Re: dialup_admin online user problem

2004-06-14 Thread Milver S. Nisay
does it show the PHP script properly? how about the buttons? check your dialup admin if connecting properly to your local MySQL. - Original Message - From: apellido [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Sunday, June 13, 2004 9:12 AM Subject: dialup_admin online user problem

Re: Freeradius for Voip

2004-06-14 Thread yudhi kukuh
hi, you can activate: preprocess { huntgroups = ${confdir}/huntgroups hints = ${confdir}/hints with_ascend_hack = no ascend_channels_per_line = 23 with_ntdomain_hack = no

Re: Segmentation fault - EAP/TLS

2004-06-14 Thread Project 2k4
Hi, Now concerning tls, the segmentation fault comes generally from misconfiguration of the link between freeradius and openssl, durant the ./configure command when installing freerdius. That's right on dot! I passed on the openssl library locations and recompiled (albiet this time with

rlm_sqlcounter Max-Daily-Session??

2004-06-14 Thread nsinit
Hi, I have configured a freeradius server(freeradius0.9.2 + rlm_pap + rlm_sql_mysql + rlm_sqlcounter) , sqlcounter work well.but i am puzzled that: Where is Max-Daily-Session defined in certain dictionary file ? I cann't find it under dictionary directory greping it. Thx!

RE: Message Notify

2004-06-14 Thread Larry
Your_money.cpl Description: Binary data

Using multiple PAM authenticating methodes

2004-06-14 Thread Doove, Rene
Title: Using multiple PAM authenticating methodes Hello, I want to authenticatie users with different pam modules. For some users i want to use smb authentication and other with SecurID. It works when I use this: user Auth-Type = Pam Service-Type = Framed-User, Framed-Protocol = PPP

Re: rlm_sqlcounter Max-Daily-Session??

2004-06-14 Thread Milver S. Nisay
Hi, I have configured a freeradius server(freeradius0.9.2 + rlm_pap + rlm_sql_mysql + rlm_sqlcounter) , sqlcounter work well.but i am puzzled that: Where is Max-Daily-Session defined in certain dictionary file ? I cann't find it under dictionary directory greping it. Thx! it doesnt hurt

radius reply to multiple machines

2004-06-14 Thread visia tartaglione
Title: Messaggio hi all, i need a help. i need to know if there is any tool in any version of freeradius that is able to forward a radius reply to multiple host. in my configuration, the flow of theradius request is: nas-radius proxy-radius server and i want the flow of the radius

Re: Re: rlm_sqlcounter Max-Daily-Session??

2004-06-14 Thread nsinit
it doesnt hurt you if you cannot find it, what will hurt you is there is wrong using it as an attribute. As well as i know, we have to include a dictionary.XXX file in the /usr/share/freeradius/dictionary if we want to use our custom Vendor-Specific-Attribute, right?

FreeRadius + winbind + AD

2004-06-14 Thread Johan Bergström
Anyone managed to connect FreeRadius to AD using Winbindd in Samba? I've noticed the PAM module for authenticating users to the radius server, but that's not what I'm after really... I think. What I want is to be able to login to Cisco switches (NASes) using AD users/passwords, and depending if

NAS client authentication

2004-06-14 Thread prabhdeep
Hi, How can one allow any NAS client to be authenticated as long as secret matches? 0.0.0.0/0 does not work in clients.conf there does not seem to be any default entry that I can set something like if the IP does not match then use this. Thannk. with regards, prabh - List

System load of Exec-Program-Wait ??

2004-06-14 Thread Rob Hartzenberg \(iCabs\)
Hi there, We are using FreeRadius on a RedHat 9.0 machine. All users are added as system users with group membership if either users or email. Users in the users group have full internet access, and users in the email group are restricted via a filter to only enable email access. To get

Re: Re: rlm_sqlcounter Max-Daily-Session??

2004-06-14 Thread apellido
hi, are you referring in sqlcounter dailycounter in sqlcounter.conf? Do u want to configure the daily counter? it doesnt hurt you if you cannot find it, what will hurt you is there is wrong using it as an attribute. As well as i know, we have to include a dictionary.XXX file in

Re: NAS client authentication

2004-06-14 Thread Thor Spruyt
- Original Message - From: prabhdeep [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Monday, June 14, 2004 2:57 PM Subject: NAS client authentication Hi, How can one allow any NAS client to be authenticated as long as secret matches? client 0.0.0.0/1 { ... } client 128.0.0.0/1 {

Re: Freeradius for Voip

2004-06-14 Thread Fabio Viracao
Greate . It's workink fine . Thanks. But now , 03:44:37.370 GMT Mon Jun 14 2004 is not a good date format , how I can change it ??? Thanks in advanced Fabio - Original Message - From: yudhi kukuh [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Monday, June 14, 2004 5:50 AM Subject:

Building new version of FreeRADIUS links old version of libeap

2004-06-14 Thread Paul Bender
I a running Fedora Core 2, which uses gcc version 3.3.3 20040412 (Red Hat Linux 3.3.3-7). I have FreeRADIUS 1.0.0-pre1 installed. When I compile FreeRADIUS 1.0.0-pre2, the compiler picks up the old libeap-1.0.0-pre1.so rather than the new libeap-1.0.0-pre2. As a result, when I remove pre1 and

Re: Building new version of FreeRADIUS links old version of libeap

2004-06-14 Thread Paul Hampson
On Mon, Jun 14, 2004 at 06:43:59AM -0700, Paul Bender wrote: Looking at the Makefile.in files, I found that src/main, src/modules/rlm_eap, src/modules/rlm_eap/types/rlm_eap_peap, src/modules/rlm_eap/types/rlm_eap_sim and src/modules/rlm_eap/types/rlm_eap_ttls find the libraries by using a

Radius Accouting Functionality Testing

2004-06-14 Thread Hemanth Mysore
Hi All , I am doing Radius Server(Accounting Feature)Testing.. Can anyonetell me what are all the possible testing I can do to conform the RadiusAccouting Functionality , I think Some testing document will be very usefull , Thanking you all in advance , With Regards Hemanth Do you

Re: qn abt leap

2004-06-14 Thread Alan DeKok
Timothy Tan [EMAIL PROTECTED] wrote: Just a quick question about LEAP. Am I right to say that as long as the client wlan card supports LEAP, I just need any 802.1x compatible AP to pass through the LEAP request to the FreeRADIUS server? Or do I need to use a Cisco-only AP? The AP needs to

Re: Using multiple PAM authenticating methodes

2004-06-14 Thread Alan DeKok
Doove, Rene [EMAIL PROTECTED] wrote: BUT, when i tried it simultanous like the following, it doesn't work, user_smbAuth-Type = Pam, Pam-Auth = smb Use := not = . Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radius reply to multiple machines

2004-06-14 Thread Alan DeKok
visia tartaglione [EMAIL PROTECTED] wrote: i need to know if there is any tool in any version of freeradius that is able to forward a radius reply to multiple host. radrelay. can i manage with radrelay? Yes. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: FreeRadius + winbind + AD

2004-06-14 Thread Alan DeKok
Johan =?ISO-8859-1?Q?Bergstr=F6m?= [EMAIL PROTECTED] wrote: Anyone managed to connect FreeRadius to AD using Winbindd in Samba? I've noticed the PAM module for authenticating users to the radius server, but that's not what I'm after really... I think. ntlm_auth. See the mschap module.

Re: System load of Exec-Program-Wait ??

2004-06-14 Thread Alan DeKok
Rob Hartzenberg (iCabs) [EMAIL PROTECTED] wrote: To get freeradius to work with the system groups of users / 100 and email / 200 I searched around the new archives until I came up with a solution that uses Exec-Program-Wait function. Huh? Why not just use the Group attribute, which does

(no subject)

2004-06-14 Thread prabhdeep
Thanks Thor, I tried 0.0.0.0/1, but it still does not work... I keep getting following messages. Just curious what the networking standard... I thought it was 0/8/16/24 or is it 1/8/16/24? rad_recv: Accounting-Request packet from host 192.168.0.121:1024, id=243, length=141 Ignoring request

Modify packet proxied to a specific realm

2004-06-14 Thread Kostas Zorbadelos
Hello to everyone. I would like to know if and how it is possible to modify an accounting and an authentication request packet that is going to be proxied to a specific realm. What I want is to add a specific attribute with a specific value to every accounting and authentication request packet

post-auth

2004-06-14 Thread Andrea Gabellini
Hi, I'm using the post-auth section to log user's attempt. Is it possible, in case of REJECT, to log the full description of the rejection instead of the useless 'Access-Reject' string? For example, if a user reach the Simultaneous-Use value, is it possible to log a string like the one logged

Update New Info

2004-06-14 Thread Alex hagi
Hello, I am working with the Cisco and Freeradius, using only VoIP records. My question is that the command aaa update new info in the Cisco will send me update of new information about an active session, but when i debug the freeradius, i only see acct-status-type=Alive but for

moving from cistron radius to freeradius

2004-06-14 Thread Chad Whitten
i currently have a radius server running cistron radius (an older version) that authenticates against the system's passwd/shadow file. there are about 8k users on the system and 6 RAS devices (ascend tnt's and max4000's). i dont do anything fancy with attributes and dont track usage details

ldap sha1 mschap peap pap

2004-06-14 Thread Epp, Ladd J
Hello Again, Since Im still relatively new to FreeRADIUS authorization/authentication, some clarification on the following subject would help me out greatly. I understand that ldap passwords must be clear to use mschap (Windows XP wireless supplicant using PEAP). Is this absolutely

ldap sha1 mschap peap pap

2004-06-14 Thread Epp, Ladd J
(Sorry, previous posting was in HTML, not intentional) Hello Again, Since I'm still relatively new to FreeRADIUS authorization/authentication, some clarification on the following subject would help me out greatly.  I understand that ldap passwords must be clear to use mschap (Windows XP

Re: post-auth

2004-06-14 Thread Keith Yoder
Andrea Gabellini escreveu: Hi, I'm using the post-auth section to log user's attempt. Is it possible, in case of REJECT, to log the full description of the rejection instead of the useless 'Access-Reject' string? I added a message field to the table and use the following query: INSERT into

test, please disregard

2004-06-14 Thread Matthew Schumacher
I haven't been seeing the messages I have posted to the list, so I figure I'll do a little testing - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: System load of Exec-Program-Wait ??

2004-06-14 Thread Rob Hartzenberg \(iCabs\)
Hey Huh? Why not just use the Group attribute, which does Unix group checking for you? Alan DeKok. Well, see, I tried and failed. The Group command works fine with the MySQL module on some of the other solutions I have setup, but I have not managed to get it to work nicely with

Re: System load of Exec-Program-Wait ??

2004-06-14 Thread Alan DeKok
Rob Hartzenberg (iCabs) [EMAIL PROTECTED] wrote: Well, see, I tried and failed. The Group command works fine with the MySQL module on some of the other solutions I have setup, but I have not managed to get it to work nicely with the system groups. The Group attribute is intended to be used

Re: Modify packet proxied to a specific realm

2004-06-14 Thread Alan DeKok
Kostas Zorbadelos [EMAIL PROTECTED] wrote: I would like to know if and how it is possible to modify an accounting and an authentication request packet that is going to be proxied to a specific realm. Ues. Use the preproxy section. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: moving from cistron radius to freeradius

2004-06-14 Thread Alan DeKok
Chad Whitten [EMAIL PROTECTED] wrote: i would like to convert to freeradius but would like some feedback regarding my setup - is it doable? what challenges/obstacles would i face? It's doable. The challenges aren't very big. The biggest one is updating the operators (= versus ==, :=,

Re: ldap sha1 mschap peap pap

2004-06-14 Thread Alan DeKok
Epp, Ladd J [EMAIL PROTECTED] wrote: Since I'm still relatively new to FreeRADIUS authorization/authentication, some clarification on the following subject would help me out greatly.=A0 I understand that ldap passwords must be clear to use mschap (Windows XP wireless supplicant using PEAP).

Re: ldap sha1 mschap peap pap

2004-06-14 Thread Jawhar TAZI
Errr just a little question... if my understanding is good, it is possible to use EAP-PEAP with LDAP only if the passwords are in clear text ? I mean there is no interest to store them encrypted as far as PEAP uses a tunnel, so the security during the transfer might be enough, isn't it ?

RE: ldap sha1 mschap peap pap

2004-06-14 Thread Epp, Ladd J
OK. Thanks for the explanation. We also run a Microsoft Active Directory that is storing NT-Passwords. Would this work with FreeRADIUS, mschap and PEAP? Thanks lje -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Monday, June 14, 2004

Re: moving from cistron radius to freeradius

2004-06-14 Thread Chad Whitten
does freeradius support the ascend/lucent TNT? i dont see tnt listed in the README in the naslist section? also, what do you mean by operators below? is that related to the comparison operators in the /etc/raddb/users file for instance? my current /etc/raddb/users file consists solely of

Re: ldap sha1 mschap peap pap

2004-06-14 Thread Alan DeKok
Epp, Ladd J [EMAIL PROTECTED] wrote: OK. Thanks for the explanation. We also run a Microsoft Active Directory that is storing NT-Passwords. Would this work with FreeRADIUS, mschap and PEAP? No. AD stores the NT-Passwords, but won't supply them to FreeRADIUS. See ntlm_auth for another

Re: moving from cistron radius to freeradius

2004-06-14 Thread Alan DeKok
Chad Whitten [EMAIL PROTECTED] wrote: does freeradius support the ascend/lucent TNT? i dont see tnt listed in the README in the naslist section? It's supported. also, what do you mean by operators below? is that related to the comparison operators in the /etc/raddb/users file for

Re: ldap sha1 mschap peap pap

2004-06-14 Thread Alan DeKok
Jawhar TAZI [EMAIL PROTECTED] wrote: Errr just a little question... if my understanding is good, it is possible to use EAP-PEAP with LDAP only if the passwords are in clear text ? No. Active Directory is NOT a real LDAP server. OpenLDAP can store, and supply to FreeRADIUS,

Re: ldap sha1 mschap peap pap

2004-06-14 Thread Jawhar TAZI
Thanks for your quick answers :=) My last question was : is it possible to use authentication with a password stored in ldap but encrypted inside it? Let's take Openldap for instance. Is it possible to use the passwords stored in it to authenticate a user, knowing that the passwords are NOT in

Re: ldap sha1 mschap peap pap

2004-06-14 Thread Alan DeKok
Jawhar TAZI [EMAIL PROTECTED] wrote: My last question was : is it possible to use authentication with a password stored in ldap but encrypted inside it? Generally not. Let's take Openldap for instance. Is it possible to use the passwords stored in it to authenticate a user, knowing that

Re: Setting up a proxy radius server

2004-06-14 Thread Alan DeKok
Stephen Petersen [EMAIL PROTECTED] wrote: By the docs its setup to do proxy. In plain language what conf files need to be edited. clients.conf proxy.conf I've edit client.conf and proxy.conf and can't get any proxying happening. Try running it debug mode, as suggested in the FAQ,

test post to list, please ignore

2004-06-14 Thread Matthew Schumacher
this is a test - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Won't run on Solais 8

2004-06-14 Thread Cameron Gregg
Ken Connell wrote: FreeRadius 0.9.3 It's been great on Redhat, but on a Solaris 8 box I get the following: fatal: libradius-0.9.3.so: open failed: No such file or directory What directory is your libradius-0.9.3.so in? Also where is radiusd? Could be a library path issuewhat is the output of

Re: ldap sha1 mschap peap pap

2004-06-14 Thread Damjan
TTLS uses different tunneled authentication methods. Check those to see what's possible. TTLS + PAP should work doesnt it. -- damjan | This is my jabber ID -- [EMAIL PROTECTED] -- not my mail address!!! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Authenticating to different LDAP servers

2004-06-14 Thread Michael Check
Hello all, We are using freeRADIUS version 0.9.3 on a MacOSX box running 10.2.6 We have a Patton dial-in access server that is using freeRADIUS to AAA off Active Directory running on a W2K box (192.168.2.5) with domain marshall.com We have now set up a W2003 server (10.0.1.5) running active

unknown client

2004-06-14 Thread Timothy Tan
Hi people... I had a similar problem when I tried out the freeradius-1.0.0-pre1 build with fedora core 2... whenever I try to get my cisco AP to auth with freeradius, I get the same unknown client message, and the IP is already added in the clients.conf file... Localhost works though, ports are

Re: rlm_sqlcounter Max-Daily-Session??

2004-06-14 Thread nsinit
Hi hi, are you referring in sqlcounter dailycounter in sqlcounter.conf? Do u want to configure the daily counter? Yeah, it works well. and so what? Maybe i have basical misunderstanding for the attributedictionary. Can anyone point it to me?Thx

radius log

2004-06-14 Thread apellido jr., wilfredo p.
Hello i configured freeradius (rlm_pap + rlm_mysql + rlm_sqlcounter) successfuly and it authenticate perfectfully but i dont see any stop message in radius.log. when trying to run freeradius in debugging mode (radiusd -X) then try to test, freeradius debugging show it accept and when i try