Re: Version 2.0 is a lot closer to reality...

2007-04-05 Thread Alan DeKok
Arran Cudbard-Bell wrote: At least in 1.1.5 it doesn't fall through properly if a user belongs to multiple groups and the check items in the first group partially match.. In which version did it stop working? Least that my experience. Anyway, nice work on pre 2.0 , looking forward to it

Re : Re : EAP/TTLS PEAP MSCHAP

2007-04-05 Thread Eshun Benjamin
Thanks I can connect windows with PEAP/ MSCHAPv2 . Need to fix the certificates. == Benjamin K. Eshun - Message d'origine De : Arran Cudbard-Bell [EMAIL PROTECTED] À : FreeRadius users mailing list freeradius-users@lists.freeradius.org

Re: FreeBSD FreeRADIUS port updated to 1.1.5, with various enhancements

2007-04-05 Thread Nicolas Baradakis
David Wood wrote: The above patch is tested and working against 1.1.5. Passing --without-docdir to configure generates a warning and prevents the installation of any documentation. If, after any desired tidying up, this can be committed to the CVS for branch_1_1 and HEAD I would be

Re: Version 2.0 is a lot closer to reality...

2007-04-05 Thread Arran Cudbard-Bell
Alan DeKok wrote: Arran Cudbard-Bell wrote: At least in 1.1.5 it doesn't fall through properly if a user belongs to multiple groups and the check items in the first group partially match.. In which version did it stop working? I will investigate, as far as I could tell it

Re: Version 2.0 is a lot closer to reality...

2007-04-05 Thread Arran Cudbard-Bell
Is freeradius development quite closed, or is it open to everyone ? One of our mantras is As always, patches are welcome. However, we get the occasional email from people saying I have a patch... give me CVS commit access. The answer is always No.. Patches get audited for

Re: Version 2.0 is a lot closer to reality...

2007-04-05 Thread Alan DeKok
Arran Cudbard-Bell wrote: So all potential patches should be created against the CVS head, and submitted to the developers mailing list ? That's probably the quickest way. You can also open an issue on the bug tracker, but that isn't always necessary for simple patches. Alan DeKok. --

performace on chainging clients.conf and huntgroup

2007-04-05 Thread Kevin J
Alan, I noticed that more IPs I add to clients.conf and huntgroups, more steep performance declines FreeRadius got. Guessing the linked-list. Have we considered other data structures like hashing or btree? -Kevin

cisco device says % Backup authentication and won't log me in

2007-04-05 Thread Molteni Davide
I configured freeradius on a Fedora Core 6 machine to use PAP against a cisco switch radtest on localhost is successfully. I think radiusd.conf users and clients.conf files are ok From the cisco device after I insert user and password telnetting to it I got: % Backup authentication 000206: Apr

Getting required information from freeradius accounting log

2007-04-05 Thread Diot, Sylvain
Hi all, Is there any kind of tool like a log viewer that would allow me to extract the information I want from the /var/log/radius/acct-radius.log? I'd like to be able to obtain a report that would look like this: +-+ | Session Start Date/Time

problem with freeradius fedors core 5,6

2007-04-05 Thread Jackson Jerry-NPC637
Hi I hope I haven't missed something obvious, but am having trouble getting radius to start after /configure/make/make install running Fedora core 5 or 6. This is the error - [EMAIL PROTECTED] freeradius-1.1.5]# radiusd -X Starting - reading configuration files ...

Re: Version 2.0 is a lot closer to reality...

2007-04-05 Thread Alan DeKok
Arran Cudbard-Bell wrote: So all potential patches should be created against the CVS head, and submitted to the developers mailing list ? That's probably the quickest way. You can also open an issue on the bug tracker, but that isn't always necessary for simple patches. Alan DeKok. --

Re: performace on chainging clients.conf and huntgroup

2007-04-05 Thread Alan DeKok
Kevin J wrote: I noticed that more IPs I add to clients.conf and huntgroups, more steep performance declines FreeRadius got. Guessing the linked-list. Have we considered other data structures like hashing or btree? In the CVS head, clients are in a binary tree. I've successfully tested it

Re: Getting required information from freeradius accounting log

2007-04-05 Thread Alan DeKok
Diot, Sylvain wrote: Is there any kind of tool like a log viewer that would allow me to “extract” the information I want from the /var/log/radius/acct-radius.log? http://freeradius.org/related/ See radiusreport. Alan DeKok. -- http://deployingradius.com - The web site of the book

Re: problem with freeradius fedors core 5,6

2007-04-05 Thread Reimer Karlsen-Masur, DFN-CERT
Hi. Look (http://www.mail-archive.com/freeradius-users@lists.freeradius.org/ at emails/threads to this list with the Subject: freeradius-1.1.5 : Aborted(core dump) and freeradius + branch_1_1 via cvs ? CVS branch_1_1 is your bet. Fixed it here, too. @ Alan: Are you releasing version 1.1.6

Re: cisco device says % Backup authentication and won't log me in

2007-04-05 Thread Alan DeKok
Molteni Davide wrote: I can't figure out what's wrong... It's seems that something missing on the cisco side Read the FAQ about the NAS not seeing the response from the server. Is right that radius send back Access-Accept on port 21645? TO port 21645. Yes, that's how it works. Alan

Re: problem with freeradius fedors core 5,6

2007-04-05 Thread Alan DeKok
Reimer Karlsen-Masur, DFN-CERT wrote: @ Alan: Are you releasing version 1.1.6 fixing this issue? Yes. There are a bunch of Coverity bugs I'd like to fix, too. Maybe early next week. Alan DeKok. -- http://deployingradius.com - The web site of the book

Re : problem with freeradius fedors core 5,6

2007-04-05 Thread Eshun Benjamin
Module: Library search path is /usr/local/lib *** glibc detected *** radiusd: double free or corruption (fasttop): 0x090fcde8 *** if you are installing 1.1.5 then install cvs . $ cvs -d :pserver:[EMAIL PROTECTED]:/source login CVS password: anoncvs $ cvs -d :pserver:[EMAIL

Res: Res: Res: NAS-IP-Address

2007-04-05 Thread Erico Augusto
Let I explain better ... I'm configuring WPA, so the Access Point sends Access-Request RADIUS packets to freeradius, with the Client-IP-Address 10.10.10.1(that is the Access Point IP Address, configured manually), to authenticate user. freeradius receives Client-IP-Address from Access Point. No

RE: Re : problem with freeradius fedors core 5,6

2007-04-05 Thread Jackson Jerry-NPC637
Eshun - Thanks for the info. Bear with me, but from the info I've received on the mailing list it looks like; (there is a fix for this, but it needs to be checked out of cvs built?), correct. I haven't used cvs in a while, but will try an grab this update/fix. Will the

timeouts through a firewall?

2007-04-05 Thread Matt Ashfield
Hi All We are seeing the following error: Error: rlm_ldap: ldap_search() failed: Timed out while waiting for server to respond. Please increase the timeout. Our radius server talks to our LDAP server through a firewall. I'm wondering if this has to do with the session lifetime setting on the

RE: Re : problem with freeradius fedors core 5,6

2007-04-05 Thread Jackson Jerry-NPC637
Last question on this I'm sure. If I wanted to get this update for version 1.1.3? Jerry From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jackson Jerry-NPC637 Sent: Thursday, April 05, 2007 1:28 PM To: FreeRadius users mailing list

Re: Res: Res: Res: NAS-IP-Address

2007-04-05 Thread Alan DeKok
Erico Augusto wrote: Let I explain better ... I'm configuring WPA, so the Access Point sends Access-Request RADIUS packets to freeradius, with the Client-IP-Address 10.10.10.1(that is the Access Point IP Address, configured manually), to authenticate user. freeradius receives

Re: timeouts through a firewall?

2007-04-05 Thread Alan DeKok
Matt Ashfield wrote: Our radius server talks to our LDAP server through a firewall. Don't do that. It's wrong. It breaks the network, as you're discovering. I'm wondering if this has to do with the session lifetime setting on the firewall? Yes. If there are no authentications taking

Re: Re : problem with freeradius fedors core 5,6

2007-04-05 Thread Alan DeKok
Jackson Jerry-NPC637 wrote: Last question on this I’m sure. If I wanted to get this update for version 1.1.3? 1.1.6. See the web site for details when it comes out. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The

[no subject]

2007-04-05 Thread Andrew
When I am goind TTLS/MSChapv2 with wrong username/password comination, I found the FreeRadius server is sending out EAP-Failure message to the Security Supplicant. My question is according to MSChapv2 RFC, a MSChapv2 Failure packet is also supposed to be sent out. Why the MSChapv2 Failure is not

TTLS/MSChapv2 Failure

2007-04-05 Thread Andrew
[sorry for sending the previous email without a subject] When I am goind TTLS/MSChapv2 with wrong username/password comination, I found the FreeRadius server is sending out EAP-Failure message to the Security Supplicant. My question is according to MSChapv2 RFC, a MSChapv2 Failure packet is also

Problem with freeradius and mysql

2007-04-05 Thread José Christian Rodríguez
Hello all When i try to run in debug mode, show and error messages # /usr/local/sbin/radiusd -X Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /etc/raddb/clients.conf Config: including file: /etc/raddb/snmp.conf Config: including

RE: Re : problem with freeradius fedors core 5,6

2007-04-05 Thread Jackson Jerry-NPC637
I appreciate the help from everyone, but ran into the same problem after checking out new source from CVS make clean ./configure Make Make install still get the double free error starting up radius. Is there anything else I need to do besides a (make clean) of the previous installation?

Re: TTLS/MSChapv2 Failure

2007-04-05 Thread Alan DeKok
Andrew wrote: When I am goind TTLS/MSChapv2 with wrong username/password comination, I found the FreeRadius server is sending out EAP-Failure message to the Security Supplicant. My question is according to MSChapv2 RFC, a MSChapv2 Failure packet is also supposed to be sent out. Why the

Re: Problem with freeradius and mysql

2007-04-05 Thread Alan DeKok
José Christian Rodríguez wrote: ... *ERROR: Cannot find a configuration entry for module sql. radiusd.conf[1801] Unknown module sql. radiusd.conf[1730] Failed to parse authorize section. You didn't configure the SQL module. Read radiusd.conf, and look for the word sql. Configure it.

Re: Re : problem with freeradius fedors core 5,6

2007-04-05 Thread Alan DeKok
Jackson Jerry-NPC637 wrote: ... still get the double free error starting up radius. Is there anything else I need to do besides a (make clean) of the previous installation? Make sure that the old version has been removed. Alan DeKok. -- http://deployingradius.com - The web