Re: How to add attributes to Access-Accept replies

2007-12-11 Thread Lucien RENAULT
Ok, thanks for your help, I found the problem in radiusd.conf : In the authorize section, the "files" line was commented because it created errors when authorizing with ldap so I uncommented and placed this line *after* the ldap line, which allowed to authorize using LDAP and parse the users fi

Re: How to add attributes to Access-Accept replies

2007-12-11 Thread Alan DeKok
Lucien RENAULT wrote: > Yes I actually read the radius -X by myself, as well as doc about users > and man 5 users, so I don't really understand why the following lines > don't add attributes to the reply : The output of "radiusd -X" shows which lines in the "users" file are matched. In your c

Re: How to add attributes to Access-Accept replies

2007-12-11 Thread Lucien RENAULT
Yes I actually read the radius -X by myself, as well as doc about users and man 5 users, so I don't really understand why the following lines don't add attributes to the reply : DEFAULT Framed-Protocol == PPP Service-Type = Framed-User, Framed-Protocol = PPP, Fall-Through = Yes Alan

Re: How to add attributes to Access-Accept replies

2007-12-11 Thread Alan DeKok
Lucien RENAULT wrote: > Yes, I checked the Access-Accept packet with tcpdump/Wireshark and they > weren't any attributes. > Here are the radiusd -X lines ( password & shared keys are for testing > purpose only...) : The reason to use "radiusd -X" is to *read* it. In this case, it's telling yo

Re: How to add attributes to Access-Accept replies

2007-12-11 Thread Lucien RENAULT
Yes, I checked the Access-Accept packet with tcpdump/Wireshark and they weren't any attributes. Here are the radiusd -X lines ( password & shared keys are for testing purpose only...) : Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /us

Re: How to add attributes to Access-Accept replies

2007-12-10 Thread tnt
>Yes indeed, I changed the default entries of the users.conf because >freeradius wasn't replying with the attributes Why? Are you sure that server didn't respont the way it was supposed to? Send the output from radiusd -X from the request. Ivan Kalik Kalik Informatika ISP - List info/subscribe

Re: How to add attributes to Access-Accept replies

2007-12-10 Thread Lucien RENAULT
Yes indeed, I changed the default entries of the users.conf because freeradius wasn't replying with the attributes so I tried many tricks in order to improve this but I never managed to get those attributes in Access-Accept packets... I also modified the ldap section of radiusd.conf but this one

Re: How to add attributes to Access-Accept replies

2007-12-10 Thread tnt
Default users file has DEFAULT entries for that Service-Type and protocol. Default radiusd.conf uses files. You have changed the defaults and it's not working anymore. In default configuration make changes only to the ldap section and leave the rest as it was. Ivan Kalik Kalik Informatika ISP Da

How to add attributes to Access-Accept replies

2007-12-10 Thread Lucien RENAULT
Hi, I'm running a configuration where a Cisco 1600 router is running a PPPoE server and check user passwords against a freeRadius server running under FreeBSD. This Radius server checks passwords against a LDAP database running on another BSD server. The authentication is working great, the Rad