ATTRIBUTE Acct-Session-Start-Time 1050 date
ATTRIBUTE Acct-Unique-Session-Id 1051 string
ATTRIBUTE Client-IP-Address 1052 ipaddr virtual
-ATTRIBUTE Ldap-UserDn 1053 string
+ATTRIBUTE LDAP-UserDN 1053 string
ATTRIBUTE NS-MTA-MD5-Password 1054 string
ATTRIBUTE SQL-User-Name 1055 string
ATTRIBUTE LM-Password 1057 octets
ATTRIBUTE EAP-Session-Id 1146 octets
ATTRIBUTE Chbind-Response-Code 1147 integer
-ATTRIBUTE Chbind-Response-Code 1147 integer
-
VALUE Chbind-Response-Code success 2
VALUE Chbind-Response-Code failure 3
ATTRIBUTE SSHA2-384-Password 1179 octets
ATTRIBUTE SSHA2-512-Password 1180 octets
+ATTRIBUTE MS-CHAP-Peer-Challenge 1192 octets
+
#
# Range: 1200-1279
# EAP-SIM (and other EAP type) weirdness.
ATTRIBUTE EAP-Sim-Ki 1215 octets
ATTRIBUTE EAP-Sim-Algo-Version 1216 integer
+ATTRIBUTE Outer-Realm-Name 1218 string
+ATTRIBUTE Inner-Realm-Name 1219 string
+
#
# Range: 1280 - 1535
# EAP-type specific attributes
# 1934 - 1939: reserved for future cert attributes
+# 1940 - 1949: reserved for TLS session caching, mostly in 3.1
+
+# Set by EAP-TLS code
+ATTRIBUTE TLS-OCSP-Cert-Valid 1943 integer
+VALUE TLS-OCSP-Cert-Valid unknown 3
+VALUE TLS-OCSP-Cert-Valid skipped 2
+VALUE TLS-OCSP-Cert-Valid yes 1
+VALUE TLS-OCSP-Cert-Valid no 0
+
+ATTRIBUTE TLS-Cache-Filename 1946 string
+
#
# Range: 1940-2099
# Free
#
VALUE Auth-Type Local 1
-VALUE Auth-Type System 2
-VALUE Auth-Type SecurID 3
VALUE Auth-Type Reject 4
-VALUE Auth-Type ActivCard 5
-VALUE Auth-Type EAP 6
#
# FreeRADIUS extensions (most originally from Cistron)
#
VALUE Auth-Type Accept 254
-VALUE Auth-Type PAP 1024
-VALUE Auth-Type CHAP 1025
-# 1026 was LDAP, but we deleted it. Adding it back will break the
-# ldap module.
-VALUE Auth-Type PAM 1027
-VALUE Auth-Type MS-CHAP 1028
-VALUE Auth-Type MSCHAP 1028
-VALUE Auth-Type Kerberos 1029
-VALUE Auth-Type CRAM 1030
-VALUE Auth-Type NS-MTA-MD5 1031
-# 1032 is unused (was a duplicate of CRAM)
-VALUE Auth-Type SMB 1033
-VALUE Auth-Type MS-CHAP-V2 1034
-
#
# Authorization type, too.
#
VALUE EAP-Type NAK 3
VALUE EAP-Type MD5-Challenge 4
VALUE EAP-Type MD5 4
+VALUE EAP-Type EAP-MD5 4
VALUE EAP-Type One-Time-Password 5
VALUE EAP-Type OTP 5
VALUE EAP-Type Generic-Token-Card 6
VALUE EAP-Type GTC 6
+VALUE EAP-Type EAP-GTC 6
VALUE EAP-Type RSA-Public-Key 9
VALUE EAP-Type DSS-Unilateral 10
VALUE EAP-Type KEA 11
VALUE EAP-Type KEA-Validate 12
VALUE EAP-Type TLS 13
+VALUE EAP-Type EAP-TLS 13
VALUE EAP-Type Defender-Token 14
VALUE EAP-Type RSA-SecurID-EAP 15
VALUE EAP-Type Arcot-Systems-EAP 16
VALUE EAP-Type LEAP 17
VALUE EAP-Type Nokia-IP-Smart-Card 18
VALUE EAP-Type SIM 18
+VALUE EAP-Type EAP-SIM 18
VALUE EAP-Type SRP-SHA1 19
# 20 is unassigned
VALUE EAP-Type TTLS 21
+VALUE EAP-Type EAP-TTLS 21
VALUE EAP-Type Remote-Access-Service 22
VALUE EAP-Type AKA 23
+VALUE EAP-Type EAP-AKA 23
VALUE EAP-Type 3Com-Wireless 24
VALUE EAP-Type PEAP 25
VALUE EAP-Type Microsoft-MS-CHAPv2 26
VALUE EAP-Type AKA2 50
VALUE EAP-Type GPSK 51
VALUE EAP-Type PWD 52
-VALUE EAP-Type EVEv1 53
+VALUE EAP-Type EKEv1 53
#
# And this is what most people mean by MS-CHAPv2
#
VALUE EAP-Type MSCHAPv2 26
+VALUE EAP-Type EAP-MSCHAPv2 26
#
# This says TLS, but it's only valid for TTLS & PEAP.