Reject user if does not match group's checks

2012-08-03 Thread Andrei Petru Mura
Although I saw some similar questions on forum, I didn't see a clear response to it. *The question is: *Is there a way to force user be rejected if it does not match check conditions for the group that belongs to? Thanks. - List info/subscribe/unsubscribe? See

RE: Tricky problem with ldap and primary groups in AD

2012-08-03 Thread Franks Andy (RLZ) IT Systems Engineer
That works fine. However I'm still intrigued about why the other method fails, and I also presume this method doesn't allow multiple attribute types to be updated as per the exec-program-wait script in the example documentation? Yes Maybe it's not supported? Must admit I am a

Re: Failed to authenticate the user

2012-08-03 Thread George Innocent
Hi, I have checked on previous forums to this issue amended but still finds errors on debug Thanks to assist On 8/1/12, alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, The two files that i have edited are attached. User and Client configuration files Thanks to advice on where i

RE: Failed to authenticate the user

2012-08-03 Thread Julson, Jim
George, Is this still on Ubuntu 12.04 or did you end up rebuilding to CentOS 6.2? Forgive me if this is redundant information. -Original Message- From: freeradius-users-bounces+jjulson=marketron@lists.freeradius.org

Re: Failed to authenticate the user

2012-08-03 Thread alan buxey
Hi, I have checked on previous forums to this issue amended but still finds errors on debug are you actually reading my messages and taking required action? your logs show that user cannot authenticate (P1Z1X2C7S9Y9B0O8[) NOWHERE have you shown that you have added this user to any of your

Re: Failed to authenticate the user

2012-08-03 Thread George Innocent
Its on the ubuntu installation failing on debug On 8/3/12, Julson, Jim jjul...@marketron.com wrote: George, Is this still on Ubuntu 12.04 or did you end up rebuilding to CentOS 6.2? Forgive me if this is redundant information. -Original Message- From:

RE: Failed to authenticate the user

2012-08-03 Thread Julson, Jim
I'm going to suggest a couple things. Take this as you will. 1. I'm not sure if it's a language barrier or not, but it really sounds as though you don't have a lot of experience with Linux in general, so, since you asked me for a step-by-step how-to document for Ubuntu, and all I had at the

Re: Reject user if does not match group's checks

2012-08-03 Thread Alan DeKok
Andrei Petru Mura wrote: Although I saw some similar questions on forum, I didn't see a clear response to it. *The question is: *Is there a way to force user be rejected if it does not match check conditions for the group that belongs to? See the FAQ. Alan DeKok. - List

Re: Tricky problem with ldap and primary groups in AD

2012-08-03 Thread Alan DeKok
Franks Andy (RLZ) IT Systems Engineer wrote: It's working from the rlm_exec module as intended now, not sure what I did wrong yesterday. No idea. I tried output_pairs=control in the module but it didn't like it, - should that work if =config is v1 stuff? It should, I guess. As

Re: Failed to authenticate the user

2012-08-03 Thread Alan DeKok
George Innocent wrote: I have checked on previous forums to this issue amended but still finds errors on debug Thanks to assist We're trying. You're not. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

user(name) and EAP-TLS

2012-08-03 Thread Klaus Klein
Hi Folks, I'm working on securing the access to a WLAN network with WPA2-Enterprise, EAP-TLS and a FreeRADIUS server. Everything seemed to work as expected until realized that a client will be authenticated (by eap) even if the user(name), provided with the mandatory identifier entry in

Re: user(name) and EAP-TLS

2012-08-03 Thread Alan DeKok
Klaus Klein wrote: I'm working on securing the access to a WLAN network with WPA2-Enterprise, EAP-TLS and a FreeRADIUS server. Which uses certificates for authentication. Everything seemed to work as expected until realized that a client will be authenticated (by eap) even if the

Re: user(name) and EAP-TLS

2012-08-03 Thread Klaus Klein
Am 03.08.2012 22:06, schrieb Alan DeKok: Klaus Klein wrote: I'm working on securing the access to a WLAN network with WPA2-Enterprise, EAP-TLS and a FreeRADIUS server. Which uses certificates for authentication. Correct. Everything seemed to work as expected until realized that a

Re: user(name) and EAP-TLS

2012-08-03 Thread Alan DeKok
Klaus Klein wrote: Which uses certificates for authentication. Correct. Thanks for the vote of confidence. The point of my comment was that it DOESNT use names passwords for authentication. Is it then correct that the 'check_cert_cn' option in eap.conf is the only way to prevent