco-MS-CHAPv2 1309 octets
  338. ATTRIBUTE EAP-Type-MS-CHAP-V2 1306 octets
  339. #
  340. # Range: 1536 - 1791
  341. # EAP Sim sub-types.
  342. #
  343. # these are PW_EAP_SIM_X + 1536
  344. ATTRIBUTE EAP_Sim-Base 1536 octets
  345. ATTRIBUTE EAP-Sim-RAND 1537 octets
  346. ATTRIBUTE EAP-Sim-PADDING 1542 octets
  347. ATTRIBUTE EAP-Sim-NONCE_MT 1543 octets
  348. ATTRIBUTE EAP-Sim-PERMANENT_ID_REQ 1546 octets
  349. ATTRIBUTE EAP-Sim-MAC 1547 octets
  350. ATTRIBUTE EAP-Sim-NOTIFICATION 1548 octets
  351. ATTRIBUTE EAP-Sim-ANY_ID_REQ 1549 octets
  352. ATTRIBUTE EAP-Sim-IDENTITY 1550 octets
  353. ATTRIBUTE EAP-Sim-VERSION_LIST 1551 octets
  354. ATTRIBUTE EAP-Sim-SELECTED_VERSION 1552 octets
  355. ATTRIBUTE EAP-Sim-FULLAUTH_ID_REQ 1553 octets
  356. ATTRIBUTE EAP-Sim-COUNTER 1555 octets
  357. ATTRIBUTE EAP-Sim-COUNTER_TOO_SMALL 1556 octets
  358. ATTRIBUTE EAP-Sim-NONCE_S 1557 octets
  359. ATTRIBUTE EAP-Sim-IV 1665 octets
  360. ATTRIBUTE EAP-Sim-ENCR_DATA 1666 octets
  361. ATTRIBUTE EAP-Sim-NEXT_PSEUDONUM 1668 octets
  362. ATTRIBUTE EAP-Sim-NEXT_REAUTH_ID 1669 octets
  363. ATTRIBUTE EAP-Sim-CHECKCODE 1670 octets
  364. #
  365. # Range: 1800-1899
  366. # Temporary attributes, for local storage.
  367. #
  368. ATTRIBUTE Tmp-String-0 1800 string
  369. ATTRIBUTE Tmp-String-1 1801 string
  370. ATTRIBUTE Tmp-String-2 1802 string
  371. ATTRIBUTE Tmp-String-3 1803 string
  372. ATTRIBUTE Tmp-String-4 1804 string
  373. ATTRIBUTE Tmp-String-5 1805 string
  374. ATTRIBUTE Tmp-String-6 1806 string
  375. ATTRIBUTE Tmp-String-7 1807 string
  376. ATTRIBUTE Tmp-String-8 1808 string
  377. ATTRIBUTE Tmp-String-9 1809 string
  378. ATTRIBUTE Tmp-Integer-0 1810 integer
  379. ATTRIBUTE Tmp-Integer-1 1811 integer
  380. ATTRIBUTE Tmp-Integer-2 1812 integer
  381. ATTRIBUTE Tmp-Integer-3 1813 integer
  382. ATTRIBUTE Tmp-Integer-4 1814 integer
  383. ATTRIBUTE Tmp-Integer-5 1815 integer
  384. ATTRIBUTE Tmp-Integer-6 1816 integer
  385. ATTRIBUTE Tmp-Integer-7 1817 integer
  386. ATTRIBUTE Tmp-Integer-8 1818 integer
  387. ATTRIBUTE Tmp-Integer-9 1819 integer
  388. ATTRIBUTE Tmp-IP-Address-0 1820 ipaddr
  389. ATTRIBUTE Tmp-IP-Address-1 1821 ipaddr
  390. ATTRIBUTE Tmp-IP-Address-2 1822 ipaddr
  391. ATTRIBUTE Tmp-IP-Address-3 1823 ipaddr
  392. ATTRIBUTE Tmp-IP-Address-4 1824 ipaddr
  393. ATTRIBUTE Tmp-IP-Address-5 1825 ipaddr
  394. ATTRIBUTE Tmp-IP-Address-6 1826 ipaddr
  395. ATTRIBUTE Tmp-IP-Address-7 1827 ipaddr
  396. ATTRIBUTE Tmp-IP-Address-8 1828 ipaddr
  397. ATTRIBUTE Tmp-IP-Address-9 1829 ipaddr
  398. ATTRIBUTE Tmp-Octets-0 1830 octets
  399. ATTRIBUTE Tmp-Octets-1 1831 octets
  400. ATTRIBUTE Tmp-Octets-2 1832 octets
  401. ATTRIBUTE Tmp-Octets-3 1833 octets
  402. ATTRIBUTE Tmp-Octets-4 1834 octets
  403. ATTRIBUTE Tmp-Octets-5 1835 octets
  404. ATTRIBUTE Tmp-Octets-6 1836 octets
  405. ATTRIBUTE Tmp-Octets-7 1837 octets
  406. ATTRIBUTE Tmp-Octets-8 1838 octets
  407. ATTRIBUTE Tmp-Octets-9 1839 octets
  408. ATTRIBUTE Tmp-Date-0 1840 date
  409. ATTRIBUTE Tmp-Date-1 1841 date
  410. ATTRIBUTE Tmp-Date-2 1842 date
  411. ATTRIBUTE Tmp-Date-3 1843 date
  412. ATTRIBUTE Tmp-Date-4 1844 date
  413. ATTRIBUTE Tmp-Date-5 1845 date
  414. ATTRIBUTE Tmp-Date-6 1846 date
  415. ATTRIBUTE Tmp-Date-7 1847 date
  416. ATTRIBUTE Tmp-Date-8 1848 date
  417. ATTRIBUTE Tmp-Date-9 1849 date
  418. ATTRIBUTE Tmp-Integer64-0 1871 integer64
  419. ATTRIBUTE Tmp-Integer64-1 1872 integer64
  420. ATTRIBUTE Tmp-Integer64-2 1873 integer64
  421. ATTRIBUTE Tmp-Integer64-3 1874 integer64
  422. ATTRIBUTE Tmp-Integer64-4 1875 integer64
  423. ATTRIBUTE Tmp-Integer64-5 1876 integer64
  424. ATTRIBUTE Tmp-Integer64-6 1877 integer64
  425. ATTRIBUTE Tmp-Integer64-7 1878 integer64
  426. ATTRIBUTE Tmp-Integer64-8 1879 integer64
  427. ATTRIBUTE Tmp-Integer64-9 1880 integer64
  428. #
  429. # These attributes shouldn't be used anywhere. They are defined here
  430. # only for casting of values in conditional expressions.
  431. #
  432. # The order and number need to be consistent with the typedefs used
  433. # in the server source.
  434. #
  435. ATTRIBUTE Tmp-Cast-String 1851 string
  436. ATTRIBUTE Tmp-Cast-Integer 1852 integer
  437. ATTRIBUTE Tmp-Cast-Ipaddr 1853 ipaddr
  438. ATTRIBUTE Tmp-Cast-Date 1854 date
  439. ATTRIBUTE Tmp-Cast-Abinary 1855 abinary
  440. ATTRIBUTE Tmp-Cast-Octets 1856 octets
  441. ATTRIBUTE Tmp-Cast-Ifid 1857 ifid
  442. ATTRIBUTE Tmp-Cast-IPv6Addr 1858 ipv6addr
  443. ATTRIBUTE Tmp-Cast-IPv6Prefix 1859 ipv6prefix
  444. ATTRIBUTE Tmp-Cast-Byte 1860 byte
  445. ATTRIBUTE Tmp-Cast-Short 1861 short
  446. ATTRIBUTE Tmp-Cast-Ethernet 1862 ether
  447. ATTRIBUTE Tmp-Cast-Signed 1863 signed
  448. # don't use or define these
  449. ATTRIBUTE Tmp-Cast-Integer64 1869 integer64
  450. ATTRIBUTE Tmp-Cast-IPv4Prefix 1870 ipv4prefix
  451. # don't use or define VSA or MAX
  452. # Range: 1900-1909
  453. # WiMAX server-side attributes.
  454. #
  455. # These are NOT sent in a packet, but are otherwise
  456. # available for testing and validation. The various
  457. # things that *are* sent in a packet are derived from
  458. # these attributes.
  459. #
  460. ATTRIBUTE WiMAX-MN-NAI 1900 string
  461. ATTRIBUTE TLS-Cert-Serial 1910 string
  462. ATTRIBUTE TLS-Cert-Expiration 1911 string
  463. ATTRIBUTE TLS-Cert-Issuer 1912 string
  464. ATTRIBUTE TLS-Cert-Subject 1913 string
  465. ATTRIBUTE TLS-Cert-Common-Name 1914 string
  466. ATTRIBUTE TLS-Cert-Subject-Alt-Name-Email 1915 string
  467. ATTRIBUTE TLS-Cert-Subject-Alt-Name-Dns 1916 string
  468. ATTRIBUTE TLS-Cert-Subject-Alt-Name-Upn 1917 string
  469. # 1918 - 1919: reserved for future cert attributes
  470. ATTRIBUTE TLS-Client-Cert-Serial 1920 string
  471. ATTRIBUTE TLS-Client-Cert-Expiration 1921 string
  472. ATTRIBUTE TLS-Client-Cert-Issuer 1922 string
  473. ATTRIBUTE TLS-Client-Cert-Subject 1923 string
  474. ATTRIBUTE TLS-Client-Cert-Common-Name 1924 string
  475. ATTRIBUTE TLS-Client-Cert-Filename 1925 string
  476. ATTRIBUTE TLS-Client-Cert-Subject-Alt-Name-Email 1926 string
  477. ATTRIBUTE TLS-Client-Cert-X509v3-Extended-Key-Usage 1927 string
  478. ATTRIBUTE TLS-Client-Cert-X509v3-Subject-Key-Identifier 1928 string
  479. ATTRIBUTE TLS-Client-Cert-X509v3-Authority-Key-Identifier 1929 string
  480. ATTRIBUTE TLS-Client-Cert-X509v3-Basic-Constraints 1930 string
  481. ATTRIBUTE TLS-Client-Cert-Subject-Alt-Name-Dns 1931 string
  482. ATTRIBUTE TLS-Client-Cert-Subject-Alt-Name-Upn 1932 string
  483. ATTRIBUTE TLS-PSK-Identity 1933 string
  484. # 1934 - 1939: reserved for future cert attributes
  485. #
  486. # Range: 1940-2099
  487. # Free
  488. #
  489. # Range: 2100-2199
  490. # SoH attributes; FIXME: these should really be protocol attributes
  491. # so that the SoH radius request can be proxied, but from which
  492. # vendor? Sigh...
  493. #
  494. ATTRIBUTE SoH-MS-Machine-OS-vendor 2100 integer
  495. VALUE SoH-MS-Machine-OS-vendor Microsoft 311
  496. ATTRIBUTE SoH-MS-Machine-OS-version 2101 integer
  497. ATTRIBUTE SoH-MS-Machine-OS-release 2102 integer
  498. ATTRIBUTE SoH-MS-Machine-OS-build 2103 integer
  499. ATTRIBUTE SoH-MS-Machine-SP-version 2104 integer
  500. ATTRIBUTE SoH-MS-Machine-SP-release 2105 integer
  501. ATTRIBUTE SoH-MS-Machine-Processor 2106 integer
  502. VALUE SoH-MS-Machine-Processor x86 0
  503. VALUE SoH-MS-Machine-Processor i64 6
  504. VALUE SoH-MS-Machine-Processor x86_64 9
  505. ATTRIBUTE SoH-MS-Machine-Name 2107 string
  506. ATTRIBUTE SoH-MS-Correlation-Id 2108 octets
  507. ATTRIBUTE SoH-MS-Machine-Role 2109 integer
  508. VALUE SoH-MS-Machine-Role client 1
  509. VALUE SoH-MS-Machine-Role dc 2
  510. VALUE SoH-MS-Machine-Role server 3
  511. ATTRIBUTE SoH-Supported 2119 integer
  512. VALUE SoH-Supported no 0
  513. VALUE SoH-Supported yes 1
  514. ATTRIBUTE SoH-MS-Windows-Health-Status 2120 string
  515. ATTRIBUTE SoH-MS-Health-Other 2129 string
  516. #
  517. # Range: 2200-2219
  518. # Utilities bundled with the server
  519. #
  520. ATTRIBUTE Radclient-Test-Name 2200 string
  521. #
  522. # Range: 2220-2999
  523. # Free
  524. #
  525. # Range: 3000-3999
  526. # Site-local attributes (see raddb/dictionary.in)
  527. # Do NOT define attributes in this range!
  528. #
  529. # Range: 4000-65535
  530. # Unused
  531. #
  532. # Range: 65536-
  533. # Invalid. Don't use.
  534. #
  535. #
  536. # Non-Protocol Integer Translations
  537. #
  538. VALUE Auth-Type Local 0
  539. VALUE Auth-Type System 1
  540. VALUE Auth-Type SecurID 2
  541. VALUE Auth-Type Crypt-Local 3
  542. VALUE Auth-Type Reject 4
  543. VALUE Auth-Type ActivCard 5
  544. VALUE Auth-Type EAP 6
  545. VALUE Auth-Type ARAP 7
  546. #
  547. # FreeRADIUS extensions (most originally from Cistron)
  548. #
  549. VALUE Auth-Type Accept 254
  550. VALUE Auth-Type PAP 1024
  551. VALUE Auth-Type CHAP 1025
  552. # 1026 was LDAP, but we deleted it. Adding it back will break the
  553. # ldap module.
  554. VALUE Auth-Type PAM 1027
  555. VALUE Auth-Type MS-CHAP 1028
  556. VALUE Auth-Type MSCHAP 1028
  557. VALUE Auth-Type Kerberos 1029
  558. VALUE Auth-Type CRAM 1030
  559. VALUE Auth-Type NS-MTA-MD5 1031
  560. # 1032 is unused (was a duplicate of CRAM)
  561. VALUE Auth-Type SMB 1033
  562. VALUE Auth-Type MS-CHAP-V2 1034
  563. #
  564. # Authorization type, too.
  565. #
  566. VALUE Autz-Type Local 0
  567. #
  568. # And accounting
  569. #
  570. VALUE Acct-Type Local 0
  571. #
  572. # And Session handling
  573. #
  574. VALUE Session-Type Local 0
  575. #
  576. # And Post-Auth
  577. VALUE Post-Auth-Type Local 0
  578. VALUE Post-Auth-Type Reject 1
  579. #
  580. # Experimental Non-Protocol Integer Translations for FreeRADIUS
  581. #
  582. VALUE Fall-Through No 0
  583. VALUE Fall-Through Yes 1
  584. VALUE Relax-Filter No 0
  585. VALUE Relax-Filter Yes 1
  586. VALUE Strip-User-Name No 0
  587. VALUE Strip-User-Name Yes 1
  588. VALUE Packet-Type Access-Request 1
  589. VALUE Packet-Type Access-Accept 2
  590. VALUE Packet-Type Access-Reject 3
  591. VALUE Packet-Type Accounting-Request 4
  592. VALUE Packet-Type Accounting-Response 5
  593. VALUE Packet-Type Accounting-Status 6
  594. VALUE Packet-Type Password-Request 7
  595. VALUE Packet-Type Password-Accept 8
  596. VALUE Packet-Type Password-Reject 9
  597. VALUE Packet-Type Accounting-Message 10
  598. VALUE Packet-Type Access-Challenge 11
  599. VALUE Packet-Type Status-Server 12
  600. VALUE Packet-Type Status-Client 13
  601. #
  602. # The following packet types are described in RFC 2882,
  603. # but they are NOT part of the RADIUS standard. Instead,
  604. # they are informational about vendor-specific extensions
  605. # to the RADIUS standard.
  606. #
  607. VALUE Packet-Type Resource-Free-Request 21
  608. VALUE Packet-Type Resource-Free-Response 22
  609. VALUE Packet-Type Resource-Query-Request 23
  610. VALUE Packet-Type Resource-Query-Response 24
  611. VALUE Packet-Type Alternate-Resource-Reclaim-Request 25
  612. VALUE Packet-Type NAS-Reboot-Request 26
  613. VALUE Packet-Type NAS-Reboot-Response 27
  614. VALUE Packet-Type Next-Passcode 29
  615. VALUE Packet-Type New-Pin 30
  616. VALUE Packet-Type Terminate-Session 31
  617. VALUE Packet-Type Password-Expired 32
  618. VALUE Packet-Type Event-Request 33
  619. VALUE Packet-Type Event-Response 34
  620. # RFC 3576 allocates packet types 40-45
  621. VALUE Packet-Type Disconnect-Request 40
  622. VALUE Packet-Type Disconnect-ACK 41
  623. VALUE Packet-Type Disconnect-NAK 42
  624. VALUE Packet-Type CoA-Request 43
  625. VALUE Packet-Type CoA-ACK 44
  626. VALUE Packet-Type CoA-NAK 45
  627. VALUE Packet-Type IP-Address-Allocate 50
  628. VALUE Packet-Type IP-Address-Release 51
  629. VALUE Response-Packet-Type Access-Request 1
  630. VALUE Response-Packet-Type Access-Accept 2
  631. VALUE Response-Packet-Type Access-Reject 3
  632. VALUE Response-Packet-Type Accounting-Request 4
  633. VALUE Response-Packet-Type Accounting-Response 5
  634. VALUE Response-Packet-Type Accounting-Status 6
  635. VALUE Response-Packet-Type Password-Request 7
  636. VALUE Response-Packet-Type Password-Accept 8
  637. VALUE Response-Packet-Type Password-Reject 9
  638. VALUE Response-Packet-Type Accounting-Message 10
  639. VALUE Response-Packet-Type Access-Challenge 11
  640. VALUE Response-Packet-Type Status-Server 12
  641. VALUE Response-Packet-Type Status-Client 13
  642. VALUE Response-Packet-Type Disconnect-Request 40
  643. VALUE Response-Packet-Type Disconnect-ACK 41
  644. VALUE Response-Packet-Type Disconnect-NAK 42
  645. VALUE Response-Packet-Type CoA-Request 43
  646. VALUE Response-Packet-Type CoA-ACK 44
  647. VALUE Response-Packet-Type CoA-NAK 45
  648. #
  649. # Special value
  650. #
  651. VALUE Response-Packet-Type Do-Not-Respond 256
  652. #
  653. # EAP Sub-types, inside of Request and Response packets
  654. #
  655. # http://www.iana.org/assignments/ppp-numbers
  656. # "PPP EAP REQUEST/RESPONSE TYPES"
  657. #
  658. #
  659. # See dictionary.microsoft, MS-Acct-EAP-Type for similar definitions
  660. #
  661. VALUE EAP-Type None 0
  662. VALUE EAP-Type Identity 1
  663. VALUE EAP-Type Notification 2
  664. VALUE EAP-Type NAK 3
  665. VALUE EAP-Type MD5-Challenge 4
  666. VALUE EAP-Type MD5 4
  667. VALUE EAP-Type One-Time-Password 5
  668. VALUE EAP-Type OTP 5
  669. VALUE EAP-Type Generic-Token-Card 6
  670. VALUE EAP-Type GTC 6
  671. VALUE EAP-Type RSA-Public-Key 9
  672. VALUE EAP-Type DSS-Unilateral 10
  673. VALUE EAP-Type KEA 11
  674. VALUE EAP-Type KEA-Validate 12
  675. VALUE EAP-Type TLS 13
  676. VALUE EAP-Type Defender-Token 14
  677. VALUE EAP-Type RSA-SecurID-EAP 15
  678. VALUE EAP-Type Arcot-Systems-EAP 16
  679. VALUE EAP-Type Cisco-LEAP 17
  680. VALUE EAP-Type LEAP 17
  681. VALUE EAP-Type Nokia-IP-Smart-Card 18
  682. VALUE EAP-Type SIM 18
  683. VALUE EAP-Type SRP-SHA1 19
  684. # 20 is unassigned
  685. VALUE EAP-Type TTLS 21
  686. VALUE EAP-Type Remote-Access-Service 22
  687. VALUE EAP-Type AKA 23
  688. VALUE EAP-Type 3Com-Wireless 24
  689. VALUE EAP-Type PEAP 25
  690. VALUE EAP-Type Microsoft-MS-CHAPv2 26
  691. VALUE EAP-Type MAKE 27
  692. VALUE EAP-Type CRYPTOCard 28
  693. VALUE EAP-Type Cisco-MS-CHAPv2 29
  694. VALUE EAP-Type DynamID 30
  695. VALUE EAP-Type Rob-EAP 31
  696. VALUE EAP-Type SecurID-EAP 32
  697. VALUE EAP-Type MS-Authentication-TLV 33
  698. VALUE EAP-Type SentriNET 34
  699. VALUE EAP-Type Actiontec-Wireless 35
  700. VALUE EAP-Type Cogent-Biomentric-EAP 36
  701. VALUE EAP-Type AirFortress-EAP 37
  702. VALUE EAP-Type HTTP-Digest 38
  703. VALUE EAP-Type TNC 38
  704. VALUE EAP-Type SecuriSuite-EAP 39
  705. VALUE EAP-Type DeviceConnect-EAP 40
  706. VALUE EAP-Type SPEKE 41
  707. VALUE EAP-Type MOBAC 42
  708. VALUE EAP-Type FAST 43
  709. VALUE EAP-Type Zonelabs 44
  710. VALUE EAP-Type Link 45
  711. VALUE EAP-Type PAX 46
  712. VALUE EAP-Type PSK 47
  713. VALUE EAP-Type SAKE 48
  714. VALUE EAP-Type IKEv2 49
  715. VALUE EAP-Type AKA2 50
  716. VALUE EAP-Type GPSK 51
  717. VALUE EAP-Type PWD 52
  718. VALUE EAP-Type EVEv1 53
  719. #
  720. # And this is what most people mean by MS-CHAPv2
  721. #
  722. VALUE EAP-Type MSCHAPv2 26
  723. #
  724. # This says TLS, but it's only valid for TTLS & PEAP.
  725. # EAP-TLS *always* requires a client certificate.
  726. #
  727. VALUE EAP-TLS-Require-Client-Cert No 0
  728. VALUE EAP-TLS-Require-Client-Cert Yes 1
  729. #
  730. # These are the EAP-Code values.
  731. #
  732. VALUE EAP-Code Request 1
  733. VALUE EAP-Code Response 2
  734. VALUE EAP-Code Success 3
  735. VALUE EAP-Code Failure 4
  736. #
  737. # For MS-CHAP, do we run ntlm_auth, or not.
  738. #
  739. VALUE MS-CHAP-Use-NTLM-Auth No 0
  740. VALUE MS-CHAP-Use-NTLM-Auth Yes 1