RE: AP> FR> LDAP authentication reject

2012-12-28 Thread Phil Mayers
Sigh. No. There are no packets in that debug. How do you expect people to read a debug unless it contains an authentication attempt? > ... adding new socket proxy address * port 51195 >Listening on authentication address * port 1812 >Listening on accounting address * port 1813 >Listening on comma

RE: AP> FR> LDAP authentication reject

2012-12-28 Thread Thanakorn Rattanatikul
> Date: Fri, 28 Dec 2012 10:46:45 +0100 > From: oliv...@heliosnet.org > To: freeradius-users@lists.freeradius.org > Subject: Re: AP> FR> LDAP authentication reject > > On 28.12.2012 09:38, Thanakorn Rattanatikul wrote: > > Still unable to connect. > > Do

Re: AP> FR> LDAP authentication reject

2012-12-28 Thread Alan DeKok
Thanakorn Rattanatikul wrote: > In LDAP server , for user "sun" , store password in clear-text in this test. No, it doesn't. Or, it's not available. Or the user isn't found. Read the debug log. Look for anything related to LDAP. It isn't hard: [ldap] performing search in ou=guest,d

Re: AP> FR> LDAP authentication reject

2012-12-28 Thread Olivier Beytrison
On 28.12.2012 09:38, Thanakorn Rattanatikul wrote: > Still unable to connect. > Do you have any configuration files for connecting with LDAP form AP> > FR> LDAP ? I tried every way but nothing works. Send a full output of freeradius -X -- Olivier Beytrison Network & Security Engineer, HES-

RE: AP> FR> LDAP authentication reject

2012-12-28 Thread Thanakorn Rattanatikul
Still unable to connect. Do you have any configuration files for connecting with LDAP form AP> FR> LDAP ? I tried every way but nothing works. Thank you very much for your time and help. thanakorn - List info/subscribe/unsubscribe? See http://www.f

Re: AP> FR> LDAP authentication reject

2012-12-27 Thread Olivier Beytrison
On 28.12.2012 08:39, Thanakorn Rattanatikul wrote: > In LDAP server , for user "sun" , store password in clear-text in this test So if you have a clear-text password in the ldap, use the ldap attribute-map to add it in the control list. Looking at the logs I guess you are running version 2.x, then

RE: AP> FR> LDAP authentication reject

2012-12-27 Thread Thanakorn Rattanatikul
In LDAP server , for user "sun" , store password in clear-text in this test. Thank you very much for your time and help. thanakorn - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: AP> FR> LDAP authentication reject

2012-12-27 Thread Olivier Beytrison
On 28.12.2012 06:17, Thanakorn Rattanatikul wrote: > I'm trying to setup the server to authenticate using LDAP. I'm having > some problem and hope to get some help from the list. > > I'm trying to setup AP->FR->LDAP. FreeRadius is new installation on > CentOS. LDAP is Sun Java System Directory Ser

RE: AP->FR->LDAP authentication

2012-03-19 Thread Julie
huh? OSX lion can do whatever you have told it to do using the mobileconfig tool (iPhone configuraton utility can generate such). now, far be it from me to shout from the rooftopsbut i wouldnt rely on some unsubstantiated result found by google. if you do the legwork you'll find it CAN do w

RE: AP->FR->LDAP authentication

2012-03-19 Thread Julie
> if your clients are doing EAP-TTLS/PAP then this will work - the PAP > module can deal the requirements. I'm trying to setup the EAP-TTLS/PAP. I'm testing with Mac Lion. Just saw someone posted online saying Lion support only MSChapV2 in the inner-tunnel part. Trying to figure out how to chan

Re: AP->FR->LDAP authentication

2012-03-17 Thread Alan Buxey
Hi, > I'm new to FreeRadius and trying to setup the server to authenticate using > LDAP. I'm having some problem and hope to get some help from the list. if your clients are doing EAP-TTLS/PAP then this will work - the PAP module can deal the requirements. if, as i suspect, you are using PEAP (

Re: AP->FR->LDAP authentication

2012-03-17 Thread Alan DeKok
Julie Chen wrote: > Yes, I understand that. Apparently you don't. > But I'm having little problem figure out right configuration. What part of "impossible" is unclear? > Would someone please advice on the configuration file? There is no configuration to change. You need to store the

Re: AP->FR->LDAP authentication

2012-03-17 Thread Alan DeKok
Fajar A. Nugraha wrote: > I'd start with reading this: > http://wiki.freeradius.org/Protocol%20Compatibility > (or the original page in deplyingradius.com). Please don't copy my content into the Wiki. The deployingradius.com link has been around for years. It's the authoritative source. Copy

Re: AP->FR->LDAP authentication

2012-03-17 Thread Fajar A. Nugraha
On Sat, Mar 17, 2012 at 11:54 AM, Julie Chen wrote: > > Yes, I understand that. But I'm having little problem figure out right > configuration.  Would someone please advice on the configuration file? I'd start with reading this: http://wiki.freeradius.org/Protocol%20Compatibility (or the original

RE: AP->FR->LDAP authentication

2012-03-16 Thread Julie Chen
f of Alan DeKok [al...@deployingradius.com] Sent: Friday, March 16, 2012 8:02 PM To: FreeRadius users mailing list Subject: Re: AP->FR->LDAP authentication Julie wrote: > The problem is when I try to authenticate through AP. The debug log shows > Failed to authenticate the user

Re: AP->FR->LDAP authentication

2012-03-16 Thread Alan DeKok
Julie wrote: > The problem is when I try to authenticate through AP. The debug log shows > Failed to authenticate the user. here is the log file. ... > [mschap] Found MS-CHAP attributes. Setting 'Auth-Type = mschap' ... > [ldap] userPassword -> Password-With-Header == > "{crypt}$1$svVH/H.V$S02t