Re: 802.1x machine authentication ads peap domainname

2009-01-29 Thread orzeh
wow! it's working great!!! Tests with two instances for now are working - thanks a lot! i'm must do more tests but it seems this is the way! regards! Lukasz 2009/1/29 : >>i'm not splitting user name from realm (well i don't know), below is >>an example with NT-Domain expand: (not working host/h

Re: 802.1x machine authentication ads peap domainname

2009-01-29 Thread tnt
>i'm not splitting user name from realm (well i don't know), below is >an example with NT-Domain expand: (not working host/host.domain.local >eap/peap but works ppp authorization from all domains User-name is >DOMAIN\\user and domain is correctly expanded it works also with >OTHERDOMAIN\\otheruser

Re: 802.1x machine authentication ads peap domainname

2009-01-29 Thread orzeh
thanks for reply i'm not splitting user name from realm (well i don't know), below is an example with NT-Domain expand: (not working host/host.domain.local eap/peap but works ppp authorization from all domains User-name is DOMAIN\\user and domain is correctly expanded it works also with OTHERDOMAIN

Re: 802.1x machine authentication ads peap domainname

2009-01-28 Thread tnt
>i know about this expand but it's expanding to only first section of >domain (eg. domain.com mschap expand gives only "domain") >i'm wondering it is possible to get to work correct expand beceause >sometimes radius must authorize users from other thrusted domains. > Can you post an example. If yo

Re: 802.1x machine authentication ads peap domainname

2009-01-28 Thread orzeh
i know about this expand but it's expanding to only first section of domain (eg. domain.com mschap expand gives only "domain") i'm wondering it is possible to get to work correct expand beceause sometimes radius must authorize users from other thrusted domains. thanks for answer! 2009/1/27 : >>

Re: 802.1x machine authentication ads peap domainname

2009-01-27 Thread tnt
>thanks but nope: >rlm_mschap: Unknown expansion string "Domain-Name" > Sorry it's NT-Domain: --domain=%{NT-Domain} Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: 802.1x machine authentication ads peap domainname

2009-01-27 Thread orzeh
thanks but nope: rlm_mschap: Unknown expansion string "Domain-Name" i'm using freeradius: FreeRADIUS Version 2.0.5, for host x86_64-pc-linux-gnu in other hands it is possible to get this to work together with domain\user and host/host123.domain.com ? regards! 2009/1/27 : >>hello for all! >>I'

Re: 802.1x machine authentication ads peap domainname

2009-01-27 Thread tnt
>hello for all! >I've configured freeradius to work with 802.x connection, everything >working well but rlm_mschap expanding user name and domain >"host/host123.domain.com" to: >username -> host123$ >domain -> domain (without .com) > >in ntlm_auth i have no correct domain name (without .com) so i'v

802.1x machine authentication ads peap domainname

2009-01-27 Thread orzeh
hello for all! I've configured freeradius to work with 802.x connection, everything working well but rlm_mschap expanding user name and domain "host/host123.domain.com" to: username -> host123$ domain -> domain (without .com) in ntlm_auth i have no correct domain name (without .com) so i've added

Re: 802.1x machine authentication patch help

2007-12-14 Thread Alan DeKok
Michael Patzer wrote: > i found the topic about "No logon workstation trust account > (0xc199)". > > i've the same problem using > freeradius-2.0.0-pre2 > samba 3.0.24 > on debian etch > > is it required to update to samba 3.0.28 (debian unstable) to fix this > issue, or cou

RE: 802.1x machine authentication patch help

2007-12-14 Thread Michael Patzer
ael Patzer Sent: Friday, December 14, 2007 1:04 PM To: freeradius-users@lists.freeradius.org Subject: Re: 802.1x machine authentication patch help i found the topic about "No logon workstation trust account (0xc199)". i've the same problem using freeradius-2.0.0-pre2

Re: 802.1x machine authentication patch help

2007-12-14 Thread Michael Patzer
essage- From: [EMAIL PROTECTED] [EMAIL PROTECTED] On Behalf Of Phil Mayers Sent: 01 October 2007 09:55 To: FreeRadius users mailing list Subject: Re: 802.1x machine authentication patch help On Fri, 2007-09-28 at 12:06 +0100, Marco Casulli wrote: > Hi Jamie, > > Marco from BBC in lond

RE: 802.1x machine authentication patch help

2007-10-01 Thread Phil Mayers
On Mon, 2007-10-01 at 10:41 +0100, Marco Casulli wrote: > Touchy! :-) Read this list for a while, then you'll see why people get irate when their advice isn't followed ;o) > > I was only asking as I am not an expert on this subject and wanted to > understand why Samba came in the loop? In a dom

RE: 802.1x machine authentication patch help

2007-10-01 Thread Marco Casulli
Behalf Of Alan DeKok Sent: 01 October 2007 10:20 To: FreeRadius users mailing list Subject: Re: 802.1x machine authentication patch help Marco Casulli wrote: > However how is samba related to this error? > > This is an error coming from the AD server no able to authenticate a >

Re: 802.1x machine authentication patch help

2007-10-01 Thread Alan DeKok
Marco Casulli wrote: > However how is samba related to this error? > > This is an error coming from the AD server no able to authenticate a > user. If you're not going to believe the answers on this list, I don't see why you're asking questions here. Q: Are you using Samba? Yes: upgrade a

RE: 802.1x machine authentication patch help

2007-10-01 Thread Marco Casulli
: FreeRadius users mailing list Subject: Re: 802.1x machine authentication patch help On Fri, 2007-09-28 at 12:06 +0100, Marco Casulli wrote: > Hi Jamie, > > Marco from BBC in london. > > I have read your message > (http://lists.cistron.nl/pipermail/freeradius-users/2005-Novem

Re: 802.1x machine authentication patch help

2007-10-01 Thread Phil Mayers
On Fri, 2007-09-28 at 12:06 +0100, Marco Casulli wrote: > Hi Jamie, > > Marco from BBC in london. > > I have read your message > (http://lists.cistron.nl/pipermail/freeradius-users/2005-November/048576.html > related to the error when the radius is trying to authenticate in AD > and I am getting

802.1x machine authentication patch help

2007-09-28 Thread Marco Casulli
Hi Jamie, Marco from BBC in london. I have read your message (http://lists.cistron.nl/pipermail/freeradius-users/2005-November/048576 .html related to the error when the radius is trying to authenticate in AD and I am getting exactly the same message. "No logon workstation trust account (0xc

Re: 802.1x machine authentication patch help

2005-11-21 Thread Jamie Crawford
I found my problem. From Andrew Bartlett himself "This is not supported against NT4. Only Samba 3.0.21rc1 and AD support this extra flag." To do machine authentication with freeradius, your workstation (supplicant) and samba server must be a member of a 2000/2003 domain. I had the supplicant an

Re: 802.1x machine authentication patch help

2005-11-18 Thread Jamie Crawford
Hi, I finally got freeradius to strip the host/ and append the $ to the host name, but it still wont validate the workstation. I get "No logon workstation trust account (0xc199)" At least now it's narrowed down to the ntlm_auth command. I tried to run the command manually with different works

Re: 802.1x machine authentication patch help

2005-11-18 Thread Jamie Crawford
Sorry for the typo, I meant to type rlm_mschap. Are there only certain files out of the /src/modules/rlm_mschap cvs snapshot that I need to copy over? Thanks, jamie >>> [EMAIL PROTECTED] 11/18/2005 12:16:43 PM >>> Make sure you used the rlm_MSchap module from the snapshot, not the rlm_chap mo

Re: 802.1x machine authentication patch help

2005-11-18 Thread Michael Griego
Make sure you used the rlm_MSchap module from the snapshot, not the rlm_chap module. They're different. --Mike Jamie Crawford wrote: Hi, I am trying to get machine authentication working with freeradius. I have patched the samba code and freeradius code. But am getting this error when the

802.1x machine authentication patch help

2005-11-18 Thread Jamie Crawford
Hi, I am trying to get machine authentication working with freeradius. I have patched the samba code and freeradius code. But am getting this error when the machine tries to authenticate. I patched the rlm_chap module by taking last nights cvs snapshot and copying over the rlm_chap folder overwr

802.1x machine authentication

2004-07-18 Thread Giles Scott
Hi,   I'm new to the list, I did a search of the archive but could not see anything near the issue I'm having.   I've managed to get Wireless 802.1x EAP PEAP working great. Next step is to get WinXP to machine authenticate, this is where I'm having a problem.   WinXP machine is a member of a