RE: freeRADIUS+samba3.0.1+AD(multiple domains)

2008-02-28 Thread Hangjun He
Great news! We are using krb5-1.3.2 and samba-3.0.1. These 2 version support multiple domains? Can you give me some example about how to configure krb5.conf and smb.comf? Thanks. John Joe Vieira [EMAIL PROTECTED] 写道: But there are multiple domains in active-directory. How

回复: Re: rlm_dbm can not work?

2008-02-26 Thread Hangjun He
It works. Thanks. There is another question: How to delete a user from rlm_dbm? I delete the user from the users file. and do rlm_dbm_parser -i users -o xxx.db, But the deleted user does not disspear from xxx.db. John. [EMAIL PROTECTED] 写道: Hi, [EMAIL PROTECTED] raddb]#

freeRADIUS+samba3.0.1+AD(multiple domains)

2008-02-26 Thread Hangjun He
Hi, We are using freeRADIUS 1.1.6. and samba 3.0.1 talk to active-directory. Followed by: http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO Now it can work. But there are multiple domains in active-directory. How to configure freeRADIUS or samba can let it

rlm_dbm can not work?

2008-02-24 Thread Hangjun He
Hi, I am using freeRADIUS 1.1.6. I can not let rlm_dbm work. Result of rlm_dbm_cat: [EMAIL PROTECTED] raddb]# pwd /usr/local/etc/raddb [EMAIL PROTECTED] raddb]# rlm_dbm_cat -f users.db hhe4 Cleartext-Password := hhe123 Reply-Message = Hello

vocera(with Peap)+AP+freeRADIUS

2008-02-18 Thread Hangjun He
Hi, I am using freeRADIUS 1.1.7. Notebook with odyssey client (peap mschap-v2) can talk to freeRADUS well. But when I use Vocera client, which can support peap + mschap-v2, It does not work. debug message (see more debug message in attachment): ... rad_recv: Access-Request

Peap(inner eap-GTC)//: Re: Peap (inner eap-popt ) issue

2008-02-01 Thread Hangjun He
... John Alan DeKok [EMAIL PROTECTED] 写道: Hangjun He wrote: hi, I am using Odyssey Client Manager and freeRADIUS 1.1.6. When I set peap with inner eap-mschap-v2, It works well.When I change inner eap type to eap-popt, seems can not work. Why do you think FreeRADIUS supports EAP-POPT

Peap (inner eap-popt) issue

2008-01-31 Thread Hangjun He
hi, I am using Odyssey Client Manager and freeRADIUS 1.1.6. When I set peap with inner eap-mschap-v2, It works well.When I change inner eap type to eap-popt, seems can not work. eap.conf: eap { default_eap_type = md5 timer_expire = 60 ignore_unknown_eap_types = no

rlm_dbm question?

2008-01-11 Thread Hangjun He
I use rlm_dbm_parser to add 2 users in file users_output. Debug info shows added successfully. But why I can not find file users_output? Where to find this file? rlm_dbm_cat shows 2 users added, right? [EMAIL PROTECTED] rlm_dbm]# ./rlm_dbm_parser -c -i users -o users_output -x Use

User with ntdomain authenticate with freeRADIUS + AD

2007-12-21 Thread Hangjun He
Hi, freeRADIUS version 1.1.6. When I use DOMAIN\user format, Can work. When I use [EMAIL PROTECTED] format, Can not work. Why? Thanks! John - 雅虎邮箱传递新年祝福,个性贺卡送亲朋! - List info/subscribe/unsubscribe? See

RE: Can I get group-name from Active-directory? [sec=unclassified]

2007-12-19 Thread Hangjun He
EAP-Message = 0x03090004 Message-Authenticator = 0x User-Name = hhe Finished request 9 Ranner, Frank MR [EMAIL PROTECTED] 写道: From: [EMAIL PROTECTED] g [mailto:[EMAIL PROTECTED] adius.org] On Behalf Of Hangjun He Sent: Monday, 17 December 2007

Can I get group-name from Active-directory?

2007-12-16 Thread Hangjun He
FreeRADIUS 1.1.6 + samba-tools + active-directory. Can I get user's group-name by rlm_ldap? How? Following is result of ldap-search.(Using ldap client) # Paul Le, Users, test.com dn: CN=Paul Le,CN=Users,DC=test,DC=com objectClass: top objectClass: person objectClass:

Question about nt-domain.

2007-12-14 Thread Hangjun He
Hi, FreeRADIUS 1.1.6. Use users file as user store. When I use username/password, It can work. When I user username/password/domain, It not work. I try to set preprocess module with_ntdomain_hack = yes. I get rlm_eap: Identity does not match User-Name, setting from EAP Identity. I

Re: Question about windowsXP(Odessey Client) + EAP-TLS with freeRADIUS

2007-12-13 Thread Hangjun He
Yes. It sounds good. Check common name in the certificate with databases(users or others). John [EMAIL PROTECTED] 写道: Hangjun He wrote: And I use EAP-TLS and with correct certs. Even if I set wrong username in Odessey Client, freeRADIUS will return success.(check_cert_cn not set

Question about windowsXP(Odessey Client) + EAP-TLS with freeRADIUS

2007-12-12 Thread Hangjun He
Hi, I am using freeRADIUS 1.1.6. And I use EAP-TLS and with correct certs. Even if I set wrong username in Odessey Client, freeRADIUS will return success.(check_cert_cn not set). Can I let freeRADIUS to check if username in the users file or other database? If not, reject

Which RADIUS server can support RFC3576?

2007-11-29 Thread Hangjun He
I know freeRADIUS can't suport RFC3576 (Dynamic Authorization Extensions to RADIUS). Do you know which one can support it? - 雅虎邮箱,终生伙伴! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

freeradius support eap-fast?

2007-11-26 Thread Hangjun He
Hi, Eap-fast introduction from cisco said freeradius support eap-fast. Is it right? http://www.t11.org/ftp/t11/pub/fc/sp-2/07-595v0.pdf John - 雅虎邮箱,终生伙伴! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

回复: Re: freeRADIUS with 2 Active-dire cotory

2007-11-07 Thread Hangjun He
. Nothing to do with freeradius/samba. Ivan Kalik Kalik Informatika ISP Dana 6/11/2007, Hangjun He pi�e: Hi, I use freeRADIUS1.1.6 and samba3 to talk with Active-directory. It can work well. Followed by wiki: http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO Now we want

SIGHUP works in 2.0.0?

2007-11-07 Thread Hangjun He
SIGHUP works in 2.0.0? Thanks. John - 雅虎邮箱,终生伙伴! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

freeRADIUS with 2 Active-direcotory

2007-11-06 Thread Hangjun He
Hi, I use freeRADIUS1.1.6 and samba3 to talk with Active-directory. It can work well. Followed by wiki: http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO Now we want to set up 2 active-directory, One is primary, The other is backup. If primary AD

回复: Re: freeRADIUS + Openldap with TLS

2007-11-06 Thread Hangjun He
I seems it need LDAP lib support. Alan DeKok [EMAIL PROTECTED] 写道: Hangjun He wrote: I use freeradius 1.1.6 and Openldap 2.3.32. And now It can authenticate success( freeRADIUS + Openldap with TLS TLS encrypt.) My question is how to set private-key password in radiusd.conf

回复: Re: freeRADIUS + Openldap with TLS

2007-10-29 Thread Hangjun He
= demand # default_profile = cn=radprofile,ou=dialup,o=My Org,c=UA # profile_attribute = radiusProfileDn access_attr = dialupAccess [EMAIL PROTECTED] 写道: You already have. eap.conf is a part of radiusd.conf. Ivan Kalik Kalik Informatika ISP Dana 29/10/2007, Hangjun He pi�e: Hi, I use

回复: Re: freeRADIUS + Openldap with TLS [sec=unclassified]

2007-10-29 Thread Hangjun He
Thanks. So key-file-password do not set in radiusd.conf/rlm_ldap section. I still donot know how to configure key-password in Openldap, Where I can get any document or Wiki ? Thanks. John. Ranner, Frank MR [EMAIL PROTECTED] 写道: Yes. eap.conf is part of radiusd.conf. But I

freeRADIUS with Active-derectory

2007-10-29 Thread Hangjun He
Hi, I have configured ntlm_auth in freeRADIUS talk to AD(user store). And It works well. Now I want to use ldap to get attribute from AD, It failed. It seems ldapsearch will search user's display name. And ntlm_auth will search user's user logon name. If I set display

freeRADIUS + Openldap with TLS

2007-10-28 Thread Hangjun He
Hi, I use freeradius 1.1.6 and Openldap 2.3.32. And now It can authenticate success( freeRADIUS + Openldap with TLS TLS encrypt.) My question is how to set private-key password in radiusd.conf? Is there a related variable to set, just like private_key_password in eap.conf .

Authentication question: Eap/peap + Switch + freeRADIUS + Lutos LDAP server

2007-08-23 Thread Hangjun He
Hi, Eap/peap + Switch + freeRADIUS(1.1.6) + Lutos LDAP server. Can this architecture work well? Can anyone give me some advice? Thanks a lot. John. - 雅虎邮箱,以安全著称,是值得信赖的邮箱专家! - List info/subscribe/unsubscribe? See

After signal HUP freeRADIUS Segmentation fault

2007-08-13 Thread Hangjun He
freeRADIUS version is 1.1.6.. I saw same question in mail-list(freeRADIUS 0.8), Did this problem fix?? Thanks. Nothing to do. Sleeping until we see a request. Reloading configuration files. reread_config: reading radiusd.conf Config: including file:

Re: Help: How to set VLAN by Tunnel-Private-Group-Id for user or group?

2007-08-03 Thread Hangjun He
; do the same for every VLAN. Ivan Kalik Kalik Informatika ISP Dana 2/8/2007, Hangjun He pi�e: Hi, We use peap + AP + fr + AD to authenticate user. Now It can work. But I need to get VLAN from freeradius for different user or group. How should I do?? Please give me some advice, Thanks. I saw

Help: How to set VLAN by Tunnel-Private-Group-Id for user or group?

2007-08-02 Thread Hangjun He
Hi, We use peap + AP + fr + AD to authenticate user. Now It can work. But I need to get VLAN from freeradius for different user or group. How should I do?? Please give me some advice, Thanks. I saw below debug info from maillist, from these info I guess freeradius

回复: Linux RADIUS and Active Directory =20?=

2007-08-02 Thread Hangjun He
Just follow this http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO inelec communication [EMAIL PROTECTED] 写道: I am trying to setup a Fedora Linux server to authenticate wireless users. I would like to use my AD server to get user information and use the RADIUS

回复: Re: Help: How to set VLAN by Tunnel-Private-Group-Id for user or group?

2007-08-02 Thread Hangjun He
question. Create a (vlan) group; add users/groups to the group; create Remote Access Policy; apply policy to this group; edit the policy to include those Tunnel attributes in dial-in profile; do the same for every VLAN. Ivan Kalik Kalik Informatika ISP Dana 2/8/2007, Hangjun He pi�e: Hi, We use peap

PEAP, switch, FR and MS-AD as user profile and vlan storage

2007-08-01 Thread Hangjun He
Hi, I would like to know if I can use FreeRADIUS for: PEAP, switch, FR and MS-Active Directory as user profile and vlan storage If so, can someone please shed some light/pointers ? Any info is highly appreciated. Thank you. - 抢注雅虎免费邮箱3.5G容量,20M附件! -

=?gb2312?q?=BB=D8=B8=B4=A3=BA=20Re:=20PEAP, =20switch, =20FR=20=20and=20MS-?= AD as user profile and vlan storage

2007-08-01 Thread Hangjun He
MESSAGE- Hash: SHA1 Hangjun He wrote: Hi, I would like to know if I can use FreeRADIUS for: PEAP, switch, FR and MS-Active Directory as user profile and vlan storage PEAP: Yes MS-AD: Yes See several post in this mailing list, and the FreeRadius Wiki: it is all in there. http

Help: eap/peap + 8021x + freeradius + Win2k3/AD

2007-06-27 Thread Hangjun He
Hi, list I have no samba installed in my linux. 1.freeradius + AD : When I user radtest tool to test user/password on Win2k3/AD, I can get correct answer when I set authenticate type to ldap too. 2.eap/peap + 8021x + freeradius + openldap: Success.

回复: Re: Help: eap/peap + 8021x + freeradius + Win2k3/AD

2007-06-27 Thread Hangjun He
Thanks Alan DeKok. But there are no enough memory on my linux system to install samba. What should I do? John Alan DeKok [EMAIL PROTECTED] 写道: Hangjun He wrote: * I have no samba installed in my linux.* Then you won't get PEAP to work with AD. There's a reason the howto's

回复: Re: Help: eap/peap + 8021x + freeradius + Win2k3/AD

2007-06-27 Thread Hangjun He
Can I start ldap-auth after eap authenticate failed..just like radclient. Hangjun He [EMAIL PROTECTED] 写道: Thanks Alan DeKok. But there are no enough memory on my linux system to install samba. What should I do? John Alan DeKok [EMAIL PROTECTED] 写道: Hangjun He

Problem on freeradius+openldap+tls

2007-06-25 Thread Hangjun He
hi, freeradis with openldap is OK when use cleartext communication. Now I want to use tls. openssl s_client -connect 127.0.0.1:636 -showcerts -state -CAfile /usr/local/etc/openldap/ssl/cacert.pem show the cacert /cert/key is correct. But when I use freeradis

re: Problem on freeradius+openldap+tls

2007-06-25 Thread Hangjun He
freeradius version 1.1.6 openldap version 2.3.23 opensll verson 0.9.7g Hangjun He [EMAIL PROTECTED] 写道: hi, freeradis with openldap is OK when use cleartext communication. Now I want to use tls. openssl s_client -connect 127.0.0.1:636 -showcerts -state -CAfile

re: Problem on freeradius+openldap+tls

2007-06-25 Thread Hangjun He
do_unbind connection_resched: attempting closing conn=11 sd=11 connection_close: conn=11 sd=11 TLS trace: SSL3 alert write:warning:close notify Hangjun He [EMAIL PROTECTED] 写道: freeradius version 1.1.6 openldap version 2.3.23 opensll verson 0.9.7g Hangjun He [EMAIL PROTECTED