Read root certificates....

2007-01-22 Thread Polyxronopoulos Adreas

Hi list ,

Is it possible for a client-user  when he/she tries to connect to the 
network over freeradius to read the root certificates of freeradius? 
Does the root-certificates stored somewhere on the users machine?


thanks


___ 
Yahoo! Messenger - with free PC-PC calling and photo sharing. http://uk.messenger.yahoo.com
- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Read root certificates....

2007-01-22 Thread Polyxronopoulos Adreas

Alan DeKok wrote:

Polyxronopoulos Adreas wrote:
  

Is it possible for a client-user  when he/she tries to connect to the
network over freeradius to read the root certificates of freeradius?
Does the root-certificates stored somewhere on the users machine?



  The root certificates are stored on the users machine.

  Alan DeKok.
--
  http://deployingradius.com   - The web site of the book
  http://deployingradius.com/blog/ - The blog
- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html



  

Thanks for the quick reply

I looked up  but i could'nt find them(root.pem,root.p12...) where 
exactly are stored on the users machine ? The authentication is 
peap-eap/mschapv2.



thanks




___ 
All new Yahoo! Mail The new Interface is stunning in its simplicity and ease of use. - PC Magazine 
http://uk.docs.yahoo.com/nowyoucan.html
- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Strange behaviour of freeradius...?

2007-01-16 Thread Polyxronopoulos Adreas

Tas Dionisakos wrote:
Why dont you have the seession-idel attribute set, so that when no 
bytes are transfered for a certain period of time the connection is 
terminated?


Tas.


Peter Nixon wrote:

On Tue 16 Jan 2007 02:22, apolyxrono wrote:
 

Hi list ,


I have set up a wlan using : freeradius-1.1.4
(peap-eap/mschapv2-authentication), AccessPoint-3Com7250 and windows xp
wireless users.  My AP  has the option for accounting and i have set it
on. I logged the accounting info in the radius database in the radacct
table to be more specific. When a wireless user connected to the wlan i
am executing the following sql query:

select  UserName , NASIPAddress , AcctStartTime , AcctStopTime ,
AcctSessionTime , AcctInputOctets , AcctOutputOctets from radacct ;


 and the output is :


+--+--+-+-+--- 


--+-+--+

| UserName | NASIPAddress | AcctStartTime   | AcctStopTime|

AcctSessionTime | AcctInputOctets | AcctOutputOctets |
+--+--+-+-+--- 


--+-+--+

| sony | 10.0.0.10| 2007-01-15 22:33:12 | -00-00 00:00:00
|41 |718 | 164 |

+--+--+-+-+--- 


--+-+--+

After
If the user select from his wireless card software to disconnect from
the specific wlan and  make the same query to the database i can see
that the AcctStopTime have a specific value and accounting for this 
user

has stopped.  However if  the user  does not  use his/her wireless
software to disconnect  from the wlan  and tun-off  the  wlan switcher
of his/her card  the  accounting is continued (AcctSessionTime is
counting) on freeradius  but  the  AcctInputOctets and AcctOutputOctets
stop counting.  Why is that happening ? How should i know when the user
is connected in the wlan and the user was just turned-off his/her 
switch

of wlan ?



If your NAS does not tell radius that the user has disconnected 
RADIUS will not know


  



- List info/subscribe/unsubscribe? See 
http://www.freeradius.org/list/users.html





Hi Tas, Peter , James and thanks for your reply ,

I noticed that when the wireless user turned-off his wireless card the 
AP stores him/her Mac-Address for 10 minutes in a table (station table) 
and then dropped the Mac-Address. However freeradius continued to do 
accounting for this user over 2 hours. I read about the Idle - Timeout 
attribute but i don't know how to set it on. I authenticate my users 
from the local file users. Do you think my AP doesn't say nothing to 
freeradius after the mac-address drop? There is nothing in the AP 
web-configuration which could set it on and solve the problem. If the 
problem is the nas there is not a solution ?


Thanks a lot for your time






___ 
All new Yahoo! Mail The new Interface is stunning in its simplicity and ease of use. - PC Magazine 
http://uk.docs.yahoo.com/nowyoucan.html
- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html