Re: Sending Reply-Message in Access-Reject (PEAP/MSCHAPv2)

2011-05-24 Thread Phil Mayers
On 05/24/2011 05:03 PM, Alan Buxey wrote: so, in inner-tunnel post-auth, set "outer.reply" to be whatever you want.. you can then, in the outer layer, query/check or use that reply. Unfortunately, outer.reply is an Access-Challenge. - List info/subscribe/unsubscribe? See http://www.freeradius

RE: Sending Reply-Message in Access-Reject (PEAP/MSCHAPv2)

2011-05-24 Thread Garber, Neal
> so, in inner-tunnel post-auth, set "outer.reply" > to be whatever you want.. you can then, in the > outer layer, query/check or use that reply. There's an additional round trip after the failure which is why Phil said it needs to be saved. I had a patch to save/restore it; but, it needs rew

Re: Sending Reply-Message in Access-Reject (PEAP/MSCHAPv2)

2011-05-24 Thread Alan Buxey
Hi, > On 24/05/11 15:23, Martin Goldstone wrote: > > > Yes, I have this in both the peap stanza and the ttls stanza. This > > seems to be fine when access is accepted, for example if I set a > > Reply-Message saying "Welcome" in the post-auth section of the > > inner-tunnel config, I see this in

Re: Sending Reply-Message in Access-Reject (PEAP/MSCHAPv2)

2011-05-24 Thread Phil Mayers
On 24/05/11 15:23, Martin Goldstone wrote: Yes, I have this in both the peap stanza and the ttls stanza. This seems to be fine when access is accepted, for example if I set a Reply-Message saying "Welcome" in the post-auth section of the inner-tunnel config, I see this in the final access-accep

Re: Sending Reply-Message in Access-Reject (PEAP/MSCHAPv2)

2011-05-24 Thread Martin Goldstone
On 24/05/11 12:46, Phil Mayers wrote: > On 24/05/11 12:16, Martin Goldstone wrote: >> Hello, >> >> Just looking for a bit of advice here. I've been setting up freeradius >> here recently, and whilst I'm mostly finished, there are a few points >> that still need to be addressed. The main one is se

Re: Sending Reply-Message in Access-Reject (PEAP/MSCHAPv2)

2011-05-24 Thread Phil Mayers
On 24/05/11 12:16, Martin Goldstone wrote: Hello, Just looking for a bit of advice here. I've been setting up freeradius here recently, and whilst I'm mostly finished, there are a few points that still need to be addressed. The main one is sending a (semi) meaningful reply message when a user

Sending Reply-Message in Access-Reject (PEAP/MSCHAPv2)

2011-05-24 Thread Martin Goldstone
Hello, Just looking for a bit of advice here. I've been setting up freeradius here recently, and whilst I'm mostly finished, there are a few points that still need to be addressed. The main one is sending a (semi) meaningful reply message when a user is rejected. Unfortunately, I'm having troub