FreeRADIUS can authenticate users on systems such as 802.1x (WiFi), dialup, PPPoE, VPN's, VoIP, and many others. It supports back-end databases such as MySQL, PostgreSQL, Oracle, Microsoft Active Directory, Apache Cassandra, Redis, OpenLDAP, and many more. It is used daily to authenticate the Internet access for hundreds of millions of people, in sites ranging from 10 to 10 million+ users.
For a list of changes in version 4.0, please see doc/ChangeLog
See raddb/README.md for information on what to do to update your configuration.
Administrators upgrading from a previous version should install this version in a different location from their existing systems. Any existing configuration should be carefully migrated to the new version, in order to take advantage of the new features which can greatly simply configuration.
Please see https://freeradius.org and https://wiki.freeradius.org for more information.
INSTALL.md file in this directory.
The most common problem is that people change large amounts of the configuration without understanding what they're doing, and without testing their changes. The preferred method of operation is the following:
- Start off with the default configuration files.
- Save a copy of the default configuration: It WORKS. Don't change it!
- Verify that the server starts - in debugging mode (
- Send it test packets using "radclient", or a NAS or AP.
- Verify that the server does what you expect
- If it does not work, change the configuration, and go to step (3)
- If you're stuck, revert to using the "last working" configuration.
- If it works, proceed to step (6).
- Save a copy of the working configuration, along with a note of what you changed, and why.
- Make a SMALL change to the configuration.
- Repeat from step (3).
radiusd -X) and READ the output. We cannot emphasize this point strongly enough. The vast majority of problems can be solved by carefully reading the debugging output, which includes WARNINGs about common issues, and suggestions for how they may be fixed.
Many questions are answered on the Wiki:
Read the configuration files. Many parts of the server are documented only with extensive comments in the configuration files.
Search the mailing lists. For example, using Google, searching "site:lists.freeradius.org " will return results from the FreeRADIUS mailing lists.