Re: Freeradius, Cisco SSC, eDirectory, EAP/(T)TLS Problem

2008-03-27 Thread Alan DeKok
Sven 'Darkman' Michels wrote: But this works only on freeradius 2.x, doesn't it? Actually i have 1.1.0 from SLES10... Download the binary Suse packages: http://freeradius.org/download.html 1.1.0 is *very* old. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Auth-Test accounts in users file

2008-03-27 Thread Alan DeKok
James McOrmond wrote: Yes. But don't set Auth-Type. Please. you seem to have a real issue with it :-) Because almost everyone gets it wrong, and then argues about it... I specifically want the test-pap account to fail if the authentication method used is anything but pap. I don't

Re: Freeradius, Cisco SSC, eDirectory, EAP/(T)TLS Problem

2008-03-27 Thread Sven 'Darkman' Michels
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, Alan DeKok wrote: Sven 'Darkman' Michels wrote: But this works only on freeradius 2.x, doesn't it? Actually i have 1.1.0 from SLES10... Download the binary Suse packages: http://freeradius.org/download.html 1.1.0 is *very* old. i

RADIUS ports

2008-03-27 Thread Santiago Balaguer García
Hi, Recently I have just configured another RADIUS server and I use /etc/services for radius service ports. I use auth port 1645 and acct port 1646. But, are these ports better than auth port 1812 and act port 1813 ? What ports are more standart ? Santiago

Re: Freeradius, Cisco SSC, eDirectory, EAP/(T)TLS Problem

2008-03-27 Thread Alan DeKok
Sven 'Darkman' Michels wrote: ...The only problem i had was where to force the client cert when using eap/tls EAP-TLS *always* uses a client cert. which seems to work except that the cisco client simply don't offer a cert when using ttls. As far as i know, this requirement is not often

Re: RADIUS ports

2008-03-27 Thread Alan DeKok
Santiago Balaguer García wrote: Hi, Recently I have just configured another RADIUS server and I use /etc/services for radius service ports. I use auth port 1645 and acct port 1646. But, are these ports better than auth port 1812 and act port 1813 ? What ports are more standart ? 1812

RE: Segmantation Fault on -HUP

2008-03-27 Thread Dmitry A. Sysoev
Thanks for answer. And I must upgrade the oracle database on upgrade 1.1.7 to 2.0.x? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Radius authentication

2008-03-27 Thread Charnjit Sidhu
Hi, My Radius client is working fine with the Radius Server, however I would also like to use this authentication on this same web server on a free resource calender application I have downloaded, to authenticate, I have created a Auth_radius.pl file with the following parameteres, as

Re: Segmantation Fault on -HUP

2008-03-27 Thread Alan DeKok
Dmitry A. Sysoev wrote: Thanks for answer. And I must upgrade the oracle database on upgrade 1.1.7 to 2.0.x? No. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Radius authentication

2008-03-27 Thread A . L . M . Buxey
Hi, I recieve an error in my log file of a missing Authen/Radius.pm file. I think this is a radius client perl module, does any one know where I can download this from, or wether there is a better solution, or I am doing somethin wrong, I am new to all this Radius authentication. as per

Re: RADIUS ports

2008-03-27 Thread A . L . M . Buxey
Hi, Hi, Recently I have just configured another RADIUS server and I use /etc/services for radius service ports. I use auth port 1645 and acct port 1646. But, are these ports better than auth port 1812 and act port 1813 ? What ports are more standart ? RFC ports - 1812, 1813 alan -

proxy.conf and virtual_server

2008-03-27 Thread Marc Boisis-Delavaud
Hello, I have two virtual server which listen on the same IP. According to realm in proxy.conf, I wich to proxy on virtual1 or virtual2. Is it possible to write this in proxy.conf ? realm toto { proxy to virtual_server = virtual1 } - List info/subscribe/unsubscribe? See

Re: Cisco AP, mysql, either MSCHAP or Auth-Type problem i think

2008-03-27 Thread A . L . M . Buxey
hi, trying to authenticate Vista against a plain password? PEAP doesnt work like this. you could put an NThash into the database instead.. or try using SecureW2 or other asupplicant that does EAP-TTLS/PAP alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Radius authentication

2008-03-27 Thread Charnjit Sidhu
Hi, Have downloaded and installed Authen:: Radius module from cpan without any problems, I know get no errors in my log files but it still does not authenticate, I already have a auth_radius.pl script which is run to authenticate which looks like this: #!/usr/bin/perl use Authen::Radius;

Re: Radius authentication

2008-03-27 Thread A . L . M . Buxey
Hi, use Authen::Radius; my $username = shift; my $password = shift; my $r = new Authen::Radius(Host = 'myserver', Secret = 'mysecret'); my $result = $r-check_pwd($username, $password); exit ($result == 1) ? 0 : 1; I thought this should pass all the relevant radius parametres to

Re: Radius authentication

2008-03-27 Thread Alan DeKok
Charnjit Sidhu wrote: Have downloaded and installed Authen:: Radius module from cpan without any problems, I know get no errors in my log files but it still does not authenticate, I already have a auth_radius.pl script which is run to authenticate which looks like this: Sorry, but this

Re: Cisco AP, mysql, either MSCHAP or Auth-Type problem i think

2008-03-27 Thread Mikael Syska
Hi, Thanks, that seemed to get me a bit further to the end now I got this: ++--+++---+ | id | username | attribute | op | value | ++--+++---+ | 2 | 44 | Cleartext-Password | := | |

Re: Cisco AP, mysql, either MSCHAP or Auth-Type problem i think

2008-03-27 Thread Alan DeKok
Mikael Syska wrote: Thanks, that seemed to get me a bit further to the end now I got this: ++--+++---+ | id | username | attribute | op | value | ++--+++---+ | 2 | 44 | Cleartext-Password |

Re: Cisco AP, mysql, either MSCHAP or Auth-Type problem i think

2008-03-27 Thread Ivan Kalik
It looks like you haven't configured sql (and password is in the database). Ivan Kalik Kalik Informatika ISP Dana 27/3/2008, Mikael Syska [EMAIL PROTECTED] piše: Hi, Thanks, that seemed to get me a bit further to the end now I got this: ++--+++---+

Re: Cisco AP, mysql, either MSCHAP or Auth-Type problem i think

2008-03-27 Thread Mikael Syska
Will look into that ... but I could auth with the radtest local on the machine, and then I asumed it was using mysql to lookup the user. But as you say, it seem logical :-) I will try and see if I can figure out where the error might be .. or else I will return to the list :-) // ouT On Thu,

ldap - freeradius

2008-03-27 Thread antoine vallée
Hi, I'm trying to to dynamic vlans assignment with freeradius (eap-md5 and chap), a ldap directory, and a HP switch procurve 2650. I have added the following attributes in the ldap.attrmap as well as on the ldap users account. And I've a (or more^^) mistake when I start freeradius. I've read

radius.log behaviour change v1 - v2

2008-03-27 Thread Stefan Winter
Hi, when doing tunneled EAP methods, the logging behaviour is different between v1 and v2. v1 used to be: inner request = localhost, outer request = real client, like below: Wed Dec 5 21:11:11 2007 : Auth: Login OK: [EMAIL PROTECTED] (from client localhost port 0) Wed Dec 5 21:11:11 2007 :

vmps documentation?

2008-03-27 Thread bmccorkle
Can someone point me to documentation on how to use vmps in freeradius 2? I've googled for documents but only find a few discussions on the topic (mostly from this forum). I get the part on adding the listen section in radiusd.conf so the server listens for vmps requests. However, I'm having

Re: ldap - freeradius

2008-03-27 Thread Ivan Kalik
http://wiki.freeradius.org/index.php/FreeRADIUS_Wiki:FAQ#It_says_.22Could_not_link_..._file_not_found.22.2C_what_do_I_do.3F Ivan Kalik Kalik Informatika ISP Dana 27/3/2008, antoine vallée [EMAIL PROTECTED] piše: Hi, I'm trying to to dynamic vlans assignment with freeradius (eap-md5 and

Re: vmps documentation?

2008-03-27 Thread Ivan Kalik
Yes, you can use users file. Ivan Kalik Kalik Informatika ISP Dana 27/3/2008, bmccorkle [EMAIL PROTECTED] piše: Can someone point me to documentation on how to use vmps in freeradius 2? I've googled for documents but only find a few discussions on the topic (mostly from this forum). I get

Re: vmps documentation?

2008-03-27 Thread Alan DeKok
bmccorkle wrote: Can someone point me to documentation on how to use vmps in freeradius 2? Er... Documentation? I've googled for documents but only find a few discussions on the topic (mostly from this forum). I get the part on adding the listen section in radiusd.conf so the server

safe_characters in freeradius 2.0.3

2008-03-27 Thread Dmitry A. Sysoev
Good afternoon! After upgrade from 1.1.7 to 2.0.3 version i have a problem in sql-queries: sql.conf: AcctStopTime = TO_TIMESTAMP_TZ('%{Event-Timestamp}','Mon dd hh24:mi:ss tzd'), \ radiusd -X (ver 2.0.3) ... AcctStopTime = TO_TIMESTAMP_TZ('=22Mar 27 2008 18:35:25 MSK=22' ...

Compile Error on FreeR 2.0.3

2008-03-27 Thread Breuer Nicolas
I've an error on compilation : MYSQL 4.1 - FC 7 ./configure --without-threads --with-mysql-lib-dir=/usr/lib64/ gcc -g -O2 -Wall -D_GNU_SOURCE -DNDEBUG -I/var/instapp/freeradius- server-2.0.3/src -DHOSTINFO=\x86_64-unknown-linux-gnu\ - DRADIUSD_VERSION=\2.0.3\ -DOPENSSL_NO_KRB5 -c xlat.c

Re: Compile Error on FreeR 2.0.3

2008-03-27 Thread Alan DeKok
Breuer Nicolas wrote: I've an error on compilation : ... ./configure --without-threads --with-mysql-lib-dir=/usr/lib64/ Hmm... the --without-threads option is not what I normally use. event.c:2305: error: 'argval' undeclared (first use in this function) event.c:2305: error: (Each

freeradius web administration

2008-03-27 Thread parfait kouassi nda
From: [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Subject: RE: freeradius web administration Date: Tue, 25 Mar 2008 09:11:00 + Hi, I've follow the instruction on the link to configure dialup admin. i've a problem with the php3 scripts. when i test the configuration

Re: freeradius web administration

2008-03-27 Thread Arran Cudbard-Bell
parfait kouassi nda wrote: From: [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Subject: RE: freeradius web administration Date: Tue, 25 Mar 2008 09:11:00 + Hi, I've follow the instruction on the link to configure dialup admin. i've a problem with

Re: freeradius web administration

2008-03-27 Thread Ivan Kalik
This is an apache problem - nothing to do with freeradius. Just add .php3 to be processed the same way as .php file. Ivan Kalik Kalik Informatika ISP Dana 27/3/2008, parfait kouassi nda [EMAIL PROTECTED] piše: From: [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Subject: RE:

Re: safe_characters in freeradius 2.0.3

2008-03-27 Thread snaut
Why the %{Event-Timestamp} is =22Mar 27 2008 20:59:09 MSK=22. And what is the =22?? Whence it undertakes? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: safe_characters in freeradius 2.0.3

2008-03-27 Thread Ivan Kalik
And what is the =22?? ASCII for double quote - . Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Freeradius and poprelayd - any ideas please

2008-03-27 Thread Bill Brunton
I am using Freeradius 1.1.3 on Centos 5. I have been trying to figure out how to add the IP address of each authenticated user to the popip database maintained by poprelayd. It is easy to add an ip address to the popip database with the command: /usr/sbin/poprelayd -a ip How do I

Re: Freeradius and poprelayd - any ideas please

2008-03-27 Thread Ivan Kalik
Do you need freeradius at all? This is normally done with pop before smtp. You contact the pop server, it logs the IP and then you can send. Ivan Kalik Kalik Informatika ISP Dana 27/3/2008, Bill Brunton [EMAIL PROTECTED] piše: I am using Freeradius 1.1.3 on Centos 5. I have been trying to

Re: Freeradius and poprelayd - any ideas please

2008-03-27 Thread Bill Brunton
Well - it seems that many customers have trouble with Outlook and Outlook Express.. If they have an email in the outbox, say they compose offline and connect to send it, it tries to send it before checking email... In other words no POP before SMTP. If Outlook does not send successfully -

Re: Freeradius and poprelayd - any ideas please

2008-03-27 Thread Bill Brunton
I also thought about doing a radlast -r and pulling out the IP addresses and adding them to the database every 5 minutes or so, but many sessions are not removed from that list and I end up with 20 times as many sessions there as I have real sessions on line. How can I get freeradius to

RE: safe_characters in freeradius 2.0.3

2008-03-27 Thread Dmitry A. Sysoev
As I should act, that all worked for me, as well as in 1.1.7? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ivan Kalik Sent: Thursday, March 27, 2008 11:52 PM To: FreeRadius users mailing list Subject: Re: safe_characters in freeradius 2.0.3 And what

PDP-Context support

2008-03-27 Thread M U
Dear all, I'm using Freeradius-1.1.0-19 on Suse Linux. I want to know how many pdp-context will be supported on freeradius per second. It depends on the server's specifiation but is there any reference ? I'm using Pentium4 machine of Dell optiplex. Please give me an advice asap.