Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FreeRADIUS3 cleartext password in users file

    Scheduled Pinned Locked Moved pfSense Packages
    2 Posts 2 Posters 921 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by

      Hi together

      I build a solution to authenticate the wifi users with radius to get dynamic VLAN assignment to work.
      I use UniFi APs with a controller and the freeradius3 package on my existing pfsense.
      Everything work fine so far. I use the "users" function of freeradius package itself.

      One point that is really annoying for me is the fact that the password of all users is stored in plaintext in the users-file that can be displayed over "view config" -> "users".

      If I select "MD5-Password" the password is stored as hash but wifi authentication doesn't work anymore :(

      Is there any solution to get my wifi authentication work but without seeing the passwords in cleartext in the users-file?

      (I also tried with LDAP but I can not find a solution to map groups to VLANs in Freeradius. So what I look for is ldap group "wifi-lan" = vlan10, "wifi-guest" = vlan20, "wifi-voip" = vlan30 ...)

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Even if they were encrypted before being put in there, they are still in plain text in config.xml. If you don't like that, set the user password to MD5-Password and put the hash in and not the actual password in FreeRADIUS.

        Keeping them plaintext but encrypting/hashing them in the users file would be pointless.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.