Re: Re: Re: Re: FreeRADIUS with Samba3, AD(Samba4) and and Windows XP

2010-09-10 Thread Бисер Миланов
I have disabled certificate checking on the Windows machine. Here's the log from the XP client: Reason: An internal error has occurred. Reason code: 327685 Error code: -2147023537 On the switch I see this repeated several times. The ca58 MAC is the Windows MAC, so this means that it somehow

SQL Logging Access-Reject

2010-09-10 Thread Kristoffer Milligan
Hello again list, I'm still working on my FreeRADIUS server in connection with 4Motion equipment from Alvarion. It's getting better and better and more integrated, but I still have a few quirks I need to work out. My main problem now is the logging part. In the post-auth section, I have

FreeRadius2+daloRAIUS mschap problem: No Cleartext-Password configured

2010-09-10 Thread Denis Iskandarov
My setup: CentOS 5.5 x32 freeradius2-2.1.7-7.el5 mysql-5.0.77-4.el5_5.3 daloRADIUS 0.9-8 SVN (0.9.-9) used for 802.1x EAP-TLS and EAP-TTLS (maybe for peap in future as well) with Ubiquiti and Mikrotik network equipment setup works perfectly without sql with text conf files. when creating user in

Re: Re: Re: Re: Re: FreeRADIUS with Samba3, AD(Samba4) and and Windows XP

2010-09-10 Thread Бисер Миланов
Guys, anyone? Do you need more config info? Can you help? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius2+daloRAIUS mschap problem: No Cleartext-Password configured

2010-09-10 Thread Alan DeKok
Denis Iskandarov wrote: used for 802.1x EAP-TLS and EAP-TTLS (maybe for peap in future as well) with Ubiquiti and Mikrotik network equipment setup works perfectly without sql with text conf files. when creating user in sql getting next error: (Output omitted) You have deleted the output

Radmin - hup query

2010-09-10 Thread John Horne
Hello, Running Freeradius 2.1.10 on CentOS 5.5 I have been taking a quick look at the radmin 'hup' command. However, I am having a problem getting it to work: radmin -e hup ERROR: You do not have write permission. See mode = rw in /var/run/radiusd/radiusd.sock However, the socket file

Re: Radmin - hup query

2010-09-10 Thread Alan DeKok
John Horne wrote: Running Freeradius 2.1.10 on CentOS 5.5 I have been taking a quick look at the radmin 'hup' command. However, I am having a problem getting it to work: radmin -e hup ERROR: You do not have write permission. See mode = rw in /var/run/radiusd/radiusd.sock See the

Re: Radmin - hup query

2010-09-10 Thread Bjørn Mork
John Horne john.ho...@plymouth.ac.uk writes: Running Freeradius 2.1.10 on CentOS 5.5 I have been taking a quick look at the radmin 'hup' command. However, I am having a problem getting it to work: radmin -e hup ERROR: You do not have write permission. See mode = rw in

Re: Radmin - hup query

2010-09-10 Thread John Horne
On Fri, 2010-09-10 at 14:17 +0200, Alan DeKok wrote: John Horne wrote: Running Freeradius 2.1.10 on CentOS 5.5 I have been taking a quick look at the radmin 'hup' command. However, I am having a problem getting it to work: radmin -e hup ERROR: You do not have write permission.

Restricting Clients and Users

2010-09-10 Thread omega_one
Hi all. I need that: - system group A access only switch 1.1.1.1 and 1.1.1.2 - system group B access only switch 2.1.1.1 and 2.1.1.2 I created local group of users A and B and associated users /etc/raddb/clients.conf client 1.1.1.1 { secret = xxx shortname =

Re: Radmin - hup query

2010-09-10 Thread John Dennis
On 09/10/2010 08:27 AM, Bjørn Mork wrote: John Hornejohn.ho...@plymouth.ac.uk writes: Running Freeradius 2.1.10 on CentOS 5.5 I have been taking a quick look at the radmin 'hup' command. However, I am having a problem getting it to work: radmin -e hup ERROR: You do not have write

Re: Restricting Clients and Users

2010-09-10 Thread John Dennis
On 09/10/2010 08:52 AM, omega_...@mail.com wrote: How can i modify my configurations to let only A users to access switch 1.1.1.1/2 and B users access switch 2.1.1.1/2 ? Use huntgroups, it's documented. -- John Dennis jden...@redhat.com Looking to carve out IT costs?

Re: Radmin - hup query

2010-09-10 Thread Alan DeKok
John Dennis wrote: FWIW if you install via Red Hat supplied RPM's this should just work (at least it did the last time I tested). We try to get all these installation details right for a smoother user experience. cough The default install *does* work. The control socket mode is set to

Re: FreeRadius2+daloRAIUS mschap problem: No Cleartext-Password configured

2010-09-10 Thread Denis Iskandarov
You have deleted the output which is needed to help you. Found Auth-Type = MSCHAP +- entering group MS-CHAP {...} [mschap] No Cleartext-Password configured. Cannot create LM-Password. [mschap] No Cleartext-Password configured. Cannot create NT-Password. So... you haven't told the

Re: FreeRadius2+daloRAIUS mschap problem: No Cleartext-Password configured

2010-09-10 Thread Alan DeKok
Denis Iskandarov wrote: Sorry i didn't understand you. which good known password ?I'm using daloRADIUS. and while creating user i appended cleartext password := to it: Here is output of radcheck table: Yes... It's almost same string as in users text conf, but in mysql table form.

Re: FreeRadius2+daloRAIUS mschap problem: No Cleartext-Password configured

2010-09-10 Thread John Dennis
On 09/10/2010 09:18 AM, Denis Iskandarov wrote: You have deleted the output which is needed to help you. Found Auth-Type = MSCHAP +- entering group MS-CHAP {...} [mschap] No Cleartext-Password configured. Cannot create LM-Password. [mschap] No Cleartext-Password configured. Cannot create

Re: FreeRadius2+daloRAIUS mschap problem: No Cleartext-Password configured

2010-09-10 Thread Denis Iskandarov
Thanks too all of You ! It worked!!! I saw all the documentations on freeradius, different howtos and forum threads, but didn't saw this option. why people didn't wrote about this. Also one newbie question about this mailing list: How should i answer on answers of my thread? Put Re:Re: in

Ignoring EAP-Type/tls because we do not have OpenSSL support.

2010-09-10 Thread Douglas Caro
Hi, In #freeradius -X, I have those messages: Ignoring EAP-Type/tls because we do not have OpenSSL support. Ignoring EAP-Type/ttls because we do not have OpenSSL support. Ignoring EAP-Type/peap because we do not have OpenSSL support. I've researched on the subject, but I didn't find anything.

Re: Ignoring EAP-Type/tls because we do not have OpenSSL support.

2010-09-10 Thread John Dennis
On 09/10/2010 02:49 PM, Douglas Caro wrote: Hi, In #freeradius -X, I have those messages: Ignoring EAP-Type/tls because we do not have OpenSSL support. Ignoring EAP-Type/ttls because we do not have OpenSSL support. Ignoring EAP-Type/peap because we do not have OpenSSL support. I've researched

RE: Ignoring EAP-Type/tls because we do not have OpenSSL support.

2010-09-10 Thread Sallee, Stephen (Jake)
I switched to CentOS for my FR server because my Ubuntu install was being too picky. I was able to get it to work but I had to compile OpenSSL from source, then the libs are in different places, etc. it was a headache. CentOS was much easier for me, if you're not forced to use Debian you may

RE: Beginner Question: Hotspot Login Failed

2010-09-10 Thread Sean Wingert
Yes, Alan, you were right. The SQL entries were causing the message about Please update your configuration so that the known good. Since DaloRadius created those entries, I will investigate it. Sean This message is intended only for the individual or entity to which it is addressed and may

Re: Ignoring EAP-Type/tls because we do not have OpenSSL support.

2010-09-10 Thread David Mitchell
Sallee, Stephen (Jake) wrote: I switched to CentOS for my FR server because my Ubuntu install was being too picky. I was able to get it to work but I had to compile OpenSSL from source, then the libs are in different places, etc. it was a headache. CentOS was much easier for me, if you're

Re: Freeradius-Users Digest, Vol 65, Issue 43

2010-09-10 Thread Douglas Caro
Thanks for all, but it didn't work... #dpkg -l |grep freer ii freeradius 2.1.8+dfsg-1~bpo50+1 a high-performance and highly configurable R ii freeradius-common 2.1.8+dfsg-1~bpo50+1

Re: Freeradius-Users Digest, Vol 65, Issue 43

2010-09-10 Thread David Mitchell
Douglas Caro wrote: Thanks for all, but it didn't work... Odd. Can you double check that OpenSSL got installed? It should be package libssl0.9.8 -David Mitchell #dpkg -l |grep freer ii freeradius 2.1.8+dfsg-1~bpo50+1 a

Re: Ignoring EAP-Type/tls because we do not have OpenSSL support.

2010-09-10 Thread Alexander Clouter
Douglas Caro douglas.c...@lightcomm.com.br wrote: In #freeradius -X, I have those messages: Ignoring EAP-Type/tls because we do not have OpenSSL support. Ignoring EAP-Type/ttls because we do not have OpenSSL support. Ignoring EAP-Type/peap because we do not have OpenSSL support. I've

After server rebuild the PEAP against Windows AD is not working any more!

2010-09-10 Thread Difan Zhao
Hi experts, I'm getting really frustrated on this... I had the server rebuilt with REHL 5 and FreeRadius2.1.7. It was running REHL 4 with FreeRadius2.1.6. It looks like the server will send the last challenge and the client won't reply anymore... The ntlm_auth part should be working right