Re: mac authentication, log rejected device in radius.log

2013-10-18 Thread John Douglass
On 10/18/2013 11:00 AM, Alan DeKok wrote: Bertalan Voros wrote: I have one question, I would like to log a message in radius.log when a device is rejected based on its mac address. I would like to put a message saying that the device was unauthorised and the Calling-Station-Id into the

Re: freeradius 2.2.0 on Fedora and oracle module

2013-10-10 Thread John Dennis
of the build process, it will tell you what went wrong. Hint: Redirection: do_something 21 | tee -a some_file -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Version 3.0.0 has been released

2013-10-09 Thread John Dennis
I can get it directly from ftp://ftp.freeradius.org/pub/freeradius/ but there should be links. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: What does FR 2.2.2 fix?

2013-10-04 Thread John Dennis
? -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

No EAP session matching the State variable (and other various messages)

2013-09-30 Thread John Douglass
can learn from (server performance tweaks, optimizations, etc?). I've optimized as best I can the SQL component. This all seems related to the samba/winbind/ntlm_auth. - John Douglass, Sr. Systems IT/Architect, Georgia Institute of Technology - List info/subscribe/unsubscribe? See http

Re: LDAP password in log files

2013-09-30 Thread John Dennis
archives before asking questions. This has been answered multiple times. Short answer is no, the debug output is meant for debugging ONLY and during debugging it's vital to be able to see the actual data in use. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Active Directory authentication question

2013-09-24 Thread John Dennis
find the libnl library, therefore you need to install the libnl-devel package for your distribution. The devel package because includes the files you need during development as opposed to runtime. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: pap always returns noop for windows dialup authentication

2013-09-23 Thread John Dennis
different, hope you weren't doing that. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: pap always returns noop for windows dialup authentication

2013-09-23 Thread John Dennis
On 09/23/2013 02:07 PM, paul trader wrote: On Mon, 23 Sep 2013 at 13:31, John Dennis opined: JD:You still haven't sent the full debug. hi john - thanks for your reply. i sent the output from running radiusd -X, are you saying i need to run -Xxx and send that instead? No. It means all

RE: ipad ssl error in free radius

2013-09-19 Thread John Carter
John, The IPhone Configuration Utility can do remote debugging with iPads, it helped me diagnose some EAP-TLS issues. John. From: freeradius-users-bounces+jcarter=identitynetworks@lists.freeradius.org [mailto:freeradius-users-bounces+jcarter=identitynetworks.com@lists.freeradi

Re: Active Directory authentication question

2013-09-18 Thread John Dennis
cycle until your server supports the range of clients you need to support. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

ipad ssl error in free radius

2013-09-18 Thread val john
: SSL: SSL_read failed in a system call (-1), TLS session fails. Tue Sep 17 13:36:25 2013 : Auth: Login incorrect (TLS Alert read:warning:close notify): [u...@ihk.com] (from client ManagementAPs port 1 cli 00-88-65-42-50-88) Do you guys any idea what cause this issue Thank you John - List info

EAP-TLS works but not PEAP/EAP-TLS

2013-09-17 Thread John Carter
to process requests. radius.log: http://pastebin.com/9fBdxfYt eap.conf: http://pastebin.com/7dL69pmQ inner-tunnel: http://pastebin.com/BGzJSKz0 Thanks, John. -- John Carter Identity Networks jcar...@identitynetworks.com skype:jcartermeru - List info/subscribe/unsubscribe? See http

Re: EAP-TLS works but not PEAP/EAP-TLS

2013-09-17 Thread John Carter
Thanks Martin, I had already changed this in the config, but it lead me to the real issue which was that I'd added a eap inner-eap section to my eap.conf, but I also had a modules/inner-eap file from the default config. When I removed modules/inner-eap file it all works fine. Thanks again, John

Debugging No EAP session matching the State variable

2013-09-16 Thread John Douglass
-Dropped-Requests = 1824 FreeRADIUS-Total-Auth-Unknown-Types = 0 After finding some messages on the devel list, I saw some reference to memory clean up but that was a while ago so not sure how valid that comment/problem is in the 2.2.0 version. How should I approach this problem? - John

Re: free radius setup

2013-09-10 Thread John Dennis
and understand the material on this page: http://deployingradius.com/documents/protocols/compatibility.html -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: free radius setup

2013-09-10 Thread John Dennis
Lists) on the password attributes so that only the admin and the radius process can read them. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: problem with initial setup

2013-09-09 Thread John Dennis
of packages, not the freeradius packages. RHEL5 initially shipped with freeradius 1.x, but you want to be running 2.x. In RHEL we can't remove a previously shipped major version of a package so we had to add freeradius2 in order to make version 2.x available. -- John - List info/subscribe/unsubscribe

Re: problem with initial setup

2013-09-09 Thread John Dennis
: /usr/bin/radtest: No such file or directory It's in the freeradius2-utils package. % yum install /usr/bin/radtest or % yum install freeradius2-utils or read how to use the yum package manager. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: my Radius goal radius and openldap.

2013-09-09 Thread John Dennis
://www.freeradius.org/list/users.html -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: [ANN] Version 3.0.0-rc1

2013-09-08 Thread John Dennis
On 09/06/2013 04:31 PM, stefan.pae...@diamond.ac.uk wrote: I shall try a RHEL6/CentOS6 compatible build tomorrow or Monday. Shouldn't be a problem. John D, I'll update my tag, you guys will probably do the same. FYI: rc1 is packaged and built for Fedora in rawhide (unreleased latest

Re: Auth by NAS-Identifier using unlang

2013-08-06 Thread John Dennis
an extremely old version, doesn't know what OS they're on, or is trying to blame the package for a failure to read the doc. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Auth by NAS-Identifier using unlang

2013-08-05 Thread John Dennis
the exact installed rpm if you think otherwise. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: TLS-Client-Cert-Expiration date format

2013-07-25 Thread John Dennis
. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Free radius version 3.0.0 rco

2013-07-23 Thread John Dennis
. Release candidates are for testing. You can help out by building and testing it. If not when it will be ready for official release. I'll let the development team answer that one. -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Free radius version 3.0.0 rco

2013-07-23 Thread John Dennis
On 07/23/2013 08:29 AM, John Dennis wrote: On 07/23/2013 05:28 AM, manjunath uthappa ponnachana wrote: Hi, I want to download free radius version 3.0.0 rco. Please let me know the downlaod link. The tarball is available here: https://github.com/FreeRADIUS/freeradius-server/archive

Re: [ANN] Version 3.0.0-rc0

2013-07-23 Thread John Dennis
On 07/23/2013 05:18 AM, stefan.pae...@diamond.ac.uk wrote: Thanks, John. I'll use that SPEC as base for CentOS 6.x packages :-) I'm will be making some tweaks to the spec file over the near term. For instance I just realized I make a mistake with the release field in the N-V-R, the package

Re: [ANN] Version 3.0.0-rc0

2013-07-23 Thread John Dennis
yet to go through and see if these are red herrings or not. I've attached the output of the analysis tool for review. -- John $ rpmdiff-cli local-analyse scratch:6062804 Setting up before packages Setting up after packages [rpmdiff-cli]$ ./rpmdiff-checker --xml-output=test-work-dir/output.xml

Re: [ANN] Version 3.0.0-rc0

2013-07-22 Thread John Dennis
in existing releases (especially if they are not configuration compatible). FWIW the F19 train just pulled away from the station so unfortunately it's too late for F19. HTH, John -- John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

logout error

2013-07-18 Thread val john
Hi guys when users logout from the wireless network , i can see following error in the log Error Error: rlm_radutmp: Logout for NAS Wlan1 port 0, but no Login record IS there any reason for that, how can fix it Thank You John - List info/subscribe/unsubscribe? See http

Re: [ANN] Version 3.0.0-rc0

2013-07-18 Thread John Dennis
stream and we didnt' want to introduce potential incompatibility. If udpfromto is sometimes necessary and benign otherwise is there a reason for this to be a configuration option at all in 3.0? John -- jden...@redhat.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: [ANN] Version 3.0.0-rc0

2013-07-17 Thread John Dennis
use is subsumed by initscript documentation for SysV, plus many systems won't install it all. I only include it in the list for completeness. John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: [ANN] Version 3.0.0-rc0

2013-07-17 Thread John Dennis
On 07/17/2013 12:26 PM, Alan DeKok wrote: John Dennis wrote: The following are installed in either /bin or /usr/sbin but there are no corresponding man pages. Every command installed needs to have a man page. dhcpclient radattr Hmm... those two probably shouldn't be installed. They're

Re: [ANN] Version 3.0.0-rc0

2013-07-17 Thread John Dennis
On 07/17/2013 04:16 PM, Alan Buxey wrote: Hi Don't you have freeradius-utils already. .. which contains radtest etc which is very useful for admins Yes, my bad, sorry, not enough coffee. John -- jden...@redhat.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Dynamic vlan assignment with ldap groups

2013-07-16 Thread val john
Hi guys I had to also set the *use_tunneled_reply=yes* in the eap.conf to get the Dynamic vlan assignment to work On 12 July 2013 19:42, val john valjohn1...@gmail.com wrote: Hi guys , Small question , do i need to import radius ldap schema ( items like radiusprofiles ) to our ldap

Dynamic vlan assignment with ldap groups

2013-07-12 Thread val john
are Accepted DEFAULT Auth-Type := Reject ,Do i need any other configuration file to be edited to get VALN assignment to work ..? or juts users file is enough Please advice Thank You John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Dynamic vlan assignment with ldap groups

2013-07-12 Thread val john
Hi guys , Small question , do i need to import radius ldap schema ( items like radiusprofiles ) to our ldap server to get this VLAN assignment work Thank You john On 12 July 2013 18:39, Arran Cudbard-Bell a.cudba...@freeradius.org wrote: On 12 Jul 2013, at 13:57, val john valjohn1

freeradius outer identity

2013-06-26 Thread val john
proceeds working file if the client not specifying any outer identity) Can you guys please advice , how to fix this issue Thank You John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap

2013-06-24 Thread John Dennis
On 06/24/2013 12:18 PM, Julian Macassey wrote: I added in /etc/freeradius/clients.conf: client plumgrid-ldap1 { # # secret and password are mapped through the secrets # file. secret = MYSECRET shortname = ldap # # the following three fields are

Re: ldap

2013-06-24 Thread John Dennis
On 06/24/2013 02:01 PM, Julian Macassey wrote: I don't follow what you're doing. Is your radius server on 192.168.10.14, the same as your client? My radius server is: 192.168.10.16 My ldap server is: 192.168.10.14 Because it looks like your sending your access-request to

Re: ldap

2013-06-24 Thread John Dennis
On 06/24/2013 03:15 PM, Julian Macassey wrote: On 2013-06-24 at 14:32, John Dennis (jden...@redhat.com) wrote: You need to configure radius to work with ldap, but you haven't done that. You have to uncomment the ldap module from /etc/raddb/sites-enabled/default in the authorize section

Re: ldap

2013-06-21 Thread John Dennis
on a limb assume you configured the ldap module correctly and suggest you look at your firewall and make sure your ldap ports are open on both nodes. John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap

2013-06-21 Thread John Dennis
On 06/21/2013 04:34 PM, John Dennis wrote: On 06/21/2013 04:21 PM, Julian Macassey wrote: I am tring to get freeradius working with ldap. The ldap server is on the same LAN as the RADIUS server. The local user test works. I have configured all files I can think are pertinent. In debug

Re: ldap

2013-06-21 Thread John Dennis
module being configured in the output you sent. John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS 3.0 : mschap module fails to execute ntlm_auth

2013-06-07 Thread John Dennis
On 06/07/2013 10:46 AM, Bjarni Hardarson wrote: I am sure that the ntlm_auth file is at /usr/bin/ntlm_auth and if i run it manually with the expanded attributes i get the NT_KEY. root@freelab:/#/usr/bin/ntlm_auth --request-nt-key --username=vpntest --challenge=d9a8b4d1c188ae1b

Re: Service Provisioning Using AAA (FreeRadius)

2013-06-05 Thread John Dennis
to a fair amount of confusion (myself included), but after a while you get used to it. John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius | shared secret is incorrect | unprintable characters in the password

2013-06-03 Thread John Dennis
On 06/02/2013 10:00 AM, a.l.m.bu...@lboro.ac.uk wrote: Hi, check the shared secret you have defined in clients.conf on the server. check the shared secret you are using on the client check the server debug logs etc to see WHAT IP the client is coming through - if you are using a localhost

Re: Having problems authenticating client computers onto the wireless network using a Cisco AP1252 via FreeRadius 2.1.10 on Ubuntu 12.04.2 serves

2013-05-23 Thread John Douglass
Elizabeth, We have had mixed results with Ubuntu's default network manager from 12.04 until the current. Have you tried an alternative wireless manager like WICD? http://www.lawn.gatech.edu/help/gtwifi/ubuntu_troubleshooting.html - John Douglass, Sr. Systems IT/Architect, Georgia Institute

Re: FreeRadius Ceritificate Migration

2013-05-14 Thread John Dennis
On 05/14/2013 12:01 PM, Mitch Yackobeck wrote: Good morning John, I appologize for making myself look like a moron. The original message had actually been sent to someone who was helping me to potentially work thru some issues that we were seeing and trying to work out. I attempted to modify

Re: FreeRadius Ceritificate Migration

2013-05-14 Thread John Dennis
being opened and files being read. If there are permission problems you'll see error information in the strace output. HTH, John -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: FreeRadius Ceritificate Migration

2013-05-13 Thread John Dennis
On 05/13/2013 01:46 PM, Mitch Yackobeck wrote: Good afternoon All, I've taken some time over the last couple little while to work with my test environment in getting it upto date and trying out some issues with regards authenticating against multiple certificates on a single SSID for the

Re: Need help with making RPM from v2.x.x branch

2013-05-10 Thread John Dennis
assume you built from git, therefore you've got every piece of information you need to figure this out. git log will give you exact information. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http

Re: Need help with making RPM from v2.x.x branch

2013-05-08 Thread John Dennis
%{_libdir}/freeradius/rlm_*.so* -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Need help with making RPM from v2.x.x branch

2013-05-07 Thread John Dennis
On 05/07/2013 04:46 AM, Fajar A. Nugraha wrote: On Tue, May 7, 2013 at 4:28 AM, John Dennis jden...@redhat.com mailto:jden...@redhat.com wrote: These project maintained build configurations are best thought of as bleeding edge developer stuff. Make some change and you want to test

Re: redundant-load-balance for AD ntlmauth

2013-05-06 Thread John Douglass
On 5/6/2013 9:24 AM, Phil Mayers wrote: On 04/29/2013 11:03 PM, FreeRadius List wrote: Thank you I'll check with the samba people and get a better understanding of how ntlm_auth works.# (Sorry for the late reply) The short version here is: badly. ntlm_auth talks to winbind. Winbind

Re: redundant-load-balance for AD ntlmauth

2013-05-06 Thread John Douglass
connections break for some reason) I want a full restart of the service. Just testing authentication doesn't give me a full radius stack picture. - John Douglass Georgia Institute of Technology Sr. Systems Architect On 05/06/2013 12:25 PM, Phil Mayers wrote: On 06/05/2013 14:40, John Douglass wrote

Re: Need help with making RPM from v2.x.x branch

2013-05-06 Thread John Dennis
to do that work. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Need help with making RPM from v2.x.x branch

2013-05-06 Thread John Dennis
in sync doesn't seem justified. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: segfault error

2013-05-01 Thread John Dennis
What am I doing wrong on this? There is information in this bz you may find useful https://bugzilla.redhat.com/show_bug.cgi?id=602567 -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: pptpd+freeradius+ldap: which password encryption can I use?

2013-04-30 Thread John Dennis
can see them (e.g. radiusd, root). -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Procautions on upgrading FR from 2.1.10 to 2.2.0

2013-04-23 Thread John Dennis
? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Profile-Name attribute

2013-04-18 Thread John Center
Hi Alan, On 04/17/2013 05:50 PM, Alan DeKok wrote: John Center wrote: I see this isn't defined in the v2.2 FreeRADIUS internal dictionary, though there is a gap in the numbering where it would be. If I understand it correctly, it looks like one could have a profiles file with individual

Re: Profile-Name attribute

2013-04-18 Thread John Center
Hi Matthew, On 04/17/2013 05:53 PM, Matthew Newton wrote: On Wed, Apr 17, 2013 at 05:04:11PM -0400, John Center wrote: it correctly, it looks like one could have a profiles file with individual named profiles defined containing NAS-specific text that would be sent back to the NAS as is upon

RE: Setting different IDLE-TIMEOUTS based on IP Address

2013-04-17 Thread John Giordano
based on IP Address Hi, On Tue, Apr 16, 2013 at 02:05:45PM -0500, John Giordano wrote: So I man’ed unlang and then did some more reading on huntgroups and the users file. If at all possible I think we would opt for a combo of the huntgroups/users file approach. I am still not clear as to how

RE: Setting different IDLE-TIMEOUTS based on IP Address

2013-04-17 Thread John Giordano
Ok... I feel as though I am trying to solve a riddle here. I thought that may be the case but! I removed the IDLE-TIMEOUT entry from my user stanza and the NAS then rejected me I think that was because no IDLE-TIMEOUT was being sent at all from the server to the client ?!

RE: Setting different IDLE-TIMEOUTS based on IP Address

2013-04-17 Thread John Giordano
=ttmi...@lists.freeradius.org] On Behalf Of John Giordano Sent: Wednesday, April 17, 2013 11:02 AM To: 'FreeRadius users mailing list' Subject: RE: Setting different IDLE-TIMEOUTS based on IP Address Ok... I feel as though I am trying to solve a riddle here. I thought that may be the case but! I

RE: Setting different IDLE-TIMEOUTS based on IP Address

2013-04-17 Thread John Giordano
:32PM -0500, John Giordano wrote: So in huntgroups I have: ### RADIUS HUNTGROUP TEST - jg ### MSP7345 NAS-IP-Address =~ /^10\.99\.3\./ SNJ7000 NAS-IP-Address =~ /^10\.3\.99\./ LAB7000 NAS-IP-Address =~ /^192\.168\.0./ Testing it here, I'm not convinced that =~ is working

RE: Setting different IDLE-TIMEOUTS based on IP Address

2013-04-17 Thread John Giordano
...@lists.freeradius.org [mailto:freeradius-users-bounces+john.giordano=ttmi...@lists.freeradius.org] On Behalf Of John Giordano Sent: Wednesday, April 17, 2013 1:47 PM To: FreeRadius users mailing list Subject: RE: Setting different IDLE-TIMEOUTS based on IP Address Hi all, We are very appreciative

Profile-Name attribute

2013-04-17 Thread John Center
. -John -- John Center Villanova University - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Setting different IDLE-TIMEOUTS based on IP Address

2013-04-16 Thread John Giordano
Hi, So I have done a fair amount of RTFM'ing and search engining but am stumped. Perhaps someone on this list has successfully done what we are trying to do: Have our FreeRADIUS Server assign a different IDLE-TIMEOUT Value based on what IP Address is contacting the RADIUS server. OS: CentOS

RE: Setting different IDLE-TIMEOUTS based on IP Address

2013-04-16 Thread John Giordano
-IP-Address == 10.3.99.0/24 IDLE-TIMEOUT = 60 Thanks! -jg From: Alan Buxey [mailto:a.l.m.bu...@lboro.ac.uk] Sent: Tuesday, April 16, 2013 10:45 AM To: John Giordano; freeradius-users@lists.freeradius.org Subject: Re: Setting different IDLE-TIMEOUTS based on IP Address If your

Re: Freeradius +LDAP + Samba integrates to Active Derectory

2013-04-15 Thread John
Thanks. Alan --- 13年4月12日,周五, Alan DeKok al...@deployingradius.com 写道: 发件人: Alan DeKok al...@deployingradius.com 主题: Re: Freeradius +LDAP + Samba integrates to Active Derectory 收件人: FreeRadius users mailing list freeradius-users@lists.freeradius.org 日期: 2013年4月12日,周五,下午9:48 John wrote: We

Freeradius +LDAP + Samba integrates to Active Derectory

2013-04-12 Thread John
Hi all,   We deploy freeradius integrated to Active Directory, but the AD enabled Require signing option (see the attachement).   net join is OK after we set LDAP SASL wrapping to 'sign'. But LDAP search failed.  Is there a way to let LDAP search work? Can someone show me some reference or

Re: compile with ldap support

2013-04-11 Thread John Dennis
as a recipe for building. If you're not sure what ingredients you need then consult the recipe. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Fwd: How to configure RADIUS +LDAP using SASL/Certificate based binding instead of usernames and passwords

2013-04-10 Thread John Dennis
On 04/10/2013 12:03 AM, pramod kulkarni wrote: Thanks John for the reply. can I use EAP-TLS method of authentication with LDAP as backend datastore to check usernames and passwords. It would be like I bind to RADIUS server with EAP-TLS method using certificate and check

Re: Fwd: How to configure RADIUS +LDAP using SASL/Certificate based binding instead of usernames and passwords

2013-04-09 Thread John Dennis
supported GSSAPI. HTH, John -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Server dosn't detect any requests except from localhost

2013-04-09 Thread John Dennis
is completely independent of whether the port is blocked, you have to check both. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

New/updated dictionary files for Meru and Trapeze

2013-03-28 Thread John Carter
Hi, Please find attached a brand-new Meru dictionary file and an updated Trapeze dictionary file (updated based on 2.2.0). Do you want diffs? Regards, John. dictionary.trapeze Description: Binary data dictionary.meru Description: Binary data - List info/subscribe

RE: New/updated dictionary files for Meru and Trapeze

2013-03-28 Thread John Carter
To: FreeRadius users mailing list Subject: Re: New/updated dictionary files for Meru and Trapeze On 28 Mar 2013, at 10:35, John Carter jcar...@identitynetworks.com wrote: Hi, Please find attached a brand-new Meru dictionary file and an updated Trapeze dictionary file (updated based on 2.2.0

How can I change proxy based on username?

2013-03-26 Thread John Horne
{ auth_pool = local_proxies } = So the realm should be stripped from the username. Anyone any ideas about this? Thanks, John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK Fax: +44 (0)1752 587001 - List info/subscribe

Re: How can I change proxy based on username?

2013-03-26 Thread John Horne
On Tue, 2013-03-26 at 14:13 +, Phil Mayers wrote: On 26/03/2013 12:50, John Horne wrote: Hello, Using Freeradius 2.1.10 I have been trying to see if I can proxy a request to a remote server but using a different User-Name attribute based on the original request User-Name attribute

Re: How can I change proxy based on username?

2013-03-26 Thread John Horne
On Tue, 2013-03-26 at 15:35 +, Phil Mayers wrote: On 26/03/2013 15:12, John Horne wrote: What is the upstream proxy? Microsoft domain controller (DC). As in, Microsoft NPS running on a DC? As far as I know, yes. I don't deal with the Microsoft side of this. Just to check I

Re: How can I change proxy based on username?

2013-03-26 Thread John Horne
wanted, and it didn't break EAP. I also checked the other formats that we wanted to allow, and they all worked fine too. I'll do further testing tomorrow, but it looks good. John. -- John Horne, Plymouth University, UK Tel: +44 (0)1752 587287Fax: +44 (0)1752 587001 - List info/subscribe

Re: Trying to integrate with LDAP

2013-03-14 Thread John Dennis
is a recommended configuration. Until you have these concepts firmly under your grasp you'll likely be frustrated trying to modify the configuration. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http

Re: Release of Version 2.2.1

2013-03-08 Thread John Dennis
before 2.2.1 goes out the door. I think the fix is fairly minor. Since this just came up about 5 minutes ago I don't have all the details at hand or a patch yet, but I'll do that soon. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info

eap-fast on freeradius 2

2013-02-25 Thread John
Hi, I found freeRADIUS support eap-fast. Can I use eap-fast in eap2, meanwhile use other eap types in eap?  Does EAP fragmentation issue fixed in eap2? Best, -John - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-TLS certificate problem

2013-02-19 Thread John Dennis
,':=' AS op FROM dual ORDER BY RC_ID [sql] User found in radcheck table Found Auth-Type = Accept Found Auth-Type = EAP Warning: Found 2 auth-types on request for user '001AAD3F8165' -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe

Re: radiusd starts but rejects test user

2013-02-15 Thread John Dennis
. It says no response from server (timed out) over and over. Clearly this has nothing to do with Radius and is a networking problem. Fix your network. (Hint: the firewall on one of your boxes is blocking port 1812, probably the box with your Radius server). -- John Dennis jden...@redhat.com

Re: git question

2013-02-14 Thread John Dennis
is can be very useful for setting up your .git/config so you don't have to deal with verbose syntax. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Upgrading from FR 2.1.10 to 2.2.x

2013-02-13 Thread John Dennis
freeradius -qV before installing will verify the installed files and tell you any you've modified. If you install via make install nothing will be preserved. Any other data stored in your backends (e.g. SQL, LDAP) shouldn't be affected and you're on your own to back that up anyway. HTH, John

Re: Load Balancing Issue

2013-02-12 Thread John Dennis
of mine it is too slow. I have changed 'max_requests' in radiusd.config. And also remove unnecessary processing on radius server (that is proxying requests). Now tell me what else can I do?? :( For starters try reading Alan's response he so graciously provided to you. -- John Dennis jden

Re: Freeradius and EAP_TLS Problem:

2013-01-23 Thread John Dennis
) -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius and EAP_TLS Problem:

2013-01-23 Thread John Dennis
On 01/23/2013 12:24 PM, John Dennis wrote: On 01/23/2013 04:32 AM, Armin Maier wrote: Hello! I have been using Windows 7, Freeradius 2.1.10 from Debian Squeeze, HP MSM710 WLAN controller and EAP_TLS Computer Certificate Authentication for a log time and worked perfect. I used Certificates

Re: suddenly problem with certificates / error in SSLv3 read client certificate B

2013-01-23 Thread John Dennis
about incomplete data my best guess is the client files might have be corrupted when the ca command failed. If it were only a CA key change issue you should have just gotten a bad signature verification failure. HTH, John -- John Dennis jden...@redhat.com Looking to carve out IT costs

Re: AD Authentication Permissions

2013-01-09 Thread John Dennis
bind as will need permission to view that portion of the ldap tree. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: AD Authentication Permissions

2013-01-09 Thread John Dennis
notfound -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Failure with TLS authentication and Freeradius on Fefora-17

2013-01-08 Thread John Dennis
. Now you're going to have to put that information to use. You really do have to invest the energy into learning how the pieces fit together. -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http

Re: Failure with TLS authentication and Freeradius on Fefora-17

2013-01-08 Thread John Dennis
On 01/08/2013 03:53 PM, Ajay Garg wrote: On Tue, Jan 8, 2013 at 6:45 PM, John Dennis jden...@redhat.com mailto:jden...@redhat.com wrote: On 01/08/2013 05:10 AM, Ajay Garg wrote: Could you please specify the order of scripts to be run, so that proper certificates

Re: Failure with TLS authentication and Freeradius on Fefora-17

2013-01-07 Thread John Dennis
differently in Fedora-17 freeradius? -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Failure with TLS authentication and Freeradius on Fefora-17

2013-01-07 Thread John Dennis
to the configuration parameters for each software component (see above). -- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

  1   2   3   4   5   6   7   8   9   10   >