Re: EAP-TLS with Freeradius, how to check locality ?

2005-02-03 Thread Riccardo Veraldi
Hi, do you know where in the source code freeradius check for certificates ? could you give me a hint about where is located the C file to modify ? thanks Rick Alan DeKok wrote: Riccardo Veraldi <[EMAIL PROTECTED]> wrote: I would like to authenticate my users who have a certificate but I want to ch

RE: mod_auth_radius

2005-02-03 Thread TRANSLER Loic
I'm sorry for this stupid question. I'm using VM-Ware and the source file was in a shared folder. I moved it and it works. Loïc > -Message d'origine- > De : TRANSLER Loic > Envoyé : mercredi 2 février 2005 16:44 > À : freeradius-users@lists.freeradius.org > Objet : mod_auth_radius > >

Timeout with freeradius1.0.1 on redhat-AS-3.1

2005-02-03 Thread Hans-Peter Fuchs
Hello, I test freeradius1.0.1 on redhat-AS-3. If I run freeradius in debug mode (radiusd -X) there are no problems (running 15 hours). If I run freeradius in normal mode (radiusd -y) after several hours all rad- access-requests which are processed via pam lead to a timeout: Wed Feb 2 04:02:07 2

Convert from gnu-radius to freeradius 1.0.1

2005-02-03 Thread Hans-Peter Fuchs
Hello, I want to change from gnu-radius to freeradius 1.0.1. For some old shiva-nases I had a rewrite rule for accounting requests: integer foo() { if (%[User-Name] == "" && *%[Acct-Session-Id]) %[Orig-User-Name] = %[Acct-Session-Id]; else %[Orig-Use

RE: Troubles with EAP-TTLS

2005-02-03 Thread Francisco Sampalo
Thanks Guy. You are right. We installed the server's (and root's) certificate in the client and now, at least, he sees the PRIVATE VLAN, but can´t connect into that VLAN. It seems that the problems are related to the certificates. We are working on it and we'll see. Regards.

Re: Huntgroup "GROUP"?

2005-02-03 Thread Roger Peña Escobio
Mensaje citado por Alan DeKok <[EMAIL PROTECTED]>: > "Cris Boisvert" <[EMAIL PROTECTED]> wrote: > > I have this in the users file > > > > pork1 Client-IP-Address != 208.243.100.5, Auth-Type := reject, Password == here yo say "Client-IP-Address" > > "test" > > > > When I test from that nas I g

Accounting Part is not working

2005-02-03 Thread Sarkis Gabriel
Hi all In the last couple of days i have noticed that the part of accounting is not working, I am using mikrotik as a NAS, when a user logs on and gets authenticated all works fine but when the user logs off the user never gets to Radius to stop the accounting. If i reboot MT NAS it kicks al

RE: Accounting Part is not working

2005-02-03 Thread Cris Boisvert
If you find out let me know I'm doing the same thing... same problem.. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Sarkis Gabriel Sent: Thursday, February 03, 2005 10:08 AM To: freeradius-users@lists.freeradius.org Subject: Accounting Part is not worki

Re: Accounting Part is not working

2005-02-03 Thread Stefan Winter
Hello! >> In the last couple of days i have noticed that the part of accounting is >> not working, >> I am using mikrotik as a NAS, when a user logs on and gets authenticated >> all works fine >> but when the user logs off the user never gets to Radius to stop the >> accounting. >> >> If i reboot

RE: Dialip_admin ?

2005-02-03 Thread Joel Eddy
Could someone give me a link to a howto and faq on dialup_admin? Having issues with the page displaying correctly on apache 2.0 with MySql 3.23.58-9.1 left column is html markup only. No buttons or anything. I've installed by the howto in dialup_admin. But need help finishing up. Joel - List in

redhat9 and freeradius1.0.1

2005-02-03 Thread dominique dalponte
hello I wont to compile freeradius on a redhat9, the make stop with this error somebody can help me best regards dom gmake[4]: Entre dans le répertoire `/usr/src/redhat/BUILD/freeradius-1.0.1/src/lib' gcc -g -O2 -D_REENTRANT -D_POSIX_PTHREAD_SEMANTICS -DOPENSSL_NO_KRB5 -Wall -D_GNU_SOURCE -g -

Re: Dialip_admin ?

2005-02-03 Thread Morgan Nelson
Joel Eddy wrote: Could someone give me a link to a howto and faq on dialup_admin? Having issues with the page displaying correctly on apache 2.0 with MySql 3.23.58-9.1 left column is html markup only. No buttons or anything. I've installed by the howto in dialup_admin. But need help finishing

Problems with PEAP/MSCHAPv2 and LDAP Server

2005-02-03 Thread Benjamin . Doellwanger1
ot; returns ok for request 0 radius_xlat: '/var/log/radius/radacct/xx/auth-detail-20050203' rlm_detail: /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands to /var/log/radius/radacct/x/auth-detail-20050203 modcall[authorize]: module "auth

Re: redhat9 and freeradius1.0.1

2005-02-03 Thread Alan DeKok
dominique dalponte <[EMAIL PROTECTED]> wrote: > dict.c:579: =AB errno =BB non d=E9clar=E9 (premi=E8re utilisation dans ce= > tte fonction) "errno" is defined by the system header files. If errno isn't found, that means your system cannot compile anything. Please install standard development

Re: Strange Error

2005-02-03 Thread Alan DeKok
"Brad Dixon" <[EMAIL PROTECTED]> wrote: > I don't presume anyone has seen the following error and I presume I have > pulled the whole process below. > Maybe however one who knows the code a little better than myself will point > me in the right direction. ... > Thu Feb 3 18:22:34 2005 : Error: r

Re: EAP-TLS with Freeradius, how to check locality ?

2005-02-03 Thread Alan DeKok
Riccardo Veraldi <[EMAIL PROTECTED]> wrote: > do you know where in the source code freeradius check for certificates ? > could you give me a hint about where is located the C file to modify ? src/modules/rlm_eap/types/rlm_eap_tls/* Alan DeKok. - List info/subscribe/unsubscribe? See http://w

Re: Timeout with freeradius1.0.1 on redhat-AS-3.1

2005-02-03 Thread Alan DeKok
"Hans-Peter Fuchs" <[EMAIL PROTECTED]> wrote: > I test freeradius1.0.1 on redhat-AS-3. If I run freeradius in debug > mode (radiusd -X) there are no problems (running 15 hours). If I run > freeradius in normal mode (radiusd -y) after several hours all rad- > access-requests which are processed vi

Re: Convert from gnu-radius to freeradius 1.0.1

2005-02-03 Thread Alan DeKok
"Hans-Peter Fuchs" <[EMAIL PROTECTED]> wrote: > I want to change from gnu-radius to freeradius 1.0.1. I'm not going to complain. > if (%[User-Name] =3D=3D "" && *%[Acct-Session-Id]) > %[Orig-User-Name] =3D %[Acct-Session-Id]; > else > %[Orig-Use

Re: Accounting Part is not working

2005-02-03 Thread Alan DeKok
"Sarkis Gabriel" <[EMAIL PROTECTED]> wrote: > In the last couple of days i have noticed that the part of > accounting is not working, I am using mikrotik as a NAS, when a user > logs on and gets authenticated all works fine but when the user logs > off the user never gets to Radius to stop the acco

Re: Problems with PEAP/MSCHAPv2 and LDAP Server

2005-02-03 Thread Alan DeKok
[EMAIL PROTECTED] wrote: > If i understood it right, the Radius Server should do a bind to LDAP Server > with DN and Password provided. What password? There's no password in MSCHAPv2, and LDAP doesn't do MSCHAPv2. > The success answer from LDAP tells the Radius Server authentication > success

Re: Problems with PEAP/MSCHAPv2 and LDAP Server

2005-02-03 Thread Benjamin . Doellwanger1
Thanks for the fast answer! The person who is responsible for the LDAP Server told me that our LDAP does not send a Password out, for security reasons, but accepts "bindings" with password (see log with radtest,down). That means if the LDAP Server would be somehow configured to send out the

Re: Problems with PEAP/MSCHAPv2 and LDAP Server

2005-02-03 Thread Stefan . Neis
[EMAIL PROTECTED] schrieb: > That means if the LDAP Server would be somehow configured > to send out the > Attribute UserPassword in cleartext, it would work with > MSCHAP? Yes. If Radius gets the cleartext password from somewhere, it can check if the MSCHAP stuff which the user did send is cor

Re: Problems with PEAP/MSCHAPv2 and LDAP Server

2005-02-03 Thread Mearl Danner
You need to check the archives. But I'll answer anyway. Here's an explanation from one of Novell's forums. It's talking about Novells' Edirectory, but would apply to any other LDAP server. You are correct that the FreeRADIUS LDAP module cannot authenticate a MS-CHAP password against eDirectory.

Re: Dialip_admin ?

2005-02-03 Thread Joel Eddy
Thanks for the tip. I think that is it. I can see the info with test.php. But see nothing but text if I use php3. I'll look into apache then. Again thanks for the info. ;-) Joel - Original Message - From: "Morgan Nelson" <[EMAIL PROTECTED]> To: Sent: Thursday, February 03, 2005 10:16 AM S

simultaneous use

2005-02-03 Thread Max Belousov
Hello All,I have configured the user"test1" Auth-Type := Local, User-Password == "test1", Simultaneous Use = 1 Session-Timeout = 1200, Fall-Through = YesUnable to loginListening on IP address *, ports 1812/udp and 1813/udp, with proxy on 1814/udp.Ready to process requests.rad_recv: Access-

MSCHAP V2 local

2005-02-03 Thread DeYoung, Brandon
    Hello all,     Thanks to a little help from the list, I have the following working: 802.1x authentication via PEAP/mschap v2 and ntlm_auth utilizing Active Directory as a backend.   I’m now trying to add a hand full of local accounts, for people/devices who do not ha

Re: MSCHAP V2 local

2005-02-03 Thread Alan DeKok
"DeYoung, Brandon" <[EMAIL PROTECTED]> wrote: > I'm now trying to add a hand full of local accounts, for people/devices who > do not have AD accounts. I've tried adding things like this to the > /etc/raddb/users file: > > test Auth-Type := MS-CHAP, User-Password == "testing" And that will

Re: Dialip_admin ?

2005-02-03 Thread Joel Eddy
FYI, for anyone else running Apache 2.0, MySql 3.23.58-9.1 with modules for php4 and the left column in dialup_admin is nothing but text, here is the fix that I had to do. cd to the /etc/httpd/conf.d and with your favorite text editor open the file php.conf and add this line under AddType AddTy

RE: MSCHAP V2 local

2005-02-03 Thread DeYoung, Brandon
Thanks for the response Alan, and sorry. 802.1x authentication is working via PEAP/mschap v2 and ntlm_auth utilizing Active Directory as a backend. I'm still having problems adding local accounts into the mix. I've read the comments from the radiusd.conf file and I guess I still don't get it. I'

Radius Authentication problem with SER

2005-02-03 Thread M.V. Jaga Mohan
Hi List, I have downloaded freeradius 0.9.1 and SER-0.8.14 source and radiusclient library version 0.4.2. compiled all of them and my radius is working well as I have tested with Radtest. I have compiled SER with radius module and I have got auth_radius.so also. But when I am trying to run ser I am

pam_radius_auth and Redhat 9

2005-02-03 Thread Latham, Andrew
Hi there,   I have had this working perfectly on Redhat 7.3. We now have to move to 9 and was wondering if anyone else had had a problem.   What I am experiencing is that the PAM module is invoked (using sshd) but never sends the request to the RADIUS server. Eventually I get a "Server time

(no subject)

2005-02-03 Thread Anderson Alves de Albuquerque
I can't store userpassword in format clean TXT. Is this possible? This is my system: ---[Server]-- CHAP --> [Radius]--clean TXT --> [LDAP Server] I need that the password of the users stay in format crypt or DES, ie. After I need that RADIUS use crypt or DES to have password in clean

Web interface similar to Dialup Admin but for dialup users to change their login passwords.

2005-02-03 Thread Shannon Sariman
Hi All,   I am using freeradius with mysql and dialup admin. Is there any open source solution out there that can cater for dialup users to manually change their password using a similar web interface like dialup admin? Please help.   Regards,   Shannon

Problems with ttls using SecureW2

2005-02-03 Thread Øystein Gåsdal
Hi again! I've decided to try the now open source SecureW2 supplicant, because I don't think the built-in supplicant in WinXP is any good, especially when logging in to NT Domains. Anyway, when I try that, I encounter a problem, the Freeradius debug gives med this error: I'm just pasting the line