Re: Certificate Error!

2008-06-10 Thread Ivan Kalik
What is the system date format on that XP: day/month/year or month/day/year? Click on the certificate details tab. Are dates printed as words or numbers? Ivan Kalik Kalik Informatika ISP Dana 10/6/2008, Kwok Sianbin [EMAIL PROTECTED] piše: Hi Ivan, The dates are ok (up-to-date). Here I attach

RE: FR 2.0.4 on Solaris 10 Sparc

2008-06-10 Thread Stefan A.
Gurus! I still have problems, getting FR 2.0.4 up and running, for days.. Reading hundreds of emails and listings I'm lost. Alan, thanks for your reply. I followed your hint and configured using this options: ./configure --with-openssl-libraries=/usr/sfw/lib \

Re: FR 2.0.4 on Solaris 10 Sparc

2008-06-10 Thread Alan DeKok
Stefan A. wrote: I still have problems, getting FR 2.0.4 up and running, for days.. Reading hundreds of emails and listings I'm lost. It's not a FreeRADIUS problem. I also renamed the src/directories of counter, eap, eap2, ippool, krb5, ldap, opt, pam, perl, python To not use

Dictionary : Ericsson-AB Packet Core Networks

2008-06-10 Thread rsg
Hi, Does anyone know of the RADIUS dictionary for Ericsson-AB PCN (Enterprise ID 10923) ? The currently available dictionary is for Ericsson -AB generic (VID 193) only. Many thanks in advance. sg. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problems compiling Freeradius 2.0.4 on Fedora 8 [Updated to 2.0.5]

2008-06-10 Thread Piero Giobbi
Hi. Update on FR 2.0.5 with Fedora 8 (from configure): [EMAIL PROTECTED] freeradius-server-2.0.5]# ./configure | grep -i warning config.status: WARNING: ./Make.inc.in seems to ignore the -- datarootdir setting config.status: WARNING: ./src/include/build-radpaths-h.in seems to ignore the

RE: FR and PEAP question

2008-06-10 Thread Matt Ashfield
HI, I’m now trying your suggestions for getting FR and PEAP working together. Below is the result of a radtest that I did. The password that is being supplied by radtest is in plain-text, should I be supplying it in ntPassword-encrypted format? It looks to me like I have something wrong with my

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Gennadiy Redko
Krzysztof Olędzki ?: I guess it works because it is properly configured. 3Com may also work if you setup it with (a blind guess): domain (...) vlan-assignment-mode string accounting optional It is updated firmware up to V3.03.01s56e. The config under your recommendations is changed.

RE: FR and PEAP question

2008-06-10 Thread Ivan Kalik
The password that is being supplied by radtest is in plain-text, should I be supplying it in ntPassword-encrypted format? No. It looks to me like I have something wrong with my authenticate section. My authorize section looks like: authorize { preprocess chap mschap

RE: FR and PEAP question

2008-06-10 Thread Matt Ashfield
I'd like to test this with PEAP/MSCHAP requests if possible. Is there a howto? Clearly I'm down the wrong path here. Matt [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ivan Kalik Sent: Tuesday, June 10, 2008 11:02 AM To:

Re: FR and PEAP question

2008-06-10 Thread Alan DeKok
Matt Ashfield wrote: I'd like to test this with PEAP/MSCHAP requests if possible. Is there a howto? Clearly I'm down the wrong path here. I'm in the process of writing some howto's for my deployingradius.com web page. But $$ work comes first. In short: - start with default config (as

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Krzysztof Olędzki
On 2008-06-10 14:45, Gennadiy Redko wrote: Krzysztof Olędzki ?: I guess it works because it is properly configured. 3Com may also work if you setup it with (a blind guess): domain (...) vlan-assignment-mode string accounting optional It is updated firmware up to V3.03.01s56e. Any

PEAP and TTLS simultaneously?

2008-06-10 Thread Tim Tyler
Freeradius experts, I am running Freeradius 1.1.3 on a Centos 5 system. My desire is to support PEAP mschapv2 clients against our ldap server's LM and NT passwords. We also want to support some other clients with a TTLS - PAP against the posix passwords in our same ldap server. I can

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Gennadiy Redko
Krzysztof Olędzki пишет: On 2008-06-10 14:45, Gennadiy Redko wrote: Krzysztof Olędzki ?: I guess it works because it is properly configured. 3Com may also work if you setup it with (a blind guess): domain (...) vlan-assignment-mode string accounting optional It is updated firmware

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Krzysztof Olędzki
On 2008-06-10 16:51, Gennadiy Redko wrote: Krzysztof Olędzki пишет: On 2008-06-10 14:45, Gennadiy Redko wrote: Krzysztof Olędzki ?: I guess it works because it is properly configured. 3Com may also work if you setup it with (a blind guess): domain (...) vlan-assignment-mode string

Re: PEAP and TTLS simultaneously?

2008-06-10 Thread Alan DeKok
Tim Tyler wrote: I am running Freeradius 1.1.3 on a Centos 5 system. I would suggest upgrading to 2.0.5. My desire is to support PEAP mschapv2 clients against our ldap server's LM and NT passwords. We also want to support some other clients with a TTLS - PAP against the posix

Radius on server X; VPN on server Y; Samba on server Z

2008-06-10 Thread Sascha Kiefer
Hi, I have the following: * Radius on server X * VPN on server Y * Samba on server Z Each server is located on a different continent. :-) Ok, user foo now connects to the VPN server and gets authorized by radius. Fine. Now, i want him to allow to connect to the samba server. Ideally without

Re: RADIUS with LDAP: changing LDAP filter based on RADIUS request

2008-06-10 Thread Sylvain Robitaille
On Mon, 9 Jun 2008, Ivan Kalik wrote: man unlang - attribute lists. *** The list: prefix is optional, and if omitted, is assumed to refer to the request list. *** Ah yes ... That helps a lot. Thank you. However, having fixed references to %{CU-LDAP-Filter} so they now refer to

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Gennadiy Redko
Krzysztof Olędzki пишет: I'm not able to locate the output of above commands there. Similar, that this config for the switch 5500 without G. I'm sorry. Tomorrow we shall understand. Regards. Gennadii. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Dependencies of Freeradius 2.0.5

2008-06-10 Thread Alan DeKok
Leander S. wrote: Is there any List of the dependencies to have a quick look that I get an overview of what I need before I can start compiling FreeRADIUS? It depends what you want. A basic FreeRADIUS install doesn't need anything other than a C compiler, and libc. If you want to do

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Ivan Kalik
Did you put use-tunneled-reply=yes in peap config? I also can't see freeradius config files. Ivan Kalik Kalik Informatika ISP Dana 10/6/2008, Krzysztof Olędzki [EMAIL PROTECTED] piše: On 2008-06-10 16:51, Gennadiy Redko wrote: Krzysztof OlÄ#65533;dzki пиŃ#65533;ĐľŃ#65533;: On 2008-06-10

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Krzysztof Olędzki
On 2008-06-10 17:33, Gennadiy Redko wrote: Krzysztof Olędzki пишет: I'm not able to locate the output of above commands there. Similar, that this config for the switch 5500 without G. I'm sorry. Tomorrow we shall understand. I'm not asking for configs here but for an output of some quite

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Gennadiy Redko
Krzysztof Olędzki пишет: On 2008-06-10 17:33, Gennadiy Redko wrote: Krzysztof Olędzki пишет: I'm not able to locate the output of above commands there. Similar, that this config for the switch 5500 without G. I'm sorry. Tomorrow we shall understand. I'm not asking for configs here but for

Re: RADIUS APIs

2008-06-10 Thread pallavi dharmadhikari
For wireless authentication ,which EAP authentication methods are more suitable to implement on linux machine. Also, if I use EAP-TLS method, how can create certificate on client side for EAP-TLS authentication? On Fri, Jun 6, 2008 at 4:27 AM, Alan DeKok [EMAIL PROTECTED] wrote: pallavi

Re: Whether the FreeRADIUS supports switch 3Com 5500G-EI ?

2008-06-10 Thread Gennadiy Redko
Ivan Kalik ?: Did you put use-tunneled-reply=yes in peap config? I also can't see Maybe *use_tunneled_reply=yes* ? freeradius config files. Has loaded once again. http://bugs.freeradius.org/showattachment.cgi?attach_id=276 It's .ZIP file with a name raddb.zip - List

Freeradius error: Discarding conflicting packet

2008-06-10 Thread jelle-e
Hi, I've enabled extensive logging and radiusd runs as daemon process (# /usr/local/sbin/radiusd). I have a medium sized network with about 25 Access Points (AP's) now (Linksys WAP54G). It runs with following encryption options: WPA-Enterprise, AES, PEAP, mschapv2, without using certificates.

Re: Freeradius error: Discarding conflicting packet

2008-06-10 Thread Alan DeKok
jelle-e wrote: Everything seems to run smoothly but before every login attempt the logs say (something like): Error: Discarding conflicting packet from client NAS-NAME port 3072 - ID: 3 due to recent request 28. That's pretty definitive. After that the user logs in correctly. I have

Re: FreeRadius/eDirectory/802.1X authentication issue

2008-06-10 Thread Ivan Kalik
rlm_mschap: Told to do MS-CHAPv2 for UserB with NT-Password rlm_mschap: FAILED: MS-CHAP2-Response is incorrect (Cached) password for that user on that laptop is wrong. Changing that wrong password will require a bit of registry hacking:

RE: FreeRadius/eDirectory/802.1X authentication issue

2008-06-10 Thread Newall, Bryce
-Original Message- From: [EMAIL PROTECTED] [mailto:freeradius-users- [EMAIL PROTECTED] On Behalf Of Ivan Kalik Sent: Tuesday, June 10, 2008 5:35 PM To: FreeRadius users mailing list Subject: Re: FreeRadius/eDirectory/802.1X authentication issue rlm_mschap: Told to do