radius using 95 % of CPU

2007-09-16 Thread Defryn, Guy
Hi, I am new to freeradius and I just had to upgrade one of our servers to RHEL5. As part of this deployment, I have installed freeradius-1.1.3-1.2 and openldap-2.3.27-5. I have looked on the web and talked to some colleagues and this is probably and openldap issue. I am sure it has popped up

[no subject]

2007-09-16 Thread Defryn, Guy
Hi, I am new to freeradius and I just had to upgrade one of our servers to RHEL5. As part of this deployment, I have installed freeradius-1.1.3-1.2 and openldap-2.3.27-5. I have looked on the web and talked to some colleagues and this is probably and openldap issue. I am sure it has popped up

Re: Freeradius doesn't detect EAP when authenticating against MySQL

2007-09-16 Thread tnt
Well, AP is not responding. Request is for wireless access and attributes in the reply are for shell access. It might not like that. Ivan Kalik Kalik Informatika ISP Dana 16/9/2007, "Andrew Rowson" <[EMAIL PROTECTED]> piše: > > >[EMAIL PROTECTED] wrote: >> Comment it out anyway. You are settin

Re: Freeradius doesn't detect EAP when authenticating against MySQL

2007-09-16 Thread Andrew Rowson
[EMAIL PROTECTED] wrote: Comment it out anyway. You are setting Auth-Type Local in SQL database then. If not in radcheck then in radgroupcheck. Ivan Kalik Kalik Informatika ISP I feel really stupid now. It was sitting there in radgroupcheck setting the auth-type to local. ARGH. Ok, regr

Re: Working MAC-auth. in 1.1.7, not working in 2.0pre2 (noob-quiz).

2007-09-16 Thread Alan DeKok
Piero Giobbi wrote: > Now i just have to try the 2.0pre-release, to get prepared for the > future. I have manually written in my clients and users in the version > 2s configs. Everything works except for one small thing; now i can't > login. These are the errors; The "users" file format hasn't c

Re: EAP and realm question.

2007-09-16 Thread tnt
Realm - since you are not using realms it is as expected. You can forget about that one. EAP - yes, your AP doesn't have EAP (802.1x) enabled. Ivan Kalik Kalik Informatika ISP Dana 16/9/2007, "Piero Giobbi" <[EMAIL PROTECTED]> piše: >Hi again all, sorry for spamming the list. > >I have two que

Re: Working MAC-auth. in 1.1.7, not working in 2.0pre2 (noob-quiz).

2007-09-16 Thread tnt
Check what you have written in users file. Nothing matched. Ivan Kalik Kalik Informatika ISP Dana 16/9/2007, "Piero Giobbi" <[EMAIL PROTECTED]> piše: >Hi all. > >Im getting my hands dirty with radius and i really enjoying it >to : ). Im totally new at this and im basically trying my way throu,

Working MAC-auth. in 1.1.7, not working in 2.0pre2 (noob-quiz).

2007-09-16 Thread Piero Giobbi
Hi all. Im getting my hands dirty with radius and i really enjoying it to : ). Im totally new at this and im basically trying my way throu, lots of trying and loggreading as you can imagine. I got some things rolling, my firewalls pptp-auths and now my Proxim AP4000 with MAC- addr auth - j

Re: FreeRADIUS 2.0.0-pre2 has been released

2007-09-16 Thread Alan DeKok
Jakob Hirsch wrote: > Quoting Alan DeKok: >> Hmm... hadn't thought of doing it that way. It could be possible. > > Meaning "try it and get back to list when you have the results"? :) No, as in it's not currently enabled. > Allow me to elaborate on that: > > a global listen section: ... > t

Re: Possible FreeBSD Jail problem, or other bug in/with FreeRADIUS 2.0.0-pre2

2007-09-16 Thread Alan DeKok
Scott Lambert wrote: > I've added some debug prints to lrad_packet_list_socket_add and changed > up the printfs in lrad_packet_list_find_byreply. I don't know that they > will help. But, just in case The problem is this: > In jailed client: > radclient: main: radclient_head->request->src_

Re: Freeradius doesn't detect EAP when authenticating against MySQL

2007-09-16 Thread tnt
Comment it out anyway. You are setting Auth-Type Local in SQL database then. If not in radcheck then in radgroupcheck. Ivan Kalik Kalik Informatika ISP Dana 16/9/2007, "Andrew Rowson" <[EMAIL PROTECTED]> piše: >>> Ok, I've upgraded to 1.1.7, and I get the auth-type local issue again. >>> The l

Re: wholesale issue

2007-09-16 Thread tnt
Try User-Name =~ '@isp1realm$' instead of Realm. Realm attribute might not work in preprocess as it's not set yet. You can use unlang to check for multiple values in 2.0 but I don't know how to implement this function in SQL in 1.1.x. Ivan Kalik Kalik Informatika ISP Dana 16/9/2007, "Ashraf Al-

Re: Freeradius doesn't detect EAP when authenticating against MySQL

2007-09-16 Thread Alan DeKok
Andrew Rowson wrote: > I had the following on line 155, which when commented out, seems to make > no difference. > > DEFAULTAuth-Type = System >Fall-Through = 1 (1) Start off with the default radiusd.conf in 1.1.7. (2) Change just enough to enable tls and peap (3) run the te

Re: Freeradius doesn't detect EAP when authenticating against MySQL

2007-09-16 Thread Alan DeKok
Andrew Rowson wrote: > Ok, I've upgraded to 1.1.7, and I get the auth-type local issue again. > The log is up at the same place as before, > http://public.growse.com/radiusd.log The output is a LOT shorter than your tests with the previous version. > I'm at a bit of a loss. I can't be the only

Re: Configuring FreeRADIUS to use ntlm_auth

2007-09-16 Thread Alan DeKok
[EMAIL PROTECTED] wrote: > radtest doesn't do MS-CHAP. The page tries to make this clear. > ==> Sorry ... but I hadn´t understood it (I thought that just radclient > doesn´t work). Now I know that radtest too ... radtest is just a shell script wrapper around radclient. > You've done rather a

Re: Freeradius doesn't detect EAP when authenticating against MySQL

2007-09-16 Thread Andrew Rowson
Ok, I've upgraded to 1.1.7, and I get the auth-type local issue again. The log is up at the same place as before, http://public.growse.com/radiusd.log I'm at a bit of a loss. I can't be the only person who wants to put user credentials for a PEAP setup into a mysql db? modcall[authorize]: