Re: last hurdle...windows clients

2008-11-25 Thread Alan DeKok
Craig White wrote: I realize that freeradius has little control over the supplicant but I'm wondering if it's something in my setup of tls that the authentication should/shouldn't be part of the tunnel because it just assumes a login of anonymous instead of the Windows User/Password or never

Re: last hurdle...windows clients

2008-11-25 Thread Craig White
On Tue, 2008-11-25 at 10:06 +0100, Alan DeKok wrote: Craig White wrote: I realize that freeradius has little control over the supplicant but I'm wondering if it's something in my setup of tls that the authentication should/shouldn't be part of the tunnel because it just assumes a login of

Re: last hurdle...windows clients

2008-11-25 Thread tnt
Am I in the right place? No. You are looking at the radius server for something configured on the suppicant. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: last hurdle...windows clients

2008-11-24 Thread Craig White
On Sun, 2008-11-23 at 02:59 -0600, Alan DeKok wrote: Craig White wrote: OK - that quiets the notification but I still can't figure out the issue where I can authenticate RRAS, Macintosh and iPod clients against radius via LDAP using mschapv2 but even with the certificates on Windows XP

Re: last hurdle...windows clients

2008-11-23 Thread Alan DeKok
Craig White wrote: OK - that quiets the notification but I still can't figure out the issue where I can authenticate RRAS, Macintosh and iPod clients against radius via LDAP using mschapv2 but even with the certificates on Windows XP clients, with the 'xpextensions' they always try to

Re: last hurdle...windows clients

2008-11-23 Thread tnt
OK - that quiets the notification but I still can't figure out the issue where I can authenticate RRAS, Macintosh and iPod clients against radius via LDAP using mschapv2 but even with the certificates on Windows XP clients, with the 'xpextensions' they always try to authenticate as 'uid=anonymous'

Re: last hurdle...windows clients

2008-11-22 Thread tnt
I don't understand the message about unknown_ca in the log below either because I am acting as my own CA and this same cacert.pem seems to be happy on the Windows system I imported it on and I've been using it for a bunch of other daemons. It probably wants cacert.der. Ivan Kalik Kalik

Re: last hurdle...windows clients

2008-11-22 Thread Craig White
On Sun, 2008-11-23 at 00:24 +0100, [EMAIL PROTECTED] wrote: I don't understand the message about unknown_ca in the log below either because I am acting as my own CA and this same cacert.pem seems to be happy on the Windows system I imported it on and I've been using it for a bunch of other

last hurdle...windows clients

2008-11-21 Thread Craig White
freeradius-1.1.3-1.2.el5 I am authenticating Windows RRAS connections, Macintosh wifi, iPhone wifi all with LDAP and mschapv2 (using sambaNTPassword hashes in OpenLDAP) My users basically consists of... DEFAULT Auth-Type = LDAP eap.conf default_eap_type = mschapv2 and of course my