[strongSwan] eap-radius authentication timeout

Martin Willi martin at strongswan.org
Tue Sep 16 14:42:04 CEST 2014


> Is there an option to set the eap-radius plugin authentication timeout /
> retransmit period?

No, these values are currently hardcoded, you may change them at [1].

> I am using StrongSwan with FreeRadius (and LDAP), problem is that
> authentication requests time out after about 15 seconds. This makes e.g.
> two-factor authentication inconvenient to use.

I don't understand why two factor authentication should be an issue.
According to your log, the RADIUS server does not respond to the
authentication request, and the retransmission times out. Why does
processing the RADIUS request take longer than 14s, given that there is
no user intervention at this stage?



