Re: FreeRadius Vs Supllicant. EAP-TLS Certificates problem

2003-12-20 Thread Alan DeKok
"Yosi Corcia" <[EMAIL PROTECTED]> wrote: > I am triying to create the client and server certificates. I am following > the Howtos: See 'scripts/CA.all'. It's a script taken from the Howto's, which will create the certificates for you. Alan DeKok. - List info/subscribe/unsubscribe? See htt

FreeRadius Vs Supllicant. EAP-TLS Certificates problem

2003-12-20 Thread Yosi Corcia
Hi guys! I am triying to create the client and server certificates. I am following the Howtos: http://www.missl.cs.umd.edu/wireless/eaptls/ http://www.impossiblereflex.com/8021x/eap-tls-HOWTO.htm When I try to create the CA hierarchy ( usin CA.pl -newca), I suppose taht the program can´t

Re: Problem EAP TLS

2003-12-16 Thread Holger Schurig
> Could you send some detail on your configuration ? You quoted about 550 lines to just add one sentence? Ahh, would it be nice for readers if writers would adopt a sensible quoting style :-) -- Try Linux 2.6 from BitKeeper for PXA2x0 CPUs at http://www.mn-logistik.de/unsupported/linux-2.6/ -

Re: Freeradius EAP/TLS authentication chooses wrong cipher suite

2003-12-12 Thread Alan DeKok
Obermeier Markus ICM MP PD TS <[EMAIL PROTECTED]> wrote: > How does Freeradius choose the cipher suite? It doesn't. It lets SSL pick it. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problem EAP TLS

2003-12-12 Thread Jean-Paul Chapalain
Arthur EBEL wrote: Hi, I am using freeradius 0.9.3 EAP TLS with openssl 0.9.7a I have got a problem with my wifi clients which dont succeed to access to the network. Here is the result of ./radiusd -X -A Can u see something wrong ??? In my AP CISCO 1100 I can see "Authentic

Re: Problem EAP TLS

2003-12-12 Thread Swen Veckes
What version of IOS are you using on your AP?? I had problems with the latest one, but 12.2(11)JA1 works fine with freeradius 0.9.0 and openssl 0.9.7b. swen At 11:10 12.12.2003, Arthur EBEL wrote: Hi, I am using freeradius 0.9.3 EAP TLS with openssl 0.9.7a I have got a problem with my wifi

Freeradius EAP/TLS authentication chooses wrong cipher suite

2003-12-11 Thread Obermeier Markus ICM MP PD TS
Dear all, I am working on a EAP/TLS authentication with Freeradius and the Odessey client. After a client hello message with a bunch of cipher suites, the odyssey client receives a server hello message with one cipher suites. It responds with a TLS Alert message that tells the server the cipher

Re: Compilation Problem using EAP/TLS

2003-12-10 Thread garelli
onfigured the > MakeFile file in src/modules/rlm_eap/types/rlm_eap_tls to match the > documentation provided by Raymond McKay at > http://www.impossiblereflex.com/8021x/eap-tls-HOWTO.htm#7. Nothing > existed in the MakeFile when I accessed it with pico. The current text > is: >

Compilation Problem using EAP/TLS

2003-12-09 Thread Justin Bailey
(RedHat 6.2)Using the CVS snapshot from 20031208, I configured the MakeFile file in src/modules/rlm_eap/types/rlm_eap_tls to match the documentation provided by Raymond McKay at http://www.impossiblereflex.com/8021x/eap-tls-HOWTO.htm#7. Nothing existed in the MakeFile when I accessed it with pico

Problem with EAP-TLS authentication

2003-12-08 Thread garelli
Hello, I am trying to configure a wireless communication network using authentication with Freeradius. I have already configured one client, my access point (aironet cisco), and my freeradius server to use TLS authentication. I took the EAP/TLS authentication HOW-TO, and I tried to do exactly what

FreeRadius EAP/TLS - WinXP

2003-12-05 Thread Thierry LARMIER (QoS Telecom)
Hello, I followed step by step the FreeRadius EAP/TLS - WinXP Howto from Raymond McKay V1.2 (10/30/02) [ http://www.impossiblereflex.com/8021x/eap-tls-HOWTO.htm ] But Freedius and OpenSSL version have been changed since this date. I used FreeRadius-snapshot-20031204 (for peap) and two

Re: Help with EAP/TLS config

2003-12-01 Thread Alan DeKok
"John Furman" <[EMAIL PROTECTED]> wrote: > I am wondering if anyone has some pointers on how I should proceed from > here. I am at a loss as to why this isn't working. Output and version > info below. I'd say you're using an older version of the server. Upgrate to 0.9.3, or the CVS snapshot.

Help with EAP/TLS config

2003-11-26 Thread John Furman
nt of the configuration is toward EAP/TLS... Thank you. Versions: freeradius-0.9.3 [RHL 7.3] openssl-0.9.7c Client: Odyssey v2.22.00.516 [Win 2000Pro] AP:SMC2804WBR Barricade + LD_LIBRARY_PATH=/usr/local/ssl/lib + LD_PRELOAD=/usr/local/ssl/lib/lib

Re: eap-tls authentication fails

2003-11-13 Thread Alan DeKok
Alvin Fernando <[EMAIL PROTECTED]> wrote: > The supplicant fails to authenticate > and i see following debug messages repeat in the log. > > rlm_eap: processing type tls > rlm_ap: list_clean deleted one item Those messages have nothing to do with the authentication failure. Read the OTHER mes

eap-tls authentication fails

2003-11-13 Thread Alvin Fernando
Hi, I'm new to radius setup. Can anyone help point me in the right direction here. The supplicant fails to authenticate and i see following debug messages repeat in the log. rlm_eap: processing type tls rlm_ap: list_clean deleted one item Thanks, - List info/subscribe/unsubscribe? See http:

crash with EAP-TLS when client Cert isn't signed by root CA

2003-11-04 Thread Andreas Wolf
I encountered a crash when using EAP-TLS. The client was trying to authenticate with a cert that wasn't signed by the root CA that the server is using (expected to fail to authenticate, but not to crash). This happens everytime unless I use a client cert that is signed by the server&#

Fwd: RE: WPA w/ EAP-TLS against 0.8.1

2003-10-14 Thread Ian Pritchard
d work and that pointing a WPA-capable AP at FreeRADIUS works just great! Thanks everyone for all the feedback, Ian From: "Ian Pritchard" <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: RE: WPA w/ EAP-TLS against 0.8.1 Date: Thu, 02 Oct 2003 23:23:0

Re: WPA w/ EAP-TLS against 0.8.1

2003-10-04 Thread Puneet B
> >Currently, FreeRADIUS runs very well with WPA access points, > >the only requirement is the PMK (Pairwise Master Key) transmission > >from the AAA to the Authenticator which is performed with > >a "keying" method such as TTLS or of course TLS. > >This is transmitted via an Accept response. >

Re: WPA w/ EAP-TLS against 0.8.1

2003-10-03 Thread Ian Pritchard
Hi Laurent, Many thanks for your reply (and thanks to others as well). From: Laurent Butti <[EMAIL PROTECTED]> Subject: Re: WPA w/ EAP-TLS against 0.8.1 Date: Fri, 03 Oct 2003 13:40:42 +0200 [snipped older stuff] You have access to the "standard" for 25$ at wi-fi.org. It is not r

802.1X & EAP/TLS authentication of Pocket PC 2003 client fails

2003-10-03 Thread Jari Ahola
Hello, Just after couple of days work, I managed to get the whole kaboodle working to this point :-) (freeradius 0.9.1, proxim AP-2000, ipaq H5550) Any ideas why there is no reply to the challenge, but an access request with the MAC address of the ipaq? regards, -jja

Re: WPA w/ EAP-TLS against 0.8.1

2003-10-03 Thread Laurent Butti
Ian Pritchard wrote: > Hi Alan, > > >From: "Alan DeKok" <[EMAIL PROTECTED]> > >Subject: Re: WPA w/ EAP-TLS against 0.8.1 Date: Thu, 02 Oct 2003 22:52:50 > >-0400 > > > >"Ian Pritchard" <[EMAIL PROTECTED]> wrote: > > > I

Re: WPA w/ EAP-TLS against 0.8.1

2003-10-03 Thread Artur Hecker
ation should be triggered. imho, that is something to be standardized by WPA but as i said earlier, you'll hardly get access to the documents... ciao artur Ian Pritchard wrote: Hi Alan, From: "Alan DeKok" <[EMAIL PROTECTED]> Subject: Re: WPA w/ EAP-TLS against 0.8.

Re: WPA w/ EAP-TLS against 0.8.1

2003-10-03 Thread Ian Pritchard
Hi Alan, From: "Alan DeKok" <[EMAIL PROTECTED]> Subject: Re: WPA w/ EAP-TLS against 0.8.1 Date: Thu, 02 Oct 2003 22:52:50 -0400 "Ian Pritchard" <[EMAIL PROTECTED]> wrote: > I've read the responses to this and to the TLS/TTLS thread... tried to find >

RE: WPA w/ EAP-TLS against 0.8.1

2003-10-02 Thread Jeremy
Sent: Thursday, October 02, 2003 4:23 PM To: [EMAIL PROTECTED] Subject: RE: WPA w/ EAP-TLS against 0.8.1 Hi Guy (and others who replied to the original thread), I've read the responses to this and to the TLS/TTLS thread... tried to find somewhere in the Funk client where I might be able to co

Re: WPA w/ EAP-TLS against 0.8.1

2003-10-02 Thread Alan DeKok
"Ian Pritchard" <[EMAIL PROTECTED]> wrote: > I've read the responses to this and to the TLS/TTLS thread... tried to find > somewhere in the Funk client where I might be able to control some kind of > reauthentication interval (there's a setting on the AP), but no luck there > unfortunately. I

RE: WPA w/ EAP-TLS against 0.8.1

2003-10-02 Thread Ian Pritchard
To: [EMAIL PROTECTED] To: "'[EMAIL PROTECTED]'" <[EMAIL PROTECTED]> Subject: RE: WPA w/ EAP-TLS against 0.8.1 Date: Fri, 26 Sep 2003 14:37:52 +0100 -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Artur is right. This was a problem previously seen by one AP vendor with whom I talk

Re: EAP TLS SSL_read Error

2003-09-29 Thread Alan DeKok
[EMAIL PROTECTED] wrote: > Authentication method is EAP-TLS. After (I suppose) successful > generation of root, server and client certifcates I get > the following output from FreeRADIUS. > What does this mean? ... > rlm_eap_tls: SSL_read Error ... > SSL Error . 2 It me

EAP TLS SSL_read Error

2003-09-29 Thread olaf . wischhusen
Hi, I'm in the process of up FreeRADIUS together with CiscoAP1200, xsupplicant from open1x.org. Authentication method is EAP-TLS. After (I suppose) successful generation of root, server and client certifcates I get the following output from FreeRADIUS. What does this mean? TLS_accept:

RE: WPA w/ EAP-TLS against 0.8.1

2003-09-26 Thread Guy Davies
Artur said, nothing to do with the supplicant (those bring their own problems ;-). Apologies for the confusion. Regards, Guy > -Original Message- > From: Artur Hecker [mailto:[EMAIL PROTECTED] > Sent: 26 September 2003 13:50 > To: [EMAIL PROTECTED] > Subject: Re: WPA

Re: WPA w/ EAP-TLS against 0.8.1

2003-09-26 Thread Artur Hecker
ubject: Re: WPA w/ EAP-TLS against 0.8.1 hi Guy! how can you change the session time in windows? thanks, artur Guy Davies wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Ian, I've seen something like this when doing MAC authentication. It was actually a "feature" of t

RE: WPA w/ EAP-TLS against 0.8.1

2003-09-26 Thread Guy Davies
be > > something more useful (1800 seconds is good) then > everything was happy. > > > > Sorry if this is totally unrelated but I thought it might help. > > > > Regards, > > > > Guy > > > > > >>-Original Message- &g

Re: WPA w/ EAP-TLS against 0.8.1

2003-09-26 Thread Artur Hecker
PROTECTED] Sent: 26 September 2003 11:42 To: [EMAIL PROTECTED] Subject: WPA w/ EAP-TLS against 0.8.1 Hi, We're running FreeRADIUS version 0.8.1, and have been trying out authentication using a couple of "WPA-capable" 802.11 APs and PCMCIA cards on laptops, with EAP-TLS and certs

RE: WPA w/ EAP-TLS against 0.8.1

2003-09-26 Thread Guy Davies
ing more useful (1800 seconds is good) then everything was happy. Sorry if this is totally unrelated but I thought it might help. Regards, Guy > -Original Message- > From: Ian Pritchard [mailto:[EMAIL PROTECTED] > Sent: 26 September 2003 11:42 > To: [EMAIL PROTECTED] > S

WPA w/ EAP-TLS against 0.8.1

2003-09-26 Thread Ian Pritchard
Hi, We're running FreeRADIUS version 0.8.1, and have been trying out authentication using a couple of "WPA-capable" 802.11 APs and PCMCIA cards on laptops, with EAP-TLS and certs. We've tried a matrix of the following: Laptops - Win2K SP4 w/ MS 802.1x patch and with

EAP-TLS + other authentication

2003-09-18 Thread Alan DeKok
"arniel" <[EMAIL PROTECTED]> wrote: > 1. With EAP-TLS enabled w/c is used for authentication on my Wireless > clients, can I have a secondary authentication that will ask my wireless > clients to input a username and a password? Did you read my earlier response? I

Re: EAP/TLS SSL certificate error

2003-09-18 Thread Alan DeKok
[EMAIL PROTECTED] wrote: > during client authentication process FreeRadius (0.9.1) reports > the attached messages. > > Here I see two problems: > > TLS_accept:error in SSLv3 read client certificate A > rlm_eap_tls: SSL_read Error That isn't much of a problem. It's fixed in the latest CVS sna

EAP/TLS SSL certificate error

2003-09-18 Thread olaf . wischhusen
User-Name = "olaf", looking up realm NULL rlm_realm: No such realm "NULL" modcall[authorize]: module "suffix" returns noop users: Matched olaf at 90 modcall[authorize]: module "files" returns ok modcall[authorize]: module "mschap" retur

RE: FreeRADIUS EAP/TLS problem

2003-09-17 Thread Paul Hampson
> From: [EMAIL PROTECTED] > Sent: Wednesday, 17 September 2003 8:33 PM > /usr/local/sbin/radiusd: > relocation error: /usr/local/lib/rlm_eap_tls-0.9.1.so: > undefined symbol: SSL_set_msg_callback_arg Try ldd /usr/local/lib/rlm_eap_tls-0.9.1.so, and see if it's linking to the correct OpenSSL libra

Re: FreeRADIUS EAP/TLS problem

2003-09-17 Thread Artur Hecker
installed on a Linux machine (Xsupplicant 0.7), the authentication protocol is EAP-TLS. The access point is a workstation with HostAP. After starting FreeRadius I get this sequence of messages: Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including

FreeRADIUS EAP/TLS problem

2003-09-17 Thread olaf . wischhusen
Hello everybody, my Radius server crashes everytime when the supplicant is trying to authenticate. I use Freeradius 0.9.1 on a Linux (Redhat8 Kernel 2.4.20) machine. The supplicant is also installed on a Linux machine (Xsupplicant 0.7), the authentication protocol is EAP-TLS. The access point is

Re: Problems with FreeRadius+EAP/TLS

2003-09-15 Thread MuLa_oMaR
Hablas español? ¿Que version de freeradius estas utilizando? Omar. Daniel López wrote: I’m using a Dlink DWL-900AP+ as AP and a Intel Centrino Notebook as the Supplicant. I have configured all to work with SSL Certified and I work 3 or 5 minutes but when it try to renove the WEP key lost the

Re: Problems with FreeRadius+EAP/TLS

2003-09-15 Thread MuLa_oMaR
Witch firmware does the AP? and the version of Freeradius??? Daniel López wrote: I’m using a Dlink DWL-900AP+ as AP and a Intel Centrino Notebook as the Supplicant. I have configured all to work with SSL Certified and I work 3 or 5 minutes but when it try to renove the WEP key lost the connec

Problems with FreeRadius+EAP/TLS

2003-09-14 Thread Daniel López
I’m using a Dlink DWL-900AP+ as AP and a Intel Centrino Notebook as the Supplicant. I have configured all to work with SSL Certified and I work 3 or 5  minutes but when it try to renove the WEP key lost the connection. Any have idea of why can be it ?

EAP TLS multiple auth

2003-09-08 Thread emy emy
HI to all, anybody know if there is a method to detect multiple auth. of EAP-TLS client? If i produce a valid couple of certificate (root + client) anybody with this certificate can be auth. on radius. I have seen that after auth, with the accounting phase i can see if someone with the same

request about "CRL Validation in 802.1x EAP-TLS in Freeradius" fo r Ivan Dolezal

2003-09-05 Thread Francois . LEBOURDELLES
Hello, I've applied your patch (posted 12 jun 2003) . and then I got the "unable to get certificate CRL" In fact I didnt understood the point 2 : Glue ...to the end of CA Certificat. I tried cut and past in the root.pem to add the content of the crl.pem but it didnt change anything Pleas

Re: EAP TLS LOAD PROBLEM...

2003-09-04 Thread Matteo Bertato
MY - Original Message - From: Matteo Bertato To: [EMAIL PROTECTED] Sent: Thursday, September 04, 2003 11:33 AM Subject: EAP TLS LOAD PROBLEM... I  Have installed 3-9-2003 snapshot of freeradius with openssl 0.9.7b, i have configured all using http://www.imposs

Re: EAP TLS LOAD PROBLEM...

2003-09-04 Thread Alan DeKok
"Matteo Bertato" <[EMAIL PROTECTED]> wrote: > 20473:error:0906D06C:PEM routines:PEM_read_bio:no start = > line:pem_lib.c:632:Expecting: CERTIFICATE ... > rlm_eap_tls: Error reading private key file ... > All what kind of error is it? It can't read the private key file? Maybe it got corrupted.

EAP TLS LOAD PROBLEM...

2003-09-04 Thread Matteo Bertato
I  Have installed 3-9-2003 snapshot of freeradius with openssl 0.9.7b, i have configured all using http://www.impossiblereflex.com/8021x/eap-tls-HOWTO.htm#7, and all seems to work until:   Module: Loaded eap eap: default_eap_type = "tls" eap: timer_expire = 60 eap: ignore_unknown

Re: EAP/TLS trouble

2003-08-29 Thread Fabrice Beauvir
Yes, I agree with you, the problem comes from My AP. Thank you for these precisions I am actually contacting Intel and I 'll share with you feedback. Anyway If anybody have some tips and feedback about using Intel Pro Wirelless 5000 Alan DeKok wrote: I'm willing to change the code in

EAP-TLS problem

2003-08-29 Thread Yu-Ping Wang
Hi,   I use WinXP supplicant to authenticate with FreeRADIUS server by EAP-TLS.   On RADIUS server debug mode "run-radiusd -X -A", I see Access-Accept log, and my network adaptor status is authenticated successfully.   ping AP, I got reply from message, but, after 5 sec, I go

Re: EAP/TLS trouble

2003-08-28 Thread Alan DeKok
2. freeradius -> AP ACCESS CHALLENGE (11) : EAP request type EAP-TLS > (flag start) > 3. AP -> freeradius ACCESS CHALLENGE (11) : EAP request type EAP-TLS > (flag start) There is NOTHING you can to do the RADIUS server to make the AP send an Access-Challenge back to

Re: EAP-TLS problem

2003-08-28 Thread Alan DeKok
Jason Haar <[EMAIL PROTECTED]> wrote: > The only way I've found to get it to work is to manually ... > There must be a cleaner way... Besides moving to another distro ;-) Find out what is in 0.9.7b, which isn't in 0.9.6, and create patches for FreeRADIUS to work with 0.9.6. The server can get

Re: EAP/TLS trouble

2003-08-28 Thread Fabrice Beauvir
case using ethereal : IAS : 1. AP -> IAS-radius ACCESS REQUEST (1) : EAP message type iddentity 2. IAS-radius -> AP ACCESS CHALLENGE (11): EAP request type EAP-TLS (flag start) 3. AP-> IAS-radius ACCESS REQUEST (1) : EAP message code response (SSL hello) 4. IAS-radius ->

Re: EAP-TLS problem

2003-08-27 Thread Jason Haar
On Thu, Aug 28, 2003 at 01:16:18AM +1000, Paul Hampson wrote: > Was this because you linked against one, but tried to run against > the other, or is there a problem between OpenSSL 0.9.6 and FreeRADIUS's > EAP-TLS? This wouldn't be a Redhat machine would it? For better or

Re: EAP-TLS problem

2003-08-27 Thread Alan DeKok
pankaj Goel <[EMAIL PROTECTED]> wrote: > Yeah it makes sense, but I am using the same > compilation and run-time varibales for both the 0.8.1 > and cvs version like > LD_LIBRAY_PATH=/usr/local/openssl/lib > > THe following libs are inluded when i do a > > ldd /usr/local/sbin/radiusd > /lib/libss

RE: EAP-TLS problem

2003-08-27 Thread pankaj Goel
same thing with using wrong libcrypto > (0.9.6 instead 0.9.7) > > shared library. > > > Check your LD_LIBRARY_PATH > > Was this because you linked against one, but tried > to run against > the other, or is there a problem between OpenSSL > 0.9.6 and FreeRADIU

RE: EAP-TLS problem

2003-08-27 Thread Paul Hampson
our LD_LIBRARY_PATH Was this because you linked against one, but tried to run against the other, or is there a problem between OpenSSL 0.9.6 and FreeRADIUS's EAP-TLS? -- = Paul "TBBle" Hampson Bubblesworth Pty Ltd (ABN: 51 09

Re: EAP-TLS problem

2003-08-27 Thread Fabrice Beauvir
pankaj Goel wrote: TLS_accept: before/accept initialization Segmentation fault I got the same thing with using wrong libcrypto (0.9.6 instead 0.9.7) shared library. Check your LD_LIBRARY_PATH - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP/TLS trouble

2003-08-27 Thread Alan DeKok
Fabrice Beauvir <[EMAIL PROTECTED]> wrote: > So, > is the misconfiguration is due to the fact that my clients are MS type > (Windows 2000 and XP) and not the radius server nor my certificates are > wrong ? No. As I said, the problem is that the AP is receiving an Access-Challenge packet from

Re: EAP/TLS trouble

2003-08-27 Thread Fabrice Beauvir
Alan DeKok wrote: Fabrice Beauvir <[EMAIL PROTECTED]> wrote: You've managed to convince the server to send packets to itself. That's quite a feat. No 192.168.6.73 is my AP .. So sorry, It's my duty fault , it my client throught the AP . Then the AP is bouncing the Access-Chall

EAP-TLS problem

2003-08-26 Thread pankaj Goel
Hi, I was succesfully using eap-tls with freeradius version 0.8.1. Last week I checkedout the latest CVS version as there have been some changes in EAP-TLS module in the latest Version. I re-configured it only to run into some problems. It breaks dowm before starting the TLS Handshake. I

Re: EAP/TLS trouble

2003-08-26 Thread Alan DeKok
Fabrice Beauvir <[EMAIL PROTECTED]> wrote: > > You've managed to convince the server to send packets to itself. > >That's quite a feat. > > No 192.168.6.73 is my AP .. Then the AP is bouncing the Access-Challenge packet back to the server. The AP SHOULD NOT be sending Access-Challenges to

Re: EAP/TLS trouble

2003-08-26 Thread Fabrice Beauvir
Alan DeKok wrote: Fabrice Beauvir <[EMAIL PROTECTED]> wrote: after generating and installing freeradius, generating and installing certificates on server and client , I tried to initiate an EAP/TLS negociation but negocation failed after the 2nd frame : "rad_recv: Acces

Re: EAP/TLS trouble

2003-08-26 Thread Alan DeKok
Fabrice Beauvir <[EMAIL PROTECTED]> wrote: >after generating and installing freeradius, generating and installing > certificates on server and client , I tried to initiate an EAP/TLS > negociation but negocation failed after the 2nd frame : > > "rad_recv: Ac

EAP/TLS trouble

2003-08-26 Thread Fabrice Beauvir
0.9.0 Cert generation : openssl openssl-certgen-0.9.7-beta3 - Wifi client : Windows 2000SP3 client with a pcmcia intel 5000 wireless LAN SO, after generating and installing freeradius, generating and installing certificates on server and client , I tried to initiate an EAP/TLS negociatio

Re: configuring eap-tls using version 0.9

2003-08-15 Thread Artur Hecker
rote: > > hi, > > I had tried using the freeRADIUS EAP/TLS - WinXP HOWTO and has been > successfully with the packages used in the guide (FreeRADIUS > snapshot-20021028). Everything was well. > > However, I tried to upgrade using the latest radius packages (version > 0.

configuring eap-tls using version 0.9

2003-08-15 Thread Lee Puay Yong
hi,   I had tried using  the freeRADIUS EAP/TLS - WinXP HOWTO and has been successfully with the packages used in the guide (FreeRADIUS snapshot-20021028). Everything was well.   However, I tried to upgrade using the latest radius packages (version 0.9) but it does work anymore (same packes

Re: EAP-TLS PROBLEM

2003-08-14 Thread diomedes
Hi, Follow the steps of this articule abaut dinamic libraries http://www.impossiblereflex.com/8021x/eap-tls-HOWTO.htm good luck omar. wen-hong wrote: > Fri Aug 8 14:13:30 2003 : Info: Using deprecated naslist file. Support > for this will go away soon. > Fri Aug 8 14:13:30 2003 : In

AW: Authentication problems with EAP/TLS (and Enterasys)

2003-08-14 Thread Sevcik Berndt
No the server just stops here with the message Finished request 1 Going to the next request Waking up in 6 seconds... Then the same process is continued 3 times (configured on AP). There is no accept or reject. Regards Berndt > Sevcik Berndt <[EMAIL PROTECTED]> wrote: > I try to authenticate an

Re: EAP/TLS problem solved (almost...)

2003-08-14 Thread Artur Hecker
from Adam Sulmicki's cert.tgz packet. I set the server date to 28.2 and on the laptop to 28.2. (the certificate is valid from and expires on that day). And the EAP/TLS authentication worked! I finally got: Sending Access-Accept of id 50 to 194.142.202.102:6001 MS-MPPE-Rec

Re: EAP/TLS problem solved (almost...)

2003-08-14 Thread Antti Mattila
>you can DEFINITLY use openssl in order to produce valid certificates, >both for windows AND freeradius (which uses openssl). > >the certification path is not valid probably because the root >certificate which you installed under windows expired. > > >ciao >artur I know that many people have ma

Re: EAP/TLS problem solved (almost...)

2003-08-14 Thread Artur Hecker
that's why i'm trying to reassure you. it probably has nothing to do with the version of openssl. every suite has to produce compliant certificates. the certificate format is mandated by its form. just verify all the certificates you installed. it's a small error somewhere. ciao artur Antti

EAP-TLS PROBLEM

2003-08-14 Thread wen-hong
away soon.Fri Aug  8 14:13:30 2003 : Error: rlm_eap: Failed to link EAP-Type/tls: file not foundFri Aug  8 14:13:30 2003 : Error: radiusd.conf[596]: eap: Module instantiation failed.   why it can not link to eap-tls¡H Please help me,thanks...

Re: EAP/TLS Invalid ACK received

2003-08-14 Thread Alan DeKok
"Jason Coutermarsh" <[EMAIL PROTECTED]> wrote: > I apologize if I'm jumping the gun on something > that's currently being worked on, since I am using the CVS build. No, the problem is that the EAP-TLS module is still a little experimental. Try grabbing the l

Re: EAP/TLS problems... The last mail 4/4

2003-08-14 Thread Alan DeKok
Artur Hecker <[EMAIL PROTECTED]> wrote: > i think that what you receive at your radius server is nor the EAP > Identity neither EAP Start, apparently it is a Notification message. The > AP sends notifications to your Radius server, and the latter tries to > send challenges back (to Alan, WHY?) F

EAP/TLS problem solved (almost...)

2003-08-14 Thread Antti Mattila
I tried certificates from Adam Sulmicki's cert.tgz packet. I set the server date to 28.2 and on the laptop to 28.2. (the certificate is valid from and expires on that day). And the EAP/TLS authentication worked! I finally got: Sending Access-Accept of id 50 to 194.142.202.102:6001

Re: EAP/TLS problems

2003-08-14 Thread Alan DeKok
st of the debug, you will see that there are messages like: rlm_chap: No CHAP-Password found in the request These are NOT errors, unless the specifically SAY that they are errors. > How come there is no error message if the EAP/TLS doesn't work. Please read the rest of t

Re: Authentication problems with EAP/TLS (and Enterasys)

2003-08-14 Thread Alan DeKok
Sevcik Berndt <[EMAIL PROTECTED]> wrote: > I try to authenticate an XP Client via an Enterasys RoamaboutR2 Access > Point with freeradius. But the client get never authenticated. Does the server send a reject? > Output from radius.log: > ri Aug 8 10:52:28 2003 : Info: rlm_eap_tls: Length Incl

Re: AW: AW: Authentication problems with EAP/TLS (and Enterasys)

2003-08-14 Thread Alan DeKok
"Sevcik Berndt" <[EMAIL PROTECTED]> wrote: > I found the problem. In radiusd.conf fragment_size was set to 1024. I > tried different values and then it worked with 500. That's annoying. > But I have not really an idea what I have done with this line. Does > someone know more about it? The TL

Re: EAP/TLS Invalid ACK received

2003-08-14 Thread Artur Hecker
x27;m having another, hopefully small, issue. Here's the error I get: auth: type "EAP" modcall: entering group authenticate rlm_eap: Request found, released from the list rlm_eap: EAP_TYPE - tls rlm_eap: processing type tls rlm_eap_tls: Authenticate rlm_eap_tls: processing TL

Re: Authentication problems with EAP/TLS (and Enterasys)

2003-08-14 Thread diomedes
sible. Regards. Omar Sevcik Berndt wrote: I try to authenticate an XP Client via an Enterasys RoamaboutR2 Access Point with freeradius. But the client get never authenticated. My problem that I have no idea where I should search for the error. I used the www.impossiblereflex.xom/8021x/eap-tls-HOWTO.htm

Re: EAP/TLS problems

2003-08-14 Thread Alan DeKok
"Antti Mattila" <[EMAIL PROTECTED]> wrote: > When accessing the Radius with w2k Orinoco supplicant I see an error on > Freeradius (using -X -A) > > modcall: entering group authenticate > rlm_eap: EAP packet type notification id 7 length 9 > rlm_eap: EAP Start not found Does it say it's an e

Re: EAP/TLS problems... The last mail 4/4

2003-08-14 Thread Artur Hecker
hi Alan Alan DeKok wrote: > > Artur Hecker <[EMAIL PROTECTED]> wrote: > > i think that what you receive at your radius server is nor the EAP > > Identity neither EAP Start, apparently it is a Notification message. The > > AP sends notifications to your Radius server, and the latter tries to > >

Re: Authentication problems with EAP/TLS (and Enterasys)

2003-08-10 Thread Sevcik Berndt
> >I try to authenticate an XP Client via an Enterasys RoamaboutR2 Access > >Point with freeradius. But the client get never authenticated. My > >problem that I have no idea where I should search for the error. I used > >the www.impossiblereflex.xom/8021x/eap-tls-HOW

EAP/TLS Invalid ACK received

2003-08-09 Thread Jason Coutermarsh
d, released from the list rlm_eap: EAP_TYPE - tls rlm_eap: processing type tls rlm_eap_tls: Authenticate rlm_eap_tls: processing TLS rlm_eap_tls: Received EAP-TLS ACK message rlm_eap_tls: ack default rlm_eap_tls: Invalid ACK received: 22 eaptls_verify returned 4 eaptls_process retu

AW: AW: Authentication problems with EAP/TLS (and Enterasys)

2003-08-09 Thread Sevcik Berndt
I found the problem. In radiusd.conf fragment_size was set to 1024. I tried different values and then it worked with 500. But I have not really an idea what I have done with this line. Does someone know more about it? Thanks. Berndt > No the server just stops here with the message > Finished re

Re: AW: Authentication problems with EAP/TLS (and Enterasys)

2003-08-09 Thread Alan DeKok
"Sevcik Berndt" <[EMAIL PROTECTED]> wrote: > No the server just stops here with the message > Finished request 1 > Going to the next request > Waking up in 6 seconds... > > Then the same process is continued 3 times (configured on AP). > There is no accept or reject. So the AP doesn't like the

Authentication problems with EAP/TLS (and Enterasys)

2003-08-08 Thread Sevcik Berndt
I try to authenticate an XP Client via an Enterasys RoamaboutR2 Access Point with freeradius. But the client get never authenticated. My problem that I have no idea where I should search for the error. I used the www.impossiblereflex.xom/8021x/eap-tls-HOWTO.htm Howto for setup. Output from

Re: EAP/TLS problems

2003-08-08 Thread Artur Hecker
> On my AP there is: > Access requests: 2 > Access Retransmissions: 6 > Timeouts: 8 apparently, your AP thinks that it never got answers back. why? be sure, the message sent by the server arrives at the AP and is recognized as an answer. you can do so by using other auth types for debugging purpos

EAP/TLS problems... The last mail 4/4

2003-08-07 Thread Antti Mattila
Freeradius log: raddb]# radiusd -A -X Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /etc/raddb/proxy.conf Config: including file: /etc/raddb/clients.conf Config: including file: /etc/raddb/snmp.conf main: prefix = "/usr/local" main:

Re: EAP/TLS problems... The last mail 4/4

2003-08-07 Thread Antti Mattila
I am using Orinoco AP-2000 (with 2.3.1 firmware). Has anyone got it working with Freeradius? I mean judging by the Artur's comments it sends notifications and it should send EAP/Identity or EAPOL Start. Is this Access Point's fault or Freeradius fault? I mean I have Freeradius and AP running and

Re: EAP/TLS problems... The last mail 4/4

2003-08-07 Thread Artur Hecker
cation" id 2 length 13 detected > rlm_eap: "EAP Start" not found > rlm_eap: "EAP Identity" WHAT? EXPECTED? FOUND? MISSED? > rlm_eap: processing type N (EAP/TLS) > rlm_eap_tls: Initiate > rlm_eap_tls: Start returned 1 (which means ) ciao artur Antti Ma

EAP/TLS problem continued again...

2003-08-07 Thread Antti Mattila
ne the order that # we try to find a matching realm. # # Make *sure* that 'preprocess' comes before any realm if you # need to setup hints for the remote radius server authorize { # # The preprocess module takes care of sanitizing some bizarre # attrib

EAP/TLS problems

2003-08-06 Thread Antti Mattila
I have a problem using EAP-TLS authentication on Freeradius 0.9. When accessing the Radius with w2k Orinoco supplicant I see an error on Freeradius (using -X -A) modcall: entering group authenticate rlm_eap: EAP packet type notification id 7 length 9 rlm_eap: EAP Start not found rlm_eap

Re: EAP/TLS problems

2003-08-06 Thread Antti Mattila
en rude to people that have not posted them. So in the future I will try to post them on a web page. So if there is no Error.: (Isn't EAP START NOT FOUND an Error?) How come there is no error message if the EAP/TLS doesn't work. The Freeradius(debug mode) should be more informative so i

error running freeradius (libcrypto.so) with EAP-TLS

2003-08-04 Thread Alex
I am trying to make FreeRadius 0.8.1 work with EAP-TLS and this error message is shown when running "run-radiusd -X -A" as specified in http://www.impossiblereflex.com/8021x/eap-tls-HOWTO.htm /usr/local/sbin/radiusd: error while loading shared libraries: /usr/local/ssl/lib/libcrypto.

Re: eap-tls with ldap?

2003-07-30 Thread Dustin Doris
On Wed, 30 Jul 2003, Luca Benassi wrote: > On Wed, 30 Jul 2003, Alan DeKok wrote: > > Luca Benassi <[EMAIL PROTECTED]> wrote: > > > eap-tls works fine but I need to use LDAP. > > > > For what? Are you willing to say what you're trying to do, and why? &

Re: eap-tls with ldap?

2003-07-30 Thread Luca Benassi
On Wed, 30 Jul 2003, Alan DeKok wrote: > Luca Benassi <[EMAIL PROTECTED]> wrote: > > eap-tls works fine but I need to use LDAP. > > For what? Are you willing to say what you're trying to do, and why? No problem ... :) I want to secure a 802.11 lan using eap-tls and

Re: eap-tls with ldap?

2003-07-30 Thread Alan DeKok
Luca Benassi <[EMAIL PROTECTED]> wrote: > eap-tls works fine but I need to use LDAP. For what? Are you willing to say what you're trying to do, and why? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

eap-tls with ldap?

2003-07-30 Thread Luca Benassi
Anyone has done this? I'm trying to get info about this but ... :( At the moment I'm using eap-tls in this configuration: Windows XP with a Cisco Client Adapter Cisco Aironet 350 FreeRadius 0.9.0 OpenSSL 0.9.7b eap-tls works fine but I need to use LDAP. Just need some documentation :)

  1   2   3   4   5   >