Re: EAP-SIM on 2.2.0

2012-09-12 Thread Alan DeKok
Francois Gaudreault wrote: [eap] processing type sim [eap] Handler failed in EAP/sim [eap] Failed in EAP select That's not nice. The module should return some kind of message. This looks like an issue for digging into the code. Alan DeKok. - List info/subscribe/unsubscribe? See

Multiple EAP config

2012-09-12 Thread BILLOT
Hi, We have a config with 3 virtual servers, running on a different port. Each virtual server must have a particular config (different LDAP server, different SQL server). However, each one uses EAP auth and so the inner-tunnel which is unique. Thus in the inner-tunnel config, default modules

Re: Multiple EAP config

2012-09-12 Thread Arran Cudbard-Bell
On 12 Sep 2012, at 10:59, BILLOT emmanuel.bil...@ac-orleans-tours.fr wrote: Hi, We have a config with 3 virtual servers, running on a different port. Each virtual server must have a particular config (different LDAP server, different SQL server). However, each one uses EAP auth and so the

Adding reply AVPs to a replicated proxy request

2012-09-12 Thread Chadwick Sorrell
Hello, I'm using replicate to proxy my authorization and accounting requests to a server. I'm curious if it's possible to add some of the auth reply attributes to the auth proxy before I send it over. That way the proxied auth has both the request and the reply. Thanks - List

Re: Adding reply AVPs to a replicated proxy request

2012-09-12 Thread Arran Cudbard-Bell
On 12 Sep 2012, at 11:12, Chadwick Sorrell mirot...@gmail.com wrote: Hello, I'm using replicate to proxy my authorization and accounting requests to a server. I'm curious if it's possible to add some of the auth reply attributes to the auth proxy before I send it over. That way the

Re: Multiple EAP config

2012-09-12 Thread BILLOT
Like any other module in the server, you instantiate multiple instances and reference them in the different virtual servers. eap instance { } Ok i did it but when trying to use instances, i get Found Auth-Type = EAP WARNING: Unknown value specified for Auth-Type. Cannot perform

Re: Multiple EAP config

2012-09-12 Thread Arran Cudbard-Bell
On 12 Sep 2012, at 11:43, BILLOT emmanuel.bil...@ac-orleans-tours.fr wrote: Like any other module in the server, you instantiate multiple instances and reference them in the different virtual servers. eap instance { } Ok i did it but when trying to use instances, i get Found

Re: Multiple EAP config

2012-09-12 Thread Phil Mayers
On 12/09/12 11:43, BILLOT wrote: Like any other module in the server, you instantiate multiple instances and reference them in the different virtual servers. eap instance { } Ok i did it but when trying to use instances, i get Found Auth-Type = EAP WARNING: Unknown value specified for

Re: freeradius OTP with OATH

2012-09-12 Thread Arran Cudbard-Bell
On 9 Sep 2012, at 05:27, Thomas Glanzmann tho...@glanzmann.de wrote: Hello Arran, What is the server missing as of 2.2.0 that requires the use of rlm_perl? I'm not aware of the FreeRadius internals but you can simply look at the FreeRadius Module rlm_smsotp. This is what happens.

Re: Multiple EAP config

2012-09-12 Thread BILLOT
Le 12/09/2012 13:03, Arran Cudbard-Bell a écrit : On 12 Sep 2012, at 11:43, BILLOT emmanuel.bil...@ac-orleans-tours.fr wrote: Like any other module in the server, you instantiate multiple instances and reference them in the different virtual servers. eap instance { } Ok i did it but when

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Francois Gaudreault
Hi, That's not nice. The module should return some kind of message. If you say so :P This looks like an issue for digging into the code. Ok. Let me know if you need me to test anything, I will be glad to do so :) Thanks! -- Francois Gaudreault, ing. jr fgaudrea...@inverse.ca ::

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Arran Cudbard-Bell
On 12 Sep 2012, at 13:12, Francois Gaudreault fgaudrea...@inverse.ca wrote: Hi, That's not nice. The module should return some kind of message. If you say so :P This looks like an issue for digging into the code. Ok. Let me know if you need me to test anything, I will be glad

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Phil Mayers
On 11/09/12 21:28, Francois Gaudreault wrote: User-Name = im...@wlan.mnc720.mcc302.3gppnetwork.org Calling-Station-Id = 5C-59-48-ED-C4-96 NAS-IP-Address = 10.0.0.24 NAS-Port = 1 Called-Station-Id = 50-A7-33-31-CF-B8:PacketFence-Ruckus Service-Type = Framed-User

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Francois Gaudreault
Hi, User-Name = im...@wlan.mnc720.mcc302.3gppnetwork.org Calling-Station-Id = 5C-59-48-ED-C4-96 NAS-IP-Address = 10.0.0.24 NAS-Port = 1 Called-Station-Id = 50-A7-33-31-CF-B8:PacketFence-Ruckus Service-Type = Framed-User Framed-MTU = 1400 NAS-Port-Type =

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Francois Gaudreault
Hi again, This is your problem. This is an EAP-AKA/SIM Client error packet. 02 - eap response f7 - ID 000c - length 12 - EAP-SIM 0e - subtype 14 - client error 1601 - client error junk Hmmm interesting. But how can it be working on 2.1.12 with the exact same client and config? Maybe

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Phil Mayers
On 12/09/12 14:14, Francois Gaudreault wrote: Hmmm interesting. But how can it be working on 2.1.12 with the exact same client and config? Maybe I can retry with 2.2.0 and see if I still get this error on multiple retries. I'll get back to you. No idea; I'm not familiar with EAP-SIM. But

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Phil Mayers
On 12/09/12 14:32, Francois Gaudreault wrote: Hi again, This is your problem. This is an EAP-AKA/SIM Client error packet. 02 - eap response f7 - ID 000c - length 12 - EAP-SIM 0e - subtype 14 - client error 1601 - client error junk Hmmm interesting. But how can it be working on

Re: Radius Config and Router

2012-09-12 Thread Michael Schwartzkopff
Hello; I have configured the radius and some servers to authenticate through the Radius. I can authenticate well from the servers but the same is not working on the routers. Users have been created on the router as a test before implementation. The log file has credentials that i have not

Re: Radius Config and Router

2012-09-12 Thread Fajar A. Nugraha
On Wed, Sep 12, 2012 at 9:15 PM, George Innocent ginnocentus2...@gmail.com wrote: Hello; I have configured the radius and some servers to authenticate through the Radius. I can authenticate well from the servers but the same is not working on the routers. Users have been created on the

Re: Radius Config and Router

2012-09-12 Thread George Innocent
The configuration works fine on the servers but fails to record the logs for the routers. Rgds On Wed, Sep 12, 2012 at 5:34 PM, Fajar A. Nugraha l...@fajar.net wrote: On Wed, Sep 12, 2012 at 9:15 PM, George Innocent ginnocentus2...@gmail.com wrote: Hello; I have configured the radius

Re: Radius Config and Router

2012-09-12 Thread Alan DeKok
George Innocent wrote: Find attached my config files. You were not asked to attach your config files. As stated this works fine with the servers i have but fails with the Routers We don't care. Please restore the users file with the help of the original file. Then add the

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Alan DeKok
Francois Gaudreault wrote: Here is the trace with the same client as 2.1.12, but on 2.2.0. The last trace we had was indeed with another SIM. There's only one change to the EAP-SIM code between 2.1.12 and 2.2.0. I'm a bit surprised that it would do anything. At this point, a git bisect

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Phil Mayers
On 12/09/12 16:00, Francois Gaudreault wrote: Hi, No idea; I'm not familiar with EAP-SIM. But the EAP-Message seemed obviously too short for that stage of a challenge/response auth, so I glanced at the RFC for the encoding. Maybe you've got a permissions problem on whatever datastore the SIM

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Francois Gaudreault
Hi, Don't know then. The client is sending the reject - it doesn't like something the server is sending it. Clock sync - is the 2.2.0 machine a different server? Nope. Simple yum remove / install. Beyond that I'm only passing familiar with EAP-SIM, so would be guessing I'm afraid. I think

Re: Radius Config and Router

2012-09-12 Thread George Innocent
Actions Taken before raising this case thats the reason why i sent the config files : The thing is the log files is getting dumps of loggings even when nobody is working on the Nodes. I have started the test with one node before doing the rest. - Restored the file using the examples on the

Re: Radius Config and Router

2012-09-12 Thread Alan DeKok
George Innocent wrote: Actions Taken before raising this case thats the reason why i sent the config files : The thing is the log files is getting dumps of loggings even when nobody is working on the Nodes. That isn't a problem with FreeRADIUS. If you understand RADIUS, the packets come

[ANN] Version 3.0.0-beta0

2012-09-12 Thread Arran Cudbard-Bell
The v2.1.x branch was created almost exactly 3 years ago (14/09/2009), and has diverged from the master branch significantly. The majority of the potentially disruptive code changes have now been completed for 3.0 and it is at a stage where community testing would be helpfull. To provide a

Re: EAP-SIM on 2.2.0

2012-09-12 Thread Francois Gaudreault
Hi, There's only one change to the EAP-SIM code between 2.1.12 and 2.2.0. I'm a bit surprised that it would do anything. At this point, a git bisect would seem to be the best option. Ok so I did bisect, and this commit appears to be the problematic one: