Re: Freeradius 3 & LDAP Generic Attributes

2013-04-12 Thread Arran Cudbard-Bell
On 12 Apr 2013, at 15:21, Arran Cudbard-Bell wrote: > > On 12 Apr 2013, at 15:00, Nicholas Lemberger wrote: > >> The ldap.attrmap syntax in FR2 was: >> checkItem $GENERIC$ radiusCheckItem >> replyItem $GENERIC$ radiusReplyItem >> >> Bas

RE: segfault error

2013-04-12 Thread Chris Taylor
Yeah this is the only version of freeradius on the box the other was an rpm version that was removed before I compiled this one. -Original Message- From: freeradius-users-bounces+chris.taylor=corp.eastlink...@lists.freeradius.org [mailto:freeradius-users-bounces+chris.taylor=corp.eas

Re: segfault error

2013-04-12 Thread Alan DeKok
Chris Taylor wrote: > Ok I have upgraded to a compiled version of freeradius 2.2.0, and I was able > to see the same result. It crashed after a few minutes with the error below. > > on-radius01 kernel: radiusd[10038]: segfault at 73d87000 rip > 003c6c07b5bb rsp 73d83c08 error

RE: segfault error

2013-04-12 Thread Chris Taylor
Ok I have upgraded to a compiled version of freeradius 2.2.0, and I was able to see the same result. It crashed after a few minutes with the error below. on-radius01 kernel: radiusd[10038]: segfault at 73d87000 rip 003c6c07b5bb rsp 73d83c08 error 4 I turned on core dumps to

Re: Freeradius 3 & LDAP Generic Attributes

2013-04-12 Thread Arran Cudbard-Bell
On 12 Apr 2013, at 15:00, Nicholas Lemberger wrote: > The ldap.attrmap syntax in FR2 was: > checkItem $GENERIC$ radiusCheckItem > replyItem $GENERIC$ radiusReplyItem > > Basically the ldap attributes radiusCheckItem & radiusReplyItem > con

Re: Re: Freeradius 3 & LDAP Generic Attributes

2013-04-12 Thread Nicholas Lemberger
The ldap.attrmap syntax in FR2 was: checkItem $GENERIC$ radiusCheckItem replyItem $GENERIC$ radiusReplyItem Basically the ldap attributes radiusCheckItem & radiusReplyItem contained FR attr/value pairs which were then added to the correspondi

Re: how can detect the cues of reject

2013-04-12 Thread Mehdi Ravanbakhsh
thanks ARRAN On 4/12/13, Arran Cudbard-Bell wrote: > > On 12 Apr 2013, at 11:01, Mehdi Ravanbakhsh wrote: > >> how we can detect cues of reject in any section of default(site enable) ? >> >> do we have any internal attribute or any source that can be use for >> determine cues of rejecting user

Re: how can detect the cues of reject

2013-04-12 Thread Arran Cudbard-Bell
On 12 Apr 2013, at 11:01, Mehdi Ravanbakhsh wrote: > how we can detect cues of reject in any section of default(site enable) ? > > do we have any internal attribute or any source that can be use for > determine cues of rejecting user ? Module-Failure-Message But it's only reliably populated

Re: Adding modified libraries without recompiling entirely FreeRADIUS

2013-04-12 Thread Alan DeKok
yoann Couble wrote: > Hi everyone, > > I have a freeRADIUS 2.0.4 server which has been running well for the > past two years. Upgrade to 2.2.0. > With the sources downloaded from packages.debian.org, > wrote my version of rlm_chap.c. > Everything compiles and works fine when i do: > ./con

Re: Betr.: Re: Question about differences between possibilities of authentication

2013-04-12 Thread Alan DeKok
Bas Penris wrote: > The reason I didn't post the debugs and config files was because I > thought there might be an easy explanation which one of you would be > able to spoon up without any trouble. We need certain information to answer questions. One piece of which is the debug output. That's

Betr.: Re: Question about differences between possibilities of authentication

2013-04-12 Thread Bas Penris
Hi Alan, The reason I didn't post the debugs and config files was because I thought there might be an easy explanation which one of you would be able to spoon up without any trouble. Especially because nothing is broken and everything works as it's supposed to. I'll get back with a debug log

how can detect the cues of reject

2013-04-12 Thread Mehdi Ravanbakhsh
how we can detect cues of reject in any section of default(site enable) ? do we have any internal attribute or any source that can be use for determine cues of rejecting user ? best regards. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

[RESOLVED] Need both Local (MySQL database) and Active directory authentications.

2013-04-12 Thread ffgch2
Thanks Alan! The following code in the sites-available/inner-tunnel solved the problem. if ("%{sql: SELECT COUNT(*) FROM radcheck WHERE username = '%{SQL-User-Name}' AND pwdtype = 'local'}" > 0) { update control { MS-CHAP-Use-NTLM-Auth := 0 } } ffgch2 wrote: > > I ha

Re: Question about differences between possibilities of authentication

2013-04-12 Thread Alan DeKok
Bas Penris wrote: > Everything is working as it should so no worries there, but I'm curious > about something. I configured the proxies and the local realm. When I > did a radtest like this: > radtest che...@localdomain.nl password 127.0.0.1 1 secret > I would get an Accept-Accept. That's the ea

Re: Freeradius +LDAP + Samba integrates to Active Derectory

2013-04-12 Thread Alan DeKok
John wrote: > We deploy freeradius integrated to Active Directory, but the AD enabled > "Require signing" option (see the attachement). That's really an AD question. > net join is OK after we set "LDAP SASL wrapping" to 'sign'. But LDAP > search failed. Is there a way to let LDAP search work?

Re: Question on certificates before deep dive into EAP-TLS

2013-04-12 Thread Alan DeKok
Mathieu Simon wrote: > Telling students how to install a internal CA root isn't going to work, > it already > didn't work for teachers in the past ... Yes. That is a problem. > But allowing only (internal) devices with certs from the internal CA > through CA_file > would allow us to more easil

SV: Group questions..several group memberships to one account. FreeRADIUS Version 2.1.10

2013-04-12 Thread Alexander Silveröhrt
And sorry again… I forgot old Fall-Through= yes which of course made it work.. I thank myself for my excellent answers☺ Cheers Alex Från: freeradius-users-bounces+alexander.silverohrt=itux...@lists.freeradius.org [mailto:freeradius-users-bounces+alexander.silverohrt=itux...@lists.freeradi

SV: Group questions..several group memberships to one account. FreeRADIUS Version 2.1.10

2013-04-12 Thread Alexander Silveröhrt
Sorry forget about priority i thought higher was first..Which it wasn’t.. Still is it possible to get replies from multiple groups an account belongs to? Cheers Alex Från: freeradius-users-bounces+alexander.silverohrt=itux...@lists.freeradius.org [mailto:freeradius-users-bounces+alexander.silv

Group questions..several group memberships to one account. FreeRADIUS Version 2.1.10

2013-04-12 Thread Alexander Silveröhrt
Hello, Never played around with groups using rlm_sql and the default schema.. I am reading what i assume is saying that it should be possible to have several groups to a account and each group should be able to supply that specific groups radgroupreply attributes.. Number 4 below sure sounds lik