LDAP failover on freeRADIUS 1.0.1

2005-05-12 Thread Jan-Piet Mens
I have two freeRADIUS 1.0.1 servers configured with two LDAP backends in order to be able to answer RADIUS requests even if one of the LDAP servers is down. We had a problem the other day, at which time the second LDAP server simply froze and the Radius server waited almost indefinitely (over 3

Re: posgresql how to

2005-05-12 Thread Marcin Jessa
Switch from MySQL? If so, the diffence lies only in knowledge of your particular DB. The database layout is included in the sources of freeradius. On Thu, 12 May 2005 00:15:17 +0700 avudz [EMAIL PROTECTED] wrote: Hello, anybody knows where can i download / read radius-postgre how to ? i

Re[14]: daily limit

2005-05-12 Thread avudz
Hello Marcin, Wednesday, May 11, 2005, 6:32:36 PM, you wrote: MJ Maybe the date format is incorrect? MJ I am not sure what those silly americans use but afair it's MJ of Month-Day-Year format - as logical as using bodyparts as the MJ scale value for meassurements :) MJ What does the debugging

Apple Airport Extreme with EAP-TTLS...

2005-05-12 Thread Achim Friedland
Hello, at our university we're using CISCO APs with EAP-TTLS and everythings works just fine. But at home I tryed to build the same with my Apple Airport Extreme and it's not really working... I configured my iBook for the airport the same way like for the CISCO AP, so I don't think it's a

Re: Re[14]: daily limit

2005-05-12 Thread Marcin Jessa
Hi! On Thu, 12 May 2005 15:42:52 +0700 avudz [EMAIL PROTECTED] wrote: nah nah, you quite right :-) when i change the date format, its work well now :-) I'd propably stumble on the same problem if I was going to implement expiration date on my system. I don't find the american date format

Re: DialupAdmin/LDAP - General Questions

2005-05-12 Thread Mathieu Bénard
Chris Carver a écrit : Mathieu Bénard wrote: 2: From what I read in the /lib/ldap/create_user.php3: $dn = 'uid=' . $login . ',' . $config[ldap_default_new_entry_suffix]; $new_user_entry[objectclass][0]=top;

Re: DialupAdmin/LDAP - General Questions

2005-05-12 Thread Kostas Kalevras
On Thu, 12 May 2005, [ISO-8859-1] Mathieu B?nard wrote: First of all thanks for your answer. What do you mean by modifiying your schema ? What you show is the original LDAP schema provided with freeradius. This schema cannot work with the following statement in dialupadmin (for example): $dn =

Re: HuntGroup + MySQL

2005-05-12 Thread Julien freeradius
Hello Dustin, Thanks for your fast answer. When I put == as the operator for the Huntgroup-Name attribute, I don't have any more result. radius log : rlm_sql (sql): No matching entry in the database for request from user [mytestusername] rlm_sql (sql): Released sql socket id: 4

Re: Apple Airport Extreme with EAP-TTLS...

2005-05-12 Thread Zoltan Ori
On Thursday 12 May 2005 05:21, Achim Friedland wrote: Afterwards I enter my username and password and everything seems to be okay. The 802.1x apple-window I counting my online-minutes, but I can't get any signalstrength information from the AP or send receive pakets via the AP. I think I not

Re: problems with 802.1x - EAP-TLS

2005-05-12 Thread Galvao Rezende
You have how to about 802.1x? 2005/5/10, Vladimir Vuksan [EMAIL PROTECTED]: Galvao Rezende wrote: eaptls_process returned 7 rlm_eap_tls: Received unexpected tunneled data after successful handshake. You need to investigate following. You may want to re-do certificates. Vladimir

Re: Auth-Type = System and DSL Static IP

2005-05-12 Thread Andrey
Not to be mean or anything, but you don't seem to have read the whole email or the full correspondence. The problem only occurs when the Auth-Type is set to System. I have bunch of other accounts (Auth-Type: Local) that work absolutely fine. And to answer your questions, I DID post debug info, and

RE: problems with digest and ser

2005-05-12 Thread Lucas Aimaretto
So you say that if I have a client returning, at authorize_check_query, a table with User-Password = , it will not work for digest ?? I'm saying it's a bad idea, and a case I didn't test. Well ... there are cases where I have no-password users. For this cases, where no-password

Re: HuntGroup + MySQL

2005-05-12 Thread Dustin Doris
Hello Dustin, Thanks for your fast answer. When I put == as the operator for the Huntgroup-Name attribute, I don't have any more result. radius log : rlm_sql (sql): No matching entry in the database for request from user [mytestusername] rlm_sql (sql): Released sql socket id: 4

Re: Auth-Type = System and DSL Static IP

2005-05-12 Thread Dustin Doris
On Thu, 12 May 2005, Andrey wrote: Not to be mean or anything, but you don't seem to have read the whole email or the full correspondence. The problem only occurs when the Auth-Type is set to System. I have bunch of other accounts (Auth-Type: Local) that work absolutely fine. And to answer

Re: Apple Airport Extreme with EAP-TTLS...

2005-05-12 Thread Vladimir Vuksan
Achim Friedland wrote: I configured my iBook for the airport the same way like for the CISCO AP, so I don't think it's a problem at the client. I'm using freeradius-1.0.2 on debian unstable from tarball because of the strange tls-bindings in the offical debian package... When I try to

First Run: Invalid ELF Header

2005-05-12 Thread Terry MacDonald
FreeRadius 0.9.3 OS: SUSE 9 Installed freeradius from SUSE supplied packages. Ran 'radiusd -X' from root and got the following error: radiusd.conf[1186] Failed to link to module 'rlm_expr': rlm_expr.a: cannot open shared object file: No such file or directory So, set up the local env with;

Re: Auth-Type = System and DSL Static IP

2005-05-12 Thread Andrey Furukin
Dustin, I appreciate your help, but everything is working fine now, so you can drop the issue, okay? Thanks. Andrey Quoting Dustin Doris [EMAIL PROTECTED]: On Thu, 12 May 2005, Andrey wrote: Not to be mean or anything, but you don't seem to have read the whole email or the full correspondence.

Re: Auth-Type = System and DSL Static IP

2005-05-12 Thread Dustin Doris
Great. On Thu, 12 May 2005, Andrey Furukin wrote: Dustin, I appreciate your help, but everything is working fine now, so you can drop the issue, okay? Thanks. Andrey Quoting Dustin Doris [EMAIL PROTECTED]: On Thu, 12 May 2005, Andrey wrote: Not to be mean or anything, but you

Re: LDAP failover on freeRADIUS 1.0.1

2005-05-12 Thread Alan DeKok
Jan-Piet Mens [EMAIL PROTECTED] wrote: With the configuration below, each of the LDAP instances is queried sequentially, which is not what I want. I see: It's what you configured. If the first one is down, it falls over to the second one. If the second one is down, there's nothing left to

token card strong authentication

2005-05-12 Thread Maqbool Hashim
Hi, I wish to use One Time Passwords with the freeradius server. I'm trying to find the best way to do this. Unfortunately there are not many of the token card manafacturers that support the freeradius server. At the moment it looks as if Cryptocard are the best bet. I would be very

Comparison

2005-05-12 Thread Paulo C. Panaligan
What do you guys think of "Linspire" compared to other Linux Distributors, especially Red hat Linux? Does it have the same Run Command Console?

RE: Comparison

2005-05-12 Thread mmiranda
Linspire sucks, sucks and really sucks, Paulo, please go somewhere else with your crack, far away from this list. -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]On Behalf Of Paulo C. PanaliganSent: Thursday, May 12, 2005 12:54 PMTo:

RE: Comparison

2005-05-12 Thread mmiranda
I mean CRAP!!! -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]On Behalf Of [EMAIL PROTECTED]Sent: Thursday, May 12, 2005 1:31 PMTo: freeradius-users@lists.freeradius.orgSubject: RE: Comparison Linspire sucks, sucks and really sucks, Paulo, please go somewhere

Freeradius + MySQL + huntgroups configuration and more questions

2005-05-12 Thread dstewart
First posting to group, please be gentle. . . Version: radiusd: FreeRADIUS Version 0.9.3, for host i686-pc-linux-gnu, built on Nov 9 2004 at 11:08:43 Running on SuSE Linux 2.6.5-7.151-smp Fri Mar 18 11:31:21 UTC 2005 i686 i686 i386 GNU/Linux For several months, our system has been working to

Re: RadZap

2005-05-12 Thread Sarkis Gabriel
I have installed freeradius from CVS and i found out that radzap in that is a bin file and it is giving Segmentation Fault, I just want a confirmation if there was any changes made on cvs? Also The Version of radwho.c is 1.44.2.1, and Changelog states that it is the candidate for 1.0.3

peap (ms-chap v2) + ldap bind

2005-05-12 Thread CHui
I would like to know if anyone has a work around to support PEAP (ms chap v2) client access authenticate against a LDAP server with bind operation. Currently, retrieving clear text password from LDAP is not an option. Thanks Cedric

Re: peap (ms-chap v2) + ldap bind

2005-05-12 Thread Vladimir Vuksan
CHui wrote: I would like to know if anyone has a work around to support PEAP (ms chap v2) client access authenticate against a LDAP server with bind operation. Currently, retrieving clear text password from LDAP is not an option. No this is not possible. Only way you can authenticate via

Re: RadZap

2005-05-12 Thread Alan DeKok
Sarkis Gabriel [EMAIL PROTECTED] wrote: I have installed freeradius from CVS and i found out that radzap in that is a bin file and it is giving Segmentation Fault, I just want a confirmation if there was any changes made on cvs? That's fixed. Do a cvs update Alan DeKok. - List

Re: peap (ms-chap v2) + ldap bind

2005-05-12 Thread Vladimir Vuksan
I would like to know if anyone has a work around to support PEAP (ms chap v2) client access authenticate against a LDAP server with bind operation. Currently, retrieving clear text password from LDAP is not an option. This is how I got it going

Re: Freeradius + MySQL + huntgroups configuration and more questions

2005-05-12 Thread Alan DeKok
[EMAIL PROTECTED] wrote: radiusd: FreeRADIUS Version 0.9.3, for host i686-pc-linux-gnu, built on Nov 9 2004 at 11:08:43 You should really upgrade to 1.0.2. What I Need to Accomplish: a. Any given user may have access to any combination of dialin, wireless, dsl The server allows this

Re: token card strong authentication

2005-05-12 Thread Alan DeKok
Maqbool Hashim [EMAIL PROTECTED] wrote: I wish to use One Time Passwords with the freeradius server. I'm trying to find the best way to do this. Unfortunately there are not many of the token card manafacturers that support the freeradius server. At the moment it looks as if Cryptocard

Re: LDAP failover on freeRADIUS 1.0.1

2005-05-12 Thread Jan-Piet Mens
On Thu May 12 2005 at 18:24:09 CEST, Alan DeKok wrote: Jan-Piet Mens [EMAIL PROTECTED] wrote: With the configuration below, each of the LDAP instances is queried sequentially, which is not what I want. I see: It's what you configured. If the first one is down, it falls over to the