Re: EAP-PEAP with LDAP for 802.1x authentication

2008-02-25 Thread Arjuna Scagnetto
reading from http://deployingradius.com/documents/protocols/compatibility.html you can achive that there's no problem to make ldap work with EAP-PEAP, the only thing you must take care is the hashing algorithm for the password. Reading carefully from http://vuksan.com/linux/dot1x/802-1x-LDAP.html

Re: extract different field from ldap on nas's ip address base

2008-01-24 Thread arjuna
m to make the rule in users file match the packet can someone tell me where to find out a guide, tutorial, README about the fields i can use in the rules inside users file? thanks, arjuna - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

extract different field from ldap on nas's ip address base

2008-01-23 Thread arjuna
Is it possible to extract (to filter) different field in a ldap entry on the base of the "nas" ip address? arjuna - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: multiple access credential

2008-01-23 Thread arjuna
whatever shell-access-password=whatever2 802.3-access-password=xx:xx:xx:xx:xx:xx something like this. So i need to get the right password on the base of the "NAS" ip (NAS is not the very right word). Now is it clearer? So, can a single radius server manages this scenario? Do i need realm

multiple access credential

2008-01-23 Thread arjuna
this is the problem: I need different kind of authentication against a Ldap dir, better with the same username (userid,uid). May i use the huntgroup file to make freeradius look for different fields into the ldap dir? for example: ou=People - List info/subscribe/unsubscribe? See http://www.fre

Re: Controlling access to my Wireless network

2007-09-19 Thread Arjuna Scagnetto
'll need to install extra software > on the WinXP machines securew2 is free and enables winxp to recognize ttls-pap packets. arjuna begin:vcard fn:Arjuna Scagnetto n:Scagnetto;Arjuna org:Universita' degli Studi di Trieste;Dipartimento Fisica Teorica adr:ICTP Main Building Office Numbe

Re: certificate read permission and user running radius problem

2007-09-14 Thread Arjuna Scagnetto
drw-r-xr-x root root cert.pem-rw-r-xr-x root root cacert.pem -rw-r-xr-x root root I'm realy confused! begin:vcard fn:Arjuna Scagnetto n:Scagnetto;Arjuna org:Universita' degli Studi di Trieste;Dipartimento Fisica Teorica adr:ICTP Main Buildin

certificate read permission and user running radius problem

2007-09-14 Thread Arjuna Scagnetto
Hi all, i can't understand why if I run radiusd as nobody (user and group) it can't access the directory that contains the certificates for eap. Can someone help me, plz. thanks in advance Arjuna Scagnetto begin:vcard fn:Arjuna Scagnetto n:Scagnetto;Arjuna org:Universita' degli S

RE:Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-03 Thread Arjuna Scagnetto
(md5) hash password. Bye begin:vcard fn:Arjuna Scagnetto n:Scagnetto;Arjuna org:Universita' degli Studi di Trieste;Dipartimento Fisica Teorica adr:ICTP Main Building Office Number 222;;Via Strada Costiera 11;Trieste;TS;34100;Italy email;internet:[EMAIL PROTECTED] title:Co-System Administrato

802.1x+EAP+LDAP

2007-06-28 Thread Arjuna Scagnetto
t shouldn't? Thanks for answering Arjuna Scagnetto - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: radius+ldap+peap

2007-05-18 Thread Arjuna Scagnetto
> > > O/H Alan DeKok ??: >> Arjuna Scagnetto wrote: >> ... >> >>> PEAP with user whose password is in LDAP >>> >> ... >> >>> userPAssword: {SSHA}tymetcetcetc >>> >> This WILL NOT WO

RE: radius+ldap+peap

2007-05-18 Thread Arjuna Scagnetto
> Arjuna Scagnetto wrote: > > can someone tell me a good tutorial about making work freeradius with > > ldap and peap on a 802.1x architecture ? Get LDAP working with PAP authentication, but NOT using "ldap bind". Get PEAP working with passwords in the "us

radius+ldap+peap

2007-05-17 Thread Arjuna Scagnetto
ap: user wclient authorized to use remote access rlm_ldap: ldap_release_conn: Release Id: 0 modcall[authorize]: module "ldap" returns ok for request 5 Segmentation fault thanks for helping Arjuna -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problems With EAP

2007-02-21 Thread Arjuna Scagnetto
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I think the Auth-Type value is the problem, try to use an entry like "username" User-Password = "pass" without explicit the Auth-Type value. but if it works i do not realy understand why it works :) i'm a freer

sending logs to mysql?

2007-02-18 Thread Arjuna Scagnetto
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Is it possible to send all logs to the mysql directly from freeradius? thanks Arjuna Scagnetto -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.6 (GNU/Linux) iD8DBQFF2JKk7hNGJisFPxQRAjd1AJ4x0EjKuzIcLCDp/g1qSrUimUiorwCeMSaF 7Z8uGN4FD2HsjMwov6C/6s0

eap-tls certificates: help needed

2007-02-07 Thread Arjuna Scagnetto
i've found only howto dated from 2002 to 2005 and they are too old ofcourse. any help would be greatly apreciated Arjuna -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.6 (GNU/Linux) iD8DBQFFyksn7hNGJisFPxQRAv3/AJ4oj7E+Cg9JnylPSKR2uCYjDiVkSgCgp6OT xjynN2T6CkLOb16BHF1JE0c= =wVsc -EN