avoiding ldap group search

2008-02-22 Thread Gopinath Reddy N
Hi, Presently my system is configured in such a way that freeradius checks whether user is present in ldap server and then it searches to find the user group in ldap. Is there a way I can avoid this? Basically I want to see if a user is present in Ldap server if he is present I will go ahead and

WRT54 and freradius with client-station-id

2008-02-22 Thread Rob
Hi Can anybody force freeradius to work with Linksys WRT54G with combinantion of /user/password/macaddress? Combination user/password works OK but there is no Client-station-id in packet Access-request. Can anybody help? - List info/subscribe/unsubscribe? See

RE: NAS-Group? - different replies to different NASes?

2008-02-22 Thread Ivan Kalik
4. Our radius sends the Tunnel information back to Telco Radius Why? It will be the same every time for every user. Configure tunnel parametars on the (virtual) interface. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

2.0.2 RPM build on redhat 5

2008-02-22 Thread Allen Tsao
Hi all, I just become a member of this mail list. After download the newest version 2.0.2 of freeradius, I try to build a RPM on redhat 5. I typed all the instructions in terms of the website, but I got an error which show some information about freeradius and freeradius-server. After google

Re: WRT54 and freradius with client-station-id

2008-02-22 Thread Alan DeKok
Rob wrote: Can anybody force freeradius to work with Linksys WRT54G with combinantion of /user/password/macaddress? Combination user/password works OK but there is no Client-station-id in packet Access-request. Can anybody help? Linksys. See their documention for how to configure the

Re: NAS-Group? - different replies to different NASes?

2008-02-22 Thread Alan DeKok
Adrian wrote: Is there a wild card I can use all the time with one NAS that will match on any domain while NAS2 needs to have a specific user? Just configure a regular expression... See man unlang. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius 1.1.7 and LDAP

2008-02-22 Thread Alan DeKok
Mike O'Connor wrote: I have a small issue with freeradius and ldap, its authenticating as 'access accept' customers which have placed a space at the beginning of there user name. That's likely do to the LDAP server accepting uid = foo and uid=foo as the same user. Maybe adding quotes

RE: 2.0.2 RPM build on redhat 5

2008-02-22 Thread Escobar, Emilio
Allen, In the spec file there is a line for the configure script that specifies: --with-ltdl-lib=/usr/lib. Try changing that to /usr/local/lib and see if that works. Regards, Emilio A. Escobar -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

RE: NAS-Group? - different replies to different NASes?

2008-02-22 Thread Adrian
Hello Ivan, The Telco wants me to send those parameters to them. I have no choice in that. I'm confused because with every other Telco the setup was straight forward, I setup a tunnel/vpnd-group+virtual template from our LNS to the Telco's LAC and the requests for the user authentication comes

Re:

2008-02-22 Thread Ivan Kalik
What's the user entry in the database? That password looks a bit suspect. Ivan Kalik Kalik Informatika ISP Dana 22/2/2008, Dustin Schuemann [EMAIL PROTECTED] piše: I am trying to setup freeradius 1. I have chap authentication working with mysql but pap authentication will not work with mysql.

Re: your mail

2008-02-22 Thread A . L . M . Buxey
Hi, I am trying to setup freeradius 1. I have chap authentication working with mysql but pap authentication will not work with mysql. This is what I receive from the nas when someone trys to connect. radius.conf does not contain the full sql details - eg sql.conf, the required SQL backend

RE: NAS-Group? - different replies to different NASes?

2008-02-22 Thread Adrian
Hello Alan, I'll do some reading as per your suggestions. Does it matter what version of FreeRadius I use? I currently have 1.17 installed using mysql. Adrian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Friday, February 22, 2008

Re: upgrade broke the users file - being read only partially - FR1.1.7 to FR2.0.2

2008-02-22 Thread Agent Smith
Yes I did make that change. What in the output suggested I didn't? I don't know what the deal is, it seems odd that it will read the file and proxy my requests but failed to authenticate a locally defined user in the file. anyways, I went back to 1.1.7 which seems to work fine, I usually stay

Re: upgrade broke the users file - being read only partially - FR1.1.7 to FR2.0.2

2008-02-22 Thread A . L . M . Buxey
Hi, Yes I did make that change. What in the output suggested I didn't? Auth-Type already set I don't know what the deal is, it seems odd that it will read the file and proxy my requests but failed to authenticate a locally defined user in the file. its matching on line * (iirc) the

RE: NAS-Group? - different replies to different NASes?

2008-02-22 Thread Ivan Kalik
NAS-IP-Address should be different in LAC and LNS requests. And unlang works in version 2.0 not 1.1.x (later post). Ivan Kalik Kalik Informatika ISP Dana 22/2/2008, Adrian [EMAIL PROTECTED] piše: Hello Ivan, The Telco wants me to send those parameters to them. I have no choice in that. I'm

Re: Re:

2008-02-22 Thread Dustin Schuemann
the user password is fun123 it is clear text. On Feb 22, 2008, at 9:15 AM, Ivan Kalik wrote: What's the user entry in the database? That password looks a bit suspect. Ivan Kalik Kalik Informatika ISP Dana 22/2/2008, Dustin Schuemann [EMAIL PROTECTED] piše: I am trying to setup freeradius

Re: Re:

2008-02-22 Thread Ivan Kalik
the user password is fun123 it is clear text. User-Password = i\374\304U\017\026\264\027:\367PU\262\t\356 That's not what you NAS is sending as password. So radius works fine. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

NAS with dynamic IP

2008-02-22 Thread Rui Oliveira
Hello, I have find an old topic in the ML where Joost asks about setting up NASes with dynamic ip. Quote: http://lists.freeradius.org/mailman/htdig/freeradius-users/2002-November/013226.html Joost [EMAIL PROTECTED] wrote: * Is it possible to allow NASes (clients) with a dynamic IP

Re: Re: Re:

2008-02-22 Thread Dustin Schuemann
So the problem is on the nas not my radius server. On Feb 22, 2008, at 10:57 AM, Ivan Kalik wrote: the user password is fun123 it is clear text. User-Password = i\374\304U\017\026\264\027:\367PU\262\t\356 That's not what you NAS is sending as password. So radius works fine. Ivan

Documentation (was Re: )

2008-02-22 Thread Alan DeKok
Dustin Schuemann wrote: So the problem is on the nas not my radius server. The problem is that the shared secret is wrong. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: NAS with dynamic IP

2008-02-22 Thread Alan DeKok
Rui Oliveira wrote: I have find an old topic in the ML where Joost asks about setting up NASes with dynamic ip. There is no patch to do the client-kickstart, because no client supports this. If you need a NAS with dynamic IP's, your network design is likely wrong. Alan DeKok. - List

Re: NAS with dynamic IP

2008-02-22 Thread Rui Oliveira
I want the NASes with dynamic ip to use in wifi hotspot server. I have several access points with ADSL lines and i want them to be able to authenticate the wifi clients in the remote radius server without a VPN server connection. You have a example, the Worldspot.net Hotspots Server has it but

Re: NAS with dynamic IP

2008-02-22 Thread Alan DeKok
Rui Oliveira wrote: I want the NASes with dynamic ip to use in wifi hotspot server. I have several access points with ADSL lines and i want them to be able to authenticate the wifi clients in the remote radius server without a VPN server connection. Yes, I know. Many people do this, and

rlm_ldap and large AD structure issue

2008-02-22 Thread Capelle, Mark (PCMC-GB)
I have an issue since pointing FR to a point higher in my AD tree (which will return more objects). I get the following error in my FR logs when I try to authenticate a user: Fri Feb 22 10:37:14 2008 : Error: rlm_ldap: ldap_search() failed: Operations error If I point the LDAP module

Re: rlm_ldap and large AD structure issue

2008-02-22 Thread Alan DeKok
Capelle, Mark (PCMC-GB) wrote: I have an issue since pointing FR to a point higher in my AD tree (which will return more objects). I get the following error in my FR logs when I try to authenticate a user: Fri Feb 22 10:37:14 2008 : Error: rlm_ldap: ldap_search() failed: Operations error

Re: NAS with dynamic IP

2008-02-22 Thread Rui Oliveira
If anyone want to do the patch i can help with some donations because i will use it a lot :) 2008/2/22, Alan DeKok [EMAIL PROTECTED]: Rui Oliveira wrote: I want the NASes with dynamic ip to use in wifi hotspot server. I have several access points with ADSL lines and i want them to be able

Mysql Crypt passwords

2008-02-22 Thread Dustin Schuemann
I have my username and passwords stored in my database as encrypted. How can I get freeradius 1 to work with this passwords. Dustin Schuemann . Network Engineer . . . . . . . . . . . . . . . . . . . . . . . . . . AMS/The Support Dept 400 Ann St NW Suite 102 Grand Rapids, MI 49504 p.

Re: Re: Re: Re:

2008-02-22 Thread Dustin Schuemann
That was it thanks. On Feb 22, 2008, at 3:31 PM, Ivan Kalik wrote: That looks like a pap request but that's not the cleartext password. Garbled password suggests that the shared secret in clients.conf and on the NAS are not the same (if you are sure you are sending the right password and not

Re: Re: Re:

2008-02-22 Thread Ivan Kalik
That looks like a pap request but that's not the cleartext password. Garbled password suggests that the shared secret in clients.conf and on the NAS are not the same (if you are sure you are sending the right password and not this). Ivan Kalik Kalik Informatika ISP Dana 22/2/2008, Dustin

Re: Mysql Crypt passwords

2008-02-22 Thread Ivan Kalik
man rlm_pap Ivan Kalik Kalik Informatika ISP Dana 22/2/2008, Dustin Schuemann [EMAIL PROTECTED] piše: I have my username and passwords stored in my database as encrypted. How can I get freeradius 1 to work with this passwords. Dustin Schuemann . Network Engineer .. . . . . . . . . . . . .