Re: How to Make Digital Certificates in Radius

2008-01-08 Thread Alan DeKok
niel m wrote: > I have already read the README file under this directory ( > /etc/raddb/certs ) No. I said to grab the CVS head. The NEW version of that README contains additional information. You are looking at the OLD version of that README. Following PART of the instructions will get yo

Re: How to Make Digital Certificates in Radius

2008-01-08 Thread niel m
Hello Sir Allan, I have already read the README file under this directory ( /etc/raddb/certs ) and this is the texts says "This directory contains a number of sample certificates for use by the rlm_eap_tls module. These certificates should be used ONLY for testing purposes. If you're not using

RPM install error.

2008-01-08 Thread mohsen rahmanian
His name I install freeradius-1.1.7-7.1.i386.rpm few days ago, When I try to install, upgrade or remove freeradius-1.1.7-7.1.i386.rpm get this error: /var/tmp/rpm-tmp.25681: line 1: fg: no job control error: %postun( freeradius-1.1.7-7.1.i386) scriptlet failed, exit status 1 I use Fedora Core 6

Re: How to Make Digital Certificates in Radius

2008-01-08 Thread Alan DeKok
niel m wrote: > Can you help me with the 2nd topic; > > Can you help me find how to generate/create self-sign digital > certificate for Server and Client? I take it you didn't read the README. > What are the step-by-step commands that I can use? Perhaps you can try reading the README. You

Re: ldap group membership required

2008-01-08 Thread Alan DeKok
Daniel Durgin wrote: > I have search the archives and google, and there seems to be lots of > confusion on the subject: Requiring membership to and LDAP group to > authenticate. No. Authentication involves checking credentials. Authorization involves *additional* and *independent* filter rul

Re: How to Make Digital Certificates in Radius

2008-01-08 Thread niel m
Hello Allan, Thanks for the help. Can you help me with the 2nd topic; Can you help me find how to generate/create self-sign digital certificate for Server and Client? What are the step-by-step commands that I can use? Thanks for all. Respectfully yours, Niel On Jan 9, 2008 11:07 A

Re: How to Make Digital Certificates in Radius

2008-01-08 Thread Alan DeKok
niel m wrote: > but 1 thing is lacking, it is how to create a Digital Certificate for > Radius both Server Certificate and Client Certificate. > > Kindly help me on this problem, I appreciate any help that you can offer > in order for me to implement such system. Download CVS head (http://free

Re: variables with 2.0.0-beta

2008-01-08 Thread Alan DeKok
Duane Cox wrote: > Thank you sir, and now the million dollar question, how soon until we see a > -rc1 ? > 2.0.0 should be released within days, if all goes well. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

How to Make Digital Certificates in Radius

2008-01-08 Thread niel m
Hello All, Good Morning Im niel, Im making a radius server for a wireless LAN and with LDAP Support. LDAP is set-up already Radius Application is ready but 1 thing is lacking, it is how to create a Digital Certificate for Radius both Server Certificate and Client Certificate. Kindly help me on

ldap group membership required

2008-01-08 Thread Daniel Durgin
Hello, I have search the archives and google, and there seems to be lots of confusion on the subject: Requiring membership to and LDAP group to authenticate. I can seem to get it to work. Notice the misspelling og the member: dn: cn=radius_wifi,ou=Groups,dc=fu,dc=bar cn: min_radius_wifi obj

RE: variables with 2.0.0-beta

2008-01-08 Thread Duane Cox
Thank you sir, and now the million dollar question, how soon until we see a -rc1 ? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] g] On Behalf Of Alan DeKok Sent: Tuesday, January 08, 2008 10:43 AM To: FreeRadius users mailing list Subject: Re: variables with 2.0.0-b

Re: OpenSSH, PAM and pam_radius_auth

2008-01-08 Thread Johan Rydberg
Alan DeKok skrev: PAM does weird things. OpenSSH does weird things. I've noticed that. Things got a bit better by setting the "ChallengeResponseAuthentication" option to no in sshd_config. ~j - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: variables with 2.0.0-beta

2008-01-08 Thread Alan DeKok
Duane Cox wrote: > Hello > > Will this still expand with 2.0.0-beta ? > > %{config:client[%{Packet-Src-IP-Address}].shortname} I've just committed a fix that will expand the contents of %{config:...}. So if you still have an old-style client definition, it should now work. > I'm using 2.0.0-p

variables with 2.0.0-beta

2008-01-08 Thread Duane Cox
Hello Will this still expand with 2.0.0-beta ? %{config:client[%{Packet-Src-IP-Address}].shortname} I'm using 2.0.0-pre2 and it's working, but I am seeing some warnings with 2.0.0-beta about not being able to expand/find it. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/

Re: OpenSSH, PAM and pam_radius_auth

2008-01-08 Thread Alan DeKok
Johan Rydberg wrote: > It seems that OpenSSH first tries to authetnicate the user with an > empty password (""), because if I set an empty password both in the > local /etc/passwd, and on the RADIUS server, sshd is able to establish > credentials for the user. PAM does weird things. OpenSSH doe

Re: OpenSSH, PAM and pam_radius_auth

2008-01-08 Thread Alan DeKok
Sobanbabu Bakthavathsalu wrote: > Hi Johan, > > Its good to hear that you reached up a level where Radius is working fine. > But we are unable to break the jinx, and I am getting the following error > when trying to telnet to the box. The installation and configuration of pam > radius module we

RE: OpenSSH, PAM and pam_radius_auth

2008-01-08 Thread Sobanbabu Bakthavathsalu
Hi Johan, Its good to hear that you reached up a level where Radius is working fine. But we are unable to break the jinx, and I am getting the following error when trying to telnet to the box. The installation and configuration of pam radius module went fine. Could you please help in this rega

Re: OpenSSH, PAM and pam_radius_auth

2008-01-08 Thread Johan Rydberg
[EMAIL PROTECTED] skrev: You have posted a question to the freeradius list and included a debug from - OpenSSH??? Don't you think that freeradius debug would be more helpful? As I stated, authentication in respect to RADIUS works just fine, therefor here's not need for the debug output from pa

Re: OpenSSH, PAM and pam_radius_auth

2008-01-08 Thread tnt
You have posted a question to the freeradius list and included a debug from - OpenSSH??? Don't you think that freeradius debug would be more helpful? Ivan Kalik Kalik Informatika ISP Dana 8/1/2008, "Johan Rydberg" <[EMAIL PROTECTED]> piše: >I'm trying to get RADIUS authentication to work on one

OpenSSH, PAM and pam_radius_auth

2008-01-08 Thread Johan Rydberg
I'm trying to get RADIUS authentication to work on one of our systems, but keep running into problems. For some reason it seems that the account system does not allow the user to login, and once the user has been authenticated, it drops the connection by not allowing sshd to establish credentials

Re: bug? in configure script

2008-01-08 Thread Alan DeKok
Andrew Higginbotham wrote: > I was installing freeradius today and the only way I could get it to > recognize my ssl install, which is in a custom location, was to change > line 21268 of the 'configure' script to from Hmmm... the generated configure script looks for -lcrypto, and then throws awa