Freeradius2 + LDAP of Lotus Notes

2010-08-13 Thread rrperez
I have configured my Freeradius2 server to authenticate in an LDAP server that is used by Lotus Notes. I'm having a problem even though it bind successfully because there is no password attribute in the LDAP server of Lotus Notes. Does it mean that Lotus Notes doesn't store the password of its

Re: Freeradius2 + LDAP of Lotus Notes

2010-08-13 Thread Phil Mayers
On 08/13/2010 08:14 AM, rrperez wrote: I have configured my Freeradius2 server to authenticate in an LDAP server that is used by Lotus Notes. I'm having a problem even though it bind successfully because there is no password attribute in the LDAP server of Lotus Notes. Does it mean that Lotus

Re: Freeradius2 + LDAP of Lotus Notes

2010-08-13 Thread Fajar A. Nugraha
I'm having a problem even though it bind successfully because there is no password attribute in the LDAP server of Lotus Notes. Does it mean that Lotus Notes doesn't store the password of its users in the LDAP server? A more accurate description is that Lotus Domino encrypts the password in

Re: Freeradius2 + LDAP of Lotus Notes

2010-08-13 Thread rrperez
Thanks for the quick response Phil. To Fajar, I have set up the server to do authentication on a wireless network, making the EAP/MS-CHAPv2 not work will fail the authentications for all my microsoft platform clients. Thanks for the response also. -- View this message in context:

Re: Freeradius2 + LDAP of Lotus Notes

2010-08-13 Thread rrperez
I have configured the /etc/raddb/modules/ldap and added an identity (although I don't if it works), but still it can't find a password for the user. Here is the debug: rad_recv: Access-Request packet from host 127.0.0.1 port 37784, id=118, length=63 User-Name = kim.almarez

Re: Freeradius2 + LDAP of Lotus Notes

2010-08-13 Thread rrperez
I have configured the /etc/raddb/modules/ldap and added an identity (although I don't if it works), but still it can't find a password for the user. Here is the debug: rad_recv: Access-Request packet from host 127.0.0.1 port 37784, id=118, length=63 User-Name = kim.almarez

simultaneous logins

2010-08-13 Thread tyllerd
Hi, I have searched on the mailing list and I see that it is suggested to limit simultaneous users by doing user,simultaneous-use,:=,1 I just need to know does this limit user to one login on freeradius or on that nas? as I add this value into the radcheck table. and I try login twice from the

Re: Freeradius2 + LDAP of Lotus Notes

2010-08-13 Thread Fajar A. Nugraha
On Fri, Aug 13, 2010 at 3:36 PM, rrperez rrpe...@apc.edu.ph wrote: I have configured the /etc/raddb/modules/ldap and added an identity (although I don't if it works), but still it can't find a password for the user. I guess rlm_ldap can't find a password attribute on the ldap of Lotus

Re: simultaneous logins

2010-08-13 Thread Alan DeKok
tyllerd wrote: Then I try login from one NAS and then again from another NAS and it works. And what does radiusd -X say? So does simultaneous-use only tell the NAS to let user X login once or is supposed to be server side? Do I need to right a script to do it server side? The

Re: simultaneous logins

2010-08-13 Thread Alan DeKok
Tyller D wrote: Hi Alan, Thank you for the response. Below you can see my user in the table as well as the radius -X. I don't really see any problems, can you? Yes. Look for words like fail or reject or error. checkrad: Net::Telnet 3.00+ CPAN module not installed rlm_sql (sql):

FreeRadius on MacOS X Server

2010-08-13 Thread Andreas Hubert
Hi all, I need help with the freeradius 2.1.3 in MacOS X Server. At the Apple discussion forum I don't get any answer. :( Using this version: radiusd: FreeRADIUS Version 2.1.3, for host i386-apple-darwin10.0, built on Feb 11 2010 at 02:25:02 Copyright (C) 1999-2008 The FreeRADIUS server

Re: FreeRadius on MacOS X Server

2010-08-13 Thread Theparanoidone Theparanoidone
Fri Aug 13 14:46:50 2010 : Auth: rlm_opendirectory: User ahu is authorized. Fri Aug 13 14:46:59 2010 : Error: rlm_eap: No EAP session matching the State variable. Greetings~ Did you turn EAP on for the network connection on the computer/laptop with the wifi card? Perhaps you need to

Re: simultaneous logins

2010-08-13 Thread Alan DeKok
Tyller D wrote: Hi Alan. Thanks for pointing that out. I have gotten rid of most of the error by installing the Net::Telnet 3.00+ CPAN module. I am however still getting the rlm_sql (sql): Released sql socket id: 0 [sql] Failed to check the terminal server for user '92263842'. ++[sql]

Re: FreeRadius on MacOS X Server

2010-08-13 Thread Alan DeKok
Andreas Hubert wrote: I also activated the debug mode and it came out this: ... rad_recv: Access-Request packet from host 192.168.214.100 port 65527, id=37, length=510 ... Sending Access-Challenge of id 37 to 192.168.214.100 port 65527 EAP-Message =

Stripping a realm in EAP

2010-08-13 Thread David Peterson
We have a working radius server and are trying to authenticate using EAP-TTLS with a stripped username. The username sent is 8...@wimax.com, the realm is defined without the nostrip option. However once it's inside the inner-tunnel, the username and domain are authenticated against the sql

Re: FreeRadius and Redundant LDAP Problems

2010-08-13 Thread Kory Wheatley
Per your suggestions from the last email I checked and the: Un-comment the unix entry from the authorize section of raddb/sites-available/default Was un-commented and below is the output from trying to authenticate a user that is a member of the DialupFS group and does not have an account in

Re: FreeRadius and Redundant LDAP Problems

2010-08-13 Thread Alan DeKok
Kory Wheatley wrote: Was un-commented and below is the output from trying to authenticate a user that is a member of the DialupFS group and does not have an account in /etc/passwd. For some reason it is falling though to PAP and saying No authenticate method (Auth-Type) configuration found

pam_auth_radius - Map radius user to local account?

2010-08-13 Thread Cory Johnson
Greetings, I have several Linux and BSD servers that I would like to authenticate against my FreeRADIUS server. My question is, do I have to create unix users on each server that match the names of the radius user that I am logging as? For example, could users logging in via radius be