Re: Newbie: General Questions About Installation

2005-08-09 Thread Paul Hampson
On Mon, Aug 08, 2005 at 08:20:25AM -0700, Kris Benson wrote: FreeRadius users mailing list freeradius-users@lists.freeradius.org on August 7, 2005 at 11:16 -0800 wrote: On Sun, 7 Aug 2005 15:05:50 +0100 Install FreeBSD, go to /usr/ports/net/freeradius and simply type make install clean

Re: Newbie: General Questions About Installation

2005-08-09 Thread Paul Hampson
On Sat, Aug 06, 2005 at 02:09:59PM -0700, Kris Benson wrote: FreeRadius users mailing list freeradius-users@lists.freeradius.org on August 6, 2005 at 00:25 -0800 wrote: in console just type apt-get install freeradius or use synaptic package managed (x windows / gnome ) and do a search for

Re: Pb with EAP/MD5

2005-08-09 Thread Rafael DiazMaurin
Jefri bin Dahari a écrit : I think you haven't put the NAS ip address in clients.conf. Yes I did it : client xxx.xxx.xxx.xxx { secret = XXX shortname= Switch nastype = cisco } - Original Message - *From:* Rafael DiazMaurin

Re: Pb with EAP/MD5

2005-08-09 Thread Jefri bin Dahari
Use 'debug radius authentication' command on your switch and run radiusd -X and see the output. Check whether the vlan you configure on the port is supported on the switch. - Original Message - From: Rafael DiazMaurin [EMAIL PROTECTED] To: FreeRadius users mailing list

Re: freeradius + chillispot + PDA

2005-08-09 Thread shane
yuniva wati wrote: I have some problem, can we use freeradius and chillispot as a login window show at PDA?? because that i know, freeradius use at personal computer or notebook. thanks This is a chillispot related question so you are going to have to modify the login page to be PDA

Re: Licence question, was: Newbie: General Questions About Installation

2005-08-09 Thread Stefan . Neis
Paul Hampson schrieb: And the exclusion of EAP/TLS is due to the well documented conflict between the GPL license of rlm_eap_tls and the OpenSSL license, which makes distributing binaries of rlm_eap_tls that link against openssl impossible, legally. Given that the authors of the software are

Re: rlm_ldap: Attribute User-Password is required for authentication

2005-08-09 Thread melvin
Hi Vladimir, Tks for your help, I've managed to setup the ldap with freeradius. One last question is that is it possible to have freeradius authenticate thru ldap and also the users file. The reason is because I need to create a guest account for guests to login our wireless network. But the

unixodbc: Query sending problem

2005-08-09 Thread Mykhaylo Tyulchenko
Hi, I'm having some problem with sending SQL query to MSSQL 7.0 Server through UnixODBC driver of FreeRadius (module rlm_sql_unixodbc) with error: rlm_sql_unixodbc: ' [unixODBC][FreeTDS][SQL Server]Unclosed quotation mark before the character string ''.' My SQL query is a stored procedure

Re: Pb with EAP/MD5

2005-08-09 Thread Rafael DiazMaurin
Jefri bin Dahari a écrit : Use 'debug radius authentication' command on your switch and run radiusd -X and see the output. Check whether the vlan you configure on the port is supported on the switch. I've got 2 errors in my logs from the switch CISCO 2950 IOS : version : 12.1(22)EA4

iptables rules from freeradius...

2005-08-09 Thread tbsky
Hi: i am using freeradius as wireless authenticator. windows xp client is using wpa + peap. and authentication through wireless ap is ok. now i want to setup some iptables rules for authenticated users. i wonder if this can be done via freeradius. can i find out the mac address

problems with mac address authentication

2005-08-09 Thread robin rapa
I have linux fedora 3 and one lan wifi. I need to install a server freeradius for mac address authentication (only, without certificates). You can help me to configure the server Thank you _ ¿Estás pensando en cambiar de coche?

Re: Licence question, was: Newbie: General Questions About Installation

2005-08-09 Thread Alan DeKok
[EMAIL PROTECTED] wrote: Given that the authors of the software are aware of the problem, wouldn't it be simply possible to modify the licence accordingly? Other projects have a specific grant saying GPL, but linking with OpenSSL is OK. We can do the same. How do companies distributing

Re: rlm_ldap: Attribute User-Password is required for authentication

2005-08-09 Thread Kris Benson
FreeRadius users mailing list freeradius-users@lists.freeradius.org on August 9, 2005 at 02:53 -0800 wrote: Hi Vladimir, Tks for your help, I've managed to setup the ldap with freeradius. One last question is that is it possible to have freeradius authenticate thru ldap and also the users file.

Re: iptables rules from freeradius...

2005-08-09 Thread Alan DeKok
[EMAIL PROTECTED] wrote: now i want to setup some iptables rules for authenticated users. i wonder if this can be done via freeradius. The proper question is: Can the NAS do it? If not, then no configuration of FreeRADIUS will make the NAS do it. can i find out the mac address or

Re: how to return multiple attributes from ldap?

2005-08-09 Thread Dusty Doris
I think so, let me see if I can find a test machine around here and try it. I might need that some day too. On Tue, 9 Aug 2005, kevin wrote: What? So, should I change the ldap attribute values with += ??? Any other way? kevin Dusty Doris wrote: Hi How can I return multiple ldap

Re: how to return multiple attributes from ldap?

2005-08-09 Thread Dusty Doris
On Tue, 9 Aug 2005, kevin wrote: What? So, should I change the ldap attribute values with += ??? Any other way? Yep, it works. I did a test, with this DN only one filter-id was returned. dn: uid=dustytest,ou=users,ou=radius,dc=test,dc=com objectClass: radiusprofile userPassword::

FreeRadius EAP-TLS quesitons

2005-08-09 Thread Hamid Salim
Hello, Two part question: 1. Is it critical to have certificates, dh and random files in etc/raddb/certs directory for eap-tls to work. 2. Is it ok to generate random file as date random thanks a lot. Hamid. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: problem with using rlm_sql for accounting only

2005-08-09 Thread John Donagher
On Tue, 2005-08-09 at 00:01 +0200, Nicolas Baradakis wrote: John Donagher wrote: If the SQL server is inaccessible (i.e. down, or locked), freeradius rejects all radius requests. In my case, since the SQL database is being used only for accounting, this is not desired behavior. The

Re: problem with using rlm_sql for accounting only

2005-08-09 Thread John Donagher
On Mon, 2005-08-08 at 18:09 -0400, Alan DeKok wrote: John Donagher [EMAIL PROTECTED] wrote: If the SQL server is inaccessible (i.e. down, or locked), freeradius rejects all radius requests. In my case, since the SQL database is being used only for accounting, this is not desired behavior.

Re: FreeRadius EAP-TLS quesitons

2005-08-09 Thread Kris Benson
FreeRadius users mailing list freeradius-users@lists.freeradius.org on August 9, 2005 at 10:54 -0800 wrote: Hello, Two part question: 1. Is it critical to have certificates, dh and random files in etc/raddb/certs directory for eap-tls to work. 2. Is it ok to generate random file as date random

sql.conf (update query)

2005-08-09 Thread Michel Bélanger
Hi, I try to add an additional query in the query update in sql.conf. This is possible to make it ? Here what I have test: accounting_update_query = UPDATE ${acct_table1} \ SET FramedIPAddress = '%{Framed-IP-Address}', \ AcctSessionTime = '%{Acct-Session-Time}', \

Re: problem with using rlm_sql for accounting only

2005-08-09 Thread Alan DeKok
John Donagher [EMAIL PROTECTED] wrote: Indeed.. under normal circumstances it wouldn't go down. My issue is that the SQL server is not a critical part of our infrastructure and I don't want it to be (at this point anyway). I'm using it for accounting trend reporting only.. in any event,

Hi. Windows RADIUS server died.

2005-08-09 Thread Derrick MacPherson
I just got asked to try and get a freeradius server running ASAP. I got it installed on a freebsd 5.4 box that I had just finished getting squid running on, not implemented yet still testing. I see freeradius can use ntlm_auth as well, though I'm not clear on it's syntax. I have squid using the

Re: Hi. Windows RADIUS server died.

2005-08-09 Thread Derrick MacPherson
On Tue, 2005-08-09 at 17:22 -0400, Alan DeKok wrote: See radiusd.conf for an example, and the ntlm_auth docs for it's command-line arguments. thank you, reading them now. Is there a way to test if the authentication is passing or failing? - List info/subscribe/unsubscribe? See

Re: how to return multiple attributes from ldap?

2005-08-09 Thread kevin
But, I am still interested in the way returning multiple attributes without changing ldap data. I thought there must be a way. kevin Dusty Doris wrote: On Tue, 9 Aug 2005, kevin wrote: What? So, should I change the ldap attribute values with "+=" ??? Any other way?

Re: Hi. Windows RADIUS server died.

2005-08-09 Thread Alan DeKok
Derrick MacPherson [EMAIL PROTECTED] wrote: Is there a way to test if the authentication is passing or failing? Debug mode? There's no real ms-chap command-line utility that I know of. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Hi. Windows RADIUS server died.

2005-08-09 Thread Derrick MacPherson
Debug mode? There's no real ms-chap command-line utility that I know of. not using ms-chap. I'm not sure what I can use other than turning our firewall at it. Is there any other way? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Hi. Windows RADIUS server died.

2005-08-09 Thread Alan DeKok
Derrick MacPherson [EMAIL PROTECTED] wrote: I'm not sure what I can use other than turning our firewall at it. Is there any other way? The radius client that comes with FreeRADIUS? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Hi. Windows RADIUS server died.

2005-08-09 Thread Derrick MacPherson
On Tue, 2005-08-09 at 18:47 -0400, Alan DeKok wrote: The radius client that comes with FreeRADIUS? hehe. You mean it's that simple? Damn. Sorry didn't realise there was a client at all. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: iptables rules from freeradius...

2005-08-09 Thread tbsky
Hi: sorry i did not describe my environment properly. my radius server is also wireless gateway firewall. so the iptables rules is setting up at radius server, not at the NAS . is this possible? Regards, sky_li [EMAIL PROTECTED] wrote: now i want to setup some iptables rules

Re: iptables rules from freeradius...

2005-08-09 Thread Alan DeKok
[EMAIL PROTECTED] wrote: my radius server is also wireless gateway firewall. so the iptables rules is setting up at radius server, not at the NAS . is this possible? Yes. Run a shell script. See Exec-Program Alan DeKok. - List info/subscribe/unsubscribe? See

Re: FreeRadius EAP-TLS quesiton

2005-08-09 Thread Hamid Salim
-- An HTML attachment was scrubbed... URL: https://list.xs4all.nl/pipermail/freeradius-users/attachments/20050809/95391bfa/attachment.html -- - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html End of Freeradius-Users Digest, Vol

can I get the MD5 codes which is used to encode the origin passwd?

2005-08-09 Thread Lee Bobby
hello,everyone, I am tring to write a NAS codes,and I need a MD5 codes to encode the origin passwd. I use PAP mode.And the passwd is encoded by authenticator and key using MD5.I need such codes in C language. Can anyone help me? regards - List info/subscribe/unsubscribe? See

Re: rlm_sqlcounter noresetcounter

2005-08-09 Thread N White
Anyone have advice/input? N White wrote: I'm having trouble setting up the noresetcounter(Max-All-Session). I'm running freeradius 1.0.4(Debian). I have compiled and added the rlm_sqlcounter.so files to the proper folder in Debian, and freeradius -X shows the module starting up(I have