16xx error codes in RADIUS Authentication attempts

  • 3456291
  • 09-Nov-2007
  • 16-Mar-2012

Environment

Novell Modular Authentication Service (NMAS) RADIUS 4.14
Novell NetWare 6.5

...or...

SUSE Linux Enterprise Server 9 or 10
Novell Open Enterprise Server (Linux based)
FreeRADIUS

Situation

In Netware, the server is logging error codes to the RADIUS console screen consisting of 1642, 1648, 1659, 1667, 1668, 1673, or 1688 (anything in the 1600 to 1699 range).

In Linux, when running FreeRADIUS using the "radiusd -X" command, the errors are shown in the output after attempting a login request.

Resolution

All error codes between 1600 and 1699 are NMAS error codes. For additional descriptions of the individual error codes, consultTID 3987489 - NMAS Error Codes. Each error will have it's own

Additional Information

As an example, the 1688 error code for NMAS results from a limitation on concurrent login requests. Either allowing additional logins or closing current connections, should prevent the concurrent login error from occuring. For example, referencing KB 3053029 - Error -1688 while logging in via NMAS Radiuscan be used in resolving 1688 (concurrent login) errors.

The radtest cannot be used to test issues with Universal Password, as it always sends credential information in plain-text format, which allows the LDAP binds to occur without attempting Universal Password retrieval.