Re: pap always returns noop for windows dialup authentication [solved]

2013-09-24 Thread paul trader
(and user info in general) in the users file is important for windows authentication. strangely enough, it doesn't seem to matter for a linux dialup, though. thanks to everyone for the help! regards, paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: pap always returns noop for windows dialup authentication [solved]

2013-09-24 Thread paul trader
authenticate but not the windows ones. only after i tried moving the entry directly under the 'steve' example did it start working, so i moved the $INCLUDE statement there too. regards, paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: pap always returns noop for windows dialup authentication

2013-09-23 Thread paul trader
. regards, paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

pap always returns noop for windows dialup authentication

2013-09-23 Thread paul trader
searching the internet for a similar problem/solution and come up empty. windows boxes will not authenticate, pap always returns noop, and the user is rejected. am i doing something glaringly wrong, or just going plain crazy? regards, paul - List info/subscribe/unsubscribe? See http

Re: pap always returns noop for windows dialup authentication

2013-09-23 Thread paul trader
request finds the user's entry in the user table, but the failed request doesn't (and uses DEFAULT instead). but the usernames passed in seem to be the same. i don't know, we've used freeradius for years and this is the 1st time i'm having a problem. weird. regards, paul - List info

Re: Freeradius-Users Digest, Vol 101, Issue 50

2013-09-23 Thread paul trader
in the users file. regards, paul- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: pap always returns noop for windows dialup authentication

2013-09-23 Thread paul trader
On Mon, 23 Sep 2013 at 14:42, John Dennis opined: JD:You have all the information you need to debug your problem. It does JD:require reading the debug output carefully. But you should really try JD:to do that yourself first. As a said earlier, verify you're reading the JD:exact same users file

Re: Comware 3 Switches (3Com 4500, 5500, 5500G - H3C S3600, S5600) - EAPOL v2 and v3 being dropped.

2013-04-18 Thread Paul Marchbank
that this is the case. Original 3Com announcement: http://web.archive.org/web/20101009093205/http://3com.com/products/en_US/end_of_life.jsp?sku=3CR17151-91 Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Prompt for new password on mac 10.7 after change with 2.1.12 ?

2012-07-30 Thread Jonathan Paul
fails ? Thanks Jonathan Paul Network Support Services - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Prompt for new password on mac 10.7 after change with 2.1.12 ?

2012-07-30 Thread Jonathan Paul
not getting the prompt to re-enter password. Is additional configuration necessary ? Thanks Jonathan Alan DeKok al...@deployingradius.com 7/30/2012 11:30 AM Jonathan Paul wrote: We are running a freeradius 2.1.12 server for access to our wifi. The server is configured to authenticate users

Re: Prompt for new password on mac 10.7 after change with 2.1.12 ?

2012-07-30 Thread Jonathan Paul
I have allow_retry = yes in /etc/raddb/modules/mschap and send_error = yes in the mschapv2 section of /etc/raddb/eap.conf I am not seeing any change in behavior from the mac, it doesn't even prompt for a new username/password so I must be missing something else Jonathan alan buxey

users file ignored and still checks sql

2012-04-24 Thread Paul Tinson
in the users file being scanned and then returning Auth-Type: Accept and not then processing the sql authorize module. Have I missed something simple, or does this config look right. Any clues appreciated. Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: users file ignored and still checks sql

2012-04-24 Thread Paul Tinson
On 24/04/12 11:44 PM, Alan DeKok al...@deployingradius.com wrote: Have I missed something simple, or does this config look right. The configuration is wrong. Setting Auth-Type = Accept doesn't mean stop authorization. It means use Accept authentication OK that makes sense. If you

RE: Mixed Environment Question

2012-01-31 Thread Paul Stewart
and the user session drops. While the user session is active, the internal route to their session never gets created properly on the MX neither so you can't pass traffic or anything. Take away any additional VSA's and sessions work perfectly Thanks, Paul -Original Message- From

Mixed Environment Question

2012-01-30 Thread Paul Stewart
to a Juniper (not at the same time, but within minutes of one another). I am trying to come up with a users file entry that keeps all vendor specific attributes in intact - am I playing with fire? ;) Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Mixed Environment Question

2012-01-30 Thread Paul Stewart
as well ignores them perfectly. Cheers, Paul From: freeradius-users-bounces+paul=paulstewart@lists.freeradius.org [mailto:freeradius-users-bounces+paul=paulstewart@lists.freeradius.org] On Behalf Of Arran Cudbard-Bell Sent: Monday, January 30, 2012 1:18 PM To: FreeRadius users

RE: Mixed Environment Question

2012-01-30 Thread Paul Stewart
Thanks so much for that info. I did roll a ticket with Juniper and will follow up with them. If anything of substance comes out of this I'll be sure to share back to the list for other Juniper users to benefit from ;) Paul From: freeradius-users-bounces+paul=paulstewart

Juniper MX auth issue

2012-01-24 Thread Paul Stewart
time JTAC has been quite helpful but we're still not operational yet. Thanks, Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Juniper MX auth issue

2012-01-24 Thread Paul Stewart
Thank you - appreciate the response. Have it working now and it ends up being a JunOS code issue - geesh.. Sorry for the noise... Paul -Original Message- From: freeradius-users-bounces+paul=paulstewart@lists.freeradius.org [mailto:freeradius-users-bounces+paul=paulstewart

Juniper Questions (MX/ERX)

2012-01-24 Thread Paul Stewart
= 512k for example in the users file I get invalid integer error. Thanks for any insight. Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problem with accounting and sql

2011-12-09 Thread Paul Thornton
. Try using the debug form on http://networkradius.com/. It will highlight things which you should look at in more detail. That looks good - I hadn't seen that before, thanks. Paul. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: git timeout

2011-12-09 Thread Paul Thornton
'. That will run Gnu Make as Alan suggested. Paul. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Problem with accounting and sql

2011-12-08 Thread Paul Thornton
gratefully received. Regards, Paul. [root@auth1 ~]# radiusd -X FreeRADIUS Version 2.1.11, for host i386-portbld-freebsd8.2, built on Aug 25 2011 at 19:01:41 Copyright (C) 1999-2009 The FreeRADIUS server project and contributors. There is NO warranty; not even for MERCHANTABILITY or FITNESS

Re: Cannot assign requested address Error starting FreeRadius

2011-11-11 Thread Paul Heil
I have a GuruPlug Server 003-GP0001 running Debian Linux 6.0.3 with FreeRadius 2.1.10 installed. I have followed the Basic Configuration HOWTOhttp://wiki.freeradius.org/Basic-configuration-HOWTO, but when I get to the point of starting the server for the first time, I get this error: Fri Nov

Re: Cannot assign requested address Error starting FreeRadius

2011-11-11 Thread Paul Heil
On Fri, Nov 11, 2011 at 3:51 PM, Fajar A. Nugraha l...@fajar.net wrote: (1) run it as root (2) make sure nothing else is running on that port (e.g. another freeradius instance) (3) if you don't know what (1) and (2) means, spend some time to learn some linux/unix basics. Especially the

Re: Cannot assign requested address Error starting FreeRadius

2011-11-11 Thread Paul Heil
On Fri, Nov 11, 2011 at 4:20 PM, Paul Heil paul.h...@gmail.com wrote: I run freeradius as root. e.g $sudo freeradius -X According to lsof, nothing is using port 1820. (netstat shows the same) $lsof -i :1820 Thanks, PaulH Edit: Typo - Nothing is on port *18120*. - List info

Re: Test

2011-09-15 Thread Paul Thornton
On 15/09/2011 15:49, Alan DeKok wrote: Is the list down, or are people quiet? I think we're all just being quiet today. Paul. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Using encrypted passwords in users file

2011-09-01 Thread Paul Bartell
that is the hashed password. You can change it by generating a hash of your new password... you would probably use crypt(3) to do that... The original password was never stored in cleartext form. You could store a cleartext password if you really wanted to, but that is less than secure. On Thu,

RE: Error: User-Name is not the same as MS-CHAP name

2011-06-03 Thread Paul Harris
On 02/06/11 14:47, Francois Gaudreault wrote: Did you have a chance to look at it? Ironically I'm having trouble finding a windows XP install CD... I have a link to a torrent, just send me a email at pau...@mail.com - List info/subscribe/unsubscribe? See

Re: Restrict access per NAS

2011-04-08 Thread Paul Bartell
you are probably looking to check for the calling-station-id attribute... im not sure how to do with ldap. On Fri, Apr 8, 2011 at 7:11 AM, Sergio Belkin seb...@gmail.com wrote: Hi, Is there a way to restrict an LDAP user to be authorized only from an specific NAS (Access Point)? I'm using

Re: Own exec module with bash: permission denied

2011-03-20 Thread Paul Thornton
for the radius user to enter them. Paul. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Set reject in post-auth

2011-03-14 Thread paul smith
...@deployingradius.com wrote: paul smith wrote: I've been trying to set reject in the post-auth section if a certain attribute hasn't been set, but it doesn't seem to work (obviously I've messed it up) $ man unlang  You can just use the word reject  Alan DeKok. - List info/subscribe/unsubscribe? See

Set reject in post-auth

2011-03-10 Thread paul smith
, or is it not possible to perform a reject in the post-auth? thanks, paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: CHAP problem with PPPoE server

2011-03-09 Thread Paul Thornton
or a server without using radius. I thought this list was exactly the sort of place that people who may have come across a similar issue could be found. Sorry for the noise if that isn't the case. Paul. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

CHAP problem with PPPoE server

2011-03-08 Thread Paul Thornton
server have the challenge is important... Has anyone had a similar problem or can suggest anything? I've been going around in circles here all day and ended up going nowhere. Many thanks, Paul. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Only run a single post-auth when using inner-tunnel

2011-03-07 Thread paul smith
== Access-Accept) { radius-user-auth } However this always evaluates as true, even though I can see the inner-tunnel authenticating successfully. thanks, paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Only run a single post-auth when using inner-tunnel

2011-03-07 Thread paul smith
, On Mon, Mar 7, 2011 at 11:08 AM, Phil Mayers p.may...@imperial.ac.uk wrote: On 07/03/11 10:10, paul smith wrote: Is there some way I can tell the server not to run things in the default post-auth, if the request has been through the inner-tunnel? I'm thinking putting something like

Re: Only run a single post-auth when using inner-tunnel

2011-03-07 Thread paul smith
Thats perfect, thanks phil, many thanks for the help. On Mon, Mar 7, 2011 at 1:19 PM, Phil Mayers p.may...@imperial.ac.uk wrote: On 07/03/11 12:18, paul smith wrote: Thanks Phil, thats great works really well. It has set me thinking about a variation though, using EAP-Message would mean

Re: How do you pass Cleartext-Password from CHAP to another module

2011-02-16 Thread paul smith
because CHAP works. thanks, On Wed, Feb 16, 2011 at 9:07 AM, Phil Mayers p.may...@imperial.ac.uk wrote: On 02/16/2011 02:07 AM, paul smith wrote: Hi, I want to authenticate a CHAP request against my sql database, but then pass the Cleartext-Password to the next module. I've got the CHAP

Re: How do you pass Cleartext-Password from CHAP to another module

2011-02-16 Thread paul smith
That works perfectly, many thanks eddie and phil. On Wed, Feb 16, 2011 at 3:00 PM, Phil Mayers p.may...@imperial.ac.uk wrote: On 16/02/11 14:22, Eddie Stassen wrote: I think that should read  %{control:Cleartext-Password}, not 'config' Well spotted... - List info/subscribe/unsubscribe? See

How do you pass Cleartext-Password from CHAP to another module

2011-02-15 Thread paul smith
Hi, I want to authenticate a CHAP request against my sql database, but then pass the Cleartext-Password to the next module. I've got the CHAP working fine, but can't work out how to pass the password on. Is this possible? I have an exec module like this: exec authz { wait = yes

Re: FreeRADIUS + Cygwin + Active Directory authentication?

2011-02-09 Thread Paul Bartell
Frankly, running Free Radius on windows sounds like a bad idea, especially should you ever need to update it or have another person (maybe 5 years down the road) change it a bit. Generally, running server process under cygwin is a lot of extra work for not much convenience. I would suggest either

Re:

2010-11-24 Thread Paul Bartell
It depends on they way your NAS (access point of whatnot) sends the mac address. some send it as the username/password... some send it other ways... On Wed, Nov 24, 2010 at 12:26 PM, Leander S. i...@netocean.de wrote: to prevent tears: check out /etc/raddb/clients.conf but now there is now

Re: Recommendation

2010-08-17 Thread Paul Dugas
On Tue, Aug 17, 2010 at 2:44 AM, Alan DeKok al...@deployingradius.com wrote: Paul Dugas wrote: On Mon, Aug 16, 2010 at 5:02 PM, Alan DeKok al...@deployingradius.com wrote:  Use PEAP.  Ensure passwords are in a form compatible with PEAP: My LDAP directory contains NT, LM, and SSHA

Re: Recommendation

2010-08-17 Thread Paul Dugas
to retrieve the password. If I do have NT hashed passwords in LDAP, is PEAP with ntlm_auth the recommendation? Thanks for the guidance, Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Recommendation

2010-08-17 Thread Paul Dugas
to identify and use the NT or SSHA hashed password? Paul -- Paul Dugas • Dugas Enterprises, LLC • Computer Engineer 522 Black Canyon Park, Canton GA 30114 USA • p...@dugasenterprises.com • +1.404.932.1355 - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Recommendation

2010-08-16 Thread Paul Dugas
installation. I'm looking to use WPA2-Enterprises and accounts stored in my existing LDAP directory. I need to support primarily WinXP wireless clients but I also need my Linux (Fedora) machines to work as well as a few smartphones (Blackberry, iPhone, etc). Thanks in advance for any direction. Paul

Re: Recommendation

2010-08-16 Thread Paul Dugas
simpler than when I originally set this up with FR1. Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: how to setup in fedora ?

2010-07-09 Thread Paul Bartell
look at the configuration files in /etc/raddb, they're pretty self-explanatory. It really depends on what you want to do. On Thu, Jul 8, 2010 at 11:03 PM, Abraham Varricatt abraham.varricatt+freerad...@googlemail.com wrote: Hello, I just flashed a linksys with dd-wrt and now I'm trying to

Re: Mail to list being bounced

2010-06-09 Thread Paul Ryszka
Because it is gmail. On Wed, 2010-06-09 at 08:51 -0400, Natr Brazell wrote: Why are some of my messages getting bounced by the list? Gmail sometimes sends me back messages saying that it tried in vain to send out and was refused by the recipient? N - List info/subscribe/unsubscribe? See

Re: How to use Freeradius with traffic limit?

2010-06-07 Thread Paul Bartell
NAS is nearly analogous to RADIUS client. basically, it depends on the thing that is talking to Freeradius to say how to configure kicking someone off in real time. You could stick a script before authentication happens to check whether or not a user has exceeded his bandwidth and then either

Re: is there a package named phpmysql

2010-05-06 Thread Paul Bartell
you are probably looking for php5-mysql or php4-mysql. A good source for this kind of info is your distro's package archive. 2010/5/6 dorra aa dj_dido2...@hotmail.com Hi.i'm working now in the install of mysql for the radius.I found a file that tell me to do: sudo apt-get install

Re: Using Vendor Attributes

2010-04-02 Thread Paul Varvel
is to bind a user in a redback context in the access-accept request. Many thanks for your help. On Fri, Apr 2, 2010 at 9:10 AM, Alan DeKok al...@deployingradius.com wrote: Paul Varvel wrote: I'm beginner with FreeRadius and I'd like to know where can I use a vendor specific attribute for my Redback

Using Vendor Attributes

2010-04-01 Thread Paul Varvel
Hi everybody, I'm beginner with FreeRadius and I'd like to know where can I use a vendor specific attribute for my Redback router (in which configuration file). The dictionary is in /usr/share/freeradius/dictionary.redback and loaded when FreeRadius starts. When is try to use Context-Name =

Re: 2 authorization tables?

2010-03-25 Thread Paul Ryszka
On Thu, 2010-03-25 at 15:25 +0100, Paweł Pogorzelski wrote: 1. Can i add another table for user authorizations in the same database for example racheck and radcheck2? the easiest way to do it would be to create view joining these 2 tables 2. For what is radreply table ? information that

Re: radiusd -X

2009-12-16 Thread Paul Ryszka
Hi, Get yourself hardware SSL accelerator card supported by openssl libraries or increase cpu speed. On Wed, 2009-12-16 at 15:38 +0530, kachin Agarwal wrote: Hi, After a lot of investigation, i have found the reason for my low auth-rate. The auth-rate i m gettin now is 3/sec. so

Re: (без темы)

2009-12-11 Thread Paul Ryszka
should be using Cleartext-Password instead. do grep -H in the config directory and find out where the user-password is used. Regards Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ntlm_auth and AD authentication

2009-11-23 Thread Paul Ryszka
On Mon, 2009-11-23 at 10:24 -0500, freerad...@corwyn.net wrote: However, whether I use ntlm_auth --request-nt-key --domain=MYDOMAIN --username=user --password=password or ntlm_auth --domain=MYDOMAIN --username=user --password=password the output/response looks the same: NT_STATUS_OK:

Re: ntlm_auth and AD authentication

2009-11-23 Thread Paul Ryszka
On Mon, 2009-11-23 at 13:35 -0500, freerad...@corwyn.net wrote: At 10:24 AM 11/23/2009, freerad...@corwyn.net wrote: to confirm, and it looks like it's working. Hmm. I have two sets of authentication I care about, VPN Users, and Cisco switches. I'd like to be able to control access to each

Re: EAP advanced auth. methods problem

2009-11-23 Thread Paul Ryszka
On Mon, 2009-11-23 at 20:37 +0100, Tomas Pelka wrote: t...@kalik.net wrote: Also tried modify wpa_supplicant conf: - ca_cert=ca.pem + ca_cert=server.pem But with the same result. Because the path is wrong, ie. certificate is not there. Put the correct path to where you have

Re: ntlm_auth and AD authentication

2009-11-23 Thread Paul Ryszka
On Mon, 2009-11-23 at 15:05 -0500, freerad...@corwyn.net wrote: At 02:33 PM 11/23/2009, Paul Ryszka wrote: On Mon, 2009-11-23 at 13:35 -0500, freerad...@corwyn.net wrote: Am I going to have to do something like create different modules (ntlm_auth and ntlm_auth2) radiusd.conf in the module

Re: need help authenticating against AD

2009-11-19 Thread Paul Ryszka
Hi, It doesn't llok like you are using ad authentication Are you trying to set up ntlm_auth ? Here is a good description : http://deployingradius.com/documents/configuration/active_directory.html Regards Paul On Thu, 2009-11-19 at 21:37 +, Michael Phillips wrote: Hello All, I need some

Re: Seeking FreeRADIUS Consultant

2009-11-08 Thread Paul Ryszka
but logging accounting information to a centralized database might be a good idea. Regards Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

NTLM

2009-11-04 Thread Paul Ryszka
like the end-client to be able to use MSCHAPv2 to use both. Thank you in advance for your help. Regards Paul FreeRADIUS Version 2.1.7, for host i386-redhat-linux-gnu, built on Sep 18 2009 at 10:59:17 Copyright (C) 1999-2009 The FreeRADIUS server project and contributors. There is NO warranty

Re: NTLM

2009-11-04 Thread Paul Ryszka
Thank you!!! On Wed, 2009-11-04 at 12:17 +, Ivan Kalik wrote: I was setting up NTLM auth against AD and it works well however I wanted to add another server sections in the config and that was working ok too up to the point when somebody wants to do mschap authentication against

Client Certificates

2009-11-02 Thread Paul Ryszka
Hello, Do I need separate certificate for each client or can I use one cert for all clients ? Is there easy way to generate bunch of them using supplied scripts ? Regards Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Multiple servers

2009-11-02 Thread Paul Ryszka
or listen in sites-enabled directory.Should I just put listen clause in one of the files remove the default file there and remove listen from radiusd.conf ? Regards Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Database Problem

2009-10-30 Thread Paul Ryszka
. I would really appriciate if you would be able to tell me how the simplest (user/password with nothing extra returned back) authentication can be done using database backend. Regards Paul - List info/subscribe/unsubscribe? See http

Re: Database Problem

2009-10-30 Thread Paul Ryszka
On Fri, 2009-10-30 at 12:34 +0100, Ana Gallardo wrote: I would really appriciate if you would be able to tell me how the simplest (user/password with nothing extra returned back) authentication can be done using database backend. Insert in

Re: Database Problem

2009-10-30 Thread Paul Ryszka
Thank you for help, I got it working. Can you tell me if there is tool that I can use to test mschap authentication rahter than use local radtest it can be linux or windows app. Thank you Paul On Fri, 2009-10-30 at 12:58 +0100, Ana Gallardo wrote: Insert in radcheck table

Re: Probably simple problem

2009-10-29 Thread Paul Ryszka
-howto.html however I remember reading that I shoudl not use Auth-Type unless absolutely necessary, would somebody be able to tell me how to replace that one ? I am new to freeradius so probably there are some obvious things that I just cannot grasp. On Wed, 2009-10-28 at 22:29 +, Paul Ryszka

Re: Probably simple problem

2009-10-29 Thread Paul Ryszka
at 13:19 +, Ivan Kalik wrote: Paul Ryszka wrote: Hello, Sorry for that the problem was simple I just forgot to put on the end of the line. I guess I spent too much time going over it yesterday. Anyway I am also looking at implementing MSSQL authentication back-end Ugh, do you

Probably simple problem

2009-10-28 Thread Paul Ryszka
see a request. So I am puzzled a little bit because even if I copy the ntlm_auth line from debug output it returns access granted and it gives wrong password from within radius Any help would be appreciated. Thank You. Paul Ryszka - List info/subscribe/unsubscribe? See http

Re: Freeradius start at boot

2009-10-01 Thread Paul Blalock
or if it was by using the radiusd -X command. I should have been logged in as root, but not sure. -- Paul Blalock - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius start at boot

2009-10-01 Thread Paul Blalock
radiusd is already running on that port. When checking /etc/rc.d/rc3.d I found a file named S88radiusd. I thought that the Address already in use error was supposed to happen if trying to start a second instance of the same service? -- Paul Blalock - List info/subscribe/unsubscribe? See http

Re: Freeradius start at boot

2009-10-01 Thread Paul Blalock
. -- Paul Blalock - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius start at boot

2009-10-01 Thread Paul Blalock
So are you saying to accomplish what I want, I need to write a system V init script? -- Paul Blalock - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Start Freeradius at boot

2009-09-30 Thread Paul . Blalock
So I went back to a clean install of Fedora 11, followed the instructions on installing freeradius via yum. Then I issued the command: chkconfig --list radiusd (and got the following) radiusd 0:off 1:off 2:off 3:off 4:off 5:off 6:off so i entered sudo chkconfig radiusd on and then I got

Re: Start Freeradius at boot

2009-09-29 Thread Paul . Blalock
I appreciate your insight, and I might have to go with a pre-built package after all. But I did go ahead and issue the commands, and when I run chkconfig --list radiusd This is what I get. radiusd 0:off 1:off 2:on 3:on 4:on 5:on 6:off According to the links that you sent me, this is what it is

Start Freeradius at boot

2009-09-28 Thread Paul . Blalock
Paul Blalock - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Start Freeradius at boot

2009-09-28 Thread Paul . Blalock
, and when I do a 'chkconfig radiusd on', it says no such file or directory. Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Start Freeradius at boot

2009-09-28 Thread Paul . Blalock
did you install FreeRADIUS via yum and a repository or from source? Downloaded freeradius-server-2.1.7.tar.gz, extracted to home directory, and then ./configure, make, make install. if from the repsository you should have a selectable service with eg the standard Fedora system startup tools -

Re: descrition tables and atributes

2009-09-26 Thread Paul Bartell
the wiki is your friend. Try the SQL HOWTO page. On Sat, Sep 26, 2009 at 12:36 PM, Nelson Acero Fino nelson.ac...@gmail.com wrote: Hi, Where can i found information and description about tables and atributes of radius database ?? Thanks :) ! - List info/subscribe/unsubscribe? See

Creating a bash file to run Hup Files

2009-08-10 Thread Paul Blalock
. Listening on command file /usr/local/var/run/radiusd/radiusd.sock Ready to process requests. ... closing socket command file /usr/local/var/run/radiusd/radiusd.sock Ready to process requests. Also, if I can get this working, I am needing to set it up to run automatically every hour or so. -- Paul

Re: Simple username password text file

2009-08-06 Thread Paul Blalock
On Wed, Aug 05, 2009 at 09:44:55AM -0500, Paul Blalock wrote: Is it possible to have a simplistic username and password setup in freeradius? For example. user, pass user1, pass1 Or is it possible to have the users file point to a file that does this? If not, is it possible to have

Simple username password text file

2009-08-05 Thread Paul Blalock
Is it possible to have a simplistic username and password setup in freeradius? For example. user, pass user1, pass1 Or is it possible to have the users file point to a file that does this? If not, is it possible to have this type of format by using mysql? -- Paul Blalock - List info

Restart radiusd after new user added

2009-07-31 Thread Blalock, Paul (NCC)
I am setting up freeradius, and am having issues with adding users and having to restart radiusd to pick up the new users. Is sql the only other way to go, or is there a way to point the users file to another directory? Also, is there a way to have username passwords formatted as (user pass) or

Huawei WiMax ASN-GW FreeRadius as AAA

2009-06-26 Thread Paul Carter-Brown
to jumpstart the effort. Thanks so much Paul CIO Smile Communications www.smilecoms.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Add users without restarting radiusd

2009-05-12 Thread Paul Bartell
you could also use SQL or another database for storing users. This doesn't require HUP ing of the server. On Tue, May 12, 2009 at 8:25 PM, ournixnat...@gmail.com ournixnat...@gmail.com wrote: I may have figured it out myself. Will this work: service radiusd reload If so, what exactly is it

Outer identity being used for LDAP group lookup in users file

2009-05-10 Thread Paul Dealy
Identity username. Is there any way of ensuring that the lookup is performed against the real inner identity not the fake outer identity? Cheers, Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Posting

2009-04-20 Thread Paul Bartell
you just have. On Mon, Apr 20, 2009 at 11:41 AM, jon jon free9...@gmail.com wrote: Help, I would like to post a messageto all the list members. Thanks - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Random quote of the week/month/whenever i get to

Re: of Mac and Men

2009-04-09 Thread Paul Bartell
SIGNED MESSAGE- Hash: SHA1 Paul Bartell wrote: I too have had weird behavior on macs. I just ended up using mac-address authentication (due to insecurities in EAP. (or possibly rumored, i havn't seen a paper on it yet)) Wait what... You went to Mac-Based authentication because you thought

Re: of Mac and Men

2009-04-09 Thread Paul Bartell
I'm aware of an attack on a bank which had implemented EAP, and had fun when a Pen tester was simply getting domain login credentials without having to work much at all. Could you maybe provide a rebuttal for this attack? and/or explain how to make it especially secure? On Tue, Apr 7, 2009 at

Re: of Mac and Men

2009-04-07 Thread Paul Bartell
I too have had weird behavior on macs. I just ended up using mac-address authentication (due to insecurities in EAP. (or possibly rumored, i havn't seen a paper on it yet)) On Tue, Apr 7, 2009 at 7:08 AM, a.l.m.bu...@lboro.ac.uk wrote: Hi, Have you actually traced the wireless traffic

Re: Radclient PHP

2009-04-01 Thread Paul Bartell
try exec() or shell_exec() 2009/4/1 AHMED KHIDR a.kh...@gmail.com: Hii All , Please Any one have an idea how to make a PHP code to  run Radclient in order to disconnect users , Thanks - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Random quote of

Filtering reply attributes for certain NAS devices

2009-03-28 Thread Paul Hanson
Quick question (I hope)... What options do I have to limit or mask certain attributes depending upon the NAS device? I have approx 14 devices that need specific attributes but other devices have issues with some optional reply attributes. My current setup uses two LDAP instances,

Problem compiling on OSX 10.5

2009-03-09 Thread Paul Bartell
I have two problems: One is with compiling in mysql support. Despite using the following ./configure line ./configure --prefix=/usr/local/freeradius --with-mysql-include-dir=/usr/local/mysql-5.1.30-osx10.5-x86/include/ --with-mysql-lib-dir=/usr/local/mysql-5.1.30-osx10.5-x86/lib/ it still says

Re: New FR server: CentOS 5 or Ubuntu 8

2009-03-02 Thread Paul Bartell
Im a bit biased towards ubuntu, but i can say from experience that it is relatively easy to implement in ubuntu. My limited experience with centos has been with squid and websense, which was quite annoying to implement. (packages didn't exist/were too old) On Mon, Mar 2, 2009 at 7:48 AM, Toledo,

Re: Wired 802.1x auth - Getting the IP address of the authed machine

2009-02-25 Thread Paul Dealy
I have accounting turned on, but I don't see the authed machines IP on that of the NAS. On Wed, Feb 25, 2009 at 8:47 PM, t...@kalik.net wrote: I have a wired 802.1x auth setup on cisco gear.  I would like to record the IP address of machines that connect and are authorized.  Is this possible?

Wired 802.1x auth - Getting the IP address of the authed machine

2009-02-24 Thread Paul Dealy
machine. The machines that are connecting to be authed are allocated their address using dhcp. Cheers Paul - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

  1   2   3   4   5   6   >