Re: authentification

2010-05-18 Thread David Seira
Hi. With MAC Address Authentication you can use freeradius to authenticate all the network elements (like camcorders, routers, switches...); so that if these elements don't authenticate, not work in the network. Other aplication is to validate users in a captive portal without user interaction.

RE: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Ramm-Ericson, Johannes
Alan DeKok wrote: > Arran Cudbard-Bell wrote: >> The problem with volunteer 're-factoring' work, is that although people mean >> well when they offer their >> assistance, it doesn't usually work out... They'll often spend a couple of >> weeks working on the task, >> get bored, figure they'll take

Re: Segmentation fault on 2.1.7 during HUP

2010-05-18 Thread Alan DeKok
coja wrote: > Hello all! > We use 2.1.7 version of freeradius+mysql 5 running on RHEL4u8. > We tried to apply PIN authentication based on file users which located in > /etc/raddb. > I inserted to crontab reload (HUP) command which runs every 30 minutes. In 2.1.8 you can use "radmin" to reload *

Re: Recommended books on freeradius

2010-05-18 Thread Alan DeKok
Mark wrote: > Is there an expected release date for this book alan? Not yet. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: windows client authentication error

2010-05-18 Thread Alan DeKok
shirkavand wrote: > I have into radcheck table the next user created: > > 1 | sqltest | Cleartext-Password | := | testpwd > > Dont know what i get the "No Cleartext-Password configured" error too. Does PAP work? Did you configure the "sql" module? Is the PEAP request for user "sqltest"?

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Fajar A. Nugraha
On Wed, May 19, 2010 at 3:12 AM, Alan DeKok wrote: >  Personally, I'd be happy if this effort results in the existing docs > being converted to RST.  It's easy to read as text, and looks good as HTML. The enthusiasm seems big enough. So how would this work? Get some people to submit an example do

Re: Recommended books on freeradius

2010-05-18 Thread Mark
Is there an expected release date for this book alan? Mark On 18-May-2010, at 1:24 PM, Alan DeKok wrote: > Mark wrote: >> Hi all, >> >> Trying to get my hands on a freeradius book for reading. Anyone might have >> any recommendations for this? > > The only RADIUS book is the O'Reilly one.

EAP mschapv2 Failed to authenticate the user

2010-05-18 Thread Pedro Alves
Hello Failed to authenticate users in Active Directory with this message "rlm_eap_mschapv2: Invalid response type 4" log with error: [eap] Request found, released from the list [eap] EAP/mschapv2 [eap] processing type mschapv2 rlm_eap_mschapv2: Invalid response type 4 [eap] Handler fai

Re: windows client authentication error

2010-05-18 Thread shirkavand
I have into radcheck table the next user created: 1 | sqltest | Cleartext-Password | := | testpwd Dont know what i get the "No Cleartext-Password configured" error too. Cheers - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

windows client authentication error

2010-05-18 Thread shirkavand
Hi there, i have installed freeradius 2.1.8 on ubuntu 10.04. radtest using mysql backend works fine. But when a windows supplicant tryes to connect the server always gets rejected. Freeradius debug console shows: ... ... [eap] Request found, released from the list [eap] EAP/mschapv2 [eap] process

Re: Freeradius 2.1.8+Windows AD+MS-CHAP with ntlm_auth

2010-05-18 Thread Alan DeKok
Cesar Ortega wrote: > I've been working on Freeradius with XP supplicants for a while but so > far I could't make it. Authentication against Active Directory works > like a charm > (http://deployingradius.com/documents/configuration/active_directory.html). That's good to hear. > I want to authe

RE: authentification

2010-05-18 Thread dorra aa
is there somebody want to tell what's the utility of it? From: dj_dido2...@hotmail.com To: freeradius-users@lists.freeradius.org Subject: authentification Date: Tue, 18 May 2010 19:40:28 + hi freeradius,i want to ask how to use MAC Address Authentication in my freeradius.besides, i a

Freeradius 2.1.8+Windows AD+MS-CHAP with ntlm_auth

2010-05-18 Thread Cesar Ortega
Hi fellas, I've been working on Freeradius with XP supplicants for a while but so far I could't make it. Authentication against Active Directory works like a charm (http://deployingradius.com/documents/configuration/active_directory.html). I want to authenticate several users against AD kee

Re: COA have I understood it correctly?

2010-05-18 Thread Alan DeKok
Simon Earthrowl (Eseye) wrote: > Hi all, > Having gone though many of the postings concerning COA, I (hope) I have > a better understanding - so please be patient with me. > > What I wanted: to send a Packet of Disconnect (PoD) to my Radius server, > which in turn would send (proxy) a PoD to the a

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Alan DeKok
Arran Cudbard-Bell wrote: > The problem with volunteer 're-factoring' work, is that although people mean > well when they offer their assistance, it doesn't usually work out... They'll > often spend a couple of weeks working on the task, get bored, figure they'll > take a break and come back to

Re: EAP mschapv2 Failed to authenticate the user

2010-05-18 Thread Alan DeKok
Pedro Alves wrote: > Failed to authenticate users in Active Directory with this message > “rlm_eap_mschapv2: Invalid response type 4” > > Do you know what is a cause of it? It means authentication has failed. > Radiusd –X log: With *no* packets. Alan DeKok. - List info/subscribe/unsub

authentification

2010-05-18 Thread dorra aa
hi freeradius,i want to ask how to use MAC Address Authentication in my freeradius.besides, i add an address mac with the daloradius. how can i test the succes of thatthnak you _ Hotmail: Po

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Arran Cudbard-Bell
The problem with volunteer 're-factoring' work, is that although people mean well when they offer their assistance, it doesn't usually work out... They'll often spend a couple of weeks working on the task, get bored, figure they'll take a break and come back to it later, and it never gets comple

COA have I understood it correctly?

2010-05-18 Thread Simon Earthrowl (Eseye)
Hi all, Having gone though many of the postings concerning COA, I (hope) I have a better understanding - so please be patient with me. What I wanted: to send a Packet of Disconnect (PoD) to my Radius server, which in turn would send (proxy) a PoD to the appropriate NAS. What I think I unders

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Nyamul Hassan
I can both write chapters, and also edit the work of other contributors who are not too well versed in English. I would still request Alan to reconsider the wiki approach. Perhaps, you can dictate the structure of the wiki, and we can all contribute to fill up the contents. But, whatever the way

Segmentation fault on 2.1.7 during HUP

2010-05-18 Thread coja
Hello all! We use 2.1.7 version of freeradius+mysql 5 running on RHEL4u8. We tried to apply PIN authentication based on file users which located in /etc/raddb. I inserted to crontab reload (HUP) command which runs every 30 minutes. After the period of time we found that radiusd crashed with Segme

Re: ISG DHCP relay

2010-05-18 Thread Igor Smitran
Nice. Alexander Clouter wrote: Igor Smitran wrote: I really don't understand why noone wants to help. After all, i am using freeradius together with cisco. Hey there, I'm trying to ping 217.23.192.1 from my laptop at work, but it seems I need 802.1X configured to connect to my local

Re: ISG DHCP relay

2010-05-18 Thread Alan Buxey
Hi, not quite in the same category :-P perhaps more people need to read 'how to ask questions...' ? http://catb.org/~esr/faqs/smart-questions.html very good resource! alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Michael Schwartzkopff
Am Dienstag, 18. Mai 2010 09:16:06 schrieb Alan DeKok: > In the interest of making the project better, we're looking for an > editor for the documentation. The existing documentation is an "ad hoc" > collection of files thrown together over a decade of effort, and written > by many different peo

Re: ISG DHCP relay

2010-05-18 Thread Alan Buxey
Hi, > And it works. At least for CPE devices. But, CM and MTA devices need tftp > server name and tftp file name. My problem is, and i have searched for more > than 15 days, how or even if possible, to use freeradius to send BOOTP > parameters to cisco. Since i wasn't able to find anything abou

Re: ISG DHCP relay

2010-05-18 Thread Alexander Clouter
Igor Smitran wrote: > > I really don't understand why noone wants to help. After all, i am using > freeradius together with cisco. > Hey there, I'm trying to ping 217.23.192.1 from my laptop at work, but it seems I need 802.1X configured to connect to my local network. As I'm trying to send tra

Re: ISG DHCP relay

2010-05-18 Thread Igor Smitran
Yes, it is definitley my bad english. I am not using freeradius as DHCP, i am using freeradius as mac address checker. That part is working ok. I am using freeradius for long time and it is a great product. But, cisco ISG is new to me. I have setup cisco ISG as a DHCP server. when cisco receives

RE: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Jack Martin
I would be willing to help as well-if its a collaboration. I can't code and this would be a way to give back. The money could be used someplace it's really needed. -Original Message- From: Ramm-Ericson, Johannes Sent: Tuesday, May 18, 2010 3:14 AM To: 'freeradius-users@lists.freeradius

Re: ISG DHCP relay

2010-05-18 Thread Alan Buxey
Hi, > I really don't understand why noone wants to help. After all, i am using > freeradius together with cisco. I just asked if anyone has any experience in > ISG+FreeRadius because i am trying to find a solution for my problem for more > than 15 days. Does it really matter what kind of NAS i

Re: ISG DHCP relay

2010-05-18 Thread Alan DeKok
Igor Smitran wrote: > I really don't understand why noone wants to help. You *think* you're asking how to configure FreeRADIUS to send something back to the NAS. We're telling you we don't know what that "something" is. Only the NAS manufacturer knows. Go ask Cisco what the NAS needs, and the

Re: ISG DHCP relay

2010-05-18 Thread Igor Smitran
Ok, I really don't understand why noone wants to help. After all, i am using freeradius together with cisco. I just asked if anyone has any experience in ISG+FreeRadius because i am trying to find a solution for my problem for more than 15 days. Does it really matter what kind of NAS i am usin

Re: ISG DHCP relay

2010-05-18 Thread Alan Buxey
Hi, > I am sking here because i wasn't able to find any answears on cisco > site. Maybe someone here has enough experience to point me to right > direction. I'm not sure what lists you are on...but you seem to be confused - this is the FreeRADIUS mialing list, not the Cisco support mailing list

RE: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Ramm-Ericson, Johannes
Hi, I'd definitely be willing to help out with this task. Particularly if it could be turned into a collaborative effort. Money is nice, however my primary motive would actually be to contribute to an outstanding piece of software that has been essential in my job. So, should I become involved

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Nyamul Hassan
I tried to "signup" to be able to edit the Wiki, but it seems that signup is disabled! Regards HASSAN On Tue, May 18, 2010 at 14:02, Ana Gallardo wrote: > I would like to do this job, but my english is poor, so I can't do it :( > > 2010/5/18 Alan DeKok > >> Nyamul Hassan wrote: >> > Not meani

Re: accouting

2010-05-18 Thread Alan Buxey
Hi, > I have installed the following two rpms: > freeradius-mysql-2.1.3-1.fc9.i386 and > freeradius-postgresql-2.1.3-1.fc9.i386 > on my Fedora machine. However, when I tried to configure sql server by using > "mysqladmin ...", system says "command not found". > > Do I need to install anythi

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Ana Gallardo
I would like to do this job, but my english is poor, so I can't do it :( 2010/5/18 Alan DeKok > Nyamul Hassan wrote: > > Not meaning any disrespect to the "paid" offer, you could also > > reconsider to put up the current documentation in a "Wiki" style > > webpage, and from there everyone can wo

Get reply items on python module

2010-05-18 Thread Miquel Canes
Hello , I'm creating a python script to handle with some policies. After getting some values using the ldap module, I need to read the reply pair-value items on the python module. How can I read the reply items using the python module? Using the perl module I can do this using the RAD_REPLY hash,

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Alan DeKok
Nyamul Hassan wrote: > Not meaning any disrespect to the "paid" offer, you could also > reconsider to put up the current documentation in a "Wiki" style > webpage, and from there everyone can work on the text that they think > needs reworking. We already have a Wiki. Few people edit it. We alr

RE: FW: EAP_TLS

2010-05-18 Thread Harshil Anil Kumar Shah
Thanks buddy :) From: freeradius-users-bounces+harshil_shah=infosys@lists.freeradius.org [mailto:freeradius-users-bounces+harshil_shah=infosys@lists.freeradius.org] On Behalf Of sunhualing Sent: Tuesday, May 18, 2010 1:09 PM To: FreeRadius users mailing list Subject: Re: FW: EAP_TLS Hi

Re: FW: EAP_TLS

2010-05-18 Thread sunhualing
Hi : tls.c provide the basic tls function,while eap_tls.c provides the whole authenticate process of the eap-tls. You will find the standard interface in eap_tls.c. More detail, you should read the standard. Best Regards sunhualing On Mon, May 17, 2010 at 4:18 PM, Harshil Anil Ku

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Nyamul Hassan
Not meaning any disrespect to the "paid" offer, you could also reconsider to put up the current documentation in a "Wiki" style webpage, and from there everyone can work on the text that they think needs reworking. Regards HASSAN On Tue, May 18, 2010 at 13:16, Alan DeKok wrote: > In the inte

Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Alan DeKok
In the interest of making the project better, we're looking for an editor for the documentation. The existing documentation is an "ad hoc" collection of files thrown together over a decade of effort, and written by many different people. We'd like to organize the documentation ("doc/" directo

Re: ISG DHCP relay

2010-05-18 Thread Igor Smitran
Alan DeKok wrote: What does the ISG documentation say? Ask the vendor how their product works... I am sking here because i wasn't able to find any answears on cisco site. Maybe someone here has enough experience to point me to right direction. Thank you all - List info/subscrib