adding new modules into Makefile

2004-10-19 Thread Geissbühler Johannes
Hi there could anyone tell me how to include a new module into the Makefile ? Is there an easy way, so that the new module is also compiled when performing make and also installed when entering make install thanks a lot for your help !! Johannes - List info/subscribe/unsubscribe? See http:/

EAP TLS: "Receiving unexpected Tunneled Data"

2004-10-19 Thread Beekmann \(EXT\), Lars
Hi,   I’m using freeradius v1.0.1 on Suse Linux 9.1 with EAP-TLS for authentication. After installing new certs, created with my own scripts I get the Message "Receiving unexpected Tunneled Data". Does anyone have a clue what went wrong ?!   THX Starting - reading configuration

Cisco NAS not authenticating

2004-10-19 Thread mahmo_t
Guys, I cannot get my cisco 5300 to get authentication from the radius box. I would appreciate any help. Thanks Tariq Output from the radiusd -X gives: Listening on authentication *:1812 Listening on accounting *:1813 Ready to process requests. rad_recv: Access-Request packet from host 172.10.

about mod_auth_radius on APACHE

2004-10-19 Thread Yyc
hi all, Anybody can give me an html/php example for apache server which can be used as a radius client to do WEB authentication? I'm not familiar with web programing. Thanks. Regards. Yyc And the vision that was planted

Re: about mod_auth_radius on APACHE

2004-10-19 Thread Josh Howlett
josh. --On Tuesday, October 19, 2004 18:28:30 +0800 Yyc <[EMAIL PROTECTED]> wrote: hi all, Anybody can give me an html/php example for apache server which can be used as a radius client to do WEB authentication? I'm not familiar wit

Re: setting User-Name to 'modified' mac address

2004-10-19 Thread Kyriaki Gali
you can do this in perl my $example = 11-c0-4f-40-47-b4; $example =~ /(\d+)\-(\w\d)\-(\d\w)\-(\d+)\-(\d+)\-(\w\d)/; my $one = ${1};#11 my $two = ${2};#c0 etc... when you have more than one digits you must write \d+ and also for words \w+. regular expretions are case sensitive for exampl

Re: Cisco NAS not authenticating

2004-10-19 Thread Paul
[EMAIL PROTECTED] wrote: Listening on authentication *:1812 Listening on accounting *:1813 Ready to process requests. rad_recv: Access-Request packet from host 172.10.30.10:1645, id=110, length=59 Ignoring request from unknown client 172.10.30.10:1645 I'm new at this and this is just a guess, bu

Re: D-Link DWL-2700AP Enterprise Access Point

2004-10-19 Thread Paul
Gene Rouse wrote: I have recently completed a freeradius install and tested it using NTradping. Everything looks good. My access point is a D-Link DWL-2700AP outdoor access point. It supports (among other things) WPA-RADIUS and 802.1x. The AP is configured to use 802.1x on port 1812 for auth an

Wireless 802.1x Help Please

2004-10-19 Thread [EMAIL PROTECTED]
Hi Group,   Im having authentication problems using FreeRadius with my wireless access point. Using radiusd -X I can see that the radius server is starting error free.   I have it setup to use peap and all the configurations seem correct. I have the shared secret set in the clients.conf fo

Freeradius on S390

2004-10-19 Thread Kinder Martyn G
Hi, I have compiled Freeradius v1.0.1 onto an IBM S390 clone. (Port 1812) All OK. I am running the daemom in Diagnostic mode (-X). I am using a mysql database, but I don't think that's relevant. Using NTRADPING from my Windoze box, the daemon responds with: rlm_sql (sql): Released sql socket

Re: Freeradius on S390

2004-10-19 Thread Josh Howlett
All networking checks out OK and no Firewalls in the way. Any suggestions please? Double-check your assertion about firewalls. Remember that your Windows box may be running a host firewall. josh. -- --- Josh Howlett, Networking & Digital Com

Re: Cisco NAS not authenticating

2004-10-19 Thread Costas Christonis
You have to instert a record in the naslist file with the ip of your NAS. That's what is missing and thats why the radius says that is an unknown client Also you have to do the same with the file acct_users so you will have accounting too. mtcu> Guys, mtcu> I cannot get my cisco 5300 to get

答复: Freeradius on S390

2004-10-19 Thread Yyc
Check windows XP firewall attached by SP2. Regards. Yyc And the vision that was planted in my brain. Still remains with the Sound of Silence. -邮件原件- 发件人: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] 代表 Kinder Martyn G 发送时间: 2004年10月19日

Re: setting User-Name to 'modified' mac address(continued)

2004-10-19 Thread Alan DeKok
"Jose Guevarra" <[EMAIL PROTECTED]> wrote: > "" Perl supports "\w" in regular expressions. Posix expressions (which > the libraries from your system the server uses) do not support "\w"."" > > how do I tell which 'libraries' are being used hence the supported regex > syntax/capabilities? You

Re: adding new modules into Makefile

2004-10-19 Thread Alan DeKok
=?iso-8859-1?Q?Geissb=FChler_Johannes?= <[EMAIL PROTECTED]> wrote: > could anyone tell me how to include a new module into the Makefile ? Is > there an easy way, so that the new > module is also compiled when performing make and also installed when > entering make install Put the module into src

Freeradius on S390

2004-10-19 Thread Kinder Martyn G
Apologies for not replying directly to the thread, but I'm on a daily digest. No Firewall running here. Definitely. I have been trying to test locally using radtest [EMAIL PROTECTED] radtest martyn password localhost 10 #secret# However, I get Usage: radtest user passwd radius-server[:port] n

RE: Freeradius on S390

2004-10-19 Thread Kinder Martyn G
Usage: radtest user passwd radius-server[:port] nas-port-number secret [ppphint] [nasname] Obviously a syntax error, but I don't know where - any clues? KM ___ Managed to sort it. We have two IP addresses assigned to the server, the

error authenticating wireless user

2004-10-19 Thread [EMAIL PROTECTED]
Hi Group,   Im having authentication problems using FreeRadius with my wireless access point. Using radiusd -X I can see that the radius server is starting error free.   I have it setup to use peap and all the configurations seem correct. I have the shared secret set in the clients.conf fo

PIX and Freeradius

2004-10-19 Thread Rangel, Luciano
Hello, I have a 515 E PIX Firewall using Freeradius authentication. Does anyone knows how can I block some VPN simultaneous connections (user to lan)? Thanks Luciano Estevam Rangel Network & Internet Security Atos Origin Rua Itapaiuna, 2434 São Paulo - SP Brasil Phone +55 (11) 2183-2678 [EMAIL

Re: problem authenticating to passwd/shadow files

2004-10-19 Thread Alan DeKok
"Cameron Birky" <[EMAIL PROTECTED]> wrote: > scenario 3. > when I have the radius plugin in the options.pptpd file, refuse > pap/chap/mschap, require mschapv2 > and mppe-128. authentication fails, with the following error from debug. ... > rad_check_password: Found Auth-Type System > auth: typ

Re: error authenticating wireless user

2004-10-19 Thread Alan DeKok
"[EMAIL PROTECTED]" <[EMAIL PROTECTED]> wrote: > I have it setup to use peap and all the configurations seem correct. > I have the shared secret set in the clients.conf for the AP and the same > key set on the Radius section along with the IP of the server on the AP. Yup. The debug log shows th

Re: error authenticating wireless user

2004-10-19 Thread [EMAIL PROTECTED]
Hi Alan thanks for the reply. The supplicant is using Windows XP with SP2 installed (just the vanilla windows, not a wifi card installed supplicant) I have read in places that the XP supplicant using peap does not need a certificate installing yet in other places it says it should have. I have n

Re: error authenticating wireless user

2004-10-19 Thread [EMAIL PROTECTED]
Additionally Sending Access-Challenge of id 134 to 192.168.0.253:1072 that is the IP of my Wireless AccessPoint as the laptop does not have an IP yet as it is set to dhcp. I dont think this is important however. Regards Dave - Original Message - From: "Alan DeKok" <[EMAIL PROTECTED]> To:

Re: error authenticating wireless user

2004-10-19 Thread [EMAIL PROTECTED]
Hi Having read a little more I added the certificate as it was falling down at responding with the cert back to the radius server. After adding it, HEY PRESTO! Sending Access-Accept of id 155 to 192.168.0.253:1076 Regards Dave - Original Message - From: "Alan DeKok" <[EMAIL PROTECTED]> T

GDB output : Problem with PEAP auth using xp clients

2004-10-19 Thread atul dhingra
So you're still getting the core dump. Let me guess... you have two versions of OpenSSL installed, and you built the server without using "--disable-shared". >> Fix one of those two problems, and it will work. >> Alan DeKok. I am still getting the same dump, I have used --disable-shared while b

Reauthenticate User

2004-10-19 Thread Nurul Faizal Bin M.Shukeri
Hi again..,   Anyone plz help me. How to reauthenticate user every example 30 min without reenter username and password ?       Nurul Faizal Bin M.Shukeri Pusat Komputer, Universiti Sains Malaysia.  

Re: error authenticating wireless user

2004-10-19 Thread [EMAIL PROTECTED]
Hi again, Ok so now I have the supplicants working after manually setting up the certificates on the clients. What is the best way of setting up a certificate server so that this kind of thing can be done seamlessly ? Manually adding certificates to 100's of laptops does not sound like my cup of

Re: Reauthenticate User

2004-10-19 Thread Julius Igugu
This will depend on your NAS/RAS. Which one do you have? --- "Nurul Faizal Bin M.Shukeri" <[EMAIL PROTECTED]> wrote: > Hi again.., > > > > Anyone plz help me. How to reauthenticate user every example 30 min without > reenter username and password ? > > > > > > > > Nurul Faizal Bin

Logging Vendor Specific Attributes in MySQL

2004-10-19 Thread Wade Kemp
I have just got freeradius 1.0.1 up on a solaris 9 machine, and my boss wants to be able to log some of the vendor specific information in the start/stop packets. Anyone have a pointer where I should look to be able to add those attributes to the logging ? Thanks in advance Wade - List info/s

Re: GDB output : Problem with PEAP auth using xp clients

2004-10-19 Thread Alan DeKok
atul dhingra" <[EMAIL PROTECTED]> wrote: > Please find below the gdb output, would appreciate your comments: ... > (gdb) bt > #0 0x401420d7 in BIO_read () from /lib/libcrypto.so.0.9.7 > #1 0x40290ffe in tls_handshake_send (ssn=0x40290798) at tls.c:230 Look at the parameters passed by that line

Re: error authenticating wireless user

2004-10-19 Thread Alan DeKok
"[EMAIL PROTECTED]" <[EMAIL PROTECTED]> wrote: > Manually adding certificates to 100's of laptops does not sound like my cup > of tea. Each laptop has to have a copy of the server certificate for PEAP to work. There really isn't any alternative. And because it's Windows, it's difficult to i

Re: Logging Vendor Specific Attributes in MySQL

2004-10-19 Thread Alan DeKok
Wade Kemp <[EMAIL PROTECTED]> wrote: > I have just got freeradius 1.0.1 up on a solaris 9 machine, and my boss > wants to be able to log some of > the vendor specific information in the start/stop packets. Anyone have > a pointer where I should look to be able to add those attributes to the > l

Calling-Station-ID

2004-10-19 Thread Gene Rouse
OK. I finally got my NAS to talk to freeRADIUS. Since we are a totally wireless ISP and don't want usernames and passwords (except for the email servers) how can we configure freeRADIUS to authenticate on the MAC address of the wireless client only? - List info/subscribe/unsubscribe? See http:

Re: Reauthenticate User

2004-10-19 Thread Nurul Faizal Bin M.Shukeri
I’ve got cisco aironet 350 series AP.   ---   This will depend on your NAS/RAS.   Which one do you have?   --- "Nurul Faizal Bin M.Shukeri" <[EMAIL PROTECTED]> wrote:   > Hi again.., > >  > > Anyone plz help me. How to reauthenticate user every example 30 min without > ree

PEAP and PAE

2004-10-19 Thread Gene Rouse
In order to use 802.1x my NAS manufacturer says that the server must support PAE. Does freeRADIUS support PEAP and PAE? Gene - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: D-Link DWL-2700AP Enterprise Access Point

2004-10-19 Thread Gene Rouse
My Windows wireless card is set for 802.1x using PEAP. How do I set up PEAP on the radius box? > -Original Message- > From: [EMAIL PROTECTED] [mailto:freeradius- > [EMAIL PROTECTED] On Behalf Of Paul > Sent: Tuesday, October 19, 2004 7:06 AM > To: [EMAIL PROTECTED] > Subject: Re: D-Link D

Re: D-Link DWL-2700AP Enterprise Access Point

2004-10-19 Thread Paul
Gene Rouse wrote: My Windows wireless card is set for 802.1x using PEAP. How do I set up PEAP on the radius box? I might as well give you this link before anyone else does: http://tldp.org/HOWTO/8021X-HOWTO/freeradius.html#confradius - List info/subscribe/unsubscribe? See http://www.freeradi

Re: Calling-Station-ID

2004-10-19 Thread Paul
Gene Rouse wrote: OK. I finally got my NAS to talk to freeRADIUS. Since we are a totally wireless ISP and don't want usernames and passwords (except for the email servers) how can we configure freeRADIUS to authenticate on the MAC address of the wireless client only? Very bad idea since MAC add

Re: problem authenticating to passwd/shadow files

2004-10-19 Thread Cameron Birky
thanks for the response, it is comforting to know that I am not entirely losing it! of course, that raises other questions. 1. is that why everybody on the list seems to use sql as a back end, so that the db can handle the encrypted passwords, and not have to make radius do it? 2. what is the b

RE: error authenticating wireless user

2004-10-19 Thread Peter Hicks
What did you do to import the certificate? I know it seems like a dumb question but I have used the IE import facility yet I am getting the same TLS_accept error as you reported. I have also tried importing .pem and .der certificates but it hasn't made a difference. EAP-TLS works fine so the certi