RE: RADIUS book from O'Reilly

2002-08-01 Thread De Yong, Doug
Title: RE: RADIUS book from O'Reilly





well it seems you might have to wait for the O'Reilly book


hey I've been to Rush../doug


Doug De Yong, CISSP, ESSE#1, SSE, CCSE
Sr. Sales  Security Engineer
Enterasys Networks, Lexington Kentucky


--
fatbrain.com
Radius Jonathan Hassell
Not Yet Available:Preorder Now 
This book will be available on September 26, place your advance order now and we will ship it when it arrives!
Format: Paperback, 304pp.
ISBN: 0596003226
Publisher: O'Reilly  Associates, Incorporated
Pub. Date: September 2002

---
Amazon.com
RADIUS by Jonathan Hassell
This item will be published in October 2002. You may order it now and we will ship it to you when it arrives. 



-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, July 30, 2002 4:12 PM
To: [EMAIL PROTECTED]
Subject: RE: RADIUS book from O'Reilly



This might be a dumb question, but... I'd like to buy the book and have 
my company pay for it. (Read: fill out a PO, go through the whole 
purchasing thing, blah blah blah...) Any way for FR to get the kickback 
then? (I'd imagine not, but figured I'd ask anyway.)


Vincent Giovannone
Network Infrastructure Group
Information Services Division
Rush - Presbyterian St. Luke's Medical Center


Pinball is a way of life. My way!







Jonathan Hassell [EMAIL PROTECTED]
Sent by: [EMAIL PROTECTED]
07/30/2002 03:07 PM
Please respond to freeradius-users



 To: [EMAIL PROTECTED]
 cc: 
 Subject: RE: RADIUS book from O'Reilly



And I just happen to be the author of said O'Reilly book, and I monitor
this list frequently. I haven't had time to contribute much during the
past few months, though. At any rate, please feel free to ask any
questions about the book to me personally, or call me stupid, and I'll
do my best to respond appropriately. (No, I won't hold it against you
for calling me stupid.)


If you do decide to purchase the book, please do so through the
FreeRADIUS site. There is a real potential for a decent chunk of change
to become available to support the development of this project. 


Thanks for your support!


Jonathan Hassell
[EMAIL PROTECTED]


-Original Message-
From: Alan DeKok [mailto:[EMAIL PROTECTED]] 
Sent: Tuesday, July 30, 2002 2:01 PM
To: [EMAIL PROTECTED]
Subject: RADIUS book from O'Reilly



 A RADIUS book from O'Reilly has been announced, and it's on Amazon.
See:


 http://www.freeradius.org/related/


 I've taken the liberty of signing up for an 'Amazon associates'
program, so if you're thinking about buying the book, please us the
link, and some $$ will be contributed to FreeRADIUS.



 Since there is currently no legal entity called FreeRADIUS, I've
signed up for the Amazon Associates program under my name. If the
incoming $$ are sufficient, it may be worth legally registering
FreeRADIUS as a non-profit entity.



 In any case, the moneys received from the associates program will go
to fostering the development of the server. I will be posting periodic
summaries of the $$, and request for comment as to where/how the money
should be spent.


 If, in fact, the link makes money. :)



 In the interests of transparency, I was a technical reviewer of the
book, and saw it in pre-publication draft. It isn't perfect, but it's
better than the nearly complete lack of documentation that comes with
the server today. It also explains in greater detail the why and the
how of the RADIUS protocol, and may answer many initial questions
someone may have about the RADIUS protocol, and the FreeRADIUS server.


 Alan DeKok.


- 
List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html



- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html





- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html





EAP Cert trust list

2002-07-05 Thread De Yong, Doug



I've been trying to 
get the EAP-TLS going but I haven't been able to figure out what need to so be 
use for the trusted CA list.

How do I generate 
this file? I used OpenSSL to generate the keys.

thanx/doug

---

 # 
Extensible Authentication Protocol 
# # For all EAP related 
authentications eap 
{ 
# Invoke the default supported EAP type 
when 
# EAP-Identity response is 
received 
default_eap_type = tls

 
# Default expiry time to clean the EAP 
list, 
# It is maintained to co-relate 
the 
# EAP-response for each EAP-request 
sent. 
timer_expire = 60

 
# Supported 
EAP-types 
md5 
{ 
}

 
## FIXME: EAP-TLS is highly experimental EAP-Type at the moment.

 
# Please give 
feedback. 
tls 
{ 
private_key_password =xxx
 
private_key_file = /etc/1x/sparcy-cert-srv.pem
 
KEYS GENERATED FROM THE OPENSSL CERT AUTHORITY
 
# Sometimes Private key  Certificate 
are 
located 
# in the same file, then private_key_file 
 
certificate_le 
# must contain the same file 
name. 
certificate_file = /etc/1x/sparcy-cert-srv.pem

 
# Trusted Root CA 
list# CA_file = 
/path/filename	CA_file = /etc/1x/r/CA.pam HERE IS THE PROBLEM 
ABOVE
 RADIUSD LOG SHOWS EAP WON'T INITIALIZE CANT 
READ TRUSTED CA FILE.
 WHERE DOES ONE GET THIS 
FILE?

 
dh_file = 
/etc/1x/r/dh 
random_file = /etc/1x/r/random