identical
from both systems. Thoughts?
Tim Tyler
Network Engineer
Beloit College
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
AP connections against (crypt and
>SSHA) passwords stored in our ldap database.
You have done it. If PEAP works, so will EAP-TTLS/PAP.
Ivan Kalik
Kalik Informatika ISP
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Tim Tyler
Network Engineer - Beloit
}
Auth-Type CHAP {
chap
}
Auth-Type MS-CHAP {
mschap
}
unix
Auth-Type LDAP {
ldap
}
eap
}
Tim Tyler
Network Engineer - Beloit College
[EMAIL PROTECTED]
-
List info/subscribe
: starting TLS
rlm_ldap: bind as cn=Manager,dc=beloit,dc=edu/tac2tmaw to
testldap.beloit.edu:389
rlm_ldap: waiting for bind result ...
rlm_ldap: Bind was successful
rlm_ldap: performing search in dc=beloit,dc=edu, with filter (uid=tyler)
rlm_ldap: looking for check items in directory...
rlm_ldap: Adding sambaAcctFlags as SMB-Account-CTRL-TEXT, value
[U ] & op=21
rlm_ldap: Adding sambaNTPassword as NT-Password, value
E02C0DC6138F12F76F424596E04E10E2 & op=21
rlm_ldap: Adding sambaLMPassword as LM-Password, value
0A5283563091373BAAD3B435B51404EE & op=21
rlm_ldap: looking for reply items in directory...
rlm_ldap: Pairs do not match. Rejecting user.
rlm_ldap: ldap_release_conn: Release Id: 0
modcall[authorize]: module "ldap_2x" returns reject for request 0
modcall: leaving group authorize (returns reject) for request 0
Delaying request 0 for 1 seconds
Finished request 0
Going to the next request
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Sending Access-Reject of id 31 to 144.89.40.88 port 33050
Waking up in 4 seconds...
--- Walking the entire request list ---
Cleaning up request 0 ID 31 with timestamp 484e906c
Nothing to do. Sleeping until we see a request.
Tim Tyler
Network Engineer - Beloit College
[EMAIL PROTECTED]
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
passwd students {
filename = /etc/raddb/ldapusers
format = "*User-Name"
authtype = ldap
}
Thanks!
Tim
At 11:57 AM 3/13/2007, you wrote:
>Tim Tyler wrote:
> > Ivan, or others,
> >Ok, I can't seem t
>I think that users will be checked against the system first and if not
>found against LDAP. Take this with a pinch of salt - I never used users
>file, System or LDAP, only MySQL.
>
>Ivan Kalik
>Kalik Informatika ISP
>
>
>Dana 12/3/2007, "Tim Tyler" <[EMAIL PROT
ates to ldap. If I put both in the users file, it
> >authenticates ldap users only. How do I allow both unix and ldap
> >modules to authenticate their respective users? Note: users are
> >unique to each module. A user in unix does
> not exist in ldap and vice versa.
> >
users? Note: users are
unique to each module. A user in unix does not exist in ldap and vice versa.
Tim Tyler
Network Engineer - Beloit College
[EMAIL PROTECTED]
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
= userPassword in the radiusd.conf file, correct?
Tim
At 04:51 PM 3/5/2007, you wrote:
>Use Crypt-Password not User-Password.
>
>Ivan Kalik
>Kalik Informatika ISP
>
>
>Dana 5/3/2007, "Tim Tyler" <[EMAIL PROTECTED]> pi¹e:
>
> > Freeradius experts,
&
sume that the ldap server
doesn't have to store the passwords in plain text, correct? I can
store them in md5 or SHA1 hash if I want, correct? I did uncomment:
authenticate {
Auth-Type LDAP {
ldap
}
Am I wrong to think this is now a password issue?
Tim
Tim Tyler
Network En
your test client machine as a NAS in
the AIX machine's clients file.
Basically you need to eavesdrop on the connection between the radius
client and new/old servers, and compare and contrast the replies. This is
the best way to work out "What has changed?"
Hope this helps,
authentication? If so, what mtu setting might be recommended?
Is there another possible explanation that might relate to Freeradius?
any thoughts are much appreciated?
Tim Tyler
Network Engineer - Beloit College
[EMAIL PROTECTED]
-
List info/subscribe/unsubscribe? See http://www.free
all[post-proxy]: module "eap" returns noop for request
5
modcall: group post-proxy returns noop for request 5
Delaying request 5 for 1 seconds
Finished request 5
Going to the next request
Waking up in 6 seconds...
rad_recv: Access-Request packet from host
144.89.40.251:1451, id=254, length=144
Sending Access-Reject of id 254 to 144.89.40.251:1451
Tim Tyler
Network Engineer
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
-ttls from a wireless
client to the freeradius proxy server, but use open text
from the freeradius proxy server to our Livingston radius
servers?
If so, how?
Tim
Tim Tyler
Network Engineer
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
14 matches
Mail list logo