"Tom Rixom" <[EMAIL PROTECTED]> wrote:
> I am using a debugged version of our SecureW2 Client v2.0.0 and I am
> seeing the double EAP-Mesage just after decryption so that means it
> must have been sent by the FreeRadius server. Even the MAC checks
> out.

  Ok.  Is the first EAP-Message a duplicate of a previous one?  If so,
we know at that point, the "tunnel data" buffer isn't being flushed.

> You are saying the Aegis Client did not pick this up?

  <g>  It looks that way.  Maybe the Aegis client didn't even get the
duplicatee EAP-Messages, because it's interaction with the server is
different.

> I can get the SecureW2 v2.0.0 client to work but then I need to ignore
> the incorrect padding...

  That should be easy to fix.  The "vp2diameter" code prints the "TTLS
tunnel data out", so you should see if the extra data is there, or is
added elsewhere.

> I want to do the same with freeradius as this is another radius server
> frequently used by our customers.

  I agree.  I'd like to see it fixed, too.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to