OpenLDAP 2.x + FreeRadius 0.93 Setup HowTO Needed

2004-03-07 Thread Ripunjay Bararia
Hi, Currently i'm running three FR0.93 servers doing AAA for about 3000 pppoe clients, with MySQL 4.X at the backend, ben facing lots of porblems about the database server, expecially the lack of master-master replication, so was thinking of moving the system over to LDAP, so needed help on ho

Re: expiration feature

2004-03-07 Thread Ivo
On Sat, Mar 06, 2004 at 12:58:15AM +0200, Evren Yurtesen wrote: > > > > >You could send Framed-Filter-Id (and of course define such filter in > >your RAS that will limit trafic to local server only) > > > Yeah, the problem is that how can I make freeradius send it > automatically for users whose

Hi

2004-03-07 Thread Marwan Rabie'
Dear all,    freeradius is a good software. We are thanks all who work and update it.   With my best regards, Marwan.

RE: Hi

2004-03-07 Thread Truong Manh Cuong
Yes, it's a good software. And I want to say thank you to you all. But how about dialup_admin web interface? I use PostgresSQL and it did not work well. I have to modify so much. Or I'm wrong something ?. The first is user_finger: show online user: how can you write such a SQL command? and t

eap error message

2004-03-07 Thread onur simsek
hi, i am new to freeradius. i am using dialways NTRadPing tool to test. i added a new user to clients.conf file but i cannot be authenticated. from the log file i always get "Error:rlm_eap:eap-message not found" message. any ideas? thank you. onur simsek "Fear gives me wings..."

Re: eap error message

2004-03-07 Thread Alan DeKok
"onur simsek" <[EMAIL PROTECTED]> wrote: > i am new to freeradius. i am using dialways NTRadPing tool to test. i added > a new user to clients.conf file but i cannot be authenticated. from the log > file i always get > "Error:rlm_eap:eap-message not found" message. any ideas? thank you. Ignore

Re: OpenLDAP 2.x + FreeRadius 0.93 Setup HowTO Needed

2004-03-07 Thread Dustin Doris
http://freeradius.org/radiusd/doc/ldap_howto.txt should give you an idea On Sun, 7 Mar 2004, Ripunjay Bararia wrote: > Hi, > > Currently i'm running three FR0.93 servers doing AAA for about 3000 > pppoe clients, > with MySQL 4.X at the backend, ben facing lots of porblems about the > database se

Re: OpenLDAP 2.x + FreeRadius 0.93 Setup HowTO Needed

2004-03-07 Thread Ripunjay Bararia
Dustin Doris wrote: http://freeradius.org/radiusd/doc/ldap_howto.txt should give you an idea On Sun, 7 Mar 2004, Ripunjay Bararia wrote: Hi, Currently i'm running three FR0.93 servers doing AAA for about 3000 pppoe clients, with MySQL 4.X at the backend, ben facing lots of por

Aplication of Free Radius Server

2004-03-07 Thread Matt Bailey
I have installed configured and tested free radius, seems to work great. My question is really whether or not I have chosen an appropriate application for Free Radius. (I hope this is not an in-appropriate post) What I am trying to accomplish: Have a Wireless Access Point at a remote location (i

Re: OpenLDAP 2.x + FreeRadius 0.93 Setup HowTO Needed

2004-03-07 Thread Dustin Doris
Hmm. This is more of an ldap issue now. Maybe you can send me (off list) your RADIUS schema file that you are using with openldap. Also, what version are you using of openldap? I have been meaning to upgrade ldap to version 2.1x and rewrite this documentation as 2.0 is no longer maintained. I

Re: Aplication of Free Radius Server

2004-03-07 Thread Jeff Warnica
On Sun, 2004-03-07 at 14:54, Matt Bailey wrote: > For some reason I am under the impression that some AP's have an HTML splash > screen to enter user name and password via a radius server. The only AP I have > had to test is a dwl900AP+ trying to authenticate a WinXP box, and it certainly > does n

Re: Aplication of Free Radius Server

2004-03-07 Thread Michael Griego
On Sun, 2004-03-07 at 12:54, Matt Bailey wrote: > The trick is that I don't want a proxy server at the remote location. I'm trying > to accomplish this with a Radius server and AP's that are 802.1X compliant, but > I'm not sure if this is the appropriate way to accomplish this. 802.1x requires the

Is CIDR Notation allowed in user file for IP Address Ranges

2004-03-07 Thread [EMAIL PROTECTED]
Hi, I am trying to proxy based off of Client-IP-Address where the client IP's are in a /18 ip range. I tried using a regular expression: DEFAULT Client-IP-Address =~ "^10.1\.4\." , Proxy-To-Realm := "foo.com" in my user file, which does work but does not properly define the entire subnet. What

unsubscribe

2004-03-07 Thread Rogelio Alvarado Anchisi
unsubscribe    

Using PAM to authenticate WinXP Machines

2004-03-07 Thread Justin D Davis
Here's the Scenario, I want to use PAM to do the authentication of WinXP machines. When I just set the authtype to PAM the thing says that no password info was sent to PAM I have xp setup to use PEAP mschapv2 I want a specific mode of operation, and since I can't figure out how mschapv2 is su

Re: Using PAM to authenticate WinXP Machines

2004-03-07 Thread Jeff Warnica
PAM can only handle cleartext passwords. Whatever it plugs into may or may not actually store cleartext passwords, but an app must send a cleartext password to PAM, and some PAM does whatever it is it does. Apps do not retrieve passwords from PAM, they send it one and ask if it is correct (amongst

Re: Using PAM to authenticate WinXP Machines

2004-03-07 Thread Justin D Davis
Where are your username/passwords stored? How are they stored? If they are stored hashed (as in unix files), you can only use cleartext exchange across the wire. My username/passwords are stored in a kerberos database. How can I get WinXP to prompt for the username/password, and then have freera

How to define a user whose auth-type is PAP-only or CHAP-only

2004-03-07 Thread ac
Hello, all. I would like to define 3 accounts(PAP-only, CHAP-only, and EAP-only) for auth testing. I've tried setting as follows. -- test_pap Auth-Type := PAP, User-Password == "pap" Session-Timeout

How to define a user whose auth-type is PAP-only or CHAP-only

2004-03-07 Thread ac
Hello, all. I would like to define 3 accounts(PAP-only, CHAP-only, and EAP-only) for auth testing. I've tried setting as follows. -- test_pap Auth-Type := PAP, User-Password == "pap" Session-Timeout

Re: Using PAM to authenticate WinXP Machines

2004-03-07 Thread Alan DeKok
Justin D Davis <[EMAIL PROTECTED]> wrote: > My username/passwords are stored in a kerberos database. How can I get > WinXP to prompt for the username/password, and then have freeradius handle > sending it to the kerberos server? There is a kerberos module for the server, but it requires acces

Re: Is CIDR Notation allowed in user file for IP Address Ranges

2004-03-07 Thread Alan DeKok
"[EMAIL PROTECTED]" <[EMAIL PROTECTED]> wrote: > What I really need is: > DEFAULT Client-IP-Address == 10.1.4.0/18, Proxy-To-Realm := "foo.com" > because 10.1.4.0/18 properly describes the subnet. I don't think so. Check the mask. It's "10.1.0.0/18", as "10.1.4.0" is in the middle of the /18 n