Re: problem with eap-tls between FR and XP client

2009-05-07 Thread Alan DeKok
bLn wrote: > I'm trying to connect a Windows XP client (also I'm trying with Vista) > with freeradius with EAP-TLS. I made my set of certificates (from this > site http://www.linuxjournal.com/node/8095/print) Why? If you just start the server in debugging mode after you first install it, it wil

Storing user MAC address after first auth

2009-05-07 Thread Tomas Mecir
Greetings ! I have the following situation here that I'd like to ask for some assistance with, if possible: My client has a RADIUS server installed (running freeRADIUS 2.0.5), and routers working as hotspots that users can connect to. Users can authorize against the RADIUS server using a name/pas

Re: Storing user MAC address after first auth

2009-05-07 Thread Arran Cudbard-Bell
On 7/5/09 10:18, Tomas Mecir wrote: Greetings ! I have the following situation here that I'd like to ask for some assistance with, if possible: My client has a RADIUS server installed (running freeRADIUS 2.0.5), and routers working as hotspots that users can connect to. Users can authorize agai

Re: Storing user MAC address after first auth

2009-05-07 Thread Arran Cudbard-Bell
On 7/5/09 10:18, Tomas Mecir wrote: Greetings ! I have the following situation here that I'd like to ask for some assistance with, if possible: My client has a RADIUS server installed (running freeRADIUS 2.0.5), and routers working as hotspots that users can connect to. Users can authorize agai

Re: Storing user MAC address after first auth

2009-05-07 Thread Arran Cudbard-Bell
You can do it with the policy language. But you'll need to upgrade to the latest version of the server. I've attached an example (so my mail client doesn't wrap it). Make sure you've defined always instances 'noop' and 'updated'. Sorry take that first ! out, and ignore the duplicate reply. L

Re: Storing user MAC address after first auth

2009-05-07 Thread Tomas Mecir
2009/5/7 Arran Cudbard-Bell : > You can do it with the policy language. But you'll need to upgrade to the > latest version of the server. > > I've attached an example (so my mail client doesn't wrap it). Make sure > you've defined always instances 'noop' and 'updated'. Excellent, thank you, works

FreeRadius and logwatch

2009-05-07 Thread Matthieu Lazaro
Hello forum, Just wondering if someone found or had written perl scripts for logwatch so that we can send the logs all tidy?? Asking this in case I missed something or if someone had this in it's drawer! I'm going to post this as well to the logwatch mailing. Best regards, Matt - List info/subs

Re: Storing user MAC address after first auth

2009-05-07 Thread Arran Cudbard-Bell
On 7/5/09 15:33, Tomas Mecir wrote: 2009/5/7 Arran Cudbard-Bell: You can do it with the policy language. But you'll need to upgrade to the latest version of the server. I've attached an example (so my mail client doesn't wrap it). Make sure you've defined always instances 'noop' and 'updated'.

freeradius - Openssl

2009-05-07 Thread new conf
Dear all; I have to remove the link that does between freeradius and openssl.. to do some tests.. Can some one tells me what is the function that I must comment in "rlm_eap_tls.c" to use the module eap_tls without openssl? thank you so much for your help! - List info/subscribe/unsubscribe? See ht

Is PEAP/EAP-MSCHAPv2 with certs a reasonable way to keep untrusted computers off the lan?

2009-05-07 Thread john
Hello all, I want to deny any untrusted computer access to our lan. Lately we've had a lot of students and staff bring laptops into our school and plugging them in to any convenient network port. I want only users with domain credentials using trusted computers on the LAN. My test setup looks like

Re: Is PEAP/EAP-MSCHAPv2 with certs a reasonable way to keep untrusted computers off the lan?

2009-05-07 Thread Ivan Kalik
> I want to deny any untrusted computer access to our lan. Lately we've had > a > lot of students and staff bring laptops into our school and plugging them > in > to any convenient network port. I want only users with domain credentials > using trusted computers on the LAN. > My test setup looks li

Re: Is PEAP/EAP-MSCHAPv2 with certs a reasonable way to keep untrusted computers off the lan?

2009-05-07 Thread john
> > > > > 1) Would PEAP/EAP-MSCHAPv2 with client certs accomplish my goal? > > No. Because your problem has nothing to do with authentication (methods). > Your problem is with authorization. Thanks for your reply. I am not sure I understand your distinction, sorry for my ignorance. I want my use

Graphing - Online users

2009-05-07 Thread AHMED KHIDR
Dear All , I have a question , is there any way to make a graph ( Like mrtg or cacti ) to graph no of online users ?? Regards - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Fair usage package implementation

2009-05-07 Thread Ming-Ching Tiew
I wonder if how such a "package" can be implemented, 1. Unlimited rate normally 2. But when downloaded packets exceed certain defined figure, download rate is trottled. Assumption == 1. Assuming the radius client is sending accounting information to the serv

Another "package" - set expiry at first use

2009-05-07 Thread Ming-Ching Tiew
I have another question about implementing another "package" :- Upon successful authentication, check it is firstuse. If yes, set expiry to say 6 months from now. Any advise how to implement this at the radius server ? My first cut thinking will be check 'radacct' for existence of any past us