accepting user with username and password depending from mac-address

2011-09-09 Thread Markus Müller
would be really appreciated and will help to give our students internet access with our laptops. If you need further information please ask. Thank you very much in advance. best wishes Markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: first authentification fail second one works

2011-01-07 Thread Markus Burghart
Am 07.01.2011 13:52, schrieb Alan DeKok: Markus Burghart wrote: But I want to perform my authentifications while the system is currently booting because i use a LDAP Directory Server and i can't login against the LDAP Server if i haven't got a running Network-Connection (i will get

first authentification fail second one works

2011-01-06 Thread Markus Burghart
to hear from you Yours Markus rslautern 3724 - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Reply with group attribute

2009-03-17 Thread Markus Wernig
Alan DeKok wrote: Markus Wernig wrote: Could not find a place where to initialise the passwd module. You list it in the authorize section. This lead to errors (from memory: no config found for passwd module). I then used the etc_group module from the example, listed _that_ in authorize

Re: Reply with group attribute

2009-03-17 Thread Markus Wernig
t...@kalik.net wrote: Did you read rlm_passwd man page? It's %{control:My-Group-Name}. Quotes, list and all. Yes, that did it! Quotes were there, but the control list part wasn't. Thank you for your help! ps: It might be just me, but I was far from deducting that from the man page:

DNS suffix, DNS servers

2009-03-17 Thread Markus Wernig
the client's DNS server assignment, but I can't make out which attribute might contain the DNS suffix the client will get sent. Is there any? kind regards Markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply with group attribute

2009-03-13 Thread Markus Wernig
are in on the freeradius server. So I need the radius server to return the user's group information together with the Access-Accept. I'm sorry but for the life of me I can't find any information on how this is done. Could somebody please point me to the right direction? Thanks /markus - List info

Re: Reply with group attribute

2009-03-13 Thread Markus Wernig
to the Firewall user group they will be using for their access. [...] --- UNQUOTE --- So, the question is: How do I make freeradius return the users' group as a class attribute in the authentication reply? Thanks for any hint. /markus Markus Wernig wrote: What I'm looking for (and can't find

Re: Reply with group attribute

2009-03-13 Thread Markus Wernig
-Type = Access-Accept Fri Mar 13 15:54:45 2009 Class := 0x So, afaict, the group attribute doesn't make it into the reply. Where should I put that line? Do I need to echo it? thx again /markus t...@kalik.net wrote: So, the question is: How do I make freeradius return the users' group

Re: Reply with group attribute

2009-03-13 Thread Markus Wernig
in authorize. Sorry, I don't understand that. There is an authorize section in /etc/freeradius/sites-enabled/default. If I change it to unix { Class := %{Group} } I get the following error when starting freeradius: Unknown action '%{Group}' /markus - List info/subscribe/unsubscribe? See http

Re: Reply with group attribute

2009-03-13 Thread Markus Wernig
{ ... unix update reply { Class := %{Group} } ... } Which gives the ERROR: Cannot find a configuration entry for module update. Clear, update is not a module. But where does such a directive go? thx /markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Reply with group attribute

2009-03-13 Thread Markus Wernig
checking against /etc/group automatically. This entry was already in the 1.1.7 modules/etc_group You need to use passwd module to populate Group: Is this possible on a system using shadow passwords? Thank you /markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Reply with group attribute

2009-03-13 Thread Markus Wernig
Alan DeKok wrote: In a new version of the server. Yes, indeed. I'm on 2.1.0 now, and no trick whatsoever will make it populate the Group or Group-Name attribute. doh /m - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Reply with group attribute

2009-03-13 Thread Markus Wernig
t...@kalik.net wrote: Did you read rlm_passwd man page? Of course So I put filename /etc/group { format = My-Group-Name:::*,User-Name } into /etc/freeradius/modules/passwd and ATTRIBUTE My-Group-Name 3000 string into /etc/freeradius/dictionary (btw. can't put in Group-Name

Re: Using Exec-Program-Wait for MOTP (mobile OTP) with MSCHAPv2

2009-02-13 Thread Markus Gaugusch
ago. Especially, it does not do the one time check correctly, because a token code can be reused until it expires!. To enable pam, I just wrote pam into the authenticate section, that's it. (and of course have a proper /etc/pam.d/radiusd file) Markus - List info/subscribe/unsubscribe? See http

Override pam_auth in virtual server

2009-02-09 Thread Markus Gaugusch
to a module /etc/raddb/sites-enabled/svn-extern[68]: Errors parsing authorize section. } } Any hints? :) Markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-12 Thread Markus Krause
Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread Markus Krause
the latter) do not return a value for the field userPassword the problem is on the LDAP side. markus -- This message was sent using https://webmail.biochem.mpg.de If you encounter any problems please report to [EMAIL

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread Markus Krause
Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been set to be used for authenication during the SUSE install. This is proven by the ability to log in to the box, both locally

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread Markus Krause
Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been set to be used for authenication during the SUSE install

Re: Using freeradius integrated with Active Directory toautenticatecisco passwords

2008-02-02 Thread Markus Moeller
You can use pam with a pam_krb5 module to authenticate users to AD. Markus Ivan Kalik [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] rad_recv: Access-Request packet from host 10.131.23.252:1645, id=84, length=79 NAS-IP-Address = 10.131.23.252 NAS-Port = 11

Re: Upgrade error for LDAP in Freeradius2.0

2008-01-27 Thread Markus Moeller
I think it should then be updated in rlm_ldap.c. Who maintains this module ? Thank you Markus Alan DeKok [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] Gopinath Reddy N wrote: We have not changed any data in AD. But when we upgrade and try to connect using valid user id..user

Re: Question about unlang functionality

2008-01-27 Thread Markus Moeller
Does this mean it is treated differently in an if condition where I don't need the quotes ? Couldn't the switch statement treat the word the same way as the if statement treats the left hand side word and the case word like the right hand side of an if statement ? Thank you Markus Alan

Re: Upgrade error for LDAP in Freeradius2.0

2008-01-26 Thread Markus Moeller
: vps = request-config_items; break; case 1: vps = request-packet-vps; packet = request-packet; break; Markus Gopinath Reddy N [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] Hi, We have upgraded our

Re: Force Auth-Type

2008-01-26 Thread Markus Moeller
that look OK ? Thank you Markus BTW Are you intereseted in my Mozilla SDK patch for the ldap module ? Alan DeKok [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] Markus Moeller wrote: if (%{ldap: stuff... } == bar) { ... I didn't know that is possible. Where is this documented

Question about unlang functionality

2008-01-26 Thread Markus Moeller
programming ? Thank you Markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Force Auth-Type

2008-01-25 Thread Markus Moeller
Alan DeKok [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] Markus Moeller wrote: That was the only way I could get it to work. If I use update control anybody can login, whereas in my setup only a user who exits in ldap get AUth-Type set to LDAP all other users have an empty value

Re: simple Ldap-group search

2008-01-25 Thread Markus Moeller
I think you need to use Ldap-Group instead of myldap-Ldap-Group or do you use do_xlat ? Markus cxu [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] Background: When a user associated with the ssid Guest, the user will authenticate against a FreeRadius server. If he has

Re: Force Auth-Type

2008-01-24 Thread Markus Moeller
Alan DeKok [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] Markus Moeller wrote: I am new to freeradius and try to authenticate users with pam and authorize with ldap groups. I try to find a minimal configuration but have some problems forcing the Auth-Type to be PAM. You

Patch for rlm_ldap to use mozilla sdk (e.g. on Solaris)

2008-01-23 Thread Markus Moeller
Find attached a patch to use the mozilla sdk instead of openldap for rlm_ldap. Use -DHAVE_LDAPSSL_ADVCLIENTAUTH_INIT and change ldap_r to ldap in configure. Markus rlm_ldap_mozilla.patch Description: Binary data - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Force Auth-Type

2008-01-23 Thread Markus Moeller
the use of the ldap.attribute mapping as I really don't need it ? Thank you Markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

mod_auth_radius

2007-07-19 Thread Rascher, Markus
error on line 205 of /etc/httpd/conf/httpd.conf: Cannot load /usr/lib/httpd/modules/mod_auth_radius-2.0.so into server: /usr/lib/httpd/modules/mod_auth_radius-2.0.so: undefined symbol: ap_snprintf [FAILED] Thanks for your answers. Markus - List info/subscribe/unsubscribe? See http

NAS-IP-Address - localhost

2007-06-27 Thread Rascher, Markus
radcheck-stored-procedure does not work. Can someone help? Is there a method to convert the 127.0.0.1 to the real ip? Nslookup? Thanks Markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

AW: freeradius performance , requests per second

2007-06-19 Thread Rascher, Markus
Via DB and Accounting via files. Greetings Markus -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Alan DeKok Gesendet: Dienstag, 19. Juni 2007 10:22 An: FreeRadius users mailing list Betreff: Re: freeradius performance , requests per second

Pam_radius_Auth - Problem

2007-06-18 Thread Rascher, Markus
for 1 seconds Finished request 24 Going to the next request Shared secret is ok, I checked it twice... I think the sshd refuses users which are not in the passwd-file and sends this confusing password-Attribute to the pam_radius-module, but why Thanks for your help Markus - List info

AW: encrypted password

2007-06-13 Thread Rascher, Markus
Did you try Crypt-Local auth-Type? -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Felipe Ceglia - PY1NB Gesendet: Mittwoch, 13. Juni 2007 00:26 An: FreeRadius users mailing list Betreff: Re: encrypted password Hi Arran, Thank you for your

Markus Wintruff istaußer Haus.

2007-06-07 Thread markus . wintruff
Ich werde ab 07.06.2007 nicht im Büro sein. Ich kehre zurück am 10.06.2007. Bitte wenden sie sich an Michael Cochu [EMAIL PROTECTED] +49-40-7339-1432. I am not in the office. Please contact Michael Cochu [EMAIL PROTECTED] +49-40-7339-1432. - List info/subscribe/unsubscribe? See

AW: using encrypted passwords in users file or sql-radcheck table

2007-05-30 Thread Rascher, Markus
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Alan Dekok Gesendet: Mittwoch, 30. Mai 2007 11:42 An: FreeRadius users mailing list Betreff: Re: using encrypted passwords in users file or sql-radcheck table Rascher, Markus wrote: Hi all, cleartext, unix crypt and MD5 - Passwords work

AW: AW: using encrypted passwords in users file or sql-radcheck table

2007-05-30 Thread Rascher, Markus
An: FreeRadius users mailing list Betreff: Re: AW: using encrypted passwords in users file or sql-radcheck table Rascher, Markus wrote: With pap I'm running into problems... Can u give me an example config? In users-File I have: (Password is 'testpwd') testuserAuth-Type = PAP, MD5-Password

using encrypted passwords in users file or sql-radcheck table

2007-05-29 Thread Rascher, Markus
Hi all, cleartext, unix crypt and MD5 - Passwords work fine in both, users file and db. does sha1-hashed pwds work? another question: can i use symmetric password encryption in users-File or radcheck table? thx for your help - List info/subscribe/unsubscribe? See

AW: Grouping users and clients

2007-05-24 Thread Rascher, Markus
Hi, I want to do the same, but with a sql-Database. Are there schemas for grouping users and devices? -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Giovanni Lovato Gesendet: Donnerstag, 24. Mai 2007 10:23 An: FreeRadius users mailing list

AW: AW: Grouping users and clients

2007-05-24 Thread Rascher, Markus
to find find out if the user should have access to the requested service. I don't know if this is possible in ldap too... I guess not. Greez Markus - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Freeradius and rlm_mysql with encrypted PWD's

2007-05-22 Thread Rascher, Markus
Hi All, In Prev. Threads i read about the same Problem i have now. But i never found an answer which solves my problem. My question is: what kind of Password-encryption is supported in the mysql-DB used by the Freeradius-Server to authenticate Users. Cleartext-PWD's are working fine.

Markus Wintruff istaußer Haus.

2007-05-11 Thread markus . wintruff
Ich werde ab 12.05.2007 nicht im Büro sein. Ich kehre zurück am 21.05.2007. Bitte wenden sie sich an Michael Cochu [EMAIL PROTECTED] +49-40-7339-1432. I am not in the office. Please contact Michael Cochu [EMAIL PROTECTED] +49-40-7339-1432. - List info/subscribe/unsubscribe? See

Radius accounting

2007-04-17 Thread markus . wintruff
Hy all, i use freeradius 1.1.3 here is my problem: i use radiusaccounting into a mysql database. I want to extract information out of the accounting packet and insert it into the sql database: My Acct-Session-Id looks like this. Acct-Session-Id = domain\\userThu Mar 1 14:29:58 2007NC the

Re: FreeRADIUS 1.1.6 has been released.

2007-04-12 Thread Markus Krause
:-) regards markus Zitat von Alan DeKok [EMAIL PROTECTED]: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The only new features in this release are a few dictionaries. All of the other changes are bug fixes, including the double-free's that were in 1.1.5. We also fixed approximately

Re: FreeRADIUS 1.1.6 has been released.

2007-04-12 Thread Markus Krause
to something weired, e.g. php5 with php4-mysql or something else but the average admin should be able to avoid this. at least it works here for me ... (well the pages are displayed correctly in a browser, i can not test more as i am using ldap as backend here) regards markus

howto define Auth-Type in perl script?

2007-03-18 Thread Markus Krause
found when running radiusd -XAs. How can i set Auth-Type from a perl script or how is this done correctly? Thanks in advance for any hints! regards, markus +-+ | Markus Krause, Mogli-Soft

Re: howto define Auth-Type in perl script?

2007-03-18 Thread Markus Krause
Zitat von Tomas Hoger [EMAIL PROTECTED]: On 3/18/07, Markus Krause [EMAIL PROTECTED] wrote: i am writing a perl script to authorize and authenticate users. authorization works (so the script itself works and seems to be used by freeradius as expected) but as i do not know how to define

Re: Debian

2007-03-12 Thread Markus Krause
sql HPW IPPools. -- Nicolas Baradakis [EMAIL PROTECTED] Mon, 09 Mar 2007 20:06:04 +0100 = end of example this is only an example, the actual text is not so important, just the version number in brackets, and of course add _your_ email address! regards markus

Re: Building freeradius 1.1.5 packages on Debian

2007-03-09 Thread Markus Krause
the correct version updated... Alan DeKok. afaik the debian package builder takes this information from the file debian/changelog. regards markus +-+ | Markus Krause, Mogli-Soft | | Support

Re: MAC authorisation (but not authentication) via LDAP

2007-02-25 Thread Markus Krause
Zitat von Phil Mayers [EMAIL PROTECTED]: Markus Krause wrote: i am not sure if your approach could really fullfill my needs (no redundancy, serving different types of requests) ... but i would really like to know ;-) Hmm. Without more details it's difficult to say, but what you need does

Re: MAC authorisation (but not authentication) via LDAP

2007-02-25 Thread Markus Krause
Zitat von Phil Mayers [EMAIL PROTECTED]: Markus Krause wrote: modules { ... ldap LdapUser1 { ldapserv1 } ldap LdapUser2 { ldapserv2 } ... } authorize { ... Autz-Type LdapUser { redundant

Re: Newbie question

2007-02-25 Thread Markus Krause
as far as i kno udp usually has no states so netstat can show nothing on port 1812 (most of the time). just a few guesses: did you try radtest or radclient? does tcpdump udp port 1812 show any attempts of the ap to connect to the server? did you set up clients.conf? markus Zitat von M

Re: MAC authorisation (but not authentication) via LDAP

2007-02-24 Thread Markus Krause
} ... } the Auth-Type is set in users file depending on huntgroups: DEFAULT Huntgroup-Name == switch, Autz-Type := LdapMAC, Auth-Type := LdapMAC i assume there are better/smarter sollutions as one can read don't set Auth-Type on many places but it works here ;-) regards markus

Re: MAC authorisation (but not authentication) via LDAP

2007-02-24 Thread Markus Krause
Zitat von Phil Mayers [EMAIL PROTECTED]: Markus Krause wrote: don't no if it is a good solution, but i just do this by setting the following in radiusd.conf: authenticate { ... Auth-Type LdapMAC { ok } ... } the Auth-Type is set in users file depending

Re: MAC authorisation (but not authentication) via LDAP

2007-02-24 Thread Markus Krause
Zitat von Martin Whinnery [EMAIL PROTECTED]: Thanks Markus, the problem seems to be that the authorisation pass returns notfound, whereas I want it to reject, as if it found an entry in LDAP without the appropriate attribute. Mart Hi Mart, ugh, you are of course right, i forgot

Re: Removing characters from usernames

2007-02-01 Thread Markus Krause
= : new_attribute = no append = no } } i call it just before the actual ldap-module i am using. hth regards markus Zitat von Andrew Zirkel [EMAIL PROTECTED]: I was thinking I could do something like this with a regular expression

Re: Why Freeradius and Mysql dont work?

2007-01-28 Thread Markus Krause
: Instantiated sql (sql) Do you see those? Regards markus -- Markus Krause email: [EMAIL PROTECTED] Mogli-Soft: Support for Mac OS X, Webmail/Horde, LDAP, RADIUS by order of the Computing Center of the Max-Planck-Institute of Biochemistry Tel.: 089 - 89 40 85 99

Re: strange error in freeradius

2007-01-28 Thread Markus Krause
markus -- Markus Krause email: [EMAIL PROTECTED] Mogli-Soft: Support for Mac OS X, Webmail/Horde, LDAP, RADIUS by order of the Computing Center of the Max-Planck-Institute of Biochemistry Tel.: 089 - 89 40 85 99 Fax.: 089 - 89 40 85 98

Re: strange error in freeradius

2007-01-28 Thread Markus Krause
markus -- Markus Krause email: [EMAIL PROTECTED] Mogli-Soft: Support for Mac OS X, Webmail/Horde, LDAP, RADIUS by order of the Computing Center of the Max-Planck-Institute of Biochemistry Tel.: 089 - 89 40 85 99 Fax.: 089 - 89 40 85 98

Re: post-proxy section and local proxy

2007-01-23 Thread Markus Krause
Hi Alan, thanks for your answer! Zitat von Alan DeKok [EMAIL PROTECTED]: Markus Krause wrote: i found out that if i am doing local proxying (by setting authhost = LOCAL in proxy.conf) That's NOT local proxying. It's a hack for telling the server that the realm exists, and it's

post-proxy section and local proxy

2007-01-22 Thread Markus Krause
a better solution for my problem? Thanks in advance for any help! Regards markus -- Markus Krause email: [EMAIL PROTECTED] Mogli-Soft: Support for Mac OS X, Webmail/Horde, LDAP, RADIUS by order of the Computing Center of the Max-Planck-Institute

setting user profile depending on realms?

2007-01-17 Thread Markus Krause
) ? Or is there even a better way to achieve this goal and i am thinking in a completly wrong direction? Thanks in advance for any hints! Regards Markus -- Markus Krause email: [EMAIL PROTECTED] Mogli-Soft: Support for Mac OS X, Webmail/Horde, LDAP, RADIUS

overwriting ldap radiusprofile according to realms?

2007-01-07 Thread Markus Krause
/ vlan according to login)? Thanks in advance for any help! Reagards Markus -- Markus Krause email: [EMAIL PROTECTED] Mogli-Soft: Support for Mac OS X, Webmail/Horde, LDAP, RADIUS by order of the Computing Center of the Max-Planck-Institute

Re: FreeRADIUS for Mac OS X

2006-11-04 Thread Markus Krause
Hi Paul, i compiled it on Mac OS X 10.4.7. Maybe you need XCode? (see http://developer.apple.com/tools/xcode/) regards markus Zitat von Paul Ammann [EMAIL PROTECTED]: Hi Markus Thank you for the email. I tried that and I got the same error messages. May I ask what version of Mac OS X

Re: FreeRADIUS for Mac OS X

2006-11-03 Thread Markus Krause
. regards markus Zitat von Paul Ammann [EMAIL PROTECTED]: Hi I'm looking for information for compiling / downloading FreeRADIUS for Mac OS X. I searched the list, and all the information seem outdated or inconclusive. Best regards, Paul -- Markus Krause

Re: Wiki

2006-10-30 Thread Markus Krause
Zitat von King, Michael [EMAIL PROTECTED]: Anyone else having trouble getting to the Wiki right now? yes, does not work here ... (munich ;-) markus -- Markus Krause email: [EMAIL PROTECTED] Mogli-Soft: Support for Mac OS X, Webmail/Horde, LDAP, RADIUS

Re: Short Deployment Platform Questionaire

2006-08-31 Thread Markus Krause
in Advance from the FreeRADIUS Development Team thanks in return to all developers for their great work and assistance! markus -- Markus Krause email: [EMAIL PROTECTED] Mogli-Soft: Support for Mac OS X, Webmail/Horde, LDAP, RADIUS by order of the Computing Center

Re: Cannot compile and run on Mac OS X 10.4.7

2006-08-30 Thread Markus Krause
). but i should point out that i do not use any sql-module (do not have the libraries installed which were required) or unixodbc, and have no libgdbm, so there is no rlm_counter, rlm_ippool. maybe there is your problem? i am using a recent mac os 10.4.7 on an ancient g4 powerbook. regards markus

Re: Cannot compile and run on Mac OS X 10.4.7

2006-08-23 Thread Markus Krause
Hi Michael, i was able to build freeradius (at least without any sql support) just yesterday from the latests cvs snapshot without any modifications. maybe you could try this or wait (one day or two?) until the next release (1.1.3). regards markus Zitat von Michael Check [EMAIL PROTECTED

Re: AAA

2006-08-01 Thread Markus Krause
= dialupAccess in the ldap section of your module definition. hth markus -- Roger --- Sign Up for free Email at http://ureg.home.net.my/ --- - List info/subscribe/unsubscribe? See http

bandwidth restrction with radius and PPTP

2006-01-13 Thread Markus Wiedner
Dear all, I have sorted out to configure freeradius/mysql on poptop server. Now i want to restrict bandwidth per user. What procedure should I follow. I know how to restrict bandwidth with tc iproute2 package. But don't know how to integrate tc with freeradius/mysql on poptop server. has any

Re: Error in Radius.log

2005-12-26 Thread Markus Krause
Location: http://map.datastormusers.com/user2.cfm?user=1591 My Web Page: http://www.rvfulltimer.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html regards markus -- Markus Krause email: [EMAIL PROTECTED] Computing Center

Re: Error in Radius.log

2005-12-26 Thread Markus Krause
Zitat von LeRoy DeVries [EMAIL PROTECTED]: On Monday 26 December 2005 06:15, Markus Krause wrote: Zitat von LeRoy DeVries [EMAIL PROTECTED]: I'm getting the following error in the radius log and don't know how to handle it. I assume it's handled somewhere within the radius.conf file

Re: Error in Radius.log

2005-12-26 Thread Markus Krause
Zitat von LeRoy DeVries [EMAIL PROTECTED]: On Monday 26 December 2005 12:41, Markus Krause wrote: I'm finally making progress. Now I'm getting the following: modcall: group authorize returns ok for request 0 auth: type Local auth: user supplied User-Password does NOT match local User

Re: patch for sqlcounter, please test!

2005-12-23 Thread Markus Krause
. Alternativelly, you could use the Expire attribute, you just put a date in it, and Freeradius will calculate the Session-Timeout. but doesn't the exipre attribute have to be set to a fixed date? i want to have the account lets say three days from first usage. regards, markus -- Markus Krause

Re: use of pam and sql db simultaneously

2005-12-23 Thread Markus Krause
Zitat von Alan DeKok [EMAIL PROTECTED]: Markus Krause [EMAIL PROTECTED] wrote: i would like to authenticate users via pam and sql. Huh? I don't know what that means. Usually if the user has a password, they have one password, which can be stored in one place. You don't need to use both

patch for sqlcounter, please test!

2005-12-22 Thread Markus Krause
feedback! ;-) with best regards, markus -- Markus Krause email: [EMAIL PROTECTED] Computing CenterTel.: 089 - 89 40 85 99 Group Lottspeich / Proteomics Fax.: 089 - 89 40 85 98

RE: regexp with ldap

2005-11-27 Thread Markus Krause
(or another better / more sophisticated way) i am still very interested in every example! regards markus Zitat von Seferovic Edvin [EMAIL PROTECTED]: Hello, has anyone got this working. I have a similar setup, but Ive decided to have an extra copy of mac-addresses in my ldap tree for mac-auth

Re: Outter User-Name for Accounting in EAP-TTLS

2005-11-23 Thread Markus Krause
? regards, markus Zitat von kevin [EMAIL PROTECTED]: I am resending this 'cause nobody reponded. Any idea? Kevin I want to use FreeRadius for proxy so our map is like AP - FreeRadius - MyRadius Problem is MyRadius gets user-name=anonymous in accounting. Is there a way that we can put

Re: pb w/ accounting: wrong username (anonymous) used

2005-11-14 Thread Markus Krause
start. can this be due to misconfiguration or is there something broken in the sql module? thanks in advance for any hints! regards, markus Zitat von Alan DeKok [EMAIL PROTECTED]: Markus Krause [EMAIL PROTECTED] wrote: Sending Access-Accept of id 238 to 192.168.10.2:2430

sqlcounter and session-timeout

2005-11-12 Thread Markus Krause
no attribute Max-Days-Passed... how can i override the value of session-timeout, lets say for 10 minutes (i dont care if a user can stay connected until 0:10) ?? thanks in advance for any hints!! with best regards, markus -- Markus Krause email: [EMAIL PROTECTED

pb w/ accounting: wrong username (anonymous) used

2005-11-12 Thread Markus Krause
as entry in the mysql table radacct is always anonymous! the table radpostauth does contain entries from both anonymous and user1. how can i fix this? thanks in advance for any hints!! with best regards, markus -- Markus Krause email: [EMAIL PROTECTED] Computing

rlm_radutmp: No NAS-Port seen

2005-11-12 Thread Markus Krause
comes from eap-ttls) thanks in advance for your help! with best regards, markus -- Markus Krause email: [EMAIL PROTECTED] Computing CenterTel.: 089 - 89 40 85 99 Group Lottspeich / Proteomics Fax.: 089 - 89 40 85 98

Re: pb w/ accounting: wrong username (anonymous) used

2005-11-12 Thread Markus Krause
the correct User-Name (or did i misunderstood your answer??) but in the mysql table radacct still username=anonymous is inserted. it seems i am on the wrong way ... or can there something wrong with the accesspoint (foundry ironpoint 200) thanks in advance for your help! regards, markus Zitat von Alan

using ldap, sql and pam for user authentification

2005-11-02 Thread Markus Krause
modules? thanx in advance for your help! regards markus -- Markus Krause email: [EMAIL PROTECTED] Computing CenterTel.: 089 - 89 40 85 99 Group Lottspeich / Proteomics Fax.: 089 - 89 40 85 98

erros building suse rpm

2005-10-22 Thread Markus Krause
containing this information (after install-scripts: in src/modules/rlm_perl/Makefile.in) the building is succesfull, and the installed package works correctly. what would the correct action and not a work-around? regards, markus -- Markus Krause email: [EMAIL PROTECTED

Re: erros building suse rpm

2005-10-22 Thread Markus Krause
) building the rpm works perfectly. regards, markus Zitat von Andrew Teixeira [EMAIL PROTECTED]: Hello, I'm no expert on freeradius, but I have done some extensive RPM packaging, so my suggestions are as follows: At the end of the %install section of the SPEC file, just add a line stating rm

ldap filter question

2005-10-21 Thread Markus Krause
? thanks in advance for any tipps! regards, markus -- Markus Krause email: [EMAIL PROTECTED] Computing CenterTel.: 089 - 89 40 85 99 Group Lottspeich / Proteomics Fax.: 089 - 89 40 85 98

Re: access for 24 hours after first login?

2005-10-06 Thread Markus Krause
Zitat von Alan DeKok [EMAIL PROTECTED]: Markus Krause [EMAIL PROTECTED] wrote: i set up freeradius succesfully for authentification against pam and users file :-) Please don't use authentification. It's authentication. sorry for my poor english, it's not my mother-tongue ... now i

RE: [m0n0wall] RE: access for 24 hours after first login?

2005-10-06 Thread Markus Krause
WHERE UserName = '%(%k)' LIMIT 1; would this mean that a user can login until 23:59 after logged in the first time that day? thank you very much for your help (and of course the help of everybody else on this greate mailing list!) regards, markus Zitat von Jonathan De Graeve [EMAIL PROTECTED

access for 24 hours after first login?

2005-10-05 Thread Markus Krause
of lets say 100 accounts and if they have been used just create new ones). (how) can this be realized using freeradius? has anyone set up a similar (or even better ;-) ) solution for this aim? (one-day passwords valid after first login) thanks for any help and hints! regards, markus -- Markus

Re: Debian 802.1x LDAP

2005-08-16 Thread Markus Krause
tried building from source and can't even get LDAP working.. each time I un-comment the ldap line from the radiusd.conf file and try to start using radiusd -x I get a segfault. for version v1.0.2: just add --with-rlm_eap_tls in debian/rules hth markus Ideally I would like to stick

seg. fault with eap/tls and wrong certificate

2005-08-11 Thread Markus Krause
Segmentation fault -8- actually i am not sure to have all configured correctly because i get an access-accept reply regardless of username and password but with the 'correct' certificate. btw: the client is a mac os x 10.3.9 any ideas anyone?? thanks in advance for any hint! markus

eap/tls access-accept without existing user?

2005-08-11 Thread Markus Krause
? thanks in advance for any hint!! markus -- Markus Krause email: [EMAIL PROTECTED] Computing CenterTel.: 089 - 89 40 85 99 Group Lottspeich / Proteomics Fax.: 089 - 89 40 85 98

conecpt question

2005-08-11 Thread Markus Krause
! ;-) markus -- Markus Krause email: [EMAIL PROTECTED] Computing CenterTel.: 089 - 89 40 85 99 Group Lottspeich / Proteomics Fax.: 089 - 89 40 85 98 - This message

Re: authentication by mac adress, username and password

2005-03-19 Thread Markus Krause
in this file? thanks in advance for any hints! markus Zitat von Alexandre Coninx [EMAIL PROTECTED]: On Thu, Mar 17, 2005, Markus Krause wrote: hi all, i want to authenticate users at a cisco router by checking the mac-adress, the username and the password. (how) can this be done using

authentication by mac adress, username and password

2005-03-17 Thread Markus Krause
with a username (i found info for either username or mac adress togehter with a password). and is it possible that freeradius gives the cisco router a vlan depending on the username (or maybe group)? thanks in advance for your help! markus -- Markus Krause email: [EMAIL

authentication Problem

2004-09-23 Thread Markus Blasl
for the perl part, which still gives back the correct vlan, if a client tries to authenticate. Does anyone have an idea, what kind of problem could exist here? Thanks in advance, Markus Blasl PS: here in our company, we are using one switch and the customer is using a stacked switch, maybe that could

  1   2   >