Re: [RADIATOR] TTLS with inner MSCHAPv2 vs. inner EAP-MSCHAPv2

2015-06-09 Thread Heikki Vatiainen
, the response Radiator calculates is incorrect. If you switch to EAP-TTLS/PAP for testing, it should work similarly with one request and immediate accept/reject from Radiator. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS

Re: [RADIATOR] Farmsize and ServerTACACSPLUS

2015-05-28 Thread Heikki Vatiainen
requests even if it has not received requests for the user yet. The option defaults to disable and it's intended for FarmSize or configurations where, for example, authentication is not done with TACACS+ Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible

Re: [RADIATOR] debug log for specific username

2015-04-17 Thread Heikki Vatiainen
not get it to break when I tried with eapol_test running full speed at the same time. You may also want to check the Monitor.pm file in the message is the current one that comes with Radiator. See the $Id: ...$ line at the top of the file for version information. Thanks, Heikki -- Heikki Vatiainen h

Re: [RADIATOR] TLS_CertificateChainFile within ServerRADSEC not working?

2015-04-16 Thread Heikki Vatiainen
: - server's own certificate - the first certificate in the file - CA certificates - the order did not matter. I'd guess it would be the same for RadSec TLS_CertificateChainFile too. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS

Re: [RADIATOR] debug log for specific username

2015-04-16 Thread Heikki Vatiainen
+ mschapv2, authdbfile. Am I doing something wrong or trace_username is not supported for peap? It is supported for PEAP. Maybe you can reply with the commands you used if the above example from what I did does not work. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most

Re: [RADIATOR] sub-second precision logging

2015-04-08 Thread Heikki Vatiainen
similar hooks in the goodies yet. The microsecond part can go there as a part of the example and the reference manual can have a pointer to the example file. Thanks for the suggestion, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS

Re: [RADIATOR] [Radiator] Error connecting to readonly RADMIN Mysql DB

2015-04-03 Thread Heikki Vatiainen
On 03/19/2015 02:49 PM, Heikki Vatiainen wrote: On 03/19/2015 12:18 PM, Laurent Duru wrote: Thu Mar 19 11:11:11 2015: ERR: Execute failed for 'select PASS_WORD, STATICADDRESS, TIMELEFT, MAXLOGINS, SERVICENAME, BADLOGINS, VALIDFROM, VALIDTO from RADUSERS where USERNAME=‘X'': Can't call

Re: [RADIATOR] sub-second precision logging

2015-04-03 Thread Heikki Vatiainen
to Util::format_special(), you should get back the microsecond part. Is this what you were looking for? Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald

Re: [RADIATOR] Processing delay in Diameter

2015-03-30 Thread Heikki Vatiainen
-- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA, Vasco, Yubikey, MOTP

Re: [RADIATOR] [Radiator] Error connecting to readonly RADMIN Mysql DB

2015-03-19 Thread Heikki Vatiainen
, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA, Vasco, Yubikey

Re: [RADIATOR] eduroam request with EAP Nak desires type 26

2015-03-16 Thread Heikki Vatiainen
-Name in the request object generated for the tunnelled PEAP message. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM

Re: [RADIATOR] Changing TACACS AuthorizeGroup on the fly

2015-03-05 Thread Heikki Vatiainen
-Authorize-Group2 etc.? You need to reuse the attribute. They are processed in the order they appear in the Access-Accept. In other words, the attribute can be present multiple times in the Access-Accept. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable

Re: [RADIATOR] Changing TACACS AuthorizeGroup on the fly

2015-03-04 Thread Heikki Vatiainen
group1 deny .* In other words, the OSC-Authorize-Group attributes, there can be more than one, returned during the authentication are evaluated before the static configuration. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS

Re: [RADIATOR] ClientListSQL RefreshPeriod parameter problem

2015-03-04 Thread Heikki Vatiainen
, but at the moment it does not. There are a couple of alternatives that are available now: You can get the parameter setting from a file or SQL. See section 5.1 in the reference manual for details. In short: RefreshPeriod file:refresh.inc RefreshPeriod sql:identifier:query Thanks, Heikki -- Heikki

Re: [RADIATOR] rcrypt implemantation in java ?

2015-03-04 Thread Heikki Vatiainen
about a java version. I guess it's time to dive :) Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory

Re: [RADIATOR] tagged-string and tag0

2015-03-02 Thread Heikki Vatiainen
with some. About the second issue, we'll take a look at this too. Decimal 32 is SPACE in ascii, so that's where the leading space comes from, but lets see what can be done to values 32 and greater. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible

Re: [RADIATOR] radpwtst changes from v4.9 to v.14 (or Starent atributes?)

2015-02-17 Thread Heikki Vatiainen
a check in dictionary loading that logs a warning if the VENDOR line is not a present but there are vendor specific attributes for the vendor. Cheers, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM

Re: [RADIATOR] radpwtst changes from v4.9 to v.14 (or Starent atributes?)

2015-02-16 Thread Heikki Vatiainen
. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA, Vasco

Re: [RADIATOR] radpwtst changes from v4.9 to v.14 (or Starent atributes?)

2015-02-16 Thread Heikki Vatiainen
On 02/16/2015 04:55 PM, Heikki Vatiainen wrote: I tried replicating the problem but could not get it to fail. Can you make sure you are using a radpwtst from Radiator 4.14? Also, check that you are using dictionary that includes this line: VENDORStarent8164format=2,2 If the line

Re: [RADIATOR] All RADIUS servers failed to respond

2015-02-11 Thread Heikki Vatiainen
authenticator. The client may log about this but I do not know if pam radius does. If the secret is incorrect, the server most likely logs about bad passwords too, because it does not have the correct secret to decrypt the User-Password attribute. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au

Re: [RADIATOR] AuthBy Syslog port

2015-02-05 Thread Heikki Vatiainen
if your Sys::Syslog is recent enough. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS

Re: [RADIATOR] Account log to MySQL

2015-02-05 Thread Heikki Vatiainen
FailureQueryParam %n FailureQueryParam %1 In addition to this, you can also define UsernameCharset if you'd like to make sure any special characters in User-Name do not reach your SIP2 server. See the reference manual for more. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most

Re: [RADIATOR] AuthBy Syslog port

2015-02-05 Thread Heikki Vatiainen
to make sure the log messages get to their destination. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active

Re: [RADIATOR] Trying to understand EAP Response type 25, but no expected type known

2015-01-21 Thread Heikki Vatiainen
in such a way that the server that starts EAP message authentication does not get all the messages that are part of the whole authentication exchange. Some messages are sent to the other server which then logs the message in the subject. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator

Re: [RADIATOR] problem connecting with EAP-TLS

2015-01-09 Thread Heikki Vatiainen
certificate selection, affect the certificate selection. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active

Re: [RADIATOR] Proxy Radius server configuration for fail over

2015-01-06 Thread Heikki Vatiainen
Secret somesecret /Host /AuthBy /Handler -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external

Re: [RADIATOR] problem connecting with EAP-TLS

2015-01-06 Thread Heikki Vatiainen
and the default values on different systems: http://open.com.au/radiator/ref.pdf If the problem persists, please reply with your configuration file. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM

Re: [RADIATOR] Radiator Authorization Cisco ASA

2015-01-05 Thread Heikki Vatiainen
A and G). There should especially be no d. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory

Re: [RADIATOR] Parsing nested Diameter grouped AVP-s

2014-12-23 Thread Heikki Vatiainen
and other details. I think the problem gets fixed when you change get_attr() to get_attrs(). Now it's fetching only the first instance of Media-Flow-Statistics (1086) instead of all (both) of them. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible

Re: [RADIATOR] Parsing nested Diameter grouped AVP-s

2014-12-22 Thread Heikki Vatiainen
to understand the message structure from a capture than XML. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external

Re: [RADIATOR] EAP-TTLS authentication problem

2014-12-12 Thread Heikki Vatiainen
-Id}'. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA

Re: [RADIATOR] AuthRADIUS MaxFailedGraceTime -1?

2014-12-08 Thread Heikki Vatiainen
noticed I did not acknowledge this at the time, so I thought I confirm that the fix you suggested is in the current Radiator version 4.14. Thanks for your report and suggestion! Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere

[RADIATOR] Radiator Version 4.14 released - includes a fix for EAP authentication vulnerability

2014-12-04 Thread Heikki Vatiainen
notes and backports for older Radiator versions to address the EAP bug in OSC security advisory OSC-SEC-2014-01. -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus

[RADIATOR] OSC Security advisory OSC-SEC-2014-01: Vulnerability in OSC Radiator EAP authentication could allow unauthenticated access

2014-12-04 Thread Heikki Vatiainen
with the test EAP method introduced in Radiator 4.9 + patches create the vulnerability which could be used to gain unauthorised access. OSC considers this as a vulnerability which requires urgent attention. -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable

Re: [RADIATOR] NAS-Identifier definition in the radiator data dictionary

2014-11-28 Thread Heikki Vatiainen
configured your Clients with MAC:... it means Radiator will check Called-Station-Id for match, not NAS-Identifier. In other words, I do not think this has anything to do with the dictionary but getting the correct value in Called-Station-Id. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au

Re: [RADIATOR] NAS-Identifier definition in the radiator data dictionary

2014-11-28 Thread Heikki Vatiainen
starts with MAC: and it is followed by a MAC address, then Called-Station-Id can be used for matching if the IP address does not match first. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files

Re: [RADIATOR] Duplicate request issues

2014-11-27 Thread Heikki Vatiainen
an AuthLog and/or AcctLogFileName in the default Handler when all requests should be handled by the other Handlers. This helps to see if there are any configuration mistakes that cause requests to miss the other Handlers. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most

Re: [RADIATOR] AVP with ipv4 or ipv6 values

2014-11-26 Thread Heikki Vatiainen
will decode IPv6 addresses correctly. Note: with 4.9 the textual address will get 'ipv6:' prefix. This will not happen with the patched version. Thanks for reporting this. Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere

Re: [RADIATOR] Duplicate request issues

2014-11-26 Thread Heikki Vatiainen
queue are processed too slow which might be your case. If the queue is not emptied quickly enough, the external may think think the request it sent (or the corresponding reply) may have been lost. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible

Re: [RADIATOR] Using Radiator and Net-SNMP on the same server?

2014-11-21 Thread Heikki Vatiainen
the accounting server subtree. This is the information that is available if you query Radiator directly (the port is now 1161): % snmpwalk -m+ALL -v2c -c public 127.0.0.1:1161 .1.3.6.1.2.1.67 Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable

Re: [RADIATOR] Use Mozilla's intermediate cipher suites set by default.

2014-11-21 Thread Heikki Vatiainen
. In addition to controlling TLS and SSL versions, more specific options, such as allowing RC4 when required, are useful to have. Thanks for your input! Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM

Re: [RADIATOR] Web GUI

2014-11-21 Thread Heikki Vatiainen
. The evaluation version has everything the fully licensed version does. For a preconfigured version, see the .ova format virtual machine image in Radiator evaluation downloads. It has the web server and a number of authentication methods already enabled. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au

Re: [RADIATOR] Issues with CachePasswords

2014-11-18 Thread Heikki Vatiainen
from the CachePasswords rutine.. Yes. Is it otherwise working as expected? Thanks for reporting this, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus

Re: [RADIATOR] CoA-Request vs Change-Filter-Request in radpwtst

2014-11-13 Thread Heikki Vatiainen
to the this AuthBy RADIUS and call handle_request() to send the CoA message. AuthBy RADIUS would then take care of retransmissions and could possibly call ReplyHook and NoReplyHook which could do any clean up that may be needed. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator

Re: [RADIATOR] CoA-Request vs Change-Filter-Request in radpwtst

2014-11-12 Thread Heikki Vatiainen
scripts that use radpwtst and any existing Radiator modules or hooks that do not come with Radiator (own custom code). The change could be applied to just radpwtst, but likely it would be less confusing to change them both. I'll see when to get this in the patches. Thanks, Heikki -- Heikki

Re: [RADIATOR] TLS 1.1 and TLS 1.2 Support in Radiator

2014-11-06 Thread Heikki Vatiainen
what the state of play is. I hope I was able to help. Thanks for letting us know about this. Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside

[RADIATOR] Radiator evaluation - now available as virtual machine

2014-11-04 Thread Heikki Vatiainen
and Microsoft SQL databases have been prepared. A simple download from the respective vendors is required to complete the set up. As always, any comments and suggestions are welcome. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server

Re: [RADIATOR] Defining share secret per NASID instead of IP

2014-11-04 Thread Heikki Vatiainen
-Station-Id'); \ ${$_[0]}-add_attr('Called-Station-Id',$nasId) unless($stationId); \ } Best regards, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus

Re: [RADIATOR] Defining share secret per NASID instead of IP

2014-10-31 Thread Heikki Vatiainen
to be the MAC address. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC

Re: [RADIATOR] log the matched AuthBy identifier

2014-10-31 Thread Heikki Vatiainen
, for example, log the Identifier of the last AuthBy as shown above. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM

Re: [RADIATOR] Defining share secret per NASID instead of IP

2014-10-30 Thread Heikki Vatiainen
as the Client name. Something like this should work. The prefix tells that the name is not a host name or IP address. name | secret ---+-- MAC:00-0C-42-FA-53-30 | Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator

Re: [RADIATOR] Troubles trying to proxy NTLM

2014-10-30 Thread Heikki Vatiainen
be fine. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA

Re: [RADIATOR] log the matched AuthBy identifier

2014-10-24 Thread Heikki Vatiainen
that was evaluated. Is this what you are thinking of? Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active

Re: [RADIATOR] radsec with dynamic discovery

2014-10-20 Thread Heikki Vatiainen
Discovery - Deployment plan -' which has more information about radsec, DNS dynamic discover and eduroam. However, I'm not exactly sure what the status with DNS dynamic discovery with eduroam is, so I can not say how eduroam organisations currently use it. Thanks, Heikki -- Heikki Vatiainen h

Re: [RADIATOR] Hiding the LDAP Password attribute on Trace level 4 [SEC=UNCLASSIFIED]

2014-10-13 Thread Heikki Vatiainen
depends on the specific log level. If I remember correctly, the password log currently does not log, for example, passwords in proxied messages, but if there are cases that it does not cover, we'd like to hear about them. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most

Re: [RADIATOR] Change Default Size for Capabilities Field

2014-10-03 Thread Heikki Vatiainen
with accounting enabled, I would check what the WiMAX ASN-GW, or the device that is sending the RADIUS requests, is logging. Anything else I can try? I'd say the next step is to check the WiMAX devices logs to see if there's anything else that it is expecting or does not like. Thanks, Heikki -- Heikki

Re: [RADIATOR] add Attributes when retrying to a new Host in AuthROUNDROBIN (radiator Digest, Vol 63, Issue 14)

2014-10-03 Thread Heikki Vatiainen
as root. One might have tried to use sudo for something similar already, but now the Group option can also be used to specify the groups. If there are group names that can not be resolved, then radiusd will not try to switch groups Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator

Re: [RADIATOR] Change Default Size for Capabilities Field

2014-09-26 Thread Heikki Vatiainen
the file that Radiator uses in case you have multiple copies on the disk. Is the WiMAX RADIUS client logging anything? Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password

Re: [RADIATOR] Change Default Size for Capabilities Field

2014-09-26 Thread Heikki Vatiainen
to see if there are hints about which directories are used. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external

Re: [RADIATOR] Change Default Size for Capabilities Field

2014-09-25 Thread Heikki Vatiainen
. Also note that Radiator access-accept is showing no accounting and we suspect this is the root cause. Thanks for your help, James Austin Manager Technology Projects Crystal Communications Ltd. 281-300-8294 Mobile 281-361-5199 Office -- Heikki Vatiainen h...@open.com.au Radiator

Re: [RADIATOR] Change Default Size for Capabilities Field

2014-09-24 Thread Heikki Vatiainen
. Don't know how to adjust it? James Austin Manager Technology Projects Crystal Communications Ltd. 281-300-8294 Mobile 281-361-5199 Office From: Heikki Vatiainen [h...@open.com.au] Sent: Tuesday, September 23, 2014 8:17 AM To: James Austin

Re: [RADIATOR] Radius authentication with Tacacs+ for authorization only

2014-09-24 Thread Heikki Vatiainen
Handler Service-Type=Authorize-only with an AuthBy that has NoCheckPassword? Add this Handler before your current Handler to process TACACS+ based authorisation requests differently from RADIUS originated access requests. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most

Re: [RADIATOR] Change Default Size for Capabilities Field

2014-09-23 Thread Heikki Vatiainen
. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA, Vasco

Re: [RADIATOR] Change Default Size for Capabilities Field

2014-09-22 Thread Heikki Vatiainen
--password=fred wimax ... mysql alter table device_session modify capabilities varchar(500); Query OK, 0 rows affected (0.00 sec) Records: 0 Duplicates: 0 Warnings: 0 This should make the capabilities column long enough to store the long data. -- Heikki Vatiainen h...@open.com.au Radiator

Re: [RADIATOR] SHA-2 SSL Certificate Support

2014-09-22 Thread Heikki Vatiainen
, but if there are problems with other platforms, we would be interested to hear more. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS

Re: [RADIATOR] Load Balancers Returning IGNORE Warnings

2014-09-18 Thread Heikki Vatiainen
it log to a local file, that might help. Or then you could use Log SYSLOG and let it log it to local syslogd, that is not to a LogHost. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files

Re: [RADIATOR] Load Balancers Returning IGNORE Warnings

2014-09-16 Thread Heikki Vatiainen
this helps to keep the configuration files more simple since you do not need to handle both accounting and authentication with the same configuration. However, it might be worth taking a look at the next hop performance first. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most

Re: [RADIATOR] Load Balancers Returning IGNORE Warnings

2014-09-16 Thread Heikki Vatiainen
. The big question is how do I determine that SQL is the bottleneck from the radius logs? --- Roberto Ullfig - rull...@uic.edu ACCC Research Programmer -Original Message- From: radiator-boun...@open.com.au [mailto:radiator-boun...@open.com.au] On Behalf Of Heikki Vatiainen Sent

Re: [RADIATOR] Missing Session Accounting

2014-09-11 Thread Heikki Vatiainen
happening. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX

Re: [RADIATOR] Dynamic handler generation for NAS-IP-Address criteria

2014-09-04 Thread Heikki Vatiainen
than creating Handlers dynamically. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS

Re: [RADIATOR] Problems with Secret and SQLClientList

2014-09-02 Thread Heikki Vatiainen
, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA, Vasco

Re: [RADIATOR] Problems with Secret and SQLClientList

2014-09-02 Thread Heikki Vatiainen
have been the only way to make sure the client and server secrets match. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM

Re: [RADIATOR] add Attributes when retrying to a new Host in AuthROUNDROBIN

2014-08-29 Thread Heikki Vatiainen
On 08/20/2014 11:30 PM, Heikki Vatiainen wrote: On 08/20/2014 03:03 AM, David Zych wrote: That's exactly right, and setting MaxTargetHosts 2 would be perfect in this case. I'll get back to you once there's something to test. MaxTargetHosts is now applicable for AuthBy RADIUS and its sub

Re: [RADIATOR] SQL Server

2014-08-27 Thread Heikki Vatiainen
accounting data. You can also store it in SQL and text files if both are needed. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM

Re: [RADIATOR] add Attributes when retrying to a new Host in AuthROUNDROBIN

2014-08-25 Thread Heikki Vatiainen
On 08/20/2014 03:03 AM, David Zych wrote: On 08/19/2014 04:07 PM, Heikki Vatiainen wrote: On 08/19/2014 01:00 AM, David Zych wrote: How can I set a new attribute value on a request _each_ time I attempt to proxy it using AuthRADIUS and friends? I'm thinking a PreForwardHook would be ideal

Re: [RADIATOR] AuthNTLM feature requests

2014-08-22 Thread Heikki Vatiainen
it? It's fine. What I was thinking was that if someone wants to try passing a rewritten username to AuthBy NTLM, they would need to be careful about what they rewrite and at which point. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable

Re: [RADIATOR] AuthNTLM feature requests

2014-08-21 Thread Heikki Vatiainen
input has been most useful. It's good to hear about the different requirements there are. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus

Re: [RADIATOR] PEAP and realm check

2014-08-21 Thread Heikki Vatiainen
-- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA, Vasco, Yubikey, MOTP

Re: [RADIATOR] PEAP and realm check

2014-08-20 Thread Heikki Vatiainen
, but it is normally the same as User-Name unless User-Name attribute has been rewritten). The purpose of anonymous identity is only to get the request to the correct authentication server within the campus or across eduroam, etc. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most

Re: [RADIATOR] AuthNTLM feature requests

2014-08-20 Thread Heikki Vatiainen
would be there for AuthBy FILE, SQL, etc. too, not just AuthBy NTLM. Please let us know why this is needed. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald

Re: [RADIATOR] add Attributes when retrying to a new Host in AuthROUNDROBIN

2014-08-20 Thread Heikki Vatiainen
, thanks for confirming this too. I'll get back to you once there's something to test. Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS

Re: [RADIATOR] add Attributes when retrying to a new Host in AuthROUNDROBIN

2014-08-19 Thread Heikki Vatiainen
it for round robin? And maybe the hook too? Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP

Re: [RADIATOR] PEAP and realm check

2014-08-19 Thread Heikki Vatiainen
the correct Handler for the inner request. The inner identity is used to for the authentication. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus

Re: [RADIATOR] Apcon Radius dictionary entry

2014-08-14 Thread Heikki Vatiainen
10830 VENDORATTR 10830 Apcon-User-Level 1 integer VALUE Apcon-User-Level Default 0 VALUE Apcon-User-Level Guest 1 VALUE Apcon-User-Level Operator 2 VALUE Apcon-User-Level Advanced 3 VALUE Apcon-User-Level Admin 4 -- Heikki Vatiainen h...@open.com.au Radiator

[RADIATOR] Support for non-blocking sockets on Windows

2014-08-13 Thread Heikki Vatiainen
as NPS, when conversion is needed. We would be interested to hear comments from Windows users, especially those who run RadSec. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS

Re: [RADIATOR] Combining AuthSQLTOTP with other authication sources

2014-08-07 Thread Heikki Vatiainen
of the authentication. You would still require cleanup for users that are no longer present, but the SQL table would not need to contain the users that are not active TOTP users. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS

Re: [RADIATOR] How to get rid of passwords in configuration files

2014-08-05 Thread Heikki Vatiainen
} as the only formatter for these, and possibly some other, values. P.S. FWIW, I like this idea. :) I'll see if a patch can be made for this and let the list know when this is available. Thanks to Johannes too for his comments. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most

Re: [RADIATOR] How to get rid of passwords in configuration files

2014-08-04 Thread Heikki Vatiainen
How can I get rid of all passwords from the configuration file (without a preprocessor of the configuration file). -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald

Re: [RADIATOR] No response with Authby URL running as a Windows service

2014-07-29 Thread Heikki Vatiainen
directory. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA

Re: [RADIATOR] Preventing Computer/Machine Authentication in AuthBy NTLM

2014-07-09 Thread Heikki Vatiainen
and/or server 2012 should be doable too, then. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS

Re: [RADIATOR] Modyfying UsernamePrompt in ServerTACACSPLUS

2014-06-26 Thread Heikki Vatiainen
want to print This is my User prompt: in order to have: This is my User prompt: username (Space between : and username) Try this: UsernamePrompt This is my User prompt:\040 Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible

Re: [RADIATOR] Radiator / Radmin - EAP TLS certificates on Android phone

2014-06-19 Thread Heikki Vatiainen
with Radiator? See the certificates/ directory in the distribution. Those certificates have been used with EAP-TLS, so they could help building an initial working configuration before switching to different certificates. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable

Re: [RADIATOR] Wireless client verification of Radiator's SSL cert EAP/PEAP

2014-06-19 Thread Heikki Vatiainen
connectivity. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX, RSA

Re: [RADIATOR] Radiator / Radmin - EAP TLS certificates on Android phone

2014-06-18 Thread Heikki Vatiainen
and appears as bad TLS record to the server. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS

Re: [RADIATOR] EAP-TTLS missing reply attributes from inner-accept

2014-06-09 Thread Heikki Vatiainen
PostAuthHook to examine the current reply and switch it to a reject. PS: Please note your message did not get to the list since you seem to be using a different address than previously. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS

Re: [RADIATOR] Differences in specifying EAP certificates in configuration

2014-06-09 Thread Heikki Vatiainen
, and then finally the CA certificate. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS

Re: [RADIATOR] Custom AuthApplicationIds

2014-06-07 Thread Heikki Vatiainen
with DiameterDictionaryFile. Please let us know if the above gets it going. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM

Re: [RADIATOR] EAP-TTLS missing reply attributes from inner-accept

2014-06-07 Thread Heikki Vatiainen
sort of disconnect in getting the attributes from the SQL statement return values to the reply. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus

Re: [RADIATOR] Custom AuthApplicationIds

2014-06-07 Thread Heikki Vatiainen
in your previous messages. Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC

Re: [RADIATOR] Trying to get Radiator to work with EAP-TTLS auth

2014-06-05 Thread Heikki Vatiainen
modules to check. Thanks, Heikki -- Heikki Vatiainen h...@open.com.au Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC

<    1   2   3   4   5   6   7   8   9   10   >