Re: Not everything is getting logged via Radius - very odd

2007-09-28 Thread Alan DeKok
Patrick M. wrote: > We use freeradius for our O1 dialup customers, as well as our SuperNews > customers. Our freeradius server authenticates via LDAP. We had a > customer come in today mentioning they could not log in to their dialup > account, so I went to the logs and did some testing. I tried

Re: Failed obtain IP address after authenticated using EAP-MD5

2007-09-28 Thread Alan DeKok
If you're using EAP, IP addresses are assigned through DHCP. This has nothing to do with FreeRADIUS. Go fix your access point to do DHCP properly. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

回复: Re: TNCC warning

2007-09-28 Thread 翔 李
Hi, I am sorry for my carelessness.Here is the running infor attachment. Thanks for your reply. [EMAIL PROTECTED] 写道: You didn't append the debug. Dana 28/9/2007, "翔 李" pi�e: >Hi, >I built TNC-Client and NAA-TNCS according to the steps introducing in "How To >build TNC-Client including IMCHo

TNCC warning

2007-09-28 Thread 翔 李
Hi, I am sorry for my carelessness.Here is the running infor attachment. Thanks for your reply. - 雅虎邮箱,终生伙伴! - @yahoo.cn 新域名、无限量,快来抢注! # radiusd -x Starting - reading configuration files ... Using deprecated naslist

Failed obtain IP address after authenticated using EAP-MD5

2007-09-28 Thread Chiu Luk
Note: forwarded message attached. - Catch up on fall's hot new shows on Yahoo! TV. Watch previews, get listings, and more!--- Begin Message --- After the supplicant authenticated successfully from the FreeRadius server, my notebook fails to obtain an IP

Failed obtain IP address after authenticated using EAP-MD5

2007-09-28 Thread Chiu Luk
After the supplicant authenticated successfully from the FreeRadius server, my notebook fails to obtain an IP address from the Access Point (router) and end up getting a 169.254.198.216 IP address. here is my setup : Supplicant = WIRE1x ( a windows port of Open 1x ) Authenticator = D-Link DI

Not everything is getting logged via Radius - very odd

2007-09-28 Thread Patrick M.
Hi all, First time poster here - go easy on me :) We use freeradius for our O1 dialup customers, as well as our SuperNews customers. Our freeradius server authenticates via LDAP. We had a customer come in today mentioning they could not log in to their dialup account, so I went to the logs

Re: [OpenSER-Users] Failed to compile openser with freeradius support

2007-09-28 Thread tnt
Try radiusclient. Ivan Kalik Kalik Informatika ISP Dana 28/9/2007, "Live Great" <[EMAIL PROTECTED]> piše: >Hi, where can I get freeradius-client? I searched the source in freeradius, >couldn't find it. > >Thanks >SW > >- Original Message >From: ram <[EMAIL PROTECTED]> >To: Live Great

Re: [OpenSER-Users] Failed to compile openser with freeradius support

2007-09-28 Thread Live Great
Hi, where can I get freeradius-client? I searched the source in freeradius, couldn't find it. Thanks SW - Original Message From: ram <[EMAIL PROTECTED]> To: Live Great <[EMAIL PROTECTED]> Cc: FreeRadius users mailing list ; [EMAIL PROTECTED] Sent: Friday, September 28, 2007 11:09:17 PM

regarding Error: rlm_ldap

2007-09-28 Thread David Stubblefield
Greetings, New to FreeRadius. I got it up and running and the basics seem to be running ok (FreeRadius version v1.1.3 Running on CentOS 5) but I'm seeing the following errors in the log and am hoping someone can shed some light or point me in the right direction. I've googled and looked around

Novell Integratoion

2007-09-28 Thread Brad Lachel
I am trying to get free radius to authenticate users with my Novell server. I know that I am close, but I don't quite have it. I can see that my access points are sending MAC address to the radius server as the user name, that MAC is then authenticated through my users file and passed to

Re: attribute value length limit

2007-09-28 Thread Alan DeKok
Fco. Javier Melero wrote: > Maybe some context will help. What we are trying to do is implement a > 802.1x wireless lan which can allow multiple EAP methods under the same > SSID. If you want TTLS/PAP and PEAP/MSCHAP working together the only way > is to use clear text passwords (or I think so).

Re: same attribute for multiple users

2007-09-28 Thread Sergio Del Pino
Thank you Ivan YOU DID IT! but for the mailing list records this block: DEFAULT Filter-Id="some_acl0.in", Fall-Through = 1 should go ABOVE users entry (once a user entry is checked the rest of the file is ignored unless you put a fall through per each user) with a "," ending the

Re: same attribute for multiple users

2007-09-28 Thread tnt
"This way didn't work." I hope that means that DEFAULT entry didn't match, not that attribute didn't do anything on the NAS. DEFAULT entry should go below the user entries. Try using operator that always matches then: DEFAULT User-Name =* "whatever" Filter-Id="some_acl0.in"

Re: EAP (PEAP) problem with MS Win XP

2007-09-28 Thread tnt
Radeapclient doesn't do EAP-MSCHAPv2, only EAP-MD5. http://linux.die.net/man/1/radeapclient Ivan Kalik Kalik Informatika ISP Dana 28/9/2007, "WAYNE VANDERMERWE" <[EMAIL PROTECTED]> piše: > >When i use Cleartext-Password I get the same resaults from the DEBUG been > >Login incorrect: [5398606

Re: attribute value length limit

2007-09-28 Thread Fco. Javier Melero
Alan DeKok escribió: Fco. Javier Melero wrote: Well, surely I'm missing something, but that's the way I've found to store clear text passwords in LDAP keeping some peace of mind. What could be the alternative? Storing them as clear-text. Encrypting them adds *zero* benefit, becau

Re: same attribute for multiple users

2007-09-28 Thread Sergio Del Pino
Dear Ivan, Thank you for your prompt reply. May be I´m not so clever as you think I´m, I've already read the users file but I couldn't understand where to put the "DEFAULT" and what to check. I've tried to put DEFAULT in first place without any check (what should I check?), after this line I put i

Re: EAP (PEAP) problem with MS Win XP

2007-09-28 Thread WAYNE VANDERMERWE
When i use Cleartext-Password I get the same resaults from the DEBUG been Login incorrect: [53986067/] (from client elhc-network port 0 cli 00-0F-CB-FA-D4-63) What I have tryed is change the settings in "EAP MSCHAPv2 Properties to not use my windows login name and password" and this connects

Re: [OpenSER-Users] Failed to compile openser with freeradius support

2007-09-28 Thread Norman Brandinger
Comment the FREERADIUS=1 in the openser/Makefile Make sure that in modules/acc/Makefile ENABLE_RADIUS_ACC=true is not commented Regards, Norm Live Great wrote: > HI, > > In FreeBSD 6.2, I got this error when I compiled openser with > freeradius support. > > ../../radius.h:36:32: freeradius-clie

Re: [OpenSER-Users] Failed to compile openser with freeradius support

2007-09-28 Thread ram
On 9/28/07, Live Great <[EMAIL PROTECTED]> wrote: > > HI, > > In FreeBSD 6.2, I got this error when I compiled openser with freeradius > support. > > ../../radius.h:36:32: freeradius-client.h: No such file or directory > install freeradius client before compiling ram - List info/subscribe/unsub

Failed to compile openser with freeradius support

2007-09-28 Thread Live Great
HI, In FreeBSD 6.2, I got this error when I compiled openser with freeradius support. ../../radius.h:36:32: freeradius-client.h: No such file or directory acc.c: In function `init_acc_rad': acc.c:464: warning: assignment makes pointer from integer without a cast acc.c:475: error: `DICT_ATTR' und

RE: Unresponsive Child Crashing Server 1.1.6

2007-09-28 Thread Reynolds, Walter
I have not seen any answers and strangly enough I did not even find in the archive so I thought I would resend it. Thanks. --- Walt Reynolds Principal Systems Security Development Engineer Information Technology Central Services University of Michigan (734) 615-9438 > -Original Message-

Re: attribute value length limit

2007-09-28 Thread Alan DeKok
Fco. Javier Melero wrote: > Well, surely I'm missing something, but that's the way I've found to > store clear text passwords in LDAP keeping some peace of mind. What > could be the alternative? Storing them as clear-text. Encrypting them adds *zero* benefit, because application that needs th

Re: attribute value length limit

2007-09-28 Thread Fco. Javier Melero
Alan DeKok escribió: Fco. Javier Melero wrote: I've got an LDAP attribute mapped into user-password RADIUS attribute. This attribute is RSA-ciphered And why would you do that? It's completely useless. Well, surely I'm missing something, but that's the way I've found to store

Re: TNCC warning

2007-09-28 Thread tnt
You didn't append the debug. Dana 28/9/2007, "Ďč Ŕî" <[EMAIL PROTECTED]> piše: >Hi, >I built TNC-Client and NAA-TNCS according to the steps introducing in "How To >build TNC-Client including IMCHostScanner" and "How To build TNCS including >IMVHostScanner" respectively.Then I run TNCC.exe to

Re: attribute value length limit

2007-09-28 Thread Alan DeKok
Fco. Javier Melero wrote: > I've got an LDAP attribute mapped into user-password RADIUS attribute. > This attribute is RSA-ciphered And why would you do that? It's completely useless. > so RADIUS have to deciphered it when it > arrives in order to use it for authentication. The problem arise

TNCC warning

2007-09-28 Thread 翔 李
Hi, I built TNC-Client and NAA-TNCS according to the steps introducing in "How To build TNC-Client including IMCHostScanner" and "How To build TNCS including IMVHostScanner" respectively.Then I run TNCC.exe to connect to the PDP server(run by executing command radius -X) but it warns that authen

802.1x machine authentication patch help

2007-09-28 Thread Marco Casulli
Hi Jamie, Marco from BBC in london. I have read your message (http://lists.cistron.nl/pipermail/freeradius-users/2005-November/048576 .html related to the error when the radius is trying to authenticate in AD and I am getting exactly the same message. "No logon workstation trust account (0xc

attribute value length limit

2007-09-28 Thread Fco. Javier Melero
Hi you all, I've got an LDAP attribute mapped into user-password RADIUS attribute. This attribute is RSA-ciphered so RADIUS have to deciphered it when it arrives in order to use it for authentication. The problem arise when I try to use an RSA key pretty much longer than 1400 bytes, because

Re: Freeradius-Users Digest, Vol 29, Issue 103

2007-09-28 Thread tnt
No. That's IP accounting ie. Mikrotik's pathetic attempt at netflow. It has nothing to do with radius. Ivan Kalik Kalik Informatika ISP Dana 28/9/2007, "Marinko Tarlac" <[EMAIL PROTECTED]> piše: >Hello > >I'm new here and I'm still learning about radius so I have one question. > >Is it possible

Re: EAP (PEAP) problem with MS Win XP

2007-09-28 Thread tnt
Try with JRadius Simulator: http://jradius.net/wiki/index.php/JRadiusSimulator And why have you commented out Cleartext-Password and entered User-Password? Ivan Kalik Kalik Informatika ISP Dana 28/9/2007, "WAYNE VANDERMERWE" <[EMAIL PROTECTED]> piše: >> have you tested from a non windows box

Re: Freeradius-Users Digest, Vol 29, Issue 103

2007-09-28 Thread Alan DeKok
Marinko Tarlac wrote: > Is it possible to configure radius to receive No. The RADIUS server receives whatever the NAS sends it. > from NAS informations > about IP pairs. For example Source IP - Destination IP - transfered > packages - transfered bytes. (4 informations) > > You can see this in

Re: Freeradius-Users Digest, Vol 29, Issue 103

2007-09-28 Thread Marinko Tarlac
Hello I'm new here and I'm still learning about radius so I have one question. Is it possible to configure radius to receive from NAS informations about IP pairs. For example Source IP - Destination IP - transfered packages - transfered bytes. (4 informations) You can see this in Mikrotik Accoun

Re: EAP (PEAP) problem with MS Win XP

2007-09-28 Thread WAYNE VANDERMERWE
> have you tested from a non windows box to ensure that you havent fallen foul > of the usual EAP problems - as clearly noted at the top of eap.conf? No, I am not able to do so as i do not have an extra box's. I have searched through all configurations to make sure that 'Auth-Type := EAP' is not