RE: SSL problem

2004-03-02 Thread Tom Rixom
Title: RE: SSL problem Thanks, But I tried the link but I guess it is an old link... funny 401 error though ;) Tom -Original Message-From: rakesh jha [mailto:[EMAIL PROTECTED]Sent: Tuesday, March 02, 2004 1:09 PMTo: '[EMAIL PROTECTED]'Subject: RE: SSL problem Have a

Checkrad times out with snmpget (trivial patch)

2004-03-02 Thread Jacques Caruso
Hi, [sorry if this has already been discussed, I looked a bit backwards on the mailing-list but didn't find anything] I'm using FR 0.9.3 on Debian, and I noticed problems when I added a Simultaneous-Use := 1 to radgroupcheck (yes, I'm using the SQL backend, although I don't think this had

(no subject)

2004-03-02 Thread Rob Williams
Hi all, I'm currently implementing FreeRadius to be used to authenticate to Cisco switches and routers. The authentication part is worked ok, however I'm having a problem with accounting. I want to log all Level 15 commands on the switches or routers back to the freeradius box via accounting.

Re: Special users only allowed to login to certain ras ports

2004-03-02 Thread Keith Yoder
JAMIE CRAWFORD escreveu: Hello, Is there a way to limit the users to login to certain ports on the ras server. For example, I need to allow the president of the company to dialin to the 1800number configured which would be port 3 on the ras sever. I need to make sure that he can get in at any

Re: Choosing Free Radius (beta?)

2004-03-02 Thread Nicolas Baradakis
Matt Bailey wrote: Is the current Free Radius server a viable solution? When will a 'non-beta' version be available? Is any one using Free Radius in production environment succesfully? We're using FreeRADIUS in production for about a year at Cegetel, a major telecom operator in France. An

DSL Caller-ID

2004-03-02 Thread Ayman Alashquar
Hi all, We are using the FreeRadius for the accounting of DSL connections. The CDRs are not showing the caller-ID for the telephone number which established the DSL connection, is there any thing to do to get such info ? Many thanks in advance Ayman Alashquat - List

Re: (no subject)

2004-03-02 Thread Graeme Hinchliffe
Hiya I want to log all Level 15 commands on the switches or routers back to the freeradius box via accounting. On the Cisco router i have: I was under the impression that this functionality was only availible if using TACAS+ ? If it is possible with RADIUS I would be interested

peap + freeradius093 + Windows XP : module eap returns handled

2004-03-02 Thread Wilfried QUET
Hello, I've installed freeradius093 compiled with this option : ./configure --prefix=/usr/local/radius093 --disable-shared --with-openssl-includes=/usr/local/openssl/include --with-openssl-libraries=/usr/local/openssl/lib The version of openssl is 097b Every seems to be OK but the client is

Re: Radius + LDAP

2004-03-02 Thread Kostas Kalevras
On Tue, 2 Mar 2004, Dave Whitehouse wrote: Hello, I'm new to this list and I've searched through the achieve for something that answers my problem but as yet I can't find anything so if this has been asked before please forgive me. Anyway to the point I am using freeradius ver 0.9.3 and I

Re: Passing back LDAP Values

2004-03-02 Thread Kostas Kalevras
On Tue, 2 Mar 2004, Paul Blaich wrote: Hi All I want FreeRadius to include with the Access-Accept packet that it sends back some information that it reads from our LDAP directory (which is authenticating our users based on 3 values that could be contained in an attribute at the moment) Is

Re: Dialup_Admin Question

2004-03-02 Thread Kostas Kalevras
On Sun, 29 Feb 2004, Nick Marino wrote: Anyone have any Ideas or simular problems with Dialup_admin not working against the radius server I have running on the same box? When I run server check from dialup admin this is all that I get. Sunday, 29 February 2004, 22:14:38 CST Server:

Re: Column Descriptions for RADACCT table

2004-03-02 Thread Kostas Kalevras
On Mon, 1 Mar 2004 [EMAIL PROTECTED] wrote: Hi All, If someone has got knowledge could U please reply me about columns in RADACCT table? I need information for columns marked as ??? Check http://www.freeradius.org/rfc/attributes.html for instance: NASPortId -

Re: Problem with LDAP attributes checking

2004-03-02 Thread Kostas Kalevras
On Wed, 25 Feb 2004, Sergio Sagliocco wrote: Hello to the list I configured my Freeradius to authenticate users with LDAP. When one of the clients send a request it includes this attribute: Cisco-AVPair = h323-ivr-out=terminal-alias:5854; This attribute depends from the user: so for user

Re: pap encryption

2004-03-02 Thread Kostas Kalevras
On Wed, 25 Feb 2004, Ossama Suleiman wrote: Dear all, i am using freeradius-ldap-mysql, which is working just fine. the question is: in LDAP i have the users stored with different encryption schemes, some are CRYPT, some are CLEAR and some are MD5, is there a way to let FR use all

Re: Choosing Free Radius (beta?)

2004-03-02 Thread Alan DeKok
Matt Bailey [EMAIL PROTECTED] wrote: Is the current Free Radius server a viable solution? There are systems using FreeRADIUS with millions of users. When will a 'non-beta' version be available? We hope some time in the next few months. Thanks for any information, I am having a dificult

Re: EAP and LDAP authentication problem

2004-03-02 Thread Alan DeKok
Fernando Lunardelli [EMAIL PROTECTED] wrote: I using a Extreme Network Summit48si switch and a Windows 2000 PRO sp4 box with MD5-challenge enabled in 802.1x authetication client. I have been trying to get FreeRadius work with LDAP and EAP (authorization - authentication), but a cant have

Re: EAP and LDAP authentication problem

2004-03-02 Thread Fernando Lunardelli
thanks Allan for the tip ... So, think you that latest cvs snapshot can solve the authentication problem ? I cant understand why Local - eap works and LDAP - eap dont ... Alan DeKok wrote: Fernando Lunardelli [EMAIL PROTECTED] wrote: I using a Extreme Network Summit48si switch and a

Re: Dialup_Admin Question

2004-03-02 Thread Nick Marino
Ok thanks I will check that. - Original Message - From: Kostas Kalevras [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Tuesday, March 02, 2004 9:45 AM Subject: Re: Dialup_Admin Question On Sun, 29 Feb 2004, Nick Marino wrote: Anyone have any Ideas or simular problems with

Re: Problem with LDAP attributes checking

2004-03-02 Thread Sergio Sagliocco
Hi thanks for the suggestion. If I use the compare_check_items keyword it doesn't work because I think the check operator is forced to == . I've found the module rlm_checkval: I've compiled it and istalled it. Now how I ca use it? I've not found documentation in freeradius distribution. Where

How to remove a user from radutmp?

2004-03-02 Thread R. Bernstein
We're using freeradius and allowing no simulataneous login (e.g. Simultaneous-Use := 1). Sometimes things get bolixed. Is there a way to remove a record from /var/log/radutmp? I notice that this seems to have a custom format (i.e. a struct radutmp which is not a Unix utmp or wtmp format).

Solved! -- How to remove a user from radutmp?

2004-03-02 Thread R. Bernstein
Sorry - I just noticed the radzap program which seems to do the trick of removing a user from radutmp.. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problem in Radius Proxy during FailOver --

2004-03-02 Thread Alan DeKok
Chris Brotsos [EMAIL PROTECTED] wrote: The server should have some configuration to use, to decide that a home server hasn't responded in N seconds, and marks it dead. That time can probably be retry_delay * retry_count. I have a patch to suggest at the bottom of this email. Added,

Re: Dual User verification

2004-03-02 Thread Alan DeKok
Kirti S. Bajwa [EMAIL PROTECTED] wrote: When I switch over to 3Com HiPer dial-in box, I would like freeRADIUS to first authenticate UID/PW from MySQL DB Not quite. It pulls the password from the DB, and then another module does the authentication. and if the user authentication fails then

Re: Problem with LDAP attributes checking

2004-03-02 Thread Kostas Kalevras
On Tue, 2 Mar 2004, Sergio Sagliocco wrote: Hi thanks for the suggestion. If I use the compare_check_items keyword it doesn't work because I think the check operator is forced to == . I've found the module rlm_checkval: I've compiled it and istalled it. Now how I ca use it? I've not found

Re: multiple repliItems from ldap

2004-03-02 Thread Kostas Kalevras
On Tue, 2 Mar 2004, Tariq Rashid wrote: Mapping from ldap attributes to radius attributes is fine using the ldap.attrmap file, such as replyItem Framed-Protocol protocol In addition, using the ldap entries to store a reply line is also fine using:

rlm_sql_unixodbc dont work with unixODBC

2004-03-02 Thread Johnnyson J. Souza
Hi dudes, I´m trying to configure freeradius to autenticate with Firebird DataBase. I´m using freeradius 0.8.1 and UnixODBC 2.2.3 I´ve just to install UnixOdbc and I configuredthe connection with the Firebird, if I test the connection with odbcconfig it says for methat every thing

What is needed to compile FreeRadius ?

2004-03-02 Thread Aime
All, I would like to know what must be in place in order to successfully compile Freeradius. I got following error when doing ./configure = localhost:~/freeradius-0.9.3.orig# ./configure loading cache ./config.cache checking for gcc... gcc checking whether the C compiler (gcc ) works... no

RE: What is needed to compile FreeRadius ?

2004-03-02 Thread Max Belousov
Title: RE: What is needed to compile FreeRadius ? Looks like you do not have compiler installed. Gcc is a most popular compiler. Install it and then run it again -Original Message- From: Aime [mailto:[EMAIL PROTECTED]] Sent: Tuesday, March 02, 2004 12:33 PM To: [EMAIL

Re: What is needed to compile FreeRadius ?

2004-03-02 Thread Daryl Tester
Aime wrote: I would like to know what must be in place in order to successfully compile Freeradius. A complete compiling environment - the error below, namely, this bit: configure:869: gcc -o conftestconftest.c 15 /usr/bin/ld: cannot open crt1.o: No such file or directory means that

RE: What is needed to compile FreeRadius ?

2004-03-02 Thread Aime
I am using Debian and gcc seems to be installed on my computer: == localhost:~/freeradius-0.9.3.orig# uname -r 2.4.22-1-386 localhost:~/freeradius-0.9.3.orig# dpkg -l | grep gcc ii gcc3.3.2-2The GNU C compiler ii gcc-3.2-base 3.2.3-8The GNU Compiler Collection

RE: What is needed to compile FreeRadius ?

2004-03-02 Thread Steinberger, Jacob
The problem may be that some C compiliers that come default with OS's, like AIX, are made not to compile executibles. You might have to see about updating your cc. Jacob -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Aime Sent: Tuesday, March 02, 2004

RE: What is needed to compile FreeRadius ?

2004-03-02 Thread Aime
gcc seems to be insatlled ( see output below) localhost:~/freeradius-0.9.3.orig# uname -r 2.4.22-1-386 localhost:~/freeradius-0.9.3.orig# dpkg -l | grep gcc ii gcc3.3.2-2The GNU C compiler ii gcc-3.2-base 3.2.3-8The GNU Compiler Collection (base package) ii

Re: Passing back LDAP Values

2004-03-02 Thread Paul Blaich
Dustin, rad_recv: Access-Request packet from host 130.194.999.999:1365, id=2, length=47 User-Name = blaich User-Password = mypassword modcall: entering group authorize for request 2 modcall[authorize]: module preprocess returns ok for request 2 rlm_realm: No '@' in User-Name

Re: What is needed to compile FreeRadius ?

2004-03-02 Thread Aime
Thanks Paul, I installed the libc6-dev and could go further. In fact as i was having problem compiling , i use Paul's debian package at www.tbble.com/freeradius but could not find rlm_sqlcounter that i would like to try. Now how can i compile only a module if the module is missing ? Thanks in

Re: RES: Conf de grupos ( Portuguese-Brazil )

2004-03-02 Thread Humberto Diogenes
Fabio, ### Em português: O FAQ do Freeradius ensina como fazer algo desse tipo com o Freeradius e um NAS Cisco: http://www.freeradius.org/faq/#5.6 ### In English: The Freeradius FAQ shows how to limit access to the network using Freeradius and a Cisco NAS:

RE: Failure: rlm_eap_tls requires: (openssl/ssl.h) libcrypto libssl

2004-03-02 Thread Tarun Bhushan
See my post of a few days ago - was exactly for this issue, on Solaris. -Original Message- From: Patrice P. [mailto:[EMAIL PROTECTED] Sent: Tuesday, 2 March 2004 6:39 PM To: [EMAIL PROTECTED] Subject: Failure: rlm_eap_tls requires: (openssl/ssl.h) libcrypto libssl Hi FreeRadius users,

Re: Customizing accounting KeepAlive Responses

2004-03-02 Thread kiel hedjam
On Mon, Mar 01, 2004, Alan DeKok wrote: So... run the server in debugging mode. the debugging mode didn't say nothing You are also aware that other than VSA's, pretty much every attribute is forbidden by the RFC's to be in an accounting response packet? Yes I knew (I was using Cisco

Freeradius/Cisco and EAP?

2004-03-02 Thread Shawn Laemmrich
I'm trying to get EAP/TLS working, and not having a lot of luck. Anyone have any pointers? Here's what I've got so far: Installed freeradius-0.9.3.tar.gz Figured out how to get it to compile the EAP TLS libs Setup radius to work with my mysql server Setup cisco AP1200 (re-packaged 350

Re: 802.1x WEP keys

2004-03-02 Thread Michael Brown
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I would suggest firing up a packet sniffer such as ethereal on the client. You will be able to see the keys changing over the network. Hope this helps. Michael Brown On Wed, 3 Mar 2004 10:56:31 +0800 (CST) Vincent Chen [EMAIL PROTECTED] wrote:

reeradius1.0-snapshort can't authenticate pap

2004-03-02 Thread Zhang LinWen
I downloaded freeradius1.0-snapshort-20040229, then I found I can't pass authentication by pap method, but other method like chap and eap are succeed. The message showed :Auth-Type = System Then I tried freeradius 0.5, authenticate again(pap method), it's ok. Someone know the question?

Re: What is needed to compile FreeRadius ?

2004-03-02 Thread Roberto Tagliaferri
Aime wrote: All, I would like to know what must be in place in order to successfully compile Freeradius. I got following error when doing ./configure = localhost:~/freeradius-0.9.3.orig# ./configure loading cache ./config.cache checking for gcc... gcc checking whether the C compiler (gcc )