session management

2013-02-05 Thread Suresh Kumar Subramanian
Hi, I am newbie and I have couple of questions in the free radius. 1) How do we maintain the session time in free radius? For example, a given user the session time is configured for 1 hour. After 1 hour, radius server should initiate "Session disconnect message" for the user to the NAS

Re: PAM error on reboot of the RADIUS client

2013-02-05 Thread Alan DeKok
Deepti kulkarni wrote: > Thanks. PAM doesnt support authorization either right? > What radius client do you prefer that can support authentication, > authorization and accounting for linux machines? There is nothing else. Alan DeKok - List info/subscribe/unsubscribe? See http://www.freeradius

Re: PAM error on reboot of the RADIUS client

2013-02-05 Thread Deepti kulkarni
Thanks. PAM doesnt support authorization either right? What radius client do you prefer that can support authentication, authorization and accounting for linux machines? Thanks On Tue, Feb 5, 2013 at 7:15 AM, Alan DeKok wrote: > Deepti kulkarni wrote: > > Authentication and accounting works fine

Re: radiusd running config - is it possible to display

2013-02-05 Thread Alan Buxey
? It's all on disk. And if that's changed since the server was run then radiusd -X won't help. You know you can run a check/verify instance...? And that using radmin you can check the configuration of particular modules in the current running instance? alan - List info/subscribe/unsubscribe? S

freeradius accounting of cdr and quotes for string attributes

2013-02-05 Thread Kelly Roestel
My question is this, I need to write CDR information out using the linelog module in csv format. The requirement is that all string attributes need to be enclosed in double quotes. How does one go about doing this? If you look at the detailed format, these string attributes are enclosed. Bu

RE: LDAP groups and profiles

2013-02-05 Thread Chris Taylor
> I added this to the users file > > DEFAULT ldap1.REALM-2.ca-Ldap-Group == residential_profile > > But I get this error when I fire up radius -X > > > /etc/raddb/users[222]: Parse error (check) for entry DEFAULT: > expecting operator Errors reading /etc/raddb/users Wild guess, but you might try

radiusd running config - is it possible to display

2013-02-05 Thread Bertalan Voros
Hello All, Is it possible to display the running config of freeradius without having to capture the output of radiusd -X? Best regards, Bertalan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: LDAP groups and profiles

2013-02-05 Thread Phil Mayers
On 05/02/13 15:50, Chris Taylor wrote: I added this to the users file DEFAULT ldap1.REALM-2.ca-Ldap-Group == residential_profile But I get this error when I fire up radius -X /etc/raddb/users[222]: Parse error (check) for entry DEFAULT: expecting operator Errors reading /etc/raddb/users Wi

RE: LDAP groups and profiles

2013-02-05 Thread Chris Taylor
> > > I have RADIUS running with multiple realms and multiple LDAP back ends > that stores all my user attributes. I am trying to apply different > user profiles to different groups. What I did was setup the profile in > the USERS file, add the group attributes to the ldap config file, and >

Re: Degradation of service when authentication fails with Windows AD

2013-02-05 Thread Alan DeKok
Antonio Alberola wrote: > I'm having random authentication failures and I think they are due to a > Radius server internal failure. I use Radius for authenticating the email of > users in Windows Active Directory via PAM. Don't do that. Use Samba. See my web page for instructions: http://dep

Re: user session & accounting mgmt

2013-02-05 Thread Alan DeKok
Suresh Kumar Subramanian wrote: > How do we maintain the session time in free radius? RADIUS doesn't do that. > For example, a given user the session time is configured for 1 hour. > > After 1 hour, radius server should initiate "Session disconnect message" > for the user to the NAS. No. R

Re: PAM error on reboot of the RADIUS client

2013-02-05 Thread Alan DeKok
Deepti kulkarni wrote: > Authentication and accounting works fine after I configure the above on > the client. As soon as I reboot client, login fails with error - "cannot > make/remove an entry for the specified session". Cannot login into the > client. Unfortunately, this is a PAM problem. I

Re: Degradation of service when authentication fails with Windows AD

2013-02-05 Thread Phil Mayers
On 05/02/13 10:20, Antonio Alberola wrote: Dear All, I'm having random authentication failures and I think they are due to a Radius server internal failure. I use Radius for authenticating the email of users in Windows Active Directory via PAM. Before I used NTLM and Kerberos together, and now I

Re: Degradation of service when authentication fails with Windows AD

2013-02-05 Thread A . L . M . Buxey
Hi, > I need help to find the cause of the problem and fix it. I do not know yet > if the problem is in the domain controllers, in the PAM module or in Radius. you backend authentication is the problem > But everything seems to point to Radius. huh? the RADIUS logs are clearly screaming out wha

Re: stored procedure value for access-reject in free radius

2013-02-05 Thread Fajar A. Nugraha
On Tue, Feb 5, 2013 at 9:44 PM, Lakshmi Narayana Baliah wrote: > >Hi all, > > I want to configure the free radius to return access-reject based on the > value in stored procedure in oracle database( i have configured oracle > database to free radius) > > > How do i do that ??? please he

Re: stored procedure value for access-reject in free radius

2013-02-05 Thread Phil Mayers
On 05/02/13 10:44, Lakshmi Narayana Baliah wrote: Hi all, I want to configure the free radius to return access-reject based on the value in stored procedure in oracle database( i have configured oracle database to free radius) How do i do that ??? please help There are many

stored procedure value for access-reject in free radius

2013-02-05 Thread Lakshmi Narayana Baliah
Hi all, I want to configure the free radius to return access-reject based on the value in stored procedure in oracle database( i have configured oracle database to free radius) How do i do that ??? please help Lakshmi narayana | Prod Engineering | Tech Mahindra #9/7 Hosur Road,Ba

Degradation of service when authentication fails with Windows AD

2013-02-05 Thread Antonio Alberola
Dear All,   I'm having random authentication failures and I think they are due to a Radius server internal failure. I use Radius for authenticating the email of users in Windows Active Directory via PAM. Before I used NTLM and Kerberos together, and now I use PAM. I use FreeRADIUS version 2.1.12 th

user session & accounting mgmt

2013-02-05 Thread Suresh Kumar Subramanian
Hi, I am newbie and I have couple of questions in the free radius. 1) How do we maintain the session time in free radius? For example, a given user the session time is configured for 1 hour. After 1 hour, radius server should initiate "Session disconnect message" for the user to the NAS