Re: Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Sergio
nf-vale escribió: Are you using vista supplicant? By reading the last lines of your radius debug file it seems so... See earlier posts with subject: "PEAP or TTLS and Microsoft Vista". Sex, 2008-07-25 às 17:10 +, Reveal MAP escreveu: installing ca.der and putting user && pass in

Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread nf-vale
Are you using vista supplicant? By reading the last lines of your radius debug file it seems so... See earlier posts with subject: "PEAP or TTLS and Microsoft Vista". Sex, 2008-07-25 às 17:10 +, Reveal MAP escreveu: > > > > installing ca.der and putting user && pass into client machine,

FreeRadius 2.0.3 setup help

2008-07-25 Thread Brooks, Kyle
Hello, We have been trying to setup the new FreeRadius server, version 2.0.3 on Fedora 9. We are very close as during testing a user was able to authenticate to AD via LDAP. Radtest was ok, but there is no accept packet/acknowledgment sent back, so the network switch thinks the user hasn't been

ippool with non-contiguous ip ranges

2008-07-25 Thread Marco C. Coelho
I've got 3 class C ranges that are contiguous assigned to a freeradius server. I want to add an additional class C ranges to this server, but they are not contiguous with the previous three. I would like to add 64.202.231.1 - 64.202.234.254 without creating an additional IP Pool . I've search

Re : Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Reveal MAP
> installing ca.der and putting user && pass into client machine, the authentication doesn't work? -- no, it doesn't! > you only need ca.der but, if you have an active directory like LDAP, check if your comunication with AD server also have tls authentication. Into ldap module you can conf

Re: Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Sergio
Reveal MAP escribió: > But I think this problem do not affect peap because peap do not use > client certs, you only need to install ca.der into client machine and > put the passwords i refer to that: > so my question is, if the certificate (with server extension) is missing on the client, coul

Re : Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Reveal MAP
> But I think this problem do not affect peap because peap do not use > client certs, you only need to install ca.der into client machine and > put the passwords i refer to that: > so my question is, if the certificate (with server extension) is missing on the client, could it interfer in EAP-P

Re: pam module

2008-07-25 Thread Nicolas Goutte
Am 25.07.2008 um 16:52 schrieb Robert Svensson: Hi, This might be a lame question but I can't get the pam module to work (with vsftpd, or any other pam aware application). I'm runing Ubuntu 8.04 an my config is the following: module version 1.3.17 my /etc/pam.d/vsftpd: authsufficient

Re: Device authentication and User+Device authentication

2008-07-25 Thread Alan DeKok
Cristian Novac wrote: > Could someone tell me what has to be configured to be able to do Device > authentication and User+Device authentication. It all depends how you plan on authenticating the devices and users. i.e. Which authentication protocols are you using? Then configure the authe

pam module

2008-07-25 Thread Robert Svensson
Hi, This might be a lame question but I can't get the pam module to work (with vsftpd, or any other pam aware application). I'm runing Ubuntu 8.04 an my config is the following: module version 1.3.17 my /etc/pam.d/vsftpd: authsufficient /lib/security/pam_radius_auth.so try_first_pass d

Re: Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Sergio
Reveal MAP escribió: HOW TO FIX THE PROBLEM OF THE ISSUER of clients certificates in default configuration? - this bug is suspected to make i can't do EAP-PEAP and affect the CRL management too. it's a real problem - Message d'origine De : Alan DeKok <[EMAIL PROTECTED]> À : FreeRa

Device authentication and User+Device authentication

2008-07-25 Thread Cristian Novac
Hi all, Could someone tell me what has to be configured to be able to do Device authentication and User+Device authentication. Thank you! Cristian NOVAC - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re : cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Reveal MAP
HOW TO FIX THE PROBLEM OF THE ISSUER of clients certificates in default configuration? - this bug is suspected to make i can't do EAP-PEAP and affect the CRL management too. it's a real problem - Message d'origine De : Alan DeKok <[EMAIL PROTECTED]> À : FreeRadius users mailing lis

Re: cert bootstrap bug? (was Re: definitively, I have a problem with eap-tls)

2008-07-25 Thread Phil Mayers
On Thu, Jul 24, 2008 at 09:14:54PM +0200, Alan DeKok wrote: Phil Mayers wrote: Alan - it does look to my untrained eye as if the "client.crt" Makefile target in /etc/raddb/certs is signing the client key with the server key. Is this intentional, or a bug? It's intentional. It's a perfectly v