Re: Fwd: radiusclient-ng in Debian

2013-09-02 Thread Alan DeKok
Daniel Pocock wrote:
> The FTP masters just accepted the new freeradius-client package, it
> should be available to install now using "apt-get"
> 
> I've opened a bug request for removal of the radiusclient-ng package
> from the Debian archive

  Thanks.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Fwd: radiusclient-ng in Debian

2013-09-02 Thread Daniel Pocock

The FTP masters just accepted the new freeradius-client package, it
should be available to install now using "apt-get"

I've opened a bug request for removal of the radiusclient-ng package
from the Debian archive




On 19/07/13 19:25, Daniel Pocock wrote:
>
> On 15/07/13 23:21, Daniel Pocock wrote:
>>
>> On 15/07/13 21:51, Alan DeKok wrote:
>>> Daniel Pocock wrote:
>>>> I just opened this report against radiusclient-ng in Debian (see below),
>>>> can anybody else comment on the situation, in particular, for
>>>> compatibility?  Is there any urgency for Debian to update to the new
>>>> client code?
>>>   It has a number of bugs fixed.  The old radiusclient-ng code is no
>>> longer maintained.
>> I'm in the pkg-voip group at Debian so I can potentially package this
>> new version of the library
>>
> I've uploaded this today, it is in Debian's approval queue now
>
> For anybody who can't wait, packaging artifacts are here:
>
> Vcs-Git: git://git.debian.org/pkg-voip/freeradius-client.git
>
> Vcs-Browser:
> http://git.debian.org/?p=pkg-voip/freeradius-client.git;a=summary
>
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Fwd: radiusclient-ng in Debian

2013-07-19 Thread Daniel Pocock


On 15/07/13 23:21, Daniel Pocock wrote:
> 
> 
> On 15/07/13 21:51, Alan DeKok wrote:
>> Daniel Pocock wrote:
>>> I just opened this report against radiusclient-ng in Debian (see below),
>>> can anybody else comment on the situation, in particular, for
>>> compatibility?  Is there any urgency for Debian to update to the new
>>> client code?
>>
>>   It has a number of bugs fixed.  The old radiusclient-ng code is no
>> longer maintained.
> 
> I'm in the pkg-voip group at Debian so I can potentially package this
> new version of the library
> 

I've uploaded this today, it is in Debian's approval queue now

For anybody who can't wait, packaging artifacts are here:

Vcs-Git: git://git.debian.org/pkg-voip/freeradius-client.git

Vcs-Browser:
http://git.debian.org/?p=pkg-voip/freeradius-client.git;a=summary

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Fwd: radiusclient-ng in Debian

2013-07-15 Thread Daniel Pocock


On 15/07/13 21:51, Alan DeKok wrote:
> Daniel Pocock wrote:
>> I just opened this report against radiusclient-ng in Debian (see below),
>> can anybody else comment on the situation, in particular, for
>> compatibility?  Is there any urgency for Debian to update to the new
>> client code?
> 
>   It has a number of bugs fixed.  The old radiusclient-ng code is no
> longer maintained.

I'm in the pkg-voip group at Debian so I can potentially package this
new version of the library

>> I think the wiki page referenced below is not up to date, it refers to a
>> CVS repository but it appears that the client code is not in github
> 
>   It's on github, as freeradius-client.

Ok, my mistake, I did see it in github - it was just a wiki issue

>> Also, is anybody aware of C++ wrappers for this code or a C++ alternative?
> 
>   Nope.  C++?  What's that? :)

That's what we use in reSIProcate - we have a very basic wrapper for
rlm_digest auth:

https://svn.resiprocate.org/viewsvn/resiprocate/main/rutil/RADIUSDigestAuthenticator.cxx?view=markup

We have a GSoC student helping us out this summer and he will probably
have a go at generalising that code to work with rlm_hmac (for
STUN/TURN) as well as existing SIP support.

It may be possible for us to contribute the most general part of our
solution back to the client library project


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient-ng in Debian

2013-07-15 Thread RONAN BLANEY
can M.I.T. model stats  for a regional mental health service to act as a 3d
shape that can represent an average that can be super imposed on other 3d
models of other health services to check for odd variation. I had a
consultant offer me uncompiled raw stats to prove regularity of diagnosis
when he thought i could do nothing with them.

On Mon, Jul 15, 2013 at 1:48 PM, Daniel Pocock  wrote:

>
> I just opened this report against radiusclient-ng in Debian (see below),
> can anybody else comment on the situation, in particular, for
> compatibility?  Is there any urgency for Debian to update to the new client
> code?
>
> I think the wiki page referenced below is not up to date, it refers to a
> CVS repository but it appears that the client code is not in github
>
> Also, is anybody aware of C++ wrappers for this code or a C++ alternative?
>
>
> ---- Original Message   Subject: radiusclient-ng in Debian  Date:
> Mon, 15 Jul 2013 14:41:54 +0200  From: Daniel Pocock
>To: Debian Bug Tracking
> System  
>
> Package: libradiusclient-ng2
> Version: 0.5.6-1.1
> Severity: normal
>
>
> I've just read through the wiki 
> at:http://wiki.freeradius.org/glossary/Radiusclient
>
> If I understand correctly,
>
> a) freeradius-client is the continuation of radiusclient-ng (which was
> the continuation of a previous project)
>
> b) it is not a fork of the previous projects
>
> c) it should be compatible (or almost compatible) with code that was
> built for radiusclient-ng
>
> d) it is NOT built from the main FreeRADIUS source tree or repository,
> it is built from a standalone repository
>
> Therefore, this leaves me feeling that Debian should drop the
> libradiusclient-ng2 package and distribute FreeRADIUS client instead and
> there will be no significant side-effects of doing so.
>
>
>
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Fwd: radiusclient-ng in Debian

2013-07-15 Thread Alan DeKok
Daniel Pocock wrote:
> I just opened this report against radiusclient-ng in Debian (see below),
> can anybody else comment on the situation, in particular, for
> compatibility?  Is there any urgency for Debian to update to the new
> client code?

  It has a number of bugs fixed.  The old radiusclient-ng code is no
longer maintained.

> I think the wiki page referenced below is not up to date, it refers to a
> CVS repository but it appears that the client code is not in github

  It's on github, as freeradius-client.

> Also, is anybody aware of C++ wrappers for this code or a C++ alternative?

  Nope.  C++?  What's that? :)

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Fwd: radiusclient-ng in Debian

2013-07-15 Thread Daniel Pocock

I just opened this report against radiusclient-ng in Debian (see below),
can anybody else comment on the situation, in particular, for
compatibility?  Is there any urgency for Debian to update to the new
client code?

I think the wiki page referenced below is not up to date, it refers to a
CVS repository but it appears that the client code is not in github

Also, is anybody aware of C++ wrappers for this code or a C++ alternative?


 Original Message 
Subject:radiusclient-ng in Debian
Date:   Mon, 15 Jul 2013 14:41:54 +0200
From:   Daniel Pocock 
To: Debian Bug Tracking System 



Package: libradiusclient-ng2
Version: 0.5.6-1.1
Severity: normal


I've just read through the wiki at:
http://wiki.freeradius.org/glossary/Radiusclient

If I understand correctly,

a) freeradius-client is the continuation of radiusclient-ng (which was
the continuation of a previous project)

b) it is not a fork of the previous projects

c) it should be compatible (or almost compatible) with code that was
built for radiusclient-ng

d) it is NOT built from the main FreeRADIUS source tree or repository,
it is built from a standalone repository

Therefore, this leaves me feeling that Debian should drop the
libradiusclient-ng2 package and distribute FreeRADIUS client instead and
there will be no significant side-effects of doing so.



-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Authentication with radiusclient 1.4

2012-04-12 Thread ikram
Hi every one ,
I have 2 major problems :
1.I can't found  documentation on radiusclient 1.4 to use it for
authenticate an asterisk server
2. Capturing with wireshark can't show radius accounting requestes even if I
specify the filter, and thgis requests are shown on the server with console
mode

please help 

--
View this message in context: 
http://freeradius.1045715.n5.nabble.com/Authentication-with-radiusclient-1-4-tp5636042p5636042.html
Sent from the FreeRadius - User mailing list archive at Nabble.com.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Miha Zoubek

On 11/4/2011 3:01 PM, Fajar A. Nugraha wrote:

On Fri, Nov 4, 2011 at 8:53 PM, Miha Zoubek  wrote:

Just curies do you maybe know if I can get radclient working with
freeswitch?
@Fajar I was trying to use with freeswitch as is written
on http://wiki.freeswitch.org/wiki/Mod_rad_auth.

But I am getting a few error s which I am unable to fix:)

My GUESS it's similar to poptop setup. See http://wiki.freeradius.org/PopTop .
In poptop's case you need to:
- have a radius client library (vendor-provided package should be enough)
- configure poptop to use the correct configuration file (radiusclient
and radiusclient-ng has different configuration directory, but both
should work)
- configure additional needed dictionary items (e.g. to support
MSCHAP, example in the wiki page)

In your case I suggest try using distro-provided radiusclient first,
and if it still doesn't work try checking radiusclient's dictionary.


Thank you for help!

BR,
Miha
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Fajar A. Nugraha
On Fri, Nov 4, 2011 at 8:53 PM, Miha Zoubek  wrote:
> Just curies do you maybe know if I can get radclient working with
> freeswitch?
> @Fajar I was trying to use with freeswitch as is written
> on http://wiki.freeswitch.org/wiki/Mod_rad_auth.
>
> But I am getting a few error s which I am unable to fix:)

My GUESS it's similar to poptop setup. See http://wiki.freeradius.org/PopTop .
In poptop's case you need to:
- have a radius client library (vendor-provided package should be enough)
- configure poptop to use the correct configuration file (radiusclient
and radiusclient-ng has different configuration directory, but both
should work)
- configure additional needed dictionary items (e.g. to support
MSCHAP, example in the wiki page)

In your case I suggest try using distro-provided radiusclient first,
and if it still doesn't work try checking radiusclient's dictionary.

-- 
Fajar

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Miha Zoubek

On 11/4/2011 2:45 PM, Arran Cudbard-Bell wrote:

On 4 Nov 2011, at 14:37, Fajar A. Nugraha wrote:


On Fri, Nov 4, 2011 at 8:20 PM, Arran Cudbard-Bell
  wrote:

On 4 Nov 2011, at 12:55, Miha Zoubek wrote:

Sorry for bothering you.
Is not radius client part of freeradius?

No, radclient is part of FreeRADIUS

@Arran: I think Miha is referring to http://wiki.freeradius.org/Radiusclient
It's hard not to think it as part of FreeRADIUS when the first line of
the wiki starts with "FreeRADIUS Client"

It was adopted. It's like the orphan child that lives in the cupboard under the
stairs.

Arran Cudbard-Bell
a.cudba...@freeradius.org

Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ !


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Ok I get it:)

Thanks guys for information:)

Just curies do you maybe know if I can get radclient working with 
freeswitch?
@Fajar I was trying to use with freeswitch as is written 
onhttp://wiki.freeswitch.org/wiki/Mod_rad_auth.


But I am getting a few error s which I am unable to fix:)

BR,
Miha
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Arran Cudbard-Bell

On 4 Nov 2011, at 14:37, Fajar A. Nugraha wrote:

> On Fri, Nov 4, 2011 at 8:20 PM, Arran Cudbard-Bell
>  wrote:
>> 
>> On 4 Nov 2011, at 12:55, Miha Zoubek wrote:
>>> Sorry for bothering you.
>>> Is not radius client part of freeradius?
>> 
>> No, radclient is part of FreeRADIUS
> 
> @Arran: I think Miha is referring to http://wiki.freeradius.org/Radiusclient
> It's hard not to think it as part of FreeRADIUS when the first line of
> the wiki starts with "FreeRADIUS Client"

It was adopted. It's like the orphan child that lives in the cupboard under the
stairs.

Arran Cudbard-Bell
a.cudba...@freeradius.org

Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ !


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Fajar A. Nugraha
On Fri, Nov 4, 2011 at 8:20 PM, Arran Cudbard-Bell
 wrote:
>
> On 4 Nov 2011, at 12:55, Miha Zoubek wrote:
>> Sorry for bothering you.
>> Is not radius client part of freeradius?
>
> No, radclient is part of FreeRADIUS

@Arran: I think Miha is referring to http://wiki.freeradius.org/Radiusclient
It's hard not to think it as part of FreeRADIUS when the first line of
the wiki starts with "FreeRADIUS Client"


@Miha: last time I tried I couldn't get freeradius-client-1.1.6 to
work correctly either. It was a while ago though, so I don't remember
exactly what went wrong. However the (old) version that comes with
most distro (e.g Ubuntu Natty has radiusclient1-0.3.2-13) works
correctly, so I suggest you try using whatever your distro has first.
After that, if you have time, you can try revisit latest
freeradius-client.

Also, what do you need it for? The common use for radiusclient is to
provide radius auth functionality to pptp, in which case the old
version would probably be enough. If you simply want to do some tests
(e.g. send a packet, see how the server responds) it's easier to just
use radtest/radclient that comes with freeradius-server.

-- 
Fajar
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Arran Cudbard-Bell

On 4 Nov 2011, at 14:30, Miha Zoubek wrote:

> On 11/4/2011 2:20 PM, Arran Cudbard-Bell wrote:
>> 
>> 
>> On 4 Nov 2011, at 12:55, Miha Zoubek wrote:
>> 
>>> On 11/4/2011 12:12 PM, Phil Mayers wrote:
 
 On 04/11/11 10:53, Miha Zoubek wrote: 
> Hi, 
> 
> I have installedradiusclient. When I start it for a test I get this: 
> 
> xxx.xxx.xxx.xxx: can't parse AV pair 
> 
> Radiusclientis on different server thatfreeradius. 
> I checked dictionary s and all looks good. 
 
 This isn't really a FreeRADIUS issue. 
 - 
 List info/subscribe/unsubscribe? See 
 http://www.freeradius.org/list/users.html 
 
>>> Sorry for bothering you.
>>> Is not radius client part of freeradius?
>> 
>> No, radclient is part of FreeRADIUS
>> 
>> Arran Cudbard-Bell
>> a.cudba...@freeradius.org
>> 
>> Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ !
>> 
>> 
>> 
>> -
>> List info/subscribe/unsubscribe? See 
>> http://www.freeradius.org/list/users.html
> This is written on Freeradius page:
> 
> FreeRADIUS Client release is available from:
>  
> ftp://ftp.freeradius.org/pub/freeradius/freeradius-client-1.1.6.tar.bz2
> Ok, do you meybe know where can I get help about this issue?
> 
> Sorry for bothering you, but I really need some information to get this 
> working.

It's dead code, unless you're developing your own application, use radclient.

-Arran

Arran Cudbard-Bell
a.cudba...@freeradius.org

Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ !

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Miha Zoubek

On 11/4/2011 2:20 PM, Arran Cudbard-Bell wrote:


On 4 Nov 2011, at 12:55, Miha Zoubek wrote:


On 11/4/2011 12:12 PM, Phil Mayers wrote:

On 04/11/11 10:53, Miha Zoubek wrote:

Hi,

I have installedradiusclient. When I start it for a test I get this:

xxx.xxx.xxx.xxx: can't parse AV pair

Radiusclientis on different server thatfreeradius.
I checked dictionary s and all looks good.


This isn't really a FreeRADIUS issue.
-
List info/subscribe/unsubscribe? See 
http://www.freeradius.org/list/users.html



Sorry for bothering you.
Is not radius client part of freeradius?


No, radclient is part of FreeRADIUS

Arran Cudbard-Bell
a.cudba...@freeradius.org 

Betelwiki, Betelwiki, Betelwikihttp://wiki.freeradius.org/ !



-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

This is written on Freeradius page:

FreeRADIUS Client release is available from:

 ftp://ftp.freeradius.org/pub/freeradius/freeradius-client-1.1.6.tar.bz2

Ok, do you meybe know where can I get help about this issue?

Sorry for bothering you, but I really need some information to get this 
working.


BR,
Miha
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Arran Cudbard-Bell

On 4 Nov 2011, at 12:55, Miha Zoubek wrote:

> On 11/4/2011 12:12 PM, Phil Mayers wrote:
>> 
>> On 04/11/11 10:53, Miha Zoubek wrote: 
>>> Hi, 
>>> 
>>> I have installedradiusclient. When I start it for a test I get this: 
>>> 
>>> xxx.xxx.xxx.xxx: can't parse AV pair 
>>> 
>>> Radiusclientis on different server thatfreeradius. 
>>> I checked dictionary s and all looks good. 
>> 
>> This isn't really a FreeRADIUS issue. 
>> - 
>> List info/subscribe/unsubscribe? See 
>> http://www.freeradius.org/list/users.html 
>> 
> Sorry for bothering you.
> Is not radius client part of freeradius?

No, radclient is part of FreeRADIUS

Arran Cudbard-Bell
a.cudba...@freeradius.org

Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ !

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Miha Zoubek

On 11/4/2011 12:12 PM, Phil Mayers wrote:

On 04/11/11 10:53, Miha Zoubek wrote:

Hi,

I have installedradiusclient. When I start it for a test I get this:

xxx.xxx.xxx.xxx: can't parse AV pair

Radiusclientis on different server thatfreeradius.
I checked dictionary s and all looks good.


This isn't really a FreeRADIUS issue.
-
List info/subscribe/unsubscribe? See 
http://www.freeradius.org/list/users.html



Sorry for bothering you.
Is not radius client part of freeradius?

BR,Miha**
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: radiusclient problems

2011-11-04 Thread Phil Mayers

On 04/11/11 10:53, Miha Zoubek wrote:

Hi,

I have installedradiusclient. When I start it for a test I get this:

xxx.xxx.xxx.xxx: can't parse AV pair

Radiusclientis on different server thatfreeradius.
I checked dictionary s and all looks good.


This isn't really a FreeRADIUS issue.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


radiusclient problems

2011-11-04 Thread Miha Zoubek

Hi,

I have installedradiusclient. When I start it for a test I get this:

xxx.xxx.xxx.xxx: can't parse AV pair

Radiusclientis on different server thatfreeradius.
I checked dictionary s and all looks good.

Please help me out with this issue.

Thank you!

BR,
Miha
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Patch for radiusclient: new program radlistdictionary and fixes to PPTP/CHAP problem

2011-07-04 Thread freeradius developer/user identity
I have posted at
  http://www.cardiothink.com/downloads/ 
a set of patches which, when applied to the latest stable
freeradius-client (version 1.1.6) and to the CVS version,
fixes the problem with PPTP and radiusclient that results
in failure of CHAP authentication with the syslog errors:
   rc_avpair_new: unknown attribute 11
   rc_avpair_new: unknown attribute 25
(The problem, for me, turned out to be blanks at the start of
every line in dictionary.microsoft. The patches, among other things,
skip the blanks.) 

Included in the patches is a new program in the src subdirectory that I
have named radlistdictionary (you can change it if you like). It is a
simple program that uses the installed freeradius-client library to read
dictionaries, and it displays the loading and parsing steps explicitly
so that you can see where errors are occurring. (This program requires that
the library itself be patched to show the parsing.)

Fixing problems with the dictionaries is easy once you can see what is
going on! Please see the above web site for more details, and let me know
of any problems.  


signature.asc
Description: Digital signature
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Question about radiusclient

2010-09-15 Thread Ali Majdzadeh
Hello All
In the radiusclient configuration file there is an option called auth_order
which accepts two values (local, radius). If we set this option as follows:
auth_order radius,local
doesn't it means that if the authentication fails using RADIUS it should be
performed using the /etc/passwd file? In other words, if we define all those
users, which are not mentioned as radius users, as local users of the
machine where radiusclient runs, it should be OK. Is that right?
I have tested the so-called scenario, but it does not work. Does anyone have
any experiences regarding this issue?

Warm Regards
Ali Majdzadeh Kohbanani
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

radiusclient configuration file format

2010-08-23 Thread Murray Long
Hi All,

Where can I find documentation on the format file format required by the
radiusclient command?

Thanks,
Murray
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Using Radiusclient to implement a radius client on Windows platform?

2010-04-26 Thread Alan DeKok
Joshua Lim wrote:
> Hi Alan,
> 
> Thanks, how about using the pgina radius plugin?
> http://userpage.fu-berlin.de/~holger/radiusplugin/RADIUSplugin-0.3src.zip
> 
> It has code taken from pam_radius_auth
> 
> Is pam_radius_auth using radiusclient?

  No. They are different code bases.

  They should really be unified at some point.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Using Radiusclient to implement a radius client on Windows platform?

2010-04-23 Thread Joshua Lim

Hi Alan,

Thanks, how about using the pgina radius plugin?
http://userpage.fu-berlin.de/~holger/radiusplugin/RADIUSplugin-0.3src.zip

It has code taken from pam_radius_auth

Is pam_radius_auth using radiusclient?

Rgds,
Joshua


Alan DeKok wrote:

Joshua Lim wrote:
  

Hi I'm a newbie, hope someone can help me.  I'm trying to implementing a
radius client on Windows platform to work with freeradius.  I intend to
use VC++ or Delphi.  radiusclient is for linux platform, can i adapt it
for Windows?



  You'll have to hack the source code.  It's not really portable right now.

  Alan DeKok.


  


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Using Radiusclient to implement a radius client on Windows platform?

2010-04-23 Thread Alan DeKok
Joshua Lim wrote:
> Hi I'm a newbie, hope someone can help me.  I'm trying to implementing a
> radius client on Windows platform to work with freeradius.  I intend to
> use VC++ or Delphi.  radiusclient is for linux platform, can i adapt it
> for Windows?

  You'll have to hack the source code.  It's not really portable right now.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Using Radiusclient to implement a radius client on Windows platform?

2010-04-23 Thread Joshua Lim
Hi I'm a newbie, hope someone can help me.  I'm trying to implementing a 
radius client on Windows platform to work with freeradius.  I intend to 
use VC++ or Delphi.  radiusclient is for linux platform, can i adapt it 
for Windows?


Grateful for any pointers.  :)

Rgds,
Joshua

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: How to send the Vendor-Specific subattributes via radiusclient

2010-01-13 Thread Rahul Panwar
Thanks for your reply Alan,

My problem was solved. I was doing some mistake in my dictionary file, i
forgot to define the vendor name "Cisco" at the end of ATTRIBUTE line, in
dictionary.cisco file. After looking at the man page of dictionary "
http://freeradius.org/radiusd/man/dictionary.html";, i resolved my problem.
It is mentioned as a optional parameter in man page but it is mandatory in
case of Vendor-Specific Attributes.

Anyway thanks a lot,
Rahul Panwar

On Wed, Jan 13, 2010 at 9:34 PM, Alan DeKok wrote:

> Rahul Panwar wrote:
> > Hi,
> >
> > I am using freeradius-client-1.1.6 on CentOS 5.4 with windows based
> > freeradius server from freeradius.net <http://freeradius.net>. I want to
> > send the Vendor-Specific attribute using radiusclient application.
> > I include the dictionary.cisco file in radiusclient dictionary file as
> > follows:
> >
> > $INCLUDE /usr/local/etc/radiusclient/dictionary.cisco
>
>  You have to add the attribute to the packet, and give it a value.  The
> dictionaries just define the attribute name.  They don't add it to the
> packet, and they don't give it a value.
>
>  Alan DeKok.
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: How to send the Vendor-Specific subattributes via radiusclient

2010-01-13 Thread Alan DeKok
Rahul Panwar wrote:
> Hi,
> 
> I am using freeradius-client-1.1.6 on CentOS 5.4 with windows based
> freeradius server from freeradius.net <http://freeradius.net>. I want to
> send the Vendor-Specific attribute using radiusclient application.
> I include the dictionary.cisco file in radiusclient dictionary file as
> follows:
> 
> $INCLUDE /usr/local/etc/radiusclient/dictionary.cisco

  You have to add the attribute to the packet, and give it a value.  The
dictionaries just define the attribute name.  They don't add it to the
packet, and they don't give it a value.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


How to send the Vendor-Specific subattributes via radiusclient

2010-01-12 Thread Rahul Panwar
Hi,

I am using freeradius-client-1.1.6 on CentOS 5.4 with windows based
freeradius server from freeradius.net. I want to send the Vendor-Specific
attribute using radiusclient application.
I include the dictionary.cisco file in radiusclient dictionary file as
follows:

$INCLUDE /usr/local/etc/radiusclient/dictionary.cisco

I am giving the following command:
radiusclient User-Name=testuser Password=testpw Vendor-Specific=9
h323-remote-address=192.168.2.1

When i am watching the tcpdump capture on radiusclient pc. The above command
is accepted by server but the packet is showing as given below:

Request Sent by client:

 Access Request (1), id: 0xba, Authenticator:
402018a985a02bceca216ab2474cd6a1
  Username Attribute (1), length: 10, Value: testuser
0x:  7465 7374 7573 6572
  Password Attribute (2), length: 18, Value:
0x:  b37e 9117 41f3 6bf3 8d5c 438f 3796 5e1d
  Vendor Specific Attribute (26), length: 3, Value:  [|radius]
0x:  39
  Framed IPX Network Attribute (23), length: 13, Value: ERROR:
length 11 != 4
0x:  31 [|radius]

My Question is : Why "Framed IPX Network Attribute (23)" is sending by
radiusclient if i declared the Vendor-Specific Attributes in dictionary?

Response received by client:

  Access Accept (2), id: 0xba, Authenticator:
6ccb55adfc0d5af921fdab7c111acf18

Please give me the response what the wrong i am doing? I googled about this
problem but not able to find anyhelp about radiusclient.

Waiting for the response.

Thanks,
Rahul Panwar
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: How to set servers file in radiusclient-ng install ?

2009-12-23 Thread Alan DeKok
Zhang Shukun wrote:
> is that say i must set the hostname of a RADIUS server, could i set IP
> addr of the RADIUS server?

  Yes.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


How to set servers file in radiusclient-ng install ?

2009-12-22 Thread Zhang Shukun
hi friend,
 i see the tutorial in the url
http://svn.dd-wrt.com:8000/dd-wrt/browser/src/router/asterisk/doc/radius.txt

 it says :

" Each line contains hostname of a RADIUS server and shared secret
used in communication with that server. "

is that say i must set the hostname of a RADIUS server, could i set IP
addr of the RADIUS server?

Thanks!



-- 
Regards,
Sucan
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Almost there... Radiusclient not sending password with MSChapv2

2009-12-08 Thread Wim De Hul
On Mon, Dec 07, 2009 at 11:31:44PM -, t...@kalik.net wrote:
> > I almost have a working Radius setup...
> 
> It's working.
> 
> > My XP tells me that the username/password is invalid (Error 961). I
> > suspect the password attibute to be empty..
> 
> There is no password attribute in mschap. Problem is with your NAS - for
> some reason it is not creating the tunnel. Debug ppp on your NAS.
> 
> Ivan Kalik

I was debugging ppp yesterday evening, I started thinking about it after I saw
the ppp0 interface coming up...

But that's another mailinglist :-)


Thanks for the support so far! I learned a lot :-)

-- 
  Wim
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Almost there... Radiusclient not sending password with MSChapv2

2009-12-07 Thread tnt
> I almost have a working Radius setup...

It's working.

> Well almost, because when I try to setup a pptp tunnel with my Windows XP,
> I see the following om my radius server:
>
> Packet number 1 has just been sniffed
> From:127.0.0.1:54717
> To:  127.0.0.1:1812
> Type:Access-Request
> Service-Type = Framed-User
> Framed-Protocol = PPP
> User-Name = "wim"
> MS-CHAP-Challenge = 0x75a4e7aeb06f3c93be685de0afae4cc2
> MS-CHAP2-Response =
> 0x60007f150b2e344755f9e0462ded8d7d6852cf323d8cd21faeb820272ccadd6b188a8ae287bd7481f1c4
> Calling-Station-Id = "8.08"
> NAS-IP-Address = XX.XX.XX.XX
> NAS-Port = 0
> Packet number 2 has just been sniffed
> From:127.0.0.1:1812
> To:  127.0.0.1:54717
> Type:Access-Accept
> Service-Type = Framed-User
> Framed-Protocol = PPP
> Framed-IP-Address = 172.16.2.10
> Framed-IP-Netmask = 255.255.255.0
> MS-CHAP2-Success =
> 0x60533d4531443844373633414240343132383837384533434639323534413541373639313346443535
> MS-MPPE-Recv-Key =
> 0x97fc624e0e2ff930716882df647c7ec4fc8a2d9c946e54d2befdc26d5292aec3562a
> MS-MPPE-Send-Key =
> 0x9ca67e3969c47454af91493d646e4cdf8fd93dcf3435868ffd42fb3c6c992fb5b989
> MS-MPPE-Encryption-Policy = 0x0002
> MS-MPPE-Encryption-Types = 0x0004
>

See. Access-Accept with MPPE keys. That all looks fine.

> My XP tells me that the username/password is invalid (Error 961). I
> suspect the password attibute to be empty..

There is no password attribute in mschap. Problem is with your NAS - for
some reason it is not creating the tunnel. Debug ppp on your NAS.

Ivan Kalik

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Almost there... Radiusclient not sending password with MSChapv2

2009-12-07 Thread Wim De Hul
On Mon, Dec 07, 2009 at 04:11:32PM +0100, Wim De Hul wrote:
> Dear list members,
> 
> I almost have a working Radius setup...
> 
> Well almost, because when I try to setup a pptp tunnel with my Windows XP, I 
> see the following om my radius server:
> 
> Packet number 1 has just been sniffed
> From:127.0.0.1:54717
> To:  127.0.0.1:1812
> Type:Access-Request
> Service-Type = Framed-User
> Framed-Protocol = PPP
> User-Name = "wim"
> MS-CHAP-Challenge = 0x75a4e7aeb06f3c93be685de0afae4cc2
> MS-CHAP2-Response = 
> 0x60007f150b2e344755f9e0462ded8d7d6852cf323d8cd21faeb820272ccadd6b188a8ae287bd7481f1c4
> Calling-Station-Id = "8.08"
> NAS-IP-Address = XX.XX.XX.XX
> NAS-Port = 0
> Packet number 2 has just been sniffed
> From:127.0.0.1:1812
> To:  127.0.0.1:54717
> Type:Access-Accept
> Service-Type = Framed-User
> Framed-Protocol = PPP
> Framed-IP-Address = 172.16.2.10
> Framed-IP-Netmask = 255.255.255.0
> MS-CHAP2-Success = 
> 0x60533d4531443844373633414240343132383837384533434639323534413541373639313346443535
> MS-MPPE-Recv-Key = 
> 0x97fc624e0e2ff930716882df647c7ec4fc8a2d9c946e54d2befdc26d5292aec3562a
> MS-MPPE-Send-Key = 
> 0x9ca67e3969c47454af91493d646e4cdf8fd93dcf3435868ffd42fb3c6c992fb5b989
> MS-MPPE-Encryption-Policy = 0x0002
> MS-MPPE-Encryption-Types = 0x0004
> 
> My XP tells me that the username/password is invalid (Error 961). I suspect 
> the password attibute to be empty..
> 
> Can anyone give me a hint?

FYI, I use the 'users' file to store my passwords in clear text:

wim Cleartext-Password := "test123"

> 
> -- 
>   Wim
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

-- 
  Wim
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Almost there... Radiusclient not sending password with MSChapv2

2009-12-07 Thread Wim De Hul
Dear list members,

I almost have a working Radius setup...

Well almost, because when I try to setup a pptp tunnel with my Windows XP, I 
see the following om my radius server:

Packet number 1 has just been sniffed
From:127.0.0.1:54717
To:  127.0.0.1:1812
Type:Access-Request
Service-Type = Framed-User
Framed-Protocol = PPP
User-Name = "wim"
MS-CHAP-Challenge = 0x75a4e7aeb06f3c93be685de0afae4cc2
MS-CHAP2-Response = 
0x60007f150b2e344755f9e0462ded8d7d6852cf323d8cd21faeb820272ccadd6b188a8ae287bd7481f1c4
Calling-Station-Id = "8.08"
NAS-IP-Address = XX.XX.XX.XX
NAS-Port = 0
Packet number 2 has just been sniffed
From:127.0.0.1:1812
To:  127.0.0.1:54717
Type:Access-Accept
Service-Type = Framed-User
Framed-Protocol = PPP
Framed-IP-Address = 172.16.2.10
Framed-IP-Netmask = 255.255.255.0
MS-CHAP2-Success = 
0x60533d4531443844373633414240343132383837384533434639323534413541373639313346443535
MS-MPPE-Recv-Key = 
0x97fc624e0e2ff930716882df647c7ec4fc8a2d9c946e54d2befdc26d5292aec3562a
MS-MPPE-Send-Key = 
0x9ca67e3969c47454af91493d646e4cdf8fd93dcf3435868ffd42fb3c6c992fb5b989
MS-MPPE-Encryption-Policy = 0x0002
MS-MPPE-Encryption-Types = 0x0004

My XP tells me that the username/password is invalid (Error 961). I suspect the 
password attibute to be empty..

Can anyone give me a hint?

-- 
  Wim
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: FreeRadius with radiusclient-ng and Cisco h323 VoIP attributes

2009-01-07 Thread Dean Elwood

Hi Luciano,

Many thanks for the reply.

Yes, it was a client-side error (now fixed, see below).

I removed the empty lines between VENDOR and the first attributes and  
that didn't make any difference.


The Cisco attributes were added by me creating a dictionary.cisco file  
which I then included in the main dictionary with the $INCLUDE  
directive.


As for testing, I was just using the radiusclient-ng at command line  
and manually trying to enter an AUTH packet with the Cisco attributes.


But it's now working fine. If anyone else stumbles upon this thread  
after having problems with using a RADIUS based SIPPY B2BUA with  
FreeRadius, the fix is:-


1. After installing the radiusclient-ng client application, edit the  
radiusclient-ng.conf file and tell it to use the SIPPY dictionary  
(which is probably in /usr/src/sippy/). Don't use the radiusclient-ng  
library (that's why mine wasn't working at first).


2. Edit the SIPPY dictionary file and add the following entries, or  
alternatively put these in to a new file and include them in the main  
dictionary with the $INCLUDE directive:-


VENDOR  Cisco   9
ATTRIBUTE   Cisco-AVPair1   string  Cisco
ATTRIBUTE   h323-remote-address 23  string  Cisco
ATTRIBUTE   h323-conf-id24  string  Cisco
ATTRIBUTE   h323-setup-time 25  string  Cisco
ATTRIBUTE   h323-call-origin26  string  Cisco
ATTRIBUTE   h323-call-type  27  string  Cisco
ATTRIBUTE   h323-connect-time   28  string  Cisco
ATTRIBUTE   h323-disconnect-time29  string  Cisco
ATTRIBUTE   h323-disconnect-cause   30  string  Cisco
ATTRIBUTE   h323-voice-quality  31  string  Cisco
ATTRIBUTE   h323-ivr-out32  string  Cisco
ATTRIBUTE   h323-credit-time102 string  Cisco
ATTRIBUTE   h323-return-code103 string  Cisco
ATTRIBUTE   h323-redirect-number106 string  Cisco
ATTRIBUTE   h323-preferred-lang 107 string  Cisco
ATTRIBUTE   h323-billing-model  109 string  Cisco
ATTRIBUTE   h323-currency   110 string  Cisco


Dean



On 6 Jan 2009, at 13:17, Luciano Afranllie wrote:


Dean,

Do you see that error on client side, right?

Some very stupid thing I can tell you is remove the empty line between
VENDOR line and first attribute. I have the same config (without the
empty line) and is working fine.

How and where do you added cisco attributes? Just a tip, you can
create a new dictionary file (dictionary.cisco for example) and use an
include directive at the end of the default dictionary file of
radiusclient-ng

$INCLUDE dictionary.cisco

How are you testing this attribute?

Regards
Luciano

On Tue, Jan 6, 2009 at 8:58 AM, Dean Elwood   
wrote:

Hi there,

I'm having real trouble getting FreeRadius and radiusclient-ng to  
talk to

each other with Cisco h323 attributes.

I believe I have set up FreeRadius correctly. I can connect using
radiusclient-ng and do standard AUTH commands and all works fine.

As soon as I try to add an attribute like:-

h323-conf-id = '78FF6EBC 2F74D29E 4F400B22 8B4AA1C1'

I get this parse error from radiusclient-ng:-

: can't parse AV pair

I assumed that this meant that radiusclient-ng didn't recognise the
h323-conf-id attribute, so I included in the radiusclient-ng *client*
dictionary the following:-

VENDOR  Cisco   9

ATTRIBUTE   Cisco-AVPair1
string

Cisco
ATTRIBUTE   h323-call-origin26   
string

Cisco
ATTRIBUTE   h323-remote-address 23   
string

Cisco
ATTRIBUTE   h323-conf-id24   
string

Cisco
ATTRIBUTE   h323-setup-time 25   
string

Cisco
ATTRIBUTE   h323-call-origin26   
string

Cisco
ATTRIBUTE   h323-call-type  27   
string

Cisco
ATTRIBUTE   h323-connect-time   28   
string

Cisco
ATTRIBUTE   h323-disconnect-time29   
string

Cisco
ATTRIBUTE   h323-disconnect-cause   30   
string

Cisco
ATTRIBUTE   h323-voice-quality  31   
string

Cisco
ATTRIBUTE   h323-gw-id  33   
string

Cisco
ATTRIBUTE   h323-incoming-conf-id   35   
string

Cisco

The client appears to be happy with this dictionary file (at least  
the
client runs and still does standard AUTH's ok), but I still get the  
parse

error on the h323 vars.

The fact that the parse error states an error parsing "AV pair"  
makes me
think that these attributes need to be formatted in a particular  
way. Could

that be it?

Any assistance or pointers in the right di

Re: FreeRadius with radiusclient-ng and Cisco h323 VoIP attributes

2009-01-06 Thread Luciano Afranllie
Dean,

Do you see that error on client side, right?

Some very stupid thing I can tell you is remove the empty line between
VENDOR line and first attribute. I have the same config (without the
empty line) and is working fine.

How and where do you added cisco attributes? Just a tip, you can
create a new dictionary file (dictionary.cisco for example) and use an
include directive at the end of the default dictionary file of
radiusclient-ng

$INCLUDE dictionary.cisco

How are you testing this attribute?

Regards
Luciano

On Tue, Jan 6, 2009 at 8:58 AM, Dean Elwood  wrote:
> Hi there,
>
> I'm having real trouble getting FreeRadius and radiusclient-ng to talk to
> each other with Cisco h323 attributes.
>
> I believe I have set up FreeRadius correctly. I can connect using
> radiusclient-ng and do standard AUTH commands and all works fine.
>
> As soon as I try to add an attribute like:-
>
> h323-conf-id = '78FF6EBC 2F74D29E 4F400B22 8B4AA1C1'
>
> I get this parse error from radiusclient-ng:-
>
> : can't parse AV pair
>
> I assumed that this meant that radiusclient-ng didn't recognise the
> h323-conf-id attribute, so I included in the radiusclient-ng *client*
> dictionary the following:-
>
> VENDOR  Cisco   9
>
> ATTRIBUTE   Cisco-AVPair1   string
>  Cisco
> ATTRIBUTE   h323-call-origin26  string
>  Cisco
> ATTRIBUTE   h323-remote-address 23  string
>  Cisco
> ATTRIBUTE   h323-conf-id24  string
>  Cisco
> ATTRIBUTE   h323-setup-time 25  string
>  Cisco
> ATTRIBUTE   h323-call-origin26  string
>  Cisco
> ATTRIBUTE   h323-call-type  27  string
>  Cisco
> ATTRIBUTE   h323-connect-time   28  string
>  Cisco
> ATTRIBUTE   h323-disconnect-time29  string
>  Cisco
> ATTRIBUTE   h323-disconnect-cause   30  string
>  Cisco
> ATTRIBUTE   h323-voice-quality  31  string
>  Cisco
> ATTRIBUTE   h323-gw-id  33  string
>  Cisco
> ATTRIBUTE   h323-incoming-conf-id   35  string
>  Cisco
>
> The client appears to be happy with this dictionary file (at least the
> client runs and still does standard AUTH's ok), but I still get the parse
> error on the h323 vars.
>
> The fact that the parse error states an error parsing "AV pair" makes me
> think that these attributes need to be formatted in a particular way. Could
> that be it?
>
> Any assistance or pointers in the right direction would be much
> appreciated
>
> Thanks,
>
> Dean
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


FreeRadius with radiusclient-ng and Cisco h323 VoIP attributes

2009-01-06 Thread Dean Elwood

Hi there,

I'm having real trouble getting FreeRadius and radiusclient-ng to talk  
to each other with Cisco h323 attributes.


I believe I have set up FreeRadius correctly. I can connect using  
radiusclient-ng and do standard AUTH commands and all works fine.


As soon as I try to add an attribute like:-

h323-conf-id = '78FF6EBC 2F74D29E 4F400B22 8B4AA1C1'

I get this parse error from radiusclient-ng:-

: can't parse AV pair

I assumed that this meant that radiusclient-ng didn't recognise the  
h323-conf-id attribute, so I included in the radiusclient-ng *client*  
dictionary the following:-


VENDOR  Cisco   9

ATTRIBUTE   Cisco-AVPair1
string  Cisco
ATTRIBUTE   h323-call-origin26   
string  Cisco
ATTRIBUTE   h323-remote-address 23   
string  Cisco
ATTRIBUTE   h323-conf-id24   
string  Cisco
ATTRIBUTE   h323-setup-time 25   
string  Cisco
ATTRIBUTE   h323-call-origin26   
string  Cisco
ATTRIBUTE   h323-call-type  27   
string  Cisco
ATTRIBUTE   h323-connect-time   28   
string  Cisco
ATTRIBUTE   h323-disconnect-time29   
string  Cisco
ATTRIBUTE   h323-disconnect-cause   30   
string  Cisco
ATTRIBUTE   h323-voice-quality  31   
string  Cisco
ATTRIBUTE   h323-gw-id  33   
string  Cisco
ATTRIBUTE   h323-incoming-conf-id   35   
string  Cisco


The client appears to be happy with this dictionary file (at least the  
client runs and still does standard AUTH's ok), but I still get the  
parse error on the h323 vars.


The fact that the parse error states an error parsing "AV pair" makes  
me think that these attributes need to be formatted in a particular  
way. Could that be it?


Any assistance or pointers in the right direction would be much  
appreciated


Thanks,

Dean

 
-

List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Openser+radiusclient-ng+Freeradius+IAS

2008-07-30 Thread António Rio Costa
Thanks, for the idea. I will try to understand what is going wrong
using wireshark.


> Date: Wed, 30 Jul 2008 08:38:14 +0200
> From: Alan DeKok <[EMAIL PROTECTED]>
> Subject: Re: Openser+radiusclient-ng+Freeradius+IAS
> To: FreeRadius users mailing list
>
> Message-ID: <[EMAIL PROTECTED]>
> Content-Type: text/plain; charset=ISO-8859-1
>
> Antonio Rio Costa wrote:
> > 1 Can radiusclient-ng authenticate in IAS  If so how? I've tried it
> > and IAS says that there is an malformed radius message.
>
>  Use wireshark to grab copies of the packets.  Put the pcap files on a
> web page, and post the URL here.
>
> > 2 Putting freeradius in the midlle of the radiusclient-ng and IAS shoud
> > he act as a proxy between the radiusclient-ng and the IAS? this
> > configuration works? has anyone done it?
>
>  Try it.  It's not hard.
>
>  Or, use freeradius-client.  There have been a number of bug fixes to
> the code.
>
>  Alan DeKok.
>
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Openser+radiusclient-ng+Freeradius+IAS

2008-07-29 Thread Alan DeKok
António Rio Costa wrote:
> 1 Can radiusclient-ng authenticate in IAS  If so how? I've tried it
> and IAS says that there is an malformed radius message.

  Use wireshark to grab copies of the packets.  Put the pcap files on a
web page, and post the URL here.

> 2 Putting freeradius in the midlle of the radiusclient-ng and IAS shoud
> he act as a proxy between the radiusclient-ng and the IAS? this
> configuration works? has anyone done it?

  Try it.  It's not hard.

  Or, use freeradius-client.  There have been a number of bug fixes to
the code.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Openser+radiusclient-ng+Freeradius+IAS

2008-07-29 Thread António Rio Costa
Hi all,
I'm trying to put toghether one way to register softphones into openser
doing the users authentication in IAS.
I would like to put some questions into the list in way to clear out my
doubts.
1 Can radiusclient-ng authenticate in IAS  If so how? I've tried it and
IAS says that there is an malformed radius message.
2 Putting freeradius in the midlle of the radiusclient-ng and IAS shoud he
act as a proxy between the radiusclient-ng and the IAS? this configuration
works? has anyone done it?
Thanks in advance for all the help that anyone can give
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Need help with Radiusclient-ng

2008-05-30 Thread Alan DeKok
Pete Kay wrote:
> I am modifiying radiusclient-ng's radexample.c and there are two
> questions I have:
> 1. How to change the radiusclient setting so it is sending in password
> in Digest format?

  You need to implement digest authentication in the client.  This
requires writing code.

>  Since my freeradius is configured to use Digest as
> Auth-Type, I need to use the Digest Auth-type but radiusclient is
> sending in password in Cleartext out-of-box.

  If you're forcing Auth-Type in FreeRADIUS, that's wrong.  You don't
need to do that.  It breaks OTHER kinds of authentication, as you have seen.

> 2. How to send additinal attribute or user-defined attribute from
> radclient.c?

  See the API.

>  I need to use that additional attribute to tell freeradius
> what table to use for authentication. 

  Don't.  Configure a policy on the server that figures it out from the
*normal* contents of the packet.  e.g. User-Name, NAS-IP-Address, etc.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Need help with Radiusclient-ng

2008-05-29 Thread Pete Kay
Hi,
I am trying to write a client using Radiusclient-ng to authenticate with
Freeradius.  I understand this question may be related to radiusclient-ng
speficially, but I can't find any radiusclient-ng specific mailing list, so
I just hope someone may be able to help me out here.

I am modifiying radiusclient-ng's radexample.c and there are two questions I
have:
1. How to change the radiusclient setting so it is sending in password in
Digest format?  Since my freeradius is configured to use Digest as
Auth-Type, I need to use the Digest Auth-type but radiusclient is sending in
password in Cleartext out-of-box.

2. How to send additinal attribute or user-defined attribute from
radclient.c?  I need to use that additional attribute to tell freeradius
what table to use for authentication.

Any help and suggestion will be greatly appreciated.

Regards,
Pete
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RadiusClient

2007-07-19 Thread Sofia Silva
I'm trying to authenticate a linux client against a radius server. I've 
implemented the radius server with freeradius and i've tested it with a 
cisco client and it worked, but, unfortunately, i'm having seriuos problems 
to authenticate the linux client using RadiusClient.
I'm running the server in debug mode and when i run  the password the server shows 
it's not plain text, it's sth like "\211pe;\336." so i thought it could 
be a problem with the secret word. However, i've checket it in the "servers" 
file (at the client) and in the "clients.conf" file (at the server) and it's 
the same.
Sth i found is that i don't seem to have the file radius.seq in /var/run, i 
would like to create it but i don't know what the sequence number is and i 
don't know what the format of the file should be.
I'd appreciate it a lot if sb could help me
Sofia

_
¿Cuánto vale tu auto? Tips para mantener tu carro. ¡De todo en MSN Latino 
Autos! http://latino.msn.com/autos/

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


how to config radiusclient!

2005-09-29 Thread zhangshuai
Dear all,


I wish to use softphone X-lite on SER and radius in db_mode. When I installed 
both freeradius 1.0.4 and radiusclient 0.4.3 on the same server which ser 
0.8.14 has installed on, I could log in X-lite through radius authorization. 
And now I want radiusclient (on server A) to send the request to a remote 
radius server (on server B) to realize authorization. I have changed those 
config files: /usr/local/etc/radiusclient/servers, 
/usr/local/etc/radiusclient/radiusclient.conf and 
/usr/local/etc/raddb/clients.conf as the document 
(http://www.iptel.org/ser/doc/ser_radius/ser_radius.html#AEN193) did. Then I 
test the radius server as the above document said on server A: radclient -f 
digest server B auth testing123 and I received expected replied message from 
server B.

But when I log in x-lite (UA), there are error messages:

Sep 29 17:11:06 localhost ser[4408]: rc_ip_hostname: couldn't look up host by 
addr: DA61FC29
Sep 29 17:11:06 localhost ser[4408]: rc_send_server: no reply from RADIUS 
server unknown:1812

And the number "DA61FC29" is exactly the hexadecimal value of the ip address of 
radius server.

How come? Did I mis-config anything?

Many thanks for your reply!


Shuai
http://www.goldentek.biz


- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


radiusclient

2005-05-30 Thread s s
i want to build up a dial up authenticating system. So  i downloaded freeradius1.0.2.tar from freeradius.org. Then i wanted to build a radiusclient using jradiusclient API. I wanted to use a PC as radius client. anybody has any idea of how to build it using API. If someone has done it then please reply.
 
also if other alternatives are present then please  post your suggestions.
 
thank you__Do You Yahoo!?Tired of spam?  Yahoo! Mail has the best spam protection around http://mail.yahoo.com - 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

freeradius + radiusclient problems.

2005-04-07 Thread Alex
Hi guys I have a strange problem and i tried to work on that without any success, so i need yours help  i installed ser, freeradius-1.0.2, radiusclient-0.4.8.  I am trying to authenticate ser users through radius (mysql).  inside my ser.cfg ---  if (method=="REGISTER") { log(1, "REGISTER: Authenticating user\n"); if (!radius_www_authorize(""))    
 { log(1, "REGISTER: challenging user\n"); www_challenge("", "0"); break; }; #setflag(1); save("location");
 sl_send_reply("200","ok"); break; }; --  the problem that i don't see any requests coming to the radius server.  i checked the freeradius installation with "radtest" and it's working correctly (the authentication is going through the mysql ).also checked with radtest from different host and it's working ,but when it's coming to ser on localhost, i can't see anything happens in the radius.furthermore i know it's going inside this "if" because i can see the logs and i see the "REGISTER:challenging user" message. the only problem what  i don't see anything at radius log. it's seems like radiusclient from ser not talking to the radius server, can it be any "version" problem ??    Thank you
 guys for any help.
 __Do You Yahoo!?Tired of spam?  Yahoo! Mail has the best spam protection around http://mail.yahoo.com 

Re: freeradius - radiusclient - ser server

2005-04-04 Thread Alex
Alan thank you for your fast reply.Alan DeKok <[EMAIL PROTECTED]> wrote:
Alex <[EMAIL PROTECTED]>wrote:> I am trying to compile modules under ser.> the name of the module is auth_radius.There is no such module in the FreeRADIUS source code.Please ask your question on another list.Alan DeKok.- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html__Do You Yahoo!?Tired of spam?  Yahoo! Mail has the best spam protection around http://mail.yahoo.com 

Re: freeradius - radiusclient - ser server

2005-04-04 Thread Alan DeKok
Alex <[EMAIL PROTECTED]> wrote:
> I am trying to compile modules under ser.
> the name of the module is auth_radius.

  There is no such module in the FreeRADIUS source code.

  Please ask your question on another list.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


freeradius - radiusclient - ser server

2005-04-04 Thread Alex
I am trying to compile modules under ser.
the name of the module is auth_radius.
 
and i am receiving this error.
make../../Makefile.modules:21: "you should run make from the main ser directory"gcc -fPIC -DPIC -g -O9 -funroll-loops  -Wcast-align  -Wall  -minline-all-stringops -malign-double -falign-loops -mcpu=athlon    -DNAME='"auth_radius.so"' -DVERSION='"0.8.14"' -DARCH='"i386"' -DOS='"linux"' -DCOMPILER='"gcc 3.2"' -D__CPU_i386 -D__OS_linux -DCFG_DIR='"/usr/local/etc/ser/"' -DPKG_MALLOC -DSHM_MEM  -DSHM_MMAP -DDNS_IP_HACK -DUSE_IPV6 -DUSE_TCP -DDISABLE_NAGLE -DF_MALLOC  -DFAST_LOCK -DADAPTIVE_WAIT -DADAPTIVE_WAIT_LOOPS=1024  -DHAVE_GETHOSTBYNAME2 -DHAVE_UNION_SEMUN -DHAVE_SCHED_YIELD -DHAVE_MSG_NOSIGNAL -DHAVE_MSGHDR_MSG_CONTROL -I/usr/local/include -c authrad_mod.c -o authrad_mod.oauthrad_mod.c: In function `mod_init':authrad_mod.c:111: `DICT_VENDOR' undeclared (first use in this function)authrad_mod.c:111: (Each undeclared identifier is reported only onceauthrad_mod.c:111: for each function it appears
 in.)authrad_mod.c:111: `vend' undeclared (first use in this function)authrad_mod.c:135: warning: assignment makes pointer from integer without a castauthrad_mod.c:140: too many arguments to function `rc_conf_str'authrad_mod.c:140: too many arguments to function `rc_read_dictionary'authrad_mod.c:145: warning: implicit declaration of function `rc_dict_findvend'authrad_mod.c:163: too many arguments to function `rc_dict_findattr'authrad_mod.c:163: too many arguments to function `rc_dict_findval'make: *** [authrad_mod.o] Error 1
 
 
Any help will be appreciated.
thanks
		Do you Yahoo!? 
Make Yahoo! your home page