Re: Freeradius rlm_pam

2012-02-12 Thread Alan DeKok
Mark wrote: I'm not able to authenticate my client. I'm trying to use EAP-GTC on the inner-tunnel. Then read the comments in raddb/eap.conf. Look for gtc. It documents how to get GTC working with other methods. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Freeradius rlm_pam

2012-02-12 Thread Alan Buxey
Hi, Your server is configured with md5 as the default EAP type. The client NAKs that and then goes on to do PEAP. Can your clients do EAP-GTC? another confusion occurs in inner tunnel due to having 2 auth-type entries. Perhaps define a new file/users instance for the inner-tunnel with DEFAULT

Re: Freeradius rlm_pam

2012-02-12 Thread Mark
On Sun, Feb 12, 2012 at 1:34 AM, Alan DeKok al...@deployingradius.com wrote: Mark wrote:  Then read the comments in raddb/eap.conf.  Look for gtc.  It documents how to get GTC working with other methods. Thanks! It wasn't entirely clear to me at first from that documentation how to achieve my

Re: Multi-domain AD and Users Who Aren't So Bright

2012-02-12 Thread McNutt, Justin M.
I'm not sure why, then, but it actually does work. We have shown that with the client configured to use u...@e.mail.address (where e.mail.address is NOT the same as the AD domain), if I have FR look for 'e.mail.address' and translate it to the correct NT domain, authentication succeeds. The

RE: Freeradius-Users Digest, Vol 82, Issue 33

2012-02-12 Thread Gilmour, Scott
Alan, I already have certificates created on my 2008 Server so I want to use those certificates on my Ubuntu Server without creating new ones. You mentioned my openssl configuration is wrong. Any suggestions on how I can fix the openssl configuration? Thanks Scott Message: 1 Date: Sun, 12 Feb