RE: Free Radius and non-plain text passwords (resolution)

2004-01-06 Thread Phillip Ames
OK, another 6 hours of digging and putzing have given me what I want (although not necessarily the way I originally wanted), and I figured I'd post it here for posterity (and hopefully so it'll be indexed by Google in case anyone else is looking to do the same). I couldn't get it to work with rlm_

Re: freeradius and mschap2 problem

2004-01-06 Thread Alan DeKok
Chet McNeill <[EMAIL PROTECTED]> wrote: > I have liberally spread DEBUG2 statements throughout the freeradius > rlm_mschap module to verify that the correct data is being sent by PPPd > and received by freeradius. I extracted the MD4 hashing algorithms from > PPPd and freeradius and compared their

Re: Settings

2004-01-06 Thread Alan DeKok
"Kirti S. Bajwa" <[EMAIL PROTECTED]> wrote: > Max_request setting in "radius.conf" is supposed to be the maximum number of > requests which the server keeps track of. It is supposed to be 4 * number of > clients. That's a guideline. The documentation for that setting says you can set it to larg

Freeradius 0.93 with MySQL configuration

2004-01-06 Thread Peter Morgan
I'm trying to setup the MySQL functionality with freeradius version 0.93, but i do not understand what i should put in the 'radreply' or 'radgroupreply' tables. I honestly do not understand what I need to in order to do this, but the tutorial that i followed ( http://www.frontios.com/freeradius.ht

Re: freeradius and mschap2 problem

2004-01-06 Thread Chet McNeill
I have been investigating the problem with MSCHAPv2 passwords as well. I can set up PPPd (2.4.2 from CVS, current as of 1/4/2004) to locally authenticate a windows (2000, XP) machine via MSCHAPv2. However, if I tell PPPD to forward to freeradius, freeradius creates an incorrect hash and denies ac

Solaries Binaries?

2004-01-06 Thread Shawn Ramsey
Our solaris box (Intel) is having problems compiling for some reason... in general, basically nothing will compile. Does anyone have Solaris 9 X86 they would share? Older Solaris binaries will work though if anyone is running an older Solaris.   TIA  

Free Radius and non-plain text passwords

2004-01-06 Thread Phillip Ames
Hi everybody, I've been poring over the FAQ, archives, config files, and Google for quite some time and have yet to uncover an answer to my problem (which I would _think_ is quite common so I have a feeling I'm missing a glaringly obvious fact). Anyway, to the point: I have been able to get Free

RE: Settings

2004-01-06 Thread Kirti S. Bajwa
Alan: Thanks for your response. I am quite sure you know the answer and I appreciate your help. I will try to clarify my question: Max_request setting in "radius.conf" is supposed to be the maximum number of requests which the server keeps track of. It is supposed to be 4 * number of clients. In

BUG?? Couldn't open syslog/radius.log for logging: Not a directory

2004-01-06 Thread Christopher D. Kotran
OS: RH9.0 Platform: i386 FreeRadius Version: 0.9.3 Problem Summary: radiusd: radiusd: Couldn't open syslog/radius.log for logging: Not a directory Problem Detials: It appears that freeradius is attempting to log to a file when asked to to log to the syslog. Listed below is the config settings an

Re: Settings

2004-01-06 Thread Alan DeKok
"Kirti S. Bajwa" <[EMAIL PROTECTED]> wrote: > As I have said, I have read the book about 5 times and there are > several references to "clients" applicable to the subject being > discussed. Ok.. > Please read my question again & if you know the answer, then, please let me > know. The problem

RE: Settings

2004-01-06 Thread Vincent_Giovannone
[EMAIL PROTECTED] wrote on 01/06/2004 11:42:41 AM: > Yes clients are mention all over the book but there is a definition on Page > 3, which states: > > "When discussing AAA and RADIUS, the terms "clients" and "server" often > comes up. However, there can be some confusion about which of these

RE: Settings

2004-01-06 Thread Kirti S. Bajwa
Yes clients are mention all over the book but there is a definition on Page 3, which states: "When discussing AAA and RADIUS, the terms "clients" and "server" often comes up. However, there can be some confusion about which of these roles a particular machine is playing..". Please read the entire

Re: Settings

2004-01-06 Thread Alan DeKok
"Kirti S. Bajwa" <[EMAIL PROTECTED]> wrote: > I have the RADIUS book from O'Rilley & I am reading it. I have read the book > about 5-times. If the answer is in the book, kindly point me to the page > number. I will really appreciate it. I don't have the book in front of me, but it definitely dis

RE: Settings

2004-01-06 Thread Vincent_Giovannone
[EMAIL PROTECTED] wrote on 01/06/2004 11:22:29 AM: > I have the RADIUS book from O'Rilley & I am reading it. I have read the book > about 5-times. If the answer is in the book, kindly point me to the page > number. I will really appreciate it. You must be reading the book in sandscrit, because

RE: Settings

2004-01-06 Thread Kirti S. Bajwa
I have the RADIUS book from O'Rilley & I am reading it. I have read the book about 5-times. If the answer is in the book, kindly point me to the page number. I will really appreciate it. Thanks. Kirti -Original Message- From: Alan DeKok [mailto:[EMAIL PROTECTED] Sent: Tuesday, January 06

Re: Settings

2004-01-06 Thread Alan DeKok
"Kirti S. Bajwa" <[EMAIL PROTECTED]> wrote: > I am a newbie to freeRADIUS. This is my first attempt to setup. I am > updating/setting "radius.conf" file. One question: > > What is RADIUS Clients? Buy the RADIUS book. If you don't know what RADIUS clients are, I don't think you need a RADIUS

Re: Session ID vs Acct-Session-ID

2004-01-06 Thread Alan DeKok
"Casey Boone" <[EMAIL PROTECTED]> wrote: > I am trying to figure out how those two session ids relate, as they should > be the same value. Really? Does the documentation from your NAS vendor say that? > Im just not certain how to read the one recorded in the radius > server's logs. Read the

Re: [apache-radius] authserver per .htaccess

2004-01-06 Thread richard lucassen
On Tue, 6 Jan 2004 10:54:29 +0100 (CET) Geller Sandor <[EMAIL PROTECTED]> wrote: > > I have an Apache server using radius authentication. This works very > > well. But is it possible to have a radius server mentioned in the > > .htaccess file rather than the systemwide httpd.conf? > > This is an

Re: CISCO PIX and RADIUS

2004-01-06 Thread Oliver Graf
On Tue, Jan 06, 2004 at 05:56:41PM +0100, Ing. Milan Cygal wrote: > Does CISCO PIX support a RADIUS authorization? > >From command reference of "aaa": > authorization - Enable or disable TACACS+ user authorization for services (PIX > Firewall does not support RADIUS authorization). Did you try t

Session ID vs Acct-Session-ID

2004-01-06 Thread Casey Boone
In my radius server's radacct.log I have this: Acct-Session-Id = "\xc3a\xf2y\x00\x01\xa5\x88" In the logs in my RAS that corresponds with: sessionID: 0001A318 I am trying to figure out how those two session ids relate, as they should be the same value. Im just not certain how to read the one r

CISCO PIX and RADIUS

2004-01-06 Thread Ing. Milan Cygal
Does CISCO PIX support a RADIUS authorization? >From command reference of "aaa": authorization - Enable or disable TACACS+ user authorization for services (PIX Firewall does not support RADIUS authorization). Thanks Milan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/us

CISCO PIX and RADIUS

2004-01-06 Thread Ing. Milan Cygal
Does CISCO PIX support a RADIUS authorization? >From command reference of "aaa": authorization - Enable or disable TACACS+ user authorization for services (PIX Firewall does not support RADIUS authorization). Thanks Milan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/us

RE: Settings

2004-01-06 Thread Kirti S. Bajwa
Please clarify NAS devices!!! I am using 3Com TC box. Is it 1-device therefore the max_requests = 1 * 256 ( = 256 )? or Is it number of Dial-up lines on a 3Com box. In my case it is 3 T1 Lines therefore max_requests = 3 * 256 ( = 768 ) Thanks. Kirti -Original Message- From: Cris Bois

RE: Settings

2004-01-06 Thread Cris Boisvert
Clients would be Nas Devices .. Such as portmasters if you have dialup pool -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kirti S. Bajwa Sent: Tuesday, January 06, 2004 11:28 AM To: '[EMAIL PROTECTED]' Subject: RE: Settings Hello List: I am a newbi

RE: Settings

2004-01-06 Thread Kirti S. Bajwa
Hello List: I am a newbie to freeRADIUS. This is my first attempt to setup. I am updating/setting "radius.conf" file. One question: What is RADIUS Clients? Is it number of users which will be dialing up and will be processed by the RADIUS server or is it the number of NAS Clients connected serv

Re: Proxy Authentication.....

2004-01-06 Thread Alan DeKok
"Callum" <[EMAIL PROTECTED]> wrote: > However no matter where I place the Proxy-To-Realm, it does not > seem to work I don't see why. Test it with the "users" file first, and then move the configuration entry to SQL. See examples in the list archive for what to do. Alan DeKok. - List in

Re: CA.all script failing

2004-01-06 Thread Jean-Paul Chapalain
This thing happens when certificates share common data. You cannot have two certificates that look otherwise the same. You have the same thing in the server's certificate and the client's certificate. You can use a different "Common Name". (don't use commonName_default in openssl.cnf) Jean-Pau

Re: LDAP with Multiple Frame-Route

2004-01-06 Thread Kostas Kalevras
On Tue, 6 Jan 2004, Wichit Ngamsomhan wrote: > I've fixed this problem like below, > --- > radiusReplyItem: Framed-Route+="192.168.0.1/24 192.168.2.1 1" > radiusReplyItem: Framed-Route+="192.168.1.1/24 192.168.2.1 1" > --- > Any idea? Use either: 1. The solution you proposed 2. radiusFrameRoute

Re: Adding new data to Dialup-Admin interface/sql

2004-01-06 Thread Kostas Kalevras
On Tue, 6 Jan 2004, Ben Johns wrote: > Hi folks, > > I'm attempting to add a new row to the userinfo table in mysql. The row is > basically used to store a number value representing a download quota for > each user. > > I've been chasing my tail for a while now and was wondering if anyone had > a

Re: [apache-radius] authserver per .htaccess

2004-01-06 Thread richard lucassen
On Tue, 6 Jan 2004 10:54:29 +0100 (CET) Geller Sandor <[EMAIL PROTECTED]> wrote: > > I have an Apache server using radius authentication. This works very > > well. But is it possible to have a radius server mentioned in the > > .htaccess file rather than the systemwide httpd.conf? > > This is an

Re: [apache-radius] authserver per .htaccess

2004-01-06 Thread Geller Sandor
On Tue, 6 Jan 2004, richard lucassen wrote: > Hello list, > > I have an Apache server using radius authentication. This works very > well. But is it possible to have a radius server mentioned in the > .htaccess file rather than the systemwide httpd.conf? This is an apache question. See 'AllowOver

[apache-radius] authserver per .htaccess

2004-01-06 Thread richard lucassen
Hello list, I have an Apache server using radius authentication. This works very well. But is it possible to have a radius server mentioned in the .htaccess file rather than the systemwide httpd.conf? I'd like to have /var/www/html/dir_a/ authenticate to server_a /var/www/html/dir_b/ authentica

Usr Netserver 16 V34 + FreeRadius

2004-01-06 Thread Andrei Loukinykh
Hello ppl If anyone has a working combination of USR Netserver 16 V34 Plus + FreeRadius - please, post here or send me - what version of firmware (Netserver) and radius' conf. files if possible. I just cant make dialup user on Netserver disconnect...I need it for my billing Andrei V.