Re: Groups Problem

2008-05-25 Thread radius
Hi, no, I didn't have same attributes... After some trials I have made it... What was the reason - no idea... :( Anyway, is it possible to set default Fall-Through for Radius with mysql? I tried adding some things in user.conf, but it didn't work. Thx, Best regards, Comec On Sat, 24 May

EAP-TLS deny access?

2008-05-25 Thread uhel
Hi, how can i deny access to a user (a certificate)? Is a CRL (with the CA_path and c_rehash stuff) the only possibility to deny access or is it possible to have a *whitelist* (like the CA_path and c_rehash stuff but as a whitelist) with certs that are allowed? I'm using Freeradius 1.1.7 with

Re: Triggering of billing engine post-acc

2008-05-25 Thread Alan DeKok
Pete Kay wrote: In the sites-enabled/default file, there is a post-auth section that I can put exec on, but what if I want to run the script only if there is a new recording being added during accounting, something like post-acc, is it possible? You can run it during the accounting

Re: EAP-TLS deny access?

2008-05-25 Thread Alan DeKok
[EMAIL PROTECTED] wrote: how can i deny access to a user (a certificate)? Set Auth-Type := Reject Is a CRL (with the CA_path and c_rehash stuff) the only possibility to deny access or is it possible to have a *whitelist* (like the CA_path and c_rehash stuff but as a whitelist) with certs

Re: undefined symbol: sql_get_socket

2008-05-25 Thread Alan DeKok
Giovanni Lovato wrote: I compiled deb packages from 2.0.4 sources. I would use rlm_sqlippool but I get this message: symbol lookup error: /usr/lib/freeradius/rlm_sqlippool-2.0.4.so: undefined symbol: sql_get_socket How can I solve that? Link the server statically: $ ./configure

Re: radius x509 authentication + LDAP ? [SEC=UNCLASSIFIED]

2008-05-25 Thread Alan DeKok
Riccardo Veraldi wrote: Not all the people having a certificate should authenticate on my WiFi infrastructure. These certificates are for general purpose, so also for EAP-TLS, Then your PKI system is wrong. You should NOT issue certificates for multiple purposes. You should issue RADIUS

Re: radius x509 authentication + LDAP ? [SEC=UNCLASSIFIED]

2008-05-25 Thread Riccardo Veraldi
I will try to put all the people I do not want to authenticate to a specific LDAP group, anyway I do not know how to do it using the users file to reject a specific LDAP group thanks Riccardo Alan DeKok wrote: Riccardo Veraldi wrote: Not all the people having a certificate should

Re: openLDAP branches

2008-05-25 Thread Jian Wang
I have the same question. Anyone can help? On Thu, May 22, 2008 at 10:36 PM, Vittore Zen [EMAIL PROTECTED] wrote: Hi, I have a openLDAP server with multiply branches: dc=domA -a list of users dc=domB -a list of users dc=domC -a list of users now I want to AAA from freeradius using this

Client Certificate!

2008-05-25 Thread Kwok Sianbin
Hi Alan, As you previous email mention, I need to run the server script. Do you mean the script in the README file that come with Freeradius (/raddb/scripts). # make server.pem # make server.csr I just started to use the Linux hence I am not quite familiar with it. - Original Message

RE: Triggering of billing engine post-acc [SEC=UNCLASSIFIED]

2008-05-25 Thread Ranner, Frank MR
UNCLASSIFIED _ From: [EMAIL PROTECTED] g [mailto:[EMAIL PROTECTED] adius.org] On Behalf Of Pete Kay Sent: Sunday, 25 May 2008 01:04 To: freeradius-users@lists.freeradius.org Subject: Triggering of billing engine post-acc

Re: Groups Problem

2008-05-25 Thread sushma
hey, even i m working with FreeRAdius 2.0.0 with mysql. i have created one clint. can u please tell how to add an user and how to store in msql. On Sat, 2008-05-24 at 08:55 -0700, [EMAIL PROTECTED] wrote: Hey, one question: I am working on FreeRadius 2.0.4 with mysql I have following

need info on EAP-SIM

2008-05-25 Thread Kalyani Garigipati (kagarigi)
Hi , I am using Free Radius for EAP-SIM authentication. Could someone please let me know the minimum configuration changes that might be needed in users, radiusd and eap.conf file. I have added the following lines in users, but I am getting errors as follows # # # # Last default: shell