Re: Starent NAS dictionary

2010-07-02 Thread JOE
Hi Alan, Sorry, I saw that freeradius has a default dictionary for Starent equipment. I replaced the file without realizing (overwrote the files). I'll use the default dictionary. Regards On Thu, Jul 1, 2010 at 6:59 PM, Alan DeKok al...@deployingradius.com wrote: JOE wrote: Hi all

Re: Starent NAS dictionary

2010-07-02 Thread JOE
Hi, my apologies, I mean I did not saw that freeradius has a default dictionary for Starent equipment. I replaced the file without realizing (overwrote the files). I'll use the default dictionary. On Fri, Jul 2, 2010 at 8:21 AM, JOE joe...@gmail.com wrote: Hi Alan, Sorry, I saw that

Re: ntlm_auth fails for none domain

2010-07-02 Thread Alan DeKok
John wrote: Hi, It is the whole debug info. I think the problem is we could not get the default domain name xjtu. Because the username does not include the domain. Log in with h...@xjtu.cn, and it will work. Alan DeKok. - List info/subscribe/unsubscribe? See

freeradius2 with EAP-TLS and LDAP authorization ?

2010-07-02 Thread Riccardo Veraldi
Hello, is it possible in some way to use EAP-TLS X509 authentication together with LDAP authorization in freeradius2 ? Actually freeradius2 allows EAP-TLS authentication, but if I wanted to extract the emailAddress or CN field from the X509 certificate and authorize it against my LDAP tree

Re: ntlm_auth fails for none domain

2010-07-02 Thread Alan Buxey
Hi, Hi, It is the whole debug info. I think the problem is we could not get the default domain name xjtu. thats not the whole debug either...never mind. from what I can see. Listening on authentication address * port 1812 Listening on command file

warnings under cygwin

2010-07-02 Thread tangfu
Hi,guys.I try to complie freeradius 2.19 under cygwin this afternoon,but i get some warning when i execute ./configure ... ./configure --without-snmp --disable-shared --with-system-libtool --without-rlm_krb5 --without-rlm_pam --without-rlm_sql_oracle --without-rlm_perl

Re: warnings under cygwin

2010-07-02 Thread Alan DeKok
tangfu wrote: Hi,guys.I try to complie freeradius 2.19 under cygwin this afternoon,but i get some warning when i execute ./configure ... Do you understand what the purpose of configure is? I don't have installed net-snmp,but i add --without-snmp to configure.I am confused why these

Re: warnings under cygwin

2010-07-02 Thread Alan Buxey
Hi, I don't have installed net-snmp,but i add --without-snmp to configure.I am confused why these warnings about snmp occur. Additionally,iodbc and unixodbc seem merely to support non-windows platform.I always don't get build succeeded. Much to my puzzlement,libmysqlclient_r.a and

My question again (was: Netmask HOWTO)

2010-07-02 Thread loki
- version in /etc). I tried through groupreply but it didn't work. Regards __ Information from ESET Mail Security, version of virus signature database 5245 (20100702) __ The message was checked by ESET Mail Security. http://www.eset.com - List info/subscribe/unsubscribe

Freeradius + AD + Cisco authetication

2010-07-02 Thread Jevos, Peter
Hello friends I was reading few tutorials regarding the Cisco authetication against Freeradius and Windows AD. Actually I'm not really clever, because main tutorial on the main pages is connected with the older version , and there are more version of the Freradius 2.0, a bit different:

Authentication delegation

2010-07-02 Thread Maria Sanchez
In the operational environment there is a RADIUS server that is already configured to handle authentication and has all the corresponding accounts. I would like to make use of the Authorization part of RADIUS and install my own server for this purpose. However I need to configure it to pass

Re: Freeradius + AD + Cisco authetication

2010-07-02 Thread Fajar A. Nugraha
On Fri, Jul 2, 2010 at 6:43 PM, Jevos, Peter peter.je...@oriflame.com wrote: Actually  I’m not really clever, because main tutorial on the main pages is connected with the older version , and there are more version of the Freradius 2.0, a bit different:

RE: Freeradius + AD + Cisco authetication

2010-07-02 Thread Jevos, Peter
Hi thank you for your email. So as I said before , I have working ntlm_auth in the form of: Linux#/usr/bin/ntlm_auth --request-nt-key --domain=MYDOMAIN --username=MYNAME --require-membership-of='DOMAIN+DOMAIN_GROUP' That works from the command line.It returns OK status So now, I have about 60

Re: My question again (was: Netmask HOWTO)

2010-07-02 Thread Phil Mayers
On 02/07/10 12:26, loki wrote: Hello all. I need some kind of solution very urgent. My question was - is it possible to set Framed-IP-Netmask, together with IPs through sqlippool, somehow by default, via groupreply or something, or to change sqlippool somewhow to achive this. Or is this only

RE: Failed disabling Core Dumps on RHEL - SELinux Updates

2010-07-02 Thread Ben Wiechman
Bugzilla submitted: Bug 610812 https://bugzilla.redhat.com/show_bug.cgi?id=610812 Ben -Original Message- From: freeradius-users- bounces+wiechman.lists=gmail@lists.freeradius.org [mailto:freeradius-users- bounces+wiechman.lists=gmail@lists.freeradius.org] On Behalf Of John

Re: My question again (was: Netmask HOWTO)

2010-07-02 Thread loki
. Sorry that I didn't specify that. THX __ Information from ESET Mail Security, version of virus signature database 5245 (20100702) __ The message was checked by ESET Mail Security. http://www.eset.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: My question again

2010-07-02 Thread Alan DeKok
loki wrote: Unfortunatly it's a production system already in heavy use so I can't use -X. Yes, you can. $ radiusd -i 127.0.0.1 -p 2000 Will start the server on 127.0.0.1, port 2000, using your current configuration. This is documented. See man radiusd. Alan DeKok. - List

RE: warnings under cygwin

2010-07-02 Thread tangfu
Date: Fri, 2 Jul 2010 12:29:34 +0200 From: al...@deployingradius.com To: freeradius-users@lists.freeradius.org Subject: Re: warnings under cygwin tangfu wrote: Hi,guys.I try to complie freeradius 2.19 under cygwin this afternoon,but i get some warning when i execute ./configure ...

mschap/peap question

2010-07-02 Thread Wegener, Norbert
With 2.1.8 and the configuration from http://deployingradius.com/scripts/eapol_test/peap-mschapv2.conf I want to test a radius configuration. The linux server running radius is member of the AD domain, mschap succeeds but finally the authentication fails. freeradius sends Challenges to which

Re: Freeradius + AD + Cisco authetication

2010-07-02 Thread Alan DeKok
Jevos, Peter wrote: How should look like the ntlm_auth file ? How should look like mschap module ? How should look like parameter --require-membership-of in these files ? How should look like users file ? These answers I was not able to find in any documentation Read the URLs from the

Re: Freeradius 2.1.8+Windows AD+MS-CHAP with ntlm_auth ( [pap] WARNING! No known good password found for the user. Authentication may fail because of this)

2010-07-02 Thread Alan DeKok
Cesar Ortega wrote: I managed to install Freeradius with OpenSSL under Debian Lenny and it did work like a charm for a while. However, after I did the same process of installation in another virtualbox machine, it has not worked anymore. The console log report the following error: [pap]

Re: warnings under cygwin

2010-07-02 Thread Alan DeKok
tangfu wrote: As you said,some problem has occured in src\rlm_sql\drivers\rlm_sql_mysql\config.log /usr/lib/mysql/libmysqlclient_r.a(my_compress.o):my_compress.c:(.text+0x66): undefined reference to `_compress' /usr/lib/libmysqlclient_r.a(my_compress.o):my_compress.c:(.text+0x187):

Re: mschap/peap question

2010-07-02 Thread Alan DeKok
Wegener, Norbert wrote: With 2.1.8 and the configuration from http://deployingradius.com/scripts/eapol_test/peap-mschapv2.conf I want to test a radius configuration. The linux server running radius is member of the AD domain, mschap succeeds but finally the authentication fails. freeradius

Freeradius 2.1.8+Windows AD+MS-CHAP with ntlm_auth ( [pap] WARNING! No known good password found for the user

2010-07-02 Thread Cesar Ortega
Hi Alan, I try using the default user file and the other one that works on the other server but I could not make it. BTW, the working users file is the same, but include DEFAULT Auth-Type := ntlm_auth at the beginning. However, the Freeradius log said: Message: 5 Date: Fri, 02 Jul

FW: Freeradius 2.1.8+Windows AD+MS-CHAP with ntlm_auth ( [pap] WARNING! No known good password found for the user

2010-07-02 Thread Cesar Ortega
Hi Alan, I tried using the default users file and the other one that works on the other server but I could not make it. BTW, the working users file is the same, but include DEFAULT Auth-Type := ntlm_auth at the beginning. However, the Freeradius log said: /etc/freeradius/users[3]:

Re: My question again (was: Netmask HOWTO)

2010-07-02 Thread Phil Mayers
On 02/07/10 15:18, loki wrote: At 15:23 2.7.2010, you wrote: On 02/07/10 12:26, loki wrote: Hello all. I need some kind of solution very urgent. My question was - is it possible to set Framed-IP-Netmask, together with IPs through sqlippool, somehow by default, via groupreply or something, or

RE: warnings under cygwin

2010-07-02 Thread tangfu
Date: Fri, 2 Jul 2010 17:21:27 +0200 From: al...@deployingradius.com To: freeradius-users@lists.freeradius.org Subject: Re: warnings under cygwin tangfu wrote: As you said,some problem has occured in src\rlm_sql\drivers\rlm_sql_mysql\config.log

Re: FW: Freeradius 2.1.8+Windows AD+MS-CHAP with ntlm_auth ( [pap] WARNING! No known good password found for the user

2010-07-02 Thread Alan DeKok
Cesar Ortega wrote: Hi Alan, I tried using the default users file and the other one that works on the other server but I could not make it. BTW, the working users file is the same, but include DEFAULT Auth-Type := ntlm_auth at the beginning. However, the Freeradius log said:

AW: mschap/peap question

2010-07-02 Thread Wegener, Norbert
Using the users file it works. So samba can be blamed even in the current version 3.4.7 :-( With best regards, Norbert Wegener Siemens AG Siemens IT Solutions and Services SIS GO NW PSU SDC ASINS Bruchstraße 5 45883 Gelsenkirchen, Germany Tel.: +49 (209) 94565716 Fax: +49 (201) 8165581284

Re: AW: mschap/peap question

2010-07-02 Thread Alan DeKok
Wegener, Norbert wrote: Using the users file it works. So samba can be blamed even in the current version 3.4.7 :-( Sometimes I hate being right. Given that MS has billions to throw at the problem and the Samba guys don't, I'd blame Windows. Alan DeKok. - List

Re: FreeRadius + AD + Realms

2010-07-02 Thread Matthew P
realm mydomain.com { auth_pool = active_directory You'll need a line: nostrip To avoid EAP identity issues. This worked, thanks. Preprocess doesn't strip the username in the default server and EAP works. Although, now a new problem arrised - I can't seem to get the

the termination of Lost-Carrier

2010-07-02 Thread Spacelee
e , I want to ask some Termination status some people was terminated because of Session-Timeout some people was terminated because of User-Request some people was terminated because of Lost-Carrier Session-Timeout means he has reached his expiration time User-Request means he request to