Re: [PacketFence-users] Intermittent Winbind Issues

2023-08-25 Thread Steven Spangle via PacketFence-users
I guess we can see just how intermittent this issue is, as it just happened again this weekend. I’ve provided the output of the commands you suggested in the previous email, however, it looks like ntlm_auth is successful while this issue is occurring. When I got on the Packetfence GUI, under

[PacketFence-users] dynamic vlan assignment for computers based on group

2023-08-25 Thread UMS ums via PacketFence-users
Hello I have setup dynamic VLAN assignment with 802.1x in packetfence. Users are put in the correct VLAN but computers are not assigned a correct role. I first tried to use the memberOf condition which works fine for users but i didn't work out for computers. I then tried computername starts

[PacketFence-users] Captive Portal is only accessible when iptables is disabled

2023-08-25 Thread Eric Rolleman via PacketFence-users
I recently upgraded my PacketFence install to 13.0.0 from 11.3.0 (in case this is related). I now have this issue where the captive portal is only available to those on the Registration Vlan if the iptables service is turned off. I have an interface assigned to Management, Registration and

[PacketFence-users] Firewall SSO broken after upgrade to 13.0 from 12.2

2023-08-25 Thread Arun Kangle via PacketFence-users
Hi, After upgrading to 13.0 from 12.2, the firewall SSO is broken. Though packetfence logs show SSO sent out, I don't see any accounting packets received on FW so I did tcpdump on packetfence and that as well shows no packet was sent out from the packetfence. Your expedited help is requested.

[PacketFence-users] EAP-TLS Azure AD Device Groups

2023-08-25 Thread Michael Brown via PacketFence-users
Hi Everyone, Using EAP-TLS/certs, is it possible to authenticate a device based on what Azure AD group they are in? I am successfully authenticating users based on Azure AD group memberships with user certificates but cannot seem to get this to work using a device certificate.  The device

Re: [PacketFence-users] OSCP not functioning to MS PKI

2023-08-25 Thread Mustafa Farhat via PacketFence-users
Hello Simon! Have you found a solution to the problem? I'm facing the same error message '' eap_tls: ocsp: Couldn't verify OCSP basic response'' and haven't been able to fix it for three days. Thank you. Mustafa ___

[PacketFence-users] Firewall SSO broken after upgrade to 13.0 from 12.2

2023-08-25 Thread Arun Kangle via PacketFence-users
Resending... Hi, After upgrading to 13.0 from 12.2, the firewall SSO is broken. Though packetfence logs show SSO sent out, I don't see any accounting packets received on FW so I did tcpdump on packetfence and that as well shows no packet was sent out from the packetfence. Your expedited help is