Re: Mac-Based auth and HP chap

2009-04-29 Thread jehan procaccia
Alan DeKok wrote: jehan procaccia wrote: hello, I use FreeRADIUS Version 2.1.3, and I try a basic configuration from my HP procurve2650 to do Mac-based radius auth. for this I've setup a simple users file 005004B7252EAuth-Type := Local, Cleartext-Password := "00

Mac-Based auth and HP chap

2009-04-29 Thread jehan procaccia
hello, I use FreeRADIUS Version 2.1.3, and I try a basic configuration from my HP procurve2650 to do Mac-based radius auth. for this I've setup a simple users file 005004B7252EAuth-Type := Local, Cleartext-Password := "005004B7252E" Tunnel-type = VLAN, Tunnel-M

Re: debug log and syslog

2009-04-03 Thread Jehan PROCACCIA
a.l.m.bu...@lboro.ac.uk a écrit : hi, why not use the raddebug functionality so you can debug the live server when you want alan good advice, don't know that tools but it seems interesting however I'am not sure it is available in my version ? freeradius-2.0.3-3.el5 how can I check, where to

Re: debug log and syslog

2009-04-03 Thread Jehan PROCACCIA
d = "157.159.27.100" I tested that without succes :-( # Jehan linelog { filename = ${logdir}/jehan.log format = "JP Login OK for %{User-Name} on %{NAS-Port-Id} ..." } the file keeps been empty please let me know how to tune radiusd logging . thanks . jehan procaccia a e'crit :

Re: eap ttls certificate config

2008-10-02 Thread jehan procaccia
idate that . Alan DeKok wrote: Jehan PROCACCIA wrote: Actually I wasn't suggesting that it is a bug, A core dump is a bug. The files I suggested you read contain instructions that help us fix the bug. my inital question is how one can use that CA_path directive and what the CA_

Re: eap ttls certificate config

2008-09-30 Thread Jehan PROCACCIA
Alan DeKok a écrit : Jehan PROCACCIA wrote: See doc/bugs a link would be greatly appreciated . Ummm... this file ships with the server. If you can't find it in the "tar" file, it's usually in /usr/share/doc/something/, depending on your local installat

Re: eap ttls certificate config

2008-09-30 Thread Jehan PROCACCIA
Alan DeKok a écrit : Jehan PROCACCIA wrote: what about that CA_path directive ? why is it generating a segmentation fault when starting radiusd ? See doc/bugs Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html a link would be greatly

Re: eap ttls certificate config

2008-09-30 Thread Jehan PROCACCIA
[EMAIL PROTECTED] a écrit : pki-chain.pem contain the concatenation of our 3 level pki hierarchy ( cat itClass1.crt > pki-chain.pem ; cat itClass2.crt >> pki-chain.pem ; cat itClass3.crt >> pki-chain.pem ) Did you find somewhere in openssl documentation that you can mix .pem and crt format

eap ttls certificate config

2008-09-30 Thread Jehan PROCACCIA
hello, I try to configure my freeradius-2.0.3-3.el5 to read our certicate chain with no success :-( . neither CA_file or CA_path directives works as expected in eap.conf . here's my config: /etc/raddb/eap.conf tls { certdir = ${confdir}/certs cadir = ${confdir}/certs/CA private_key_password =

CA certificates

2008-09-05 Thread jehan procaccia
hello, we are running our own PKI with a 3 level hierarchy: it-master-class1(self-signed) -> it-ca-class2 -> it-ca-class3. it-ca-class3 signed our radius server (radiux-pkiit-2008.pem) In eap.conf file in the tls section I have tls { private_key_password = secret private_key_file = ${certdir}/ra

Re: debug log and syslog

2008-09-05 Thread jehan procaccia
[EMAIL PROTECTED] wrote: I can run debug log by starting radiusd -X , but for production, I want logs to go to a file and not stdout . http://linuxbasics.org/course/book/chap_05 indeed ;-) for now with that config I only get 2 lines in radiusd.log when I log in 802.X EAP-ttls , tellin

debug log and syslog

2008-09-05 Thread Jehan PROCACCIA
hello I can run debug log by starting radiusd -X , but for production, I want logs to go to a file and not stdout . When I start radiusd without -X I only get very few logs, how can I have equivalent to -X log with syslog or a log file ? or a least get more log the the very few ones I get with