Re: strip domain

2007-08-14 Thread Ashraf Al-Basti
Dear All, what i did is to add the following in the radcheck and in the authorize section to add sql and remove the suffix; because if i leave the suffix in the authorize section it will do the proxy even it didnt match the query in the sql. so i remove the suffix and so cant do stripping for

Re: Authenticate users from 3 realms in one MySQL database

2007-08-14 Thread Scott Lambert
On Mon, Aug 13, 2007 at 11:48:06PM -0500, Scott Lambert wrote: I am attempting to build a setup which authenticates users from 3 realms in one MySQL database. Some of my users, actually a large proportion of them, are currently not using their realm to authenticate. I am about to merge the

Radiusd.conf dictionary troubleshooting

2007-08-14 Thread Dan Jones
Hi all and thanks ahead of time for any responders. The scenario: I have been given the task to install a radius server on a Linux platform. After doing some research, I went with Fedora Core 6 and FreeRadius-1.1.7. It's currently running on my HP Laptop for configuring and testing. As for my

Re: EAP-TLS certificate based authentication in linux

2007-08-14 Thread Phil Mayers
On Tue, 2007-08-14 at 10:11 +0530, Anoop wrote: Hi I have certificate based EAP_TLS authentication working with windows xp clients.Does the same set up works for linux also.F Yes. Consult your supplicant documentation for info how to set it up - List info/subscribe/unsubscribe? See

Re: Radiusd.conf dictionary troubleshooting

2007-08-14 Thread Phil Mayers
On Tue, 2007-08-14 at 01:00 -0700, Dan Jones wrote: Hi all and thanks ahead of time for any responders. The scenario: I have been given the task to install a radius server on a Linux platform. After doing some research, I went with Fedora Core 6 and FreeRadius-1.1.7 . It's currently

RE: Configuration issue - unknown client

2007-08-14 Thread Jeff Crowe
-Original Message- From: [EMAIL PROTECTED] org [mailto:[EMAIL PROTECTED] eradius.org] On Behalf Of Dan O'Reilly Sent: August 13, 2007 6:58 PM To: FreeRadius users mailing list Cc: FreeRadius users mailing list Subject: Re: Configuration issue - unknown client My

RE: OR Problem in authorize_check_query

2007-08-14 Thread E. abdelghani
hello,i have a problem in this sql-statement (in mssql.conf): authorize_check_query = "SELECT id,UserName,Attribute,Value,op,right FROM ${authcheck_table} WHERE ((Username = '%{SQL-User-Name}') AND (right = 1) AND (CallingID = '%{Calling-Station-Id}')) OR ('%{Called-Station-Id}' IN (SELECT

RE: Configuration issue - unknown client

2007-08-14 Thread Dan O'Reilly
D'OH! massive forehead slap You're right, I apparently have a reading disability of some sort. That made it work, thanks! At 06:39 AM 8/14/2007, Jeff Crowe wrote: -Original Message- From: [EMAIL PROTECTED] org [mailto:[EMAIL PROTECTED] eradius.org] On Behalf Of Dan

Re : Help Using PEAP with Unix Password

2007-08-14 Thread Eshun Benjamin
use smbpasswd and mschap == Benjamin K. Eshun - Message d'origine De : Alan DeKok [EMAIL PROTECTED] À : FreeRadius users mailing list freeradius-users@lists.freeradius.org Envoyé le : Dimanche, 12 Août 2007, 15h11mn 02s Objet : Re: Help

Re: Radius is running away with the CPU

2007-08-14 Thread Alan DeKok
David wrote: I have been using freeradius for several years but in the last few months have seen a problem with the cpu usage. TOP almost always shows radius with 100% CPU much of the time it is at 300%. The load average runs up to 32 at times as well. This corresponds with the max_servers.

Re: EAP-TLS Certificates

2007-08-14 Thread Alan DeKok
Peter Nixon wrote: I think for 2.0 would should make an etc/raddb/experimental/xxx.conf setup with a main file somewhere which includes each one, but where each include line is commented out by default.. Sounds good to me. Alan DeKok. - List info/subscribe/unsubscribe? See

RE: Radius is running away with the CPU

2007-08-14 Thread David
I am not intentionally/manually HUP'ing the server. The problem happens pretty much as soon as I start the server. David -Original Message- From: [EMAIL PROTECTED] s.org [mailto:[EMAIL PROTECTED] reeradius.org] On Behalf Of Alan DeKok Sent: Tuesday, August 14, 2007 10:50 AM To:

Re: Radius is running away with the CPU

2007-08-14 Thread Alan DeKok
David wrote: I am not intentionally/manually HUP'ing the server. The problem happens pretty much as soon as I start the server. Well, something changed. It worked before, didn't it? Find out what changed. Run the server in debugging mode. Use 'strace' to see what it's doing. Alan

Re: Authenticate users from 3 realms in one MySQL database

2007-08-14 Thread Scott Lambert
On Tue, Aug 14, 2007 at 01:24:15AM -0500, Scott Lambert wrote: On Mon, Aug 13, 2007 at 11:48:06PM -0500, Scott Lambert wrote: The failure happens in rlm_pap when the user does not specify a realm. I don't see the cause of the failure in the debug output. I'm probably not interpreting the

dynamically corrupting the radius databse

2007-08-14 Thread ASHWIN KUMAR
Hi, Can you dynamically alter or corrupt the radius database at run time? I want this for testing one of the switches .Moreover is it possible to have cistron and freeradius running in the same system? Thanks - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Compile error - rlm_sqlippool

2007-08-14 Thread Dominique Demore
Hi Everyone. I'm in the process of migrating our older installation to 1.1.7. During the compile, I am receiving the following error during make /home/demored/free/freeradius-1.1.7/libtool --mode=compile gcc -g -O2 -I/home/demored/free/freeradius-1.1.7/src/include

RE: Radius is running away with the CPU

2007-08-14 Thread David
I found that when running radius -x to the console I see lines like the following WARNING: Unresponsive child (id 3074419616) for request 8978 I don't know what they mean. I see lines like Dropping conflicting packet from client Bogus:2377 - ID: 195 due to unfinished request 8978 above the

Telnet Connection Refused

2007-08-14 Thread Sofia Silva
for request 6 radius_xlat: '/var/log/radius/radacct/10.220.5.32/auth-detail-20070814' rlm_detail: /var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands to /var/log/radius/radacct/10.220.5.32/auth-detail-20070814 modcall[authorize]: module auth_log returns ok for request 6

Multiple (different) LDAP servers and authorisation

2007-08-14 Thread Stewart James
Hi all, I have been roped in to look over an issue we have with migrating from Novell to AD. What we would like to do while we in the transitional phase is check both the AD and Novell LDAP services for authorisation and authentication (usernames are completely different so no need to be

Re: Multiple (different) LDAP servers and authorisation

2007-08-14 Thread Alan DeKok
Stewart James wrote: I have been roped in to look over an issue we have with migrating from Novell to AD. Repeat after me: AD is not an LDAP server. It's not. It fakes it pretty well, but it's not. As I stated earlier authentication fall through works like a treat (if in the users file

what do rlm mean ?

2007-08-14 Thread 郭红华
Can you tell me what rlm mean ? And where can I find informaion about it ? Thank you !- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

building RPM from source

2007-08-14 Thread Fred Zinsli
Hi Everyone I am rather new to this, so I hope I am not asking something obvious. I am attempting to build an RPM from source on my FC5 box. The reason is that I am wanting to use hotcakes (a wifi administration app) and it requires 1.1.4 minimum and the latest stable for FC5 is 1.0.5 What I

RE: Radius is running away with the CPU

2007-08-14 Thread David
I have verified that the database can run all of the queries quickly. I was having trouble running radiusd -X (it was slow ) but radiusd -x was better but the thread count and load average would run up. At you suggest I ran in debugging mode -X again and this time notice that it was pausing for a

RE: Radius is running away with the CPU

2007-08-14 Thread David
Oops I wrote that a little out of order. It should have gone like this: I have verified that the database can run all of the queries quickly. I was having trouble running radiusd -X (it was slow ) but radiusd -x was better but the thread count and load average would run up. At you suggest I ran

RE: Multiple (different) LDAP servers and authorisation

2007-08-14 Thread Stewart James
Hi Alan, Thanks for offering some help, no need to point out that in reality AD != True LDAP. Well and truly aware of it. Lets step through what we need. At the moment we have a large number of people that get their authentication/authorisation through the Radius server (VPN Service). There

Re: sql.conf file

2007-08-14 Thread zahra bahar
I use fedora core6. when I active sql for accunting ,radiusd -x gives error with sql.conf.there isn't rlm_sql_mysql.so. when I searched find out that I should install freeradius_mysql package.but installing it wants alot of system files. what is wrong? Mordor Networks [EMAIL PROTECTED] wrote:

Re: sql.conf file

2007-08-14 Thread Fred Zinsli
Nothing is wrong. If you are installing freeradius from RPM on Fedora and you want to use an SQL backend then you need both freeradius and freeradius-mysql (complete with dependencies). Regards Fred -Original Message- From: zahra bahar [EMAIL PROTECTED] To: FreeRadius users mailing

RE: Multiple (different) LDAP servers and authorisation

2007-08-14 Thread Stewart James
Further to my previous email I have gained a better understanding for the situation, as I said in my first post - I have been roped in, so this is my introduction to Radius, specifically freeradius - nothing like being thrown in the deep end to learn a new service. :) What I have realised is

Re: sql.conf file

2007-08-14 Thread Peter Nixon
On Wed 15 Aug 2007, zahra bahar wrote: I use fedora core6. when I active sql for accunting ,radiusd -x gives error with sql.conf.there isn't rlm_sql_mysql.so. when I searched find out that I should install freeradius_mysql package.but installing it wants alot of system files. what is wrong?

Re: Radius is running away with the CPU

2007-08-14 Thread Peter Nixon
On Wed 15 Aug 2007, David wrote: I have verified that the database can run all of the queries quickly. I was having trouble running radiusd -X (it was slow ) but radiusd -x was better but the thread count and load average would run up. At you suggest I ran in debugging mode -X again and this