FreeRADIUS 1.1.6 & max_servers

2007-06-11 Thread Dow, Corey
Hi there, I'm using freeRADIUS 1.1.6 and am authenticating users via NTLM to AD. From time to time, radiusd stops authenticating connections and I see in radius.log that the maximum number of threads has been reached: Fri Jun 8 13:55:54 2007 : Info: The maximum number of threads (32) are activ

Multiple shared secrets?

2007-06-11 Thread Mark J Elkins
Can one have multiple shared secrets for the same client(NAS) ? ie - in clients.conf - something like... client 192.168.10.20{ secret = secret1 secret = secret2 shortname = mynas nastype = other } ... so that if the first secret d

Server dies

2007-06-11 Thread Hugh Messenger
Having been running freeradius in debug mode (with no problems at all) for a month or so while testing and provisioning, it's time to put it in production. Unfortunately, when I run it as a service, it dies after a few hours. No clues, no errors, no nothing . it just silently dies off. Load i

Re: Help with Multiple AD/LDAP

2007-06-11 Thread Ryan Kramer
it works! Just a quick followup for anyone else that might run into it... You need to define the DEFAULT users.conf entry differently as it can apply to different servers individually. DEFAULT LDAP1-Ldap-Group == "WIFIUSER" Filter-ID = "WIFIUSER", Fall-Through=0 DEFAULT LDAP2-Ldap

Help with Multiple AD/LDAP

2007-06-11 Thread Ryan Kramer
Hello, I'm working on a new config to allow multiple AD servers to be hit, and am running into a problem. Just a quick background, I have one server that has multiple root level OU's with users under it. It may not be the recommended design, but for our needs it is suitable. I've set up freera

Re: help in setting up PEAP in freeRADIUS with winXp

2007-06-11 Thread Alan Dekok
Apangshu Saha wrote: > Hi Martin, > Thanks for your reply.Everything you mentioned is configured in eap.conf > file.Still i am facing the problem. If the server says "no such EAP type mschapv2", then the module isn't defined, or the server isn't reading same configuration file you're looking at.

Re: Big "VSA + Proxy" problem

2007-06-11 Thread Guilherme Franco
gle[authorize]: calling auth_log (rlm_detail) for request 1 Mon Jun 11 11:18:18 2007 : Debug: radius_xlat: '/usr/local/var/log/radius/radacct/192.168.1.1/auth-detail-20070611' Mon Jun 11 11:18:18 2007 : Debug: rlm_detail: /usr/local/var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y

Re: Freeradius as a secondary

2007-06-11 Thread Jeff
Ok new issue thats eluding me I uninstalled version 1. then installed version 2 anyway. i resetup the configs and made sure my services file is 1645 radius and 1646 for acct as before anyway when i do a auth with ntradping all connects aok when i do anykind of an accouting request, s

Re: help in setting up PEAP in freeRADIUS with winXp supplicant

2007-06-11 Thread Martin Gadbois
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Apangshu Saha wrote: > rad_check_password: Found Auth-Type EAP > auth: type "EAP" > Processing the authenticate section of radiusd.conf > modcall: entering group authenticate for request 5 > rlm_eap: EAP Identity > rlm_eap: No such EAP type ms

help in setting up PEAP in freeRADIUS with winXp supplicant

2007-06-11 Thread Apangshu Saha
Dear All, I am a newbee in freeRADIUS and unable to setting up PEAP in freeRADIUS with winXp supplicant.On the client side it always show attempting to authenticate.I am getting the following lines at the last of the log file of freeRADIUS.Help me to sort out the problem please. *

Re: freeradius eap-ttls pap ldap

2007-06-11 Thread Stefan Winter
Hi, > I saw in the forum of securew2 that is no free dor windows plataforms. Of course it is. About one year ago, someone hijacked the site and tried for a few hours to make a quick buck "selling" copies. I guess that's where the forum discussions came from. The supplicant is open source and d

Re: POD and HP Products.

2007-06-11 Thread Arran Cudbard-Bell
Phil Mayers wrote: > Arran Cudbard-Bell wrote: >> Hi, >> >> Trying to find out whether any HP products support PoD (Packet of >> Disconnect). I've got a HP2626 ProCurve switch and one of the new HP >> 530 WAPs (released last august). > > If you don't have a reason to believe they *do* i.e. docs

Re: freeradius eap-ttls pap ldap

2007-06-11 Thread emmcosta
[EMAIL PROTECTED] wrote: > Does securew2 support EAP-GTC? > > Ivan Kalik > Kalik Informatika ISP > > > Dana 8/6/2007, "emmcosta" <[EMAIL PROTECTED]> piše: > > >> Hi everyone, >> >> I have a problem with my configuration, authorize is ok but >> authentication fail.I use freeradius 1.1.6 e openlda

Re: POD and HP Products.

2007-06-11 Thread Phil Mayers
Arran Cudbard-Bell wrote: > Hi, > > Trying to find out whether any HP products support PoD (Packet of > Disconnect). I've got a HP2626 ProCurve switch and one of the new HP > 530 WAPs (released last august). If you don't have a reason to believe they *do* i.e. docs saying so, they almost cert

Re: v2 pre1 style regexp modifiers

2007-06-11 Thread Arran Cudbard-Bell
Alan Dekok wrote: > Arran Cudbard-Bell wrote: >> I was wondering if it's possible to use the modifiers with regexp >> like /regexp/i with the v2 config files. > > Sure. Send a patch. :) > > It's a good idea, and probably not that hard to do. I'll add it to > the list... > ty ! , Thanks fo

Re: v2 pre1 style regexp modifiers

2007-06-11 Thread Alan Dekok
Arran Cudbard-Bell wrote: > I was wondering if it's possible to use the modifiers with regexp > like /regexp/i with the v2 config files. Sure. Send a patch. :) It's a good idea, and probably not that hard to do. I'll add it to the list... Alan DeKok. -- http://deployingradius.com

Re: v2 pre1 style regexp modifiers

2007-06-11 Thread Alan Dekok
Arran Cudbard-Bell wrote: > The inequality operator (!=) doesn't appear to work either Fixed. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users

EAP-TLS problem

2007-06-11 Thread shantanu choudhary
hello all, earlier i was having problem of segmentation fault for wpa supplicant, that i have resolved(at least i think so, it was because i was not using xauth module of ath card). but now i am having a problem of validating CA, i am not able to validate server certificate. i am sending u my wp

Re: EAP-Handshakes: every reply runs the full authorize-section

2007-06-11 Thread Arran Cudbard-Bell
Rainer Brinkmann wrote: > FreeRADIUS Version 1.1.0: > > Hello, > we run EAP-TTLS and what we get in Debug-Mode is, that every received > EAP-Packet within the TLS-Tunnel-establish runs the complete > authorize-section and slows down the overall time to create a TTLS-Tunnel. > Reason is, that the

Re: Installing freeradius on hosted directory : can't create /usr/local/sbin

2007-06-11 Thread A . L . M . Buxey
Hi, > [~/public_html/freeradius-1.1.6]# make install > /home/lvkinfon/public_html/freeradius-1.1.6/install-sh -c -d -m 755 > /usr/local/sbin > mkdir: cannot create directory `/usr/local/sbin': Permission denied > make: *** [install] Error 1 you dont have permission to write in that directory

Re: Attribute usages / syntax

2007-06-11 Thread Alan Dekok
PD wrote: > I got the answer myself by some try and error... Why? What's wrong with the documentation that ships with FreeRADIUS? > but only for > session-timeout and called-station-id See the README's for documentation on Login-Time. > + session-timeout is should be on radreply, not radc