⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 dictionary.5

📁 使用最广泛的radius的linux的源码
💻 5
字号:
.\"     # DS - begin display.de DS.RS.nf.sp...\"     # DE - end display.de DE.fi.RE.sp...TH dictionary 5 "31 Oct 2005".SH NAMEdictionary \- RADIUS dictionary file.SH DESCRIPTIONThe master RADIUS dictionary file resides in\fI/etc/raddb/dictionary\fP.  It references other \fIdictionary\fPfiles located in \fI/usr/local/share/freeradius/\fP.  Each dictionaryfile contains a list of RADIUS attributes and values, which the serveruses to map between descriptive names and on-the-wire data.  The nameshave no meaning outside of the RADIUS server itself, and are neverexchanged between server and clients..PPThat is, editing the dictionaries will have NO EFFECT on anythingother than the server that is reading those files.  Adding newattributes to the dictionaries will have NO EFFECT on RADIUS clients,and will not make RADIUS clients magically understand thoseattributes.  The dictionaries are solely for local administratorconvenience, and are specific to each version of FreeRADIUS..PPThe dictionaries in \fI/usr/local/share\fP SHOULD NOT be edited unlessyou know exactly what you are doing.  Changing them will most likelybreak your RADIUS deployment..PPIf you need to add new attributes, please edit the\fI/etc/raddb/dictionary\fP file.  It's sole purpose is to containsite-local defintions that are added by the local administrator..SH FORMATEvery line starting with a hash sign.RB (' # ')is treated as comment and ignored..PPEach line of the file can contain one of the following strings.TP 0.5i.B ATTRIBUTE name  number  type [vendor|options]Define a RADIUS attribute name to number mapping.  The \fIname\fPfield can be any non-space text, but is usually taken from\fIRFC2865\fP, and other related documents.  The \fInumber\fP field isalso taken from the relevant documents, for that name.  The \fItype\fPfield can be one of \fIstring\fP, \fIoctets\fP, \fIipaddr\fP,\fIinteger\fP, \fIdate\fP, \fIifid\fP, \fIipv6addr\fP,\fIipv6prefix\fP, or \fIether\fP \fIabinary\fP.  See the RFC's, or the main\fIdictionary\fP file for a description of the various types.The last (optional) field of an attribute definition can have either avendor name, or options for that attribute.  When a vendor name isgiven, the attribute is defined to be a vendor specific attribute.Alternately, the options may be the a comma-separated list of thefollowing options:.TP 0.5i.DS	encrypt=[1-3].DE.RSMark the attribute as being encrypted with one of three methods.  "1"means that the attribute is encrypted with the method as defined in\fIRFC2865\fP for the User-Password attribute.  "2" means that thepassword is encrypted with the method as defined in \fIRFC2868\fP forthe Tunnel-Password attribute.  "3" means that the attribute isencrypted as per Ascend's definitions for the Ascend-Send-Secret attribute..RE.DS	has_tag.DE.RSMark the attribute as being permitted to have a tag, as defined in\fIRFC2868\fP.  The purpose of the tag is to allow grouping ofattributes for tunnelled users.  See \fIRFC2868\fP for more details..REWhen the server receives an encoded attribute in a RADIUS packet, itlooks up that attribute by number in the dictionary, and uses the namefound there for printing diagnostic and log messages..TP 0.5i.B VALUE attribute-name value-name numberDefine an attribute value name to number mapping, for an attribute oftype \fIinteger\fP.  The \fIattribute-name\fP field MUST be previouslydefined by an \fIATTRIBUTE\fP entry.  The \fIvalue-name\fP field canbe any non-space text, but is usually taken from \fIRFC2865\fP, orother documents..  The \fInumber\fP field is also taken from therelevant documents, for that name.When the server receives an encoded value in a RADIUS packet, it looksup the value of that attribute by number in the dictionary, and usesthe name found there for printing diagnostic and log messages..TP 0.5i.B VENDOR vendor-name number [format=t,l]Define a Vendor Specific Attribute encapsulation for \fIvendor-name\fPto \fInumber\fP.  For a list of vendor names and numbers, seehttp://www.iana.org/enterprise-numbers.txt..PPThe "format=t,l" statement tells the server how many octets to use toencode/decode the vendor "type" and "length" fields in the attributes.The default is "format=1,1", which does not have to be specified.  ForUSR VSA's, the format is "format=4,0", for Lucent VSA's it's"format=2,1", and for Starent VSA's it's "format=2,2"..PPThe supported values for the number of type octets (i.e. the firstdigit) are 1, 2, and 4.  The support values for the number of lengthoctets (i.e. the second digit) are 0, 1, and 2.  Any combination ofthose values will work..TP 0.5i.B $INCLUDE filenameInclude dictionary entries from the file \fIfilename\fP.  The\fIfilename\fP is taken as relative to the location of the file whichis asking for the inclusion..PP.SH FILES.I /etc/raddb/dictionary,.I /usr/share/freeradius/dictionary.*.SH "SEE ALSO".BR radiusd (8),.BR naslist (5),.BR RFC2865,.BR RFC2866,.BR RFC2868

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -