rlm_caching with freeradius (2.1.7 or 2.1.8)

2010-02-08 Thread Max Mazur
Hi! I have some strange problems with freeradius (2.1.7 or 2.1.8) and rlm_caching. After module was compliled, it can not be loaded. Error: /etc/raddb/modules/caching[44]: Failed to link to module 'rlm_caching': file not found Error: /etc/raddb/sites-enabled/default[11]: Failed to find module

Re: Too many closing braces / Errors reading

2010-02-08 Thread Teguh Kurniawan
 You edited the configuration files, and broke them.  Go back to the default configuration, and make *small* edits.  Alan DeKok. I was change it to default and give some change. But I've got another error message below : /usr/local/etc/raddb/sites-enabled/default[159]: Failed to find module

Re: Radius + PostgreSQL + MD5 Passwords

2010-02-08 Thread Phillip Smith
On 8 February 2010 17:58, Alan DeKok al...@deployingradius.com wrote: Phillip Smith wrote: I forgot to mention in my first post that this is freeradius-1.1.3-1.5.el5_4 on CentOS 5.4. Do I need 2.1.8 for this MD5 stuff to work?  Yes. Doh! Sorry to bother you with this waste of time then...

Re: Too many closing braces / Errors reading

2010-02-08 Thread Alan DeKok
Teguh Kurniawan wrote: I was change it to default and give some change. But I've got another error message below : /usr/local/etc/raddb/sites-enabled/default[159]: Failed to find module sql. /usr/local/etc/raddb/sites-enabled/default[62]: Errors parsing authorize section. what should I

Help getting rid Info: WARNING: Child is hung for request message

2010-02-08 Thread José Manuel
Hi, I have upgraded recently one of my servers to 2.1.8 (RHEL 5), and am seeing thousands of messages like this in a day. It looks the message was introduced with patch no. 139c45b4c51c945414b53ece36bbeb42edb1b2a7 from November 29. I'm wondering what parameters should I tune to get these

modify realm in authenticate section

2010-02-08 Thread cd
hi is it possible to modify realm like this ? and then use the realm in users file ..see below Auth-Type ldap { group { ldap_admin { reject = 1 ok = return } if (ok) { update reply { Realm:=admin } } ldap_peda { reject = 1 ok = return } if (ok) { update reply { Realm:=pedago } } } } users

Upgrading from 2.0.5 to 2.1.8

2010-02-08 Thread Henry C.
Greetings, I'd like to upgrade an existing setup from version 2.0.5 to 2.1.8. Are there any gotchas/config changes/problems that I need to be aware of? For example, will the existing config files be OK, or will they require tweaks 'n things? Any comments are appreciated. Thanks Henry - List

Re: Upgrading from 2.0.5 to 2.1.8

2010-02-08 Thread Alan DeKok
Henry C. wrote: I'd like to upgrade an existing setup from version 2.0.5 to 2.1.8. Are there any gotchas/config changes/problems that I need to be aware of? For example, will the existing config files be OK, or will they require tweaks 'n things? They should mostly be OK. There are

Re: NAS Client Behind a NAT Router

2010-02-08 Thread Rahul Panwar
If you are using Disconnect request you can map its port also to the server. On Mon, Feb 8, 2010 at 4:32 AM, Fahd Kasri fahd.ka...@weblib.eu wrote: How about for disconnecting users? http://wiki.freeradius.org/index.php/Packet_of_Disconnect 2010/2/6 Rahul Panwar panwar.ra...@gmail.com Map

Radius Proxy Accounting

2010-02-08 Thread Jeremy Brown
Hi Everyone, I'm trying to setup a FreeRadius server to act as a proxy for another DNS server, and this seems straightforward enough from the documentation, however I also want the FreeRadius proxy to send accounting information to another Radius server. I haven't seen any documentation on how

Invitation to connect on LinkedIn

2010-02-08 Thread Eduardo Gui
LinkedIn Eduardo Gui requested to add you as a connection on LinkedIn: -- Glen, I'd like to add you to my professional network on LinkedIn. - Eduardo Accept invitation from Eduardo Gui

Re: Run user defined scripts on client connect and disconnect

2010-02-08 Thread Craig Campbell
__ Information from ESET Smart Security, version of virus signature database 4847 (20100208) __ The message was checked by ESET Smart Security. http://www.eset.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: NAS Client Behind a NAT Router

2010-02-08 Thread Fahd Kasri
No need for it to be mapped to the client? I'm asking because I'm not sure how the mechanism works. Thank you very much for the info. 2010/2/8 Rahul Panwar panwar.ra...@gmail.com If you are using Disconnect request you can map its port also to the server. On Mon, Feb 8, 2010 at 4:32 AM,

Re: Radius + PostgreSQL + MD5 Passwords

2010-02-08 Thread John Dennis
On 02/08/2010 01:58 AM, Alan DeKok wrote: Phillip Smith wrote: I forgot to mention in my first post that this is freeradius-1.1.3-1.5.el5_4 on CentOS 5.4. Do I need 2.1.8 for this MD5 stuff to work? Yes. I'd prefer to be able to use the distro's packages, but if I have to compile it to

Re: NAS Client Behind a NAT Router

2010-02-08 Thread Rahul Panwar
Disconnect request uses port UDP port 3799 or 1700, may be you mapped all the ports of Public IP interface to Radius server. On Mon, Feb 8, 2010 at 6:03 PM, Fahd Kasri fahd.ka...@weblib.eu wrote: No need for it to be mapped to the client? I'm asking because I'm not sure how the mechanism

inner vs outer User-Name

2010-02-08 Thread Kenneth Grady
Is there any way to authorize a user using the inner-tunnel User-Name and not the outer? I get an outer User-Name of anonymous and a reject when searching for authorized users in an ldap group. If they convolute the configuration for the device with an outer User-Name of a person in the ldap

Proxy on Fail.. Or intelligent proxy...Or Utilize multiple acocunt directories

2010-02-08 Thread Larry Ross
Good afternoon all; I am looking at configuring FR to Auth accounts across multiple account directories. Basically I would like FR to take in PAP queries, attempt Auth against krb, then if that comes back as a fail, try a secondary Radius server (Eduroam...) or module (Shibboleth). We are

Re: Radius + PostgreSQL + MD5 Passwords

2010-02-08 Thread Phillip Smith
On 9 February 2010 01:54, John Dennis jden...@redhat.com wrote: On 02/08/2010 01:58 AM, Alan DeKok wrote: Phillip Smith wrote: I forgot to mention in my first post that this is freeradius-1.1.3-1.5.el5_4 on CentOS 5.4. Do I need 2.1.8 for this MD5 stuff to work?   Yes. I'd prefer to be

FreeRadius 2.1.8 works fine in DEBUG mode

2010-02-08 Thread Amal Janardhanan
Hi, I am using freeradius version 2.1.8. All the installation and everything went fine. Freeradius is able to accept and process the request in DEBUG mode. But in in normal mode, I am getting the following error. Mon Feb 8 17:29:20 2010 : Info: Ready to process requests. Mon Feb 8

Re: FreeRadius 2.1.8 works fine in DEBUG mode

2010-02-08 Thread Alan DeKok
Amal Janardhanan wrote: But in in normal mode, I am getting the following error. Mon Feb 8 17:29:20 2010 : Info: Ready to process requests. Mon Feb 8 17:29:59 2010 : Error: WARNING: Unresponsive child for request 0, in module python component authorize Mon Feb 8 17:30:00 2010 : Info:

Re: Proxy on Fail.. Or intelligent proxy...Or Utilize multiple acocunt directories

2010-02-08 Thread Alan DeKok
Larry Ross wrote: I am looking at configuring FR to Auth accounts across multiple account directories. Basically I would like FR to take in PAP queries, attempt Auth against krb, then if that comes back as a fail, try a secondary Radius server (Eduroam…) or module (Shibboleth). That's

Re: Radius Proxy Accounting

2010-02-08 Thread Alan DeKok
Jeremy Brown wrote: I'm trying to setup a FreeRadius server to act as a proxy for another DNS server, and this seems straightforward enough from the documentation, however I also want the FreeRadius proxy to send accounting information to another Radius server. That's not very clear. You

Re: rlm_caching with freeradius (2.1.7 or 2.1.8)

2010-02-08 Thread Alan DeKok
Max Mazur wrote: After module was compliled, it can not be loaded. How did you compile it? Error: /etc/raddb/modules/caching[44]: Failed to link to module 'rlm_caching': file not found Error: /etc/raddb/sites-enabled/default[11]: Failed to find module caching. But as far as I can see

Re: Help getting rid Info: WARNING: Child is hung for request message

2010-02-08 Thread Alan DeKok
José Manuel wrote: I have upgraded recently one of my servers to 2.1.8 (RHEL 5), and am seeing thousands of messages like this in a day. It looks the message was introduced with patch no. 139c45b4c51c945414b53ece36bbeb42edb1b2a7 from November 29. The message was *changed* in that commit:

Re: modify realm in authenticate section

2010-02-08 Thread Alan DeKok
cd wrote: is it possible to modify realm like this ? This is a solution, not a problem. Yes, it's possible to put that in the config files. But i have no idea why you would do that, what it will do. Please explain the problem you're trying to solve. That's usually a lot more

Re: inner vs outer User-Name

2010-02-08 Thread Alan DeKok
Kenneth Grady wrote: Is there any way to authorize a user using the inner-tunnel User-Name and not the outer? Yes. Use the inner-tunnel virtual server. I get an outer User-Name of anonymous and a reject when searching for authorized users in an ldap group. Because you're doing the LDAP