Basic Question about group management

2005-04-19 Thread Julien freeradius
Hello, I m using Freeradius with mysql for PPP since two years, everything work great. I want to allow some user to use a vpn (VPNcisco3000). I don't have any problem to identify a user in PPP, or to identify a user in from the concentrator. But I don't know how to set correctly the group

Re: nas-identifier and ldap.attrmap

2005-04-19 Thread guest01
Solved Thank you guys, you made my day!! :-) I didn't know that there was a checkval-modul in freeradius. This modul does exactly what I want!! Thank you very much!! regards peda - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

ip-pool

2005-04-19 Thread Tom Fritz
Hi everybody, I'm using a Cisco Aironet 1200 AP and I want that my laptop get an ip address from my specified ip-pool in the radiusd.conf file. The radius server is sending the correct Framed-IP-Address with the Access-Accept message, but it isn't assigned to the connection. How can I solve

ip-pool

2005-04-19 Thread Tom Fritz
Hi everybody, I'm using a Cisco Aironet 1200 AP and I want that my laptop get an ip address from my specified ip-pool in the radiusd.conf file. The radius server is sending the correct Framed-IP-Address with the Access-Accept message, but it isn't assigned to the connection. How can I solve

Re: rlm_tcl module

2005-04-19 Thread Alexei Chetroi
On Mon, Apr 18, 2005 at 01:27:17PM -0400, Alan DeKok wrote: Date: Mon, 18 Apr 2005 13:27:17 -0400 From: Alan DeKok [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Reply-To: freeradius-users@lists.freeradius.org Subject: Re: rlm_tcl module Alexei Chetroi [EMAIL PROTECTED]

Re: deployment question

2005-04-19 Thread Maqbool Hashim
Sorry, what I'm trying to ask is: Most secure way to create a unix login whose sole function is to execute adduser to add users to the /etc/passwd file. I'm running openbsd. Hmmm... as I finish writing this question it looks like this is rather off topic. Anyhows any ideas welcome. Thanks

Radius in demon mode problem.

2005-04-19 Thread Emil Wilmanski
Hi, When I start radius with freeradius -X everythin working ok. But when I run freeradius in demon mode (from Debian startup scripts) it can't authorize anybody. == radius.log == Tue Apr 19 10:38:48 2005 : Info: Using deprecated naslist file. Support for this will go away soon. Tue Apr 19

rlm_perl and perl modules

2005-04-19 Thread Emil Wilmanski
Hi, Can I use any perl modules in rlm_perl script? I try to use DBI and I get freeradius: relocation error: /usr/lib/perl5/auto/DBI/DBI.so: undefined symbol: Perl_Gthr_key_ptr I try to use Socket and I get freeradius: relocation error: /usr/lib/perl/5.8/auto/Socket/Socket.so: undefined

AW: verify server certificate XP supplicant ?

2005-04-19 Thread PhonTom
Hi! That's right! I had the same problems during my tests. But I didn't try to solve the problem! Maybe there is a bug in Windows XP?? Bw tom -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von [EMAIL PROTECTED] Gesendet: Dienstag, 19. April 2005

User Account Expiration

2005-04-19 Thread Jaco van Tonder
I am using freeradius 0.9.3 running with a Posgres sql db. If I add an Expiration attribute to the radcheck table - it only works for the date and not the time. For example it makes no difference is I enter 19 April 2005 or 19 April 2005 21:00:00 as the expiration value. The server still allows

Re: AW: verify server certificate XP supplicant ?

2005-04-19 Thread Jim Seymour
[Jeopardy-style follow-ups, mis-quoting and excess text corrected...] PhonTom [EMAIL PROTECTED] wrote: [mailto:[EMAIL PROTECTED] Im Auftrag von [EMAIL PROTECTED] Zitat von Riccardo Veraldi [EMAIL PROTECTED]: Hello, I am using EAP-TLS. Windows XP, Cisco 1200 AP, freeradius.

Stop Date and Time field

2005-04-19 Thread Abdul Lateef
Hello, I wated to put stop date and time in diffrent field of mySQL databse. For the example. the date should be StoDate_field and the time should be in StopTime_field. How i can add this quey in sql.cfg file? thank You __ Do you Yahoo!?

reached maximum clones 33 cannot grow

2005-04-19 Thread Emil Wilmanski
Problem like this: radius_xlat: Running registered xlat function of module perl for string 'getAuthTableName %u' reached maximum clones 33 cannot grow radius_xlat: 'SELECT id,UserName,Attribute,Value,op FROM WHERE Username = 'test2' ORDER BY id' rlm_sql (sql): Reserving sql socket id: 1

xlat LDAP woes

2005-04-19 Thread Jan-Piet Mens
I'm using FreeRadius 1.0.1 on Linux RHES3 and would like to return a dynamically constructed Framed-IP-Address. Unfortunately, I can't get xlat to work correctly for that. This works when in a user's LDAP entry: radiusReplyItem: Reply-Message += JP

Re: rlm_perl and perl modules

2005-04-19 Thread Emil Wilmanski
Dnia 19-04-2005, wto o godzinie 11:03 +0200, Emil Wilmanski napisa(a): Can I use any perl modules in rlm_perl script? I don't know what the problem is... noone of perl modules dos work... Can't load '/usr/local/lib/perl/5.8.4/auto/Data/Dumper/Dumper.so' for module Data::Dumper:

freeradius ntlm_auth

2005-04-19 Thread Sylvain Clerc
Hello, I'm using freeradius 1.0.2 in PEAP-mschapv2, All is ok when I authenticate an user who is in the users file but when I want to authenticate a user who is in an active directory database, I have this error : rad_recv: Access-Request packet from host 10.74.1.110:3072, id=0, length=211

sql_mysql problem on compiling freeradius1.0.2 on solaris sparcv9,plz help!

2005-04-19 Thread fan wang
Hi, today i tried to compile freeradius1.0.2 on solaris v9. I want to make mysql as the database server for freeradius. During the process of making freeradius, error occured as the following: ar cru rlm_sql_mysql.a sql_mysql.oar: cannot open sql_mysql.o No such file or directoryar: sql_mysql.o

bug in scripts/certs.sh?

2005-04-19 Thread Richard Arkner
I think there's a tiny bug in certs.sh. Line 21 is $(SSL)/bin/openssl gendh dh but the parentheses should either not be there or should be curly: ${SSL}/bin/openssl gendh dh Perhaps this is a shell peculiarity. I'm using FreeRadius 1.0.2 on WhiteBox Linux 2.4.21-20.0.1.EL.

Re: Freeradius-Users digest, Vol 1 #4534 - 14 msgs

2005-04-19 Thread Vicente Barrientos Valdivia
Hi all. freeradius can use two database mssql primary and mysql secondary Thanks you. -- Vicente Barrientos V. Tecnico en Telecomunicaciones L.@C. Sistemas S.A. Telf.(511) 422-4959 Email: [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Session resumption

2005-04-19 Thread Bilal Shahid
Does FreeRADIUS v1.0.1 support session resumption (fast reconnect during reauthentication) for TLS, TTLS and PEAP? Thanks, Bilal _ Don't just search. Find. Check out the new MSN Search! http://search.msn.com/ - List

SQL accounting and users on seperate servers

2005-04-19 Thread Greg Ulyatt
I'm trying to get a 2 server SQL setup going where all user data is kept on one system, and the accounting is on another. I have tried several things (including copyingrenaming sql.conf to sqlacct.conf then using them both... no joy!) Of course, I could do this with radrelay but that seems to

Unsubscribe

2005-04-19 Thread Stewart, Bill
Unsubscribe - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: SQL accounting and users on seperate servers

2005-04-19 Thread Kostas Kalevras
On Tue, 19 Apr 2005, Greg Ulyatt wrote: I'm trying to get a 2 server SQL setup going where all user data is kept on one system, and the accounting is on another. I have tried several things (including copyingrenaming sql.conf to sqlacct.conf then using them both... no joy!) Of course, I could

Re: Session resumption

2005-04-19 Thread Michael Griego
Not yet. --Mike --- Michael Griego Wireless LAN Project Manager The University of Texas at Dallas Bilal Shahid wrote: Does FreeRADIUS v1.0.1 support session resumption (fast reconnect during reauthentication) for TLS, TTLS and PEAP? Thanks, Bilal

RE: Radrelay error

2005-04-19 Thread David Jones
Thanks for the help! Once I created the file and just add the secret my command executed and is now populating my secondary accounting server with data. The key for me was finding out that I need the file with the secret in it instead of trying to pull it from a clients.conf file on either server.

RE: Radrelay error

2005-04-19 Thread Dustin Doris
Thanks for the help! Once I created the file and just add the secret my command executed and is now populating my secondary accounting server with data. The key for me was finding out that I need the file with the secret in it instead of trying to pull it from a clients.conf file on either

syslog and freeradius

2005-04-19 Thread Norbert Wegener
I want to collect messages from different machines on a single server . Is it possible to forward freeradius' (1.0.2) logging to another machine? man radiusd says, that -l with the special value syslog sends the log information with syslog and that this option is deprecated. See log_dir in

Re: SQL accounting and users on seperate servers

2005-04-19 Thread Greg Ulyatt
aha! works like a charm. I was mis-reading the docs on that, but I now see how it works. Cheers! Kostas Kalevras wrote: On Tue, 19 Apr 2005, Greg Ulyatt wrote: I'm trying to get a 2 server SQL setup going where all user data is kept on one system, and the accounting is on another. I have tried

Freeradius can use 2 databases disctints?

2005-04-19 Thread vicente barrientos
Hi all. Freeradius can use two database mssql primary on other pc with w2k server and mysql secondary on itself pc? Thanks you. Las mejores tiendas, los precios mas bajos, entregas en todo el mundo, YupiMSN Compras: Haz clic aquí... - List info/subscribe/unsubscribe? See

Re: ip-pool

2005-04-19 Thread Alan DeKok
Tom Fritz [EMAIL PROTECTED] wrote: The radius server is sending the correct Framed-IP-Address with the Access-Accept message, but it isn't assigned to the connection. Then the NAS is not doing what it's told. Either the NAS is buggy, or you didn't assign Framed-Protocol and Service-Type,

Re: xlat LDAP woes

2005-04-19 Thread Alan DeKok
Jan-Piet Mens [EMAIL PROTECTED] wrote: and correctly returns Reply-Message = JP 1.1.1.1 to the client, but this doesn't work: radiusFramedIPAddress: %{ldap1:ldap:///dc=retail-sc,dc=com?cn?sub?uid=su00-%n}; The LDAP attribute is supposed to be an IP address, not a string that

Re: freeradius ntlm_auth

2005-04-19 Thread Alan DeKok
Sylvain Clerc [EMAIL PROTECTED] wrote: //The problem is here, if the user is in the users file, the following line is Success but here... rlm_eap_peap: Had sent TLV failure, rejecting. Please read ALL of the debugging output. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: bug in scripts/certs.sh?

2005-04-19 Thread Alan DeKok
Richard Arkner [EMAIL PROTECTED] wrote: but the parentheses should either not be there or should be curly: ${SSL}/bin/openssl gendh dh Fixed, thanks. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: syslog and freeradius

2005-04-19 Thread Alan DeKok
Norbert Wegener [EMAIL PROTECTED] wrote: I want to collect messages from different machines on a single server . Is it possible to forward freeradius' (1.0.2) logging to another machine? Not really. It doesn't work in 1.0.2. It *does* work in the CVS head. Alan DeKok. - List

Re: rlm_perl and perl modules

2005-04-19 Thread Thor Spruyt
Emil Wilmanski wrote: Can I use any perl modules in rlm_perl script? I try to use DBI and I get I don't know about any, must normally they *should* work. For example, I use the following: use strict; use DBI; Write a normal perl script that uses the module's functions and see if that works.

(no subject)

2005-04-19 Thread Andre Herkenrath
Hi, I have a very strange problem. I authenticate a user agains a Novell 6 Server, which is not the problem. But I need some Attributes from the authentication brought back to the NAS I put these in the users file and it worked with another server: Users (complete) - DEFAULT

Re: rlm_perl and perl modules

2005-04-19 Thread Jakub Wartak
On Tuesday 19 April 2005 11:03, Emil Wilmanski wrote: Hi, Can I use any perl modules in rlm_perl script? Yes, you can. I try to use DBI and I get freeradius: relocation error: /usr/lib/perl5/auto/DBI/DBI.so: undefined symbol: Perl_Gthr_key_ptr I try to use Socket and I get freeradius:

radreply works even with access-reject

2005-04-19 Thread Lucas Aimaretto
Hi all, I have the following situation. The user XXX exists in the radcheck table. He has its password and everytingh works ok. Upon an access-request, if user/password provided are ok, I get an access-accept response with a reply containing the attribute assigned to the XXX user in the radreply

RV: radreply works even with access-reject

2005-04-19 Thread Lucas Aimaretto
I have the following situation. The user XXX exists in the radcheck table. He has its password and everytingh works ok. Upon an access-request, if user/password provided are ok, I get an access-accept response with a reply containing the attribute assigned to the XXX user in the radreply

Re: rlm_perl and perl modules

2005-04-19 Thread Emil Wilmanski
I don't know about any, must normally they *should* work. For example, I use the following: use strict; use DBI; Hmmm... I need DBI to work :) Write a normal perl script that uses the module's functions and see if that works. All of normal scripts work perfect with any module... Only

Re: how to use exec and expr

2005-04-19 Thread Ming-Ching Tiew
From: Ming-Ching Tiew [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Sent: Tuesday, April 19, 2005 12:53 PM Subject: how to use exec and expr I have exec and expr included in the instantiate{}. Then in mssql.conf, somewhere in the middle I do this :- Acct-Authentic =

Re: redirect

2005-04-19 Thread Dan Bethe
--- Kevin Hoffer [EMAIL PROTECTED] wrote: Question about re-directing? I have a friend who uses radius who wants pop-up a message to everyone who signs in through his radio server. Hi Kevin. You're looking for a captive portal. http://www.linuxjournal.com/article/6887

Re: (no subject)

2005-04-19 Thread Sayantan Bhowmick
HI Can you run the server in debug mode and post the messages that you get. -Sayantan.[EMAIL PROTECTED] 04/19/05 5:52 pm HiI have a very strange problem.I authenticate a user agains a Novell 6 Server which is not theproblem.But I need some

Re: xlat LDAP woes

2005-04-19 Thread Jan-Piet Mens
On Tue Apr 19 2005 at 18:46:49 CEST, Alan DeKok wrote: Jan-Piet Mens [EMAIL PROTECTED] wrote: and correctly returns Reply-Message = JP 1.1.1.1 to the client, but this doesn't work: radiusFramedIPAddress: %{ldap1:ldap:///dc=retail-sc,dc=com?cn?sub?uid=su00-%n}; The LDAP