Re: rlm_eap: Handler failed in EAP/peap

2006-02-27 Thread Agus Supriyadi
On 2/28/06, Laker Netman <[EMAIL PROTECTED]> wrote: It looks like you didn't include the domain info byhaving --domain=%{mschap:NT-Domain} in your"ntlm_auth" command line in the mschap section of yourradius.conf file. Thanks Laker,,, You're right.. after I added --domain=%{mschap:NT-Domain} to ntlm

Re: FreeRadius and MySQL boot problem

2006-02-27 Thread Diniz Da Rocha
I also had that impression so I did a sleep for 30 secs but still no luck, I was wondering if it has something to do with the user who runs at startup if its not root??? but havent any info on this yet... what os are you running your FreeRadius on???     On 2/28/06, Dennis Skinner <[EMAIL PROTECTE

Re: FreeRadius and MySQL boot problem

2006-02-27 Thread Diniz Da Rocha
do you know how long it *should* take before retrying?? On 2/27/06, Alan DeKok <[EMAIL PROTECTED]> wrote: "Diniz Da Rocha" <[EMAIL PROTECTED]> wrote:> The MySQL server is on another server with ip "myip" I initially thought it > was a firewall block but even with no firewall I get this error. But o

Re: FreeRadius and MySQL boot problem

2006-02-27 Thread Dennis Skinner
Diniz Da Rocha wrote: > The MySQL server is on another server with ip "myip" I initially thought > it was a firewall block but even with no firewall I get this error. But > once the server has started and I run "service radiusd restart" from a > terminal the connect to the MySQL server works fine a

Re: Is it possible to make PAP module understand both CRYPT (MD5) and plaintext passwords?

2006-02-27 Thread Dennis Skinner
Alex Savguira wrote: > Having > pap pap{ > encryption_scheme = crypt > } > pap papplain{ > encryption_scheme = clear > } > If I understand you, then you are redoing what the server already does. FreeRADIUS knows which scheme to use based on the a

Re: rlm_eap: Handler failed in EAP/peap

2006-02-27 Thread Laker Netman
SEE BELOW: --- Agus Supriyadi <[EMAIL PROTECTED]> wrote: > Dear All, > > I've got a problem with my freeradius. I've > installed freeradius 1.1.0. I'm > gonna using EAP/PEAP and MSCHAPv2. The radius > returned Access-Reject message > when I try to authenicate user. > > This is the debug message

Re: Please HELP!!! Any ideas??? MySQL and users file... Difference???

2006-02-27 Thread Dennis Skinner
Alex Savguira wrote: > Alan, > > I've solved my problems already... I've even finished the custom > modification to dialup-admin which takes care of changing the > Crypt-Passwords to User-Passwords for users accessing the new > services. Thanks for clearing things up... > >>> btest| NT-Pa

rlm_eap: Handler failed in EAP/peap

2006-02-27 Thread Agus Supriyadi
Dear All, I've got a problem with my freeradius. I've installed freeradius 1.1.0. I'm gonna using EAP/PEAP and MSCHAPv2. The radius returned Access-Reject message when I try to authenicate user. This is the debug message from freeradius: --- BEGIN DEBUG --- rad

RE: type of lvalue in VALUE_PAIR

2006-02-27 Thread Jonathan De Graeve
> -Oorspronkelijk bericht- > Van: freeradius-users- > [EMAIL PROTECTED] > [mailto:freeradius-users- > [EMAIL PROTECTED] Namens Alan > DeKok > Verzonden: maandag 27 februari 2006 23:17 > Aan: [EMAIL PROTECTED]; FreeRadius users mailing list > Onderwerp: Re: type of lvalue in VALUE_PAIR > >

Re: type of lvalue in VALUE_PAIR

2006-02-27 Thread Alan DeKok
"Seferovic Edvin" <[EMAIL PROTECTED]> wrote: > Okay - but I suppose I will have to patch my NAS ( Poptop server ) to use > Acct-Input-GigaWords and Output- instead of Octets. Still if I patch my NAS > to send GigaWords.. when I use sqlcounter to count the MBs I will still not > be able to compare t

RE: type of lvalue in VALUE_PAIR

2006-02-27 Thread Seferovic Edvin
>"Seferovic Edvin" <[EMAIL PROTECTED]> wrote: >> As I "promised", I am patching freeradius ( sqlcounter actually ) so it >can >> do traffic accounting. I have patched it but since I want to have the >> ability to set the limit by entering the amount of bytes ( in my backend >), >> I am limited by

another sql database

2006-02-27 Thread debik
I have got onother database on my serwer. I it used by ISP accounting. In this database is the table called users where are logins and passwords. I have tried to put in radiusd.conf another module called sql1 and create file sql1.conf When i start radius it says me that the parameters are in

Re: LDAP auth and different use of access_attr

2006-02-27 Thread Alan DeKok
John Keimel <[EMAIL PROTECTED]> wrote: > What we'd rather do is allow access based on the value of access_attr . > So rather than just allowing if it exists, we might later pass on some > extra rights to people in different groups. vpntype: fooor > vpntype: bar vpntype: baz - whatever t

Re: FreeRadius and MySQL boot problem

2006-02-27 Thread Alan DeKok
"Diniz Da Rocha" <[EMAIL PROTECTED]> wrote: > The MySQL server is on another server with ip "myip" I initially thought it > was a firewall block but even with no firewall I get this error. But once > the server has started and I run "service radiusd restart" from a terminal > the connect to the MyS

Re: logging Access-Reject messages

2006-02-27 Thread Geoff Silver
Richard Marriner II wrote: > Geoff Silver wrote: > >> post-auth { >> reply_log >> } >> > > > Mine looks like this, I log to an sql db. I am sure you could replace > "sql" with "reply_log". > > post-auth { >sql >Post-Auth-Type REJECT { >sql >}

Re: type of lvalue in VALUE_PAIR

2006-02-27 Thread Alan DeKok
"Seferovic Edvin" <[EMAIL PROTECTED]> wrote: > As I "promised", I am patching freeradius ( sqlcounter actually ) so it can > do traffic accounting. I have patched it but since I want to have the > ability to set the limit by entering the amount of bytes ( in my backend ), > I am limited by lvalue o

Re: Re[2]: Disconnect the user if reach the limit

2006-02-27 Thread Alan DeKok
Yudi Wijaya <[EMAIL PROTECTED]> wrote: > > For 50MBytes, it's not really possible. > + is there any trick of it? i really want implement that, so when > user reach 500 MBytes will be disconnect and can not login until they > re-fill the deposit. The most you can do is to write a script that ru

LDAP auth and different use of access_attr

2006-02-27 Thread John Keimel
I've a FreeRADIUS server (1.0.2, from debian stable) that is set up to authenticate users of a VPN into the network. I've presently got the firewall talking to FreeRADIUS which then talks to LDAP and check the existence access_attr: vpntype If the users profile has the attribute of vpntype in

Re: freeradius authorization without "username"

2006-02-27 Thread Phil Mayers
???, ?? wrote: rlm_sql (sql): zero length username not permitted modcall[authorize]: module "sql" returns invalid for request 0 This has been discussed at length recently. You would need to patch the code. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/u

re: Client certs with MSCHAPV2 in PEAP

2006-02-27 Thread Norbert Wegener
"Dave Huff" http://lists.freeradius.org/mailman/listinfo/freeradius-users>> wrote: / > For EAP-TLS to work, the client certs have to be />>/ > signed by the server cert. />>/ Signed by the server cert or by the CA cert? I have a CA that signed the />/> server and client certs, and the eap.conf

freeradius authorization without "username"

2006-02-27 Thread ???????, ?? ????????
I have a freeradius, and I need "Calling-Station-Id" for authorization. This is the one attribute, which I select in the radiusd.conf checkval { # The attribute to look for in the request item-name = Calling-Station-Id # The attribute to look for i

how to confirm locally??

2006-02-27 Thread pelusa vali
hi everybody, i'm using debian sarge kernel 2.6.13, openssl 0.9.8a, hostapd 0.5.1, freeradius 1.0.5, madwifi-ng-r1406, i want to use eap-tls in my wlan and over my own ap over linux. so i can install and configure all programs (except hostapd, so instead compile myself i installed it from .deb f

type of lvalue in VALUE_PAIR

2006-02-27 Thread Seferovic Edvin
Hi, I know this question is probably for the developer list, but I think someone can answer me without any further complications ;) As I "promised", I am patching freeradius ( sqlcounter actually ) so it can do traffic accounting. I have patched it but since I want to have the ability to set the

Re[2]: Disconnect the user if reach the limit

2006-02-27 Thread Yudi Wijaya
Hello Alan, Wednesday, February 22, 2006, 12:25:07 AM, you wrote: > Yudi Wijaya <[EMAIL PROTECTED]> wrote: >> How to disconnect user when reach the usage limit (ex: 50 >> hours, 50 MBytes)? depends on they prepaid registration, so it will >> stored at RADIUS (MySQL Database). Everyone can registe

Re: Open Authentication for a realm

2006-02-27 Thread John Oxley
On Fri, Feb 24, 2006 at 11:39:17AM -0500, Dusty Doris wrote: > >I want to have open authentication on a realm and setup an IP pool for > >that realm. So if your username is [EMAIL PROTECTED], you will be > >authenticated, no matter what your password is and you will be given an > >IP from the pool