Re: Freeradius on lenny doesn't permit mschap auth

2011-01-17 Thread Fabien COMBERNOUS
On 14/01/2011 23:47, Alan DeKok wrote: Fabien COMBERNOUS wrote: [...] David is not bridling but just remember his constraints. They are *his* constraints. If he can't even install a version of 2.1.10 in order to run radtest which can do MS-CHAP, then those constraints are ridiculous.

Re: Freeradius on lenny doesn't permit mschap auth

2011-01-17 Thread Bjørn Mork
Fabien COMBERNOUS fcombern...@kezia.com writes: In a complex environment to change a piece of software can have unexpected consequences. And so to change it, it demands long testing procedures for several teams. I already worked in this kind of environment. And you have to give good reasons

Re: Freeradius on lenny doesn't permit mschap auth

2011-01-17 Thread David Dumortier
Le Mon Jan 17 2011 � 09:29:47AM +0100, Fabien COMBERNOUS dit : On 14/01/2011 23:47, Alan DeKok wrote: Fabien COMBERNOUS wrote: [...] David is not bridling but just remember his constraints. They are *his* constraints. If he can't even install a version of 2.1.10 in order to run radtest

Re: Freeradius on lenny doesn't permit mschap auth

2011-01-17 Thread Martín Ruiz [Ibersystems.es]
I think some comments.. are too heavys : P I'm reading this list looking for solutions, or improvements for my servers, but this threads are disgusting me. It's not necessary to write thing like this.. I'm not agree with this. When someone requests help, you can help as usually. If he can't do

Re: Freeradius on lenny doesn't permit mschap auth

2011-01-17 Thread David Dumortier
Le Mon Jan 17 2011 � 10:13:56AM +0100, Bjørn Mork dit : Fabien COMBERNOUS fcombern...@kezia.com writes: [...] So? You've painted yourself into an unsupportable environment. The polite thing to do would be to state this when asking, to avoid wasting everyones time. Noone really cares

Re: Freeradius on lenny doesn't permit mschap auth

2011-01-17 Thread Josip Rodin
On Mon, Jan 17, 2011 at 10:20:00AM +0100, David Dumortier wrote: In a complex environment to change a piece of software can have unexpected consequences. And so to change it, it demands long testing procedures for several teams. I will try to find a mschap string with a second

Install problems

2011-01-17 Thread Breuer Nicolas
Hello I can't install the last freeradius to our new server ./configure --libdir=/usr/local/lib/freeradius2 --with-mysql-lib-dir=/usr/lib64/mysql --disable- libltdl-install --with-system-libtool --without-openssl libtool: link: rm -f .libs/radiusd.nm .libs/radiusd.nmS .libs/radiusd.nmT

Re: Freeradius on lenny doesn't permit mschap auth

2011-01-17 Thread Bjørn Mork
Josip Rodin j...@entuzijast.net writes: As usual, it would have helped if all parties would have steered away from snappy remarks. Rather than do that, it's often simpler and eminently more productive to keep silent. You are of course correct. I apologise for my unnecessary comment. I will

Re: Install problems

2011-01-17 Thread Alan DeKok
Breuer Nicolas wrote: I can't install the last freeradius to our new server ./configure --libdir=/usr/local/lib/freeradius2 --with-mysql-lib-dir=/usr/lib64/mysql --disable-libltdl-install --with-system-libtool --without-openssl ...

Re: Install problems

2011-01-17 Thread Breuer Nicolas
Hello I just do that. MAKE= /usr/bin/gmake CC = gcc RANLIB = ranlib INCLUDE = CFLAGS = $(INCLUDE) -g -O2 -D_REENTRANT - D_POSIX_PTHREAD_SEMANTICS -Wall -D_GNU_SOURCE -DNDEBUG - DIE_LIBTOOL_DIE Same error libtool: compile: gcc -g -O2

Re: freeradius 2.1.10 with oracle instantclient11.2

2011-01-17 Thread Waqas Toor
Dear Alexandre, Ok the patch you sent didnt work for me so here are some steps that I took and would like to share so that other may benefit from it :) these steps are working with FreeRadius 2.1.10 and Oracle Instantclient 11.2, autoconf 2.59 and libtool 1.5.4 and OS is centOS 5.4 (final) Steps

Re: Problem with iPods/iTouches

2011-01-17 Thread Rob Yamry
Does this problem also happen with iOS 4.x devices other than the iPod Touch? Does the problem happen with non-Enterasys gear? (Do you have any that you can test with?) Additionally, what firmware version are you running on the Enterasys gear? Can you share your config (or at least the

mschap fails

2011-01-17 Thread Jason Hall
Ntlm_auth nt and lm key requests NT_STATUS_OK: Success (0x0) but the mschap section still fails after cert exchance... Log file - http://pastebin.com/rDhRKgiC Suse Ent 11.0.0.32, samba 3.2.7, FreeRadius 2.1.1 Any ideas? Pointers? Suggestions?! Anyone recommend a distro that just works?

Re: mschap fails

2011-01-17 Thread Phil Mayers
On 17/01/11 14:34, Jason Hall wrote: Ntlm_auth nt and lm key requests NT_STATUS_OK: Success (0x0) but the mschap section still fails after cert exchance… Has it ever worked? If not, this is probably the Samba bug documented (in newer versions of FreeRadius) in eap.conf:

RE: Sub-TLV's

2011-01-17 Thread David Peterson
Understood. Here is the dictionary I am working with: The changes start at line 168. # -*- text -*- ## # # WiMAX Forum # # Updated from NWG_R1_V1.2.1-Stage-3.pdf # # NWG_R1_V1.2-Stage-3.pdf #

Re: Sub-TLV's

2011-01-17 Thread Alan DeKok
David Peterson wrote: Understood. Here is the dictionary I am working with: The changes start at line 168. Ah. Nested TLV's aren't supported in 2.1.x. Instead, see the git stable branch for massive changes to allow all of the WiMAX goodness. It has many updates to the dictionary parser,

RE: Sub-TLV's

2011-01-17 Thread David Peterson
OK that makes sense. I am using the Master branch per the git instructions. I am receiving this error during compile: make[4]: Entering directory `/usr/src/freeradius-server/src/main' /bin/sh /usr/src/freeradius-server/libtool --mode=compile gcc -g -O2 -D_REENTRANT -D_POSIX_PTHREAD_SEMANTICS

Re: Sub-TLV's

2011-01-17 Thread Alan DeKok
David Peterson wrote: OK that makes sense. I am using the Master branch per the git instructions. Uh... no. My email said the stable branch. I'll get around to fixing the web page and/or git in the next while. Alan DeKok. - List info/subscribe/unsubscribe? See

cleaning house on radius server?

2011-01-17 Thread Christ Schlacta
I've got a radius server up and running, and I want to clean up my configuration as much as possible. is it a safe assumption that if I remove a file (actually move it out of the way) and attempt to authenticate a client that if the client can successfully authenticate that everything is

modules directory

2011-01-17 Thread Christ Schlacta
I've found something odd in regard to the modules directory. I ended up needing to use checkval module for ldap authentication to work properly for me. the documentation I found said to place the following in config files: checkval { item-name = Calling-Station-Id check-name

Re: cleaning house on radius server?

2011-01-17 Thread John Dennis
On 01/17/2011 03:36 PM, Christ Schlacta wrote: I've got a radius server up and running, and I want to clean up my configuration as much as possible. is it a safe assumption that if I remove a file (actually move it out of the way) and attempt to authenticate a client that if the client can

Re: modules directory

2011-01-17 Thread John Dennis
On 01/17/2011 03:37 PM, Christ Schlacta wrote: one more question: can there be multiples of ANY module specified? In general modules can be instantiated multiple times under different names with configuration parameters unique to that name. Not sure if this is true for *all* modules though,

Re: cleaning house on radius server?

2011-01-17 Thread Alexander Clouter
Christ Schlacta li...@aarcane.org wrote: I've got a radius server up and running, and I want to clean up my configuration as much as possible. is it a safe assumption that if I remove a file (actually move it out of the way) and attempt to authenticate a client that if the client can

RE: cleaning house on radius server?

2011-01-17 Thread Tim Sylvester
I've got a radius server up and running, and I want to clean up my configuration as much as possible. is it a safe assumption that if I remove a file (actually move it out of the way) and attempt to authenticate a client that if the client can successfully authenticate that everything is

problem in opensips+radius accounting

2011-01-17 Thread happyeveryday1025
Hello: I am doing accounting with opensips+freeradius+radiusclient-ng.Now when i make a call using X-Lite,the radius server has response,but the accounting message is not right,the attribute service-type and eap-service-typeis present in the log,I dont know what is the matter,how to set

acc:acc_aaa_request: failed to add Contact, 17

2011-01-17 Thread happyeveryday1025
Hello: When I am do accounting with opensips1.6.4+freeradius2.1.10+radiusclient0.5.6,I meet the following error: acc:acc_aaa_request: failed to add Contact, 17 I kmow I need to define the attribute Contactin the dictionary file dictionary.opensips,but I can not find the value and type of the

来自happyeveryday1...@126.com的邮件

2011-01-17 Thread happyeveryday1025
/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d - /usr/local/var/log/radius/radacct/192.168.118.39/detail-20110117 [detail] /usr/local/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands to /usr/local/var/log/radius/radacct/192.168.118.39/detail-20110117 [detail]expand

accounting with opensip and radius;error-cause=invite

2011-01-17 Thread happyeveryday1025
/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d - /usr/local/var/log/radius/radacct/192.168.118.39/detail-20110117 [detail] /usr/local/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands to /usr/local/var/log/radius/radacct/192.168.118.39/detail-20110117 [detail]expand

Re: cleaning house on radius server?

2011-01-17 Thread Christ Schlacta
I have everyone setup to use tls authentication, with authorization via ldap check on the hostname and the mac address. that's the ONLY path. On 1/17/2011 13:28, John Dennis wrote: On 01/17/2011 03:36 PM, Christ Schlacta wrote: I've got a radius server up and running, and I want to clean

Re: modules directory

2011-01-17 Thread Johan Meiring
On 2011/01/17 10:37 PM, Christ Schlacta wrote: one more question: can there be multiples of ANY module specified? for example, can I use two different ldap or sql modules if I were to need to (just as a bad example, I propose: 1 radius server, 2 wlans with different user bases that can't be