Using nas-ip address for user authorization

2007-12-05 Thread ajay raut
Hi, I want to use nas-ip address of the radius-request to be checked in users.conf file for the users authorization to access that NAS server. Is it possible in FreeRadius and i need to know the configuration to do it... Thanks, Ajay Raut -

Using nas-ip addrees attribute

2007-12-05 Thread ajay raut
Hi, i have one query, Can we use nas-ip address attribute in check items of radius request using the users.conf configuration file... Thanks, Ajay Raut - Be a better friend, newshound, and know-it-all with Yahoo! Mobile.

RE: free radius with radauth discarding packet?

2007-12-05 Thread satyanarayanam
Hi, I am running sucessfully freeraduis with raduth-freeradius know it is working fine but only taking USERNAME-root PASSWD-root123 why not others i am changing this in clients.conf file also but working with only this ... Please tell me what to do.. Thank you inadvance Thank you, Satyanarayna

Re: free radius with radauth discarding packet?

2007-12-05 Thread Alan DeKok
satyanarayanam wrote: > I am running free radius and with radauth , > radauth sending a packet for authanetication reqest, > But freeradius discarding the packet due to size is more tha 4096.. The client is broken, and is not following the RADIUS specification. There are very few reasons to s

free radius with radauth discarding packet?

2007-12-05 Thread satyanarayanam
Hi, I am running free radius and with radauth , radauth sending a packet for authanetication reqest, But freeradius discarding the packet due to size is more tha 4096.. I am unable to understand what to do.. Any body can help me...? Thank you in advance .. Thank you, Satyanarayna reddy menda

Re: EAP-TTLS tunnel

2007-12-05 Thread Sergio Belkin
Guy, Thanks for your explanation --- El Mié 05 Dic 2007, Guy Davies encontró un teclado y tipeó lo siguiente: > GD: No, the tunnel is between the authentication server and the > GD: supplicant. The authenticator (the AP or switch) cannot see into the > GD: tunnel. > GD: > GD: Rgds, > GD: > GD: G

Re: EAP-TTLS tunnel

2007-12-05 Thread Guy Davies
No, the tunnel is between the authentication server and the supplicant. The authenticator (the AP or switch) cannot see into the tunnel. Rgds, Guy On 05/12/2007, Sergio Belkin <[EMAIL PROTECTED]> wrote: > When using EAP-TTLS the tunnel is between Access Point and client only? > > I mean: Is it

EAP-TTLS tunnel

2007-12-05 Thread Sergio Belkin
When using EAP-TTLS the tunnel is between Access Point and client only? I mean: Is it protected data between AP and freeradius? Thanks in advance -- -- Open Kairos http://www.openkairos.com Watch More TV http://sebelk.blogspot.com Sergio Belkin - - List info/subscribe/unsubscribe? See http://ww

Re: Oracle LDAP and password

2007-12-05 Thread Alan DeKok
Fabio Pedretti wrote: > I am using FreeRADIUS 1.1.7 and I want to authenticate my users against > an Oracle LDAP. TTLS-PAP works fine, but I also need PEAP-MSCHAPv2, so I > have to be able to read NT-LM password. I noticed that the Oracle LDAP > server stores password in this format: > > authpassw

Re: freeradius-users@lists.freeradius.org

2007-12-05 Thread Alan DeKok
radius wrote: > these are the radius-packages installed on that machine: Which doesn't answer the question I asked. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Oracle LDAP and password

2007-12-05 Thread Fabio Pedretti
I am using FreeRADIUS 1.1.7 and I want to authenticate my users against an Oracle LDAP. TTLS-PAP works fine, but I also need PEAP-MSCHAPv2, so I have to be able to read NT-LM password. I noticed that the Oracle LDAP server stores password in this format: authpassword;orclcommonpwd: {X- ORCLLMV

Re: freeradius-users@lists.freeradius.org

2007-12-05 Thread radius
Hi Alan these are the radius-packages installed on that machine: [EMAIL PROTECTED] ~]# pkg_info -A |grep -i radius freeradius-1.1.6RADIUS server implementation freeradius-ldap-1.1.6 freeradius ldap rlm addon [EMAIL PROTECTED] ~]# and these are the ldap-packages installed on it: [EMAIL PROT

Re: freeradius-users@lists.freeradius.org

2007-12-05 Thread Alan DeKok
radius wrote: >> I presume you're using the OpenBSD PAM RADIUS module? > > no, i installed freeradius-ldap, no openBSD PAM radius module that i knew. Then how are you doing OpenBSD RADIUS login? Can you say? Please also follow my advice to compare the configurations on the two systems. T

Re: freeradius-users@lists.freeradius.org

2007-12-05 Thread radius
Hi Alan thanks for immediate reply. > I presume you're using the OpenBSD PAM RADIUS module? no, i installed freeradius-ldap, no openBSD PAM radius module that i knew. suomi Alan DeKok wrote: radius wrote: we use radius authentication on this openBSD server as workaround, because for openB

Re: freeradius-users@lists.freeradius.org

2007-12-05 Thread Alan DeKok
radius wrote: > we use radius authentication on this openBSD server as workaround, > because for openBSD no pam-(ldap) is available. here, all users, mail, > ftp, yni are authenticated against openldap using various authentication > methods (pam-ldap, pure ldap, courier-authlib with ldap, pure-ftpd

Re: AW: AW: Authenticate by MAC address

2007-12-05 Thread tnt
That's it. Simple and unsecure. Ivan Kalik Kalik Informatika ISP Dana 5/12/2007, "Bernd" <[EMAIL PROTECTED]> piše: >To do authentication by MAC-address. Maybe some settings in radiusd.conf or >smth another conf. file. I can hardly believe it's just typing the >MAC-adress into the database and i

Re: AW: AW: Authenticate by MAC address

2007-12-05 Thread Stieven . Struyf
i don't use a database, but for the normal flat textfile you set the mac address as username and as password. The switch(i have procurves) sends the macadress as both username and password to the radius server. Stieven Struyf M.I.S. Division - System Operations Komatsu Europe International NV M

AW: AW: Authenticate by MAC address

2007-12-05 Thread Bernd
To do authentication by MAC-address. Maybe some settings in radiusd.conf or smth another conf. file. I can hardly believe it's just typing the MAC-adress into the database and it works? -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Alan DeKok

Re: problem with attributes in access-reject

2007-12-05 Thread Stefan Winter
> However freeradius appears to be blocking all but Reply-Message from > getting to the client. Which is the correct behaviour according to RFC2865 - only EAP-Message, Message-Authenticator and Reply-Message are allowed. The other attributes are stripped non-configurably in src/main/util.c, func

Re: AW: Authenticate by MAC address

2007-12-05 Thread Alan DeKok
Bernd wrote: > I have a MySQL database to do it. I set the MACadress as "UserName", "op" > should be :=. What do I have to do with "Value" and "Attribute"? You have mixed that up. The MySQL schema attempts to mirror the "users" file. So see "man users", and the "users" file for examples of wh

freeradius-users@lists.freeradius.org

2007-12-05 Thread radius
Hi listers [EMAIL PROTECTED] ~]# uname -a OpenBSD myhost.mydomain.com 4.2 GENERIC#375 i386 [EMAIL PROTECTED] ~]# [EMAIL PROTECTED] ~]# pkg_info -A freeradius-1.1.6RADIUS server implementation freeradius-ldap-1.1.6 freeradius ldap rlm addon [EMAIL PROTECTED] ~]# [EMAIL PROTECTED] ~

AW: Authenticate by MAC address

2007-12-05 Thread Bernd
I have a MySQL database to do it. I set the MACadress as "UserName", "op" should be :=. What do I have to do with "Value" and "Attribute"? And are there any further settings to do in a conf. file? Bernd -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftra