freeradius and counters.

2004-08-16 Thread Shannon Sariman
Hi All, I'm using freeradius-0.9.3 with MySQL accounting on a Linux Red Hat 9.0 box.My NAS is a Cisco 2500 series. I have rlm_counter and rlm_sqlcounter installed as well. I'm trying to get freeradius with the use of counters to enforce dialup user time-limits. Is there a way to enforce an

Cannot compile FreeRADIUS

2004-08-16 Thread
hi all: I've successfully ./configure freeradius at redhat7.0 but some problem at make command [EMAIL PROTECTED] freeradius-1.0.0]# make gmake[1]: Entering directory `/home/hyweb/freeradius-1.0.0' Making all in src... gmake[2]: Entering directory `/home/hyweb/freeradius-1.0.0/src' gmake[3]:

unsubscribe

2004-08-16 Thread Maurice Al-Khaliedy
unsubscribe - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

CHAP not working after upgrade from 0.9.3 to 1.0

2004-08-16 Thread Rohaizam Abu Bakar
Just upgraded from 0.9.3 to 1.0 on my FreeBSD 4.9 machine... Previously while on 0.9.3, PAP CHAP working fine... But now... after upgrade to 1.0.. CHAP is not working... The configuration in 1.0 is following previous 0.9.3 version... (rewritten.. not replacing!!) From the debug log below.. It

Re: logging issue to stderr

2004-08-16 Thread richard lucassen
On Sun, 15 Aug 2004 18:17:40 -0400 Alan DeKok [EMAIL PROTECTED] wrote: Ok. The issue there is that the log file is probably opened *after* stdin, stdout, and stderr are closed. So /dev/stderr is a magic file, and doesn't exist any more once stderr is closed. It looks like that indeed.

FreeRadius, PAM and RH Enterprise Linux 3 - cont.

2004-08-16 Thread Mike Bickham
Hi, Thanks for your reply. I have put print statements into the code and get as far as the following line in the .c file: DPRINT(LOG_DEBUG, Got user name %s, user); The script then goes into the initialize routine but does not appear to go any further. Any fprintf statements ro LOG message

clients.conf problem

2004-08-16 Thread Tobias Amon
Hello, i'm trying to run a freeradius-server on Suse 7.0 I have a new installation of freeradius 0.8.1 I changed the clients.conf and useres Files I added client 10.44.3.222{ secret = XXX nastype = other } to clients.conf and username userpassword Password = XXX to users I did not Change the

Username lenght limitation

2004-08-16 Thread Gopal Varshney
Hi All, I am testing the maximum length of username for my application. I tried to use username of length 128, but even after exchanging the MD5 challenge packets, free radius server rejected. It said password required. Is there any size limitation in free radius server. Regards Gopal Varshney

AW: clients.conf problem

2004-08-16 Thread Tobias Amon
Hello, I got a solution, but i donÄt know i fit fits your problem. I changed the values at the false clients.conf . The clients.conf-file used by the server is in the /usr/local/etc/raddb/ directory . if not in your case try finding a clients.conf file useing find -name clients.conf at the

RE : rlm_exec error on Mac OS X

2004-08-16 Thread MINODIER David RD-RESA-LAN
how did you compile it ? tell us the exact line you used in configure make makefile -Message d'origine- De : [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] De la part de Mahesh S Kudva Envoyé : lundi 16 août 2004 15:09 À : [EMAIL PROTECTED] Objet : rlm_exec error on Mac OS X

RE: Handler failed in EAP/peap

2004-08-16 Thread Willey Kurt D
The error is higher up the debug output -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Hugo Sousa Sent: Sunday, August 15, 2004 2:06 PM To: [EMAIL PROTECTED] Subject: Handler failed in EAP/peap Hi all, I'm having a problem in the EAP/PEAP part, I

Re: freeradius and counters.

2004-08-16 Thread Alan DeKok
Shannon Sariman [EMAIL PROTECTED] wrote: Is there a way to enforce an accounting stop packet to the radius server when the counter (rlm_counter) reaches it's allotted time-limit for a particular dialup user? No. The server tells the NAS when the users time limit is up, via the

Re: Conditional statement in file 'users'... more

2004-08-16 Thread Alan DeKok
MINODIER David RD-RESA-LAN [EMAIL PROTECTED] wrote: In a more general case, is there a doc on the various operators (==, =, :=, +=, etc) we can use une the users file ? The man page for the users file. The first paragraph of the sample users file mentions the man page. any *complex*

Re: logging issue to stderr

2004-08-16 Thread Alan DeKok
richard lucassen [EMAIL PROTECTED] wrote: There's nothing magic to stderr, I tried stdout but that didn't work, so I tried stderr which didn't work either. I tried -x and that works, but that also logs passwords in cleartext. But apparently the options log_file = /dev/stderr log_auth = yes

Re: clients.conf problem

2004-08-16 Thread Alan DeKok
Tobias Amon [EMAIL PROTECTED] wrote: I have a new installation of freeradius 0.8.1 Do NOT use 0.8.1! Use 1.0.0. If there's no package for your OS, try 0.9.3. testing with radtest username userpassword 127.0.0.1 0 XXX is no problem but testing with radtest username userpassword

Re: Username lenght limitation

2004-08-16 Thread Alan DeKok
Gopal Varshney [EMAIL PROTECTED] wrote: I tried to use username of length 128, but even after exchanging the MD5 challenge packets, free radius server rejected. It said password required. Why will you not post the *real* error message, or the debug log? Is there any size limitation in

Re: EAP Message with disconnect request

2004-08-16 Thread Alan DeKok
Gopal Varshney [EMAIL PROTECTED] wrote: I am tring to send EAP-Message with disconnect request. In the command prompt I give free text EAP-Msg = This is Disconnect request from server. I expect this message to come in proper EAP-Message format, but it does not happen. What proper

Re: How to send reply for some client ip groups

2004-08-16 Thread kevin J
Alan, I could not find those cases in the users file. What I want is to configure and send different reply packets based on nas type (ie, USR, ASCEND, PM...). I also want to configure some filters based on the clients' ip. You know client ip is different from nas ip if we do proxy, right?

EAP/peap mschapv2 broken since pre3?

2004-08-16 Thread Andrew W. Elble
radius_xlat: '/project/radiusbeta/var/log/radius/radacct/129.21.6.215/auth-detail-20040816' rlm_detail: /project/radiusbeta/var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands to /project/radiusbeta/var/log/radius/radacct/129.21.6.215/auth-detail-20040816 modcall[authorize

Re: EAP/peap mschapv2 broken since pre3?

2004-08-16 Thread Alan DeKok
Andrew W. Elble [EMAIL PROTECTED] wrote: I'm curious as to if anyone has freeradius 1.0 working with EAP/peap/mschapv2? I had done a proof-of-concept with a CVS version of 1.0 (~October 2003) and everything was working fine. Have you tested it with -pre3, or with some CVS version? A

Re: How to send reply for some client ip groups

2004-08-16 Thread Alan DeKok
kevin J [EMAIL PROTECTED] wrote: I could not find those cases in the users file. The users file doesn't support if then, else. The documentation explains what it does support. What I want is to configure and send different reply packets based on nas type (ie, USR, ASCEND, PM...). I

Re: How to send reply for some client ip groups

2004-08-16 Thread Alan DeKok
kevin J [EMAIL PROTECTED] wrote: But, that is attribute-based. What if I want to send a reply with some filters to an IP in the clients file rather than NAS-IP-Address attribute? Use the Client-IP-Address attribute. Alan DeKok. - List info/subscribe/unsubscribe? See

Cannot compile FreeRADIUS

2004-08-16 Thread
hi all: I've successfully ./configure freeradius at redhat7.0 but some problem at make command [EMAIL PROTECTED] freeradius-1.0.0]# make gmake[1]: Entering directory `/home/hyweb/freeradius-1.0.0' Making all in src... gmake[2]: Entering directory `/home/hyweb/freeradius-1.0.0/src' gmake[3]:

Fw: CHAP not working after upgrade from 0.9.3 to 1.0

2004-08-16 Thread Rohaizam Abu Bakar
Anyone can help...?? I've changed a few line in radiusd.conf.. still problem.. But when I divert the request to 0.9.3 version reading same LDAP entry It is OK So the password is confirm in clear form --haizam - Original Message - From: Rohaizam Abu Bakar [EMAIL PROTECTED]

Seg fault in rlm_ldap on Redhat Enterprise Linux 3

2004-08-16 Thread Tarun Bhushan
On Redhat Enterprise Linux 3, when I try to use LDAP (Port = 636 and hence with TLS), FreeRadius seg faults within rlm_ldap. I have been following the various seg faults for this module discussed recently (including on Fedora Core 2, etc), but this appears to be a different problem to Bug #73.

AW: LDAP authorization filter question

2004-08-16 Thread Markus.Wintruff
Maybe huntgroups are that what you are looking for. Markus -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von J. Fowler Gesendet: Dienstag, 17. August 2004 00:08 An: [EMAIL PROTECTED] Betreff: LDAP authorization filter question Hello, ( radiusd: