using an external program for preauth?

2002-11-11 Thread Adrian Chadd
Hi, I'm a little stumped, but its entirely possible the answer is staring me in the face. I have a radius proxy server which has a bunch of realms configured. I would like to be able to sit a program in the authentication/authorisation chain somewhere which lets me auth a user via some alterna

RE: Free 802.1X supplicant software for Win2K?

2002-11-11 Thread Glynn Taylor
Try here: http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/8021xc lient.asp --- Secure Wireless Networking Now --- Glynn Taylor President WiFiConsulting, Inc. Web: http://www.WiFiConsulting.com --- Secure Wireless Networking Now ---

Re: Free 802.1X supplicant software for Win2K?

2002-11-11 Thread Sarick
Hi Jeffery: Thanks for your kind help. But I am looking for the free windows supplicant for permanent use. Can anyone help me? Regards Sarick - Original Message - From: "Jeffery Huang" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Monday, November 11, 2002 1:14 PM Subject: Re: Free 80

certificate extension key usage!

2002-11-11 Thread Jeffery Huang
Is extension key usage just use in windows xp or all the other also should use this ! -- Regard, Jeffery Huang iMining Technology Inc., 8F-4, No.432, Sec.1 Keelung Rd., Taipei,Taiwan Tel:886-2-27235122 ext 20 Fax:886-2-27232287 http://www.imining.com.tw email:[EMAIL PROTECTED] w - List info/su

Re: Configuring without libltdl

2002-11-11 Thread Alan DeKok
Dave Wreski <[EMAIL PROTECTED]> wrote: > So you don't have libltdl but do have libtool installed? Huh? No. I don't have either installed. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Fw: MySQL-Proxy-Exec-Program-Wait

2002-11-11 Thread Alan DeKok
"Mike Dain" <[EMAIL PROTECTED]> wrote: > I've tried adding: > > DEFAULT Exec-Program-Wait = "/shell/example" > > to the users file. What's the point of writing documentation (what little there is), if it's not going to be read? What's the point of adding debugging, warning, and erro

RE: freeradius and tls

2002-11-11 Thread Jeffery Huang
Thank you for your help! I have resolve this problem now! :) ¦b ¶g¤@, 2002-11-11 23:35, McKay, Raymond ¼g¹D¡G > > > I use certificate to authorize user! why it become auth: type "system"? > > and I have use certificate! why I need password? :( > > It looks like you may have some configuration

freeradius and tls

2002-11-11 Thread Jeffery Huang
Hi! guys, I use freeradius via certificate got the following error message: ./radiusd: relocation error: /usr/local/radiusd/lib/rlm_eap_tls-0.8-pre.so: undefined symbol: SSL_set_msg_callback Why it occur! how do I resolve the problem! -- Regard, Jeffery Huang iMining Technology Inc., 8F-4, N

Re: Fw: MySQL-Proxy-Exec-Program-Wait

2002-11-11 Thread Mike Dain
I've tried adding: DEFAULT Exec-Program-Wait = "/shell/example" to the users file. I also uncommented "files" in the "authorize" section of radius.conf. After restarting the radius server with these set (and the example from /scripts/exec-program-wait) the example script is still not be

Re: Questing re: conditional syntax for variables

2002-11-11 Thread Malcolm Caldwell
On Tue, 2002-11-12 at 03:51, Alan DeKok wrote: > Malcolm Caldwell <[EMAIL PROTECTED]> wrote: > > This works find but it does not give the level of redundancy I wish. I > > have tried to use conditional syntax for the xlats: > > > > sql_user_name = >%{serverXldap:ldap:///o=abc?uid?sub?(|(uid=%{Us

Re: Configuring without libltdl

2002-11-11 Thread Dave Wreski
It's libtool magic. All I know is that I don't have libltdl installed, so I just do: $ configure $ make $ make install and it works. So you don't have libltdl but do have libtool installed? libtool, and libltdl, are insane "helpful" tools from the GNU people. (Who are obviously *m

Cisco VPN Concentrator VSA - Lock User to a Specific Group

2002-11-11 Thread Andrew Grimmett
On the Cisco VPN Concentrator 3000 using authentication to the Freeradius Server, what VSA should I use to lock a user to a specific group? I found the following web page at Cisco.com, that lists all the attributes that can used, but I am uncertain how this gets translated into my users file?

bind error with LDAP

2002-11-11 Thread nrg004
hi Iam a newbie to LDAP and RADIUS, forgive me if this is too novice question here. I have my openldap working. I installed freeradius0.7.1 im trying to connect to my LDAP my 'radiusd -X -A' gives me this error rlm_ldap: - authorize rlm_ldap: performing user authorization for reddy radius_xla

Re: Fw: MySQL-Proxy-Exec-Program-Wait

2002-11-11 Thread Alan DeKok
"Mike Dain" <[EMAIL PROTECTED]> wrote: > Now I'm trying to add in an Exec-Program-Wait script. I don't care > if it only runs for proxy users or if it runs for everyone, I just > need to add in that attribute/value (Exec-Program-Wait/scriptname) > to everyone that logs in. Can someone tell me how

Fw: MySQL-Proxy-Exec-Program-Wait

2002-11-11 Thread Mike Dain
I didn't get any responses...so I'm trying again... See message below. - Mike - Original Message - From: "Mike Dain" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, November 06, 2002 1:12 PM Subject: MySQL-Proxy-Exec-Program-Wait > I'm using my server for both local authe

using oracle db and getting user group info

2002-11-11 Thread Gloria Chung
Hi, I'm using an oracle database with free radius. I'm trying to get the user group information returned to me in the response. What do I need to do? For a start, I wanted to get a correct response when a user with group information in the database is authenticated. I've tried adding an

Re: Configuring without libltdl

2002-11-11 Thread Alan DeKok
Dave Wreski <[EMAIL PROTECTED]> wrote: > It looks like making only the following change builds radiusd successfully: > > make LIBLTDLPATH=$RPM_BUILD_DIR/freeradius-snapshot-20021108/libltdl \ > > LIBLTDL=$RPM_BUILD_DIR/freeradius-snapshot-20021108/libltdl/.libs/libltdl.a > > Alan, does this sou

Re: Configuring without libltdl

2002-11-11 Thread Alan DeKok
Dave Wreski <[EMAIL PROTECTED]> wrote: > In order to generate libltdl.la, it's necessary for me to run make > manually. It isn't built automatically for some reason. If you don't have libltdl installed, then a 'make' should build it. > Even once it's built, there is nothing in that file that e

Re: OS X Darwin build

2002-11-11 Thread Alan DeKok
Muskie Zia <[EMAIL PROTECTED]> wrote: > Does anyone have a working binary for the Apple's latest Darwin-FreeBSD? > I can't seem to get it to build on my Mac. If no one can offer me the > binary some pointers for a successful build would be helpful also. Grab the latest CVS snapshot. It shoul

Re: mysql

2002-11-11 Thread Alan DeKok
Kevin Bonner <[EMAIL PROTECTED]> wrote: > Here's the output when I use the new changes. Just moving the type > of error from a NULL op to an empty op. For now, it's OK. The huge annoying warning messages I added to the module should help. Also, there's no 'doc/rlm_sql' which explains all of

Re: sql counter xlat problem

2002-11-11 Thread Alan DeKok
Malcolm Caldwell <[EMAIL PROTECTED]> wrote: > I found a bug that stoped sqlcounters working for me. > > Basically sql_xlat in rlm_sql is doing > rlm_sql_select_query(sqlsocket,ins... > ... > rlm_sql_fetch_row(sqlsocket, inst) > (inst->module->sql_finish_select_query)(sqlsocket, inst->confi

Re: Vendor Specific Attributes..

2002-11-11 Thread Alan DeKok
=?iso-8859-1?q?Gbenga?= <[EMAIL PROTECTED]> wrote: > This is the full radiusd -X debug message. Again, your mailer (or something) has mangled the log messages. If you can't post a *clean* copy of the logs to the list, then put them on a web page somewhere, and post a URL on the list. Alan De

Re: Vendor Specific Attributes..

2002-11-11 Thread Gbenga
Thanks, This is the full radiusd -X debug message. I also attached a copy of router config. Starting - reading configuration files ...reread_config: reading radiusd.confConfig: including file: /usr/local//etc/raddb/clients.confConfig: including file: /usr/local//etc/raddb/snmp.confConf

Re: Questing re: conditional syntax for variables

2002-11-11 Thread Alan DeKok
Malcolm Caldwell <[EMAIL PROTECTED]> wrote: > This works find but it does not give the level of redundancy I wish. I > have tried to use conditional syntax for the xlats: > > sql_user_name = >%{serverXldap:ldap:///o=abc?uid?sub?(|(uid=%{User-Name})(cn=%{User-Name})):-%{serverYldap:ldap:///o=abc?

Re: Vendor Specific Attributes..

2002-11-11 Thread Alan DeKok
=?iso-8859-1?q?Gbenga?= <[EMAIL PROTECTED]> wrote: > But somehow the users are not > getting logged into the router in privileged mode. > > The following is the relevant part of my radiusd -X > message... ... Could you please post the log *without* mangling it? What was sent to the list was un

Re: sql reconnect code?

2002-11-11 Thread Alan DeKok
Peter Nixon <[EMAIL PROTECTED]> wrote: > Hmm.. Finally got the reconnect to work for Postgres.. > Messy messy code. Am I right in saying that the postgres driver is a copy > of the mysql driver that has been hacked to work with postgres? I believe so, yes. > I will try to make my patch a little

Re: freeradius and tls

2002-11-11 Thread Alan DeKok
Jeffery Huang <[EMAIL PROTECTED]> wrote > modcall[authorize]: module "suffix" returns noop > users: Matched DEFAULT at 153 > modcall[authorize]: module "files" returns ok > modcall: group authorize returns updated > rad_check_password: Found Auth-Type System > auth: type "System" ... > I

Re: Negative Number

2002-11-11 Thread Alan DeKok
"Joseph Kwan" <[EMAIL PROTECTED]> wrote: > I would like to return a negative number to RADIUS client in a VSA. The data > type of the attribute is defined as 'integer'. But 'integer' for RADIUS > should be an unsigned integer. Can anyone tell me how can I put a negative > number in the attribute

Re: mysql op field

2002-11-11 Thread Alan DeKok
"Enesha Fairluck" <[EMAIL PROTECTED]> wrote: > Thanks for everything taht everyone did last weel about the op field. > Heh guess I opened a can of worms :) Anyway everyone seems to be saying > that the op value needs to be something. The problem is I don't know what. > I don't know what that

freeradius-users@lists.cistron.nl

2002-11-11 Thread Mehdi Roomi
Hi, I don't know in which place to use the following: Default User-name=~ 'K', Proxy-To-Realm='nttakplus' Fall-Thriugh = No P.S. Freeradius 7.1 + Mysql + Freebsd 4.6 Mehdi _ Add photos to your messages with MSN 8. Get 2 months

mysql op field

2002-11-11 Thread Enesha Fairluck
Good Afternoon Thanks for everything taht everyone did last weel about the op field. Heh guess I opened a can of worms :) Anyway everyone seems to be saying that the op value needs to be something. The problem is I don't know what. I don't know what that field is, much less what should go t

Re: sql reconnect code?

2002-11-11 Thread Peter Nixon
OK. I swear I have implemented it correctly. I have even gone so far as to simply change all the "return -1" lines to "return SQL_DOWN" as a test but the driver never tries to reconnect. I know I am getting the new versions installed etc as I have modified the output of the error messages so its

RE: freeradius and tls

2002-11-11 Thread McKay, Raymond
> I use certificate to authorize user! why it become auth: type "system"? > and I have use certificate! why I need password? :( It looks like you may have some configuration information missing in your configuration files. You need to enable EAP-TLS in the radiusd.conf file. See http://www.imp

Re: Vendor Specific Attributes..

2002-11-11 Thread Gbenga
Hi, I have had the "cisco-avpair" attribute inserted into the radgroupreply table and I still cannot get the users to login into privileged mode. I tried this as well on another user from a users file now and it's the same result. On the two occassions, I can see from the debugging messages that

Re[2]: sql counter xlat problem

2002-11-11 Thread delphi
> I found a bug that stoped sqlcounters working for me. >>I am trying to use sqlcounter and oracle to implement download... May be this problem is specific to oracle driver (sql_oracle.c)? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radutmp file

2002-11-11 Thread Angelos Karageorgiou
On Fri, 8 Nov 2002, Alan DeKok wrote: > No, but the long port numbers *may* get truncated in the radutmp > file. > > Look at the source to be sure. > > Alan DeKok. they are only truncated on output , use the raw flag - List info/subscribe/unsubscribe? See http://www.freeradius.org/

radwho , radlast not working

2002-11-11 Thread Nihal Piyasiri
Dear members , I installed freeradius 0.7 on linux box. It is working with quintum box. Authentication is done very well and the Accounting information is in the radacct/detail file. The problem is I dont like long accounting information in the detail file. Can anybody try to get 'radlast' like

RE: radiusd:Cannot find ELF

2002-11-11 Thread Gene Parks
I used to have freeradius running on Solaris 8. I found that Solaris wanted all sorts of special things in order to make it work. I ended up installing Suse Linux 7.3 for Sparc and the system never fails. Just thought I would give you another option. Gene Parks VIP Direct -Original Message

Re:radiusd:Cannot find ELF

2002-11-11 Thread nihal_p
At 04:42 PM 10/17/2002 +0600, Nihal Piyasiri wrote: Dear members, I have compiled and installed freeradius-0.6 on solaris 8. But when I try to start radius it is saying that radiusd: Cannot find ELF Killed Can you supply the outpu