Re: eap/peap certificate problems?

2008-04-23 Thread David Hláčik
Great , but it was not the case of freeradius 1.x which i was using and discussing about all the time. Regards, D. 2008/4/22 Alan DeKok <[EMAIL PROTECTED]>: > David Hláčik wrote: > > i did a lot of reading about certificate generation, > > This just kills me. > >

Re: eap/peap certificate problems?

2008-04-22 Thread David Hláčik
Oou, its freeradius-1.1.3-1.2.el5 :( D. 2008/4/22 Ivan Kalik <[EMAIL PROTECTED]>: > Version? If it is before 1.1.4 it will not work with Vista. > > Ivan Kalik > Kalik informatika ISP > > > Dana 21/4/2008, "David Hláčik" <[EMAIL PROTECTED]> pi

Re: eap/peap certificate problems?

2008-04-21 Thread David Hláčik
s > working, replace them with your certificates and you will know if > certificates are the problem. > > Ivan Kalik > Kalik informatika ISP > > > Dana 21/4/2008, "David Hláčik" <[EMAIL PROTECTED]> piše: > > >Hi, becouse for a period of time i was not

Re: frammed ip adress

2008-04-14 Thread David Hláčik
d to parse accounting section. D. 2008/4/14 David Hláčik <[EMAIL PROTECTED]>: > Can i before : > > DEFAULT Ldap-Group == "GroupLetters", Pool-Name := letters > DEFAULT Ldap-Group == "GroupNumbers", Pool-Name := numbers > add > > DEFAULT Pool-N

Re: frammed ip adress

2008-04-14 Thread David Hláčik
6 Ivan Kalik <[EMAIL PROTECTED]>: > ldap looks fine to me, but I don't use it. > > Ivan Kalik > Kalik Informatika ISP > > > Dana 6/4/2008, "David Hláčik" <[EMAIL PROTECTED]> piše: > > >Thanks Ivan!, > > > >can i understand it like that m

Re: frammed ip adress

2008-04-14 Thread David Hláčik
Hi, does my own ip - pools needs to be added to post-auth and to accounting section? Thanks! D. 2008/4/6 Ivan Kalik <[EMAIL PROTECTED]>: > ldap looks fine to me, but I don't use it. > > Ivan Kalik > Kalik Informatika ISP > > > Dana 6/4/2008, "David Hláčik&q

generating tls certificates for radius under centos

2008-04-10 Thread David Hláčik
Hi all, i need to generate certificate files for radius tls. I am using CentOS 5.1 and scripts in /etc/pki/tls/misc for generated own CA key, and for own keys signed with my CA. For Radius i need a server certificate with xpextensions support. How can i generate server certificate with xpextension

Re: frammed ip adress

2008-04-06 Thread David Hláčik
> DEFAULT Ldap-Group == "GroupNumbers", Pool-Name := numbers > > Ivan Kalik > Kalik Informatika ISP > > > Dana 5/4/2008, "David Hláčik" <[EMAIL PROTECTED]> piše: > > >Hi, > > > >i will describe what i am trying to achieve. > > > >T

Re: frammed ip adress

2008-04-05 Thread David Hláčik
Sorry for that mistake in last lines DEFAULT NAS-Port-Type == letters, Ldap-Group == cn=GroupLetters,ou=Groups,o=Polarion Fall-Through = no *DEFAULT Pool-Name == letters, Ldap-Group == cn=GroupLetters,ou=Groups,o=Polarion Fall-Through = no On Sat, Apr 5, 2008 at 4:38 PM, David Hláčik

Re: frammed ip adress

2008-04-05 Thread David Hláčik
Hi, i will describe what i am trying to achieve. This is my sample ldap structure users (inetOrgPerson) : cn=User1,ou=Users,o=Polarion cn=User2,ou=Users,o=Polarion cn=UserA,ou=Users,o=Polarion cn=UserB,ou=Users,o=Polariong groups (GroupOfNames) cn=GroupNumbers,ou=Groups,o=Polarion membe

Re: frammed ip adress

2008-04-02 Thread David Hláčik
e. Have a look at ippool section of radiusd.conf. > > Ivan Kalik > Kalik Informatika ISP > > > Dana 25/3/2008, "David Hláčik" <[EMAIL PROTECTED]> piše: > > >Hi, in my working solution, i have pptp (vpn) configured with radius > using > >LDAP. &g

Re: WPA enterprise

2008-03-29 Thread David Hláčik
Hi, i forgot to mention, that passwords in LDAP are stored in plaintext. Thanks! David. On Sun, Mar 30, 2008 at 2:14 AM, David Hláčik <[EMAIL PROTECTED]> wrote: > Hi i have freeradius mschap ldap working configuration - i am using it for > pptpd (VPN server) to authentific

WPA enterprise

2008-03-29 Thread David Hláčik
Hi i have freeradius mschap ldap working configuration - i am using it for pptpd (VPN server) to authentificate against freeradius with ldap . Windows VPN client can connect to our company network and use it. Next i want to add user/password auth to our WIFI (based on Dlink AP - with radius suppo

frammed ip adress

2008-03-25 Thread David Hláčik
Hi, in my working solution, i have pptp (vpn) configured with radius using LDAP. Each user has a value Framed IP Adress which will assign him exact IP adress. Currently i am rebuilding ldap structure to groups. And i want the users which will be members of group foo , to have dynamically assignet

Re: NTLM in MSCHAP

2008-03-25 Thread David Hláčik
What about that ntlm_auth - it will create from crypt nt and send it to mschap? Thanks in advance! David 2008/3/5 Alan DeKok <[EMAIL PROTECTED]>: > David Hláčik wrote: > > Hi, I have working configuration of PPTPD (Windows VPN) trought Radius > > to LDAP stored users. The

NTLM in MSCHAP

2008-03-04 Thread David Hláčik
Hi, I have working configuration of PPTPD (Windows VPN) trought Radius to LDAP stored users. The think is ,that it accepts only plain text stored passwords in ldap becouse of very well known NT-Password for MSCHAPv2 I figure out there is an option to make it work with ntlm_auth in mschap config

radius ldap tls

2007-12-16 Thread David Hláčik
Hi to all, i am finding in my radiusd.log on CentOS 5.1 Sun Dec 16 14:45:04 2007 : Error: rlm_ldap: could not set LDAP_OPT_X_TLS_REQUIRE_CERT option to allow In radiusd.conf i have use_tls to off , my ldap server (open ldap) is configured with tls support and set to not regueire certificate from