Microsoft PEAP

2003-12-14 Thread Sevcik Berndt
I have already testet freeRADIUS with EAP-TLS and it worked fine. Now I also want to offer PEAP authentication. How far is it implemented in freeradius now? Is it possible to use it with about 200 clients or should I wait till the code is more stable? Thanks Berndt ---

Re: Problem with attr_filter

2003-12-14 Thread Stephan von Krawczynski
On Sat, 13 Dec 2003 15:09:03 -0500 "Alan DeKok" <[EMAIL PROTECTED]> wrote: > Stephan von Krawczynski <[EMAIL PROTECTED]> wrote: > > 1) It does not recognize at all vendor specific attributes. The reason is > > this code part taken from src/modules/rlm_attr_filter/rlm_attr_filter.c : > ... > >

freebsd vs. wireless 802.1x

2003-12-14 Thread Vincent Chen
Hi, all I just got freeradius work with 802.1x working recently. But I have some questions left. 1. My client is a notebook running windows xp. I can establish connection to AP using predefined key or just check 'the key is provided for me automatically'. My question is the key radius send to AP

Re: Microsoft PEAP

2003-12-14 Thread Alan DeKok
"Sevcik Berndt" <[EMAIL PROTECTED]> wrote: > I have already testet freeRADIUS with EAP-TLS and it worked fine. Now I also > want to offer PEAP authentication. How far is it implemented in freeradius > now? Is it possible to use it with about 200 clients or should I wait till > the code is more stab

Re: Problem with attr_filter

2003-12-14 Thread Alan DeKok
Stephan von Krawczynski <[EMAIL PROTECTED]> wrote: > > Huh? I don't see why that would be true. If the standard API's are > > used to create VP's, then the 'attribute' entry ALWAYS contains the > > vendor information. > > Hm, this was my first thought, too. But I checked the incoming data via

Re: freebsd vs. wireless 802.1x

2003-12-14 Thread Alan DeKok
=?big5?q?Vincent=20Chen?= <[EMAIL PROTECTED]> wrote: > 1. My client is a notebook running windows xp. I can > establish connection to AP using predefined key or > just check 'the key is provided for me automatically'. > My question is the key radius send to AP and client. > How do those key generat

Re: Problem with attr_filter

2003-12-14 Thread Stephan von Krawczynski
On Sun, 14 Dec 2003 09:15:55 -0500 "Alan DeKok" <[EMAIL PROTECTED]> wrote: > Stephan von Krawczynski <[EMAIL PROTECTED]> wrote: > > > Huh? I don't see why that would be true. If the standard API's are > > > used to create VP's, then the 'attribute' entry ALWAYS contains the > > > vendor inform

Re: Problem with attr_filter

2003-12-14 Thread Stephan von Krawczynski
On Sun, 14 Dec 2003 09:15:55 -0500 "Alan DeKok" <[EMAIL PROTECTED]> wrote: > Then you're *very* confused. Go read the "dictionary.ascend" file. > Both vendors are idiots, and have put their attributes into the base > 256 attributes, rather than using VSA's. > > THAT'S why you didn't see a ve

Re: Problem with attr_filter

2003-12-14 Thread Alan DeKok
Stephan von Krawczynski <[EMAIL PROTECTED]> wrote: > > THAT'S why you didn't see a vendor Id: They weren't using VSA's. If > > you had said that in the first place, it would have helped > > significantly. > > Unfortunately it would not, If you know more about RADIUS & the server than I do, w

Re: Problem with attr_filter

2003-12-14 Thread Stephan von Krawczynski
On Sun, 14 Dec 2003 14:05:19 -0500 "Alan DeKok" <[EMAIL PROTECTED]> wrote: > Stephan von Krawczynski <[EMAIL PROTECTED]> wrote: > > > THAT'S why you didn't see a vendor Id: They weren't using VSA's. If > > > you had said that in the first place, it would have helped > > > significantly. > > >

Re: freebsd vs. wireless 802.1x

2003-12-14 Thread Vincent Chen
--- Alan DeKok <[EMAIL PROTECTED]> 的訊息:> =?big5?q?Vincent=20Chen?= <[EMAIL PROTECTED]> wrote: > > 1. My client is a notebook running windows xp. I > can > > establish connection to AP using predefined key or > > just check 'the key is provided for me > automatically'. > > My question is the key ra

Re: rlm_perl & Client-IP-Address

2003-12-14 Thread Bruce Cook
Hmm, don't see it in the current version I'm running, I'll suck the latest CVS and have a look at that. Mon Dec 1 23:20:53 2003 : Info: rlm_perl: ?/RAD_REQUEST: Mon Dec 1 23:20:53 2003 : Info: rlm_perl: ? Calling-Station-Id = wpp212100900202 Mon Dec 1 23:20:53 2003 : Info: rlm_perl: ? NAS-P

Radius Class and users file

2003-12-14 Thread Wichit Ngamsomhan
I want to reject user by checking with NAS and User Class, i am using OpenLDAP + FreeRadius 0.9.3 and set 'users' file like below but it not work. DEFAULT NAS-IP-Address==192.168.0.25, Class == TYPE1, Auth-Type := Reject Reply-Message = "NAS Access denied!", Fall-Throu

RE: MySQL Help!

2003-12-14 Thread Deramus, Chris
Title: RE: MySQL Help! Alan, What file(s) should I run ldd against? Chris DeRamus OCIO VPN Administrator SAIC -Original Message- From: Alan DeKok [mailto:[EMAIL PROTECTED]] Sent: Friday, December 12, 2003 4:44 PM To: [EMAIL PROTECTED] Subject: Re: MySQL Help! "Deramus, Chri

RE: MySQL Help!

2003-12-14 Thread Deramus, Chris
Title: RE: MySQL Help! Chris, Thanks for the input, however, when I updated the configure script with your extra code configure would not find lmysqlclient and prompted that I specify the path to the library files by using --with-mysql-lib= When I put in the path to the MySQL library files,

Digital Cert + Username/Password against LDAP = ???

2003-12-14 Thread Patrick Mowry
Hello, I have a requirement for two stage authentication for wireless networks. Before the wireless Windows 2000/XP client is even allowed to reach the domain, it must authenticate to the network with Digital Certs issued from an iPlanet certificate server (EAP-TLS) and also a username/password ag

Upgrade questions

2003-12-14 Thread Nick Marino
Can anyone point in the direction of the best way to upgrade to Freeradius version 0.9.3 from version FreeRADIUS Version 0.8-pre with out losing my current configuration? currently FreeRADIUS Version 0.8-pre is being used to authenticate users dialing into a Lucent Max 6000. If there is any other