How does one keep monthly download limits

2004-01-23 Thread ripunjay
Hi, i have been trying with perl scripts to limit the download my users can do per month, but i'm facing regular problems that a user logs in at 10:00am in the morning and has about 1mb worth of downloads left he is connected at 128Kbps which will require about just over a minute to finish his

0.9.3 LDAP problem

2004-01-23 Thread andy-freeradius
I've got an older version of freeradius successfully authenticating off of our Novell NDS via LDAP. I'm doing some testing with 0.9.3 and having problems. On the LDAP server it doesn't even look like it is receiving the query. I've even tried this without the SSL and on the standard port. I've a

Multiple LDAP instances, realms and enforcing group membership

2004-01-23 Thread Kevin M. Myer
Hello, I have a LDAP directory server, with users and groups stored in domain component trees. For authentication credentials, I'm having users supply their email address and using the domain to determine the realm. In my "users" file, I have a bunch of DEFAULT entries that use the realm to set

Re: Setting up monthly time limits

2004-01-23 Thread Chris Parker
At 01:33 PM 1/23/2004, Lisa Casey wrote: Hi, I'm using Free Radius and need to set up monthly time limits of 200 hours/month/user. I have read rlm_counter in radiusd.conf, and even though I'm not sure how well I understand this, I've proceeded to try to set it up. Here's what I've done. In radiusd

Re: radacct table question

2004-01-23 Thread Alan DeKok
Bartosz Jozwiak" <[EMAIL PROTECTED]> wrote: > Could you please tell me where I should put it ? > I am new to radius thats why Buy the RADIUS book. Read http://www.freeradius.org/rfc/attributes.html Click on "Accounting-Request" Alan DeKok. - List info/subscribe/unsubscribe? See ht

Setting up monthly time limits

2004-01-23 Thread Lisa Casey
Hi, I'm using Free Radius and need to set up monthly time limits of 200 hours/month/user. I have read rlm_counter in radiusd.conf, and even though I'm not sure how well I understand this, I've proceeded to try to set it up. Here's what I've done. In radiusd.conf: counter monthly { filename =

Execute Program after logout

2004-01-23 Thread Claudiney Resende Costa
how I excute a script in logout?  

Re: radacct table question

2004-01-23 Thread Bartosz Jozwiak
Could you please tell me where I should put it ? I am new to radius thats why > "Bartosz Jozwiak" <[EMAIL PROTECTED]> wrote: > > FreeRadius is working, I put one user in mysql database and I get > > authentication. But I do not see update in radacct in mysql database. Can > > somebody tell m

Re: radacct table question

2004-01-23 Thread Alan DeKok
"Bartosz Jozwiak" <[EMAIL PROTECTED]> wrote: > FreeRadius is working, I put one user in mysql database and I get > authentication. But I do not see update in radacct in mysql database. Can > somebody tell my who ? authentication != accounting Send it accounting packets, and they will be logge

radacct table question

2004-01-23 Thread Bartosz Jozwiak
Hello everyone, I would like to say on start that I am new to FreeRadius and also new to this mailing list. I have set up my FreeRadius server with MySql using HOWTO ( http://www.frontios.com/freeradius.html ) FreeRadius is working, I put one user in mysql database and I get authentication. But I

Repost: mysql+groups+huntgroups

2004-01-23 Thread Marius Onica
Hi! I'm reposting my own message since nobody answered it. Unfortunately my problems remain unsolve. Maybe now I'll be more lucky. TIA, Marius > > I'm new to freeradius and I'm trying to implement groups in huntgroups. > I'm using freeradius 0.93 with mysql. I must note that user authorization >

Re: Exec-Program problem..

2004-01-23 Thread Andrei Loukinykh
Fri, 23 Jan 2004, Alan DeKok писал(а): > Andrei Loukinykh <[EMAIL PROTECTED]> wrote: > > So I started FR as root:daemon and gave the same own's to the program. > > Still the same. > > May be FR changes effective uid/gid for the external program it runs...? > > No. > > Can you say what platf

Re: Binary for Win2K Server

2004-01-23 Thread A. Clausen
- Original Message - From: "Martin Nicholls" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, January 23, 2004 02:45 Subject: Binary for Win2K Server > Does anyone have a Win 2K server binary for 0.9.3 they could point me to. I would like that too, or at least the source patch

Re: Help on EAP - MS-CHAP (fwd)

2004-01-23 Thread Alan DeKok
[EMAIL PROTECTED] wrote: >I was thinking about eap/tls but it looks very complicated to me, > because it need's to install certificates on the client (can this be > ommited?). Yes. Use EAP-TTLS, or EAP-PEAP. >Then there is the eap ms-chap authentification. But I have no idea how > to c

Re: rlm_pap: No password (or empty password) to check against for for user

2004-01-23 Thread Alan DeKok
Hans Bornemann <[EMAIL PROTECTED]> wrote: > please help. I can't find the failure: > > Pap with md5 dont work. What does it mean: > rlm_pap: No password (or empty password) to check against for for user > testomat It means that the server needs a clear-text password to do EAP-MD5 authenticatio

Re: multiple module lookups when only one should be used

2004-01-23 Thread Alan DeKok
Mike Sturdee <[EMAIL PROTECTED]> wrote: > Has anything come of this yet? Nope. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Exec-Program problem..

2004-01-23 Thread Alan DeKok
Andrei Loukinykh <[EMAIL PROTECTED]> wrote: > So I started FR as root:daemon and gave the same own's to the program. > Still the same. > May be FR changes effective uid/gid for the external program it runs...? No. Can you say what platform you're running on? Alan DeKok. - List info/subs

Re: 802.1x: PEAP + MS-CHAPv2

2004-01-23 Thread Alan DeKok
Christian Richter <[EMAIL PROTECTED]> wrote: > I have tested the provided configuration, but something goes wrong... The server is telling you what you're doing wrong. Read the ouput you posted to the list. > My Radius is starting the Challenge but not more If you would *continue* watc

Re: Sanity check for proxy setup

2004-01-23 Thread Alan DeKok
"john zurowski" <[EMAIL PROTECTED]> wrote" > Do I have to create a realm target{...} entry in the radiusd.conf file or > will the suffix entry handle all realms using suffixes ? The suffix entry will handle all realms using suffixes. Alan DeKok. - List info/subscribe/unsubscribe? See http:

Re: 802.1x: PEAP + MS-CHAPv2

2004-01-23 Thread Alan DeKok
Christian Richter <[EMAIL PROTECTED]> wrote: > Wich Auth-Type need to be set then, EAP? I could swear I said to NOT set Auth-Type... Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Initial Installation glitch

2004-01-23 Thread Alan DeKok
"Frank Philip" <[EMAIL PROTECTED]> wrote: > I installed the RADIUS server I started it under debug mode and it ends > up saying "Ready to process request". But when I open another terminal > and use radtest, it says server not responding and I don't seem to get > any feedback from the server itself

Help on EAP - MS-CHAP (fwd)

2004-01-23 Thread zip
Hello! Please, help me to begin. I'm quite new to configuring radius. I need to make a AP hot spot for wireless users on our school. And for some visitors too. I was thinking about eap/tls but it looks very complicated to me, because it need's to install certificates on the client (can this

rlm_pap: No password (or empty password) to check against for for user

2004-01-23 Thread Hans Bornemann
Hi, please help. I can't find the failure: Pap with md5 dont work. What does it mean: rlm_pap: No password (or empty password) to check against for for user testomat modcall[authenticate]: module "pap" returns invalid for request 1 --- users

Re: multiple module lookups when only one should be used

2004-01-23 Thread Mike Sturdee
Has anything come of this yet? On Wed, 14 Jan 2004, Alan DeKok wrote: > Chris Parker <[EMAIL PROTECTED]> wrote: > > > I'm open to suggestions for what to do with the "authorize" section > > >and Autz-Type. I don't want to break older configurations, so that's > > >a bit of a constraint. > > >

Re: Exec-Program problem..

2004-01-23 Thread Andrei Loukinykh
Fri, 23 Jan 2004, Albert Miles Enabe писал(а): > In my Linux box, my radiusd starts up as a daemon, so I did this: > > chown daemon:root setexpiredate > > where setexpiredate is an external C program specified in Exec-Program > in radiusd.conf. May be it's stupid, but I tried to run FR as roo

Re: Exec-Program problem..

2004-01-23 Thread Albert Miles Enabe
>Thu, 22 Jan 2004, Alan DeKok ÐÉÓÁÌ(Á): > > > Andrei Loukinykh <[EMAIL PROTECTED]> wrote: > > > I'm trying to get my external program to work ( which is in fact - > > > a billing program for users' accounting) > > > > Which version are you using? If you're not using 0.9.3, upgrade to > > i

Re: 802.1x: PEAP + MS-CHAPv2

2004-01-23 Thread Eugene Kandlen
My config works fine. Do you config also work for the integrated Windows supplicant? (No use of Aegis) If you don't know, can you please test it... WinXP with internal supplicant autenticating, but in few seconds (10 icmp requests replyed...) it report that link is unavailable and authenticate

Binary for Win2K Server

2004-01-23 Thread Martin Nicholls
Does anyone have a Win 2K server binary for 0.9.3 they could point me to.   Thanks, Martin 

Re: 802.1x: PEAP + MS-CHAPv2

2004-01-23 Thread Christian Richter
I have tested the provided configuration, but something goes wrong... My Radius is starting the Challenge but not more I trying the two default EAP types: md5 and tls (suggested by Brian Clarkson). As additional information i provide an etherreal capture (only the informations) from the Call

Sanity check for proxy setup

2004-01-23 Thread john zurowski
This is the first time I've setup up proxy settings and just wanted confirmation that what I'm doing is right. Have looked at docs + mail archive for info. but still not clear in one aspect. in radiusd.conf have the realm suffix { .. } setup + added "suffix" to preacct{} and authorize{} sect

Re: Problem with EAP/TLS : OK

2004-01-23 Thread Jean-Paul Chapalain
Alan, Thanks so much, everythings fine now when usercollide is set to 'no'. Jean-Paul. smime.p7s Description: S/MIME Cryptographic Signature

Identity spoofing using eap-tls

2004-01-23 Thread Gunter Burchardt
Hello, When you use authentication via eap-tls it is possible to send user-names in radius which didn't match the user-name in the client-certificate. In such a case the user gets authenticated with a wrong user-name. Accouting information will be saved with a wrong user-name. Someone can spoof