Windows Phone CA verification debugging

2013-09-16 Thread Mathieu Simon
Hi list While I've been quite successful in making preconfigured profiles and docs for our students on how to make proper proper wireless configuration, I'm encountering some issues with those (yet quite rare) people with Windows Phone 8 (WP8) systems. WP8 devices are yet able to connect

Re: Windows Phone CA verification debugging

2013-09-16 Thread A . L . M . Buxey
Hi, encountering some issues with those (yet quite rare) people with Windows Phone 8 (WP8) systems. WP8 devices are yet able to connect without (any) CA or common name verification, but seem to fail when I let them check the CA by choosing it from the device' CA store.

Re: Windows Phone CA verification debugging

2013-09-16 Thread Mathieu Simon
Hi, 2013/9/16 a.l.m.bu...@lboro.ac.uk we've had no problems with self-signed CA or with 3rd party CA and standard RADIUS certificate BUT the certificate must have CRLDP (CRL distribution point) URL defined. that can either be at CA level or RADIUS level - or both. eg

Last call for Version 2.2.1

2013-09-16 Thread Alan DeKok
Unless there are any objections, we'll release 2.2.1 tomorrow. The list of changes is large: - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Last call for Version 2.2.1

2013-09-16 Thread Alan DeKok
Unless there are any objections, we'll release 2.2.1 tomorrow. The list of changes is large: https://github.com/FreeRADIUS/freeradius-server/blob/v2.x.x/doc/ChangeLog Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Last call for Version 2.2.1

2013-09-16 Thread Arran Cudbard-Bell
On 16 Sep 2013, at 13:44, Alan DeKok al...@deployingradius.com wrote: The list of changes is large: Seems sort of small to me :) Here's the changelog: https://github.com/FreeRADIUS/freeradius-server/blob/v2.x.x/doc/ChangeLog Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS

RE: Freeradius 2.1.12 Second LDAP Server

2013-09-16 Thread Beliars Fire
Hi, thanks for the Help. Actually im decided to create a new VM and reinstall the complete Server. I`m following the complete How-To, but i`m getting two different Errors. The First One is this: It`s under the first Point: Configuring Authentification with Active Directory I`m startet the

Re: Freeradius 2.1.12 Second LDAP Server

2013-09-16 Thread Alan DeKok
Beliars Fire wrote: The next Step wbinfo -a *user*%*password *works too, but i`m getting this Error-Message: /Could not authenticate user Username%Password with plaintext password/ challenge/response password authentication succeeded Is this normal? How can I fix it? The Response seems to

Re: Last call for Version 2.2.1

2013-09-16 Thread A . L . M . Buxey
Hi, ..so many new features... thought 3.x was where the new features and dev work was going into ;-) PS has anyone tested it with MariaDB? Wondering if its 100% drop-in compatible? (I'm postgres myself but looks like MySQL is dying) alan - List info/subscribe/unsubscribe? See

Re: Freeradius 2.1.12 Second LDAP Server

2013-09-16 Thread A . L . M . Buxey
Hi, Could not authenticate user Username%Password with plaintext password challenge/response password authentication succeeded thats okay. means you couldnt do PAP and only MSCHAPv2 worked. expected for that command. In this Step, i must edit the following line with this text in

Re: Last call for Version 2.2.1

2013-09-16 Thread Alan DeKok
a.l.m.bu...@lboro.ac.uk wrote: ..so many new features... thought 3.x was where the new features and dev work was going into ;-) Well, yes. 2.2.1 has a lot of tiny features that are minor code changes. v3 is nearly everything re-written or updated. Those re-writes allow the addition of

Re: Last call for Version 2.2.1

2013-09-16 Thread Arran Cudbard-Bell
On 16 Sep 2013, at 16:08, Alan DeKok al...@deployingradius.com wrote: a.l.m.bu...@lboro.ac.uk wrote: ..so many new features... thought 3.x was where the new features and dev work was going into ;-) Well, yes. 2.2.1 has a lot of tiny features that are minor code changes. v3 is nearly

Re: Freeradius + 2 x LDAP + VLAN

2013-09-16 Thread Miroslav Lednicky
Thank you, it works with simple modification (not too effective): ldap1 if (ok) { update reply { Tunnel-Type = VLAN Tunnel-Medium-Type = IEEE-802 Tunnel-Private-Group-Id = 1

Debugging No EAP session matching the State variable

2013-09-16 Thread John Douglass
I run two freeradius servers (both 2.2.0 x86_64) with MySQL backends doing ntlm_auth (RHEL 6 Samba 3.6.9) for EAP-PEAP-MSChapV2 for our client devices. I have enabled the server debug using radmin (the debug file is HUGE so that is why I am not posting it along with). I have googled and

Re: Debugging No EAP session matching the State variable

2013-09-16 Thread A . L . M . Buxey
Hi, Sep 16 09:57:56 newdvlanb radiusd[15211]: rlm_eap: No EAP session matching the State variable. turn on full debug for just a single User-Name or Calling-Station-Id (check radmin docs). whats your authentication clean-up/tidy up times - as if the clients dont respond then the session is