Re: FreeRadius 2.1.12, why is EAP AKA support in eap2 module

2012-03-16 Thread Altaf Husain
On Thu, Mar 15, 2012 at 6:14 PM, Alan DeKok al...@deployingradius.comwrote: Altaf Husain wrote: We are using FreeRadius ver 2.1.12, I had query regarding EAP-AKA support in eap2 module, its mentioned in FreeRadius website that This module is experimental, and may not be

Re: FreeRadius 2.1.12, why is EAP AKA support in eap2 module

2012-03-16 Thread Phil Mayers
On 03/15/2012 12:36 PM, Altaf Husain wrote: Hi, We are using FreeRadius ver 2.1.12, I had query regarding EAP-AKA support in eap2 module, its mentioned in FreeRadius website that This module is experimental, and may not be ready for use in a production environment, Is it

Re: FreeRadius 2.1.12, why is EAP AKA support in eap2 module

2012-03-16 Thread Altaf Husain
Thanks Phil this information was helpful On Fri, Mar 16, 2012 at 2:58 PM, Phil Mayers p.may...@imperial.ac.ukwrote: On 03/15/2012 12:36 PM, Altaf Husain wrote: Hi, We are using FreeRadius ver 2.1.12, I had query regarding EAP-AKA support in eap2 module, its mentioned in FreeRadius

Re: FreeRadius 2.1.12, why is EAP AKA support in eap2 module

2012-03-16 Thread Alan DeKok
Altaf Husain wrote: What do u mean by native code hasn't been written, we do have EAP AKA support in eap 2 module in free radius?? No. See Phil's response for details. Regarding code submission and pay to someone, we already have code to support EAP AKA, but wanted to

Re: LDAP Search Questions

2012-03-16 Thread ryuukuu
Can someone throw me a bone here? This is really the last step in my process in getting FreeRadius production ready. -- View this message in context: http://freeradius.1045715.n5.nabble.com/LDAP-Search-Questions-tp5565845p5571520.html Sent from the FreeRadius - User mailing list archive at

Re: Add Users in MySQL database

2012-03-16 Thread ryuukuu
What is the one that is included with FreeRadius? I am trying to use DaloRadius and imho its terrible. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Add-Users-in-MySQL-database-tp5559384p5571530.html Sent from the FreeRadius - User mailing list archive at Nabble.com.

Re: Add Users in MySQL database

2012-03-16 Thread Alan Buxey
Hi, What is the one that is included with FreeRadius? I am trying to use DaloRadius and imho its terrible. dialup_admin IIRC. whats wrong with DoloRADIUS? give the author feedback and your problems/issues might be worked on. alan - List info/subscribe/unsubscribe? See

Re: LDAP Search Questions

2012-03-16 Thread Alan Buxey
Hi, Can someone throw me a bone here? This is really the last step in my process in getting FreeRadius production ready. i'd advise getting a basic grasp of LDAP and terminology before using it as a tool - plenty of free resources out there. you have a group RADIUS that you want to check

md5 passwords in mysql database

2012-03-16 Thread pamela pomary
Hello Please I have a challenge encrypting passwords using md5 in MySQL database for radius users. When I do a radtest like this: radtest test password localhost 0 key for user test with md5(password) in MySQL database it is successful. However when do this : radtest -t mschap testmd5 password

Re: LDAP Search Questions

2012-03-16 Thread Phil Mayers
On 14/03/12 19:04, ryuukuu wrote: Hello All, I've got a question about the settings for limiting access/authenticating to a specific LDAP group. I have setup a group on my OpenLDAP called RADIUS and I want the users in there to be the only ones that have access. The problem I am having is with

Re: md5 passwords in mysql database

2012-03-16 Thread Phil Mayers
On 16/03/12 16:14, pamela pomary wrote: I read online,it is not possible to do md5 with MS-CHAP. I don't want to This is correct. save users passwords in clear text. How can I achieve encrypting user's passwords in MySQL database. I have Freeradius2.1.12 installed. Please I will be grateful

Freeradius crash with two radclient

2012-03-16 Thread fulvio fabiani
Hi all, i’ve a problem with concurrent accounting requests with free radius 2.1.11. In details: I’ve 2 free radius servers balanced by bigip f5 through roundrobin algorithm. I use to send account request using radclient on a machine placed in the same sub-netmask of f5, and it forward the

Re: Freeradius crash with two radclient

2012-03-16 Thread Phil Mayers
On 16/03/12 16:57, fulvio fabiani wrote: Hi all, i’ve a problem with concurrent accounting requests with free radius 2.1.11. Upgrade to 2.1.12 and try again. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: proxy server goes deaf after Client has closed connection (RadSec to home server)

2012-03-16 Thread Alan DeKok
Brian Julin wrote: request_proxy_anew was assuming its argument would be installed in the proxy_list, which wasn't the case, so it was removing it twice causing .num_outgoing counters to roll over. Then, request_proxy was not expecting the case where the argument was already in the

RE: proxy server goes deaf after Client has closed connection (RadSec to home server)

2012-03-16 Thread Brian Julin
Alan DeKok Wrote Brian Julin wrote: The latter makes me wonder why or if request_proxy_anew works at all. It was tested at one point. But the code has changed since then. Given the complexity of RADIUS state management, automating a comprehensive test suite for it would be a very

Re: Add Users in MySQL database

2012-03-16 Thread Fabricio Flores
I want to know if there is a module that I can add users in the database before AAA... I can add users with daloRadius but is important that the user and password in the captive portal be added in the database before authentication... El 16 de marzo de 2012 10:44, Alan Buxey

Re: Add Users in MySQL database

2012-03-16 Thread Alan Buxey
Hi, I want to know if there is a module that I can add users in the database before AAA... I can add users with daloRadius but is important that the user and password in the captive portal be added in the database before authentication... yes. you keep on saying this - but you are

IF-MAP Support

2012-03-16 Thread Francois Gaudreault
Hello, I believe some work have been done on this topic lately with external log modules to populate an IF-MAP database, correct? I am wandering if there is a working -as-PoC piece of code available somewhere? We are interested in testing and add the support for IF-MAP in PacketFence (long

Re: IF-MAP Support

2012-03-16 Thread Alan DeKok
Francois Gaudreault wrote: I believe some work have been done on this topic lately with external log modules to populate an IF-MAP database, correct? I've heard rumors. I am wandering if there is a working -as-PoC piece of code available somewhere? We are interested in testing and add

Question on logging EAP/PEAP authentication rejections

2012-03-16 Thread Josh Hiner
Hello. Im running freeradius 2.1.6 and logging to /var/log/radius in file/detail format. Currently connection logging is working if the user authenticates correctly. I cant get access rejects to log though. Ive turned on reply detail but that is only showing successful attempts too. I have :

Re: Question on logging EAP/PEAP authentication rejections

2012-03-16 Thread Alan DeKok
Josh Hiner wrote: Hello. Im running freeradius 2.1.6 and logging to /var/log/radius in file/detail format. Currently connection logging is working if the user authenticates correctly. I cant get access rejects to log though. Ive turned on reply detail but that is only showing successful

Two-Factor Auth using FreeRADIUS

2012-03-16 Thread Ryon Day
Hello all, long-time reader, first time poster to this list. I've watched many posters go down in flames on this list, so I'm going to try to learn from their mistakes and be as precise as possible; I'm also going to make it known at the outset that I have read all the documentation that I can

Re: IF-MAP Support

2012-03-16 Thread Alan Buxey
Hi, I believe some work have been done on this topic lately with external log modules to populate an IF-MAP database, correct? I am wandering if there is a working -as-PoC piece of code available somewhere? We are interested in testing and add the support for IF-MAP in PacketFence (long

Re: Two-Factor Auth using FreeRADIUS

2012-03-16 Thread Alan Buxey
Hi, Hello all, long-time reader, first time poster to this list. I've watched many posters go down in flames on this list, so I'm going to try to learn from their mistakes and be as precise as possible; I'm also going to make it known at the outset that I have read all the documentation

AP-FR-LDAP authentication

2012-03-16 Thread Julie
I'm new to FreeRadius and trying to setup the server to authenticate using LDAP. I'm having some problem and hope to get some help from the list. I'm trying to setup AP-FR-LDAP. Both FreeRadius and LDAP are new installation on CentOS. I tried to follow the installation for FR and test each

Re: IF-MAP Support

2012-03-16 Thread Francois Gaudreault
Hi, we wrote a perl script to log into an IF-MAP instance - since that code was written the IF-MAP stuff has been updated to latest specand since we wrote the code the IF-MAP instance we used has been turned off and we have no current plans to use IF-MAP presently (for what it was used for

Re: Add Users in MySQL database

2012-03-16 Thread Fabricio Flores
Mmm I have a web service so I have users and password... So If somebody wants to login in the captive portal first i want to see in the web service if ther is this user, and if the user exists i add the user in the mysql database and freeradius athenticate thes user from the mysql database... El

Re: Two-Factor Auth using FreeRADIUS

2012-03-16 Thread Ryon Day
:-( Sometimes it's tough being *almost* perfect. Will reply back later with an exhaustive list of things I have tried that didn't work, their sites-enabled/default configurations, and the debug output! From: Alan Buxey a.l.m.bu...@lboro.ac.uk To: Ryon Day

Re: Add Users in MySQL database

2012-03-16 Thread Fajar A. Nugraha
On Sat, Mar 17, 2012 at 7:55 AM, Fabricio Flores fabriflor...@gmail.com wrote: Mmm I have a web service so I have users and password... So If somebody wants to login in the captive portal first i want to see in the web service if ther is this user, and if the user exists i add the user in the

Re: Two-Factor Auth using FreeRADIUS

2012-03-16 Thread Alan DeKok
Ryon Day wrote: Hello all, long-time reader, first time poster to this list. I've watched many posters go down in flames on this list, so I'm going to try to learn from their mistakes and be as precise as possible; I'm also going to make it known at the outset that I have read all the

Re: AP-FR-LDAP authentication

2012-03-16 Thread Alan DeKok
Julie wrote: The problem is when I try to authenticate through AP. The debug log shows Failed to authenticate the user. here is the log file. ... [mschap] Found MS-CHAP attributes. Setting 'Auth-Type = mschap' ... [ldap] userPassword - Password-With-Header ==

Any body here?Please help me to test my server.

2012-03-16 Thread ZhenJoey
Hello every body: I just set up a freeradius server right now, Please help me to test it by run $radtest snan4love 123456 119.127.12.6 1812 12345678 I will be waiting here. BTW,i do a test my self via a NAS not radtest, it doesnt work. is there something like TimeOut in NAS when it try to

Re: Add Users in MySQL database

2012-03-16 Thread Fabricio Flores
Ok you really help me... Thank you very much... El 17/03/2012 02:42, Fajar A. Nugraha l...@fajar.net escribió: On Sat, Mar 17, 2012 at 7:55 AM, Fabricio Flores fabriflor...@gmail.com wrote: Mmm I have a web service so I have users and password... So If somebody wants to login in the captive

RE: AP-FR-LDAP authentication

2012-03-16 Thread Julie Chen
Yes, I understand that. But I'm having little problem figure out right configuration. Would someone please advice on the configuration file? [pap] WARNING: Auth-Type already set. Not setting to PAP ++[pap] returns noop Found Auth-Type = MSCHAP # Executing group from file