pam_radius_auth - vasco + dead links on freeradius.org

2005-01-10 Thread Joost De Cock
Hello list, I hope it's ok to submit a question regarding the pam_radius_auth PAM module as there seems to be no separate mailinglist for it. I'm trying to use pam_radius_auth PAM module on a Debian (Sarge) system to authenticate users to a Vasco radius server using their digipass tokens. The

Obtain IP Address from AD/LDAP

2005-01-10 Thread Markus.Wintruff
Hello and Happy new Year, here is my prob, hope someone can help me. I use freeradius to authenticate users against MS Active directory. Most of my users obtain their Ips from ippool within radius, but some should obtain their Address from AD. Who do i get the Address out of the AD and can

Re: authenticate all requests

2005-01-10 Thread Dustin Doris
Hi all, I am sure I saw somebody ask this recently, but I cannot find it. How can I setup radius to accept all requests from a particular NAS, based on the NAS ip address? DEFAULT NAS-IP-Address == 127.0.0.1, Auth-Type := Accept change 127.0.0.1 to the nas you want or add that nas to

Re: limiting Access rights for Remote user by Proxying Radius Server

2005-01-10 Thread Dustin Doris
On Fri, 7 Jan 2005, Cool Man wrote: Hi , My question is how can we send a certain attribute to NAS based on some information or reply from Remote Radius server. My set up looks like (NAS)--(Local Radius)---(Remote Radius) Now if I proxy an authentication request to Remote radius

RE: Radius with SSL

2005-01-10 Thread Willey Kurt D
Use port 636 to your ldaps server, and let the radius server do the work. The hardest part is generating the certificate trust. Sample radiusd.conf for ldaps to Win2K AD: server = 127.0.0.1 port = 636 identity = cn=ldapuser,cn=users,dc=domain,dc=com

errror on make with MySQL

2005-01-10 Thread Lewis Bergman
I apologize for posting an earlier question about a binary to a list that doesn't supply one. I am trying to build freeradius (latest) against Mysql supplied binaries for version 4.1.8. I have installed MySQL-client-4.1.8-0.i386.rpm, MySQL-devel-4.1.8-0.i386.rpm, and

Re: errror on make with MySQL

2005-01-10 Thread Lewis Bergman
Lewis Bergman wrote: Has anybody else tried to compile freeradius against 4.1.8 and if so, how did that go? Asked to soon. It ended up to be the lack of openssl libs causing the error. -- Lewis Bergman Texas Communications 4309 Maple St. Abilene, TX 79602-8044 325-691-3301 800-299-6962 - List

RE: authenticate all requests

2005-01-10 Thread Dustin Doris
Hi all, I am sure I saw somebody ask this recently, but I cannot find it. How can I setup radius to accept all requests from a particular NAS, based on the NAS ip address? DEFAULT NAS-IP-Address == 127.0.0.1, Auth-Type := Accept change 127.0.0.1 to the nas you want or add that

RE: freeradius 1.0 and unix style auth.

2005-01-10 Thread Brian Ertel
Brian Ertel wrote: Sure, but where do I view the debug output? http://www.freeradius.org/faq/#4.11 http://www.freeradius.org/faq/#4.12 Ok, if anyone is still willing to help me out here... Here is my debug info.(BELOW) Yea the NAS IP looks funny, but I guess a Broadcast could

radzap in FreeBSD

2005-01-10 Thread Luiz Gustavo Anflor Pereira
Hello all There is some problem about radzap 0.9.1 in a FreeBSD system? Why it does not zap the users from radutmp? Do you know anything about freeradius-snapshot-20030514? thank you very much! Luiz Gustavo - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius 1.0 and unix style auth.

2005-01-10 Thread Alan DeKok
Brian Ertel [EMAIL PROTECTED] wrote: I was under the impressesion that radiusd would use PAP to recognize the encrypted passwords of the /etc/passswd file. Yes. If the password is correct. Since the module is saying that the password isn't correct, I'm not sure what else I can add.

Re: Multiple NAS Vendors, one user-id?

2005-01-10 Thread James Feger
On Fri, 7 Jan 2005, Dustin Doris wrote: On Fri, 7 Jan 2005, Dustin Doris wrote: Maybe you can do groups. For example, setup an unlimited group and a read_only group. Then put the users into the appropriate group. Have your users file say something like. DEFAULT Huntgroup-Name == Juniper,

dialup_admin - blank right frames

2005-01-10 Thread Lewis Bergman
Freeradius 1.0.1 Mysql-max-4.1.8 Apache 2.0.46 PHP 4.2.3 (from rpm) register globalsOn Magic QoutesOff Most of the right frames come back empty. Technically, they come back with some html but no information. No php errors are reported. To try

RE: authenticate all requests

2005-01-10 Thread Dustin Doris
On Mon, 10 Jan 2005, Robert Ulbrich wrote: Hi all, I am sure I saw somebody ask this recently, but I cannot find it. How can I setup radius to accept all requests from a particular NAS, based on the NAS ip address? DEFAULT NAS-IP-Address == 127.0.0.1,

RE: freeradius 1.0 and unix style auth.

2005-01-10 Thread Brian Ertel
Brian Ertel [EMAIL PROTECTED] wrote: I was under the impressesion that radiusd would use PAP to recognize the encrypted passwords of the /etc/passswd file. Yes. If the password is correct. Since the module is saying that the password isn't correct, I'm not sure what else I can

RE: freeradius 1.0 and unix style auth.

2005-01-10 Thread Brian Ertel
Does anyone know of any known issues with freeradius and Fedora Core ? __ Brian Ertel Network Administrator Amherst College [EMAIL PROTECTED] 413.542.8320 __ -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Alan

Re: freeradius 1.0 and unix style auth.

2005-01-10 Thread Thor Spruyt
Brian Ertel wrote: Does anyone know of any known issues with freeradius and Fedora Core ? Runs out of the box on Fedora Core 1 -- Regards, Thor Spruyt E: [EMAIL PROTECTED] W: www.thor-spruyt.com M: +32 (0)475 67 22 65 Bestel nu uw exemplaar van Operationele verkoop (Walter Spruyt - Liesbeth

Re: freeradius 1.0 and unix style auth.

2005-01-10 Thread Alan DeKok
Brian Ertel [EMAIL PROTECTED] wrote: So I just added a new user (again) the debug gave me the same results, no PAP indicated and invalid password Are you using the default configuration, or did you edit it? As I said, the configuration FreeRADIUS uses WORKS. If you edit it without

8e6 technologies and radius

2005-01-10 Thread Terry J Fike Jr
Has anyone out there used these boxes with freeradius? We are trying to set up a demo (to see if it work/if we can get it working) and what i have gotten from the 8e6 is that an attribute needs to be added to the user, the attribute is Class (value 25?) and it does show up in the base

Re: PEAP and LDAP

2005-01-10 Thread Alan DeKok
AJ Grinnell [EMAIL PROTECTED] wrote: I am getting mixed messages hear. Is it possible to authenticate against an LDAP server using 801.1x PEAP? The mixed messages are because of a confusion as to how authentication works. See my previous messages on the list, where I discuss this in detail.

Re: 8e6 technologies and radius

2005-01-10 Thread Alan DeKok
Terry J Fike Jr [EMAIL PROTECTED] wrote: and what i have gotten from the 8e6 is that an attribute needs to be added to the user, the attribute is Class (value 25?) and it does show up in the base dictionary file (but as requiring an octet value not a string which the 8e6 box wants).

Re: PEAP and LDAP

2005-01-10 Thread AJ Grinnell
That is the answer I was waiting to hear. Thank you very much for your quick response. On Mon, 10 Jan 2005 20:53:34 -0500, Alan DeKok [EMAIL PROTECTED] wrote: AJ Grinnell [EMAIL PROTECTED] wrote: I am getting mixed messages hear. Is it possible to authenticate against an LDAP server using

What is X-Ascend-Data-Rate Attributes represent?

2005-01-10 Thread Marendra Nutriaji
hi all, What is X-Ascend-Data-Rate Attributes represents? does it represent the connection speed of the dial in connection? What's the difference between attribute Ascend-Xmit-Rate ? i hope somebody could help me Thank you Marendra - List info/subscribe/unsubscribe? See

Re: 8e6 technologies and radius

2005-01-10 Thread Terry J Fike Jr
They use the Class attribute to tell their box what users are being filtered and how (which filtering ruleset). but it means that either the nas device has to send the data to it, or i can radrelay it to the 8e6 box (which is what i'm using for testing at the moment). it also has the ability

Configuring IP pool

2005-01-10 Thread Jacques VUVANT
Hi I've configured freeradius with EAP/TLS successful. Now I I would like to create an IP Pool on Freeradiusassign it to a wireless user. How should I configure then ? Someone can help me ? Thanks Jacques

Re: 8e6 technologies and radius

2005-01-10 Thread Mike O'Connor
Terry J Fike Jr wrote: They use the Class attribute to tell their box what users are being filtered and how (which filtering ruleset). but it means that either the nas device has to send the data to it, or i can radrelay it to the 8e6 box (which is what i'm using for testing at the moment).