unlang help please

2010-02-17 Thread Leighton Man
Tunnel-Type:0 = VLAN Tunnel-Medium-Type:0 = IEEE-802 Tunnel-Private-Group-Id:0 = 13 +- entering group authorize {...} ++[preprocess] returns ok [auth_log] expand: /usr/local/var/log/radius/radacct/auth-detail-%Y%m%d - /usr/local/var/log/radius/radacct/auth-detail-20100217 [auth_log

Re: unlang help please

2010-02-17 Thread Alan DeKok
Leighton Man wrote: I have unlang in authorise section of sites-enabled/default, after pap: if (request:Tunnel-Private-Group-Id:0 == 13){ Use: if (request:Tunnel-Private-Group-Id == 13) { i.e. without the :0 Alan DeKok. - List info/subscribe/unsubscribe? See

RE: unlang help please

2010-02-17 Thread Leighton Man
Use: if (request:Tunnel-Private-Group-Id == 13) { i.e. without the :0 Many thanks Alan Leighton --- This transmission is confidential and may be legally privileged. If you receive it in error, please notify us immediately by e-mail and remove it from your system. If the

Re: Matching Airespace-Wlan-Id in users files or radgroupcheck database

2010-02-17 Thread Adam Wien
Here's my database setup. mysql select * from radcheck where username='a...@cpanel.net'; +--+-+++--+ | id | username| attribute | op | value| +--+-+++--+ | 1072 |

Re: Matching Airespace-Wlan-Id in users files or radgroupcheck database

2010-02-17 Thread Alan DeKok
Adam Wien wrote: Here's my database setup. Please read doc/rlm_sql. mysql select * from radcheck where username='a...@cpanel.net'; +--+-+++--+ | id | username| attribute | op | value|

Re: Matching Airespace-Wlan-Id in users files or radgroupcheck database

2010-02-17 Thread Adam Wien
On Feb 17, 2010, at 10:54 AM, Alan DeKok wrote: Adam Wien wrote: Here's my database setup. Please read doc/rlm_sql. mysql select * from radcheck where username='a...@cpanel.net'; +--+-+++--+ | id | username| attribute

How to configure EAP PEAPv0/EAP-MSCHAPv2 in freeradius 2.10 Ubuntu linux 9.04

2010-02-17 Thread Dilip Patel
I am using FreeRADIUS Version 2.1.0 in Ubuntu linux 9.04. How do I configure Free Radius to use EAP PEAPv0/EAP-MSCHAPv2? I have updated the default configuration in eap.conf to the following: eap { # Invoke the default supported EAP type when #

Re: How to configure EAP PEAPv0/EAP-MSCHAPv2 in freeradius 2.10 Ubuntu linux 9.04

2010-02-17 Thread Alan DeKok
Dilip Patel wrote: I am using FreeRADIUS Version 2.1.0 in Ubuntu linux 9.04. Don't. Install 2.1.8. See: http://wiki.freeradius.org/Build#Building_Debian_packages How do I configure Free Radius to use EAP PEAPv0/EAP-MSCHAPv2? Install 2.1.8. Add a user/password in the users file. Then,

Is Centralized SSH Public Key Authentication Possible?

2010-02-17 Thread John L. Singleton
Hi All, I am trying to set up a centralized SSH authentication server that allows authentication via public keys. I can't find anything on the web about if this is possible with FR. Is it? Basically all I need is for FR to allow authentication off of a respective users's .ssh/.authorized_keys

Re: Matching Airespace-Wlan-Id in users files or radgroupcheck database

2010-02-17 Thread Fajar A. Nugraha
On Thu, Feb 18, 2010 at 12:26 AM, Adam Wien adam.w...@gmail.com wrote: I guess that's my real question. What database does that belong in? try radcheck first. Make sure it works on per-user basis. I've tried adding it to 'radgroupreply' and also 'radgroupcheck' with a higher ID(although the

Re: Matching Airespace-Wlan-Id in users files or radgroupcheck database

2010-02-17 Thread Adam Wien
On Feb 17, 2010, at 3:55 PM, Fajar A. Nugraha wrote: On Thu, Feb 18, 2010 at 12:26 AM, Adam Wien adam.w...@gmail.com wrote: I guess that's my real question. What database does that belong in? try radcheck first. Make sure it works on per-user basis. I've tried adding it to

Re: How to configure EAP PEAPv0/EAP-MSCHAPv2 in freeradius 2.10,

2010-02-17 Thread Dilip Patel
Thanks Alan for your suggestion. I tried to install freeradius2.1.8, but ran into following error: patel...@pateldil-desktop:~/freeradius-server-2.1.8[17:00:07]$ sudo dpkg -i ../freeradius_2.1.8+git_amd64.deb Selecting previously deselected package freeradius. (Reading database ... 179982

Re: Is Centralized SSH Public Key Authentication Possible?

2010-02-17 Thread Emmett Culley
We are using tunneling via SSH (with authorized keys only) to connect radius servers across the Internet. We do this to keep from sending user names and passwords between the sites and the central radius server as clear text. Each radius server running on remote site connects via the SSH

Re: Matching Airespace-Wlan-Id in users files or radgroupcheck database

2010-02-17 Thread Alan DeKok
Adam Wien wrote: I have this so far in my users file and it's working. adamCleartext-Password := testing radcheck Airespace-Wlan-Id = 8, Airespace-Interface-Name = SecWifiTesting0, Tunnel-Type = VLAN,

Re: How to configure EAP PEAPv0/EAP-MSCHAPv2 in freeradius 2.10,

2010-02-17 Thread Fajar A. Nugraha
On Thu, Feb 18, 2010 at 5:04 AM, Dilip Patel dilip.pa...@hp.com wrote: patel...@pateldil-desktop:~/freeradius-server-2.1.8[17:00:07]$ sudo dpkg -i ../freeradius_2.1.8+git_amd64.deb dpkg: dependency problems prevent configuration of freeradius:  freeradius depends on libfreeradius2 (=

Re: Is Centralized SSH Public Key Authentication Possible?

2010-02-17 Thread Nick Owen
On Wed, Feb 17, 2010 at 3:24 PM, John L. Singleton jsing...@gmail.comwrote: Hi All, I am trying to set up a centralized SSH authentication server that allows authentication via public keys. I can't find anything on the web about if this is possible with FR. Is it? Basically all I need is for

How long it take to auth in 802.1X/WPA-enterprise?

2010-02-17 Thread JaeJong Baek
How long it take to auth in 802.1X/WPA-enterprise? I set up 802.1X/WPA-Enterprise network simply as follows. Free radius 2.1.8 server ubunt on VMware 10.10.20.14 | |EAP-TLS(wired. 802.3) | AP Belkin 54g WPA-Enterprise Tkip : :EAP-TLS(wireless 802.11) : Client : Laptop

Re: Is Centralized SSH Public Key Authentication Possible?

2010-02-17 Thread Peter Lambrechtsen
On Thu, Feb 18, 2010 at 11:47 AM, Nick Owen owen.n...@gmail.com wrote: On Wed, Feb 17, 2010 at 3:24 PM, John L. Singleton jsing...@gmail.comwrote: Hi All, I am trying to set up a centralized SSH authentication server that allows authentication via public keys. I can't find anything on the