Re: Freeradius kerberos

2010-07-07 Thread Alan DeKok
Thiago Gonzaga B. Galvão wrote: > The user will authenticates onto a freeradius server, it will refer to > external source kerberos, and kerberos will be configured with openldap > backend (the openldap server that i have). > > Is it possible??? Instead of freeradius directly authenticates to ldap

Re: rlm_exec

2010-07-07 Thread Alan DeKok
Hubert Kupper wrote: > I used the RPMs from Suse, but the same error still occurs. OK... find out where the libraries are, and ensure that the dynamic linker can find them. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radius dont work

2010-07-07 Thread Alan DeKok
Aziz YÜCELEN wrote: > I am setup freeradius again and not edit default configuration, I am > trying configure inner-tunnel but result didn't change. How to configure > inner-tunnel file for ttls thanks. You don't configure it. The default installation of the server configures it. The debug l

Re: ntlm_auth fails for none domain

2010-07-07 Thread John
  Sorry. I did not set the 'xjtu' in the first time. But I set 'xjtu' after that. Pls see the second mail I wrote.   I put ntlm_auth line to file 'mschap'. The attached file is my 'mschap' and the related debug info. --- 10年7月5日,周一, Alan Buxey 写道: 发件人: Alan Buxey 主题: Re: ntlm_auth fails for

RE: radius dont work

2010-07-07 Thread Aziz YÜCELEN
> > server inner-tunnel { > > No authenticate method (Auth-Type) configuration found for the request: > > Rejecting the user > > Failed to authenticate the user. > > } # server inner-tunnel > > You have edited the default configuration and broken it. Don't do that. > > You need the "inner-t

Re: rlm_exec

2010-07-07 Thread Hubert Kupper
Am 07.07.2010 07:54, schrieb Alan DeKok: Hubert Kupper wrote: I have installed freeradius 2.1.9-0 on a SLES 11 64 bit machine. From an RPM, or from source? When I try to start with freeradius -X then I get the following error: radiusd: Instantiating modules instantiate { /et

Freeradius kerberos

2010-07-07 Thread Thiago Gonzaga B . Galvão
Hi guys, I have the following situation on my network... I have an Openldap server working as well, and it stores all my users informations... I configure a Kerberos server to use this openldap as a backend... We would like to implement an Single Sign On to our "web intranet" using kerberos t

Re: DHCP server will not send DHCP-Boot-Filename

2010-07-07 Thread Mark Price
On Wed, Jul 7, 2010 at 12:00 PM, Alan DeKok wrote: >  Hmm.. I don't see the DHCP-Boot-Filename as an option later in the > DHCP packet.  Could you point it out more specifically? Let me try to clarify: Currently, DHCP-Boot-Filename value is not being sent and DHCP-Boot-File-Name is being sent.

Re: DHCP server will not send DHCP-Boot-Filename

2010-07-07 Thread Alan DeKok
Mark Price wrote: > My understanding is that the DHCP server should feed > DHCP-Boot-Filename in the ACK response to client and this is the way > I've done the configuration. Note that this should show in the dhcp > header response sent to client. OK. > DHCP-Boot-File-Name parameter does work,

Re: User-Name issue and mac based authentication

2010-07-07 Thread Alan DeKok
Fabien COMBERNOUS wrote: > I'm using Free radius for Mac Address authentication. > > When a use tcpdump on the radius server, the Radius Request packet > contains all the mac Address. But in the "radiusd -X" output, the > User-Name is truncated. The last digit is erased and so the device is > reje

User-Name issue and mac based authentication

2010-07-07 Thread Fabien COMBERNOUS
Hi there, I'm using Free radius for Mac Address authentication. When a use tcpdump on the radius server, the Radius Request packet contains all the mac Address. But in the "radiusd -X" output, the User-Name is truncated. The last digit is erased and so the device is rejected. Any help is ap

DHCP server will not send DHCP-Boot-Filename

2010-07-07 Thread Mark Price
Tested with 2.1.9 and latest 2.1.x from git Compile options: --with-dhcp --prefix=/usr/local/freeradius dictionary.dhcp enabled in dictionary configuration below client is gPXE Etherboot My understanding is that the DHCP server should feed DHCP-Boot-Filename in the ACK response to client and thi

Re: freeradius 2.1.9 segfault

2010-07-07 Thread Alan DeKok
Fred MAISON wrote: > Unfortunately, I have not been able to find the date of the issue ... See doc/bugs > Does this seems to you a known issue ? Seeing as the problem has no information other than "it crashes"... I have no idea. > If not, what may I do to further investigate ? See doc/b

Re: RadSQLRelay

2010-07-07 Thread Alan DeKok
Marius Pesé wrote: > We are still struggling to get our FreeRadius2 servers running on > CentOS5.5 to relay accounting packages to one another. ? raddb/sites-available/copy-acct-to-home-server > However if we start radsqlrelay Uh... why? > (radsqlrelay -d mysql -b freeradius -h > 196.25.xxx

RadSQLRelay

2010-07-07 Thread Marius Pesé
Hi everyone, We are still struggling to get our FreeRadius2 servers running on CentOS5.5 to relay accounting packages to one another. Right now I have one FR2 server with a local mySQL database and one additional machine just running mysqld. The FR2 machine writes it's own database and the

freeradius 2.1.9 segfault

2010-07-07 Thread Fred MAISON
Hi all, I found a segfault on radiusd in dmesg. This production server has been installed since 2010/06/03 with no problems. CentOS release 5.5 (Final) radiusd: FreeRADIUS Version 2.1.9, for host x86_64-redhat-linux-gnu, built on Jun 2 2010 at 22:11:51 radiusd[5198]: segfault at 003

RE: Restricting certain users access to certain NAS devices

2010-07-07 Thread Whitmarsh Mark (Leeds Teaching Hospitals NHS Trust)
OK Alan. I'll look into alternative strategies until a fix is in place. Thanks for your help in getting me this far. Mark Whitmarsh. From: freeradius-users-bounces+mark.whitmarsh=nhs@lists.freeradius.org [freeradius-users-bounces+mark.whitmarsh=nhs

Re: radius dont work

2010-07-07 Thread Alan DeKok
Aziz YÜCELEN wrote: > Hi > > Sorry for my carelessness. Debug output is here and I am using eap TTLS > but login not success.Please help me thanks. ... > server inner-tunnel { > No authenticate method (Auth-Type) configuration found for the request: > Rejecting the user > Failed to authenticate t

Re: "Exiting normally" on FreeBSD -- Synopsis?

2010-07-07 Thread Alan DeKok
Brian A. Seklecki wrote: > So it turns out, since April, there have been two distinctive types of > crashes. OK... > The unexplained SIGHUP, which we eventually tracked down to faulty > logging configurations (now using SYSLOG instead of file logging), and > an ongoing Sig11. Ouch. > #0 0x

Re: Restricting certain users access to certain NAS devices

2010-07-07 Thread Alan DeKok
Whitmarsh Mark (Leeds Teaching Hospitals NHS Trust) wrote: > Hi Alan, > > Thanks for the simplifications - I've put those in. > I have done lots more reading and testing and found that any attribute I > check for in a group file which has type ipaddr fails. I cannot see why this > is. > When deb

RE: radius dont work

2010-07-07 Thread Aziz YÜCELEN
Hi Sorry for my carelessness. Debug output is here and I am using eap TTLS but login not success.Please help me thanks. rad_recv: Access-Request packet from host 10.1.1.252 port 1206, id=20, length=183 User-Name = "deneme"NAS-IP-Address = 10.1.1.252 NAS-Port = 0Called-Statio

Re: radius dont work

2010-07-07 Thread Alan DeKok
Aziz YÜCELEN wrote: > I am using freeradius version 2.1.4 and I want to set up config to eap > TTLS using users and clients file but didnt work.Please help me.Thanks. The FAQ says to post the debug output, *not* a heavily edited version. The FAQ does *not* say to post the configuration. Fo

Re: Anonymous/Guest users and WPA with EAP-TLS/TTLS

2010-07-07 Thread Alan DeKok
Erik Norgaard wrote: > Question, is it possible to use EAP with say TLS or TTLS and if no > credentials are specified, no client certificate is sent, then anonymous > access is granted rather than fail authentication? No. For TTLS or PEAP, the user *must* enter some kind of credentials for it t

Anonymous/Guest users and WPA with EAP-TLS/TTLS

2010-07-07 Thread Erik Norgaard
Hi: I want to do a WLAN setup that allows restricted anonymous access yet offers the security of encryption with WPA. I currently use EAP-TLS. Ofcourse, I could create an Anonymous or guest account, but then I'd have to tell about it. Question, is it possible to use EAP with say TLS or TTLS

radius dont work

2010-07-07 Thread Aziz YÜCELEN
Hi I am using freeradius version 2.1.4 and I want to set up config to eap TTLS using users and clients file but didnt work.Please help me.Thanks. ***OUTPUTFinished request 18.Going to the next requestWaking up in 2.0 seconds.Cleaning up request