Re: MS-CHAP-V2 with no retry

2011-04-22 Thread Alan DeKok
john.hayw...@wheaton.edu wrote: I like your changes better. It allows to in the future add a retry max so each failure could be counted and send a R=0 after a certain number of failures. The EAP module already does *some* checking of this. If there are more than ~40 or so round trips, it

Re: MS-CHAP-V2 with no retry

2011-04-22 Thread Phil Mayers
On 04/22/2011 09:56 AM, Alan DeKok wrote: If enough people test it and say it works. 2.1.11 is a stable release, so breaking things is very, very, bad. Agreed. It's an extensive change, and needs extensive testing. Personally I'd be inclined to say don't delay 2.1.11. I hope to be

Re: MS-CHAP-V2 with no retry

2011-04-22 Thread Alan Buxey
Hi, Do we know if the password change (and adjustments to retry which make it work) will be included in 2.1.11? If enough people test it and say it works. do we have a direct single known patch now for application to a 2.1.10 source? (theres been a lot of subtle updates flying around)

Re: Help with machine authentication

2011-04-22 Thread Phil Mayers
On 04/21/2011 08:08 PM, Eldred, Bob wrote: After configuring a Windows XP SP3 supplicant for machine authentication (which is stupidly complex, given the required registry hacks to make it work) Once you've done it once, you can export it as a netsh XML profile, then re-import it on other

Re: MS-CHAP-V2 with no retry

2011-04-22 Thread Phil Mayers
On 04/22/2011 11:22 AM, Alan Buxey wrote: Hi, Do we know if the password change (and adjustments to retry which make it work) will be included in 2.1.11? If enough people test it and say it works. do we have a direct single known patch now for application to a 2.1.10 source? (theres

Limit Period time

2011-04-22 Thread googerdi
Hi How can i limit a group or user to be logined in a specific time. for example i have night group that i want to be logined from 1 am to 7 am. Thanks -- View this message in context: http://freeradius.1045715.n5.nabble.com/Limit-Period-time-tp4333210p4333210.html Sent from the FreeRadius -

Re: Limit Period time

2011-04-22 Thread Marc Phillips
How can i limit a group or user to be logined in a specific time. for example i have night group that i want to be logined from 1 am to 7 am. Some NAS's support Time of Day attributes. You could look at http://wiki.freeradius.org/Authorization Enforcing TOD restrictions would be fairly easy

Re: Example of how to use caching (Cached-Session-Policy)?

2011-04-22 Thread John Douglass
Awesome Phil, that was exactly the kind of example that is awesomely useful :) I see that by default the username is stored along with this. [peap] Adding cached attributes to the reply: User-Name = jd187 Cached-Session-Policy = vlan=316 Do you know exactly how the session resumption

Radius bug?

2011-04-22 Thread duhvir
Hello. I use last git freeradius version. radiusd -v (3.0.0) All config in default state, except: proxy.conf --- realm xxx { authhost=192.168.1.1:18121 secret=test } modules/eap.conf --- default_eap_type = peap #Certificate definitions peap {

Re: Limit Period time

2011-04-22 Thread EasyHorpak.com
On 22/04/2554 22:32, googerdi wrote: Hi How can i limit a group or user to be logined in a specific time. for example i have night group that i want to be logined from 1 am to 7 am. Thanks -- View this message in context: