Problem with EAP TLS authentication in Freeradius

2009-12-04 Thread senthil kumar
Hi, Iam using Freeeadius 2.1.0. The setup is working fine with EAP-TTLS, PEAP method.But for EAP TLS, it gives the below error.. Please let me know how to solve.. [eap] Handler failed in EAP/tls [eap] Failed in EAP select ++[eap] returns invalid Failed to authenticate the user. Regards S

Re: Which RPM Should I use

2009-12-04 Thread John Dennis
On 12/04/2009 03:35 PM, Alex Bahoor wrote: I would need LDAP and Mysql. Should I install two RPMSs? freeradius-ldap-2.1.7-2.fc12.i686.rpm freeradius-mysql-2.1.7-2.fc12.i686.rpm What is i686 means? I have a dell laptop IBM clone. Start by reading this: http://wiki.freeradius.org/Red_Hat_FAQ On

RE: Which RPM Should I use

2009-12-04 Thread Alex Bahoor
l two RPMSs? > freeradius-ldap-2.1.7-2.fc12.i686.rpm > freeradius-mysql-2.1.7-2.fc12.i686.rpm > > What is i686 means? I have a dell laptop IBM clone. > thx, > > Alex > > > __ Information from ESET NOD32 Antivirus, version of virus > signature >

RE: Which RPM Should I use

2009-12-04 Thread freeradius
__ Information from ESET NOD32 Antivirus, version of virus > signature > database 4661 (20091204) __ > > The message was checked by ESET NOD32 Antivirus. > > http://www.eset.com > > > - > List info/subscribe/unsubscribe? See > http://www.freeradius

Re: Problem with EAP-TLS, please give me a hint

2009-12-04 Thread tnt
> Well after i read your post i tried to sign the client certificates with > the > ca. I make some changes in the makefile but it think I made something > wrong > because it doesn't work: > > > > old: > > client.csr client.key: client.cnf > openssl req -new -out client.csr -keyout client.key

RE: Which RPM Should I use

2009-12-04 Thread Gary Gatten
us-ldap-2.1.7-2.fc12.i686.rpm > freeradius-mysql-2.1.7-2.fc12.i686.rpm > > What is i686 means? I have a dell laptop IBM clone. > thx, > > Alex > > > __ Information from ESET NOD32 Antivirus, version of virus > signature > database 4661 (20091204) _

RE: Which RPM Should I use

2009-12-04 Thread Tim Sylvester
> > > Hi, > > I would need LDAP and Mysql. Should I install two RPMSs? > freeradius-ldap-2.1.7-2.fc12.i686.rpm > freeradius-mysql-2.1.7-2.fc12.i686.rpm > > What is i686 means? I have a dell laptop IBM clone. > thx, > > Alex > > >

Which RPM Should I use

2009-12-04 Thread Alex Bahoor
(20091204) __ The message was checked by ESET NOD32 Antivirus. http://www.eset.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

AW: Pre-release of Version 2.1.8

2009-12-04 Thread Wegener, Norbert
Building an rpm on Suse10.3 fails with: Processing files: freeradius-server-dialupadmin-2.1.8-0 Processing files: freeradius-server-devel-2.1.8-0 Processing files: freeradius-server-debuginfo-2.1.8-0 Checking for unpackaged file(s): /usr/lib/rpm/check-files /var/tmp/freeradius-server-2.1.8-build

Re: How do I stop RADIUS running in debug mode (radiusd -X)?

2009-12-04 Thread agalnx77
Cool. Thank you very much. On 12/4/09 1:52 PM, "t...@kalik.net" wrote: >> I have tried 'radiusd stop' but the process remains up and running. > > While it's running in the foreground: Ctrl+C > > If you close the session without exiting the debug - killall as suggested. > > Ivan Kalik > > - >

Re: How do I stop RADIUS running in debug mode (radiusd -X)?

2009-12-04 Thread tnt
> I have tried 'radiusd stop' but the process remains up and running. While it's running in the foreground: Ctrl+C If you close the session without exiting the debug - killall as suggested. Ivan Kalik - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-TTLS auth

2009-12-04 Thread tnt
> > > > > > > Hi again: > > I have just tried with both CN that I could found at my 'client > certificate' > > > href="mailto:subject=/C=FR/ST=Isere/O=ESRF/CN=swatzy01.esrf.fr/emailaddress=u...@example.com";>subject=/C=FR/ST=Isere/O=ESRF/CN=swatzy01.esrf.fr/emailaddress=u...@example.co

Re: MySQL user reject by date

2009-12-04 Thread tnt
> can i reject (and how ?) a demand by date (it's too late or too early to > connect) Current-Time > or < then whatever. > with > Mysql users (in raddcheck table) and of course where can i store these two > fields (date_begin and date_end) in mysql radius database (new table ?, > new field ?) A

Re: AD, Groups, and LDAP (was Re: separating Users?)

2009-12-04 Thread freeradius
At 11:00 AM 12/4/2009, Alan DeKok wrote: freerad...@corwyn.net wrote: >> Update max_requests to # users * 256 >> That isn't necessary. It should be no more than "max request/s * >> max_request_time". > > Well the docs say: > # max_requests: The maximum number of requests which the server keep

Re: Pre-release of Version 2.1.8

2009-12-04 Thread Alan DeKok
Bjørn Mork wrote: > No problem, I thought. I can just go and checkout the "v2.1.x" branch. > But there seems to be no such branch: It's on github. If there are cries of panic over 2.1.8, we'll make it an official branch on git.freeradius.org. Alan DeKok. - List info/subscribe/unsubscribe? S

Re: Pre-release of Version 2.1.8

2009-12-04 Thread Alan DeKok
Bjørn Mork wrote: > Alan DeKok writes: > >> I've put a pre-release of version 2.1.8 on the web site: >> >> http://git.freeradius.org/pre/ > > Hmm, they were both a bit small. I see 14 and 20 bytes. Something > probably went wrong with the packacking script? Yup. Let me fix that in a bit..

Re: How do I stop RADIUS running in debug mode (radiusd -X)?

2009-12-04 Thread agalnx77
Got it. Thank you much for the prompt response and clarification. AG On 12/4/09 12:21 PM, "John Dennis" wrote: > On 12/04/2009 11:30 AM, agalnx77 wrote: >> I have tried 'radiusd stop' but the process remains up and running. > > That won't do it, perhaps you've confused that with "service radiu

Re: How do I stop RADIUS running in debug mode (radiusd -X)?

2009-12-04 Thread John Dennis
On 12/04/2009 11:30 AM, agalnx77 wrote: I have tried 'radiusd stop' but the process remains up and running. That won't do it, perhaps you've confused that with "service radiusd stop", which by the way only works when you've started the server as a service, which isn't the case if you've run i

Re: Pre-release of Version 2.1.8

2009-12-04 Thread Bjørn Mork
Bjørn Mork writes: > Alan DeKok writes: > >> I've put a pre-release of version 2.1.8 on the web site: >> >> http://git.freeradius.org/pre/ > > Hmm, they were both a bit small. I see 14 and 20 bytes. Something > probably went wrong with the packacking script? No problem, I thought. I can just

Re: Pre-release of Version 2.1.8

2009-12-04 Thread Bjørn Mork
Alan DeKok writes: > I've put a pre-release of version 2.1.8 on the web site: > > http://git.freeradius.org/pre/ Hmm, they were both a bit small. I see 14 and 20 bytes. Something probably went wrong with the packacking script? Bjørn - List info/subscribe/unsubscribe? See http://www.freerad

MySQL user reject by date

2009-12-04 Thread Cristophe DECOR
Hi, can i reject (and how ?) a demand by date (it's too late or too early to connect) with Mysql users (in raddcheck table) and of course where can i store these two fields (date_begin and date_end) in mysql radius database (new table ?, new field ?) thanks -- Cristophe DECOR Montpellier Supa

How do I stop RADIUS running in debug mode (radiusd -X)?

2009-12-04 Thread agalnx77
I have tried 'radiusd stop' but the process remains up and running. agalnx-srv-01:~ # ps -a PID TTY TIME CMD 22599 pts/100:00:00 su 22603 pts/100:00:00 bash 22812 pts/200:00:00 su 22814 pts/200:00:00 bash 23218 pts/200:00:00 radiusd 23400 pts/300:00:00 su 23402 p

Re: AD, Groups, and LDAP (was Re: separating Users?)

2009-12-04 Thread Alan DeKok
freerad...@corwyn.net wrote: >> Update max_requests to # users * 256 >> That isn't necessary. It should be no more than "max request/s * >> max_request_time". > > Well the docs say: > # max_requests: The maximum number of requests which the server keeps > # track of. This should be 256 multi

Re: AD, Groups, and LDAP (was Re: separating Users?)

2009-12-04 Thread freeradius
At 04:33 AM 12/4/2009, Alan DeKok wrote: freerad...@corwyn.net wrote: > Note that the configuring of SAMBA, kerberos, and adding to the domain > should already be done as part of the default Linux install, see > h:\is\operating system\Linux\Guide_linux.doc This file is... ? Heh, part of our

Pre-release of Version 2.1.8

2009-12-04 Thread Alan DeKok
I've put a pre-release of version 2.1.8 on the web site: http://git.freeradius.org/pre/ Please do some sanity checks, and see if it works for you. This version is from the new "v2.1.x" branch, which is Version 2.1.7, plus *only* bug fixes. The "stable" branch is now planned to become vers

Re: EAP-TTLS auth

2009-12-04 Thread Fernando Calvelo Vazquez
Hi again: I have just tried with both CN that I could found at my 'client certificate' subject=/C=FR/ST=Isere/O=ESRF/CN=swatzy01.esrf.fr/emailaddress=u...@example.com issuer=/C=FR/ST=Isere/L=Grenoble/O=ESRF/emailaddress=ad...@example.com/CN=radiusserv.esrf.fr So I have tested with: - Server

Re: query about users file and Radius restarting

2009-12-04 Thread Alan DeKok
Yagnesh Dave wrote: > I want to know that do we need to restart the radius server once we add > a new user in the users file or it is automatically taken in affect. > Because at the moment I re-start the freeRadius every time I add a new > user. Send a HUP signal to the server. Alan DeKok. -

Re: Freeradius-Users Digest, Vol 56, Issue 34

2009-12-04 Thread Alan DeKok
Nadir M. Aliyev wrote: > Hello all, > > I installed freeradius-1.1.7_4 with only pgsql support. > > When I start radius on normal mode or on debug mode this errors appears: > /libexec/ld-elf.so.1: /usr/local/lib/rlm_sqlippool-1.1.7.so: Undefined > symbol "sql_get_socket" Upgrade to 2.1.7. A

Re: Logins against AD failing in *most* cases. Can see why, but don't*understand* why.

2009-12-04 Thread Alan Buxey
Hi, > 1) We needed to upgrade to a newer version of Samba to be able to talk > to Windows Server 2008 R2 (R2 made some significant changes over > straight 2008, according to our Windows admins, so R1 or straight 2008 interesting - do you have more details about this - as we have still quite an ol

RE: Logins against AD failing in *most* cases. Can see why, but don't*understand* why.

2009-12-04 Thread Meyers, Dan
> Given *my* background: I tend to blame everything *other* than > FreeRADIUS. If there's a bug, it gets fixed pretty quickly. That's > more than you can say for Microsoft. Finally got it sorted, and it was indeed nothing to do with FreeRADIUS but was a combination of several factors all relat

RE: Freeradius-Users Digest, Vol 56, Issue 34

2009-12-04 Thread Nadir M. Aliyev
Hello all, I installed freeradius-1.1.7_4 with only pgsql support. When I start radius on normal mode or on debug mode this errors appears: /libexec/ld-elf.so.1: /usr/local/lib/rlm_sqlippool-1.1.7.so: Undefined symbol "sql_get_socket" - List info/subscribe/unsubscribe? See http://www.freeradius.

query about users file and Radius restarting

2009-12-04 Thread Yagnesh Dave
Hi All, I want to know that do we need to restart the radius server once we add a new user in the users file or it is automatically taken in affect. Because at the moment I re-start the freeRadius every time I add a new user. Regards, Dave.- List info/subscribe/unsubscribe? See http://www.free

Re: Missing dependency operator when start make

2009-12-04 Thread Andrew Rikhlivsky
Alan DeKok wrote: Andrew Rikhlivsky wrote: After downloading latest freeradius v2.1.7 sources, and configuring (./configure --without-openssl --without-snmp) i start make and see next messages: # make Use "gmake". FreeRADIUS requires GNU Make. Alan DeKok. - List info/subscribe/u

Re: AD, Groups, and LDAP (was Re: separating Users?)

2009-12-04 Thread Alan DeKok
freerad...@corwyn.net wrote: > Having just followed all of those instructions to build out my > production systems, I have a few tweaks to fix all those little things > that drive one insane when following someone's instructions because they > never tested them. Thanks. Here's a short review.

debug lofile

2009-12-04 Thread Yagnesh Dave
Hello, I wanted know that is there any way by which we can direct the debug logs of the radius server to a file created with date extension on daily basis...similar to the detail-%Y%m%d. Regards, Dave. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

inner/outer-session users in sql

2009-12-04 Thread Maciej Łukasz Wojszkun
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, i'm using FR 2.0.4. In my configuration (PEAP) connected users are logged into postgres database. And there is logged username from outer tunnel; i want to logging username from inner tunnel. How i can do it? - -- Regards Maciej Łukasz Wojszkun t

RE: Active directory ldap groups

2009-12-04 Thread Leighton Man
> > http://wiki.freeradius.org/Rlm_ldap#Group_Support > One hour to formulate the problem, One line to fix it!! MANY thanks Ivan. Regards, Leighton --- This transmission is confidential and may be legally privileged. If you receive it in error, please notify us immediately by e-mail and re

Re: AD, Groups, and LDAP (was Re: separating Users?)

2009-12-04 Thread Alan DeKok
freerad...@corwyn.net wrote: > no it does not. FYI I believe 1813 is actually TCP (empirically working > through my firewalls that way). 1813 is RADIUS accounting. It's currently over UDP. RADIUS over TCP is coming, too. > 1814 only necessary if you're using proxy I think. 1814, *and* a