FreeRadius - LDAP

2011-07-20 Thread m4xmr
t 2 for 1 seconds Finished request 2 Going to the next request --- Walking the entire request list --- Waking up in 1 seconds... I hope, someone could help me... I'm totally in stuck. Regards, Max -- View this message in context: http://freeradius.1045715.n5.nabble.com/FreeRadius-LDAP-tp46

Freeradius + LDAP

2012-12-10 Thread Brekler Custodio
Hello guys, i was wondering, anyone knows how to configure an LDAP (phpldapadmin) to work with freeradius ?I search all over the web and couldnt find a tutorial that teachs how to configure a simple DB to work with FR.The FR is configured already, its very simple, but the LDAP i cant handle.

FreeRadius + LDAP

2004-10-04 Thread Christopher Price
I am running freeradius 1.0.0 and I am attempting to configure an LDAP backend DB to authenticate Windows users. The Windows users are using PEAP with MSCHAPv2. Earlier I got the LDAP authentication working with clear passwords, but now that the passwords are being hashed. I know that LDAP stores c

Freeradius + ldap

2010-06-25 Thread Marzieh Raoufnezhad
don't know how to do it with freeradius+LDAP. I would be grateful if you can answer me as soon as possible. Regards, Raoufnezhad - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

freeradius + ldap

2010-12-01 Thread Ana Gallardo
Hello, I'm using freeradius 2.1.10 and I want to use ldap like a backend in authorize section to take userPassword attribute (unix crypt) to authenticate the user. My problem is: the ldap server don't have public key that an admin user (who bind) can take. So I have to bind in the authorize secti

Freeradius Ldap

2011-03-21 Thread Usuário do Sistema
Hello everyone, I'm dificult with freeradius and LDAP. the user autheticate only it's work when I put in the user file User-Password clear text as follow. "maicon.pereira"Cleartext-Password := "meleca" Reply-Message = "Hello, %{User-Name}" however, my integration b

freeradius + ldap

2006-05-02 Thread ludovic cailleau
Good morning,   I have made an authentification 802.11x with Freeradius and his ‘user’ file. Now I would like to use Ldap. I have made a configuration but it does not run.   Have you got a procedure of the configuration of Freeradius and Ldap?   thank Faites de Yahoo! votre page d'accue

freeradius+LDAP

2005-02-22 Thread anderson souza
Good morning to all!! He/she would like to know some of the friends he/she knows some referring documentation the freeradius implementation + LDAP or even same a possible "road of the stones" for the configuration in the debian sarge!!! at once I thank attention of all... At

freeradius + LDAP

2005-02-23 Thread anderson souza
Good morning to all!! > > He/she would like to know some of the friends > he/she knows some referring documentation > the poptop implementation + freeradius + LDAP or even > same a possible "road of the stones" for > the configuration in the debian sarge!!! > >

Freeradius Ldap

2005-09-23 Thread Cris Boisvert
I'm setting up freeradius to talk to a Ipswitch Imail server for authetication. Just needs to do the basic User Pass... Ok. LDAP Server is 192.168.77.6 (this is all private testing) (the imail server) Domain on the server is pork.com A snippet of the config.

Freeradius LDAP

2005-09-26 Thread Cris Boisvert
Cris Boisvert wrote: > I'm setting up freeradius to talk to a Ipswitch Imail server for > authetication. > > Just needs to do the basic User Pass... Ok. > > [..] > A snippet of the config. > --- > ldap { > server = "192.168.77.6" >

freeradius + ldap

2004-01-13 Thread Joe Hetrick
Hey all, I'm currently doing a bit of battle with FreeRadius rlm_ldap. I'm not quite sure where my problems lie, so I figured I'd ask the list. Background: New OpenLDAP install with what seemed to be working entries for qmail-ldap/pop3/courier-imap-ldap to be happy but I'm afraid I'm miss

Freeradius + Ldap + attributes

2008-08-28 Thread Ivan .
Hi I have Freeradius configured with a backend of OpenLdap for user management. I would like to be able to pass attributes for Nortel and Juniper gear, which when statically defining users in user file is done via: user Auth-type:=Local, User-Password := "test" Juniper-Local-User-Name =

Freeradius LDAP problem

2007-08-29 Thread George Beitis
Hi everyone I have a problem. I set up freeradius to use a local ldap server to authenticate a user. When i say authenticate i mean check if the user is there, check their password, and accept or reject them. When i do such an authentication i get a message from freeradius saying that user is au

Re: FreeRadius - LDAP

2011-07-20 Thread Fajar A. Nugraha
On Wed, Jul 20, 2011 at 3:07 PM, m4xmr wrote: > Hello, > I'm trying to make working LDAP as authentication backend for RADIUS. > I verified that the data are right and the query to LDAP is properly working > if I use ldapsearch. does LDAP BIND work correctly using ldapsearch (i.e. ldapsearch -D)

Re: FreeRadius - LDAP

2011-07-20 Thread m4xmr
ting for bind result ... rlm_ldap: Bind failed with invalid credentials ++[ldap] returns reject Failed to authenticate the user. Using Post-Auth-Type Reject +- entering group REJECT {...} [attr_filter.access_reject] expand: %{User-Name} -> ldapuser attr_filter: Matched entry DEFAULT at line 11

Re: FreeRadius - LDAP

2011-07-20 Thread up
eturns noop > [suffix] No '@' in User-Name = "ldapuser", looking up realm NULL > [suffix] No such realm "NULL" > ++[suffix] returns noop > [eap] No EAP-Message, not doing EAP > ++[eap] returns noop > ++[unix] returns notfound > ++[files] returns no

Re: FreeRadius - LDAP

2011-07-20 Thread Massimiliano Tommasi
t;> } >> listen { >> type = "control" >> listen { >> socket = "/var/run/radiusd/radiusd.sock" >> } >> } >> Listening on authentication address * port 1812 >> Listening on accounting a

Re: FreeRadius - LDAP

2011-07-20 Thread Massimiliano Tommasi
ket = "/var/run/radiusd/radiusd.sock" >> } >> } >> Listening on authentication address * port 1812 >> Listening on accounting address * port 1813 >> Listening on command file /var/run/radiusd/radiusd.sock >> Listening on proxy address * port 1814 >&

Troubleshooting FreeRadius +LDAP

2011-09-12 Thread Ricardo Sousa
Greetings list users, I'm trying setup FreeRadius to work with LDAP in a deployment of ClearOS and have followed this How-To http://www.clearfoundation.com/docs/howtos/setting_up_freeradius2_to_use_ldap and this How-To http://deployingradius.com/documents/configuration/pap.html with success, u

AW: Freeradius + LDAP

2012-12-10 Thread Matthias Nagel
Hello, what exactly ist your problem? a) Do you want to know how to configure a web administration GUI (phpldapadmin) for your LDAP server? Then your problem is purly related to LDAP server, PHP and a web server. Hence, this is Thermometer wrong mailing list to ask for advice. b) Or do you want

PPTP + FreeRadius + LDAP

2008-11-26 Thread Douglas Macedo
Hey guys, i'm trying configure a VPN Server with PPTP, using the 'radiusclient', to connect on a FreeRadius, with auth in a LDAP Server. I "finished" the configure, but when a try connect with a client Windows XP, don't work. The radiusd -X output: = [EMAIL PROTECTED] /usr/local/etc/raddb]#

FreeRADIUS LDAP HOWTO

2009-02-14 Thread Andrew Hall
I'd just like to make other subscribers / searchers / admins pulling their hair out aware of the FreeRADIUS LDAP HOWTO available here... http://freeradius.org/radiusd/doc/ldap_howto.txt For some reason it doesn't seem to be linked to on any main website or wiki page - bizarrely inc

Secure FreeRADIUS & LDAP

2009-02-20 Thread Dan Hawker
Hi All, I used to use FreeRADIUS *years* back (iirc pre v1) on Linux and it worked rather well :) Not touched it since, however have just started a new contract and there is a requirement to use a RADIUS server to connect to our LDAP box (Red Hat Dir Server) to in turn authenticate some users/equ

Re: FreeRadius + LDAP

2004-10-04 Thread Alan DeKok
"Christopher Price" <[EMAIL PROTECTED]> wrote: > I am running freeradius 1.0.0 and I am attempting to configure an LDAP > backend DB to authenticate Windows users. The Windows users are using > PEAP with MSCHAPv2. Earlier I got the LDAP authentication working with > clear passwords, but now that th

Re: FreeRadius + LDAP

2004-10-04 Thread Christopher Price
Well, I had the LDAP auth working when I passed a cleartext password, so I assumed that they were stored in the clear. (I am not the administrator of the eDirectory server that I am authenticating against) I attempted to use the Microsoft built-in 802.1x client in conjunction with

Re: FreeRadius + LDAP

2004-10-04 Thread Alan DeKok
"Christopher Price" <[EMAIL PROTECTED]> wrote: > Well, I had the LDAP auth working when I passed a cleartext password, so > I assumed that they were stored in the clear. No. Read the debug log to see what kind of passwords are read from LDAP. > I attempted to use the Microsoft built-in 802.1x

Re: FreeRadius + LDAP

2004-10-05 Thread Christopher Price
Here is the debug information...   Starting - reading configuration files ... Using deprecated naslist file.  Support for this will go away soon. Module: Loaded expr Module: Instantiated expr (expr)

Re: FreeRadius + LDAP

2004-10-05 Thread Andreas Haumer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi! Christopher Price wrote: > I am running freeradius 1.0.0 and I am attempting to configure an LDAP > backend DB to authenticate Windows users. The Windows users are using > PEAP with MSCHAPv2. Earlier I got the LDAP authentication working with > cl

Re: FreeRadius + LDAP

2004-10-05 Thread Alan DeKok
"Christopher Price" <[EMAIL PROTECTED]> wrote: > Here is the debug information... No, it isn't. You have very carefully edited out significant portions of the debug log. I don't see why. > EAP-Message = 0x0201000b01637072696365 ... > rlm_ldap: Attribute User-Password is required f

Re: FreeRadius + LDAP

2004-10-05 Thread Alan DeKok
Andreas Haumer <[EMAIL PROTECTED]> wrote: > 2.2) The FreeRADIUS server ist set up to support MSCHAPv2 authentication. > This is not trivial and requires some fiddling. Absolutely not. If you configure a user && clear-text password, then MSCHAPv2 authentication will work the first time you

Re: FreeRadius + LDAP

2004-10-05 Thread Andreas Haumer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi! Alan DeKok wrote: > Andreas Haumer <[EMAIL PROTECTED]> wrote: > >>2.2) The FreeRADIUS server ist set up to support MSCHAPv2 authentication. >> This is not trivial and requires some fiddling. > > > Absolutely not. If you configure a user &&

Re: FreeRadius + LDAP

2004-10-05 Thread Christopher Price
  I tried starting from scratch with the default configuration files. Just for giggles I put a dummy user in the users file and commented out any reference to ldap in the authorize and authentication sections of radiusd.conf. The 802.1X worked fine in this manner. Now that I a

Re: FreeRadius + LDAP

2004-10-05 Thread Alan DeKok
Andreas Haumer <[EMAIL PROTECTED]> wrote: > But clear-text passwords are in many situations a no-no Too bad. Debugging a system is very different than running a live system. For debugging purposes, the FIRST THING anyone should do is to configure a test user && a clear-text password for th

Re: FreeRadius + LDAP

2004-10-05 Thread Alan DeKok
"Christopher Price" <[EMAIL PROTECTED]> wrote: > I tried starting from scratch with the default configuration files. Just > for giggles I put a dummy user in the users file and commented out any > reference to ldap in the authorize and authentication sections of > radiusd.conf. The 802.1X worked fi

Re: FreeRadius + LDAP

2004-10-05 Thread Stefan . Neis
Hi, > But clear-text passwords are in many situations a no-no > and usually you already have the sambav3 schema which > gives you > the windows password hashes which will work with mschapv2 > authentication The whole security of RADIUS (and any similar product) is based on clear-text pass

Re: FreeRadius + LDAP

2004-10-05 Thread Christopher Price

Doubt - Freeradius + Ldap

2010-11-01 Thread eduardo moreira
Hello list, Im new with freeradius, but read many about this and dont solve my problem. I have this problem with my implemention. Only appears this message with freeradius -X -x Mon Nov 1 15:04:23 2010 : Debug: rlm_eap: Ignoring EAP-Type/tls because we do not have OpenSSL support. Mon Nov 1 15:

Freeradius + LDAP auth

2010-11-23 Thread Old Eduardo
Sorry list, but i try to configure this in few weeks and no get sucess. Realy need help for list. im try to all sites in google, but no get sucess. i try this: http://blog.yufeng.net/index.php/2010/07/debian-poptop-freeradius-openldap/ http://wiki.freeradius.org/Rlm_ldap http://mhoran.wordpress.

Re: freeradius + ldap

2010-12-01 Thread Josip Rodin
On Wed, Dec 01, 2010 at 12:48:14PM +0100, Ana Gallardo wrote: > My problem is: the ldap server don't have public key that an admin user > (who bind) can take. So I have to bind in the authorize section with the > user and password (clear text) in the request. > authenticate { > Auth-Type PAP { >

Re: freeradius + ldap

2010-12-02 Thread Ana Gallardo
Josip, thanks for your response. Add LDAP into the authenticate section, so that it simply tries to re-bind > with the provided credentials? Like this: > >Auth-Type LDAP { >ldapPerson >} > I try this configuration too, but it doesn't work for me. Freeradius doesn'

Re: freeradius + ldap

2010-12-02 Thread Josip Rodin
On Thu, Dec 02, 2010 at 09:09:51AM +0100, Ana Gallardo wrote: > > Add LDAP into the authenticate section, so that it simply tries to re-bind > > with the provided credentials? Like this: > > > >Auth-Type LDAP { > >ldapPerson > >} > > > > I try this configuration too

Re: freeradius + ldap

2010-12-02 Thread Ana Gallardo
Hello again. Ok, now I can authenticate an user using LDAP. I'm using freeradius 2.1.10 and I want to use ldap like a backend in > authorize section to take userPassword attribute (unix crypt) to > authenticate the user. > My problem is: the ldap server don't have public key that an admin user (wh

Re: freeradius + ldap

2010-12-02 Thread Ana Gallardo
Hello Josip and thank you again for your response. This is an orthogonal issue; you don't have to allow anyone to read the > value of the userPassword attribute, you just have to get the FR ldap > module to *bind* to the LDAP server with the username and password from > the request. Ok, now I kn

Re: freeradius + ldap

2010-12-02 Thread Josip Rodin
On Thu, Dec 02, 2010 at 02:37:43PM +0100, Ana Gallardo wrote: > I have read that this is not ok > > http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg49993.html OK, and you're not doing that which is described above, so you're fine. > The configuration that work: > > ldap lda

Re: freeradius + ldap

2010-12-03 Thread Josip Rodin
On Thu, Dec 02, 2010 at 03:48:34PM +0100, Josip Rodin wrote: > > The configuration that work: > > > > ldap ldapPerson{ > >set_auth_type = yes > > } > > I think this is the catch. I don't have this particular option in my config, > but I see now that it looks like they're all 2.1.8. I re-chec

Re: Freeradius Ldap

2011-03-21 Thread joao...@gmail.com
Maicon, como vi o Pereira no seu nome, deduzo que você seja do Brasil, portanto irei responder sua pergunta em português. 1º Sim o freeradius se integra perfeitamente com o LDAP> 2º Que base LDAP vc esta utilizando? OpenLDAP, Active Directory??? 3° Como esta a configuração de seu arquivo ldap?

Re: Freeradius Ldap

2011-03-21 Thread Sven Hartge
Usuário do Sistema wrote: > Hello everyone, I'm dificult with freeradius and LDAP. > the user autheticate only it's work when I put in the user file > User-Password clear text as follow. > "maicon.pereira"Cleartext-Password := "meleca" >Reply-Message = "Hello, %{

Re: Freeradius Ldap

2011-03-22 Thread Usuário do Sistema
Hello everyone, after a long time my freeradius it's working with Ldap. The problem it was because I hasn't Installed the Samba. my aim is to use the freeradius to authencticate my wireless users with EAP-TLS. As I'm using the MSCHAP it's necessary the attributes SambaNTPassword and SambaLMPass

Re: Freeradius + ldap

2006-04-26 Thread Phil Mayers
ludovic cailleau wrote: Good morning, I send this email because I don't found my error about freeradius + ldap. I thinhk, I have an error of the userPassword at the request 7. Please don't send mails directly to me. I'm not a personal helpline. The mailing list is the ap

Re: freeradius + ldap

2006-05-02 Thread Alan DeKok
ludovic cailleau <[EMAIL PROTECTED]> wrote: > I have made a configuration but it does not run. Read the FAQ for comments like "it doesn't work". Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius + ldap

2006-05-03 Thread Alan DeKok
ludovic cailleau <[EMAIL PROTECTED]> wrote: > Yes I have read the FAQ. But I haven't find my error. > > When I make "radiusd -X" I have this log (log.radiusd) Which contains the problem: > rlm_eap: processing type mschapv2 > Processing the authenticate section of radiusd.conf > modcall: e

Re: freeradius + ldap

2006-05-04 Thread ludovic cailleau
Sorry, but I don't understand. Can you explain me.   ThanksAlan DeKok <[EMAIL PROTECTED]> a écrit : ludovic cailleau <[EMAIL PROTECTED]>wrote:> Yes I have read the FAQ. But I haven't find my error.> > When I make "radiusd -X" I have this log (log.radiusd)Which contains the problem:> rlm_eap: pro

Re: freeradius + ldap

2006-05-04 Thread Alan DeKok
ludovic cailleau <[EMAIL PROTECTED]> wrote: > I send radius.conf, if it can help you to answer me. What part of my message was unclear? You edited radiusd.conf without understanding what the side effects were. As a result, the server no longer works. The solution is for you to NOT edit radi

Re: freeradius + ldap

2006-05-04 Thread ludovic cailleau
I understand the side effects when I edit radius.conf, because I have already make a 802.11x authentifacation for wireless.  But with users files. And this configuration works perfectly.  But now I would like use Ldap for authentification. But it don't works.   Ludovic cailleau Alan DeKok <[EM

Re: freeradius + ldap

2006-05-04 Thread Alan DeKok
ludovic cailleau <[EMAIL PROTECTED]> wrote: > I understand the side effects when I edit radius.conf, because I > have already make a 802.11x authentifacation for wireless. But with > users files. And this configuration works perfectly. The error message you saw happens ONLY if you edit the conf

Re: freeradius + ldap

2006-05-05 Thread ludovic cailleau
Ok, I mixed myself between the module ‘authenticate’ and ‘authorize.’ Now it is clearer!   I make the default config and change little part and now it works perfectly.   Thank you very much Alan Dekok   Ludovic Cailleau Faites de Yahoo! votre page d'accueil sur le web pour retrouver di

NoCat + FreeRadius + LDAP

2005-02-02 Thread Chan Min Wai
Greeting, I'm trying to setup a computer with the above configuration. Anyone know about how to pass the NoCat Attribute of (Member) back to the NoCat Gateway? I've got this in the radtest Vendor-32767-Attr-1 = 0x4d656d626572 Idle-Timeout = 300 Anyone know if I'm on the right tr

Re: freeradius + LDAP

2005-02-23 Thread Anderson Alves de Albuquerque
Look this: http://www.lh.freeradius.org/radiusd/doc/ldap_howto.txt On Wed, 23 Feb 2005, anderson souza wrote: > Good morning to all!! > > > > He/she would like to know some of the friends > > he/she knows some referring documentation > > the poptop implementa

Re: freeradius + LDAP

2005-02-23 Thread Lou Moore
files: acctusersfile = "/opt/freeradius-1.0.1/etc/raddb/acct_users" files: preproxy_usersfile = "/opt/freeradius-1.0.1/etc/raddb/preproxy_users" files: compat = "no" Module: Instantiated files (files) Segmentation Fault (core dumped) --- Anderson Alves de Albuquerque <

Re: Freeradius Ldap

2005-09-23 Thread Linus van Geuns
Cris Boisvert wrote: > I'm setting up freeradius to talk to a Ipswitch Imail server for > authetication. > > Just needs to do the basic User Pass... Ok. > > [..] > A snippet of the config. > --- > ldap { > server = "192.168.77.6" >

freeradius/ldap documentation

2004-01-02 Thread Dustin Doris
Would like to let everyone know that I have some documentation up about using freeradius w/ ldap auth and autz. The URL is http://doris.cc/radius. Hope that may help anyone that is looking to use freeradius w/ ldap. -Dusty Doris - List info/subscribe/unsubscribe? See http://www.freeradius.org

Re: freeradius + ldap

2004-01-14 Thread Alan DeKok
Joe Hetrick <[EMAIL PROTECTED]> wrote: > After some thought, I changed my crypt in the LDIF to something else, > first SSHA, and then MD5, and all of a sudden > auth worked (with both). Clearly I have a probem with CRYPT... I recall something a while ago about link ordering with crypt on *BSD.

freeradius ldap connector

2007-03-06 Thread [EMAIL PROTECTED]
Hello, I use freeradius 1.0.1 LDAP connector to request a LDAP directory. I notice that Freeradius tries 6 times to find a user in my LDAP directory when this user doesn't existe. Is there a mean to make freeradius tries only one time ? Thanks Thomas- List info/subscribe/unsubscribe? See http://w

Re: Freeradius + Ldap + attributes

2008-08-29 Thread Ivan Kalik
Yes. Add the reply attributes to ldap.attrmap. Ivan Kalik Kalik Informatika ISP Dana 28/8/2008, "Ivan ." <[EMAIL PROTECTED]> piše: >Hi > >I have Freeradius configured with a backend of OpenLdap for user management. > >I would like to be able to pass attributes for Nortel and Juniper >gear, whic

Re: Freeradius + Ldap + attributes

2008-08-31 Thread Ivan .
Hi any chance you can provide the actual syntax of whats required? replyItem Service-Type Administrative-User replyItem Juniper-Local-User-Name DEV Sorry, a bit of a novice freeraidus user thanks Ivan 2008/8/29 Ivan Kalik <[EMAIL PROTECTED]>: > Yes. Add

Re: Freeradius + Ldap + attributes

2008-09-01 Thread Ivan Kalik
>any chance you can provide the actual syntax of whats required? Syntax is the same as for other entries: replyItem radiusAttribute ldapAttribute so something like: replyItem Service-Type radiusServiceType replyItem Juniper-Local-User-Name juniperLocalName >replyItem

Re: Freeradius LDAP problem

2007-08-30 Thread Alan DeKok
George Beitis wrote: > I have a problem. I set up freeradius to use a local ldap server to > authenticate a user. When i say authenticate i mean check if the user > is there, check their password, and accept or reject them. When i do > such an authentication i get a message from freeradius sayin

Re: Freeradius LDAP problem

2007-08-30 Thread tnt
>users: Matched entry DEFAULT at line 153 .. > rad_check_password: Found Auth-Type System >auth: type "System" It's picking up Auth-Type System from users file. Comment out that entry. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/us

Re: Freeradius LDAP problem

2007-08-30 Thread Alan DeKok
George Beitis wrote: ... > rlm_ldap: looking for check items in directory... > rlm_ldap: looking for reply items in directory... The LDAP database doesn't contain the "known good" password for the user. > rlm_ldap: user gb85 authorized to use remote access > rlm_ldap: ldap_release_conn: Release

freeradius + ldap + cisco sslvpn

2008-01-21 Thread satish patel
Dear all I have requirement of sslvpn authentication with freeradius + ldap server is there anyone have worked on freeradius + ldap or authenticate with goruping and other features... $ cat ~/satish/url.txt http

Freeradius + Ldap + SSL/TLS

2011-06-28 Thread RATSIMIVEH Remi
Hi, I install freeradius on Debian machine. I have my user in ldap and I use that directory to authentication.But when I want to use SSL or TLS in connections between radius and ldap, I have that error in radius log. (Freeradius -X) - [ldap] ldap_get_conn: Checki

FreeRadius LDAP OID Numbering

2012-04-26 Thread Peter Lambrechtsen
A question for Alan, or others on the list. There is the FR LDAP Schema LDIF file to import FreeRadius related schema into your LDAP directory. Searching around it seems that OID 1.3.6.1.4.1.3317.4.3.1 up to 68 is allocated. http://permalink.gmane.org/gmane.comp.freeradius.devel/6134 Who "owns"

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Alan DeKok
Douglas Macedo wrote: > i'm trying configure a VPN Server with PPTP, using the 'radiusclient', > to connect on a FreeRadius, with auth in a LDAP Server. > > I "finished" the configure, but when a try connect with a client Windows > XP, don't work. > > The radiusd -X output: The client is doing

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Douglas Macedo
Alan, how I can fix that? Thanks in advanced, Douglas On Wed, Nov 26, 2008 at 4:54 PM, Alan DeKok <[EMAIL PROTECTED]>wrote: > Douglas Macedo wrote: > > i'm trying configure a VPN Server with PPTP, using the 'radiusclient', > > to connect on a FreeRadius, with auth in a LDAP Server. > > > > I "f

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Alan DeKok
Douglas Macedo wrote: > how I can fix that? Read the web page. It tells you. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Douglas Macedo
Sorry Alan, but the webpage tells that its don't work. Its impossible? Correct? So, how I can fix that the other way? My pptp-options: == epiderme:/etc/ppp# cat pptpd-options name pptpd refuse-pap ##refuse-chap require-chap ##refuse-mschap require-mschap require-mschap-v2 require-mppe-128 proxy

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Alexandre Chapellon
trying forcing windows pptp client to use mschapv2 Le 26.11.2008 09:15, Douglas Macedo a écrit : > Sorry Alan, > > but the webpage tells that its don't work. Its impossible? Correct? > > So, how I can fix that the other way? > > My pptp-options: > > == > epiderme:/etc/ppp# cat pptpd-options > name

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Alan DeKok
Douglas Macedo wrote: > but the webpage tells that its don't work. Its impossible? Correct? Since I wrote that web page... I won't disagee with it. > So, how I can fix that the other way? Do you have questions about the suggestions on the web page? > My pptp-options: > > == > epiderme:/etc

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Douglas Macedo
Alexandre, if I try mschapv2 in Windons client: -- rad_recv: Access-Request packet from host 150.162.67.254:32839, id=46, length=52 Service-Type = Framed-User Framed-Protocol = PPP User-Name = "nobody" NAS-IP-Address = 1.1.1.1 NAS-Port = 0 Processing the authorize section of

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Alexandre Chapellon
Le 26.11.2008 09:32, Douglas Macedo a écrit : > Alexandre, > > if I try mschapv2 in Windons client: > > -- > rad_recv: Access-Request packet from host 150.162.67.254:32839 > , id=46, length=52 > Service-Type = Framed-User > Framed-Protocol = PPP > User-Nam

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread Alan DeKok
Douglas Macedo wrote: > Any idea? Use a recent version of the server. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PPTP + FreeRadius + LDAP

2008-11-26 Thread tnt
>if I try mschapv2 in Windons client: > >-- >rad_recv: Access-Request packet from host 150.162.67.254:32839, id=46, >length=52 >Service-Type = Framed-User >Framed-Protocol = PPP >User-Name = "nobody" >NAS-IP-Address = 1.1.1.1 >NAS-Port = 0 This is not an mschap request. http:/

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread Douglas Macedo
Hey guys, i force in WIndows Client to use only mschap2, but the problem continue: - Module: Instantiated radutmp (radutmp) Listening on authentication *:1812 Listening on accounting *:1813 Ready to process requests. rad_recv: Access-Request packet from host 150.162.67.254:32858, id=109, length=5

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread tnt
>i force in WIndows Client to use only mschap2, but the problem continue: > >- >Module: Instantiated radutmp (radutmp) >Listening on authentication *:1812 >Listening on accounting *:1813 >Ready to process requests. >rad_recv: Access-Request packet from host 150.162.67.254:32858, id=109, >length=53

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread Douglas Macedo
Hey TNT, On Thu, Nov 27, 2008 at 2:54 PM, <[EMAIL PROTECTED]> wrote: > >i force in WIndows Client to use only mschap2, but the problem continue: > > > >- > >Module: Instantiated radutmp (radutmp) > >Listening on authentication *:1812 > >Listening on accounting *:1813 > >Ready to process requests.

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread Alexandre Chapellon
Le 27.11.2008 07:17, Douglas Macedo a écrit : > Hey TNT, > > On Thu, Nov 27, 2008 at 2:54 PM, <[EMAIL PROTECTED] > > wrote: > > >i force in WIndows Client to use only mschap2, but the problem > continue: > > > >- > >Module: Instantiated radutmp (radut

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread Douglas Macedo
Hey, i copy the dictionary to /etc/radiusclient. But now the connections don't target the Radius Server. -- epiderme:/etc/radiusclient# ls -l total 68 -rw-r--r-- 1 root root 6593 2008-11-27 15:02 dictionary -rw-r--r-- 1 root root 12388 2006-10-29 08:54 dictionary.ascend -rw-r--r-- 1 root root 1

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread Alexandre Chapellon
Le 27.11.2008 10:15, Douglas Macedo a écrit : > Hey, > > i copy the dictionary to /etc/radiusclient. But now the connections > don't target the Radius Server. > -- > epiderme:/etc/radiusclient# ls -l > total 68 > -rw-r--r-- 1 root root 6593 2008-11-27 15:02 dictionary > -rw-r--r-- 1 root root 12

Re: PPTP + FreeRadius + LDAP

2008-11-27 Thread Douglas Macedo
Alexandre, that's work. The problem is that the dictionaries of radiusclient, isn't correct. The default microsoft dictionary don't work perfectly. I use this page to modify my dictionary.microsoft: http://wiki.freeradius.org/PopTop#The_radiusclient_setup_part_.28on_the_Poptop_server.29 Now tha

Re: FreeRADIUS LDAP HOWTO

2009-02-14 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andrew Hall wrote: > I'd just like to make other subscribers / searchers / admins > pulling their hair out aware of the FreeRADIUS LDAP HOWTO available > here... > > http://freeradius.org/radiusd/doc/ldap_howto.txt > > For s

Re: FreeRADIUS LDAP HOWTO

2009-02-14 Thread Andrew Hall
Arran Cudbard-Bell wrote... > Maybe because it was written 6 years ago, and very few of the > freeRADIUS 1.* examples will still work with 2 I see your point but why deny users access to this information ? Surely all that's required is a note informing them of this. I administer a legacy 1.

Re: FreeRADIUS LDAP HOWTO

2009-02-14 Thread Alan DeKok
Andrew Hall wrote: > On a similar note does anyone know if O'Reilly plan to update their RADIUS > book? They don't. The book sold well initially (i.e. the first few months). After that, people realized it was less than helpful. I've been trying to write a book for a while. I've recently f

Re: FreeRADIUS LDAP HOWTO

2009-02-15 Thread Mihamina Rakotomandimby (R12y)
Arran Cudbard-Bell wrote: http://freeradius.org/radiusd/doc/ldap_howto.txt For some reason it doesn't seem to be linked to on any main website or wiki page - bizarrely including the HOWTO page... Maybe because it was written 6 years ago, Is someone aare of any up to date one? -- Chef de proje

Re: FreeRADIUS LDAP HOWTO

2009-02-15 Thread Alan DeKok
Mihamina Rakotomandimby (R12y) wrote: > Arran Cudbard-Bell wrote: >>> http://freeradius.org/radiusd/doc/ldap_howto.txt >>> For some reason it doesn't seem to be linked to on any main website >>> or wiki page - bizarrely including the HOWTO page... >> Maybe because it was written 6 years ago, > >

Re: FreeRADIUS LDAP HOWTO

2009-02-15 Thread Michael Schwartzkopff
Am Montag, 16. Februar 2009 07:37:10 schrieb Alan DeKok: > Mihamina Rakotomandimby (R12y) wrote: > > Arran Cudbard-Bell wrote: > >>> http://freeradius.org/radiusd/doc/ldap_howto.txt > >>> For some reason it doesn't seem to be linked to on any main website > >>> or wiki page - bizarrely including th

Re: FreeRADIUS LDAP HOWTO

2009-02-15 Thread Mihamina Rakotomandimby (R12y)
Michael Schwartzkopff wrote: http://freeradius.org/radiusd/doc/ldap_howto.txt For some reason it doesn't seem to be linked to on any main website or wiki page - bizarrely including the HOWTO page... Maybe because it was written 6 years ago, Is someone aare of any up to date one? Feel free to

Re: FreeRADIUS LDAP HOWTO

2009-02-15 Thread Michael Schwartzkopff
Am Montag, 16. Februar 2009 08:46:17 schrieb Mihamina Rakotomandimby (R12y): > Michael Schwartzkopff wrote: > > http://freeradius.org/radiusd/doc/ldap_howto.txt > > For some reason it doesn't seem to be linked to on any main website > > or wiki page - bizarrely including the HOWTO page.

Re: Secure FreeRADIUS & LDAP

2009-02-20 Thread tnt
># Can freeradius talk to the ldap box using TLS/SSL (ldaps) Yes. See tls section in ldap module. ># Can freeradius read hashed credentials from the LDAP store and then >actually use them??? Yes. You will have to enable auto-headers in pap module if you are storing them with headers in userPassw

Re: Secure FreeRADIUS & LDAP

2009-02-20 Thread Dan Hawker
Cool, thanks for the info Ivan. Will give it a go and report back Thanks again Dan 2009/2/20 : >># Can freeradius talk to the ldap box using TLS/SSL (ldaps) > > Yes. See tls section in ldap module. > >># Can freeradius read hashed credentials from the LDAP store and then >>actually use them???

  1   2   3   4   5   >