Re: EAP Session resumption reply attributes

2010-01-21 Thread James J J Hooper
On 20/01/2010 23:36, Arran Cudbard-Bell wrote: On 1/17/2010 8:37 AM, Alexander Clouter wrote: James J J Hooperjjj.hoo...@bristol.ac.uk wrote: In order to also return e.g. VLAN IDs (that could be computed from the inner User-Name in a non-session-resumption enabled config), I can move the

Re: EAP Session resumption reply attributes

2010-01-21 Thread Alexander Clouter
James J J Hooper jjj.hoo...@bristol.ac.uk wrote: How did you get around the my policy rejects you now, but i've already sent a tunneled success TLV in the TLS tunnel and you're now ignoring my EAP-Failure messages issue... or are you just happily ignoring it/ encouraging adoption of TTLS-PAP

Re: EAP Session resumption reply attributes

2010-01-21 Thread James J J Hooper
--On Thursday, January 21, 2010 10:05:36 AM + Alexander Clouter a...@digriz.org.uk wrote: James J J Hooper jjj.hoo...@bristol.ac.uk wrote: How did you get around the my policy rejects you now, but i've already sent a tunneled success TLV in the TLS tunnel and you're now ignoring my

Re: EAP Session resumption reply attributes

2010-01-20 Thread Arran Cudbard-Bell
On 1/17/2010 8:37 AM, Alexander Clouter wrote: James J J Hooperjjj.hoo...@bristol.ac.uk wrote: In order to also return e.g. VLAN IDs (that could be computed from the inner User-Name in a non-session-resumption enabled config), I can move the config that sets the VLAN to the outer tunnel

Re: EAP Session resumption reply attributes

2010-01-20 Thread Alexander Clouter
Arran Cudbard-Bell arran.cudbard-b...@hp.com wrote: On 1/17/2010 8:37 AM, Alexander Clouter wrote: James J J Hooperjjj.hoo...@bristol.ac.uk wrote: In order to also return e.g. VLAN IDs (that could be computed from the inner User-Name in a non-session-resumption enabled config), I can

Re: EAP Session resumption reply attributes

2010-01-18 Thread Alan Buxey
Hi, In order to also return e.g. VLAN IDs (that could be computed from the inner User-Name in a non-session-resumption enabled config), I can move the config that sets the VLAN to the outer tunnel post-auth ensure the inner tunnel sets: reply:outer User-Name to request:inner User-Name

EAP Session resumption reply attributes

2010-01-17 Thread James J J Hooper
Hi All, When a client does session resumption: cache { enable = yes} in eap.conf The session User-Name (from previous access-accept) is restored from the cache e.g: [ttls] Skipping Phase2 due to session resumption [ttls] Adding cached attributes to the reply: User-Name = ab1234

Re: EAP Session resumption reply attributes

2010-01-17 Thread Alexander Clouter
James J J Hooper jjj.hoo...@bristol.ac.uk wrote: In order to also return e.g. VLAN IDs (that could be computed from the inner User-Name in a non-session-resumption enabled config), I can move the config that sets the VLAN to the outer tunnel post-auth ensure the inner tunnel sets:

Re: EAP Session resumption reply attributes

2010-01-17 Thread Alan Buxey
Hi, One thing to remember, is for *your* users roaming at other universities to remember to remove the reply:User-Name attribute to protect the guilty. :) the best thing to do for this is to create a new virtual server - eg 'eduroam' - which is identical to your normal stuff EXCEPT that it

Re: EAP Session resumption reply attributes

2010-01-17 Thread James J J Hooper
On 17/01/2010 20:22, Alan Buxey wrote: Hi, One thing to remember, is for *your* users roaming at other universities to remember to remove the reply:User-Name attribute to protect the guilty. :) the best thing to do for this is to create a new virtual server - eg 'eduroam' - which is