Advice needed (Acct-Session-Id vs. User-Name)

2004-10-28 Thread Roman Suzi
Hi, I need an advice. One of my collegues suggested to drop User-Name for accounting purposes to avoid realm clashes (when CISCO drops realms in some cases). He suggests to store Acct-Session-Id at authorisation and then restore User-Name at accounting stop event to make accounting. He claims

help about freeradius popup reply-message

2004-10-28 Thread
Hi All : I have a stupid question . :( If I edit users file,like this /etc/raddb/users "bobo" Auth-Type := Reject Reply-Message = "Your Accounthas beenDisabled!", When bobo use broswer to Internetthan keyin her's account and password system can popup a message tell bobo , "Your

Radius accounting on VOIP

2004-10-28 Thread Per Jørgensen
I am new to freeradius, so hope some one on this list can guide me in the right direction. I am going to set up a Freeradius server witch collect accounting from the VOIP system based on a cisco 5300 box as NAS, but what sould i change in freeradius for this to work ? Do i have to put in a new

Re: research project

2004-10-28 Thread Martin Pauly
Alan,   Since FreeRADIUS doesn't entger trade shows, or buy advertising space in magazines, it doesn't win awards.  It doesn't even get included in magazine comparisons of RADIUS servers, because the commercial vendors threaten to pull their advertising dollars if FreeRADIUS is mentioned in

Re: Training users to append @realm

2004-10-28 Thread Martin Pauly
I was thinking of redirecting all successfully authenticated users without a or the proper realm to a webpage stating something like: ... If your NAS supports it, sure. The problem is that many NASes dont. Does anyone know if I can force this redirection on a TNT MAX, or have

Re: research project

2004-10-28 Thread Alan DeKok
Martin Pauly [EMAIL PROTECTED] wrote: at least, that's definitely not true for the german c't magazine. Only recently, they ran an long article by Stefan Krecher describing an 8021.x/11i-based WLAN setup using FreeRadius as auth backend. Some on-line publications do write articles about

Re: exec and multiline paras

2004-10-28 Thread Alan DeKok
Jev [EMAIL PROTECTED] wrote: When receiving the following request (below), I want to invoke a external script and pass %{Sip-Uri-User} as a command line argument, but all I get is the first line \n\0068668. The latest CVS snapshots support %{Attribute-Name[n]} to address a specific

Support for EAP and LDAP?

2004-10-28 Thread Scott J. Wolke
Hey All, I'm trying to get away from Steel Belted Radius and after realizing that Freeradius can't auth against LDAP using EAP.noted in the radiusd.conf filedoes anyone have a idea if this is going to be supported in the futureand if yesdo you have an idea of when? Not

Re: Training users to append @realm

2004-10-28 Thread Dana Hudes
On Thursday 28 October 2004 08:04, Martin Pauly wrote: Does anyone know if I can force this redirection on a TNT MAX, or have suggestions on how else to do it? AFAIK, the Ascend MAX TNT doesn't deal with anything above TCP/IP level (nothing like NBAR on modern Cisco gear etc.) Actually,

Re: research project

2004-10-28 Thread Josh Howlett
--On Thursday, October 28, 2004 09:56:50 -0400 Alan DeKok [EMAIL PROTECTED] wrote: THAT'S why they didn't discuss FreeRADIUS: the commercial people saw a pre-print in which an open source product trounced them, and they probably threated to pull their advertising dollars unless mention of

Re: Support for EAP and LDAP?

2004-10-28 Thread Alan DeKok
Scott J. Wolke [EMAIL PROTECTED] wrote: I'm trying to get away from Steel Belted Radius and after realizing that Freeradius can't auth against LDAP using EAP FreeRADIUS can obtain user passwords from an LDAP database, and use those passwords to perform EAP authentication. No RADIUS

attr_rewrite issues

2004-10-28 Thread Brian Ammons
Hello FreeRadius list: I'm having difficulty getting the attr_rewrite module to do...well, anything. I have a working RADIUS installation validating off of a mySQL database. Our existing NASs (Wireless APs) transmit mac addresses as 12 character lower case letter/number combos - this corresponds

Re: attr_rewrite issues

2004-10-28 Thread Dustin Doris
Hello FreeRadius list: I'm having difficulty getting the attr_rewrite module to do...well, anything. I have a working RADIUS installation validating off of a mySQL database. Our existing NASs (Wireless APs) transmit mac addresses as 12 character lower case letter/number combos - this

Setting up EAP-TLS with Freeradius

2004-10-28 Thread Ronald I. Nutter
I have everything compiled but have a few questions that the howto's I have read don't answer - 1) Where do I need to put the scripts that create the certs so that FreeRadius will use them ? 2) Is there a particular location for the certificates to be in ? Thanks, Ron

users-file+sql

2004-10-28 Thread j . dostal
hi all, searching for a solution to use users-file and auth-database at the same time for different users with differen realms. i have to use the database-(users) for dynamical added users (from another application) and the users-file for cronjob added users ... how could i define, that after

changing username in hints file.

2004-10-28 Thread tfike
Okay, this question is similar to something asked before http://lists.freeradius.org/pipermail/freeradius-users/2004-October/037262.html the question there was about a reg/ex to modify the username to mac addy. I would like to do something similiar (though i don't necessarily need the reg/ex)

Re: Setting up EAP-TLS with Freeradius

2004-10-28 Thread Alan DeKok
Ronald I. Nutter [EMAIL PROTECTED] wrote: 1) Where do I need to put the scripts that create the certs so that FreeRadius will use them ? FreeRADIUS doesn't run the scripts. You run them from the command line. 2) Is there a particular location for the certificates to be in ? See the

SUCCESS, now User-Password...was RE: attr_rewrite issues

2004-10-28 Thread Brian Ammons
So...if anyone can get me any advice re: how to check the functionality of the attr_rewrite module I'd appreciate it. Thank you - Brian Ammons Its because you defined the name of the module as mac_colons. Change attr_rewrite to mac_colons in your authorize section. That