Re: 802.1x with freeradius + PEAP + 3com Switch

2009-02-06 Thread Laurent CARON
t...@kalik.net wrote: That should be: ldap ldap1 { .. } ldap ldap2 { .. } What i wrote should go in the authorize section instead of ldap entry. Hi, Thanks a zillion times ;) Laurent - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: command autho. is it possible?

2009-02-06 Thread tnt
I have read a lot of manual, example and post, but I still don't know what is the solutions. I have newest freeradius, and cisco devices(now AP). I want the user authentication to the cisco device by fr, It works, I configure the users file like this: test Cleadtext-Password := test

otp daemon for use with freeradius

2009-02-06 Thread Norbert Wegener
in otp.conf an otpd is mentioned for use with freeradius. According to the licence the daemon can only be used with tokens from tri-dsystems. Is there another otpd around that is free? Thanks Norbert Wegener - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

PAP authentication and multiple LDAP userpassword attributes

2009-02-06 Thread Christophe Saillard
Hi, I'm working on upgrading from FR 1.1.7 to FR 2.1.3. I use FR for EAP-TTLS/PAP authentication with LDAP. FR 1.1.7 successfully authenticates users with multiple LDAPuserpassword attributes which are stored with crypt and/or MD5 hash, the passwords are not the same (even it's better if the

command autho. is it possible?

2009-02-06 Thread Hegedus Gabor
Hi all! I have read a lot of manual, example and post, but I still don't know what is the solutions. I have newest freeradius, and cisco devices(now AP). I want the user authentication to the cisco device by fr, It works, I configure the users file like this: test Cleadtext-Password :=

Re: command autho. is it possible?

2009-02-06 Thread Alan DeKok
Hegedus Gabor wrote: What is the solutions? I don't want use 2 server (tacacs+ and fr) for this. I saw something tacacs+ integration into freeradius but I don't know this is a good solution, an how can I configure. FreeRADIUS doesn't currently support TACACS+. Maybe in a future release.

Re: otp daemon for use with freeradius

2009-02-06 Thread Alan DeKok
Norbert Wegener wrote: in otp.conf an otpd is mentioned for use with freeradius. According to the licence the daemon can only be used with tokens from tri-dsystems. Is there another otpd around that is free? Not that I know of. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: otp daemon for use with freeradius

2009-02-06 Thread Alexander Clouter
* Alan DeKok al...@deployingradius.com [Fri, 06 Feb 2009 19:30:06 +0100]: Norbert Wegener wrote: in otp.conf an otpd is mentioned for use with freeradius. According to the licence the daemon can only be used with tokens from tri-dsystems. Is there another otpd around that is free? Not

VLAN assignment on PEAP

2009-02-06 Thread Michael Schwartzkopff
Hi, When I use 802.1x and MD5 (PAP) I can add easily pass VLAN assignment back to the NAS using username Cleartext-Password := password Reply-Message = Hello, misch, Tunnel-Type = VLAN, Tunnel-Medium-Type = IEEE-802, Tunnel-Private-Group-ID = 100 in the users

Re: VLAN assignment on PEAP

2009-02-06 Thread tnt
When I use 802.1x and MD5 (PAP) I can add easily pass VLAN assignment back to the NAS using username Cleartext-Password := password Reply-Message = Hello, misch, Tunnel-Type = VLAN, Tunnel-Medium-Type = IEEE-802, Tunnel-Private-Group-ID = 100 in the users file.

Re: Reject user by Calling-Station-Id

2009-02-06 Thread Alex M
yey thats seam to work, but still getting one problem. So the comp gets bloket regardless of username, but the Reply-message from the bloked table is not being displayed. So I have bloked huntgroup name and I have SQL group: Deny_Trial that sends Reply-Message + Reject for all its members (which

Re: Reject user by Calling-Station-Id

2009-02-06 Thread tnt
yey thats seam to work, but still getting one problem. So the comp gets bloket regardless of username, but the Reply-message from the bloked table is not being displayed. So I have bloked huntgroup name and I have SQL group: Deny_Trial that sends Reply-Message + Reject for all its members (which

Re: Reject user by Calling-Station-Id

2009-02-06 Thread Alex M
ok well i guess i will do manuall replys for each user :( So freeRadius 2.x have taken care of my problem and I actually can use SQL to controll everything? On Fri, Feb 6, 2009 at 8:07 PM, t...@kalik.net wrote: yey thats seam to work, but still getting one problem. So the comp gets bloket

Re: otp daemon for use with freeradius

2009-02-06 Thread Alan DeKok
Alexander Clouter wrote: Would Alan grumble if I was to xlat enable the challenge in rlm_eap_gtc? Then a bit of pam_opie action could be probably called upon...or something could get excited and shovel the information into LDAP. Sure... send a patch. Alan DeKok. - List