Re: redundant LDAP server with free-radius

2007-02-02 Thread Alexei Monastyrnyi
, I can probably update it by adding ~200-300 bytes of text and in case you won't like it, you can always roll back. A. on 2/1/2007 4:55 PM Alan DeKok wrote: Alexei Monastyrnyi wrote: this works as expected, though it is not that obvious that Auth-Type name refers to module name

redundant LDAP server with free-radius

2007-02-01 Thread Alexei Monastyrnyi
Folks, sorry for bringing this up again. I am running FreeRADIUS 1.1.4 and OpenLDAP 2.3.32 on two Solaris10/x86 hosts. Non-redundant config works fine with FreeRADIUS and OpenLDAP on a single host. modules { ldap { } } authorize { ... ldap } authenticate { ...

Re: redundant LDAP server with free-radius

2007-02-01 Thread Alexei Monastyrnyi
that enough? A. Alexei Monastyrnyi wrote: / When I use a redundant config as per instruction in docs, I have the // auth: No authenticate method (Auth-Type) configuration found for the // request: Rejecting the user in debugs and user is rejected. Please see // config and debug output below. I

Re: redundant LDAP server with free-radius

2007-02-01 Thread Alexei Monastyrnyi
-02 { ds-02 } } on 2/1/2007 4:04 PM Alan DeKok wrote: Alexei Monastyrnyi wrote: But I do define it when switching from singe server to redundant group, don't I? Yes. Isn't that enough? What did my previous response say? You can argue

Re: groupmembership_filter for LDAP module [sec: unclas]

2006-08-22 Thread Alexei Monastyrnyi
AM Ranner, Frank MR wrote: -Original Message- From: [EMAIL PROTECTED] g [mailto:[EMAIL PROTECTED] adius.org] On Behalf Of Alexei Monastyrnyi Sent: Tuesday, 22 August 2006 07:12 To: FreeRadius users mailing list Subject: groupmembership_filter for LDAP module Hi List. I am trying to enable

groupmembership_filter for LDAP module

2006-08-21 Thread Alexei Monastyrnyi
Hi List. I am trying to enable group filter to allow only certain LDAP users to be able to login to my VPN hub. I run FreeRADIUS 1.0.2 on SPARC Solaris 9 All users are in group cn=vpnusers,ou=group,dc=mydomain,dc=com listed as memberUids In radiusd.conf I have the following filter =

Re: special characters in passwords + FR + ldap

2006-03-06 Thread Alexei Monastyrnyi
22:19 Natalia Escalera wrote: Hello, What is needed is that Freeradius accepts passwors even if special charaters are part of them. This is what is happening: pass$word - FR - LDAP - FR (Answer: wrong password) Any ideas of how to solve it? Thank you, Natalia. On 3/3/06, Alexei

Re: special characters in passwords + FR + ldap

2006-03-03 Thread Alexei Monastyrnyi
Hey. Does one need to handle it in any special way? I have deployment like this, where special chars work as good as normal ones. Cisco VPN clients - Cisco PIX - FreeRADIUS - OpenLDAP. A. on 03/03/2006 00:28 Natalia Escalera wrote: Hello all, Do somebody know how to handle passwords

rlm_eap_tls.so is missing

2006-03-02 Thread Alexei Monastyrnyi
Hi List! This might be off-topic but I couldn't find any solution so far. I am running FreeRADIUS 1.1.0 on Solaris 9 (SPARC) and cannot get it configured with PEAP support. Both FreeRADIUS and OpenSSL 0.9.8 are built from sources with no errors or warnings. When I start radiusd with PEAP

FreeRADIUS + MPPE for PPTP VPN clients

2005-06-03 Thread Alexei Monastyrnyi
Hi List. I have a Q about MS-CHAP and MPPE configuration for FreeRADIUS. OS and software versions Servers OS Solaris 9 SPARC FreeRADIUS 1.0.2 OpenLDAP 2.2.24 SAMBA 3.0.11 Network gateways Cisco PIX 506, IOS 6.3(4) PPTP VPN Clients Windows 2K/XP, MAC OSX. The RADIUS server we're talking

Re: Configuring maximum number of password attempts

2005-06-03 Thread Alexei Monastyrnyi
Hi. From FreeRADIUS debug I can conclude that if first does search against LDAP with given username and base DN and then, if the search is successful, binds with given credentials. Both posixAccount and shadowAccount in LDAP does not have any attributes to count bad passwords and block users

Re: FreeRadius documentation

2005-06-02 Thread Alexei Monastyrnyi
Hi. There is a bit of info here, which is pretty much in correlation with O'Reilly book RADIUS. http://www.tldp.org/HOWTO/LDAP-Implementation-HOWTO/radius.html The book helped me a lot with configuring simple auth via RADIUS against LDAP userPassword attribute. I'm trying now to find now

Re: Filter

2005-05-31 Thread Alexei Monastyrnyi
Hi. Filter here is a usual LDAP filter, you can find some good examples in OpenLDAP documentation or man pages. Or you can check here. http://www.zytrax.com/books/ldap/apa/search.html The complete RFC for this is # 2254. A. José Berenguer wrote: Hello, Anyone can tell me where can I