Re: reauth-problem with WPA2-tls

2010-06-03 Thread Alexander Clouter
/SELECTing your accounting logs that much easier. Cheers -- Alexander Clouter .sigmonster says: You are so boring that when I see you my feet go to sleep. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Using rml_perl to modify calling_station_id and set as sql_user_name

2010-05-31 Thread Alexander Clouter
syntax you wrap it in a call to LOWER() so then everything is in lowercase in your table. Cheers -- Alexander Clouter .sigmonster says: Snoopy: No problem is so big that it can't be run away from. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ISG DHCP relay

2010-05-18 Thread Alexander Clouter
to send traffic to your network, after all it involves a device on blic.net's network, can you help with my connectivity problems? /sarcasm -- Alexander Clouter .sigmonster says: Stay on the trail. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Private attribute assigned in clients.conf and checked in huntgroups ?

2010-05-03 Thread Alexander Clouter
in the commented out section above :) Cheers -- Alexander Clouter .sigmonster says: You may get an opportunity for advancement today. Watch it! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Dynamic Vlan assigment 802.1x with cisco

2010-04-22 Thread Alexander Clouter
/12.1_22_ea11x/configuration/guide/sw8021x.html -- Alexander Clouter .sigmonster says: Do not use if foil seal is broken. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Dynamic Vlan assigment 802.1x with cisco

2010-04-22 Thread Alexander Clouter
the use of names. Cheers -- Alexander Clouter .sigmonster says: Neckties strangle clear thinking. -- Lin Yutang - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Dynamic Vlan assigment 802.1x with cisco

2010-04-22 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: Life is to you a dashing and bold adventure. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: User enabled for one only NAS

2010-04-07 Thread Alexander Clouter
that... ...it would be impolite for us to say. Cheers -- Alexander Clouter .sigmonster says: We are the people our parents warned us about. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP Session resumption reply attributes

2010-01-21 Thread Alexander Clouter
in the authentication section via an amended LDAP filter where you only authenticate against user objects where 'accountdisabled=false' or something -- Alexander Clouter .sigmonster says: Your aim is high and to the right. - List info/subscribe/unsubscribe? See http

Re: Removing an attribute from reply message!

2010-01-20 Thread Alexander Clouter
in 2.1.8...you will see the workaround for eariler version is: Session-Octets-Limit -= '%{reply:Session-Octets-Limit} Cheers -- Alexander Clouter .sigmonster says: Poverty begins at home. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP Session resumption reply attributes

2010-01-20 Thread Alexander Clouter
Arran Cudbard-Bell arran.cudbard-b...@hp.com wrote: On 1/17/2010 8:37 AM, Alexander Clouter wrote: James J J Hooperjjj.hoo...@bristol.ac.uk wrote: In order to also return e.g. VLAN IDs (that could be computed from the inner User-Name in a non-session-resumption enabled config), I can

Re: EAP Session resumption reply attributes

2010-01-17 Thread Alexander Clouter
[1] in my opinion[2] it's a Bad Idea(tm) to do *user* authorisation...host authorisation is fine though [2] the 'why' is in how do you handle multi-user hosts where there *could* be multiple simultaneous interactive users on the host -- Alexander Clouter .sigmonster says: Memory

Re: Have a client with multiple secrets?

2010-01-13 Thread Alexander Clouter
. Cheers -- Alexander Clouter .sigmonster says: Postmen never die, they just lose their zip. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FR 2.1.8 Issue - Unjustified(?) Access-Rejects.

2010-01-12 Thread Alexander Clouter
that could probably be NFS shared or something or other with locking safely enough -- Alexander Clouter .sigmonster says: How come only your friends step on your new white sneakers? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: On-line debugging tool

2010-01-07 Thread Alexander Clouter
there is actually a mismatch). Of course you could have a '-o attr1,attr2' to protect other attributes at runtime too. Only something to add to the wishlist. :) Cheers -- Alexander Clouter .sigmonster says: Straw? No, too stupid a fad. I put soot on warts. - List info/subscribe/unsubscribe

Re: On-line debugging tool

2010-01-07 Thread Alexander Clouter
very, very, difficult. I was not really thinking past the common ones, however thinking about things more so, I actually prefer the checkpatch.pl-esque approach, then we can all contribute and fix things :) Cheers -- Alexander Clouter .sigmonster says: I'm so broke I can't even pay attention

Re: Managing the RADIUS database

2010-01-06 Thread Alexander Clouter
? Cheers -- Alexander Clouter .sigmonster says: Cure the disease and kill the patient. -- Francis Bacon - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Managing the RADIUS database

2010-01-06 Thread Alexander Clouter
of postgreSQL For me it's the CIDR syntax: SELECT * FROM dot1x_auth WHERE nas_ip_address = 1.2.0.0/16 Cheers -- Alexander Clouter .sigmonster says: The price of greatness is responsibility. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

rlm_perl symbol lookup errors

2010-01-01 Thread Alexander Clouter
[1] http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg56983.html P.S. seems there is a missing /li on the freeradius homepage so the recent news after the first item is left wedged over -- Alexander Clouter .sigmonster says: Your supervisor is thinking about you

Re: FreeRADIUS Server version 2.1.8 problem with Debian 5 64bit

2009-12-31 Thread Alexander Clouter
you read the error message and type 'aptitude install quilt'? Cheers -- Alexander Clouter .sigmonster says: Misuse may cause suffocation. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Recall: MAC authentication bypass --- How?am?Isupposedto?edit?theusersfile to include multiple MAC addresses??

2009-12-30 Thread Alexander Clouter
... Is it some weird outlook feature that is meant to 'unsend' email? Yep, only works if you have a MS Exchange server apparently (maybe it works with Outlook-Outlook). Meanwhile the rest of the world just laughs and smiles. :) Cheers -- Alexander Clouter .sigmonster says: And on the seventh day, He

OT: MS do I hate thee?

2009-12-30 Thread Alexander Clouter
that have to deal with their cruft. However that's why we have anti-trust cases and multi-billion ${UNIT-CURRENCY} fines :) Cheers -- Alexander Clouter .sigmonster says: The best things in life are for a fee. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Deny internet access to delinquent accounts

2009-12-28 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: Memories of you remind me of you. -- Karl Lehenbauer - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

OT: Re: Deny internet access to delinquent accounts

2009-12-28 Thread Alexander Clouter
infrastructure can do what you need. Means you need to know someone who knows your infrastructure *and* knows how to build something like this. You might need to hire in some conslutant time. Cheers -- Alexander Clouter .sigmonster says: Stone's Law: One man's simple

Re: Calling-Station-Id

2009-12-21 Thread Alexander Clouter
EasyHorpak.com i...@easyhorpak.com wrote: [-- text/html, encoding quoted-printable, charset: TIS-620, 66 lines --] [-- text/plain, encoding 7bit, charset: us-ascii, 2 lines --] Please learn to how to use an email client *sigh* -- Alexander Clouter .sigmonster says: Don't hit a man

Re: MAC authentication bypass --- How am I supposed to?edit?theusers?file to include multiple MAC addresses??

2009-12-21 Thread Alexander Clouter
Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk wrote: the real answer is to get the vendors to sort their cheap shoddy kit out ;-) Ahem *Vendor :P - - Sorry I have to do it or they beat me :( dare I ask why you do not use you new 'formal' email address? ;) Cheers -- Alexander

Re: Pre-release of Version 2.1.8

2009-12-21 Thread Alexander Clouter
the SIGPIPE there? As for the latter one, that's new to me. Alas it is going to be difficult to repeat this 'experiment' as I would have to turn power off to one of our server rooms...tends to annoy the yokels. Cheers -- Alexander Clouter .sigmonster says: BOFH excuse #276: U.S

Re: Pre-release of Version 2.1.8

2009-12-21 Thread Alexander Clouter
to a neutrino burst? :) Cheers -- Alexander Clouter .sigmonster says: Shut off engine before fueling. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Multiple clients on same IP address

2009-12-21 Thread Alexander Clouter
to the RADIUS server -- Alexander Clouter .sigmonster says: A dead man cannot bite. -- Gnaeus Pompeius (Pompey) - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Multiple clients on same IP address

2009-12-21 Thread Alexander Clouter
-Identifier attribute -- Alexander Clouter .sigmonster says: TAILFINS!! ... click ... - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: MAC authentication bypass --- How am I supposed to edit?theusers file to include multiple MAC addresses??

2009-12-20 Thread Alexander Clouter
later on why you are looking through your logs you are not running into case-sensitive issues (LDAP lookups are not case sensitive so for authorisation, it does not matter). Cheers -- Alexander Clouter .sigmonster says: Don't get even -- get odd! - List info/subscribe/unsubscribe? See http

Re: MAC authentication bypass --- How am I supposed to?edit?theusers file to include multiple MAC addresses??

2009-12-20 Thread Alexander Clouter
cannot even get past the tendering phase now :) Although it does nothing about the legacy guff, it stops new guff connecting. Cheers -- Alexander Clouter .sigmonster says: A sinking ship gathers no moss. -- Donald Kaul - List info/subscribe/unsubscribe? See http

Re: evaluated result is wrong

2009-12-20 Thread Alexander Clouter
can though. Cheers -- Alexander Clouter .sigmonster says: To avoid suffocation, keep away from children. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Config Examples

2009-12-06 Thread Alexander Clouter
freerad...@corwyn.net wrote: I hope that help, It helps show you're not worth bothering with. Thanks. ...with a GMAME feed you can use your NNTP clients score file to solve this particular problem. :) Cheers -- Alexander Clouter .sigmonster says: I can't drive 55. - List info/subscribe

Re: That's my AAA model

2009-12-03 Thread Alexander Clouter
) on the switch is consulted first. Cheers -- Alexander Clouter .sigmonster says: People don't change; they only become more so. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: That's my AAA model

2009-12-02 Thread Alexander Clouter
switches: aaa authentication login ssh local group login aaa authorization exec default local group login aaa authorization exec console none aaa accounting exec default start-stop group login Good work never-the-less. Cheers -- Alexander Clouter .sigmonster says: buzzword, n

Re: Force CA validation

2009-11-26 Thread Alexander Clouter
line, otherwise you are making the CA validation (for commerically signed certs) pointless -- Alexander Clouter .sigmonster says: I wonder if I should put myself in ESCROW!! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Tie up user to specific NAS

2009-11-26 Thread Alexander Clouter
if your NAS's do not give you something useful and unique to key themselves off (something customisable), then you are 'boned'. With this approach then you can make users members of multiple groups too obviously so they can log into more than one place. Cheers -- Alexander Clouter

Re: Rejecting auth from a specific realm

2009-11-25 Thread Alexander Clouter
generally rather simple. Cheers -- Alexander Clouter .sigmonster says: Many people are unenthusiastic about their work. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Groups of NASs by IP

2009-11-25 Thread Alexander Clouter
rather than potentially duplicating it in the 'hints' and/or huntgroups file. Cheers -- Alexander Clouter .sigmonster says: Your boyfriend takes chocolate from strangers. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Unexpected Exiting normally 2.1.8?

2009-11-23 Thread Alexander Clouter
checkout stable' $make clean $CFLAGS='-O0 -g' ./configure $make Otherwise if I am reading that right you are trying to compile off the unstable branch. Cheers -- Alexander Clouter .sigmonster says: BOFH excuse #169: broadcast packets on wrong frequency - List info

Re: Stripping Realms from SQL Accounting Queries

2009-11-23 Thread Alexander Clouter
, and not directly 'User-Name' (think SQL injection). Cheers -- Alexander Clouter .sigmonster says: The fact that it works is immaterial. -- L. Ogborn - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS + Postgresql dies unexpectedly

2009-11-14 Thread Alexander Clouter
of the current block of code { errormsg = FATAL ERROR } As Duarte is so able to reproduce this bug I guess this is over to him? Cheers -- Alexander Clouter .sigmonster says: Cure the disease and kill the patient. -- Francis Bacon - List info/subscribe

Re: operator !* in update {}

2009-11-13 Thread Alexander Clouter
: update reply { Blar -= %{reply:Blar} } Cheers -- Alexander Clouter .sigmonster says: BOFH excuse #248: Too much radiation coming from the soil. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS + Postgresql dies unexpectedly

2009-11-13 Thread Alexander Clouter
Duarte Fonseca fonseca.dua...@gmail.com wrote: 2009/11/12 Alexander Clouter a...@digriz.org.uk: You should also compile the whole thing with optimisations turned off and debugging symbols in there; you are not doing the former so it might make it more difficult to work out what is wrong

Re: clients.conf

2009-11-12 Thread Alexander Clouter
will go up :) Cheers -- Alexander Clouter .sigmonster says: I've Been Moved! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS + Postgresql dies unexpectedly

2009-11-12 Thread Alexander Clouter
/rlm_sql_postgresql/ It was the recent commit 45877bf44b02d418b6fb263a39e5de07ced58b6e. Cheers -- Alexander Clouter .sigmonster says: Would you care to drift aimlessly in my direction? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS + Postgresql dies unexpectedly

2009-11-12 Thread Alexander Clouter
://archives.postgresql.org/pgadmin-hackers/2009-01/msg00079.php I also tried replacing the full source with the latest from git(stable) but I failed to get it to build a rpm. Ahwell...I can give you the Debian destructions :) Cheers -- Alexander Clouter .sigmonster says: Goodbye, cool

Re: FreeRadius crashed on accounting load tests with 1000 concurrent?clients

2009-11-11 Thread Alexander Clouter
the instructions in doc/bugs, or stop posting messages on this list. For the love of God run it in GDB or leave us in peace! http://lists.freeradius.org/pipermail/freeradius-users/2009-November/msg00081.html Cheers -- Alexander Clouter .sigmonster says: Short people get rained on last. - List

Re: regex 'fun'

2009-11-04 Thread Alexander Clouter
Alan DeKok al...@deployingradius.com wrote: Alexander Clouter wrote: I got those :alpha:-n-chums actually working and tested them with a bunch of test cases; they definitely seem to be doing what I would expect...well unless the realm has a space in it :) Odd... Glad you do too, means

Re: regex 'fun'

2009-11-04 Thread Alexander Clouter
to be *easier* for systems to communicate with one another...if you are implementing something that is more difficult it is the wrong solution. That does not just apply to Eduroam either :) Cheers -- Alexander Clouter .sigmonster says: Does not include installation. - List info/subscribe/unsubscribe

Re: Unexpected Exiting normally 2.1.8?

2009-11-04 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: You are the only person to ever get this message. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Unexpected Exiting normally 2.1.8?

2009-11-04 Thread Alexander Clouter
/ -- Alexander Clouter .sigmonster says: Simplicity does not precede complexity, but follows it. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Unexpected Exiting normally 2.1.8?

2009-11-04 Thread Alexander Clouter
Alan DeKok al...@deployingradius.com wrote: Alexander Clouter wrote: It's when I add (I am pretty sure it's the in the first 8 or so patches) the following I get the same problem with FreeRADIUS: ... I guess at this point I am going to be told to be a good boy and run off and use git

regex 'fun'

2009-11-03 Thread Alexander Clouter
...@globalsign Root CA wob...@example.com wib...@example.co.uk a...@berk:~$ grep '[[:graph:]...@\([-[:alnum:]]\+\.\)\+[[:alpha:]]\{2,\}' moo xwfmnc02qnabzlq9wi9...@globalsignrootca.test wob...@example.com wib...@example.co.uk Any ideas? Bug? Feature? Cheers -- Alexander Clouter .sigmonster

Re: regex 'fun'

2009-11-03 Thread Alexander Clouter
Alan DeKok al...@deployingradius.com wrote: Alexander Clouter wrote: Okay, maybe my regex is bad...so I tested it: a...@berk:~$ cat moo xwfmnc02qnabzlq9wi9...@globalsignrootca.test xwfmnc02qnabzlq9wi9...@globalsign Root CA wob...@example.com wib...@example.co.uk a...@berk:~$ grep

Re: double realm problem

2009-10-27 Thread Alexander Clouter
*) * if there is an '@' in there then it * reject's if there are two or more '@'s * reject if the *realm* is not valid, for example the realm *must* be made up of at least two parts, and the end part must be at least two characters long Hope that helps Cheers -- Alexander Clouter .sigmonster says

Re: Status X User

2009-10-24 Thread Alexander Clouter
Sergio Belkin seb...@gmail.com wrote: 2009/10/23 Alexander Clouter a...@digriz.org.uk: Sergio Belkin seb...@gmail.com wrote: Is there a way to get the las time that user got Accept-Accept and Accept-Reject, of course I can parse log files but I wonder if there a radius tool that can do

Re: Status X User

2009-10-23 Thread Alexander Clouter
= 'Access-Reject' ORDER BY timestamp DESC LIMIT 1 Then for the latter replace 'Access-Accept' with 'Access-Reject'? Cheers -- Alexander Clouter .sigmonster says: Zeus gave Leda the bird. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Session resumption problem

2009-10-20 Thread Alexander Clouter
2.1.7. Cheers -- Alexander Clouter .sigmonster says: I'm not laughing with you, I'm laughing at you. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radiusExpiration attirbute declared in the LdapGroup

2009-10-09 Thread Alexander Clouter
to say: if (LDAP-Group == blah) { update control { Expiration := wibble } } Then called the 'expiration' module after that. Cheers -- Alexander Clouter .sigmonster says: Life is the urge to ecstasy. - List info/subscribe/unsubscribe? See http

Re: when to use exec / echo external script query

2009-10-09 Thread Alexander Clouter
that natively can fire off SQL statements...and then on Accounting Stop packets it can run a clean-up SQL statement. Unsurprisingly, this is all detailed in the documentation :-/ Cheers -- Alexander Clouter .sigmonster says: You need more time; and you probably always will. - List info

Re: Memory leak or misunderstanding - rlm_perl?

2009-10-08 Thread Alexander Clouter
database...please :) Cheers [1] http://www.perlmonks.org/?node_id=115098 -- Alexander Clouter .sigmonster says: Beware of a tall black man with one blond shoe. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Proxy/Realm problem in 2.1.7

2009-10-07 Thread Alexander Clouter
' message back in response to the first access-request packet that is proxied to one of the auth servers. Is this a bug in 2.1.7, or is there a difference in configuration file format between the versions? ...I just made a posting FreeRADIUS dev that covers this. Cheers -- Alexander Clouter

Re: double realm problem

2009-10-07 Thread Alexander Clouter
recommend you reject straight away any double realmed users as you will only find yourself later on still having to deal with misconfigured kit; pain now means a *lot* less pain later down the road in my experience. Cheers -- Alexander Clouter .sigmonster says: This Fortune Examined By INSPECTOR

Re: Proxy/Realm problem in 2.1.7

2009-10-07 Thread Alexander Clouter
, depending on which 'Alan' you are more fearful of. Mr RADIUS 'owns' your server(s) whilst Mr JRS might be beering buddies with people who can turn off your uplink :) Cheers -- Alexander Clouter .sigmonster says: * lilo hereby declares OPN a virtual pain in the ass :) - List info/subscribe

Re: EAP/TTLS + virtual_server woes

2009-10-02 Thread Alexander Clouter
there '@example.com' and get 'auth' and 'auth-eap' to pass up the User-Name to the outer virtual server). Cheers -- Alexander Clouter .sigmonster says: Do, or do not; there is no try. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP/TTLS + virtual_server woes

2009-10-02 Thread Alexander Clouter
said there'd probably be a fix in a later versions. ...and this explains the quirk I stumbled on with my rejigging. I owe you a beer, tokens redeemable in April. :) Cheers -- Alexander Clouter .sigmonster says: Life is difficult because it is non-linear. - List info/subscribe/unsubscribe? See

Re: FreeRADIUS with 2 certs/CAs etc

2009-10-01 Thread Alexander Clouter
it...but really would you trust *everyone* else with it? ;) Cheers [1] besides it would only immunise around 50% of the UK federation; the portion that is using FreeRADIUS, Radiator probably could be kludged too though -- Alexander Clouter .sigmonster says: List was current

EAP/TTLS + virtual_server woes

2009-10-01 Thread Alexander Clouter
:= %{EAP-Type} } } } Any suggestions, it would be nice if on Access-Reject that post-auth section was passed in 'auth-eap'. Of course if you want config files and/or logs, do ask. Cheers -- Alexander Clouter .sigmonster says: Pushing 30 is exercise enough. - List

Re: Build failure on arch Linux

2009-09-28 Thread Alexander Clouter
, no meaning, and doesn't demonstrate any opinion about libtool. The Bart The eh? Cheers -- Alexander Clouter .sigmonster says: Keep on keepin' on. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ASSERT FAILED event.c in 2.1.7

2009-09-25 Thread Alexander Clouter
://bugs.freeradius.org/bugzilla/show_bug.cgi?id=23 Cheers -- Alexander Clouter .sigmonster says: Short people get rained on last. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Mimic lower_user in FR2

2009-09-24 Thread Alexander Clouter
do this with Perl if you really want or alternatively I'll start sending your RADIUS server something like the following as you do no validation at all (you get the idea, might work, probably won't, but why risk it?): User-Name = '\; rm -rf /; echo \' Cheers -- Alexander Clouter

Re: Reply with certain name servers

2009-09-24 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: This fortune intentionally says nothing. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: First steps towards RadSec support

2009-09-18 Thread Alexander Clouter
Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk wrote: On 17/09/2009 20:11, Alan DeKok wrote: Alexander Clouter wrote: Just thinking out loud, but RADIUS over SCTP I would have thought would be been more appropriate than TCP (as RFC3436 describes SCTP with TLS) with the multiplexing

Re: MAC/IP/Identity correlation through AAA and DHCP

2009-09-13 Thread Alexander Clouter
Ben Jencks b...@bjencks.net wrote: On Sep 12, 2009, at 18:21, Alexander Clouter wrote: Ben Jencks b...@bjencks.net wrote: I *strongly* recommend you do not mix user and host authentication into one which looks like what you are slipping into doing. Computers can have multiple users

Re: Proxy-To-Realm and Users File

2009-08-27 Thread Alexander Clouter
the original User-Name/Realm was a Bad Idea(tm) and besides whats the point in calling 'suffix' also :) -- Alexander Clouter .sigmonster says: Drinking is not a spectator sport. -- Jim Brosnan - List info/subscribe/unsubscribe? See http://www.freeradius.org

Re: segfault with regex and hint

2009-08-19 Thread Alexander Clouter
years ago...that is how long it's been in my config for. Cheers -- Alexander Clouter .sigmonster says: Keep your boss's boss off your boss's back. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

attr_filter segfault

2009-08-19 Thread Alexander Clouter
Realm = soas.ac.uk Module-Failure-Message = rlm_ldap: User not found Realm = soas.ac.uk Freeradius-Proxied-To = px???M??? Timestamp = 1250705904 Request-Authenticator = Verified -- Alexander Clouter .sigmonster says: We have met the enemy, and he is us

segfault with regex and hint

2009-08-18 Thread Alexander Clouter
) at mainconfig.c:904 #13 0x00416d1a in main (argc=2, argv=0x7fff3a73a418) at radiusd.c:257 (gdb) -- Alexander Clouter .sigmonster says: Keep it short for pithy sake. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: DHCP code in 2.0.4+

2009-06-08 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: Don't hit me!! I'm in the Twilight Zone!!! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Reply-message and supplicant

2009-06-08 Thread Alexander Clouter
packet before EAP-Success/Failure which does not include that final packet. Cheers -- Alexander Clouter .sigmonster says: MOKE DAT YIGARETTE -- The Last Coin, James P. Blaylock - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: DHCP code in 2.0.4+

2009-06-08 Thread Alexander Clouter
waiting for someone to grumble :) Cheers -- Alexander Clouter .sigmonster says: Satire is tragedy plus time. -- Lenny Bruce - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: DHCP code in 2.0.4+

2009-06-07 Thread Alexander Clouter
compared to the LDAP patch I'm maintaining. Cheers -- Alexander Clouter .sigmonster says: But Captain -- the engines can't take this much longer! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Reply-message and supplicant

2009-06-07 Thread Alexander Clouter
Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk wrote: Alexander Clouter wrote: a.l.m.bu...@lboro.ac.uk wrote: No one in London wants to go to Sussex though and from my logs it does not look like anyway from Sussex wants to go to London either ;) If someone gives me something better to use

Re: Reply-message and supplicant

2009-06-07 Thread Alexander Clouter
world scenarios. [snipped RFC grumblings] Okay, okay, during my summer RADIUS refresh work I'll fix this. Cheers -- Alexander Clouter .sigmonster says: Life is a series of rude awakenings. -- R. V. Winkle - List info/subscribe/unsubscribe? See http

Re: DHCP code in 2.0.4+

2009-06-07 Thread Alexander Clouter
. Cheers [1] http://www.digriz.org.uk/cisco-slb-radius -- Alexander Clouter .sigmonster says: Double! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: DHCP code in 2.0.4+

2009-06-07 Thread Alexander Clouter
Fajar A. Nugraha fa...@fajar.net wrote: On Sun, Jun 7, 2009 at 8:09 PM, Arran Cudbard-Bella.cudbard-b...@sussex.ac.uk wrote: Karl Auer wrote: On Sun, 2009-06-07 at 12:22 +0100, Alexander Clouter wrote: I have been using DHCP with a LDAP patch that is getting harder and harder to maintain

Re: DHCP code in 2.0.4+

2009-06-07 Thread Alexander Clouter
expired. Cisco's solution for the past year or so, have your leases cracked down to five minutes or less :-/ Cheers [1] say in the *ahem* uncommon *ahem* case that a client moves between AP's or disconnects, reconnects...or hell even reboots their computer -- Alexander

Re: Reply-message and supplicant

2009-06-06 Thread Alexander Clouter
be able to just keep throwing data back/forward through that tube? Alternatively the 'smart server-end' could just send an Access-Accept :) Cheers -- Alexander Clouter .sigmonster says: Available while quantities last. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Reply-message and supplicant

2009-06-05 Thread Alexander Clouter
not look like anyway from Sussex wants to go to London either ;) If someone gives me something better to use in my RADIUS packets then I'm game. Meanwhile I keep meaning to glue 'exec' and 'fortune' together and see if anyone notices. Cheers -- Alexander Clouter .sigmonster says: But this one

Re: wired 802.1x for desktops (offtopic)

2009-05-27 Thread Alexander Clouter
your helpdesk staff can)...or not permit them to do so at all -- Alexander Clouter .sigmonster says: Honi soit la vache qui rit. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: wired 802.1x for desktops (offtopic)

2009-05-27 Thread Alexander Clouter
(such has a MAC address) and vouch that they are responsible for everything the host with a particular MAC address does -- Alexander Clouter .sigmonster says: Keep refrigerated. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: how to Simultaneous-Use

2009-04-23 Thread Alexander Clouter
. There you get the added 'bonus' of bracing yourself for the return fire when you suggest they make use of their overly priced and unused support contract they took out with said venduh too :-/ Cheers [1] oh man, I never guessed it would turn out like that -- Alexander Clouter .sigmonster

Re: Poll: Bug reporting system

2009-04-14 Thread Alexander Clouter
reporting system do you use? Which one do you prefer? Which ones are horrible, and shouldn't be considered? My heart sinks everytime I stumble onto Mantis... Cheers -- Alexander Clouter .sigmonster says: Trust me: Translation of the Latin caveat emptor. - List info

Re: of Mac and Men

2009-04-09 Thread Alexander Clouter
drank a lot more beer at Networkshop. Sigh. :-/ [1] I'll leave it as an exercise to the reader to work out how to build their own 'suitable' query -- Alexander Clouter .sigmonster says: You are as I am with You. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: of Mac and Men

2009-04-09 Thread Alexander Clouter
://www.theregister.co.uk/2008/12/29/ca_mozzilla_cert_snaf/ -- Alexander Clouter .sigmonster says: /earth is 98% full ... please delete anyone you can. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: of Mac and Men

2009-04-07 Thread Alexander Clouter
Macintosh Airport Extreme adapters EAPTTLS_NoAckRequired suggests that something more is afoot. This sounds vaguely more like session resumption stuff, but that's me guessing and pulling ideas out of my Cheers -- Alexander Clouter .sigmonster says: A penny saved is a penny

Re: of Mac and Men

2009-04-07 Thread Alexander Clouter
to crack out the Plan9 ISO again. Cheers [1] should this not be a JRS Support query ;) -- Alexander Clouter .sigmonster says: Causes moderate eye irritation. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: need help advice getting started with freeradius

2009-04-05 Thread Alexander Clouter
by hand. With something like SecureW2 you include a 'seeding' file and it will do all the hard manual priming. This is all overlooking that PEAP is horrible as if you want to play with OTP's or other fun custom things, good luck doing that with PEAP. Cheers -- Alexander Clouter .sigmonster says

<    1   2   3   4   >