Re: FreeRadius on MacOS X Server

2010-08-18 Thread Andreas Hubert
Do you have any other idea, after I sent out the logs of both servers, the one where everything works and the other server where it don't work? Am 17.08.10 21:56, schrieb Alan DeKok: Andreas Hubert wrote: I dont know if updating is such a good idea. Mac OS X comes with 2.1.3 and another

Re: FreeRadius on MacOS X Server

2010-08-18 Thread Andreas Hubert
Okay, I just found out I messed something with the eap.conf on my first server, I accidental out commented these options: fragment_size = 1024 include_length = yes check_crl = yes CA_path = /path/to/directory/with/ca_certs/and/crls/ check_cert_cn = %{User-Name} But now the eap.conf is on both

Re: FreeRadius on MacOS X Server

2010-08-18 Thread Alan DeKok
Andreas Hubert wrote: But now the eap.conf is on both servers nearly the same (without certificate paths). I tried to make the problem happen again, mabye now it is easier in the log files to see the difference. Or should I maybe add here my complete config folder of booth servers? I

Re: FreeRadius on MacOS X Server

2010-08-18 Thread Andreas Hubert
Use an AP that works. Use a client PC that works. The strange thing is, both work, but only together with the second server, not with the first one. On the AP I can enter two RADIUS servers, in case one gets down, what I also want to use. I also switched them in the configuration with

Re: FreeRadius on MacOS X Server

2010-08-18 Thread Alan DeKok
Andreas Hubert wrote: I really have no clue, why the AP and client should work with the second server and not with the first one :( It's a networking issue. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius on MacOS X Server

2010-08-18 Thread Andreas Hubert
But all packets are coming trough, I think. Both servers are on the same subnet, with same gateway. Am 18.08.10 15:53, schrieb Alan DeKok: Andreas Hubert wrote: I really have no clue, why the AP and client should work with the second server and not with the first one :( It's a networking

Re: FreeRadius on MacOS X Server

2010-08-17 Thread Andreas Hubert
Like it is always: Tue Aug 17 17:42:48 2010 : Auth: rlm_opendirectory: User ahu is authorized. Tue Aug 17 17:42:57 2010 : Error: rlm_eap: No EAP session matching the State variable. Tue Aug 17 17:44:21 2010 : Auth: rlm_opendirectory: User ahu is authorized. Tue Aug 17 17:44:30 2010 : Error:

Re: FreeRadius on MacOS X Server

2010-08-17 Thread Andreas Hubert
I dont know if updating is such a good idea. Mac OS X comes with 2.1.3 and another mailinglist reader told me that everything in his environment with Snow Leopard Server works So I guess this thing should work somehow with Mac OS X Servers freeradius 2.1.3 implementation together with

Re: FreeRadius on MacOS X Server

2010-08-17 Thread Alan DeKok
Andreas Hubert wrote: Like it is always: Tue Aug 17 17:42:48 2010 : Auth: rlm_opendirectory: User ahu is authorized. Tue Aug 17 17:42:57 2010 : Error: rlm_eap: No EAP session matching the State variable. Tue Aug 17 17:44:21 2010 : Auth: rlm_opendirectory: User ahu is authorized. Tue Aug

Re: FreeRadius on MacOS X Server

2010-08-17 Thread Andreas Hubert
I attached the log with debug mode. And I read the instructions and did this: System Preferences - Network - Select The Airport adapter in the left column -- Click Advanced (bottom right corner next to the help ?) Select the 802.1x tab Click the + to add a profile Add a User Profile Name it test

Re: FreeRadius on MacOS X Server

2010-08-17 Thread Andreas Hubert
After a bit more investigating, I think I come closer to the problem and can locate it on somewhere with Mac OS X Server Access Control List for services. We have a second server here, which is Open Directory Replica and the RADIUS connection with this server works! I attach logfile from

Re: FreeRadius on MacOS X Server

2010-08-17 Thread Andreas Hubert
Okay sorry again, I tried it completely fresh, with empty logs and debug mode. This time I don't get the error with missing com.apple.access_radius group on booth servers. Can anyone see, why who what's the problem and difference between these servers? They are boot configured the same, Airport

Re: FreeRadius on MacOS X Server

2010-08-17 Thread Alan DeKok
Andreas Hubert wrote: I dont know if updating is such a good idea. Mac OS X comes with 2.1.3 and another mailinglist reader told me that everything in his environment with Snow Leopard Server works So I guess this thing should work somehow with Mac OS X Servers freeradius 2.1.3

Re: FreeRadius on MacOS X Server

2010-08-17 Thread Alan DeKok
Andreas Hubert wrote: Okay sorry again, I tried it completely fresh, with empty logs and debug mode. Stop CC'ing me on messages to the list. In case you hadn't noticed, I *do* read the list. This time I don't get the error with missing com.apple.access_radius group on booth servers.

FreeRadius on MacOS X Server

2010-08-13 Thread Andreas Hubert
Hi all, I need help with the freeradius 2.1.3 in MacOS X Server. At the Apple discussion forum I don't get any answer. :( Using this version: radiusd: FreeRADIUS Version 2.1.3, for host i386-apple-darwin10.0, built on Feb 11 2010 at 02:25:02 Copyright (C) 1999-2008 The FreeRADIUS server

Re: FreeRadius on MacOS X Server

2010-08-13 Thread Theparanoidone Theparanoidone
Fri Aug 13 14:46:50 2010 : Auth: rlm_opendirectory: User ahu is authorized. Fri Aug 13 14:46:59 2010 : Error: rlm_eap: No EAP session matching the State variable. Greetings~ Did you turn EAP on for the network connection on the computer/laptop with the wifi card? Perhaps you need to

Re: FreeRadius on MacOS X Server

2010-08-13 Thread Alan DeKok
Andreas Hubert wrote: I also activated the debug mode and it came out this: ... rad_recv: Access-Request packet from host 192.168.214.100 port 65527, id=37, length=510 ... Sending Access-Challenge of id 37 to 192.168.214.100 port 65527 EAP-Message =