Re: Freeradius and RSA SecurID

2002-02-12 Thread Alan DeKok
Charlie Watts [EMAIL PROTECTED] wrote: I'm just astonished you still answer the once-a-week FAQs. There's a lot I don't answer, too. If the response is only one-line, I don't mind firing off a quick note. If the response is longer, or there are many, many repeated 1-line questions, I

postgreSQL

2002-02-12 Thread vladimir ezcurra
Someone know somethink about this matter: Freeradius using postgreSQL (Configuration) Vlad __ Do You Yahoo!? Send FREE Valentine eCards with Yahoo! Greetings! http://greetings.yahoo.com - List info/subscribe/unsubscribe? See

Re: Counter module doesn't work

2002-02-12 Thread Andrew Kelaidis
Thanks!!! Now I have only this record in radcheck table: Username Attribute Value op - UserName Max-Daily-Session-Time7200 := .. - but I had to change the

Re: unable to get a clean gmake

2002-02-12 Thread the ACTUAL zeke
the version that produces these errors is: freeradius-snapshot-20020209 Z Upgrade to the latest CVS snapshot. Z Alan DeKok. has freeradius ever worked on BSDI? if so, what options need to be added to ./configure. i think that could be my only problem. i am sorry to be such a pain, we

Re: FreeRADIUS with MS SQL

2002-02-12 Thread Alan DeKok
Michael Vasilenko [EMAIL PROTECTED] wrote: I need to setup RADIUS wich works with MS SQL, can somebody give me an advice? Does FreeRADIUS can do this? ODBC or something? ODBC should work in the latest CVS snapshot. Alan DeKok. - List info/subscribe/unsubscribe? See

Counter module doesn't work

2002-02-12 Thread Andrew Kelaidis
I have installed the latest snapshot of freeRadius and I am using mySQL for AAA. I would also like to limit the online time for all users. Here is a part of my radiusd.conf file: counter { filename = ${raddbdir}/db.counter key = User-Name

Re: problem with DEFAULT realm

2002-02-12 Thread Alan DeKok
[EMAIL PROTECTED] (Rainer Clasen) wrote: during my tests of Freeradius, I found a tiny annoyance when all servers for a realm are marked dead: Although there are entries with an exact match (but marked dead), the DEFAULT entry is used. Yes, that's how the DEFAULT realm works. This

PostgreSQL's configuration

2002-02-12 Thread kao shimit
Hello I have my database created, now i need to setup RADIUS to work with postgreSQL, this is with configure command... Does anybody know how to do it? or the parameters for configure command Thanks _ MSN Photos es la manera

Freeradius and RSA SecurID

2002-02-12 Thread Cleo
Good day, Can I configure Free radius to us securID? If yes, can somebody please give me some configuration steps. Thank you = = Cleophas Toe, CISSP | Phone:650-980-3686 Sr. Info. Security Officer | Cell:

Re: Radius Question

2002-02-12 Thread Alan DeKok
William Kelley [EMAIL PROTECTED] wrote: I have multiple users who are logged in who stay logged in but they = aren't actually connected to the NAS. It seems sometimes the radacct = (using mysql) never sets a stop time for users. So they stay connected = and when you radwho they are still

RE: Counter module doesn't work

2002-02-12 Thread Kostas Kalevras
On Mon, 11 Feb 2002, Peter Santiago wrote: Based on what I'm reading below ... to set time limits for my users, I need to use a database (MySQL). Do I? I'm using portslave wih freeradius If I just want to use /etc/passwd for authentication... where and how should I store the time limits

Re: Freeradius and RSA SecurID

2002-02-12 Thread Charlie Watts
On Mon, 11 Feb 2002, Alan DeKok wrote: Many of my posts are responsive because I'm waiting for a 5-minute job to finish in another window, and I can fire off a quick reply. I'm just astonished you still answer the once-a-week FAQs. You're a saint! -- Charlie Watts [EMAIL PROTECTED]

Re: Identical attributes on auth

2002-02-12 Thread Alan DeKok
Thomas Jalsovsky [EMAIL PROTECTED] wrote: OK, I see that in the last CVS is the paircmp fix. I compiled the latest CVS, and made som debugs. Unfortunately I can't make it working. It would be easier to debug the problem if you used a simple test entry in the 'users' file, and poked at the

freeradius with PostgreSQL...

2002-02-12 Thread Gus Rios
Hi, How can i install freeradius with postgreSQL? What are the arguments for 'configure' ? or what other things i have to do? regards, _ Hable con sus amigos en lĂ­nea, pruebe MSN Messenger: http://messenger.msn.es - List

R: Always on rlm_sql: Could not link driver rlm_sql_mysql

2002-02-12 Thread Maurice Foschiatti
You was right. I' have no shared versions of mysql libraries. Where can i find them ? I've tried to recompilig mysql, but the only library that i'have, are: drwxr-xr-x 15 root mysql512 Feb 7 11:23 .. -rw-r--r-- 1 mysqlmysql 15054 Jan 3 09:43 libdbug.a -rw-r--r-- 1

Simultaneous Use not working

2002-02-12 Thread Graham @ LEC Dalby
Simultaneous Use is not working for me. The checkrad script works fine when I call it manually, but it is never executed by radius. I have turned debugging on in checkrad - but the script is never executed. running radiusd -xx does not give any indication that it is trying to call checkrad or

Login-Time

2002-02-12 Thread Troy
Can some please give me the correct syntax for this statement on cistron radius Is it ? Login-Time = Wk0800-1700,Sa,Su And where should it go, IE straight under the username password line? Also if I put DEFAULT Simultaneous-Use = 1 Fall-Through = 1 at the top of my users file will

Re: port 25 filtering

2002-02-12 Thread Miquel van Smoorenburg
In article 010701c1b0c3$1b92c780$[EMAIL PROTECTED], John Singewald [EMAIL PROTECTED] wrote: We are authenticating modem pools using cistron 1.6. Wrong list - this is not the cistron radius mailinglist. Can someone give advise on how to set up a filter to limit port 25 relaying to one

FreeRadius with 802.1x

2002-02-12 Thread Nick
I am trying to configure FreeRaduis to work with 802.1x LEAP/CISCO 350 Access Point and CISCO 350 card. Has anyone been able to get this working? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See

Access Reject

2002-02-12 Thread Thomas Jalsovsky
Hello I would like to send an Access reject packet to NAS when the User-Name and User-Password fields match (successfull auth.) I want to do that with DB, but I don't know what and where I have to put. Could anybody tell me? I tryed put to radgroupreply: mygroup | Auth-Type | Reject

Re: Simultaneous Use not working

2002-02-12 Thread Graham @ LEC Dalby
No, I'm not using realms. It is just the straight username / password. checkrad isn't even getting called. If i run checkrad manually it gives the results you would expect, but radiusd isn't running it at all - ever. - Original Message - From: Randy Moore [EMAIL PROTECTED] To: [EMAIL

unsubscribe

2002-02-12 Thread Supriya
its blocking my account,plz unsubscribe me, - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius and RSA SecurID

2002-02-12 Thread Alan DeKok
Tim Monaghan [EMAIL PROTECTED] wrote: And another thing, I wouldnt mind helping in a documentation effort, if one is underway, Im kinda dumb about radius at the moment, but Im getting a crash course, and I think a good set of docs would not exactly require experts on the case. Is there

Re: UTF-8

2002-02-12 Thread Alan DeKok
Raghu Seshadri [EMAIL PROTECTED] wrote: Hi, does FreeRadius support usernames encoded in UTF-8 ? No. I would like usernames such as j=F6rg and har=E4ld to be authenticated. If yes, which version of FreeRadius should I = download ? If you can type the binary characters into a string,

bug: no default auth port

2002-02-12 Thread Rainer Clasen
Hello, if you specify the port in radiusd.conf as 0, the auth port is set after the configs were read. But while reading the realms file, it is already used as default. You end up with 0 as the auth port for those entries without a :port. And even more anoying: There is only a debug message,

me- unsubscribe

2002-02-12 Thread Supriya
- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Is their a way to check for a suspended account?

2002-02-12 Thread Do-Risika RAFIEFERANTSIARONJY
Michael Letchworth wrote: I'm trying to figure if their is a field for checking a suspended account? if you try the Expiration attribute ? you just pull it out when you reactivate the account ... @+ -- DouRiX - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Using PAM to auth to FR w/ mysql?

2002-02-12 Thread Michael Letchworth
I'm still trying to figure out all the possibilities about how I can use freeradius on our system? Is it possible or even a good idea to configure a system like the following? I want to have the users (10,000) in the radius server running mysql and not /etc/passwd file except for the system

okeeffe.bestweb.net re-sending all freeradius posts back to list

2002-02-12 Thread dan kelley
Hi- okeeffe.bestweb.net is re-sending every message that's been sent to this list in the last week or so. Is there any way that this address can be blocked until they fix thr problem? Thanks- Dan -- Forwarded message -- Return-Path: [EMAIL PROTECTED] Delivered-To: [EMAIL

Re: Freeradius and RSA SecurID

2002-02-12 Thread Alan DeKok
[EMAIL PROTECTED] (Rainer Clasen) wrote: And BTW, this list is far better than most commercial support I had to struggle with. There's a reason for that. The biggest one is that commercial support usually doesn't include a users list, where everyone helps everyone else. Even if there WAS

Re: Using PAM to auth to FR w/ mysql?

2002-02-12 Thread Alan DeKok
Michael Letchworth [EMAIL PROTECTED] wrote: Correct me if I an wrong but doesn't PAM return the same information like UID,GID, shell and home directory that the getpasswd does? No. PAM doesn't do that. It's impossible. PAM only does username/password authentication. You'll need to use

ADMIN: somebody reinjecting old messages.

2002-02-12 Thread Miquel van Smoorenburg
In article [EMAIL PROTECTED], Alan DeKok [EMAIL PROTECTED] wrote: No he didn't - somebody is reinjecting old messages with a new message-id and new Received: headers back into the list. I've mailed the admins and blocked the machine that is doing that. Unfortunately already 200 messages have

Re: radius detail log question

2002-02-12 Thread Alan DeKok
Peter Santiago [EMAIL PROTECTED] wrote: This is taken from the detail log file... I have already set the MAX-DAILY-SESSION variable in the users file syntax : DEFAULT Max-Daily-Session := 3600 How come that variable is not seen in this log? Because it's not actually added to the

radius detail log question

2002-02-12 Thread Peter Santiago
This is taken from the detail log file... I have already set the MAX-DAILY-SESSION variable in the users file syntax : DEFAULT Max-Daily-Session := 3600 How come that variable is not seen in this log? Tue Feb 12 12:38:26 2002 Acct-Status-Type = Start User-Name =

unsubscribe

2002-02-12 Thread Vijay Akasapu
Please unsubscribe me. thanks. _ Chat with friends online, try MSN Messenger: http://messenger.msn.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: [List-Error] Doubled up messages..

2002-02-12 Thread Vincent_Giovannone
Yeah, I'm having that problem with the list also. (receiving double messages all of a sudden.) Although, as I write this, it _seems_ to have stopped. seems. :) Vincent Giovannone Network Infrastructure Group Information Services Division Rush - Presbyterian St. Luke's Medical Center Monday is

Re: LDAP Authentication

2002-02-12 Thread Kostas Kalevras
On Tue, 12 Feb 2002, Steve Tolman wrote: I have the latest CVS Snapshot installed and running using Netscape LDAP for authentication. My users are grouped in LDAP into 4 major groups. Is there a way in FreeRadius to control access based on the different groups configured in LDAP? If so where

UUNET VIP Configuration

2002-02-12 Thread Net Admin
Freeradius 0.4 We have been trying to establish a radius connection with UUNET VIP services for a few weeks now and just can't seem to get the Ascend Filters to work. Could someone using UUNET VIP with Freeradius 0.4 on this list e-mail me their radius config files so that I can compare

Diff time

2002-02-12 Thread Gus Rios
hello, I'm working with cisco 5300 and i want to get the difference beetween the start time (h323-connect-time) and the stop time (h323-disconnect-time) at the same time i get the stop time... is this a parameter sent by cisco? or i have to do it manually... regards.

Re[2]: Is their a way to check for a suspended account?

2002-02-12 Thread Galileo
Session_Timeout figure of 1 second - user connects and before they get a chance to do anything they are disconnected. I also use the same principle of controlling the Session_Timeout parameter for my prepaid users. When they run out of time, the Session_timout becomes 1 second and they are

Re: Diff time

2002-02-12 Thread horape
Use standard session time. On Tue, Feb 12, 2002 at 05:48:24PM -0500, Gus Rios wrote: hello, I'm working with cisco 5300 and i want to get the difference beetween the start time (h323-connect-time) and the stop time (h323-disconnect-time) at the same time i get the stop time... is this a

Which program is responsible for kicking users out....?

2002-02-12 Thread Peter Santiago
Another question... which or what program is responsbile for disconnecting users once their available online time is used up? I'm using portslave.. Thanks - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Fix for consideration: re: checkrad timeout

2002-02-12 Thread scott.list
I rarely get a chance to contibute, and may get shot down here, but I think I have a fix for implementation. The script I debugged to fix was from Cistron 1.6.6. I had tried the current freeradius version of checkrad with the same (not working) result. Therefore I am assuming (without

Re: UUNET VIP Configuration

2002-02-12 Thread Eric Dean
UUNET does not support Ascend VSAs...and neither do any other commercial carriers to my knowledge. I add the following in a user profile. X-Ascend-Data-Filter += ip in forward tcp est, X-Ascend-Data-Filter += ip in forward dstip 10.1.1.0/24, X-Ascend-Data-Filter += ip

Re: [fradius] Re: UUNET VIP Configuration

2002-02-12 Thread R P Herrold
On Tue, 12 Feb 2002, Eric Dean wrote: UUNET does not support Ascend VSAs...and neither do any other commercial carriers to my knowledge. I add the following in a user profile. X-Ascend-Data-Filter += ip in forward tcp est, X-Ascend-Data-Filter += ip in forward dstip

RE: [fradius] Re: UUNET VIP Configuration

2002-02-12 Thread David Woolley
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 At OzEmail were tested sucessfully the following on the UUNET DAN. Ascend-Data-Filter = ip in forward dstip 203.2.192.0/24 tcp dstport = smtp Ascend-Data-Filter = ip in drop tcp dstport = smtp Ascend-Data-Filter = ip in forward -Original

Re: [fradius] Re: UUNET VIP Configuration

2002-02-12 Thread R P Herrold
On Tue, 12 Feb 2002, Eric Dean wrote: Does BWing require the VSA or old X-Ascend style? Herrold: Broadwing does, and mandated (for anti-UCE purposes) just such a set of attributes effective January 7 this year; While it I have elided the customer's C class info ... I believe this is