RE: Cant Start Radius Server MAC OSX (snow leopard)

2011-08-16 Thread Elizabeth Fife
Thanks Alan You are of course right. Being new to this i did not realize the very tight restrictions on formatting and type. Fixing the entry in users has done the trick. Radius server on mac oxs 10.6.x now authenticates users accessing login to the router. I will now go on to try do the same

Re: Using a single row in radreply

2011-08-16 Thread denizaydin
Hi Fajar, Thanks for your reply. I guess we have to redesign the database as you said with one row it is not easy to add new attributes. I don't prefer to make changes in the source code as it may lead additional problems while upgrading freeradius. - Deniz AYDIN Senior Network Engineer

Re: Cant Start Radius Server MAC OSX (snow leopard)

2011-08-16 Thread Alan Buxey
Hi, including configuration file /private/etc/raddb/radiusd.conf Unable to open file /private/etc/raddb/radiusd.conf: Permission denied Errors reading /private/etc/raddb/radiusd.conf check permissions on the /private , /private/etc and /private/etc/raddb directory as well as the radiusd.conf

Re: NAS-IP-Address or NAS-Identifier in Access-Request?

2011-08-16 Thread Alan Buxey
Hi, Does anyone happen to know if consumer-level Wi-Fi routers typically transmit the NAS-IP-Address or NAS-Identifier (or maybe both) in the Access-Request? RFC's say An Access-Request MUST contain either a NAS-IP-Address attribute or a NAS-Identifier attribute (or both). so, you will get

Re: Declare a time availability of NASs?

2011-08-16 Thread Alan Buxey
Hi, Is there any way to declare a time availability of NASs…such as a Login-Time attribute for NASs? I’d like to globally control when (time of yes day, time of week) all users can login through a certain wireless access point on my 802.1X network. the code/config is there - its

RE: NAS-IP-Address or NAS-Identifier in Access-Request?

2011-08-16 Thread Eric Geier
Thanks, Alan. Yes I read that in the RFC, but was wondering what vendors usually do, what's the most typical, etc. I'm also wondering the same about the Calling-Station-Id and Called-Station-ID. But sounds like those aren't included very often, completely optional. But now that I've thought of

Openssl Private Key error

2011-08-16 Thread voxner
Hi, I had generated certificates for EAP-TLS authentication. It worked fine in a linux setup but windows wouldn't play ball. Somebody pointed out that the CA.* scripts in the ssl directory can generate windows compatible certs. I did that but when I try to use that I get the following error

RE: NAS-IP-Address or NAS-Identifier in Access-Request?

2011-08-16 Thread Eric Geier
Understood, thanks! Can I log the source IP address to the Post-Auth DB table? Thanks, Eric -Original Message- From: freeradius-users-bounces+me=egeier@lists.freeradius.org [mailto:freeradius-users-bounces+me=egeier@lists.freeradius.org] On Behalf Of Alan DeKok Sent: Tuesday,

Re: Need help authenticating local users on Apple server

2011-08-16 Thread Raymond Norton
And then list it in the authorize section. What is the proper syntax for adding the opendirectory module? I am getting errors when attempting to start radius: /usr/local/etc/raddb/sites-enabled/inner-tunnel[195]: Entry is not a reference to a module

Re: Need help authenticating local users on Apple server

2011-08-16 Thread Johan Meiring
On 2011/08/16 10:39 PM, Raymond Norton wrote: And then list it in the authorize section. What is the proper syntax for adding the opendirectory module? I am getting errors when attempting to start radius: /usr/local/etc/raddb/sites-enabled/inner-tunnel[195]: Entry is not a reference to a

Re: Need help authenticating local users on Apple server

2011-08-16 Thread Raymond Norton
Read again. list it in the authorize section not the authenticate section My mistake. I thought the word And meant do both, based on my question. Removed from authenticate and listed opendirectory under authorize of inner tunnel. I now get the following error:

Re: Need help authenticating local users on Apple server

2011-08-16 Thread Alan DeKok
Raymond Norton wrote: What is the proper syntax for adding the opendirectory module? $ man unlang Or, read the dozens of examples in the configuration file you edited. I am getting errors when attempting to start radius: /usr/local/etc/raddb/sites-enabled/inner-tunnel[195]: Entry is not

Re: Need help authenticating local users on Apple server

2011-08-16 Thread Raymond Norton
OK... you made a change to the file which created that error. Is it a secret? Or did you think we could guess what you did wrong? Johan informed me I misunderstood your original instructions and I was not to put anything under Authenticate of the inner-tunnel. I removed what I

RE: NAS-IP-Address or NAS-Identifier in Access-Request?

2011-08-16 Thread Eric Geier
I found %{Packet-Src-IP-Address} but when I include this in the postauth_query, it doesn't work...the fields are blank in the DB when I view it. How could I log the source IP address of successful authentications? - Eric -Original Message- From:

Re: Need help authenticating local users on Apple server

2011-08-16 Thread Fajar A. Nugraha
On Wed, Aug 17, 2011 at 7:51 AM, Raymond Norton ad...@lctn.org wrote: And this is the error I now get with radiusd _X:  Module: Checking authenticate {...} for more modules to load  Module: Checking authorize {...} for more modules to load /usr/local/etc/raddb/modules/opendirectory[11]: