RE: chap authentication and freeradius

2009-01-31 Thread gf fg
Ok you are told me that my router are not sending chap ??? I will chek on monday and will send again my config. > To: freeradius-users@lists.freeradius.org > Subject: RE: chap authentication and freeradius > Date: Sun, 1 Feb 2009 03:22:38 +0100 > From: t...@kalik.net > > >I have this when the u

RE: chap authentication and freeradius

2009-01-31 Thread tnt
>I have this when the user try to authenticate but on Monday i will post all >info of the freeradius -X The request would be nice. >why the radius sayd me rlm_chap: Attribute "CHAP-Password" is required for >authentication. ??? Because you are forcing Auth-Type CHAP on something that isn't a

RE: chap authentication and freeradius

2009-01-31 Thread gf fg
Sorry for the las email this is the correct with my question I have this when the user try to authenticate but on Monday i will post all info of the freeradius -X why the radius sayd me rlm_chap: Attribute "CHAP-Password" is required for authentication. ??? auth: type "CHAP" +- entering group

RE: chap authentication and freeradius

2009-01-31 Thread gf fg
I have this when the user try to authenticate but on Monday i will post all info of the freeradius -X auth: type "CHAP" +- entering group CHAP rlm_chap: Attribute "CHAP-Password" is required for authentication. ++[chap] returns invalid auth: Failed to validate the user. Login incorrect: [Olg

RE: chap authentication and freeradius

2009-01-31 Thread tnt
>and my freeradius -X was : > >FreeRADIUS Version 2.1.0, for host i486-pc-linux-gnu, built on Nov 14 2008 at >11:57:03 >Copyright (C) 1999-2008 The FreeRADIUS server project and contributors. >There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A >PARTICULAR PURPOSE. >You may redi

RE: chap authentication and freeradius

2009-01-31 Thread tnt
.. >Listening on authentication address 192.168.1.49 port 1812 >Listening on accounting address * port 1813 >Listening on proxy address 192.168.1.49 port 1814 >Ready to process requests. > You didn't send the request. The idea is to debug the request processing that "isn't working". Ivan Kalik Ka

RE: chap authentication and freeradius

2009-01-31 Thread gf fg
Here i post the tables and the config files: +--+ | Tables_in_radius | +--+ | badusers | | mtotacct | | radacct | | radcheck | | radgroupcheck| | radgroupreply| | radpostauth | | radreply | | radusergroup |

Re: chap authentication and freeradius

2009-01-31 Thread tnt
>I have installed Freeradius and diualup admin and mysql >I configurated the both ! I have an an aplication called vyatta. I am trying >that this vyatta validate the users with the freeradius >I configurated in the admin.conf with chap and clear-password and i set that >the password are store in

Re: Reject user by Calling-Station-Id

2009-01-31 Thread tnt
Here is a trick from the old days: Create a huntgroup like: blocked Calling-Station-Id == whatever SQL-Group == "suspend" Where suspend is the group with Auth-Type := Reject in it. That will blok him if he is in suspend group or not (only the message in radius.log will be differ

chap authentication and freeradius

2009-01-31 Thread gf fg
Hi Freeradius users! I have installed Freeradius and diualup admin and mysql I configurated the both ! I have an an aplication called vyatta. I am trying that this vyatta validate the users with the freeradius I configurated in the admin.conf with chap and clear-password and i set that the pass

Re: Certificate Provisioning for EAP-TLS Networks

2009-01-31 Thread Matt Causey
> How do you get the certificates on the device in the first place? Well - that's the problem. I would like for there be a USB cable method of putting the key material on the device. Then we could build some nifty client script to automate the provisioning. But these devices in particular don

Re: Reject user by Calling-Station-Id

2009-01-31 Thread Alex M
damn, upgrade will be painfull for me :( I guess I will try to use other means to block missbehaving users. At least we got only 3 people who try to free ride. thanks for help 2009/1/31 > Ah, sql groups don't work properly in 1.x. Upgrade. > > Ivan Kalik > Kalik Informatika ISP > > > Dana 31/1/

Re: Reject user by Calling-Station-Id

2009-01-31 Thread tnt
Ah, sql groups don't work properly in 1.x. Upgrade. Ivan Kalik Kalik Informatika ISP Dana 31/1/2009, "Alex M" piše: >I guess its different in newer version of radius but in my 1.5 the only >table that has PRIO is radgroupreply > >and there is table radusergroup instead there is a group called