Re: licensing question

2008-07-11 Thread Steven Van Ingelgem
Thanks Alan for your answer. Although I'm not very happy with it ... This means I need to put more work on the program. If your module calls GPL'd functions in FreeRADIUS, then it would be clear that it should follow the terms of the GPL. I am calling cf_section_parse, rad_malloc, rad_log,

Re: licensing question

2008-07-11 Thread Alan DeKok
Steven Van Ingelgem wrote: Thanks Alan for your answer. Although I'm not very happy with it ... This means I need to put more work on the program. Since you're leverage nearly 10 years of FreeRADIUS development, the balance is clearly in your favor. I am calling cf_section_parse,

Freeradius and Cisco (cisco-avpair = shell:priv-lvl=15 doesn't work)

2008-07-11 Thread Simo
hello Mailing-List, i'm trying to do the authentication of cisco cat switches with the freeradius. The Authentication works fine, also the authentication of the enable lvl mode (e.g. $enab15$) and the accounting too (the configuration is from the freeradius-wiki cisco artical). But i'm still

Re: general howto bandwidth control

2008-07-11 Thread mike
Alan DeKok wrote: mike wrote: we have a little network with some cable modems. all modems use freeradius for authenticating and all useres use a pppoe session against freeradius to connect with the router. this works. now we want a bandwidth limitation for each modem. is this possible with

Re: Freeradius and Cisco (cisco-avpair = shell:priv-lvl=15 doesn't work)

2008-07-11 Thread Alan DeKok
Simo wrote: i'm trying to do the authentication of cisco cat switches with the freeradius. The Authentication works fine, also the authentication of the enable lvl mode (e.g. $enab15$) and the accounting too (the configuration is from the freeradius-wiki cisco artical). But i'm still having

Re: general howto bandwidth control

2008-07-11 Thread Alan DeKok
mike wrote: hm, i believe i have a problem with the terminology. the NAS is here the modem not the pppd, right? The NAS is the RADIUS client. If you're going to use RADIUS, please familiarize yourself with basic terminology. The NAS is the one sending the RADIUS Access-Requests, and

Re: Freeradius and Cisco (cisco-avpair = shell:priv-lvl=15 doesn't work)

2008-07-11 Thread Ivan Kalik
Something is not right here. Request is for: Cisco-NAS-Port = tty2 and there is no Service-Type attribute in the request. And then Cisco aaa debug is for a different port which should have a Service-Type in the request: 03:27:12: AAA/AUTHEN/START (2153705482): port='tty3' list=''

Re: Freeradius and Cisco (cisco-avpair = shell:priv-lvl=15 doesn't work)

2008-07-11 Thread Simo
On Fr, 2008-07-11 at 10:38 +0100, Ivan Kalik wrote: Cisco-NAS-Port = tty2 Thnx for your reply. I have setting the NAS-Port to tty2 but i'm still having the same Problem. And here is the reply of switch (priv=1 was requested): 04:25:06: AAA: parse name=tty2 idb type=-1 tty=-1 04:25:06: AAA:

Re: about freeradius accepts anybody

2008-07-11 Thread Sergio
Fernando escribió: Sergio wrote: Fernando escribió: Sergio Yébenes Moreno wrote: Ivan Kalik escribió: Ok. DNIe gives PUBLIC access control, to a public network (university, madrid Wifi (jeje, gallardón va de rey alcalde) etc), Dinamic keys, and all in 802.1x and, in consequence, 802.11i.

Re: about freeradius accepts anybody

2008-07-11 Thread Fernando
Sergio wrote: Fernando escribió: Sergio wrote: Fernando escribió: Sergio Yébenes Moreno wrote: Ivan Kalik escribió: Ok. DNIe gives PUBLIC access control, to a public network (university, madrid Wifi (jeje, gallardón va de rey alcalde) etc), Dinamic keys, and all in 802.1x and, in

Re: about freeradius accepts anybody

2008-07-11 Thread Ivan Kalik
AUTENTICACIÓN is a suffix of user-name, but only for those certificates that are subordinated to FNMT ca. NOMBRE is a prefix of user-name which have DNIe, subordinated to another ca. I want to configure two virtual servers based on this details, if I can. OK. I had a look and found out that

Re: about freeradius accepts anybody

2008-07-11 Thread Sergio
Ivan Kalik escribió: AUTENTICACIÓN is a suffix of user-name, but only for those certificates that are subordinated to FNMT ca. NOMBRE is a prefix of user-name which have DNIe, subordinated to another ca. I want to configure two virtual servers based on this details, if I can. OK. I had

Re: licensing question

2008-07-11 Thread John Dennis
Steven Van Ingelgem wrote: Thanks Alan for your answer. Although I'm not very happy with it ... So I guess I am subject to the GPL, even if 99% of the code is mine ;-). That is a remarkably bad attitude which will find little sympathy from open source developers. It never ceases to amaze me

Re: Freeradius and Cisco (cisco-avpair = shell:priv-lvl=15doesn't work)

2008-07-11 Thread David Mitchell
Ivan Kalik wrote: You need to have a look at switch radius documentation to see which Service -Type are you suposed to return. Administrative-User? This is IOS, correct? You need to add 'aaa authorization exec default group radius none' to your config or else the switch will ignore your higher

Re: about freeradius accepts anybody

2008-07-11 Thread Sergio
Ivan Kalik escribió: AUTENTICACIÓN is a suffix of user-name, but only for those certificates that are subordinated to FNMT ca. NOMBRE is a prefix of user-name which have DNIe, subordinated to another ca. I want to configure two virtual servers based on this details, if I can. OK. I had

rlm_pap: WARNING! No known good password found for the user.

2008-07-11 Thread Maciej Drobniuch
Hi! radtest fred somepass localhost 1813 somesecret Sending Access-Request of id 102 to 127.0.0.1 port 1812 User-Name = fred User-Password = somepass NAS-IP-Address = 127.0.0.1 NAS-Port = 1813 rad_recv: Access-Reject packet from host 127.0.0.1 port 1812, id=102,

Re: rlm_pap: WARNING! No known good password found for the user.

2008-07-11 Thread Ivan Kalik
You probably have two instances of the server installed. These files don't belong to the server that is running. Ivan Kalik Kalik Informatika ISP Dana 11/7/2008, Maciej Drobniuch [EMAIL PROTECTED] piše: Hi! radtest fred somepass localhost 1813 somesecret Sending Access-Request of id 102 to

Re: rlm_pap: WARNING! No known good password found for the user.

2008-07-11 Thread Scott Lambert
On Fri, Jul 11, 2008 at 08:14:13PM +0200, Maciej Drobniuch wrote: Hi! radtest fred somepass localhost 1813 somesecret Sending Access-Request of id 102 to 127.0.0.1 port 1812 User-Name = fred User-Password = somepass NAS-IP-Address = 127.0.0.1 NAS-Port =

Re: rlm_pap: WARNING! No known good passwor d found for the user.

2008-07-11 Thread Maciej Drobniuch
Hi! I've deleted the old /sbin /bin /raddb dirs and then i've executed make install in the freerad 2.0.5 dir... So what is the fastest and the cleanest way to remove the old version? Usually I use packages but I've had problems running radiusd when installing from them... Thanks and sorry for my

Re: rlm_pap: WARNING! No known good passwor d found for the user.

2008-07-11 Thread Maciej Drobniuch
I've cleaned the mess up like you've said, but i've got new errors for you which are not familiar to me ;) Fri Jul 11 21:17:56 2008 : Debug: auth: No authenticate method (Auth-Type) configuration found for the request: Rejecting the user Fri Jul 11 21:17:56 2008 : Debug: auth: Failed to validate

Re: rlm_pap: WARNING! No known good password found for the user.

2008-07-11 Thread Sambuddho Chakravarty
Hello I think I had a very similar problem couple of days back. I think your authorization is working but authentication is failing right ? Thanks Sambuddho On Fri, 2008-07-11 at 21:21 +0200, Maciej Drobniuch wrote: I've cleaned the mess up like you've said, but i've got new errors for you

Re: rlm_pap: WARNING! No known good passwor d found for the user.

2008-07-11 Thread Maciej Drobniuch
I thing that authorization because the user can't be found in the users file... just look at the part of debug output: Fri Jul 11 21:40:46 2008 : Debug: modsingle[authorize]: calling files (rlm_files) for request 1 Fri Jul 11 21:40:46 2008 : Debug: modsingle[authorize]: returned from files

Re: rlm_pap: WARNING! No known good password found for the user.

2008-07-11 Thread Ivan Kalik
Am I using an old definition of Auth-Type in my users file? Or what ? fred Auth-Type := Local, Cleartext-Password ==somepass Service-Type = Framed-User, Framed-Protocol = PPP With what should i replace the Auth-Type variable or variable name? Read instructions in