Weird huntgroup issue

2005-09-20 Thread Jonathan De Graeve
Hello, I have a weird huntgroup issue. I have users in a group 'artsen' with HuntgroupName = == ^(vpn|ras)$ I have users in group 'stagiars' with HuntgroupName = == hotspot On the radiussystem itself I can successfully authenticate users from group artsen but not from group stagiairs. But I can

Nortel Networks Passport 8600 + Radius AAA

2005-09-20 Thread Inci Gedik
Hi Everyone, I have the same problem. Could someone send me the correct configuration Radiusd.conf , users, clients.conf or if it is necessary dictionary files? Thanks Inci Gedik --I am in the testing

RE: Nortel Networks Passport 8600 + Radius AAA

2005-09-20 Thread Jonathan De Graeve
There were bugs in that release. Upgrade to 3.5.10.0 J. -- Jonathan De Graeve Network/System Administrator Imelda vzw Informatica Dienst 015/50.52.98 [EMAIL PROTECTED] - Always read the manual for the correct way to do things because the number of incorrect ways to do

Re: Weird huntgroup issue

2005-09-20 Thread Michael Mitchell
The first Huntgroup that matches will be used, so in this case vpn will always match for requests with NAS-IP-Address == localhost. Jonathan De Graeve wrote: Hello, I have a weird huntgroup issue. I have users in a group 'artsen' with HuntgroupName = == ^(vpn|ras)$ I have users in group

RE: Nortel Networks Passport 8600 + Radius AAA

2005-09-20 Thread Inci Gedik
a copy.-*P*H*L* __ NOD32 1.1224 (20050920) Information __ This message was checked by NOD32 antivirus system. http://www.eset.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Hashed passwords in the users file???

2005-09-20 Thread Miguel Angel Quiles
Hi, does someone know how to use hashed passwords for the users entries in the users file? I hope someone can help me. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: 12077 error???

2005-09-20 Thread Ben Walding
To me, it looks like your private key file might bea) in the wrong formatb) not contain the private keyOn 9/16/05, Armin Krämer [EMAIL PROTECTED] wrote:I build the deb Files out of the source.-Ursprüngliche Nachricht- Von: [EMAIL PROTECTED][mailto:[EMAIL PROTECTED] ] Im Auftrag von

Multiple LDAPS

2005-09-20 Thread S�bastien Cantos
Hi, I was wondering if there's a way to look for users in differents LDAP trees and/or servers depending of the suffix (@something) in the login. If it's possible could someone show me the config ? Thanks in advance. Regards, -- Sebastien Cantos [EMAIL PROTECTED] Network / System Manager Neopost

Transmitted packet

2005-09-20 Thread Iandc Davies
All, The contents of the transmitted packet include an uint8_t *data. What exactly is this pointing to ? The radius.c code sems to check it the first time round against NULL ? Ian Davies {02476 564662} Internal (x740 4662) IMS-SIPAC Software Development Engineer - List

freeradius EAP/PEAP and LDAP

2005-09-20 Thread François Dagorn
Hello all, I'm trying to configure a secured Wireless network, so I want to use EAP/PEAP/LDAP for authentication and then try WPA to crypt sessions. As a beginner, I'm doing that step by step. So I've done the following : - set up a freeradius server and test it with a simple radius

RE: Transmitted packet

2005-09-20 Thread Jonathan De Graeve
Actie voltooid. Wordt naar zowel Wendy als kathleen gestuurd. J. -- Jonathan De Graeve Network/System Administrator Imelda vzw Informatica Dienst 015/50.52.98 [EMAIL PROTECTED] - Always read the manual for the correct way to do things because the number of incorrect ways to do things

Re: Multiple LDAPS

2005-09-20 Thread Dusty Doris
Hi, I was wondering if there's a way to look for users in differents LDAP trees and/or servers depending of the suffix (@something) in the login. If it's possible could someone show me the config ? Thanks in advance. Sure. First you need to define two ldap configs in radiusd.conf.

RE: Multiple LDAPS

2005-09-20 Thread S�bastien Cantos
Ok, very good. I'm gonna try this. Thanks a lot. Regards, -- Sebastien Cantos [EMAIL PROTECTED] Network / System Manager Neopost DIVA -Message d'origine- De : [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] De la part de Dusty Doris Envoyé : mardi 20 septembre 2005 16:12 À :

Radius PEAP protocol

2005-09-20 Thread Juan Daniel Moreno
Hi everyone, I am trying to create a client's interface for Radius PEAP protocol. The server has donne all I wonder it to do, but now I have a question about the finish handshake message I have to send. When I get the server's cetificate, I get a public key too. I have to public-key-encrypt a

Re: Radius PEAP protocol

2005-09-20 Thread Alan DeKok
Juan Daniel Moreno [EMAIL PROTECTED] wrote: I am trying to create a client's interface for Radius PEAP protocol. Will this be code submitted for inclusion in FreeRADIUS? My question is how can I do that. Am I obliged to get the ssl libraries to public-key-encrypt this packet? Thank you for

Re: Transmitted packet

2005-09-20 Thread Alan DeKok
Iandc Davies [EMAIL PROTECTED] wrote: The contents of the transmitted packet include an uint8_t *data. What exactly is this pointing to ? The transmitted packet. Your terminology is confused: - RADIUS_PACKET = internal FreeRADIUS data structure holdin uint8_t *data -

Re: freeradius EAP/PEAP and LDAP

2005-09-20 Thread Alan DeKok
=?ISO-8859-1?Q?Fran=E7ois_Dagorn?= [EMAIL PROTECTED] wrote: the process is unable to valid the password , the error is as follows : rlm_mschap: Told to do MS-CHAPv2 for xxx with NT-PAssword FAILED: No NT/LM-Password. In this case before I can see

ntlm_auth multiple domains

2005-09-20 Thread Jamie Crawford
Hi, I'm using ntlm_auth to authenticate users in freeradius. My samba server is joined to DOMAINA. When I run ntlm_auth --username=domainauser everything works great. When I run ntlm_auth --username=domainbuser it fails because the user does not exist in domaina which the server is joined

Re: ntlm_auth multiple domains

2005-09-20 Thread Alan DeKok
Jamie Crawford [EMAIL PROTECTED] wrote: When I run ntlm_auth --username=domainauser everything works great. When I run ntlm_auth --username=domainbuser it fails because the user does not exist in domaina which the server is joined to. You need to point winbindd to a global catalog server,

Cisco Privilege Level

2005-09-20 Thread Ryan Sharpe
Hello all, I'm having a problem getting users to default to the right privilege level. aaa authentication login default group radius local aaa authorization exec default group radius local radius-server host xx.20.xx.xx auth-port 1645 acct-port 1646 radius-server key 7 privilege

proxy EAP/PAP ?

2005-09-20 Thread Tim Winders
Hello All - As I can't seem to get freeradius working on my Tru64 box and my box seems to be broken I thought I'd try to install freeradius on a RHEL box and use the fr proxy feature to proxy back to my Tru64 box running the Livinginston Radius server. My question, I want to be able to

Cisco Privilege Level

2005-09-20 Thread Ryan Sharpe
I finally figured it out. I apologize for my own stupidity. It was a syntax error CiscoAVPair = shell:priv-lvl=2 Should be cisco-avpair = shell:priv-lvl2 -- Ryan Sharpe Junior Technical Analyst LARG*net (519) 661-2111 x86356 http://www.largnet.on.ca - List info/subscribe/unsubscribe? See

stdout on startup

2005-09-20 Thread Duane Cox
List: Is there anyway to prohibit (without editing the source or redirecting the output to /dev/null) freeradius from displaying the following message to stdout on startup. [EMAIL PROTECTED]:/# radiusd Tue Sep 20 15:08:47 2005 : Info: Starting - reading configuration files ... Thanks Duane Cox

Re: ntlm_auth multiple domains

2005-09-20 Thread Jamie Crawford
I'm trying to validate a user from two trusted NT4 domains. I cannot get ntlm_auth --username=domainb/domainbuser to work. How are you supposed to validate a user with domain credentials, when you can't pass along the domain information? I think it's more of a limitation with ntlm_auth than

Re: ntlm_auth multiple domains

2005-09-20 Thread Alan DeKok
Jamie Crawford [EMAIL PROTECTED] wrote: I'm trying to validate a user from two trusted NT4 domains. I cannot get ntlm_auth --username=domainb/domainbuser to work. How are you supposed to validate a user with domain credentials, when you can't pass along the domain information? I think it's

Re: ntlm_auth multiple domains

2005-09-20 Thread Jamie Crawford
First Thanks for the help. I solved my own problem in my previous email and didnt realize it. Second This got it working. change radiusd.conf /usr/bin/ntlm_auth --domain=realm--request-nt-key --username=mschap:User-Name

Re: freeradius EAP/PEAP and LDAP

2005-09-20 Thread Vladimir Vuksan
François Dagorn wrote: I'm trying to configure a secured Wireless network, so I want to use EAP/PEAP/LDAP for authentication and then try WPA to crypt sessions. As a beginner, I'm doing that step by step. So I've done the following : - set up a freeradius server and test it with a simple