RE: EAP documentation

2002-07-10 Thread Henrik Eriksson
From: Raghu [mailto:[EMAIL PROTECTED]] Sent: Tuesday, July 09, 2002 7:35 PM AFAIK the authentication server and supplicant agree on a shared session secret, but that is not the actual WEP unicast key to be used between the AP and STA. I believe that the key distribution actually do

is there a way to select users file based on called_id or nas_ip

2002-07-10 Thread Martin Shears
Hi all I am using freeRADIUS 0.6. I have two problems approaching me in the future which I am sure I can hack code to solve but maybe someone has a suggestion or two. I need to be able to select users file to authenticate from based on called_id and then more into the future I want to be

Re[2]: SP/ROUTING: Re: HELP!.....Using Berkeley DBM

2002-07-10 Thread Andrei Koulik
Hello. I not often read this list, so can't answer question related to dbm module in proper time. Here new version of rlm_dbm module documentation written by Bjorn Nordbo. Please apply this version. Now I can answer subject questions. Wednesday, July 10, 2002, 12:07:15 AM, Alan DeKok wrote:

Re: COMPARE module

2002-07-10 Thread Marcello Lupo
Hi, I need it.. I need a way to let a user to login, with his user password, only from 1 telephone line ( for a flat service). And if it is possible that after 2 hours of contiguous connection he is kicked out and can't reconnect for 10 minutes. Is it possible?? Thank you, Bye Marcello

Newbie: compiling radius with pam support

2002-07-10 Thread Wim
Hello, I'm trying to compile freeradius 0.6 with pam support. I looked in /doc for the options and I couldn't find anything that could help me... I guess i have to run: ./configure --with-static-modules=pam some of the output is: configure: warning: silently not building rlm_pam. configure:

Re: Newbie: compiling radius with pam support

2002-07-10 Thread Frank Cusack
On Wed, Jul 10, 2002 at 10:23:34AM +0200, Wim wrote: Hello, I'm trying to compile freeradius 0.6 with pam support. I looked in /doc for the options and I couldn't find anything that could help me... I guess i have to run: ./configure --with-static-modules=pam

FreeRADIUS Proxy and MS IAS

2002-07-10 Thread Dimitar Peikov
Hi, Did someone tryed to proxy to MS IAS on 2K Server? I've got bad success about that and need some help, or example on this. If I point directly from NAS to either FreeRADIUS ot MS IAS authentication goes alright but when try to proxy MS IAS via FreeRADIUS I get errors on MS Event viewer.

How to port FreeRadius?

2002-07-10 Thread Alberto
Hi, I am trying to install freeradius in Darwin BSD OS (FreeBSD better cmpatibility). But I have problems... Following the INSTALL instructions I am not sucessful. Is there any special thing to do freeradius install or compile in my OS? Could anybody help me?? Follow my installation log:

Re: Newbie: compiling radius with pam support

2002-07-10 Thread Wim
Frank Cusack wrote: On Wed, Jul 10, 2002 at 10:23:34AM +0200, Wim wrote: Hello, I'm trying to compile freeradius 0.6 with pam support. I looked in /doc for the options and I couldn't find anything that could help me... I guess i have to run: ./configure --with-static-modules=pam

Re: Success with 0.6 on BSDI 4.2

2002-07-10 Thread Frank Cusack
On Sat, Jul 06, 2002 at 11:02:02AM -0600, Spike Ilacqua wrote: The remaining problems all relate to rlm_x99_token: It can't find the SSL include files so added -I/usr/local/ssl/include to src/modules/rules.mak x99.h includes inttypes.h, which BSDI 4.2 does not have, commented it out.

Re: Success with 0.6 on BSDI 4.2

2002-07-10 Thread Frank Cusack
On Sun, Jul 07, 2002 at 10:42:13AM +, Michael Bailey wrote: On Sat, Jul 06, 2002 at 11:02:02AM -0600, Spike Ilacqua wrote: The remaining problems all relate to rlm_x99_token: It can't find the SSL include files so added -I/usr/local/ssl/include to src/modules/rules.mak I also

Server startup sql

2002-07-10 Thread Mozzi
Hallo all When starting my newly compiled(freeradius-0.5) radius server I get this radiusd: Starting - reading configuration files ... radiusd: radiusd.conf: SQL modules aren't allowed in 'authenticate' sections -- they have no such method. When running ./configure --help I see no option to

Re: Server startup sql

2002-07-10 Thread Nikodim Nikodimov
version 0.5 of the free-radius doesn't support sql module in the authenticate section...remove it from there. NN - Original Message - From: Mozzi [EMAIL PROTECTED] To: Radius [EMAIL PROTECTED] Sent: Wednesday, July 10, 2002 2:04 PM Subject: Server startup sql Hallo all When starting

Re: Server startup sql

2002-07-10 Thread Mozzi
How does it authenticate from Mysql then ?? Or am I missing something? Mozzi Nikodim Nikodimov wrote: version 0.5 of the free-radius doesn't support sql module in the authenticate section...remove it from there. NN - Original Message - From: Mozzi [EMAIL PROTECTED] To: Radius

Re: Server startup sql

2002-07-10 Thread Nikodim Nikodimov
punt sql in authorize section in radiusd.conf and put driver = rlm_sql_mysql in sql.conf file NN - Original Message - From: Mozzi [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Wednesday, July 10, 2002 2:42 PM Subject: Re: Server startup sql How does it authenticate from Mysql then ??

freeradius 0.6 not authenticating

2002-07-10 Thread Mozzi
Hallo all After some trials and tribulations I compiled and installed freeradius-0.6 It starts up and initiates with my mysql server(rlm_sql: Connected new DB handle, #49). Then goes into sleep mode(nothing to do) When I run radtest on the server itself I get [root@ais-rad01 raddb]# radtest

converting detail files into a db

2002-07-10 Thread Stefan Immel
Has anybody a tool to convert old details files into the current sql schema ??? -- Stefan Immel |N|O|C Network Operation Center -+-+-+--- | Grove Auf der Stuecke 6Tel. +49 2773-8167-0 35708 Haiger / Germany

Re: freeradius and mysql replication question

2002-07-10 Thread Chris Parker
At 07:40 PM 7/9/2002 -0700, Koyabu, Ken wrote: I looked up Colin Bloch's documentation, and I managed to setup mysql replication option. I'm running two identical freeradius 0.6 with mysql 3.23.38 radius database on two separate FreeBSD 4.5 servers, and our ISP is proxing their radius

Re: How to port FreeRadius?

2002-07-10 Thread Chris Parker
At 05:39 AM 7/10/2002 -0300, Alberto wrote: Hi, I am trying to install freeradius in Darwin BSD OS (FreeBSD better cmpatibility). But I have problems... Following the INSTALL instructions I am not sucessful. Is there any special thing to do freeradius install or compile in my OS? Could

RE: How to port FreeRadius?

2002-07-10 Thread Chris Parker
At 11:24 AM 7/10/2002 -0400, Funk, Michael wrote: I'm seeing a lot of these in my Radius Log What does it mean??? NOTE: I omitted the name of Dial-Up Provider, so the DialUp Provider is a hack on the original name! SNIP Error: Dropping conflicting authentication packet from client DialUp

RE: How to port FreeRadius?

2002-07-10 Thread Funk, Michael
I'm seeing a lot of these in my Radius Log What does it mean??? NOTE: I omitted the name of Dial-Up Provider, so the DialUp Provider is a hack on the original name! SNIP Error: Dropping conflicting authentication packet from client DialUp Provider:1651 - ID: 0 /SNIP -Original

RE: How to port FreeRadius?

2002-07-10 Thread Funk, Michael
All users. I get tons of good ones littered with that error between them... -Original Message- From: Chris Parker [mailto:[EMAIL PROTECTED]] Sent: Wednesday, July 10, 2002 10:26 AM To: [EMAIL PROTECTED] Subject: RE: How to port FreeRadius? At 11:24 AM 7/10/2002 -0400, Funk,

Ascend dictionary file correction

2002-07-10 Thread Johnsen, Lasse
Hello, According to this file: https://support.lucent.com/cgi-bin/gx.cgi/GUIDGX-{6949ce8f-d22f-11d2-a303-00 c04f72f8ac}/Live/Product/terminator/General/Documentation/dslradius-710.pdf I believe something like the following patch should be applied to the dictionary.ascend file ---

RE: How to port FreeRadius?

2002-07-10 Thread Chris Parker
At 11:36 AM 7/10/2002 -0400, Funk, Michael wrote: All users. I get tons of good ones littered with that error between them... May just be a timeout issue. It shouldn't necesarily be an indication of a problem, unless the same users are reporting trouble connecting. If the Dial-Up

Re: Re[2]: SP/ROUTING: Re: HELP!.....Using Berkeley DBM

2002-07-10 Thread Alan DeKok
Andrei Koulik [EMAIL PROTECTED] wrote: Here new version of rlm_dbm module documentation written by Bjorn Nordbo. Please apply this version. Added, thanks. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS Proxy and MS IAS

2002-07-10 Thread Alan DeKok
Dimitar Peikov [EMAIL PROTECTED] wrote: If I point directly from NAS to either FreeRADIUS ot MS IAS authentication goes alright but when try to proxy MS IAS via FreeRADIUS I get errors on MS Event viewer. Which are...? Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Server startup sql

2002-07-10 Thread Alan DeKok
Mozzi [EMAIL PROTECTED] wroteL How does it authenticate from Mysql then ?? You pull the authentication information (i.e. password) FROM MySQL. You do NOT authenticate the user TO the mySQL server. The 'authenticate' section in the server is meant to authenticate the user. If you want to

Re: Newbie: compiling radius with pam support

2002-07-10 Thread Alan DeKok
Wim [EMAIL PROTECTED] wrote: I ran configure withou options, the warnings that says configure: warning: silently not building rlm_pam is still there... but the make and make install commands are successfull! Yes and the rlm_pam module isn't installed. Alan DeKok. - List

Re: freeradius 0.6 not authenticating

2002-07-10 Thread Alan DeKok
Mozzi [EMAIL PROTECTED] wrote: Why is it rejecting me ? Have you read the FAQ? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS Proxy and MS IAS

2002-07-10 Thread Dimitar Peikov
On Wed, 10 Jul 2002 12:00:18 -0400 Alan DeKok [EMAIL PROTECTED] wrote: Dimitar Peikov [EMAIL PROTECTED] wrote: If I point directly from NAS to either FreeRADIUS ot MS IAS authentication goes alright but when try to proxy MS IAS via FreeRADIUS I get errors on MS Event viewer. Which

Re: FreeRADIUS Proxy and MS IAS

2002-07-10 Thread Alan DeKok
Dimitar Peikov [EMAIL PROTECTED] wrote: In this case NAS is MS RAS on 2k Server. This is explanation of error event 'A malformed request was received from= client . The data is the packet.' OK, it may be bugs in tunnelling code, which was fixed in 0.6. If you're running an earlier

FreeRADIUS 0.6 - Escaping '/' for SQL?

2002-07-10 Thread Karl Pielorz
Hi All, I just went from FreeRADIUS 0.5 to 0.6, only to find all my users being rejected... A quick run in debug mode looking at the changelog/cvs - I found that the '/' character in our usernames was being escaped into a 'mime encoded' equivalent. I'll confess to not knowing if '/' is

Re: FreeRADIUS 0.6 - Escaping '/' for SQL?

2002-07-10 Thread Alan DeKok
Karl Pielorz [EMAIL PROTECTED] wrote: I just went from FreeRADIUS 0.5 to 0.6, only to find all my users being rejected... A quick run in debug mode looking at the changelog/cvs - I found that the '/' character in our usernames was being escaped into a 'mime encoded' equivalent. Yes.

SQL fail-over patch

2002-07-10 Thread Alan DeKok
CheongMeng submitted a patch to allow the SQL module to fail-over. I've reformatted it, and put it up at: http://www.striker.ottawa.on.ca/~aland/rlm_sql.diff Right now, if the SQL module cannot connect to the server, it returns 'OK'. This means it's impossible to have two SQL modules,

Re: Success with 0.6 on BSDI 4.2

2002-07-10 Thread Spike Ilacqua
I've added a test to configure that should avoid compiling x99_token if inttypes.h isn't found. Please let me know if it works for you. I'll give this a try, but as far as I can tell all inttypes.h is needed for is the uint32_t typedef. It might be cleaner to just typedef that if inttypes.h

Re: Success with 0.6 on BSDI 4.2

2002-07-10 Thread Alan DeKok
Spike Ilacqua [EMAIL PROTECTED] wrote: I'll give this a try, but as far as I can tell all inttypes.h is needed for is the uint32_t typedef. It might be cleaner to just typedef that if inttypes.h is not found. That's exactly what the top-level 'configure' script does. See

Re: Success with 0.6 on BSDI 4.2

2002-07-10 Thread Frank Cusack
On Wed, Jul 10, 2002 at 12:25:09PM -0600, Spike Ilacqua wrote: I've added a test to configure that should avoid compiling x99_token if inttypes.h isn't found. Please let me know if it works for you. I'll give this a try, but as far as I can tell all inttypes.h is needed for is the

Re: COMPARE module

2002-07-10 Thread Alexandre Strube
On Wed, 10 Jul 2002 10:42:06 +0200, [EMAIL PROTECTED] wrote: You don't need this new module to do that. I do this using Calling-Station-Id attribute on mysql's radcheck table. The other one I was unable to do here. I need it.. I need a way to let a user to login, with his user password, only

Re: HELP!.....Using Berkeley DBM

2002-07-10 Thread Brad Crotchett
ndrei Koulik [EMAIL PROTECTED] wrote: Here new version of rlm_dbm module documentation written by Bjorn Nordbo. Please apply this version. Added, thanks. Alan DeKok. Yeah, thanks a lot...that is helpful. I have added the following lines to radiusd.conf: dbm {

Re: HELP!.....Using Berkeley DBM

2002-07-10 Thread Alan DeKok
Brad Crotchett [EMAIL PROTECTED] wrote: Yeah, thanks a lot...that is helpful. I have added the following lines to radiusd.conf: ... under the modules section. *in* the modules section. Now when I start radius I get the following error: ERROR: Cannot find a configuration entry

RE: SP/ROUTING: Re: HELP!.....Using Berkeley DBM

2002-07-10 Thread Brad Crotchett
*in* the modules section. Ok, then what parameters would it be looking for? I have told it the path to the dbm file, what else would it need? should be it. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List

Re: converting detail files into a db

2002-07-10 Thread Mattt
There are dozens of perl scripts floating around that can parse a detail file - find one that's close to your needs and modify it to suit... I did exactly this, and tried several perl parsers - and then, in usual form, went and wrote one out in PHP from scratch... On Wed, 2002-07-10 at 23:46,

Re: Success with 0.6 on BSDI 4.2

2002-07-10 Thread Frank Cusack
On Wed, Jul 10, 2002 at 01:43:51PM -0600, Spike Ilacqua wrote: That's true, but if you lack inttypes.h you lack other C99 features and I don't want to worry about it. Call me crazy but if a module compiles now I don't think it should be exclude it because there *might* be a future

Re: SP/ROUTING: Re: HELP!.....Using Berkeley DBM

2002-07-10 Thread Alan DeKok
Brad Crotchett [EMAIL PROTECTED] wrote: Ok, then what parameters would it be looking for? I have told it the path to the dbm file, what else would it need? I don't know, sorry. All I know about it is what I've read in the module documentation. Alan DeKok. - List

Re: SP/ROUTING: Re: HELP!.....Using Berkeley DBM

2002-07-10 Thread J.J.Bailey
Ok, then what parameters would it be looking for? I have told it the path to the dbm file, what else would it need? I don't know, sorry. All I know about it is what I've read in the module documentation. A few months ago I looked into dbm support too. I wasn't sure it was working, so

Re: SP/ROUTING: Re: HELP!.....Using Berkeley DBM

2002-07-10 Thread Alan DeKok
J.J.Bailey [EMAIL PROTECTED] wrote: A few months ago I looked into dbm support too. I wasn't sure it was working, so I started reading the code. This is from today's snapshot, unchanged since earlier: muttley# find . -print | xargs fgrep use_dbm ./src/include/radiusd.h:extern int

Re: EAP documentation

2002-07-10 Thread Raghu
Henrik Eriksson wrote: From: Raghu [mailto:[EMAIL PROTECTED]] Sent: Tuesday, July 09, 2002 7:35 PM If you have already tested it I would like to take your point. If I got your point right then, 1. Authentication server generates Session Secret, but not Session Key, and sends it to both

about reply packets

2002-07-10 Thread wheatly
hi how can i add the session-timeout and idle-timeout into the accept packet? wheatly shiICQ#: 10499351More ways to contact me http://wwp.icq.com/10499351

Re: freeradius and mysql replication question

2002-07-10 Thread CheongMeng
Hi, another way is to write a script to pull all acct stored at the slave/frontend sql server, then insert into the master/backend sql server. In that case, the master sql server will always hv all the acct. If still feel insecure, try replicating the master sql server to another backup server