VS: Chap auhtentication against LDAP

2009-04-05 Thread Ville Leinonen
Hi, So i cannot do this about using freeradius, but i can make it using IAS (see link)? http://h40060.www4.hp.com/procurve/includes/application-notes/index.php?cc=uklc=encontent=ans2-en Br, Ville -Alkuperäinen viesti- Lähettäjä:

Re: VS: Chap auhtentication against LDAP

2009-04-05 Thread Alan DeKok
Ville Leinonen wrote: So i cannot do this about using freeradius, but i can make it using IAS (see link)? No. You seemed to have misunderstood my response. Let me say it a different way: LDAP servers cannot do CHAP authentication. Why? Because LDAP servers are *DATABASES*. LDAP

VS: VS: Chap auhtentication against LDAP

2009-04-05 Thread Ville Leinonen
Hi, Thank you for this reply. Well then i do some scripting and pull userinfo inside ldap and export it to my radsrv. Br, Ville -Alkuperäinen viesti- Lähettäjä: freeradius-users-bounces+ville.leinonen=solodel@lists.freeradius.org puolesta: Alan DeKok Lähetetty: su 5.4.2009 16:16

Re: need help advice getting started with freeradius

2009-04-05 Thread Alexander Clouter
t...@kalik.net wrote: In my scenario I would like to use PEAP if possible but not require the user client to have a certificate, just the radius-server (which is why i believe the TTLS solution will be in-efficient here as i would have to deal with handy out client certificates to hundreds of

Re: need help advice getting started with freeradius

2009-04-05 Thread daniel knox
Okie, I've spent some of this weekend looking into this and some of the files included in freeradius (havnt had a chance to play around testing it though). Am I right in guessing once i've configured the ldap group membership filter, i include the unlang statement: if (Ldap-Group == whatever) {

Re: need help advice getting started with freeradius

2009-04-05 Thread daniel knox
Lol just actually read some stuff on WPA and learnt abit more about EAP. I realise now that TTLS does not require client certificates like I previously thought only the server. Apologies for this miss understanding. Although I do realise now that SecureW2 would be required to give my Windows users

Re: need help advice getting started with freeradius

2009-04-05 Thread A . L . M . Buxey
Hi, Lol just actually read some stuff on WPA and learnt abit more about EAP. I realise now that TTLS does not require client certificates like I previously thought only the server. Apologies for this miss understanding. Although I do realise now that SecureW2 would be required to give my

Re: need help advice getting started with freeradius

2009-04-05 Thread Alexander Clouter
daniel knox m...@dknox.co.uk wrote: Lol just actually read some stuff on WPA and learnt abit more about EAP. I realise now that TTLS does not require client certificates like I previously thought only the server. Apologies for this miss understanding. Although I do realise now that SecureW2

FreeRadius 1.x Or 2.x

2009-04-05 Thread AHMED KHIDR
Dear All, I use freeradius 1.1.7 and I am thinking of migrate to new ver. 2.x so i want to ask which ver is better ? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

EAP Outer and Inner Tunnel Behaviour Discussion

2009-04-05 Thread Jacky Chan
Hi all, We are going to proxy EAP to another site with all freeradius (we are using 2.1.4, another site using 1.x), but there are some interest problems occurred, details are as follows: Our site only accept non �...@domain” format for inner EAP tunnel authentication since user DB only store