Re: Windows 7 EAP-TLS WIred Auth

2011-02-14 Thread Phil Mayers
On 02/13/2011 10:37 PM, Christ Schlacta wrote: it seems to get to the same point (Finished request xxx.) and then repeats the entire process four times (the same number of times specified in my switch config) then fails to connect. I'm not sure if I'm missing something, or what.. but it should

AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Schaatsbergen, Chris
OK, I think I found out where things are going wrong. In my Radius -X log I noticed the Starting - reading configuration files is short, compared to those of others. What is missing is actually: including files in directory /usr/local/etc/raddb/modules/ (followed by including

EAP transaction benchmark

2011-02-14 Thread Waqas Toor
Hi community, I need to benchmark the eap transactions in the case of EAP-TLS auth. I mean how many transactions per second of eap a system can handle ( test bed is a multi core intel based system with 36 GB of ram ) also if there are any tools available the we can use to benchmark eap process (

Re: EAP transaction benchmark

2011-02-14 Thread Alan DeKok
Waqas Toor wrote: I need to benchmark the eap transactions in the case of EAP-TLS auth. I mean how many transactions per second of eap a system can handle ( test bed is a multi core intel based system with 36 GB of ram ) CPU matters more than RAM. also if there are any tools available the

Re: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Alan DeKok
Schaatsbergen, Chris wrote: OK, I think I found out where things are going wrong. In my Radius -X log I noticed the Starting - reading configuration files is short, compared to those of others. What is missing is actually: including files in directory /usr/local/etc/raddb/modules/ ...

eappeap_postproxy() - set fake-proxy_reply

2011-02-14 Thread Ken-ichirou MATSUZAWA
Hello, I can't think I understand what went wrong but it works. just escaping from first NULL check in eap_post_proxy() or commit: add0068afc3b732c27c9cc116d7ec331f9a32735 says I misconfigured PEAP proxy? --- src/modules/rlm_eap/types/rlm_eap_peap/peap.c |3 ++- 1 files changed, 2

AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Schaatsbergen, Chris
That is clear, but it seems it is missing in the Lenny Package somehow as http://lists.freeradius.org/pipermail/freeradius-users/2011-January/msg00192.html has exactly the same problem as me, no modules folder being read causing the ntlm_auth not being recognized as module. Where can I find a

Re: AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Alan DeKok
Schaatsbergen, Chris wrote: That is clear, but it seems it is missing in the Lenny Package somehow as http://lists.freeradius.org/pipermail/freeradius-users/2011-January/msg00192.html has exactly the same problem as me, no modules folder being read causing the ntlm_auth not being recognized

AW: AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Schaatsbergen, Chris
I think freeradius is a great piece of software and I will certainly continue to use it. I am also very happy with the great documentation that can be found, both the wiki and Alan's website are an awesome source of very good information. The support community here is also very active, which is

AW: Freeradius on lenny doesn't permit mschap auth

2011-02-14 Thread Schaatsbergen, Chris
Hi David, In case you have not found it yet, in the lenny package somehow there is one line missing in the radiusd.conf file. In the modules section there should be: $INCLUDE ${confdir}/modules/ I would suggest, top of the modules section. Then ntlm_auth should work. Good luck, Chris

Re: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Alan Buxey
Hi, That is clear, but it seems it is missing in the Lenny Package somehow as http://lists.freeradius.org/pipermail/freeradius-users/2011-January/msg00192.html has exactly the same problem as me, no modules folder being read causing the ntlm_auth not being recognized as module. Where can

AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Schaatsbergen, Chris
Thanks! Actually in this case I was too early writing the mail (because I was rather annoyed), something I should not allow myself to happen. The radiusd.conf file is documented on the Wiki site (though the link there that should point to the latest version is not working as it points to the

Freeradius2.1.3 + Fedora9 + PEAP + AD = problem

2011-02-14 Thread Lukas Hofrichtr
Hello everyone, is there any progress resolving this issue? I have samba 3.5.6 on FC14 and have the SAME problem like I've had with FC9/10, Freeradius2 and samba included with distribution. The problem is I cant rollback to older Samba version as it does not support Windows 2008R2 domain

Re: AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Johan Meiring
On 2011/02/14 01:50 PM, Schaatsbergen, Chris wrote: That is clear, but it seems it is missing in the Lenny Package somehow as http://lists.freeradius.org/pipermail/freeradius-users/2011-January/msg00192.html has exactly the same problem as me, no modules folder being read causing the

Support

2011-02-14 Thread Schaatsbergen, Chris
A slightly different question, does the support from http://networkradius.com come from the active users of this mailing list? I.e. if I buy a support contract there, do the Alans get a part of that? I am missing a donate button on the freeradius website and I hope/expect we do not need that

Re: AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Alan DeKok
Schaatsbergen, Chris wrote: Thanks! Actually in this case I was too early writing the mail (because I was rather annoyed), something I should not allow myself to happen. The radiusd.conf file is documented on the Wiki site (though the link there that should point to the latest version is

Re: Support

2011-02-14 Thread Alan DeKok
Schaatsbergen, Chris wrote: A slightly different question, does the support from http://networkradius.com come from the active users of this mailing list? I.e. if I buy a support contract there, do the Alans get a part of that? I am missing a donate button on the freeradius website and I

AW: Support

2011-02-14 Thread Schaatsbergen, Chris
-Ursprüngliche Nachricht- Von: freeradius-users-bounces+chris.schaatsbergen=aleo- solar...@lists.freeradius.org [mailto:freeradius-users- bounces+chris.schaatsbergen=aleo-solar...@lists.freeradius.org] Im Auftrag von Alan DeKok Gesendet: Montag, 14. Februar 2011 15:33 An: FreeRadius

AW: AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Schaatsbergen, Chris
Most of the howtos assume you're running a recent version of the server. Some systems have *old* versions of the server. We're unable to maintain copies of the documentation for each version of the server. This makes life harder for the average admin, but we have to draw the line

AW: AW: AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Schaatsbergen, Chris
-Ursprüngliche Nachricht- Von: freeradius-users-bounces+chris.schaatsbergen=aleo- solar...@lists.freeradius.org [mailto:freeradius-users- bounces+chris.schaatsbergen=aleo-solar...@lists.freeradius.org] Im Auftrag von Alan DeKok Gesendet: Montag, 14. Februar 2011 16:00 An: FreeRadius

AW: AW: AW: AW: AW: Authenticating SSH login on a Cisco IOS switch to AD

2011-02-14 Thread Schaatsbergen, Chris
-Ursprüngliche Nachricht- Von: freeradius-users-bounces+chris.schaatsbergen=aleo- solar...@lists.freeradius.org [mailto:freeradius-users- bounces+chris.schaatsbergen=aleo-solar...@lists.freeradius.org] Im Auftrag von Johan Meiring Gesendet: Montag, 14. Februar 2011 14:48 An:

Re: Freeradius2.1.3 + Fedora9 + PEAP + AD = problem

2011-02-14 Thread Alan Buxey
Hi, first off, i dont think this is a SAMBA issue...thats just me though - the SAMBA issue manifests itself in the authentication phase where ntlm_auth blows up (or rather is a damp squib) is there any progress resolving this issue? I have samba 3.5.6 on FC14 and have the SAME problem like

Re: Freeradius2.1.3 + Fedora9 + PEAP + AD = problem

2011-02-14 Thread Alan DeKok
Alan Buxey wrote: first off, i dont think this is a SAMBA issue...thats just me though - the SAMBA issue manifests itself in the authentication phase where ntlm_auth blows up (or rather is a damp squib) Sometimes ntlm_auth returns the *wrong* results, and only the client PC knows that

Re: Windows 7 EAP-TLS WIred Auth

2011-02-14 Thread Christ Schlacta
On 2/14/2011 01:07, Phil Mayers wrote: On 02/13/2011 10:37 PM, Christ Schlacta wrote: it seems to get to the same point (Finished request xxx.) and then repeats the entire process four times (the same number of times specified in my switch config) then fails to connect. I'm not sure if I'm

Proxying CoA Disconnect in freeRADIUS 2.1.10

2011-02-14 Thread Charles Price
Dear All, I'm having some trouble asking my freeRADIUS-2.1.10 server (Linux, x86_64) to correctly proxy CoA and Disconnect-Request packets. I am generating Disconnect-Request packets from my network_control machine (172.16.3.2) to the freeRADIUS server at 172.16.3.11 using: cat packet.txt

Re: Proxying CoA Disconnect in freeRADIUS 2.1.10

2011-02-14 Thread Alan DeKok
Charles Price wrote: I'm having some trouble asking my freeRADIUS-2.1.10 server (Linux, x86_64) to correctly proxy CoA and Disconnect-Request packets. It's intended to work, but it hasn't been well tested recently. As far as I know, I have followed instructions documented in

Re: Proxying CoA Disconnect in freeRADIUS 2.1.10

2011-02-14 Thread Charles Price
I'll see if I can find time to look into it. This configuration is simple enough that I should be able to use it pretty much as-is. Much appreciated, Alan. If you need any additional testing or information from me, please let me know. Regards, Charlie - List info/subscribe/unsubscribe?

Re: Support

2011-02-14 Thread Alan Buxey
Hi, A slightly different question, does the support from http://networkradius.com come from the active users of this mailing list? I.e. if I buy a support contract there, do the Alans get a part of that? I am missing a donate button on the freeradius website and I hope/expect we do

RE: Windows 7 EAP-TLS WIred Auth

2011-02-14 Thread Gary Gatten
Hi, I did eventually find a sorta fix. I had jumbo frames enabled, disabling them fixed the problem temporarily. the problem has returned in a different form now. the radius server doesn't even see the auth requests now, and the client just won't even try to authenticate. I think

Re: Support

2011-02-14 Thread Fajar A. Nugraha
On Tue, Feb 15, 2011 at 4:45 AM, Alan Buxey a.l.m.bu...@lboro.ac.uk wrote: please think about networkradius.com if you want to have a solid support for the product - it will ensure that you have a good FreeRADIUS deployment and you wont get Mr Random in management bearing down on you with

How to set Authentication method priority??

2011-02-14 Thread vijay s sheelavantar
Hi, 1. nbsp;nbsp;nbsp;nbsp;I have pam_radius_auth module configured to authenticate the login users. I have configured FreeRadius Server on a linux machine. I want to set the the priority for local authentication or Radius authentication for SSH. How can I do this? 2. I have created a user