Redback SMS and checkrad

2003-03-11 Thread Holger Steppke
Hi, sorry for bothering the list again. Iam just looking into how i can make the checkrad script Redback SMS1800 aware. Is some doing this already and is checking for PPP sessions on the Kit. Would be nice to know wich MIB you are query then. Iam sure the SMS can do finger but i dont realy

Simultaneous-Use works not properly

2003-03-11 Thread Eric
I'm using mysql authentication scheme. As shown in documentation i'm set in radgroupcheck table such row: groupname | parameter| op | value| - test|Simultaneous-Use| := | 1 | But I still have double,

calling line identification - IP address

2003-03-11 Thread Ronald . VERLAAN
Hi all, I have been asked to setup a radius server, however I do know nothing about radius yet. Because it should be a cheap but stable solution I choose to install solaris 8 for intel on a pc. I could have choosen linux as well, but let's not argue about that as its irrelevant for my question.

Testing EAP-MD5

2003-03-11 Thread Miquel Bordoy
Hi everybody, I'm testing windows XP with 802.1X and EAP-MD5 authentication protocol. My main goal is to change the user authentication interface for this procotol EAP-MD5. Windows OS display the default win logon dialog and the user must enter username/password manually. I want to change this

Re: freeradius with ldap and ssl

2003-03-11 Thread Robert Morse
I would suggest using port = 389, tls_mode = no and start_tls = yes That way you will use the StartTLS extended operation and not the old LDAPS I just tried that and now I get this error from radiusd: modcall: entering group authorize rlm_ldap: - authorize

unsubscribe

2003-03-11 Thread Fernando Teodoro

Re: EAP-MD5 auth failure

2003-03-11 Thread [EMAIL PROTECTED]
Hi, I'm continuing having problems. Althought I modified radiusd.conf the log coming with radiusd -X shows that also the commented items are considered by the server (for example MS-CHAP is commented but the server however load and instantiate it). It seems the server reads a previous and an

checking radiusd with cron

2003-03-11 Thread Thomas S. Crum - AAA Web Solution, Inc.
This may seem like an oversimplified approach, but can someone please comment. I've noticed that when radius dies, it usually kills all of its processes with it. Some have written a cron that checks first and then restarts etc. I wrote a cron that every minute just runs /usr/local/sbin/radiusd,

Re: Testing EAP-MD5

2003-03-11 Thread Artur Hecker
hi Miquel sorry, but what does this have to do with freeradius? I'm testing windows XP with 802.1X and EAP-MD5 authentication protocol. My main goal is to change the user authentication interface for this procotol EAP-MD5. Windows OS display the default win logon dialog and the user must enter

Re: EAP-MD5 auth failure

2003-03-11 Thread Artur Hecker
i think you should really either: 1. relaunche ./configure and rebuild the server giving the good prefixes for the config files - OR - 2. launch your radiusd with: strace radiusd 21 | grep radiusd.conf you will see which config file it is really using. ciao artur [EMAIL PROTECTED] wrote: Hi,

Re: checking radiusd with cron

2003-03-11 Thread Artur Hecker
why not use radwatch? rc.radiusd supplied with the server already starts radiusd with radwatch. otherwise, the only problem about your approach is the active waiting. Thomas S. Crum - AAA Web Solution, Inc. wrote: This may seem like an oversimplified approach, but can someone please comment.

Re: checking radiusd with cron

2003-03-11 Thread Simon
On Tue, Mar 11, 2003 at 09:24:02AM -0500, Thomas S. Crum - AAA Web Solution, Inc. wrote: This may seem like an oversimplified approach, but can someone please comment. I've noticed that when radius dies, it usually kills all of its processes with it. Some have written a cron that checks

rlm_eap: State verification failed

2003-03-11 Thread Klemens Jaeger
hi! do I need the module "files" in radiusd.conf where the file "user" will be implemented? or is the module eap enough? thanks, kle

Re: Redback SMS and checkrad

2003-03-11 Thread Chris Parker
At 10:37 AM 3/11/2003 +0100, Holger Steppke wrote: Hi, sorry for bothering the list again. I¢¥am just looking into how i can make the checkrad script Redback SMS1800 aware. Is some doing this already and is checking for PPP sessions on the Kit. Would be nice to know wich MIB you are query

Re: Simultaneous-Use works not properly

2003-03-11 Thread Chris Parker
At 03:54 PM 3/11/2003 +0500, Eric wrote: I'm using mysql authentication scheme. As shown in documentation i'm set in radgroupcheck table such row: groupname | parameter | op| value| - test|Simultaneous-Use | :=

Re: calling line identification - IP address

2003-03-11 Thread Chris Parker
At 02:01 PM 3/11/2003 +0100, [EMAIL PROTECTED] wrote: Hi all, I have been asked to setup a radius server, however I do know nothing about radius yet. Because it should be a cheap but stable solution I choose to install solaris 8 for intel on a pc. I could have choosen linux as well, but let's not

RE: Dialup_admin (...or smth else) not working properly

2003-03-11 Thread Redi Tela
Hello, It still doesn't work. Those php scripts wont talk to mysql database. I guess there should smth wrong with my apache server, or php support, probably I will have to reinstall itthat's a big headache. Anyway, thanks a lot for your help Redi Redi Tela Systems Administrator Mail [EMAIL

dialup_admin and large groups

2003-03-11 Thread Nick Lomonte
My main group has about 3800 users in it. From the web interface if I click on 'show groups' and then click on that group, it just sits there and eventually times out. Running the latest CVS on a redhat 7.3 machine. The other groups with fewer members work fine. I'm assuming this has something

Sql module problems

2003-03-11 Thread Keith Ballard
Hi all, I'm happily using sql module to authorise 1 users. However I wanted to disallow 1 user and did it by: Radgroupreply: 29,noaccess,Auth-Type,:=,Reject,0 Usergroup: 1000,fred,noaccess Radcheck: 1000,fred,password,==,password It seems as long as fred's username password are correct,

FreeRadius, LDAP to a remote Active Directory Server

2003-03-11 Thread Ron Wahler
Has anyone integrated FreeRadius/LDAP to a Remote Active Directory Server? I am trying to integrate the two and need some examples of radiusd.conf for the LDAP to Active Directory. I also tried uid=ron And [EMAIL PROTECTED] I have no organization just a list of users under

Re: Sql module problems

2003-03-11 Thread Chris Parker
At 04:56 PM 3/11/2003 +, Keith Ballard wrote: Hi all, I'm happily using sql module to authorise 1 users. However I wanted to disallow 1 user and did it by: Radgroupreply: 29,noaccess,Auth-Type,:=,Reject,0 Usergroup: 1000,fred,noaccess Radcheck: 1000,fred,password,==,password It seems as

Re: dialup_admin and large groups

2003-03-11 Thread twebster
Nick, Sounds like the php page is timing out. Default is 30 seconds. Try to up the max_execution_time in your php.ini file good luck, Tony |-+--- | | Nick Lomonte| | | [EMAIL PROTECTED]

Re: dialup_admin and large groups

2003-03-11 Thread Kostas Kalevras
On Tue, 11 Mar 2003, Nick Lomonte wrote: My main group has about 3800 users in it. From the web interface if I click on 'show groups' and then click on that group, it just sits there and eventually times out. Running the latest CVS on a redhat 7.3 machine. The other groups with fewer

Round robin proxy not working

2003-03-11 Thread Mark Moody
We have several realms configured to do round robin between two downstream radius servers. We have observed that our freeradius (0.8.1) servers are sending all traffic for a realm to the first server listed for that realm. I have seen in the logs where it does do failover however. Here's an

Re: Round robin proxy not working

2003-03-11 Thread Chris Brotsos
At 11:28 AM 3/11/2003, you wrote: We have several realms configured to do round robin between two downstream radius servers. We have observed that our freeradius (0.8.1) servers are sending all traffic for a realm to the first server listed for that realm. I have seen in the logs where it does do

Re: Working on the server

2003-03-11 Thread Toni Mueller
Hi, On Tue, Mar 04, 2003 at 06:16:24AM -0500, Alan DeKok wrote: Y Sreenivasulu [EMAIL PROTECTED] wrote: Thanks for your information Alan. Can you suggest where can I find such source code patches? It's free software. You have the power to create them yourself. speaking of which,

RE: Redback SMS and checkrad

2003-03-11 Thread Holger Steppke
Hi, Probably not. There are MIBs in the Redback documentation. You can check those to determine if there is a usable MIB for use with 'checkrad'. I have ask our Redback contact´s usualy they respond fast. If this will fail i will try using telnet. As usual, patches are welcome! Sure i will

Freeadius and LDAP unix sockets

2003-03-11 Thread Simon Allard
I had a look though the LDAP docs and I couldn't see anything obvious. Is there a way to specify the use of a URI rather than a hostname? I want to be able to use ldapi:// to it uses the unix socket rather than the tcp socket. Its quite a lot faster! Is that possible with the current code base

Re: Freeadius and LDAP unix sockets

2003-03-11 Thread Kostas Kalevras
On Wed, 12 Mar 2003, Simon Allard wrote: I had a look though the LDAP docs and I couldn't see anything obvious. Is there a way to specify the use of a URI rather than a hostname? I want to be able to use ldapi:// to it uses the unix socket rather than the tcp socket. Its quite a lot faster!

Re: EAP-TLS just stopped working

2003-03-11 Thread seterajunk
you *should* have at least devel version of 0.9.7beta. former it always was the newer the better. Looking at openssl.org there actually is a 0.9.7a which is a follow-up to 0.9.7. I believe that that is what I have installed. perhaps you should regenerate your Certificates using the same

Re: checking radiusd with cron

2003-03-11 Thread Alan DeKok
Thomas S. Crum - AAA Web Solution, Inc. [EMAIL PROTECTED] wrote: I've noticed that when radius dies, it usually kills all of its processes with it. Yes. That makes sense, the way the server is written. I wrote a cron that every minute just runs /usr/local/sbin/radiusd, if radiusd is

Re: Round robin proxy not working

2003-03-11 Thread Alan DeKok
Chris Brotsos [EMAIL PROTECTED] wrote: Alan and I submitted *many* changes to the original round_robin code, and although I'm not positive...I think it ended up *not* being supported in the 0.8.1 release. I don't have the base 0.8.1 release running, though, so I'm not 100% sure on that.

Re: Freeadius and LDAP unix sockets

2003-03-11 Thread Alan DeKok
Simon Allard [EMAIL PROTECTED] wrote: Is there a way to specify the use of a URI rather than a hostname? I want to be able to use ldapi:// to it uses the unix socket rather than the tcp socket. Its quite a lot faster! I thought there was a patch on the list a while ago... if not, I might

Re: Working on the server

2003-03-11 Thread Alan DeKok
Toni Mueller [EMAIL PROTECTED] wrote: speaking of which, below is one that's untested. If someone can please explain how to regenerate an individual configure script, I'd rather try that instead of hacking directly into the generated code. 'make reconfig' should work. $ gmake reconfig

failed logins page on dialup_admin returns blank usernames

2003-03-11 Thread Nick Lomonte
It will show an entry each time there is a failed login, but just leaves a '-' for the username. The only time it properly displays the login is when I try it from the 'check server' link and it tries to authenticate locally. I also get the address is not in a.b.c.d form error, but I'm not sure