TLS Error with Freeradius 2: unkown_ca

2008-06-16 Thread Julian Stöver
Hi I'm running Freeradius2 with EAP-TLS. I've created new certificates and putted them into my certs-dir. Radius starts with no errors. But if I try to login, I get this TLS Error: rlm_sql (sql): Released sql socket id: 3 ++[sql] returns ok rad_check_password: Found Auth-Type EAP auth: t

Deny/Allow access between clients

2008-04-25 Thread Julian Stöver
Hi, I would like to know if its possible to deny/allow traffic between clients or groups. I've already searched for a solution but I just found out how to limit some ports for a user. Thanks for you help. bye julian - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users

Re: New bee to FreeRadius; need help in configuration

2008-02-05 Thread Julian Stöver
Hi, i think thats wrong. I can add SQL users without refreshing the server, and the debug mode also shows me, how the database is requested for the user data on every request! bye julian Am 05.02.2008 um 22:40 schrieb [EMAIL PROTECTED]: Hi, Deepak, Have you considered using a ldap o

Re: Cisco 1200 AP

2008-02-05 Thread Julian Stöver
freeradius bug you should post the debug log. bye julian Am 05.02.2008 um 17:30 schrieb John Melton: Hi, 1200 AP is running c1200-k9w7-mx.123-8.JEB1 -- John Julian Stöver wrote: Hello, which firmware version? bye julian Am 05.02.2008 um 17:05 schrieb John Melton: I have configured a Cis

Re: Cisco 1200 AP

2008-02-05 Thread Julian Stöver
Hello, which firmware version? bye julian Am 05.02.2008 um 17:05 schrieb John Melton: I have configured a Cisco 1200 AP for WPA2-PSK which is working with a wireless device able to connect OK. I have tried to add MAC authentication using the FreeRadius server, but have not been able to g

Re: Monitoring Tool for Freeradius

2008-02-04 Thread Julian Stöver
n't want to upgrade your firmware, you've to disable WPAv2 encryption. bye julian Am 04.02.2008 um 18:43 schrieb Julian Stöver: Hi, ok, I will search some cisco documentation for that! but if someone knows a solution i woult be thankful for a solution (to log usernames fr

Re: Monitoring Tool for Freeradius

2008-02-04 Thread Julian Stöver
Hi, ok, I will search some cisco documentation for that! but if someone knows a solution i woult be thankful for a solution (to log usernames from cisco 1360AG in radacct). thank you all for helping me bye julian Am 04.02.2008 um 18:36 schrieb Alan DeKok: Julian Stöver wrote: Hm no, I

Re: Monitoring Tool for Freeradius

2008-02-04 Thread Julian Stöver
;unix" returns ok for request 0 radius_xlat: '/var/log/freeradius/radutmp' radius_xlat: '001e528015c6' modcall[accounting]: module "radutmp" returns ok for request 0 modcall: leaving group accounting (returns ok) for request 0 Sending Accounting-Response of id 29 to 172

Re: Monitoring Tool for Freeradius

2008-02-04 Thread Julian Stöver
4.02.2008 um 17:12 schrieb Arran Cudbard-Bell: Julian Stöver wrote: Hi! I worked my radacct problem today. I fixed the most problems, so now I get all informations stored in my 'radacct'-table. But the username is saved encrypted in the database, something like '001e528015c6&#x

Re: Monitoring Tool for Freeradius

2008-02-04 Thread Julian Stöver
Hi! I worked my radacct problem today. I fixed the most problems, so now I get all informations stored in my 'radacct'-table. But the username is saved encrypted in the database, something like '001e528015c6' for username 'julian'. In the radius debug log i can read the name in cleartext.

Re: Monitoring Tool for Freeradius

2008-02-01 Thread Julian Stöver
ent to the accounting port. To no surprise it did not respond. You have to send an accounting packet to the accounting port. Ivan Kalik Kalik Informatika ISP Dana 1/2/2008, "Julian Stöver" <[EMAIL PROTECTED]> piše: I just tried radtest and radclient, with no result, but I think i

Re: Monitoring Tool for Freeradius

2008-02-01 Thread Julian Stöver
I just tried radtest and radclient, with no result, but I think i found my fault. I used the authentication port for accounting. Now I tried it with the accounting port, with this result: # echo "User-Name = julian,Password=blabla" | /usr/bin/radclient localhost:1813 acct somesecret # radc

Re: Monitoring Tool for Freeradius

2008-02-01 Thread Julian Stöver
Yes, I read it twice, but with no answer bye julian Am 01.02.2008 um 15:56 schrieb Marinko Tarlac: freeradius WIKI - SQL Howto On Feb 1, 2008 3:46 PM, Julian Stöver <[EMAIL PROTECTED]> wrote: Hi, I'm using the sql backend so i decided for getting the informations from the da

Re: Monitoring Tool for Freeradius

2008-02-01 Thread Julian Stöver
S-IP-Address}', '%{NAS-Port}', '%{NAS-Port-Type}', DATE_SUB('%S', INTERVAL (%{Acct-Session-Time:-0} + %{Acct-Delay- Time:-0}) SECOND), '%S', '%{Acct-Session-Time}', '%{Acct- Authentic}', '', '%{Connect-Info}'

Monitoring Tool for Freeradius

2008-01-31 Thread Julian Stöver
Hello, is there any monitoring tool for freeradius or another possibility to see how many people are logged in and to do some other stuff? like the monitoring tool for openvpn? Would be nice if there's something avaible! bye! julian - List info/subscribe/unsubscribe? See http://www.freeradiu

Re: Configure Cisco Aironet 1130 with PEAP/Ms-Chap2

2007-12-27 Thread Julian Stöver
Hi, first, i'm sorry for this late answer, I was in holiday. Julian Stöver wrote: after solving my problem with creating certificates i got another problem: I enabled MsCHAP in the Radius configuration The default configuration already enables mschap. Why are you editing it to &q

Re: Configure Cisco Aironet 1130 with PEAP/Ms-Chap2

2007-12-19 Thread Julian Stöver
accounting, whereas free-radius and radtest use 1812 and 1813. If I'm wrong please correct me, but might be worth checking? Rupes On 19/12/2007, Julian Stöver <[EMAIL PROTECTED]> wrote: Hi, after solving my problem with creating certificates i got another problem: I enabled MsCHAP in the

Configure Cisco Aironet 1130 with PEAP/Ms-Chap2

2007-12-19 Thread Julian Stöver
Hi, after solving my problem with creating certificates i got another problem: I enabled MsCHAP in the Radius configuration and added the server as an radius authentication and accounting server and also enables aes-ccmp and wpa2 mendatory key. but if i want to login, i get the message "lo

Re: EAP-TLS: Certificate creation doesn't work (Debian)

2007-12-15 Thread Julian Stöver
to look at certs.sh and modify the paths in that file. aswell the openssl.cnf file. its a kindda workaround but i dont have a better way. or you can echo 00 > serial On 15/12/2007, Julian Stöver <[EMAIL PROTECTED]> wrote: Hi! I'm using Freeradius 1.1.3 under Debian Etch! I want to co

EAP-TLS: Certificate creation doesn't work (Debian)

2007-12-15 Thread Julian Stöver
Hi! I'm using Freeradius 1.1.3 under Debian Etch! I want to configure Freeradius with EAP-TLS in my network but there some problems with the certficate creation. I get this message when i run the file "certs.sh" in the "docs/ freeradius/examples/" directory: