Re: freeradius integration to new Open Directory

2012-05-24 Thread Alan DeKok
John wrote: > We use PEAP (ms-chapv2) + freeradius + Samba to integation with Open > Directory (OSX version < 10.6.8), it work good. But in new OSX 10.7, > there is no SMB component. > > Is there a way to let PEAP (ms-chapv2) + freeradius integation with new > Open directory? rlm_opendirectory

freeradius integration to new Open Directory

2012-05-24 Thread John
Hi,   We use PEAP (ms-chapv2) + freeradius + Samba to integation with Open Directory (OSX version < 10.6.8), it work good. But in new OSX 10.7, there is no SMB component.   Is there a way to let PEAP (ms-chapv2) + freeradius integation with new Open directory?   Best, Hangjun - List info/subscr

Re: FR over TCP

2012-05-24 Thread alan buxey
Hi, > Can we use TCP instead of udp with freeradius (for more secure communication > link and some other reasons) and how? RADIUS over TCP using TLS - aka RADSEC - check out the latest GIT release of FR (3.x) alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FR over TCP

2012-05-24 Thread Arran Cudbard-Bell
On 24 May 2012, at 21:18, yagizozen wrote: > Hello Guys, > > I have a question about radius over tcp, is it possible? > > Can we use TCP instead of udp with freeradius (for more secure communication > link and some other reasons) and how? > > can you forward me to necessary documentations if i

FR over TCP

2012-05-24 Thread yagizozen
Hello Guys, I have a question about radius over tcp, is it possible? Can we use TCP instead of udp with freeradius (for more secure communication link and some other reasons) and how? can you forward me to necessary documentations if it is possible and I can read and understand how. Thank you !

Re: Proxying multiple times to virtual and external servers

2012-05-24 Thread Alan Buxey
From my mobile. So terse... if("%{Called-Station-Id}" =~ /:eduroam$/){ update control { proxy-to-server = eduroam } } ...or such (there will be some lexical errors above) Search the mail Archives as there have been similar discussions PS its 'eduroam', NEVER a capital E alan -- This smartp

Re: Proxying multiple times to virtual and external servers

2012-05-24 Thread Bob Franklin
On Thu, 24 May 2012, Graeme Hamilton wrote: Ideally, I'd like a generic default virtual server which would process all authentications initially, but which would act upon the suffix (e.g. ':eduroam') appended to the Called-Station-Id by our wireless controllers to proxy the request off to anot

Proxying multiple times to virtual and external servers

2012-05-24 Thread Graeme Hamilton
Hello, I'm configuring FreeRADIUS (2.1.12) for use as part of our Eduroam deployment. We're using EAP-MSCHAPv2 authentication, so I've got both an outer and inner virtual server configured and working correctly. Currently, the outer server configuration (configured as default i.e. without a 'se

Re: ssh authentication failed problem use freeradius & pam_radius

2012-05-24 Thread Fajar A. Nugraha
On Thu, May 24, 2012 at 9:44 PM, sam wrote: > The pam_radius_auth module is installed on linux, and if the user-A is not > created in local and  only existed in remote radius server. > In following function() in pam_radius_auth.c, the *password always is > INCORRECT That is the expected behavior.

Re: ssh authentication failed problem use freeradius & pam_radius

2012-05-24 Thread sam
The pam_radius_auth module is installed on linux, and if the user-A is not created in local and only existed in remote radius server. In following function() in pam_radius_auth.c, the *password always is INCORRECT +code+ static int rad_converse(pam_handle_t *pamh, int msg

Re: FR on RHEL

2012-05-24 Thread John Dennis
On 05/24/2012 07:22 AM, Tobias Hachmer wrote: Hello list, the red hat faq on http://wiki.freeradius.org/Red-Hat-FAQ supposes that the newest version of FR is in the official channel. Here on a RHEL6 server there is only version 2.1.10 in the repo (and only the base package, not the additional mo

Re: FR on RHEL

2012-05-24 Thread Tobias Hachmer
Am 24.05.2012 13:37, schrieb Alan Buxey: From previous discussions on this list I believe that the next point release of 6 will have 2.1.12. Its a little crazy that 5.x release is ahead of the 6.x but that's how it is... thanks for the information, I hope they will be in soon Regards, Tobi

Re: FR on RHEL

2012-05-24 Thread Alan Buxey
>From previous discussions on this list I believe that the next point release >of 6 will have 2.1.12. Its a little crazy that 5.x release is ahead of the 6.x >but that's how it is... Alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

FR on RHEL

2012-05-24 Thread Tobias Hachmer
Hello list, the red hat faq on http://wiki.freeradius.org/Red-Hat-FAQ supposes that the newest version of FR is in the official channel. Here on a RHEL6 server there is only version 2.1.10 in the repo (and only the base package, not the additional modules like mysql, ldap and so on): # yum i

Error: SSL: SSL_read failed in a system call (-1), TLS session fails.

2012-05-24 Thread Nikolaos Pavlidis
Hello all, The error: Thu May 24 08:51:17 2012 : Error: TLS Alert write:fatal:unexpected_message Thu May 24 08:51:17 2012 : Error: TLS_accept:error in SSLv3 read finished A Thu May 24 08:51:17 2012 : Error: rlm_eap: SSL error error:1408E0F4:SSL routines:SSL3_GET_MESSAGE:unexpected me

Re: ssh authentication failed problem use freeradius & pam_radius

2012-05-24 Thread sam
Is there anyone to contribute this fix? -- View this message in context: http://freeradius.1045715.n5.nabble.com/ssh-authentication-failed-problem-use-freeradius-pam-radius-tp5687733p5713353.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe