Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-30 Thread Jean-Yves Avenard
Hi On 31 August 2010 13:58, Fajar A. Nugraha wrote: > On Tue, Aug 31, 2010 at 10:41 AM, Jean-Yves Avenard > wrote: >> Looking at the log, I don't think that when win7 sent the computer >> name as the login, the user's name is sent anywhere, so configuration >> change can only be done on the win

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-30 Thread Fajar A. Nugraha
On Tue, Aug 31, 2010 at 10:41 AM, Jean-Yves Avenard wrote: > Looking at the log, I don't think that when win7 sent the computer > name as the login, the user's name is sent anywhere, so configuration > change can only be done on the win7 client So did you finaly manage to get it working by changi

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-30 Thread Jean-Yves Avenard
Hi On Tuesday, August 31, 2010, Alan DeKok wrote: >  The first debug log shows the user being found by the "unix" module. > i.e. the User-Name has an entry in /etc/passwd, or the Apple equivalent. > >  The second debug log shows that the user is *not* found by the "unix" > module. > Yes, becau

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-30 Thread Alan DeKok
Jean-Yves Avenard wrote: > As requested. > Here is the log from the Win 7 client, when it is configured in > Advanced Settings -> 802.11X Settings -> Specify authentication mode: > user authentication The first debug log shows the user being found by the "unix" module. i.e. the User-Name has an

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-30 Thread Jean-Yves Avenard
Hi On 31 August 2010 02:04, Fajar A. Nugraha wrote: > I think what Alan is saying is look at what User-Name being sent by > the CLIENT. Your Win7 client log says the client is sending "User-Name > = "host/ramon"". If you want it to be something like, change the > client configuration. At this poi

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-30 Thread Fajar A. Nugraha
On Mon, Aug 30, 2010 at 9:25 PM, Jean-Yves Avenard wrote: > This is from a Win 7 client, using default configuration settings that > is just username / password and that Authentication is PEAP:MSCHAPv2 > >> rad_recv: Access-Request packet from host 192.168.0.20 port 65513, id=112, >> length=163 >

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-30 Thread Jean-Yves Avenard
Hi On 27 August 2010 23:06, Alan DeKok wrote: > Jean-Yves Avenard wrote: >> You seem to miss the point that the issue occurs *only* with Win 7 >> clients. All other clients are fine. > >  I don't really care which client it is.  All that matters is: > > a) what data is in the packet > > b) what y

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-27 Thread Alan DeKok
Jean-Yves Avenard wrote: > You seem to miss the point that the issue occurs *only* with Win 7 > clients. All other clients are fine. I don't really care which client it is. All that matters is: a) what data is in the packet b) what you configure the server to do with that data You have po

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-27 Thread Phil Mayers
On 27/08/10 13:38, Jean-Yves Avenard wrote: You seem to miss the point that the issue occurs *only* with Win 7 clients. All other clients are fine. Please post the debug output of freeradius, obtained by running: radiusd -X ...for a working and failing case. - List info/subscribe/unsubscrib

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-27 Thread Jean-Yves Avenard
Hi On 27 August 2010 20:46, Alan DeKok wrote: > Jean-Yves Avenard wrote: >> Here are some logs... > ... >> rlm_opendirectory: The host 192.168.0.20 does not have an access group. > >  And... what does this message mean?  It's an OpenDirectory error > message, so find out what it means, and how to

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-27 Thread Alan DeKok
Jean-Yves Avenard wrote: > Here are some logs... ... > rlm_opendirectory: The host 192.168.0.20 does not have an access group. And... what does this message mean? It's an OpenDirectory error message, so find out what it means, and how to fix it. > rlm_opendirectory: Could not get the user's uu

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-27 Thread Jean-Yves Avenard
Hi On 26 August 2010 23:35, Alan DeKok wrote: > Jean-Yves Avenard wrote: >> I am running freeradius that comes installed and configured with MacOS >> 10.6 server. >> >> A Windows XP can connect just fine using Microsoft Protected EAP. >> iPhone, mac os client connect just fine using EAP-TTLS >> >

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-26 Thread Jean-Yves Avenard
On 27 August 2010 05:19, Nolan King wrote: > check the capitalization of username. I have seen instances where xp clients > sends all lower, and win7 capitalised the first two characters. > What do you do in this case then? Have a script run by freeradius putting all characters as lower case? -

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-26 Thread Nolan King
check the capitalization of username. I have seen instances where xp clients sends all lower, and win7 capitalised the first two characters. nolan -- Nolan King Moulton Niguel Water District 27500 La Paz Rd. Laguna Niguel, CA 92677 (949) 425-3542 24hr: (949) 831-2500 >>> On 8/26/2010 at 11:44

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-26 Thread Jean-Yves Avenard
Hi On Thursday, August 26, 2010, Alan DeKok wrote: > Jean-Yves Avenard wrote: >> I am running freeradius that comes installed and configured with MacOS >> 10.6 server. >> >> A Windows XP can connect just fine using Microsoft Protected EAP. >> iPhone, mac os client connect just fine using EAP-TTLS

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-08-26 Thread Alan DeKok
Jean-Yves Avenard wrote: > I am running freeradius that comes installed and configured with MacOS > 10.6 server. > > A Windows XP can connect just fine using Microsoft Protected EAP. > iPhone, mac os client connect just fine using EAP-TTLS > > Windows 7 will connect fine using Securew2 EAP-TTLS s

Re: Freeradius problem, EAP-TTLS works fine, EAP-PEAP does not

2010-06-05 Thread Josip Rodin
On Sat, Jun 05, 2010 at 12:50:59AM +0200, David wrote: > connecting with Window 7 the following gets written to radius.log: > > Sat Jun 5 00:00:59 2010 : Info: rlm_eap_md5: Issuing Challenge > Sat Jun 5 00:00:59 2010 : Info: rlm_eap_mschapv2: Issuing Challenge > > As opposed to EAP-TTLS, then t