[PacketFence-users] Known WMI YUM Issue, any one know of a Workaround?

2018-11-15 Thread Matthew Knott via PacketFence-users
Hi All,

I'm hitting this Issue and have no Idea how to work around it.  I just need to 
get the openvas-cli on the packetfence box so I can pass the scanning over to a 
second server to scan the nodes and I'm hitting this exact bug.
https://github.com/inverse-inc/packetfence/issues/1703

  There is no workaround that I can see in this issue except that it has been 
set to be addressed in 8.1 or 8.2.

Im running 8.2 but still having the same issue.

Anyone got any idea's?


Thanks


Matthew






Matthew Knott
IT Network & Security Administrator
E. matthew.kn...@jbssa.com.au

[JBS Australia]
T.  07 3810 2269
M.  0477733185
F.  07 3816 0535




JBS Australia
1 Lock Way, Riverview QLD 4303
P.O. Box 139 Booval Qld 4304


jbssa.com.au  .  
LinkedIn



Important Notice:

The contents of this electronic message and any attachments are intended only 
for the addressee and may contain legally privileged or confidential 
information. They may be only used for the purposes for which they were 
supplied. If you are not the addressee, you are notified that any transmission, 
distribution, downloading, printing or photocopying of the contents of this 
message or attachments is strictly prohibited. Any privilege and/or 
confidentiality attached to this message and attachments is not waived, lost or 
destroyed by reason of mistaken delivery to you. If you have received this 
message in error you should notify the sender by return e-mail or telephone +61 
7 3810 2100, and destroy all copies of the message and any attachments.
___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


[PacketFence-users] Reg VLAN and gaming devices

2018-11-15 Thread Wifi Guy via PacketFence-users
Hi All,

Me again! :)

I have Reg VLAN (open SSID with Mac-Auth, CoA to reassign role, returing
filter ID to APs) setup with no issues. I am able to use CoA to assign
devices into a role, Im using a combination of 802.1X and guest feature
this works great!

But what is the best solution for gaming devices, specifically PS4? If
possible I want them to be on the registration SSID under a gaming role.
Would that be able to work.!?  I see you can do violation rules to auto
assign the device into a role. I seem to have that element working.
However, the device will not connect. Is this because Mac-Auth is not
supported? Is there a way to bypass this for these devices?
___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] PF 8.2 and HP Procurve 2824

2018-11-15 Thread Enrico Becchetti Gmail via PacketFence-users

Hi all,


Il 15/11/2018 13:52, Nicolas Quiniou-Briand via PacketFence-users ha 
scritto:

Hello Enrico,

On 2018-11-15 10:15 a.m., Enrico Becchetti Gmail via PacketFence-users 
wrote:

Dear All,
I'm a newbie in PF and I'd like to make some tests to use it for 802.1x
authentication and Freeradius to store users, but my old equipment 
aren't supported

so what are you think about it ?


Welcome on list !


thanks to everybody

Can I use Procurve 2824 or not ? PF supports 2600 and 2500 , so which is
the switch that I can use to make a test ?


I will let Fabrice give you an answer.
Did you try with some of these modules ?

both of them and it's seems that the first step of 802.1x works fine 
because ports are blocked
and procurve asks to supplicant login info ,Procurve uses Radius inside 
PF,  but...

Can PF forward user verification to external Radius server ?


Yes, you need to configure a RADIUS source.
the main issue is this radius inside PF because it doesn't forward any 
authentication request to my

"internal" official freeradius server.

In fact PF  would be only as proxy but now it try the authentication 
user and it fail.


Thanks a lot !
Best Regards
Enrico



___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] Error trying to upgrade from 8.1 to 8.2

2018-11-15 Thread Virginie Girou via PacketFence-users

Hello,

Yes, i have a pb with my VM so I went back on a backup and it's getting 
better !


Regards,

Virginie Girou
Equipe systeme
DSI - UT1 Capitole
Tel : +33 (0)5.61.63.39.19

Le 14/11/2018 04:22, Durand fabrice via PacketFence-users a écrit :

Hello Virginie,

it's not related to PacketFence, it looks that you have an issue with 
your python modules on your system.


Regards

Fabrice

Le 18-11-13 à 05 h 14, Virginie Girou via PacketFence-users a écrit :

Hi,

I try to upgrade my packetfence from 8.1 to 8.2.
I first stop pfcmd and packetfence-config and when i update i have 
this following message :



# /usr/local/pf/bin/pfcmd service pf stop
# service packetfence-config stop

#yum update packetfence --enablerepo=packetfence

Traceback (most recent call last):
  File "/usr/bin/yum", line 4, in 
import yum
  File "/usr/lib/python2.7/site-packages/yum/__init__.py", line 62, 
in 

import rpmsack
  File "/usr/lib/python2.7/site-packages/yum/rpmsack.py", line 38, in 


import yum.depsolve
  File "/usr/lib/python2.7/site-packages/yum/depsolve.py", line 30, 
in 

from transactioninfo import TransactionMember
  File "/usr/lib/python2.7/site-packages/yum/transactioninfo.py", 
line 32, in 

from sqlitesack import YumAvailablePackageSqlite
  File "/usr/lib/python2.7/site-packages/yum/sqlitesack.py", line 31, 
in 

from sqlutils import executeSQL, sql_esc, sql_esc_glob
  File "/usr/lib/python2.7/site-packages/yum/sqlutils.py", line 170, 
in 

if sqlite.version_info[0] > 1:
AttributeError: 'module' object has no attribute 'version_info'


Do you have any idea ?

Thank you.

Regards,




___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

!DSPAM:67760,5beb955038739658187727!






___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] PF 8.2 and HP Procurve 2824

2018-11-15 Thread Nicolas Quiniou-Briand via PacketFence-users

Hello Enrico,

On 2018-11-15 10:15 a.m., Enrico Becchetti Gmail via PacketFence-users 
wrote:

Dear All,
I'm a newbie in PF and I'd like to make some tests to use it for 802.1x
authentication and Freeradius to store users, but my old equipment 
aren't supported

so what are you think about it ?


Welcome on list !


Can I use Procurve 2824 or not ? PF supports 2600 and 2500 , so which is
the switch that I can use to make a test ?


I will let Fabrice give you an answer.
Did you try with some of these modules ?


Can PF forward user verification to external Radius server ?


Yes, you need to configure a RADIUS source.
--
Nicolas Quiniou-Briand
n...@inverse.ca  ::  +1.514.447.4918 *140  ::  https://inverse.ca
Inverse inc. :: Leaders behind SOGo (https://sogo.nu), PacketFence 
(https://packetfence.org) and Fingerbank (http://fingerbank.org)



___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


Re: [PacketFence-users] SSL and Clustering

2018-11-15 Thread Nicolas Quiniou-Briand via PacketFence-users

Hello,

On 2018-11-15 10:38 a.m., Wifi Guy via PacketFence-users wrote:
However, im looking for some advice when trying to upload an SSL 
certificate for registration and https admin. What is the best process? 


Command line !

Is a certain SSL cert required (wildcard as each server has a different 
hostname)?


For the captive portal (registration), web browsers will check if the 
certificate match the DNS name use to reach PF. This DNS name depends on 
following settings:

- general.hostname
- general.domain
in pf.conf.

So, you just need one SSL certificate that match this DNS name (the same 
on all cluster members).



 Is this replicated over the cluster or a manual process?


See 
https://packetfence.org/doc/PacketFence_Clustering_Guide.html#_resynchronizing_the_configuration_manually


--
Nicolas Quiniou-Briand
n...@inverse.ca  ::  +1.514.447.4918 *140  ::  https://inverse.ca
Inverse inc. :: Leaders behind SOGo (https://sogo.nu), PacketFence 
(https://packetfence.org) and Fingerbank (http://fingerbank.org)



___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


[PacketFence-users] SSL and Clustering

2018-11-15 Thread Wifi Guy via PacketFence-users
Hi All,

I have setup a cluster of 3 servers, which seems to work great!

However, im looking for some advice when trying to upload an SSL
certificate for registration and https admin. What is the best process? Is
a certain SSL cert required (wildcard as each server has a different
hostname)? Is this replicated over the cluster or a manual process?

Thanks community

Wifiguy
___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


[PacketFence-users] PF 8.2 and HP Procurve 2824

2018-11-15 Thread Enrico Becchetti Gmail via PacketFence-users

Dear All,
I'm a newbie in PF and I'd like to make some tests to use it for 802.1x
authentication and Freeradius to store users, but my old equipment 
aren't supported

so what are you think about it ?
Can I use Procurve 2824 or not ? PF supports 2600 and 2500 , so which is
the switch that I can use to make a test ?
Can PF forward user verification to external Radius server ?
Thanks a lot !
Best Regards
Enrico



___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users