Re: [RADIATOR] Is the Radiator NFV customizable?

2016-06-30 Thread Tuure Vartiainen
mponents on VMs based on nodes' role. There’s however an ad video available at http://www.open.com.au/nfv/ ;) BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Fr

Re: [RADIATOR] Is the Radiator NFV customizable?

2016-06-28 Thread Tuure Vartiainen
s (RADIUS or Diameter) - 2 Radiator AAA workers (number of workers scales according to load) - 3 Database/message broker nodes - 2 External database connector nodes (LDAP, SQL, RADIUS or Diameter) - 2 Management nodes With OpenStack, creating Radiator VNF stack is automated through its Heat orchestrati

Re: [RADIATOR] Multiple accounting output formats

2016-06-14 Thread Tuure Vartiainen
does not seem to be available for accounting logs). > unfortunately currently that’s not possible, all AcctLogFileNames use the same configured format. AuthLog could be companied with AcctLog which would allow to configure the described feature. BR -- Tuure Vartiainen Radiator: the most

Re: [RADIATOR] help diagnosing failure to connect to LDAP

2016-05-11 Thread Tuure Vartiainen
oreground. E.g. $ perl radiusd -config /etc/radiator/radius.cfg -trace 4 -log_stdout -foreground BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, ext

Re: [RADIATOR] syntax

2016-05-11 Thread Tuure Vartiainen
Please see Radiator reference manual (http://www.open.com.au/radiator/ref.pdf) section "5.27.1 AuthByPolicy" for different policies. BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, E

Re: [RADIATOR] A few questions regarding MacSec

2016-04-17 Thread Tuure Vartiainen
nfiguration/guide/trustsec/arch_over.html) BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiM

Re: [RADIATOR] Performance logging

2016-04-04 Thread Tuure Vartiainen
Hi, > On 04 Apr 2016, at 11:24, Hartmaier Alexander > wrote: > > On 2016-03-30 15:10, Tuure Vartiainen wrote: >> >>> On 30 Mar 2016, at 14:55, Hartmaier Alexander >>> wrote: >>> >>> we use PEAP-TLS, EAP-PEAP as outer EAP type with EAP-

Re: [RADIATOR] Performance logging

2016-03-30 Thread Tuure Vartiainen
l time for an EAP authentication can be seen in the log. E.g. Wed Mar 30 12:55:58 2016 816812: DEBUG: EAP Success, elapsed time 0.71221 We’ll add a feature, which will allow the total time along with an on-demand timing to be used through %{...} special format in AuthLogs etc. BR -- Tuur

Re: [RADIATOR] Performance logging

2016-03-30 Thread Tuure Vartiainen
or. Does PEAP-TLS mean, that you are using EAP-PEAP with EAP-TLS as an innner EAP method or EAP-PEAP with EAP-MSCHAPv2? BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Free

Re: [RADIATOR] Performance logging

2016-03-30 Thread Tuure Vartiainen
eeing your configuration and Trace 4 (DEBUG) log of a single request including microseconds (LogMicroseconds). I assume that those timings are for the last Access-Request of EAP authentication which produces either Access-Accept or Access-Reject. Usually most of the time goes to a user lookup f

Re: [RADIATOR] RAdmin Authentication (Access to RAdmin Website)

2015-11-05 Thread Tuure Vartiainen
ROM RADMINCONFIG WHERE NAME = ´AuthenticateAdmin´; BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, TTLS, PEAP, TNC, WiMAX

Re: [RADIATOR] Feature request - Different encryption methods in AuthBy UNIX

2015-11-04 Thread Tuure Vartiainen
Hi, > On 04 Nov 2015, at 00:30, Johnson, Neil M wrote: > > Yes it does. > > Hmm. I must of mistyped a password somewhere. > Ack. > Sorry. > No problem, were you able to get it to work? BR -- Tuure Vartiainen Radiator: the most portable, flexible and co

Re: [RADIATOR] Is this config possible?

2015-11-01 Thread Tuure Vartiainen
er will match to the first DEFAULT entry above. If you just want to authenticate WirelessAdmins, then just add a user/users to the group to make it non-empty, e.g. WirelessAdmins:x:1235:admin1 BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS serve

Re: [RADIATOR] Feature request - Different encryption methods in AuthBy UNIX

2015-11-01 Thread Tuure Vartiainen
as been a support for e.g. SHA-512 passwords (“$6$” prefix in shadow file). AuthBy UNIX supports all the same password formats which Radiator suppports. BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, p

Re: [RADIATOR] Is this config possible?

2015-10-30 Thread Tuure Vartiainen
r users, the current code allows also authenticated users when comparing against non-existing group. We’ll fix the later in a following release. BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password,

Re: [RADIATOR] Password/certificate security seems next to none on Radiator server

2015-10-02 Thread Tuure Vartiainen
PrivateKeyPassword %{GlobalVar:tls_cert_key_pass} The protection of secrets is then implemented in conf_secrets.pl script. When authorized to output, it should print stdout: DefineGlobalVar client1_secret mysecret DefineGlobalVar tls_cert_key_pass whatever BR -- Tuure Vartiainen Radiator: the most portable, flexibl

Re: [RADIATOR] How to combine HASHBALANCE with AuthBy RadSec?

2015-09-14 Thread Tuure Vartiainen
Hi, > On 11 Sep 2015, at 12:08, Jan Tomasek wrote: > > On 09/08/2015 11:12 AM, Tuure Vartiainen wrote: >> We’ll add a Gossip support for RadSec later, probably to 4.16 patches, and >> look >> into implementing equivalent balancing support for RadSec as what there is

Re: [RADIATOR] How to combine HASHBALANCE with AuthBy RadSec?

2015-09-08 Thread Tuure Vartiainen
BALANCE.pm AuthHASHBALANCE.pm AuthLOADBALANCE.pm AuthVOLUMEBALANCE.pm AuthROUNDROBIN.pm AuthRADIUSBYATTR.pm BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, Platypus, Freeside, TACACS+, PAM, externa

Re: [RADIATOR] Best way to strip leading DOMAIN\ with PEAP

2015-06-24 Thread Tuure Vartiainen
Hi, > On 24 Jun 2015, at 10:52, Christian Kratzer wrote: > > On Wed, 24 Jun 2015, Tuure Vartiainen wrote: >> >>> On 24 Jun 2015, at 10:00, Christian Kratzer wrote: >>> >>> I have a couple of windows users that send a DOMAIN\ prefix to their >>

Re: [RADIATOR] Best way to strip leading DOMAIN\ with PEAP

2015-06-24 Thread Tuure Vartiainen
dentity) as the username with PEAP and %w > (orig username) in the TTLS case. > by using RewriteUsername I would say. E.g. RewriteUsername s/^([^\\]*)\\(.*)/$2/ BR -- Tuure Vartiainen Radiator: the most portable, flexible and configurable RADIUS server anywhere. SQL, proxy, DBM, f