Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-03 Thread Alan DeKok
Vieri wrote: However, user authentication is rejected when I add the --domain parameter: ntlm_auth = /usr/bin/ntlm_auth --request-nt-key --domain=%{mschap:NT-D omain} --username=%{Stripped-User-Name:-%{User-Name:-None}} --challenge=%{mschap:Challenge:-00}

Re: Suggestions

2008-10-03 Thread Alan DeKok
Bert Beaudin wrote: I am looking to use Freeradius and Active Directory along with adding members to a group to secure telnet access to Cisco devices. I am looking for sugestions on the best way to do this. Configure AD as an LDAP server, and use the LDAP-Group attribute to check group

Re: EAP-TTLS first connection works, other won't

2008-10-03 Thread Alan DeKok
Giovanni Lovato wrote: I set up freeradius 2.1.1 for EAP-TTLS, on Debian Lenny. As client I'm using Ubuntu. When I try to connect, first user, (on the logs, heruan) connect successfully, but subsequent users (e.g. jamila) won't. If I restart freeradius, and try to connect first with jamila and

Re: Make Install Errot : FreeRadius V 2.1.1 on Suse

2008-10-03 Thread Alan DeKok
Syed Anwarul Hasan wrote: I have compiled FreeRadius V 2.1.1 on SLES 10 SP2 .And after config and make steps when I tried the 'make Install' to install the binaries. I got an libtool error and Installation stopped. ... libtool: install: error: cannot install rlm_acctlog.la to a directory not

Re: The client does not connect _*_*_*_

2008-10-03 Thread Anders Holm
Again, what's the debug output? Does the client manage to send a RADIUS packet that actually arrives at the server? //anders 2008/10/1 Martin Silvero [EMAIL PROTECTED] sorry what they say is ... The access point has an IP 10.0.31.x and is included within raddb/client.conf, forget

Re: Make Install Errot : FreeRadius V 2.1.1 on Suse

2008-10-03 Thread Syed Anwarul Hasan
Hi Alan, I tried by the Prefix option --prefix =/usr in Configure step to Install files in /usr rather than /usr/local which is default. *Still, I got the same error*. And to inform you, when I build the freeradius rpm package from freeradius.spec file. I have removed the autoreconf line to

control-socket name one character short

2008-10-03 Thread Zoltan Ori
I have installed version 2.1.1 on FreeBSD 7.0 from source obtained at download link on www.freeradius.org. The server just works! Thank you Mr. DeKok et. al. I wanted to try radmin, so I copied control-socket from sites-available to sites-enabled. When I started the server I received #

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-03 Thread luis a
pal if you are using freeradius binary version as i was using before you can debug typing freeradius -X if you are using the compiled version as i did a few days ago , should work only tipping radiusd -X PD: my freeradius still does not authenticating against AD :-( --- El jue, 2/10/08,

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-03 Thread tnt
Don't hijack other peoples thread. BTW did you fix the users file entry so the server can start up? Ivan Kalik Kalik Informatika ISP Dana 3/10/2008, luis a [EMAIL PROTECTED] piše: pal if you are using freeradius binary version as i was using before you can debug typing freeradius -X if you

Re: EAP-TTLS first connection works, other won't

2008-10-03 Thread Giovanni Lovato
Alan DeKok wrote: Giovanni Lovato wrote: I set up freeradius 2.1.1 for EAP-TTLS, on Debian Lenny. As client I'm using Ubuntu. When I try to connect, first user, (on the logs, heruan) connect successfully, but subsequent users (e.g. jamila) won't. If I restart freeradius, and try to connect

The client does not connect _*_*_*_

2008-10-03 Thread Martin Silvero
the problem is... when I want to connect from the notebook to the network radius, asking me to configure the profile to the type of authentication, and so on. what set everything is ready and when I try to connect but does not connect to the server and are not recorded requests. on the server

Re: The client does not connect _*_*_*_

2008-10-03 Thread tnt
Get Wireshark and start looking at what happens to radius packets. Staring at it is not going to make it work. You will find out that you do have a firewall after all. Or your AP is sending packets to the wrong address. Or your routing is messed up. Ivan Kalik Kalik Informatika ISP Dana

The client does not connect _*_*_*_

2008-10-03 Thread Martin Silvero
ok tnt, I try that with the application, testing and do you notice. Thank you very much! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

The client does not connect _*_*_*_

2008-10-03 Thread Martin Silvero
Well, monitoring and testing in the log have this: Going to the next request Waking up in 2.9 seconds. rad_recv: Access-Request packet from host 10.0.31.40 port 1645, id=68, length=144 User-Name = msilvero Framed-MTU = 1400 Called-Station-Id = 0019.2fdb.9e00

Re: The client does not connect _*_*_*_

2008-10-03 Thread tnt
rlm_eap_tls: TLS 1.0 Handshake [length 0384], Certificate -- verify error:num=20:unable to get local issuer certificate rlm_eap_tls: TLS 1.0 Alert [length 0002], fatal unknown_ca TLS Alert write:fatal:unknown CA TLS_accept:error in SSLv3 read client certificate B rlm_eap: SSL error

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-03 Thread tnt
Use: --username=%{mschap:User-Name} and it should work. Ivan Kalik Kalik Informatika ISP Dana 3/10/2008, Vieri [EMAIL PROTECTED] piše: --- On Thu, 10/2/08, Vieri [EMAIL PROTECTED] wrote: I'm running freeradius-2.0.5 on Linux. My setup is as follows: Windows Vista native client -

The client does not connect _*_*_*_

2008-10-03 Thread Martin Silvero
yes, I imported client.p12 and ca.der to the notebook, the checked again and are fine - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: The client does not connect _*_*_*_

2008-10-03 Thread Vegard Svanberg
* Martin Silvero [EMAIL PROTECTED] [2008-10-03 21:02]: yes, I imported client.p12 and ca.der to the notebook, the checked again and are fine Can you please learn to quote and reply properly. Thanks. -- Vegard Svanberg [EMAIL PROTECTED] [EMAIL PROTECTED] (EFnet)] - List

The client does not connect _*_*_*_

2008-10-03 Thread Martin Silvero
I apologize to you for not knowing English well, I live in Argentina and my native language is spanish (I doubt you know Spanish), if you are unable to interpret what I am trying to say is your problem with your gray matter , but please if I express ticket that I am not wrong understanding and can

unable to write 'random state' when starting freeradius

2008-10-03 Thread Madwifi Wireless
Has anyone come across this error? This happens when I start freeradius for the first time. Platform: RedHat ES 4.0 Version: FreeRadius 2.1.1 I have highlighted the message in read. It doesn't matter if I run this command as root. Thanks for you help. AM sudo ./radiusd - Fri Oct 3

unable to write 'random state' on startup

2008-10-03 Thread Madwifi Wireless
Has anyone come across this error? This happens when I start freeradius for the first time. Platform: RedHat ES 4.0 Version: FreeRadius 2.1.1 I have highlighted the message in read. It doesn't matter if I run this command as root. Thanks for you help. Sorry if this is posted twice. AM

Re: unable to write 'random state' when starting freeradius

2008-10-03 Thread John Dennis
Madwifi Wireless wrote: Has anyone come across this error? This happens when I start freeradius for the first time. Platform: RedHat ES 4.0 Version: FreeRadius 2.1.1 random_file = /usr/local/freeradius-2.1.1/etc/raddb/certs/random What are the ownership and permissions and ownership on the

Re: unable to write 'random state' when starting freeradius

2008-10-03 Thread Madwifi Wireless
Hi John, Thanks for the response, here is my settings. I am basically running this as root since am just testing right now. In my radiusd.conf the user/group is commented out. # #user = radius #group = radius And the permission on the certs directory is 770 [EMAIL PROTECTED] sbin]# ls -ld