Re: Free radius 2.1.4 Installation

2009-05-12 Thread A . L . M . Buxey
Hi, Thanks for the response. I have installed Python-3.1a1 in redhat linux 9. Which version I should install for FREERADIUS or which file I should look for? redhat linux 9 ? as in pre-Fedora, pre-ES ? I've running okay with python 2.4.3 - you have to have the python-devel RPM installed

Re: Proposed release of 2.1.6

2009-05-12 Thread A . L . M . Buxey
Hi, We plan on releasing 2.1.6 this week. Please test the pre release at: http://git.freeradius.org/pre/ If there are any concerns, problems, errors, etc., please let us know before we release the final version. no showstopper just yet... however, noted error in Makefile (spotted

Re: Proposed release of 2.1.6

2009-05-12 Thread A . L . M . Buxey
Hi, crash bang boom. after a successful auth, things go wonky in SQL logging land +- entering group post-auth {...} [reply_log] expand: /var/log/radius/radacct/%{Client-IP-Address}/reply-detail-%Y%m%d - /var/log/radius/radacct/192.168.5.13/reply-detail-20090512 [reply_log]

Re: Proposed release of 2.1.6

2009-05-12 Thread A . L . M . Buxey
Hi, a.l.m.bu...@lboro.ac.uk wrote: crash bang boom. after a successful auth, things go wonky in SQL logging land radiusd: symbol lookup error: /usr/lib/rlm_sql_log-2.1.6.so: undefined symbol: rad_assert the daemon crashes out Hah! I already caught that and committed a fix

Re: Still having problems with Active Directory FreeRADIUS integration

2009-05-11 Thread A . L . M . Buxey
Hi, Check what is file you altered called. You have something called mschap.org in there: including configuration file /etc/raddb/modules/mschap.org i'd suggst that that was the 'original' file - without realising that al files in that directory get read. if you want to keep original

Re: FREE RADIUS INSTALLTION WITH 2.1.4

2009-05-11 Thread A . L . M . Buxey
hi, what platform and what version of python? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Still having problems with Active Directory FreeRADIUS integration

2009-05-11 Thread A . L . M . Buxey
Hi, Sure. Send a patch. :) ;-) hmm, am i being too naive radiusd.conf $INCLUDE ${confdir}/modules/ becomes $INCLUDE ${confdir}/modules-enabled/ and the contents of modules/ goes into that new directory with another modules-available being created. (and then the install code updated to

Re: Still having problems with Active Directory FreeRADIUS integration

2009-05-11 Thread A . L . M . Buxey
Hi, Patches go into git. English descriptions don't. now what kind of 1990's system is that? ;-) okay, seriously, i thought it worth a discussion before provision - perhaps there was some facet or issue that i hadnt thought of So... if it's important to get this done, send a patch. i

Re: freeradius upgrade help

2009-04-30 Thread A . L . M . Buxey
Hi, Appreciate if some one can please forward any docs/details about the upgrade from old freeradius version 1.1.6 to 2.1.4 in linux. copy the old config to somewhere safe install version 2.1.4 now configure 2.1.4 to match the requirements you used to use in 1.1.6 - although some things have

Re: freeradius upgrade help

2009-04-29 Thread A . L . M . Buxey
Hi, I'm currently using freeradius version 1.1.6, planning to upgrdate to a stable version. Please suggest a version which is stable. My radius box running linux. compared to 1.1.6 any of the 2.1.x are more stable ;-) alan - List info/subscribe/unsubscribe? See

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, are you sure that the accounting server was ever alive and handling accounting packets? Those logs look exactly like they would if , for example, you were sending auth+acct to an IAS RADIUS server not configured for accounting. the RADIUS server attempts to send an accounting packet to

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, Accounting server was alive and receving packets till yesterday. And suddenly got receiving dead alive messages. So restarted radiusd process then it got resolved. are we talking about the same box? I'm not talking about this FreeRADIUS box you gave logs from, I'm talking about the box

Re: %RADIUS-4-RADIUS_ALIVE | %RADIUS-4-RADIUS_DEAD help

2009-04-27 Thread A . L . M . Buxey
Hi, Same box. and you do live accounting database insertions? This sounds to me very much like the classic 'tables have now grown just too big' - everything works fine then barfs one day. the request isnt getting serviced in time therefore its marking as dead..check your query times...remove

Re: problems with some libraires

2009-04-24 Thread A . L . M . Buxey
Hi, *casa:/usr/local/etc/raddb# radiusd -X radiusd: error while loading shared libraries: libfreeradius-radius-2.1.5.so: cannot open shared object file: No such file or directory* with the current 2.1.4 release there is an identity crisis - please check the source code and replace the 2.1.5

Re: eap-peap inner outer identity

2009-04-23 Thread A . L . M . Buxey
Hi, Nearly all of them haven't been updated in *years*. i.e. Since long before 2.0 was released. They are not just wrong, they are actively harmful. yeh. most of them are from 2006/2007 era and are 'heres how I configured FreeRADIUS 1.x in some wierd way to do this' - which, whilst may

Re: eap-peap inner outer identity

2009-04-23 Thread A . L . M . Buxey
Hi, Per, if you read the debug log you will clearly see the problem. (cutting everything until the auth occurring. rad_recv: Access-Request packet from host 127.0.0.1 port 43395, id=1, length=168 User-Name = 0016dbd4b7d5 User-Password = 0016dbd4b7d5 NAS-IP-Address = 192.168.1.1

Re: Hello Alan

2009-04-23 Thread A . L . M . Buxey
Hi, When I start it for the first time, it builds all of the 'fake' certs okay and runs properly. (I am not sure if this would be an OpenSSL error or FreeRADIUS error. What would you think the best way to troubleshoot this would be? Or do you have any helpful hints?) However, when

Re: Releasing 2.1.5 or 2.1.6

2009-04-22 Thread A . L . M . Buxey
Hi, I noticed this version mismatch too: radiusd -v returns 2.1.5 when built from the 2.1.4 tarball. thats exactly what John was talking about I'd expect the next version to be 2.1.6 with 2.1.5 marked in changelog as a short-term interim release. alan - List info/subscribe/unsubscribe? See

Re: Possible bug in rlm_perl

2009-04-21 Thread A . L . M . Buxey
Hi, Ok, but if I do not filter out the extra slashes then after the perl module returns, freeradius gives the error that the User-Name field does not match the peap identity. Then it shows the User-Name with too many slashes (four slashes). If, in my perl module, I filter out two slashes

Re: problev with radius

2009-04-17 Thread A . L . M . Buxey
Hi, Fri Apr 17 09:52:09 2009 : Auth: Login OK: [miracle] (from client st17-gw port 367362 cli 00:14:A4:46:73:26) Fri Apr 17 09:52:12 2009 : Auth: Login OK: [stepanov] (from client st17-gw port 367363 cli 00:0E:A6:3A:A5:4E) Fri Apr 17 09:52:13 2009 : Auth: Login OK: [260130] (from client

Re: FreeRADIUS 2 Installation failed on ubuntu hardy

2009-04-17 Thread A . L . M . Buxey
Hi, My installation process and other steps i took can be found on this link: http://voiprookie.blogspot.com/ I tried to install it several time but no luck, first I used aptitude which installed the 1.x version so i removed it and then I used synaptic to install that didn't work, finally

Re: Freeradius server not starting!

2009-04-10 Thread A . L . M . Buxey
Hi, now its giving like this... [r...@localhost init.d]# /usr/local/fnmt/etc/init.d/radiusd start Starting FreeRADIUS:Fri Apr 10 07:15:32 2009 : Info: Starting - reading configuration files ... radiusd # ps -eaf|grep radiusd root 4412 31100 0 07:15 pts/000:00:00 grep radius

Re: Sending Access-Challenge

2009-04-10 Thread A . L . M . Buxey
Hi, But when I try with eap-ttls eap-md5/eap-mschapv2, eap-peap eap-mschapv2 it fails: PEAP works but TTLS fails - so, does your eap.conf have ttls configured? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius-server-2.1.4 make fails

2009-04-10 Thread A . L . M . Buxey
hi, fixed in CVS IIRC - for now, enable vmps support and it'll compile alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Install FreeRadius with Python enabled

2009-04-08 Thread A . L . M . Buxey
Hi, My Server Configuration: CentOS release 5 (Final) FreeRadius 2.1.4 Python 2.5.2 you need the -devel packages for programs you want support for alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius + aironet 1131AG

2009-04-08 Thread A . L . M . Buxey
Hi, Hi! Please write me some links to materials where i can find how to configure freeradius with Cisco AP 1131 AG. I need to use it for eduroam. cisco configuration guide alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: of Mac and Men

2009-04-07 Thread A . L . M . Buxey
Hi, thanks for the list I can confirm all of these issues. Also, if you have WPA/AES turned on, then the Mac wont touch the lovely WPA2/AES - ie it wont do 802.11n properly. if you reratify the wifi so you only do WPA/TKIP and WPA2/AES then the Mac is a _little_ happier I can also confirm

Re: of Mac and Men

2009-04-07 Thread A . L . M . Buxey
Hi, Let's not put Lenny out of his misery just yet. I've never had problems with EAP-TTLS on Macs, I've actually started recommending people use it, as it appears to be slightly more efficient than PEAPv0 (based purely on the number of rounds it takes to complete), and far better documented.

Re: of Mac and Men

2009-04-07 Thread A . L . M . Buxey
Hi, Have you actually traced the wireless traffic (passively), are you sure it's the Macs at fault with this one? as everything works fine on the same Mac when it runs Vista (yes, I know...) and works all okay on random PCs and PDAs/smartphones..the big greasy pointy finger is pointing

of Mac and Men

2009-04-06 Thread A . L . M . Buxey
hi, taking some Steinbeck metaphor too far... oh, how I wish Lenny were a code name for MacOSX rather than Debian... anyway, or lovely friend Lenny or having a few issues compared to his friend George. Lenny wants to have the lovely Wifi...but cant. You see, Lenny has 'issues' and some of these

Re: need help advice getting started with freeradius

2009-04-05 Thread A . L . M . Buxey
Hi, Lol just actually read some stuff on WPA and learnt abit more about EAP. I realise now that TTLS does not require client certificates like I previously thought only the server. Apologies for this miss understanding. Although I do realise now that SecureW2 would be required to give my

Re: Windows XP hangs forever during PEAP auth on freeradius withwinbind/AD backend

2009-04-04 Thread A . L . M . Buxey
Hi, The howto you sent me says If all goes well, you should see authentication succeeding (NT_STATUS_OK). You should also see the NT_KEY output, which is needed in order for FreeRADIUS to perform MS-CHAP authentication. I (0x0) the output being referred to or is something missing here? what

Re: debug log and syslog

2009-04-03 Thread A . L . M . Buxey
hi, why not use the raddebug functionality so you can debug the live server when you want alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: debug log and syslog

2009-04-03 Thread A . L . M . Buxey
Hi, good advice, don't know that tools but it seems interesting however I'am not sure it is available in my version ? freeradius-2.0.3-3.el5 how can I check, where to find a doc ? no. not available - you need to run 2.1.4 for these new features alan - List info/subscribe/unsubscribe? See

Re: proxy setup questions

2009-04-02 Thread A . L . M . Buxey
Hi, Here's the relevant portion of my proxy.conf: although old, proxying works in 1.0.1. the bit that doesnt work here is when you say 'relevant portion' - no, its not the relevant portion at all - you've got something else going on in proxy.conf please supply rhe whole file - I dont care if

Re: Handling of duplicates in clients.conf

2009-03-26 Thread A . L . M . Buxey
Hi, I'm running FR 2.0.3 and I just found that if there is more than one client with the same IP address in clients.conf, then it will stop processing the remainder of the file and continue startup. The only indication it has done this are 2 error messages that are easily missed when

Re: API

2009-03-26 Thread A . L . M . Buxey
Hi, Please I'd like to know if with freeradius-server-2.1.3 , i must install freeradius-ldap before synchronize a ldap database to my radius server; Is-it necessary also to install freeradius-dialupadmin before creating An API? These two modules aren't integrated in freeradius-server-2.1.3 ?

Re: Handling of duplicates in clients.conf

2009-03-26 Thread A . L . M . Buxey
Hi, Thanks for taking the time to share your thoughts Alan. I recently started investigating SQL for client and huntgroup definitions and I appreciate your insight. Does using the SQL approach still require a server restart to refresh any changes? Do you know if there are any plans to

Re: Get fail [MS-CHAP2-Response is incorrect] while proxy the mschapv2between two Freeradius 2.1.4

2009-03-25 Thread A . L . M . Buxey
Hi, But username isn't. You can't strip the username. yep. add 'nostrip' to the proxy section for that realm on the proxy server alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Login to Cisco devices through freeradius

2009-03-20 Thread A . L . M . Buxey
Hi, There is nothing related to eap to comment out in these files... Should I create a certificate? Is it compulsory? hang on - do you actually HAVE any EAP cert/CA files that you are referencing in eap.conf? read eap.conf - see what files it is trying to read (cert, CA , pkcs12, random,

Re: Login to Cisco devices through freeradius

2009-03-20 Thread A . L . M . Buxey
Hi, RADIUS:/etc/raddb/certs # ls -l total 104 -rwxrwxrwx 1 root root4210 Mar 17 10:49 01.pem -rwxrwxrwx 1 root root4441 Nov 19 14:20 Makefile -rwxrwxrwx 1 root root5343 Nov 19 14:20 README -rwxrwxrwx 1 root radiusd 462 Nov 19 14:20 bootstrap -rwxrwxrwx 1 root radiusd 1288 Nov

Re: FreeRadius with Postgresql

2009-03-19 Thread A . L . M . Buxey
Hi, On following the messages; this is what I get from running freeradius -X but before point it to PostgreSQL it runs fine. snip rlm_sql (sql): Could not link driver rlm_sql_postgresql: rlm_sql_postgresql.so: cannot open shared object file: No such file or directory rlm_sql (sql):

Re: dear everyone..

2009-03-19 Thread A . L . M . Buxey
Hi, iam a new bie freeradius user, i have a duty from my lecture to build a hotspot captive portal using chillispot and freeradius. now i make it, chilispot and freeradius working well on ubuntu machine, but the problem is my lecture want me to do stress test on the radius server to make

Re: FreeRadius with Postgresql

2009-03-19 Thread A . L . M . Buxey
Hi, I install the freeradius from the Ubuntu repo. yep - and as explained in my message, you didnt install all the required freeradius packages that ubuntu give you, for example http://packages.ubuntu.com/hardy/freeradius-postgresql apt-get install freeradius-postgresql ..and for other

Re: dear everyone..

2009-03-19 Thread A . L . M . Buxey
Hi, still can't get it. can u show me please which script to do benchmarking the RADIUS server, and how to running the script,. freeradius-server-$version/doc/performance-testing read, follow, run. alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Perl/Peap-MSChapV2 Issues

2009-03-19 Thread A . L . M . Buxey
Hi, you dont have a LOCAL defined in proxy.conf - set that. you are allowing EAP to come before perl, it seems, in your auth or post-auth sections. also, are you hardcoding Auth-Type ? it appears that you are. that is bad in general. if the PERL isnt being called check that you have enabled

Re: packet freeradius-mysql for RH

2009-03-19 Thread A . L . M . Buxey
Hi, I need the packets freeradius-mysql... I have this: freeradius-mysql-1.1.3-1.2.el5.i386.rpm but my freeradius is 2.1.3 and this rpm don´t work. I have Red Hat 5.1 you've built this yourself? if so, you need to install the mysql-devel package FIRST, then build freeradius (do make

Re: FreeRadius 2.0.5... canŽ t make it work

2009-03-18 Thread A . L . M . Buxey
hi, the magic stuff is here: Listening on authentication address * port 1812 Listening on accounting address * port 1813 Ready to process requests. there you go! its ready and listening. but wait! when you test with radtest you see nothing in that debug output? what can that mean? well, the 2

Re: FreeRadius only works in debug mode

2009-03-18 Thread A . L . M . Buxey
Hi, So, unless there's another location that the radiusd user needs access to? yes, /var/run/ whatever - chek the variables at top of radiusd.conf to see what/where it looks. you can also use 'strace' on the daemon, output the output to a file and check all the file open stuff. alan - List

Re: FreeRadius with Postgresql

2009-03-17 Thread A . L . M . Buxey
Hi, Please link me to a resources on how to make FreeRadius to work with postgreSQL on Ubuntu 8.04 LTS? follow the usual MySQL/SQL stuff - just use postgres instead - ie 1) install postgres 2) configure postgres 3) install FreeRADIUS with postgres support 4) configure FreeRADIUS part 4

Re: Radius and performance

2009-03-17 Thread A . L . M . Buxey
Hi, but it does not show (for example) what happens when freeradius is stopped and restarted before all entries in the detail file processed : Does it re-process everything, or does it ignore everything and only process new detail log. if you run it, you'll see what it does and how it does

Re: Radius and performance

2009-03-17 Thread A . L . M . Buxey
Hi, Sorry for bothering but what if detail file is on daily basis ... detail-20090101 for example... As Ivan says - if you are using buffered-sql and tking in that detail file, then there will be nothing to rotate or deal with - everything that is currently in the detail file get slurped into

Re: Relaying of accounting requests between Freeradius servers

2009-03-17 Thread A . L . M . Buxey
Hi, I have finally been able to upgrade my secondary freeradius server to 2.1.3 and I must commend everyone on their hard work, the changes are great :) any reason why not 2.1.4 ? :-) Is my understanding in this correct, that server 1 will send the request to server 2, and server 2

Re: MS-CHAP2 Failure

2009-03-17 Thread A . L . M . Buxey
Hi, I've made no progress in finding a solution to my MSCHAP problem. To summarize, Winbind and FreeRadius authenticate via PAP fine on both servers (RedHat V5), but MSCHAP fails on one of the two (see below). I tried tar'ing up the entire /etc/raddb directory and copied it to the

Re: FreeRadius only works in debug mode

2009-03-17 Thread A . L . M . Buxey
Hi, My other email to the list from last week appears to have disappeared into the ether...probably too big with the whole config file. Hopefull someone can offer advice on this issue. If I start up radiusd (on SuSE/OES linux, install from Yast) with the standard script in init.d it

Re: Logging the return code from the ldap authentication to SQL.

2009-03-16 Thread A . L . M . Buxey
Hi, if (rejected) { are you sure sucha return code is available and comparable in such a way? looks like 'rejected' got matched...possibly because the check went okay - a value of 0 - rejected isnt defined...has a value of 0 too? just a guess!

Re: MS-CHAP2 Failure

2009-03-16 Thread A . L . M . Buxey
hi, the one that fails is failing at the mschap phase - ntml_auth etc - so that server isnt configured the same as the other.. or if the config is the same, its not able to talk to the AD as the other one can. alan - List info/subscribe/unsubscribe? See

Re: Help setting up machine auth with peap

2009-03-13 Thread A . L . M . Buxey
Hi, I do see the Exec-Program output: Must change password (0xc224) which to me means the computer account password has expired? I tried removing and re-adding the computer to the domain but get the same error. you are right - the password needs changing - this is MS proprietary code

Re: Running an external script

2009-03-12 Thread A . L . M . Buxey
Hi, Thanks for your reply, Ivan. So I don't need to update control to place a user in a vlan? If I can safely remove this section, that's my problem solved - thanks. this sort of stuff needs to go into the RADIUS REPLY. you can use eg PERL to do this, see the examples that come with the

Re: How to allow nas'es to serve only groups of clients?

2009-03-12 Thread A . L . M . Buxey
Hi, Thank you for help. I try to do as you say and put this to authorize section after preprocess: preprocess # allow hotspot users only if (SQL-Group != 'Spot') { reject } if (SQL-Group != /Spot/) ? alan - List

Re: Re: No accounting Freeradius + EAP/PEAP/TLS

2009-03-12 Thread A . L . M . Buxey
Hi, The Zinwell manual didn't say anything about enabling account. My Freeradius is configured with default values, only things I changed was to use EAP/PEAP and freeradius, at radius database I configured tables NAS, Usergroup, radcheck ang groupreply(Auth-Type:=EAP). if it doesnt

Re: Dropping requests when no authentication possible

2009-03-12 Thread A . L . M . Buxey
Hi, Is there any way to force a logic whereby if the ldap module fails, it would drop the RADIUS request on the floor, to make it look like a service failure to the client? Kinda wrecks our resiliency model if not! We're only using a single ldap server per box, but even if we were using other

Re: [How To] Freeradius 2.14 ( PEAP – MSCHAP)

2009-03-11 Thread A . L . M . Buxey
Hi, For thoses, who are interested by setting up PEAP/MSHCAP under Freeradius 2.14, I wrote a simple how-to. I hope it could help someone. :) Thanks for the how-to. Sorry if this is such a basic question, but what are the advantages of using freeradius for this purpose (PEAP/MSCHAP)

Re: Log says duplicate requests, CPU maxing out

2009-03-11 Thread A . L . M . Buxey
Hi, The debug output for one such client is below: (chap/mschap/suffix returns noop. I don't know what that means.) 'no operation' - they had nothing to do, didnt see anything to do or didnt need to do anything (in basic speak). if your system is configured for one or 2 types of known auth

Re: [How To] Freeradius 2.14 ( PEAP – MSCHAP)

2009-03-10 Thread A . L . M . Buxey
hi, nice - a good compendium of other resources to make a complete task. one small quirk though, you say its for FR 2.14 - in fact, its for FR 2.1.3 - (2.1.4 isnt yet released) alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: [How To] Freeradius 2.14 ( PEAP – MSCHAP)

2009-03-10 Thread A . L . M . Buxey
Hi, one small quirk though, you say its for FR 2.14 - in fact, its for FR 2.1.3 - (2.1.4 isnt yet released) correction - 2.1.4 is out - I've finally caught up with todays email - but your guide references 2.1.3 and downloads 2.1.3 - hope that helps! :-) alan - List

Re: Version 2.1.4 has been released

2009-03-10 Thread A . L . M . Buxey
hi, thanks for the rad_assert pointers etc. still coming a cropper on another part of the build process: gmake[6]: Entering directory `/usr/src/freeradius-server-2.1.4/src/modules/rlm_smsotp' gmake[7]: Entering directory `/usr/src/freeradius-server-2.1.4/src/modules/rlm_smsotp' gmake[7]: ***

Re: Version 2.1.4 has been released

2009-03-10 Thread A . L . M . Buxey
Hi, I'll re-spin 2.1.4, unless there are objections. for reference, i did the old classic 'rm -rf src/modules/rlm_smsotp' and 'make install' then worked (it was the install part failing with that message, not the main make process). it built. it runs fine (after blowing away the old

Re: radius proxy senario

2009-03-09 Thread A . L . M . Buxey
Hi, Hi I'm putting the following code under /etc/freeradius/site-available/default, authorize section just after preproccess if (User-Name =~ ^ABC\/) { update control { Realm == %another_realm} } But i'm getting such error: Expected

Re: radius proxy senario

2009-03-09 Thread A . L . M . Buxey
Hi, if (%{User-Name} =~ /^ABC\// ) { if (%{User-Name} =~ /^ABC\// ) { read a few online regex resources. ++? if (%{User-Name} =~ /^ABC\//) expand: %{User-Name} - ABC/use...@my_realm ? Evaluating (%{User-Name} =~ /^ABC\//) - FALSE ++? if (%{User-Name} =~ /^ABC\//) - FALSE this

Re: What does 'radius -C' do? (2.1.3)

2009-03-09 Thread A . L . M . Buxey
Hi, Mike Diggins wrote: According to the documentation, radiusd -C is supposed to Check configuration and exit. I was assuming that would catch errors in the configuration that might prevent it from restarting. However, if I intentionally mangle the configuration to the point it won't

Re: radiusd server does not respond to radtest from another host

2009-03-09 Thread A . L . M . Buxey
Hi, Thanks it was the Linux firewall. I opened UDP ports 1812:1816 and everything works any reason for 1815 and 1816 ? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: What does 'radius -C' do? (2.1.3)

2009-03-09 Thread A . L . M . Buxey
Hi, It checks: a) if the configuration files are formatted correctly b) if some modules can be loaded If more things need to be checked, we will need a patch to add that functionality. much as thought. is it also the case that it only checks stuff that can be 'HUP'd' ?

Re: Freeradius 2.1-1: failure modes

2009-03-09 Thread A . L . M . Buxey
Hi, Right now FreeRadius returns reject to NAS rlm_sql (sql): Failed to connect DB handle #8 rlm_sql (sql): reconnect failed, database down? rlm_sql_getvpdata: database query error [sql] SQL query error; rejecting user rlm_sql (sql): Released sql socket id: 8 ++[sql] returns fail Sending

Re: radius proxy senario

2009-03-09 Thread A . L . M . Buxey
Hi, Thanks Alan With this: if (%{User-Name} =~ /^ABC\//) { update request { Realm := 'another_realm' } } The regex is working by now, but the other problem exist, the rewrite not working properly. dont play with User-Name!

Re: What does 'radius -C' do? (2.1.3)

2009-03-09 Thread A . L . M . Buxey
Hi, Err.. try echo $? after that. It doesn't print out log messages to stdout unless you also do -X. I was about to say the same thing - the man page clearly states that it fails with a value - this is a shell fail, not a human readble fail - exit value isnt 0 therefore something is wrong.

Re: radius proxy senario

2009-03-07 Thread A . L . M . Buxey
Hi, 1. I have a local realm (suffix), xyz.com. I'm using freeradius 2.1.3+mysql. 2. My own user's username in mysql radcheck table is store in usern...@xyz.com format 3. A person want me to proxy his prefix ABC/his-customer-usern...@myrealm to his radius server, i.e:

Re: failed to receive Accounting Response

2009-03-07 Thread A . L . M . Buxey
Hi, Ok! Then I have one a question about moving Accounting packets through my network: When I login to cisco on log server(radius server) I racieve a: tcpdump port 1813 15:48:00.281073 IP 192.168.255.10.radacct carlogg.radacct: RADIUS, Accounting Request (4), id: 0x67 length: 93

Re: radiusd server does not respond to radtest from another host

2009-03-07 Thread A . L . M . Buxey
Hi, Next I tried testing radiusd using radtest from a 2nd host (10.10.10.10), which I had added previously added to the clients.conf (Note I can successfully ping the radius server 10.10.10.11 from this 2nd host 10.10.10.10).?But, I get no response from radius acc-request on either the

Re: Production servers num_sql_socks

2009-03-05 Thread A . L . M . Buxey
Hi, Granted your DB is fast enough to query quickly. Upping this value on a slow DB will severely degrade performance. What's sort of values are you guys using for production servers? we found that any value over 20 caused issues with mysql... we moved to postgresql anyway a year back.

Re: Production servers num_sql_socks

2009-03-05 Thread A . L . M . Buxey
Hi, If it is not a secret, how many users do you have (active users in the same time) and how many connections per minute can your system handle without problems. around 15k concurrent users, hundreds of thousand per minute could be handled (when we last did a load test) alan - List

Re: New FR server: CentOS 5 or Ubuntu 8

2009-03-02 Thread A . L . M . Buxey
Hi, Please accept my apologies for this complicate question. I need make a new FR server from sources with mysql support, and I have only two OS options: CentOS 5 or Ubuntu 8. I used only FreeBSD, but now I have only these two options. Any suggestions? either will be alien to you. I

Re: FW: upgraded from freeradius 1.1.3 to 2.0.4

2009-02-19 Thread A . L . M . Buxey
Hi, Well, I didn't expect this kind of reactions. I tried to give as much information as I had. First of all I upgraded to the newest packages of debian etch before I did a dist-upgrade to lenny. With the latest version of etch it still worked. The latest version in debian lenny is the

Re: Freeradius is crashing in krb auth

2009-02-16 Thread A . L . M . Buxey
Hi, The setup that works well is running FreeBSD 7.0 Stable on an i386 system. The one that keeps crashing is running FreeBSD 7.1 PreRelease on an AMD system. so 2 totally different systems then. Anyone have any ideas about what is happening here? I think theres a nice hint with

Re: No authenticate method using Mysql

2009-02-16 Thread A . L . M . Buxey
hi, you've edited your ocnfigs beyond all hope and reasonable anount - why dont you use the sites-enabled files and do minor edits to the default config? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

FreeRADIUS with some HP Multifunction printers

2009-02-11 Thread A . L . M . Buxey
hi, I wonder if anyone can help or has seen such behaviour. We are running FreeRADIUS on site extensively - for wireless and wired authentication. the perennial issue of printers + 802.1X has raised its head again - and this time we're trying to hit it head on - configure them to use 802.1X ! (ie

Re: add: I Can't compile freeradius2.1.3 with RHEL4

2009-02-11 Thread A . L . M . Buxey
Hi, the problem is always listen.c:99:1: directives may not be used inside a macro argumentlisten.c:98:54: unterminated argument list invoking macro rad_assert in main/src/listen.c By the way,I have try to install 2.1.3 on serval machine with RHEL4U7 but face the same problem.

Re: FreeRADIUS with some HP Multifunction printers

2009-02-11 Thread A . L . M . Buxey
Hi, So once you enable authentication and the printer fails to authenticate, it won't let you Telnet into the jetdirect card or use the web interface until you do a cold restart (and clear all the 802.1X settings)... tell me about it! even if you let it onto via a failed auth = okay it still

Re: FreeRADIUS with some HP Multifunction printers

2009-02-11 Thread A . L . M . Buxey
Hi, The printers are *claiming* that they're doing PEAPv0. However, the protocol they're running is actually PEAPv2. ..on this note, any update on when/if FR will do PEAPv1 and PEAPv2? (i note more and more devices are coming with such options - eg Nokia S60 smartphones have all the boxes

Re: chap authentication and freeradius

2009-02-02 Thread A . L . M . Buxey
Hi, What is wrong ??? well, the debug clearly shows these lines: [chap] login attempt by ale with CHAP password [chap] Cleartext-Password is required for authentication ++[chap] returns invalid Failed to authenticate the user. Login incorrect (rlm_chap: Clear text password not available):

Re: Cisco Aironet 1130ag dynamic VLAN assignment

2009-01-23 Thread A . L . M . Buxey
Hi, I have been having trouble recently with getting dynamic VLAN assignment working on my Cisco AP. Clients are successfully authenticating with FreeRADIUS. However, they do not seem to be picking up extra attributes from the users file (below is the relevant portion of it). wgraeber

Re: regular expression problem on 2.1.3

2009-01-23 Thread A . L . M . Buxey
Hi, Hi, I have updated my Freeradius from 2.0.5 to 2.1.3 and am having a problem with the regular expressions I am using in the users file. If I provide a simple example users file I am testing against: DEFAULT NAS-IP-Address =~ 192.168.1.1|10.0.1.1 (192.168.1.1|10.0.1.1) ?

Re: FreeRADIUS + MSCHAPv2 + Vista

2009-01-22 Thread A . L . M . Buxey
Hi, radiusd -X - how are you auth'ing the actual TLS stuff - ntml_auth? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Strage problem

2009-01-21 Thread A . L . M . Buxey
Hi, Any idea? you've got something not liking the big fragments and chucking stuff around/away - got a UDP fragment throw-away firewall between the freeradius and IAS? got iptables on the Linux box configured up? change the eap.conf to have a small fragment size and see what happens alan -

Re: help with freeradius + winxp

2009-01-19 Thread A . L . M . Buxey
Hi, On Mon, 2009-01-19 at 13:26 +0100, t...@kalik.net wrote: Server didn't build with OpenSSL support. Fix that if you want to use peap. Ivan, Thanks for getting back and help, I appreciate that. I've checked if I have openssl: r...@radius:/# dpkg -l | grep ssl ii libssl0.9.8,

Re: help with freeradius + winxp

2009-01-19 Thread A . L . M . Buxey
Hi, I was running script during install here are WARNINGs: r...@radius:/home/radius# grep WARNING ../logs/configure configure: WARNING: snmpget not found - Simultaneous-Use and checkrad.pl may not work configure: WARNING: snmpwalk not found - Simultaneous-Use and checkrad.pl may not work

Re: 802.1X wireless, FR, and accounting...

2009-01-14 Thread A . L . M . Buxey
hi, fwiw, we see many session times of 00:00 sent from our cisco kit. its a pain because a value of 0 isnt valid with the default SQL code and statements (obviously). we can certainly liaise with this issue - some of it, i believe, is due to the way the LWAPP protocol ships clients into mobility

Re: eap/tls freeradius openssl

2009-01-13 Thread A . L . M . Buxey
hi, linux admin task: you can also do 'make -n install' and this will show you what and where make is going to put the files (its a test/dummy run) - then you can grep through the output for eg /usr/local and see what files to get rid of. as well as the tools themselves - radiusd, radtest etc,

Re: Optimum MYSQL settings

2009-01-13 Thread A . L . M . Buxey
hi, gosh. its such a wide question (well, the answer can be very open...). there are many many ways to optimise the DB - you can chuck more memory at the server settings - increase the buffers etc. you can add more index keys to the tables... you can change the DB engine - eg InnoDB instead or

Re: 3gpp2 parameter starts with '\0'

2009-01-12 Thread A . L . M . Buxey
Hi, I need to store ESN value to my database, but it comes in format[3GPP2-ESN = \000\000\000\000\000\000\0BBF636]. Freeradius counts '\0' as the end of the line and puts blank instead of actual parameter value. Not only ESN comes in that format but [Acct-Session-Id = 000\000] does

<    1   2   3   4   5   6   7   8   9   10   >