Re: PEAP/MSCHAPv2 problem

2011-04-04 Thread Stefan Winter
Hi, >>The solution to the problem is simple. The answer is in front of >> you. >> >>Alan DeKok. > Looks like i'm blind...please give me a hint ;-) Dude... supplicants are typically configured to trust only the exact one certificate that is in the RADIUS Server (CN=... is in the supplican

Custom sql post-auth help

2011-04-04 Thread Trey Briggs
Hi, I'm trying to get similar logging in mysql to what you see with: log { ... auth = yes auth_badpass = yes auth_goodpass = yes } "Login OK: [/] (from client port 0)" I've found how to log accepts and rejects using the sql module in the post-auth section, but I'm unsure how to insert

Re: How to make a NAS(Cisco) send MSCHAP request

2011-04-04 Thread Alan Buxey
hi, >To all Cisco guys out there how can I make a NAS(Cisco 2960 switch) to >send MSCHAP requests to FR server instead of PAP requests. what makes you even think it can? are you talking about the cisco switch device itself for local admin access etc or are you talking about end clients us

Re: bug

2011-04-04 Thread Alan Buxey
hi, turn on sqltrace and turn on tcpdump - you will find what is causing it alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PEAP/MSCHAPv2 problem

2011-04-04 Thread Jürgen Stader
Am 04.04.2011 18:02, schrieb Alan DeKok: Jürgen Stader wrote: When you cloned your RADIUS server, did you give the clone a different certificate afterwards? Since you didn't answer that question directly, it looks like a "yes". You' re right, but you can read this out of the lines. The two m

Re: PEAP/MSCHAPv2 problem

2011-04-04 Thread Alan DeKok
Jürgen Stader wrote: >> When you cloned your RADIUS server, did you give the clone a different >> certificate afterwards? Since you didn't answer that question directly, it looks like a "yes". > The original radius has a trusted certificate, signed by our CA. The > clone has also a trusted cert

Re: PEAP/MSCHAPv2 problem

2011-04-04 Thread Jürgen Stader
Hi, thanks for your reply. Am 04.04.2011 16:27, schrieb Stefan Winter: Hi, PEAP can work with or without client certs. Both run through the "tls" instance; that is no error. The problem is much rather here: Sending Access-Challenge of id 219 to ... port 32769 Waking up in 2.0 seconds. Cleani

Re: PEAP/MSCHAPv2 problem

2011-04-04 Thread Stefan Winter
Hi, PEAP can work with or without client certs. Both run through the "tls" instance; that is no error. The problem is much rather here: > Sending Access-Challenge of id 219 to ... port 32769 > Waking up in 2.0 seconds. > Cleaning up request 0 ID 219 with timestamp +3 > WARNING: >

PEAP/MSCHAPv2 problem

2011-04-04 Thread Jürgen Stader
Hello, i have a problem with my freeradius 2.1.10. I try to use PEAP and MSCHAPv2 to authenticate my wireless client against radius and ldap. The client is a Windows XP Proffesional and configuered to use "protected EAP(PEAP)" for the wireless network. On the radius servers console the follo

RE: unlang question

2011-04-04 Thread Garber, Neal
> i have made my modifications Perhaps if you show us the modifications, someone might be able to suggest what's wrong. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

bug

2011-04-04 Thread Rtz Poknat
hello. I deleted an entry in the database , yet it returns,, and session time is 59000 seconds. i check the openvpn server but no user is connected and it is continously updating the last update in sql table. also, even if i turn off the NAS,, the entry still updates by itself.. (a ghost??)

unlang question

2011-04-04 Thread Omer Faruk SEN
I want to insert Quintum-h323-remote-address value to radacct table at sql//dialup.conf i have made my modifications but i see entries like h323-remote-address=3D10.241.1.202 which is h323-remote-address=10.241.1.202 but I only want 10.241.1.202 (IP address) My entry at details file: Quint

Re: Strip off the domain part from the User-Name

2011-04-04 Thread Phil Mayers
On 04/04/2011 07:57 AM, Thomas Wunder wrote: Hi, On Friday 01 April 2011 18:32:21 Phil Mayers wrote: On 01/04/11 13:43, Thomas Wunder wrote: [mschap] No Cleartext-Password configured. Cannot create LM-Password. [mschap] Found NT-Password [mschap] ERROR: User-Name (winmac\tom1) is not the same

Re: Strip off the domain part from the User-Name

2011-04-04 Thread Thomas Wunder
Hi, On Friday 01 April 2011 18:32:21 Phil Mayers wrote: > On 01/04/11 13:43, Thomas Wunder wrote: > > [mschap] No Cleartext-Password configured. Cannot create LM-Password. > > [mschap] Found NT-Password > > [mschap] ERROR: User-Name (winmac\tom1) is not the same as MS-CHAP Name > > (tom1) from EA