RE: Freeradius + PEAP + MSCHAPv2 + ntlm_auth + Windows XP client

2004-08-23 Thread Hand, Chris
[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Monday, August 23, 2004 5:19 PM To: [EMAIL PROTECTED] Subject: Re: Freeradius + PEAP + MSCHAPv2 + ntlm_auth + Windows XP client "Hand, Chris" <[EMAIL PROTECTED]> wrote: > Exactly... The username is not getting fed into ntlm_auth. It s

Re: Freeradius + PEAP + MSCHAPv2 + ntlm_auth + Windows XP client

2004-08-24 Thread Alan DeKok
"Hand, Chris" <[EMAIL PROTECTED]> wrote: > Yes, I am using the ntdomain realm. However, I do not see it show up in > the debugging output. Do I need to do anything other than list > "ntdomain" in the 'authorize' section to make freeradius use it? If it's listed there, you should see it printed o

RE: Freeradius + PEAP + MSCHAPv2 + ntlm_auth + Windows XP client

2004-08-24 Thread Hand, Chris
2004 10:51 AM To: [EMAIL PROTECTED] Subject: Re: Freeradius + PEAP + MSCHAPv2 + ntlm_auth + Windows XP client "Hand, Chris" <[EMAIL PROTECTED]> wrote: > Yes, I am using the ntdomain realm. However, I do not see it show up in > the debugging output. Do I need to do anything oth

Re: Freeradius + PEAP + MSCHAPv2 + ntlm_auth + Windows XP client

2004-08-25 Thread Alan DeKok
"Hand, Chris" <[EMAIL PROTECTED]> wrote: > I'm still not seeing it. If it's listed in the "authorize" section, it will be printed out in debugging mode. Are you willing to provide debug logs? > Let's start over. What is the best way of authenticating users to an > NT domain over PEAP? Am I e

freeradius PEAP/MS-CHAPv2 and aegis client setup

2005-04-12 Thread Jie Yang
Hi, All, I am setting up a freeradius server to do PEAP authentication with MS-CHAPv2. My freeradius version is 1.0.1. The supplicant is a PC running aegis client version 2.0.5. The authenticator is a Cisco Switch with dot1x enabled. When trying to authenticate the client, I always received the fol

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread tnt
As with every other freeradius problem - when it doesn't work - debug (radiusd -X). Ivan Kalik Kalik Infromatika ISP Dana 2/10/2008, "Vieri" <[EMAIL PROTECTED]> piše: >Hi, > >I'm running freeradius-2.0.5 on Linux. > >My setup is as follows: > >Windows Vista native client - Linksys AP - FreeRadiu

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread Vieri
--- On Thu, 10/2/08, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > As with every other freeradius problem - when it doesn't > work - debug > (radiusd -X). That's how I'm running it. Does the list mind if I post the debug lines? - List info/subscribe/unsubscribe? See http://www.freerad

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread Vieri
I forgot to mention that I already tried: with_ntdomain_hack = yes I'll try to post the relevant radiusd -X debug lines if the ML doesn't mind. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread Lech Karol Pawłaszek
Vieri wrote: > --- On Thu, 10/2/08, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > >> As with every other freeradius problem - when it doesn't >> work - debug >> (radiusd -X). > > That's how I'm running it. Does the list mind if I post the debug lines? You're supposed to do so! It's even in the

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread Nicolas Goutte
Am 02.10.2008 um 19:46 schrieb Vieri: --- On Thu, 10/2/08, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: As with every other freeradius problem - when it doesn't work - debug (radiusd -X). That's how I'm running it. Does the list mind if I post the debug lines? Asking for the output of

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread Alan DeKok
Vieri wrote: > However, user authentication is rejected when I add the --domain parameter: > > ntlm_auth = "/usr/bin/ntlm_auth --request-nt-key --domain=%{mschap:NT-D > omain} --username=%{Stripped-User-Name:-%{User-Name:-None}} > --challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Resp

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-03 Thread Vieri
--- On Thu, 10/2/08, Vieri <[EMAIL PROTECTED]> wrote: > I'm running freeradius-2.0.5 on Linux. > > My setup is as follows: > > Windows Vista native client - Linksys AP - FreeRadius Linux > server (PEAP/mschapv2) - Active Directory Windows server > > Everything works smoothly with the following

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-03 Thread luis a
, Nicolas Goutte <[EMAIL PROTECTED]> escribió: De: Nicolas Goutte <[EMAIL PROTECTED]> Asunto: Re: Freeradius, PEAP, Active Directory and --require-membership-of Para: "FreeRadius users mailing list" Fecha: jueves, 2 octubre, 2008 6:09 Am 02.10.2008 um 19:46 schrieb Vieri: &

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-03 Thread tnt
escribiĂł: >De: Nicolas Goutte <[EMAIL PROTECTED]> >Asunto: Re: Freeradius, PEAP, Active Directory and --require-membership-of >Para: "FreeRadius users mailing list" >Fecha: jueves, 2 octubre, 2008 6:09 > >Am 02.10.2008 um 19:46 schrieb Vieri: > >> >>

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-03 Thread tnt
Use: --username=%{mschap:User-Name} and it should work. Ivan Kalik Kalik Informatika ISP Dana 3/10/2008, "Vieri" <[EMAIL PROTECTED]> piše: >--- On Thu, 10/2/08, Vieri <[EMAIL PROTECTED]> wrote: > >> I'm running freeradius-2.0.5 on Linux. >> >> My setup is as follows: >> >> Windows Vista nativ

urgent help needed!! freeradius peap enterasys ap 3000 xp certificate failure?

2005-08-16 Thread Jamie Crawford
Hello, Trying to setup freeradius to use peap authentication using xp clients and using enterasys 3000 access points. Everything seems to work great until the certificate negotiation, then it blows chunks. I've followed the how to's on tlpd.org and "securing wlan's with wpa and freeradius" fro

Re: urgent help needed!! freeradius peap enterasys ap 3000 xp certificate failure?

2005-08-16 Thread Zoltan Ori
On Tuesday 16 August 2005 10:28, Jamie Crawford wrote: > Everything seems to work great until > the certificate negotiation, then it blows chunks. > Bad or wrong certificates. Server and supplicant need a copy of the same trusted root certificate. Zoltan - List info/subscribe/unsubscribe? S

Re: urgent help needed!! freeradius peap enterasys ap 3000 xp certificate failure?

2005-08-16 Thread Jamie Crawford
Thanks for your response. I downloaded my cacert.pem and imported it into my xp client as a trusted root authority and that did not help. Here are the steps I took to create my certs. Remember I am trying to use "PEAP". Thanks Here's what I did to create the certs. rhel as 4.0 freeradius

<    1   2