Re: about EAP using 1.1.7 and 2.0.3

2008-07-10 Thread Ryan Setiawan H
Alan wrote: hi, as Alan stated - your NAS doesnt seem to be getting the responses from your server. some ACL or routing issue? (stick a sniffer directly in front of the switch...if you need to, you may need to have a 'port mirror' or somesuch from the switch that feeds that switch if traffic

Re: about freeradius accepts anybody

2008-07-10 Thread Fernando
I don't understand, what is your goal? Sergio Yébenes Moreno wrote: Using eap-tls we can make a filter to users, based on different attibutes (I think). In my case, the identity field in wpa_supplicant.conf. Freeradius config: file users contains this . . $INCLUDE autorizados

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com To use eap-tls with client certs signed by a public CA. Public CA means that I can't do anything with this. But I don't want that everybody comes to my network. I know

Re: about freeradius accepts anybody

2008-07-10 Thread Fernando
://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com To use eap-tls with client certs signed

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com To use eap-tls

general howto bandwidth control

2008-07-10 Thread mike
hi folk, we have a little network with some cable modems. all modems use freeradius for authenticating and all useres use a pppoe session against freeradius to connect with the router. this works. now we want a bandwidth limitation for each modem. is this possible with freeradius? or how can

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com To use eap-tls

Re: about freeradius accepts anybody

2008-07-10 Thread Fernando
/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http

Re: general howto bandwidth control

2008-07-10 Thread Ivan Kalik
http://wiki.freeradius.org/Vendor-Specific_Attributes Ivan Kalik Kalik Informatika ISP Dana 10/7/2008, mike [EMAIL PROTECTED] piše: hi folk, we have a little network with some cable modems. all modems use freeradius for authenticating and all useres use a pppoe session against freeradius to

Re: general howto bandwidth control

2008-07-10 Thread Alan DeKok
mike wrote: we have a little network with some cable modems. all modems use freeradius for authenticating and all useres use a pppoe session against freeradius to connect with the router. this works. now we want a bandwidth limitation for each modem. is this possible with freeradius? or how

Re: about freeradius accepts anybody

2008-07-10 Thread Ivan Kalik
Ok. DNIe gives PUBLIC access control, to a public network (university, madrid Wifi (jeje, gallardón va de rey alcalde) etc), Dinamic keys, and all in 802.1x and, in consequence, 802.11i. But probably we don't want everybody in this network.Surely we hadn't spend money and time issuing

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
this. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus

Re: about freeradius accepts anybody

2008-07-10 Thread Alan DeKok
Sergio Yébenes Moreno wrote: I don't want to use passwords. Then why did the configurations you posted use passwords? Now I want to put 3 virtual server, one for DNIe and one for another public CA (FNMT) that have less range than DNIe. I'd like to ask you, if you know. authorize section

RE: about freeradius accepts anybody

2008-07-10 Thread Ivan Kalik
first, freeradius looks in users file, and only if client is authorized, checks DNIe. There aren't any problem, only want to show, maybe help somebody, and to show Ivan Kalik how clients and servers can trust in different ca's. Oh, but I know exactly what you have done. You have created a

Re: about freeradius accepts anybody

2008-07-10 Thread Fernando
://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com I don't want to use passwords. Only want to use what at this time is working: public domain eap-tls

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
. If it was supported, it would have been documented. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com Oh, I'll try this. Really empty password is shit. Thanks - List info/subscribe/unsubscribe? See http

Re: about freeradius accepts anybody

2008-07-10 Thread Alan DeKok
Sergio Yébenes Moreno wrote: Oh, I'll try this. Really empty password is shit. Thanks I think it's time for you to be polite. Cursing at people who are trying to help you is inappropriate. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: about freeradius accepts anybody

2008-07-10 Thread Alan DeKok
Sergio Yébenes Moreno wrote: If I don't put Cleartext-Password := field (!!!), the user always be rejected. Can anybody to explain this? Read the debug output as suggested in the FAQ, README, INSTALL, and daily on this list. It's not hard. Alan DeKok. - List

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com I don't want to use passwords. Only want to use what at this time is working: public

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio Yébenes Moreno
://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com Sorry if I offend anybody. I don't bring bad intentions and my vocabulary is little, I have a word translation web

Compiling client PAM files on Mac OS

2008-07-10 Thread Paul Goodman
Does anyone have some hacks to enable a clean compile on Mac OS X? When I try to run make, I get the following compile errors: cc -Wall -fPIC -c pam_radius_auth.c -o pam_radius_auth.o pam_radius_auth.c: In function ‘get_random_vector’: pam_radius_auth.c:358: error: storage size of ‘tz’ isn’t

Re: Compiling client PAM files on Mac OS

2008-07-10 Thread Nicolas Goutte
Am 10.07.2008 um 18:28 schrieb Paul Goodman: Does anyone have some hacks to enable a clean compile on Mac OS X? When I try to run make, I get the following compile errors: cc -Wall -fPIC -c pam_radius_auth.c -o pam_radius_auth.o pam_radius_auth.c: In function ‘get_random_vector’:

licensing question

2008-07-10 Thread Steven Van Ingelgem
How does the GPL apply to the freeradius plugins? I want to create a freeradius plugin (completely my code), but does the GPL apply to it? I ask because dynamic linking is a very gray area in the GPL field. Thanks for your answer, Steven - List info/subscribe/unsubscribe? See

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio
/unsubscribe? See http://www.freeradius.org/list/users.html __ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com I don't want to use passwords. Only want to use what at this time is working: public

Re: about freeradius accepts anybody

2008-07-10 Thread Ivan Kalik
If I don't put Cleartext-Password := field (!!!), the user always be rejected. Can anybody to explain this?I haven't tried with some password, because results me ridiculous, I haven't configure any password for clients... Let's put that to the test. Put the username that you

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio
__ Información de NOD32, revisión 3257 (20080710) __ Este mensaje ha sido analizado con NOD32 antivirus system http://www.nod32.com The situation that you exposed logically works. But I can't authorize all users in spite of having a valid certificate, because the public PKI. Then, users

Re: about freeradius accepts anybody

2008-07-10 Thread Ivan Kalik
The situation that you exposed logically works. But I can't authorize all users in spite of having a valid certificate, because the public PKI. .. what? You can authenticate some users (which) - what's the problem with the others? Then, users file: ... user1 . user2 .

Re: about freeradius accepts anybody

2008-07-10 Thread Sergio
Ivan Kalik escribió: The situation that you exposed logically works. But I can't authorize all users in spite of having a valid certificate, because the public PKI. .. what? You can authenticate some users (which) - what's the problem with the others? Any problem now Then,

RE: detail records

2008-07-10 Thread Roy Kartadinata
Hi Pshem, I tried your suggestion but still didn't work. Any other suggestion? Cheers, Roy Kartadinata -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] s.org] On Behalf Of Pshem Kowalczyk Sent: Wednesday, July 09, 2008 4:25 PM To: FreeRadius users mailing

Re: detail records

2008-07-10 Thread Pshem Kowalczyk
Hi, I tried your suggestion but still didn't work. Any other suggestion? Does anything get logged at all? Or are they only missing the additional attribute? kind regards Pshem - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: detail records

2008-07-10 Thread Roy Kartadinata
We only missing Freeradius-Proxied-To attribute which is the most important one. Below is what we have for accounting setting: Accounting { detail sql } Cheers, Roy Kartadinata -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] s.org] On Behalf

Re: detail records

2008-07-10 Thread Pshem Kowalczyk
Hi, We only missing Freeradius-Proxied-To attribute which is the most important one. Below is what we have for accounting setting: Accounting { detail sql } You have to do the logging in the pre-proxy section of the proxy server, otherwise the server doesn't know yet that

Re: detail records

2008-07-10 Thread Alan DeKok
Roy Kartadinata wrote: I tried your suggestion but still didn't work. Any other suggestion? Read the FAQ for it doesn't work. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html