Cannot get EAP/TLS working

2007-05-25 Thread prajakta choudhari
Hi all: My setup is a linksys router enabled with radius authentication and client connecting to it. I get the following messages and it just gets stuck on it. Can somebody help in understanding the problem. I am pasting it. Thank You Prajakta [EMAIL PROTECTED] sbin]# ./radiusd -X -A

Re: Freeradius-Users Digest, Vol 25, Issue 117

2007-05-25 Thread [EMAIL PROTECTED]
Ich bin am 25. Mai nicht im Haus und kann Ihre Nachricht erst am Dienstag den 29. Mai bearbeiten. In dringenden Fällen wenden Sie sich bitte an Herrn René Böhm (E-Mail: [EMAIL PROTECTED]). Mit freundlichen Grüßen Tobias Drollinger - List info/subscribe/unsubscribe? See

log_badlogins problem

2007-05-25 Thread satish patel
Dear all I have some problem with dailup admin i got this error when i run log_badlogin script suse:/usr/local/dialup_admin/bin # perl -w log_badlogins /var/log/radius/radius.log /usr/local/dialup_admin/conf/admin.conf Name main::force used only once: possible typo at

Including Vendor specific dictionary file

2007-05-25 Thread H . Theissen
Hi, I have created a vendor specific dictionary file for freeradius. This file includes two attributes for our mini switches. Is it possible to include this file within the next freeradius release? You will find the text below. Kind regards Hubert Theißen Research Development Tel. +49 2166

Re: Including Vendor specific dictionary file

2007-05-25 Thread Patric
[EMAIL PROTECTED] wrote: Hi, I have created a vendor specific dictionary file for freeradius. This file includes two attributes for our mini switches. Is it possible to include this file within the next freeradius release? AFAIK you can just include it via the {sysconfig

Re: Wiki

2007-05-25 Thread Peter Nixon
On Thu 24 May 2007, Doug Hardie wrote: On Sun 20 May 2007, Doug Hardie wrote: I am having problems finding the way to get from the main Wiki page to the configuration information. The pages are there. When I search for something they are found. I just can't figure out how you are

Re: Wiki

2007-05-25 Thread Arran Cudbard-Bell
Peter Nixon wrote: On Thu 24 May 2007, Doug Hardie wrote: On Sun 20 May 2007, Doug Hardie wrote: I am having problems finding the way to get from the main Wiki page to the configuration information. The pages are there. When I search for something they are found. I just can't

Re: FreeRadius crash

2007-05-25 Thread Alan Dekok
Doug Hardie wrote: I am completely unable to replicate this situation on my test system. I can run thousands of requests via multiple radclients without any problems. I can drive the test system to overload and other than responses slow down a bit, it just works properly. #0

Re: AW: Freeradius and rlm_mysql with encrypted PWD's

2007-05-25 Thread Alan Dekok
Rascher, Markus wrote: Thx for your answer. My situation is: I want to authenticate users who are logging into linux systems or cisco systems via ssh. The ssh-Client sends a radius request to the freeradius-server. The Radius-Server can read the user-Password from the request and decrypt

Re: Very critical: Memory leak in freeradius-1.1.6

2007-05-25 Thread Alan Dekok
nikitha george wrote: On 5/23/07, nikitha george [EMAIL PROTECTED] wrote: Please find the valgrind output below. It shows so much memory is still reachable. That's because the server doesn't clean up memory on exit. Run it with the -m flag on the command line, and it will try to clean up

Re: FreeRadius crash

2007-05-25 Thread Doug Hardie
On May 25, 2007, at 01:24, Alan Dekok wrote: Doug Hardie wrote: I am completely unable to replicate this situation on my test system. I can run thousands of requests via multiple radclients without any problems. I can drive the test system to overload and other than responses slow down a

Re: Accounting-Response with invalid signature

2007-05-25 Thread Alan Dekok
Rio Yang wrote: I got the following message from my radius.log. Wed May 23 16:39:11 2007 : Error: Received Accounting-Response packet from 172.16.1.1:1813 with invalid signature (err=2)! (Shared secret is incorrect.) Wed May 23 16:39:11 2007 : Error: Reply from home server 172.16.1.1:1813

Re: FreeRadius crash

2007-05-25 Thread Doug Hardie
On May 25, 2007, at 01:24, Alan Dekok wrote: Doug Hardie wrote: I am completely unable to replicate this situation on my test system. I can run thousands of requests via multiple radclients without any problems. I can drive the test system to overload and other than responses slow down a

Re: freeradius as a middleware between multiple ldap/ADS-servers and CMS

2007-05-25 Thread Alan Dekok
[EMAIL PROTECTED] wrote: Now other schools are also interested in single-sign-in to our moodle. Unfortunately only one ldap-connecting is accepted by moodle at one time. File a bug with moodle. So I'm looking for a middleware. On one side the middleware has to handle multiple

Re: dictionary handling

2007-05-25 Thread Alan Dekok
Wolfgang Rosenauer wrote: since I just begun to use freeradius in production I found some strangeness. The default configuration is to include all dictionaries but I wonder how they are evaluated? As documented. I have a Cisco NAS which sends (at least I think) VSA records and so I

Re: Radius authentication problems

2007-05-25 Thread Alan Dekok
sizo nsibande wrote: We are having a problem testing the authentication process on our radius box, please do not flame me, I am just trying to find out if any of you guys have ever maybe come across any such issue. There is no RADIUS traffic in that debug. I suggest asking the same question

Re: FreeRadius crash

2007-05-25 Thread Alan Dekok
Doug Hardie wrote: Nope. All memory that is used is local. Nothing is retained. Only the authorize module is used. Nothing is dynamically allocated in the module. Are you sure there are no buffer overruns in your module? Are you sure you're calling the FreeRADIUS API correctly?

Re: Including Vendor specific dictionary file

2007-05-25 Thread Alan Dekok
[EMAIL PROTECTED] wrote: I have created a vendor specific dictionary file for freeradius. This file includes two attributes for our mini switches. Is it possible to include this file within the next freeradius release? I've added it, thanks. Alan DeKok. -- http://deployingradius.com

Re: windows 2003 AD authentication with freeradius (for 802.1X)

2007-05-25 Thread A . L . M . Buxey
Hi, The proxy.conf configuration(without it i got realm not found), your document is also missing the tls section of eap.conf. as i said, i didn't found a document that i could follow and immediately gave results. There where always some smaller(but crucial) parts that where missing for

Re: Dynamic VLAN - limiting switchs VLANs?

2007-05-25 Thread Alan Dekok
Robert wrote: I can plug a computer into the switch, have the switch grab the MAC addy, pass it to FR, hit the DB and return what VLAN that MAC belongs to, and then have the switch configure to port to the correct VLAN. Now the complication that I'm facing is that in our environment, a MAC

freeradius 1.1.4 stops answering (why?)

2007-05-25 Thread Roberto S. G.
hi, I'm experiencing strange problems with a compiled freeradius 1.1.4 that I have on a Reh Hat... I've used there other previous freeradius versions without problem, but this one seems to maintain service for just a couple of days, after which it stops authenticating. I had not noticed this

mysql database limit

2007-05-25 Thread satish patel
Dear ALL I have single machine with model name : Intel(R) Pentium(R) D CPU 2.80GHz + RAM 512 - configuration i am plaing to use freeradius-1.0.0 with mysql with 500 users so what about the performance issue so it will working fine in this configuration or not

RE: mysql database limit

2007-05-25 Thread Edvin Seferovic
Use the latest stable version of freeradius. I am using MySQL5 for accouting of 200 users and LDAP for 200 users and ca. 400 machines. No performance issues although my machine is slower. Be nice to your DB and add another 512MB of RAM to the machine ;) Regards, E:S From: [EMAIL

2.0.0-pre1 compile problem on ubuntu

2007-05-25 Thread Norbert Wegener
on an ubuntu 6.06 configure does not show an error with 2.0.0-pre1. Compiling fails: . make[6]: Betrete Verzeichnis '/home/norbert/Desktop/freeradius-server-2.0.0-pre1/src/modules/rlm_perl'^M /home/norbert/Desktop/freeradius-server-2.0.0-pre1/libtool --mode=link gcc -release 2.0.0-pre1 \^M

Freeradius pauses before responding when not running in debug mode

2007-05-25 Thread Patric
Hi all, As per the subject, I have found the following interesting behaviour with freeradius 1.1.6 When running the server in normal mode or in debug level 1 mode : radiusd -y or radiusd -y -x (lowercase x) When sending an access request, the server pauses for a few seconds somewhere in

missing entry for evaluate.c in Makefile.in

2007-05-25 Thread Milan Holub
Hi Alan, I just compiled cvs head and it fails because of not updated makefile. here is a patch: Index: src/main/Makefile.in === RCS file: /source/radiusd/src/main/Makefile.in,v retrieving revision 1.66 diff -u -r1.66 Makefile.in

Re: rlm_sql: processing radcheck radgroupcheck

2007-05-25 Thread Milan Holub
Hi All, On Thu, Apr 12, 2007 at 12:00:26PM +0200, Milan Holub wrote: Here is my patch which enables read_groups option and targets the issue above(rejects user immediately if it's found that the radcheck failed): == it looks like nobody was interested... but anyway the patch contained a bug,

Re: 2.0.0-pre1 compile problem on ubuntu

2007-05-25 Thread Alan Dekok
Norbert Wegener wrote: on an ubuntu 6.06 configure does not show an error with 2.0.0-pre1. ... /home/norbert/Desktop/freeradius-server-2.0.0-pre1/src/lib/.libs/libradius.so -L/usr/local/lib /usr/lib/perl/5.8/auto/DynaLoader/DynaLoader.a -L/usr/lib/perl/5.8/CORE -lperl -ldl -lm -lc -lcrypt

Re: missing entry for evaluate.c in Makefile.in

2007-05-25 Thread Alan Dekok
Milan Holub wrote: Hi Alan, I just compiled cvs head and it fails because of not updated makefile. OK, I've committed a slightly different patch which will hopefully prevent this from happening again. Alan DeKok. -- http://deployingradius.com - The web site of the book

Re: DB handles dying slowly

2007-05-25 Thread Milan Holub
Hi all, However any comments/experience/suggestions to the cause of DB handles dying are welcome! == mea culpa! just to make clear: I was using slightly hacked rlm_sql.c and I did not release the socket when returning from the function... Milan Holub holub (at) thenet (dot) ch

Re: 2.0.0-pre1 compile problem on ubuntu

2007-05-25 Thread A . L . M . Buxey
Hi, on an ubuntu 6.06 configure does not show an error with 2.0.0-pre1. Compiling fails: apt-get libperl-dev alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: DB handles dying slowly

2007-05-25 Thread Milan Holub
Hi Alan, On Wed, May 16, 2007 at 03:38:27PM +0200, Milan Holub wrote: == only during (re)-start I'm getting following message: ERROR: Cannot find a configuration entry for module sql_restart. == with latest CVS head the garbage ERROR message is no more present thanks:) Milan Holub holub (at)

Re: Freeradius-Proxied-To, radrelay and 2.0

2007-05-25 Thread Alan Dekok
Milan Holub wrote: == my humble attempt to add the backwards compatibility for Freeradius-Proxied-To attribute: In 2.0.0, the detail file reader looks for Packet-Src-IP-Address Packet-Dst-IP-Address. The detail module needs to write these, too. Then, the realm module needs to be updated

Authenticating many devices using one attribute

2007-05-25 Thread Brian Johnson
Hello -- We're hoping to begin using radius to authenticate logins to our Cisco routers and Cisco switches. Currently, we're going to start with a group of core routers, but would like to make all of our switches authenticate to radius. Being the networking group for the University, our

Re: 2.0.0-pre1 compile problem on ubuntu

2007-05-25 Thread Kostas Zorbadelos
On Fri, May 25, 2007 at 02:27:48PM +0200, Alan Dekok wrote: Norbert Wegener wrote: on an ubuntu 6.06 configure does not show an error with 2.0.0-pre1. ... /home/norbert/Desktop/freeradius-server-2.0.0-pre1/src/lib/.libs/libradius.so -L/usr/local/lib

Re: Freeradius-Proxied-To, radrelay and 2.0

2007-05-25 Thread Milan Holub
Hi Alanothers, On Mon, May 21, 2007 at 04:57:51PM +0200, Alan Dekok wrote: Milan Holub wrote: I wonder whether there is any use for Freeradius-Proxied-To attribute with freeradius 2.0. It should be there for backwards compatibility, but there are likely better ways of achieving the

Re: Freeradius-Proxied-To, radrelay and 2.0

2007-05-25 Thread Milan Holub
Hi Alanothers, On Mon, May 21, 2007 at 04:57:51PM +0200, Alan Dekok wrote: What I'm trying to achieve actually is freeradius 2.0 + radrelay(using binary from 1.1.6) and above is the show stopper:( Any advise? The radrelay functionality in 2.0 doesn't yet work properly. This was

Re: Authenticating many devices using one attribute

2007-05-25 Thread A . L . M . Buxey
Hi, We're hoping to begin using radius to authenticate logins to our Cisco routers and Cisco switches. Currently, we're going to start with a group of core routers, but would like to make all of our switches authenticate to radius. Being the networking group for the University, our

Bug 233 and 234 - only match one huntgroup per nas

2007-05-25 Thread Walt Reynolds
I have looked at both of these bugs and am not sure I understand the programming, but I do understand that there seemed to be simple solutions to allowing a NAS to be in more than one huntgroup. One had a patch attached and the other mentions a section that needed to be re-added from a

FYI : My workaround for freeradius not sending back an Access-Reject on a failed external script

2007-05-25 Thread Patric
Hey guys, Thought it might interest some of you as to how I worked around the problem where freeradius does not return an Access-Reject if my php script does not exit successfully (in my case because a user should be rejected). The original code that checks the exit status of the script is

Re: Wiki

2007-05-25 Thread Kevin Bonner
On Friday 25 May 2007 04:11:24 Arran Cudbard-Bell wrote: Now which bloody wiki are you using, so I can look up the formatting rules :) http://wiki.freeradius.org/Special:Version says MediaWiki: 1.8.2. -Kevin pgpd5qhwcXFFw.pgp Description: PGP signature - List info/subscribe/unsubscribe? See

Re: Wiki

2007-05-25 Thread Arran Cudbard-Bell
Kevin Bonner wrote: On Friday 25 May 2007 04:11:24 Arran Cudbard-Bell wrote: Now which bloody wiki are you using, so I can look up the formatting rules :) http://wiki.freeradius.org/Special:Version says MediaWiki: 1.8.2. -Kevin

Re: FreeRadius crash

2007-05-25 Thread Doug Hardie
I think I may have found the cause of my crashes. One of the proxy servers or NASs is occasionally sending me an incorrectly formatted authentication request. I have not been able to capture the entire packet yet but I did manage to log part of the last one just as the crash occurred and

Re: rlm_sql: processing radcheck radgroupcheck

2007-05-25 Thread Peter Nixon
On Fri 25 May 2007, Milan Holub wrote: Hi All, On Thu, Apr 12, 2007 at 12:00:26PM +0200, Milan Holub wrote: Here is my patch which enables read_groups option and targets the issue above(rejects user immediately if it's found that the radcheck failed): == it looks like nobody was

Re: Wiki

2007-05-25 Thread Peter Nixon
On Fri 25 May 2007, Doug Hardie wrote: I have disabled the front page's protection (for the time being). I previously turned it on because we were getting too much spam. I should be done with the front page. Some of the lower pages may need some tweaking. The information is all there, but

How to re-forward a request rejected by one proxy server to another proxy server?

2007-05-25 Thread Clark J. Wang
I configuired two proxy servers `radius1' and `radius2' for realm `foo.com' in file `proxy.conf'. And I want those requests rejected by `radius1' to be re-forwarded to `radius2'. How can I do that? Thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html