Re: PEAP problem when using domain suffix

2008-06-08 Thread A . L . M . Buxey
Hi, >> I've written a small patch for 2.0.4 which fixes this: >> >> http://bugs.freeradius.org/show_bug.cgi?id=562 >> - >> List info/subscribe/unsubscribe? See >> http://www.freeradius.org/list/users.html > > That's amazing; thanks for the quick update; would you be so kind as to > provide a ver

Re: PEAP problem when using domain suffix

2008-06-08 Thread Graham Marsh
- Original Message - From: "Phil Mayers" <[EMAIL PROTECTED]> To: "FreeRadius users mailing list" Sent: Friday, June 06, 2008 8:17 PM Subject: Re: PEAP problem when using domain suffix Phil Mayers wrote: [EMAIL PROTECTED] wrote: hi, you need to remove

Re: PEAP problem when using domain suffix

2008-06-06 Thread Phil Mayers
Phil Mayers wrote: [EMAIL PROTECTED] wrote: hi, you need to remove the domain suffix but you cannot play with the User-Name attribute or the response will be wrong - use the 'stripped-user-name' attribute for the authenticate step - and ensure that if you are querying an LDAP or AD et cin that

Re: PEAP problem when using domain suffix

2008-06-06 Thread Alan DeKok
Graham Marsh wrote: > The results I posted in the original message were generated using the > Odyssey Access Client, I apologise for not mentioning that first. So > with OAC, the username without suffix works, with suffix fails. ... > Anyway, the interesting thing is that when the native client in

Re: PEAP problem when using domain suffix

2008-06-06 Thread Graham Marsh
> You will need to strip it; what "other" problem did it cause? The "other" problem it caused was as follows and as another respondent wrote, you can't mess with the User-Name attribute, so that's the wrong path to take it seems. Anyway I found some additional info in the main branch of the thread

Re: PEAP problem when using domain suffix

2008-06-06 Thread Graham Marsh
On 6/6/08, Phil Mayers <[EMAIL PROTECTED]> wrote: > [EMAIL PROTECTED] wrote: > > hi, > > > > you need to remove the domain suffix but you cannot > > play with the User-Name attribute or the response will > > be wrong - use the 'stripped-user-name' attribute > > for the authenticate step - and ensur

Re: PEAP problem when using domain suffix

2008-06-06 Thread Phil Mayers
[EMAIL PROTECTED] wrote: hi, you need to remove the domain suffix but you cannot play with the User-Name attribute or the response will be wrong - use the 'stripped-user-name' attribute for the authenticate step - and ensure that if you are querying an LDAP or AD et cin that stage that DOMAIN be

Re: PEAP problem when using domain suffix

2008-06-06 Thread A . L . M . Buxey
hi, you need to remove the domain suffix but you cannot play with the User-Name attribute or the response will be wrong - use the 'stripped-user-name' attribute for the authenticate step - and ensure that if you are querying an LDAP or AD et cin that stage that DOMAIN being used is the correct dom

Re: PEAP problem when using domain suffix

2008-06-06 Thread Phil Mayers
Graham Marsh wrote: Hi Have set up freeradius on a SLES10SP1 box in order to do 802.1X authentication. All is fine if the client submits a request using just the user name e.g. test05 in the case below: Processing the authenticate section of radiusd.conf modcall: entering group authenticate f

PEAP problem when using domain suffix

2008-06-05 Thread Graham Marsh
Hi Have set up freeradius on a SLES10SP1 box in order to do 802.1X authentication. All is fine if the client submits a request using just the user name e.g. test05 in the case below: Processing the authenticate section of radiusd.conf modcall: entering group authenticate for request 6 rlm_eap