Re:Re: Questions about latest CVS

2006-09-29 Thread 高嵩
Hi,all >> Does the radiusd server listen on IPv6 address by default?>No.  You have to configure it.   Could you tell me how to configure it  listen on IPv6 address? >> How to use the radclient in Ipv6 ? >Send the request to an IPv6 address? Yes,send the request to the Radius server listening on IPv

Re: help with undocumented attributes

2006-09-29 Thread Alan DeKok
Andrew Long <[EMAIL PROTECTED]> wrote: > I am working with an inherited system (freeradius 0.9.0 on RH). The > system is running but as a new user/admin I am having trouble getting > info on the actual setup. I do 'rpm -qv freeradius' and it returns > freeradius is not installed, yet it IS. Some

help with undocumented attributes

2006-09-29 Thread Andrew Long
Hello freeradius-users, I am working with an inherited system (freeradius 0.9.0 on RH). The system is running but as a new user/admin I am having trouble getting info on the actual setup. I do 'rpm -qv freeradius' and it returns freeradius is not installed, yet it IS. /usr/local/etc/raddb is popul

Re: Accounting Stopped

2006-09-29 Thread sean
Hi Alan, Thanks for taking the time to respond. I've already fixed the problem. It only took a bit of lateral thinking. The ADSL modem wasn't exchanging any information on port 1813. For the life of me I can't understand how it could re-boot and only loose a bit of it's setup. It would have been m

Re: Login-Time and Session-Time Conflict

2006-09-29 Thread Alan DeKok
"Adam Tybor" <[EMAIL PROTECTED]> wrote: > I have the following two rows in my radcheck table and I made sure the > natural sort, without the id, that Session-Timeout comes before Login-Time OK... looking at src/main/auth.c, the Login-Time update of Session-Timeout is done just before the Access-

VSA and other attributes in Access-Accept

2006-09-29 Thread Mohammed Petiwala
Hi: Could anyone please provide me some advice on my question below. Currently I am seeing VSAs in my reply messages from freeRADIUS being passed in Access-Accept, Access-Challenge. I would like to limit certain VSAs to only Accepts, or Challenge. Is this possible - because according to the R

Re: Login-Time and Session-Time Conflict

2006-09-29 Thread Adam Tybor
Alan,I tried that prior and I just confirmed it.I have the following two rows in my radcheck table and I made sure the natural sort, without the id, that Session-Timeout comes before Login-Time and I still always get the Login-Time timespan diff as my Session-Timeout value.  Interestingly enough wh

Re: Why is the default DH keysize only 512 bits?

2006-09-29 Thread Alan DeKok
Jason Wittlin-Cohen <[EMAIL PROTECTED]> wrote: > So, if dh_key_length is being ignored, how is the DH key size > determined? By the DH parameter file? Apparently. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List

Re: repeat until success?

2006-09-29 Thread Alan DeKok
"Proft, Michael" <[EMAIL PROTECTED]> wrote: > Hmm i cant get it to work :( How would the configuration part for > passwd module look (linux) ? Why not post what you did here? That would be the easiest way to solve the problem. Alan DeKok. -- http://deployingradius.com - The web

Re: Accounting stopped

2006-09-29 Thread Alan DeKok
[EMAIL PROTECTED] wrote: > Since a power cut last Sunday FreeRadius has stopped writing to its log > files and updating radacct in MySQL. It is continuing to authenticate > users. It gives no error messages running radiusd -X. I've tried upgrading > from 1.0.3 to 1.1.3 with no effect. I would su

Re: Login-Time and Session-Time Conflict

2006-09-29 Thread Alan DeKok
"Adam Tybor" <[EMAIL PROTECTED]> wrote: > I remember reading somewhere that in cases of both attributes being used, > the most restrictive should be returned, however this is not happening. Can > someone confirm what the real implementation is? We are running freeradius > 1.1.1 on a Gentoo linux p

Re: How to add group in freeradius

2006-09-29 Thread Alan DeKok
"William A. Peroche" <[EMAIL PROTECTED]> wrote: > Can someone explain how to add groups in freeradius. And how to add the user > in that group. See the FAQ, or "man rlm_passwd" Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - T

Re: Freeradius is not restarting properly (fails to quit and becomes a zombie process)

2006-09-29 Thread Alan DeKok
Jason Wittlin-Cohen <[EMAIL PROTECTED]> wrote: > Over the last few days I've been having a recurring problem. Whenever I > start Freeradius either with radiusd in a terminal or as a service in > Debian, I can not restart/kill radiusd properly if it's authenticated > any clients. Restarting the serv

Re: Questions about latest CVS

2006-09-29 Thread Alan DeKok
"=?GB2312?B?uN/h1A==?=" <[EMAIL PROTECTED]> wrote: > Does the radiusd server listen on IPv6 address by default? No. You have to configure it. > How to use the radclient in Ipv6 ? Send the request to an IPv6 address? Alan DeKok. -- http://deployingradius.com - The web site of the

Help to pass a local variable from Freeradius to exec program

2006-09-29 Thread Shankar Ganesh C
Hi All I am trying to pass a integer value from Free radius to exec program . I have tryed to add as a value pair using paircreate() and then added the same to the request->packet->vps using pairadd. Set the lvalue , strvalue etc and passed to the radius_exec_program from rad_accounting module.

Questions about latest CVS

2006-09-29 Thread 高嵩
Hi,all I just installed the radiusd on CVS successfully. There are two questions: Does the radiusd server listen on IPv6 address by default?How to use the radclient in Ipv6 ?   Regards    - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: mysql radacct table no query

2006-09-29 Thread Jan Mulders
you should be putting it in radcheck, so it's checked when you log in. radacct is used to store accounting information (like session times etc :)) Hope this helps, Jan Mulders On 29/09/06, Collen Blijenberg <[EMAIL PROTECTED]> wrote: Hmm, i was testing the mysql backend with freeradius 1.1.3.

mysql radacct table no query

2006-09-29 Thread Collen Blijenberg
Hmm, i was testing the mysql backend with freeradius 1.1.3. looks good at first glance, but i bumped into something essential (for us that is). We like to link MAC addresses with the user account's. what did i do: I added a user in table radcheck. worked! next step, added same user in table:

rlm_perl behaviour

2006-09-29 Thread Garber, Neal
When I call a perl module via rlm_perl and don’t undef %RAD_CHECK and %RAD_REPLY before exiting, rlm_perl duplicates some attributes contained within the hashes.  For instance:   At entry to rlm_perl instance: $RAD_CHECK{‘Ldap-Group’} is an ARRAY: (GroupA, GroupB)   After exiting the s

Re: My FreeRadius don't log anything

2006-09-29 Thread Peter Nixon
On Fri 29 Sep 2006 17:08, Didier Benza wrote: > Hi everybody, > > I am a real newbie to FreeRadius, I am migrating from an existing > Livington radius. > > My concern here is this one : I am unable to configure my server to log > auth requests. > > The two Auth-Type I use here are either "Local" or

My FreeRadius don't log anything

2006-09-29 Thread Didier Benza
Hi everybody, I am a real newbie to FreeRadius, I am migrating from an existing Livington radius. My concern here is this one : I am unable to configure my server to log auth requests. The two Auth-Type I use here are either "Local" or "System", the server doesn't log neither. Here a run

Re: dumb humble question about sqlippool

2006-09-29 Thread Peter Nixon
On Fri 29 Sep 2006 15:23, Guilherme Franco wrote: > Thanks for all the answers Mr. Peter! > > To clarify some things: > >> NONE of the ippool modules let you set the pool name. You HAVE to set > >> Pool-Name = whatever as a check > >> item > > The radcheck ta

Re: Why is the default DH keysize only 512 bits?

2006-09-29 Thread Jason Wittlin-Cohen
Alan DeKok wrote: Jason Wittlin-Cohen <[EMAIL PROTECTED]> wrote: I noticed that the default DH keysize in FreeRadius 1.1.3 is 512 bits. If you're talking about the key length in the EAP-TLS module, it looks like those aren't being used for anything. See the source.

peap client constantly re-authenticating

2006-09-29 Thread Rob Shepherd
Dear list, This may not be the right place to discuss this issue, but radiusd -X is the only info i've got to go on. The windows PEAP client re-authenticates every 10-20 seconds or so. Has anybody else seen this? is it normal behavour? I have a cisco wlan controller, and freeradius 1.1.2. m

Re: dumb humble question about sqlippool

2006-09-29 Thread Guilherme Franco
Thanks for all the answers Mr. Peter! To clarify some things: NONE of the ippool modules let you set the pool name. You HAVE to set Pool-Name = whatever as a check item The radcheck table already have Pool-Name := "whatever" as a attribute, op, value fo

RE: Deny user based on MAC-address

2006-09-29 Thread DESEtech - German P. Santillan
You can use in the users file some like that   DEFAULT Fall-Through = Yes   # === 00:13:96:00:D3:7F == 00139600D37F    Auth-Type := Local, [Some_Input_Attribute]     [Some_Output_Attribute_1],     [Some_Output_Attribute_2]   DEFAULT Auth-Type := Reject     Ger

RE: repeat until success?

2006-09-29 Thread Proft, Michael
> -Original Message- > From: freeradius-users-bounces+proft=medizin.uni- > [EMAIL PROTECTED] [mailto:freeradius-users- > [EMAIL PROTECTED] On Behalf Of > Alan DeKok > Sent: Thursday, September 28, 2006 6:43 PM > To: FreeRadius users mailing list > Subject: Re: repeat until success? > > "

Deny user based on MAC-address

2006-09-29 Thread Torkel Mathisen
Hi,   How can I deny a user from freeradius based on the MAC-address on the PC?   I use users file only.   Do I need MAC Authentication for that ?     Regards, Torkel - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Accounting stopped

2006-09-29 Thread sean
Hi All, Since a power cut last Sunday FreeRadius has stopped writing to its log files and updating radacct in MySQL. It is continuing to authenticate users. It gives no error messages running radiusd -X. I've tried upgrading from 1.0.3 to 1.1.3 with no effect. I've been working round the clock for

Login-Time and Session-Time Conflict

2006-09-29 Thread Adam Tybor
We are using both Login-Time and Session-Time attributes with a rlm_sql configuration and the Login-Time attribute is always overriding the Session-Time.  Meaning that if the Session-Time attribute value is less than the timeSpan difference of the Login-Time, the Login-Time timespan difference is s