Re: freeradius 1.1.6 / syslog problems

2007-07-02 Thread Alan DeKok
Andreas Wetzel wrote: > I installed freeRadius 1.1.6 on a FreeBSD 6.2-RELEASE system from the ports > collection, and am trying to get it to log via syslog. I followed the > instructions from the wiki for configuring radiusd to use syslog, but when > radiusd starts, I get the following: 1.1.6 do

Freeradius and MySQL problem!!!

2007-07-02 Thread Ackbar Joolia
Dear all, I have been using freeradius properly configured with mysql for some time now. However it suddenly stopped working. What more, I upgraded to the 1.6 version, and now when I run radiusd -X, it doesn't even show that its tied in with the MySQL database... Can anyone please help me? I ha

Re: Using two tables (postgreSql) to validate users

2007-07-02 Thread Krzysztof Olędzki
On 2007-06-30 17:24, Daniel Bojczuk wrote: > Hi again... > > I have a doubt: Is it possible to use two tables to check the users? I > need to do something like this... Freeradius checks if the user is valid > on the table 1, if it returns true the user is validated, but if the > return is false, f

Re: Freeradius and MySQL problem!!!

2007-07-02 Thread tnt
You haven't posted your radiusd -X output. Ivan Kalik Kalik Informatika ISP Dana 2/7/2007, "Ackbar Joolia" <[EMAIL PROTECTED]> piše: >Dear all, > >I have been using freeradius properly configured with mysql for some >time now. However it suddenly stopped working. What more, I upgraded to >the 1

RE: Freeradius and MySQL problem!!!

2007-07-02 Thread Ackbar Joolia
Here it is: Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /usr/local/etc/raddb/proxy.conf Config: including file: /usr/local/etc/raddb/clients.conf Config: including file: /usr/local/etc/raddb/snmp.conf Config: including file: /usr/

misconfigured adsl modems hammering my freeradius

2007-07-02 Thread Tom De Wispelaere
Hello, we are using freeradius (with mysql backend) in an isp environment for authentication and accounting of adsl modems. Some of these modems are misconfigured with a wrong password and try to authenticate every 5 secs or so, so i was wondering if there is a simple way to tell radius not to do

RE: Freeradius and MySQL problem!!!

2007-07-02 Thread tnt
Have you included sql in your radiusd.conf or are sql entries still commented out? Ivan Kalik Kalik Informatika ISP Dana 2/7/2007, "Ackbar Joolia" <[EMAIL PROTECTED]> piše: >Here it is: >Starting - reading configuration files ... >reread_config: reading radiusd.conf >Config: including file:

Re: misconfigured adsl modems hammering my freeradius

2007-07-02 Thread Alan DeKok
Tom De Wispelaere wrote: > > we are using freeradius (with mysql backend) in an isp environment for > authentication and accounting of adsl modems. > Some of these modems are misconfigured with a wrong password and try > to authenticate every 5 secs or so, so i was wondering if there is a > simple

RE: Freeradius and MySQL problem!!!

2007-07-02 Thread Ackbar Joolia
HI Ivan The sql in authorize and accounting are all uncommented. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: 02 July 2007 14:16 To: FreeRadius users mailing list Subject: RE: Freeradius and MySQL problem!!! Have you included s

RE: Freeradius and MySQL problem!!!

2007-07-02 Thread tnt
It's not reading sql.conf. Check permissions on that file. Ivan Kalik Kalik Informatika ISP Dana 2/7/2007, "Ackbar Joolia" <[EMAIL PROTECTED]> piše: >HI Ivan >The sql in authorize and accounting are all uncommented. > > >-Original Message- >From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECT

Re: Using two tables (postgreSql) to validate users

2007-07-02 Thread Hugh Messenger
Krzysztof Ol?dzki <[EMAIL PROTECTED]> said: > On 2007-06-30 17:24, Daniel Bojczuk wrote: > > Hi again... > > > > I have a doubt: Is it possible to use two tables to check the users? I > > need to do something like this... Freeradius checks if the user is valid > > on the table 1, if it returns true

Re: Using two tables (postgreSql) to validate users

2007-07-02 Thread Daniel Bojczuk
Let me see if I understood. Shold I stop using the rlm_slq and start using rlm_perl with my own authentication script (using the freeradius' variables and functions, I read something about it)?? Thanks Daniel 2007/7/2, Krzysztof Olêdzki <[EMAIL PROTECTED]>: On 2007-06-30 17:24, Daniel Bojczuk w

RE: Freeradius and MySQL problem!!!

2007-07-02 Thread Ackbar Joolia
Ivan, I've given all permissions to sql.confnothing...it's still the same. Its strange, this used to work well before for the previous version of freeradius. Seems simple, yet!!! Any other advice? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMA

Proxy and clear-text password

2007-07-02 Thread Luis Galan
Hello! I have set up my freeradius 1.1.3 server to use proxy feature. [EMAIL PROTECTED] are redirected to the radius2 which store the usernames and password for that user. It seems that my nas is sending encrypted passwords but radius2 only accept clear text passwords. And my radius1 is prox

Re: Freeradius and MySQL problem!!!

2007-07-02 Thread Alan DeKok
Ackbar Joolia wrote: > Ivan, > I've given all permissions to sql.confnothing...it's still the same. Its > strange, this used to work well before for the previous version of > freeradius. Seems simple, yet!!! > > Any other advice? Is the server reading the file you are editing? ... >>> re

Re: Proxy and clear-text password

2007-07-02 Thread Alan DeKok
Luis Galan wrote: > It seems that my nas is sending encrypted passwords No. If the User-Password field is garbage in debugging mode, it's because the shared secret is wrong. Fix it. > but radius2 only > accept clear text passwords. And my radius1 is proxying the request of > the [EMAIL PROT

Re: Proxy and clear-text password

2007-07-02 Thread Luis Galan
Hello! The secret key between nas and radius1 is right. In debug mode I receive a clear password: Sending Access-Request of id 0 to radius2 port 1645 User-Password = "estestA243" NAS-Identifier = "10.1.0.102" User-Name = "[EMAIL PROTECTED]" Acct-Session-Id = "

RE: Freeradius and MySQL problem!!!

2007-07-02 Thread Ackbar Joolia
Obvious silly mistake...previous install was in /etc/raddbthanks Ivan...knew I was doing something silly -Original Message- From: [EMAIL PROTECTED] rg [mailto:[EMAIL PROTECTED] radius.org] On Behalf Of Alan DeKok Sent: 02 July 2007 17:13 To: FreeRadius users mailing list Subject: Re: F

Re: Using two tables (postgreSql) to validate users

2007-07-02 Thread Krzysztof Olędzki
On 2007-07-02 17:48, Daniel Bojczuk wrote: > Let me see if I understood. > > Shold I stop using the rlm_slq and start using rlm_perl with my own > authentication script (using the freeradius' variables and functions, I > read something about it)?? Yes. But of course there may be other (simpler?)

Re: Proxy and clear-text password

2007-07-02 Thread A . L . M . Buxey
Hi, > The secret key between nas and radius1 is right. yep. but look a little further down! > rad_recv: Access-Reject packet from host radius2:1645, id=0, length=85 > Received Access-Reject packet from client radius2 port 1645 with invalid > signature (err=2)! (Shared secret is incorrect.) Dro

Re: Proxy and clear-text password

2007-07-02 Thread tnt
>But, with tcpdump, I only see garbage and radius2 receive garbage. As you should. Radius packets are encrypted (that's what the secret is for). >Received Access-Reject packet from client radius2 port 1645 with invalid >signature (err=2)! (Shared secret is incorrect.) Dropping packet >without

User-Password, Cleartext-Password, Crypt-Password and others (2.0.0-pre1)

2007-07-02 Thread Pshem Kowalczyk
Hi, I have a question regarding the usage of various flavours of passwords with PAP module. When I run the server in debugging mode it complains: !!! !!!Replacing User-Password in config items with Cleartext-Password.

Re: User-Password, Cleartext-Password, Crypt-Password and others (2.0.0-pre1)

2007-07-02 Thread Alan DeKok
Pshem Kowalczyk wrote: > I have a question regarding the usage of various flavours of passwords > with PAP module. > When I run the server in debugging mode it complains: ... > (password (User-Password) is pulled out from the database using rlm_sql ). > > If I change the attribute to Cleartext-Pas

SQL IP Pool maximum timeout.

2007-07-02 Thread Dave
I use the sqlippool setup for handling IP pools, and it works well, except I want to rid of the expiry time, (maximum timeout=0). right now its setting for 24 hours, and then it cleans itself out, and then freeradius starts handing out already assigned/used IP addresses. Im not sure where to p

Re: SQL IP Pool maximum timeout.

2007-07-02 Thread Hugh Messenger
Dave <[EMAIL PROTECTED]> said: > I use the sqlippool setup for handling IP pools, and it works well, > except I want to rid of the expiry time, (maximum timeout=0). right now > its setting for 24 hours, and then it cleans itself out, and then > freeradius starts handing out already assigned/used IP

Re: SQL IP Pool maximum timeout.

2007-07-02 Thread Dave
Hugh Messenger wrote: > Dave <[EMAIL PROTECTED]> said: > >> I use the sqlippool setup for handling IP pools, and it works well, >> except I want to rid of the expiry time, (maximum timeout=0). right now >> its setting for 24 hours, and then it cleans itself out, and then >> freeradius starts han

Re: freeradius 1.1.6 / syslog problems

2007-07-02 Thread Andreas Wetzel
Jay Banks wrote: > Here is the same problem, found in the archives for this list, which was > posted back in January of 2004: > > BUG?? Couldn't open syslog/radius.log for logging: Not a directory > > Problem Summary: radiusd: radiusd: Couldn't open syslog/radius.log for > logging: Not a director

Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-02 Thread [EMAIL PROTECTED]
Hi all, I've try to setup a new freeradius server for my wireless users using WPA/WPA2 with 802.1x authentication. all the clients are using secureW2 to login. FYI, I've another freeradius which is currently run for EAPOL (802.1x over L2 switch) with EAP-MD5 and it is working fine for me. Afte

Re: SQL IP Pool maximum timeout.

2007-07-02 Thread Peter Nixon
On Tue 03 Jul 2007, Dave wrote: > Hugh Messenger wrote: > > Dave <[EMAIL PROTECTED]> said: > >> I use the sqlippool setup for handling IP pools, and it works well, > >> except I want to rid of the expiry time, (maximum timeout=0). right now > >> its setting for 24 hours, and then it cleans itself o

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-02 Thread Alan DeKok
[EMAIL PROTECTED] wrote: > I've try to setup a new freeradius server for my wireless users using > WPA/WPA2 with 802.1x authentication. all the clients are using secureW2 > to login. FYI, I've another freeradius which is currently run for EAPOL > (802.1x over L2 switch) with EAP-MD5 and it is worki