Re: FreeRadius with Eduroam - Accounting

2011-10-15 Thread Alan DeKok
Mike Diggins wrote: > Does FreeRadius work synchronously only, so a slow response from one > remote server stops any other pending authentications from completing > until that first one is finished? No. You're probably seeing other authentications fail because they share the same home server.

Re: FreeRADIUS EAP-TLS Lookup Client Cert From LDAP DIT

2011-10-15 Thread Alan DeKok
subcon wrote: > Imagine I want to store x509 certificate data (specifically a client > certificate) in an attribute in LDAP (perhaps as a binary attribute, etc). That's outside of the scope of FreeRADIUS. > I would like FreeRADIUS, should it be passed a client certificate INSTEAD of > a user/p

Re: Policy construct for string "concatenation"

2011-10-15 Thread Arran Cudbard-Bell
On 15 Oct 2011, at 13:14, Ray Scholl wrote: > Good morning: > > So, I took all of your advice - example constructs, suggestion to do a little > testing etc. I built a duplicate server and my question still remain. > > The construct I have - > > if ( clients_ldap-Ldap-Group ==

Re: Policy construct for string "concatenation"

2011-10-15 Thread James J J Hooper
On 15/10/2011 12:14, Ray Scholl wrote: Good morning: So, I took all of your advice - example constructs, suggestion to do a little testing etc. I built a duplicate server and my question still remain. The construct I have - if ( clients_ldap-Ldap-Group == "%{FreeRadius-Cli

RE: Policy construct for string "concatenation"

2011-10-15 Thread Ray Scholl
Good morning: So, I took all of your advice - example constructs, suggestion to do a little testing etc. I built a duplicate server and my question still remain. The construct I have - if ( clients_ldap-Ldap-Group == "%{FreeRadius-Client-Shortname}%{'otp'}" ) {

Re: Windows (7) Machine Certificates (Half Domain).

2011-10-15 Thread Phil Mayers
On 10/15/2011 03:17 AM, Christ Schlacta wrote: I've got a handful of windows clients. I'm most concerned about the Windows 7 machines, but there are a few Vista, and even an XP client. I want to deploy "Machine account certificates" for wifi authentication, so machines will be able to connect to

Re: FreeRADIUS EAP-TLS Lookup Client Cert From LDAP DIT

2011-10-15 Thread Phil Mayers
On 10/14/2011 10:43 PM, subcon wrote: I've searched for this sort of posting, but found issues unrelated that responded to my search string, so I decided to post it here. OK, currently I have Radius authenticating LDAP users via PAP. Works great. Imagine I want to store x509 certificate data (