RE: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-08 Thread Domenico Viggiani
Brett Littrell wrote: Not sure if your just having issues with the OID or something else, but I found the thread really helped to fix cert issues I had.  http://lists.cistron.nl/pipermail/freeradius-users/2006-October/msg00515.htm l  I used the MS cert server as described in this listing as

Re: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-08 Thread John Dennis
On 02/08/2011 06:16 AM, Domenico Viggiani wrote: Thanks but I think that recent versions of Freeradius contains a certs generation script that provide test certificates with all OIDs needed. Or am I wrong? I'm currently still unable to authenticate a XP SP3 client to FR by Active Directory. I

RE: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-08 Thread Brett Littrell
I do not recall FR 2.11 default working with Windows so I followed the instructions from the link I posted and it started to work after that; of course I am using a LDAP back end not AD directly. I can and do authenticate Windows XP SP3 no problem against FR, but as I said it is with an LDAP

Re: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Alan Buxey
Hi, } # server inner-tunnel [peap] Got tunneled reply code 11 EAP-Message = 0x010a00331a0309002e533d4341303635413435333430423234384542433237433546463731 3133303545423545354633383131 Message-Authenticator = 0x State =

RE: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Domenico Viggiani
..this is where it ends - an access challenge never gets responded to. do you have the CA of the RADIUS server installed on the client? No but I disabled Validate Server Certificate on the client. Is it not enough? Thanks again for quick reply -- DV - List info/subscribe/unsubscribe? See

Re: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Alan Buxey
Hi, ..this is where it ends - an access challenge never gets responded to. do you have the CA of the RADIUS server installed on the client? No but I disabled Validate Server Certificate on the client. Is it not enough? add the CA alan - List info/subscribe/unsubscribe? See

RE: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Domenico Viggiani
..this is where it ends - an access challenge never gets responded to. do you have the CA of the RADIUS server installed on the client? No but I disabled Validate Server Certificate on the client. Is it not enough? add the CA Done but same problem. I read certs/README file with

Re: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Alan DeKok
Domenico Viggiani wrote: Done but same problem. I read certs/README file with MANY other caveats about Windows: http://deployingradius.com has *complete* and *detailed* instructions for getting EAP to work with Windows. I'm forced to abandone this project and resort to M$'NAP server :(

RE: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Domenico Viggiani
I'm forced to abandone this project and resort to M$'NAP server :( If it works with NAP, you can get it to work with FreeRADIUS. There are 10's of 1000's of sites using Windows clients with FreeRADIUS. There is *every* reason to believe that it works. Of course. Sorry for my previous

Re: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Alan Buxey
Hi, I'm forced to abandone this project and resort to M$'NAP server :( if you do, then its your loss and you'll be limited for the future of your infrastructure. use freeRADIUS - after all, at least it will give you information and debug detailed informationwhen NPS goes wrong...well,

RE: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Domenico Viggiani
if you do, then its your loss and you'll be limited for the future of your infrastructure. use freeRADIUS - after all, at least it will give you information and debug detailed informationwhen NPS goes wrong...well, good luck. I understand very well: I used older M$'IAS and it offered NO

Re: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Alan Buxey
Hi, service (installed from Red Hat official RPM package, not compiled). What else can I do? A client PC with an OS different from XP? for initial testing/verification, use a client that isnt stupid or fussy. I'd say start with basic reference system - eg Linux with wpa_supplicant (eg

RE: 802.1x on Active Directory: no errors in debug but auth fails

2011-02-07 Thread Brett Littrell
Hi Not sure if your just having issues with the OID or something else, but I found the thread really helped to fix cert issues I had. http://lists.cistron.nl/pipermail/freeradius-users/2006-October/msg00515.html . I used the MS cert server as described in this listing as well as used