Re: Newbie: General Questions About Installation

2005-08-09 Thread Paul Hampson
On Mon, Aug 08, 2005 at 08:20:25AM -0700, Kris Benson wrote: FreeRadius users mailing list freeradius-users@lists.freeradius.org on August 7, 2005 at 11:16 -0800 wrote: On Sun, 7 Aug 2005 15:05:50 +0100 Install FreeBSD, go to /usr/ports/net/freeradius and simply type make install clean

Re: Newbie: General Questions About Installation

2005-08-09 Thread Paul Hampson
On Sat, Aug 06, 2005 at 02:09:59PM -0700, Kris Benson wrote: FreeRadius users mailing list freeradius-users@lists.freeradius.org on August 6, 2005 at 00:25 -0800 wrote: in console just type apt-get install freeradius or use synaptic package managed (x windows / gnome ) and do a search for

Re: Disconnect-Request packet

2005-07-28 Thread Paul Hampson
On Thu, Jul 28, 2005 at 06:20:35PM -0700, N White wrote: That's correct. Read my second reply. So other then writing custom scripts, is there a way for the RADIUS server(FreeRADIUS) to be told to send a disconnect packet to the NAS that a particular user is logged in to(NAS could vary -

Re: rlm_sql_mysql make error for 1.0.4 and snapshot-20050718

2005-07-19 Thread Paul Hampson
On Mon, Jul 18, 2005 at 05:22:51PM +0200, Thor Spruyt wrote: Hi, `/home/thor/freeradius-1.0.4/src/modules/rlm_sql/drivers/rlm_sql_mysql' gcc -g -O2 -D_REENTRANT -D_POSIX_PTHREAD_SEMANTICS -DOPENSSL_NO_KRB5 -Wal l -D_GNU_SOURCE -DNDEBUG -I../.. -I../../../../include -I'/usr/include/mysq l'

Re: Need help installing 1.0.4 on RHEL update 4

2005-07-08 Thread Paul Hampson
On Fri, Jul 08, 2005 at 11:36:33AM -0400, Ken George wrote: I am not a RHEL expert, but have installed the 1.0.1 RPM of freeradius. I am trying to get freeradius to authenticate against a Windows 2003 Active Directory. Once I can get radtest to work on the server I'll configure the clients

Re: [radius] Freeradius/MySql problem

2005-07-02 Thread Paul Hampson
On Sat, Jul 02, 2005 at 10:42:44AM -0700, Radius wrote: OK, let me try this way, when our wholesale provider receives a realm, they know where to send the request. If the user sends [EMAIL PROTECTED] or [EMAIL PROTECTED] our radius regardless if I have lower_user before/after/no They

Re: external script in defunct state

2005-06-27 Thread Paul Hampson
On Mon, Jun 27, 2005 at 12:29:27PM +0500, rashad wrote: I wan to run external script when Acct-Stop packets received. My acct_users file: DEFAULT Acct-Status-Type == Stop Exec-Program = /usr/local/sbin/testacct.php Script runs and executes normally but stays in defunct state for

Re: external script stays in defunct state after executing

2005-06-27 Thread Paul Hampson
On Mon, Jun 27, 2005 at 09:02:04PM +0500, rashad wrote: External script stays in defunct state after successfull executing. My configuration: OS: Debian Linux 3.0 Freeradius: 1.0.4 acct_users file: DEFAULT Acct-Status-Type == Stop Exec-Program = /usr/local/sbin/testacct.php

Re: x99_rlm.c:550: error: label at end of compound statement

2005-06-25 Thread Paul Hampson
On Sat, Jun 25, 2005 at 02:00:27PM +0600, [EMAIL PROTECTED] wrote: Здравствуйте, Paul. Вы писали 25 июня 2005 г., 6:49:39: PH On Fri, Jun 24, 2005 at 02:58:14PM +0600, [EMAIL PROTECTED] wrote: make faild with this error... but new error was occured :( gmake[6]: Entering directory

Re: Debian .deb Installation Version 1.0.2 Ca.all dosn' exist

2005-06-22 Thread Paul Hampson
On Tue, Jun 21, 2005 at 03:21:17PM +0200, Michael Langer wrote: HI, you have done it at weekend? Today i try apt-upgrade and nothing has changed. The current Version is 1.0.2 in sarge, isn't it? Sorry, I didn't do the update until Monday, and my sponsor picked a problem with it, so I've just

Re: How to solve alive user who actually has loged off

2005-06-20 Thread Paul Hampson
On Mon, Jun 20, 2005 at 06:54:45PM +0800, ??? wrote: I want to do something to make freeradius to believe that user testuser is not alive,but do not konw how to do.Is there a way to solve the problem? Have a look at Simultaneous-Use in the docs directory. -- Paul TBBle Hampson, on an

Re: stripping a slash?

2005-06-18 Thread Paul Hampson
On Fri, Jun 17, 2005 at 10:00:16AM -0500, Chris Sigler wrote: Okay, checked into it, and we don't use a / as a delimiter at any point that we can find. In that case, freeradius -X and see if you can spot where it's happening. -- Paul TBBle Hampson, on an alternate email client. - List

Re: 1.0.4

2005-06-16 Thread Paul Hampson
On Thu, Jun 16, 2005 at 10:51:09AM +0200, Nicolas Baradakis wrote: Paul Hampson wrote: Could you also get 1.0.4 ready? It should be released soon, and I've been busy... 1.0.4's autoconf'd and tagged in CVS as release_1_0_4, and I believe is ready to ship. (Only build-tested

Re: 1.0.4

2005-06-16 Thread Paul Hampson
On Thu, Jun 16, 2005 at 12:04:51PM +0200, Nicolas Baradakis wrote: Paul Hampson wrote: Is it too late now to include in 1.0.4 the clients.conf(5) manpage added recently in CVS head ? Only if Alan's already taken a snapshot to tarball. I've just imported and tagged it for release_1_0_4

Re: Undefined symbol with eaptls / freeradius 1.0.3 (debian)

2005-06-16 Thread Paul Hampson
On Thu, Jun 16, 2005 at 02:57:37PM +0200, Antonio-Blasco Bonito wrote: I compiled and installed freeradius-1.0.3 on debian sarge. It runs. But when using rlm_eap_ttls-1.0.3.so I'm having the same problem described six months ago by Julien (see below). Then I tried the latest

Re: stripping a slash?

2005-06-16 Thread Paul Hampson
On Thu, Jun 16, 2005 at 04:51:53PM -0500, Chris Sigler wrote: For some reason, when we run a query against radius and the username starts with a slash, it seems to ignore the slash. As a result, a user is able to log in with both bob and /bob, although only one is right. Any ideas what could

Re: stripping a slash?

2005-06-16 Thread Paul Hampson
On Thu, Jun 16, 2005 at 08:15:32PM -0500, Chris Sigler wrote: We're using mysql to authenticate... Sorry, I guess I should have mentioned that. If I'm not mistaken, this won't apply... Nope. Using rlm_sql has no bearing on which preprocess modules are run (unless you've got a very very strange

Re: Generating freeradius 1.0.3

2005-06-15 Thread Paul Hampson
On Mon, Jun 13, 2005 at 01:43:36PM -0400, Software Development Group wrote: Running Debian, I have done a $ fakeroot dpkg-buildpackage -b on the freeradius 1.0.3 directory. I get a warning saying That should be dpkg-buildpackage -rfakeroot -b, although the above should also work... remember

Re: Debian .deb Installation Version 1.0.2 Ca.all dosn' exist

2005-06-15 Thread Paul Hampson
On Tue, Jun 14, 2005 at 03:09:20PM +0200, Michael Langer wrote: Hi @all, i read some HowTo's for installing FreeRadius/PEAP and they have used the CA.all script to create the certificats. But i can't find this script after installing FreeRadius deb version 1.0.2 on my PC. I have to install

Re: Generating freeradius 1.0.3

2005-06-15 Thread Paul Hampson
On Wed, Jun 15, 2005 at 10:24:23AM -0400, Software Development Group wrote: Yes, it generated .deb packages. I have run them and apparently they installed correctly but when I run the application I get an: radiusd.conf[2] Failed to link to module 'rlm_sqlcounter':

Re: freeradius 1.0.4

2005-06-15 Thread Paul Hampson
On Thu, Jun 16, 2005 at 03:29:05PM +1200, Andrew Thompson wrote: Hi, I maintain the FreeRADIUS port for FreeBSD and am holding off upgrading from 1.0.2 due to the imminent release of 1.0.4 (06 June). There doesn't seem to be any discussion on the mailing lists, is 1.0.4 due soon or should I

1.0.4 (Was: Debian .deb Installation Version 1.0.2 Ca.all dosn' exist)

2005-06-15 Thread Paul Hampson
On Wed, Jun 15, 2005 at 12:53:49PM -0400, Alan DeKok wrote: [EMAIL PROTECTED] (Paul Hampson) wrote: If you're working from the version in the Debian archive, I'll make an upload of 1.0.3 to address this by the weekend. If you're working from the release on the website, you'll have to grab

Re: Exec-Program-Wait vs rlm_exec

2005-05-06 Thread Paul Hampson
On Thu, May 05, 2005 at 08:22:44AM -0600, [EMAIL PROTECTED] wrote: [EMAIL PROTECTED] wrote: On Tue, May 03, 2005 at 10:23:05AM -0600, [EMAIL PROTECTED] wrote: Hi, what do you consider the best solution wheen you need to run an external program to make aditional checks when an access

Re: Upgrading freeradius 1.0.2 with freeradius-snapshot-20050502

2005-05-06 Thread Paul Hampson
On Thu, May 05, 2005 at 01:05:33PM -0400, Alan DeKok wrote: [EMAIL PROTECTED] (Paul Hampson) wrote: Which will give you the current 1.0.3 candidate. Then you can cvs update whenever something else comitted to it. We should probably release 1.0.3 soon. Well, I've just been handed some

Re: Upgrading freeradius 1.0.2 with freeradius-snapshot-20050502

2005-05-04 Thread Paul Hampson
On Mon, May 02, 2005 at 10:54:39PM -0700, Abdul Lateef wrote: Hi guys, I installed freeradius 1.0.2 on my redhat box. all thing is working well. But there is some error like: Mon May 2 14:43:09 2005 : Error: Exec-Program: Abnormal child exit: No child processes Mon May 2 15:06:36 2005

Re: Exec-Program-Wait vs rlm_exec

2005-05-04 Thread Paul Hampson
On Tue, May 03, 2005 at 10:23:05AM -0600, [EMAIL PROTECTED] wrote: Hi, what do you consider the best solution wheen you need to run an external program to make aditional checks when an access request in received, exec-program-wait or rlm_exec, im using exec-program-wait, sould i use rlm_exec

Re: clients.conf - allowing all?

2005-05-04 Thread Paul Hampson
On Wed, May 04, 2005 at 06:33:13AM -0700, Jacques wrote: Hi. Quick question. Is there any way to do some sort of allow all on clients.conf. So FreeRadius wont care where the client is coming from, as long as it has the secret. The reason (obviously) is my radius server is external and NAS

Re: Best Way to Run Radius Server over Multi - Satellite Pops

2005-05-02 Thread Paul Hampson
On Mon, May 02, 2005 at 11:28:52PM +0200, Sarkis Gabriel wrote: Brilliant that is something to work on, i am already using mysql as a backend for my user list, so i can use that with replication. I just want to make sure does it replicate both ways or just main Replication server to

Re: Error: Dropping conflicting packet due to unfinished request

2005-04-08 Thread Paul Hampson
On Thu, Apr 07, 2005 at 02:05:04PM -0400, Alan DeKok wrote: Juan Nin [EMAIL PROTECTED] wrote: also, another issue that worries me is that if I change my authentication method on /etc/raddb/users so as to be the following: Ah... That's a bug in the run external program code. It's fixed

Re: Automated logout for rogue/zombie user sessions

2005-04-06 Thread Paul Hampson
On Wed, Apr 06, 2005 at 03:05:41PM +0200, John Eckert wrote: Hi List, is there a way to log out zombie users. I mean users that did a login (auth. + acct.) but no logout because of a problem with the NAS. This happens when the NAS gets rebooted due to a power fault with logged in users. No

Re: Freeradius and MySQL -- missing libraries?

2005-04-02 Thread Paul Hampson
On Fri, Apr 01, 2005 at 12:42:18PM -0800, Rick Kunkel wrote: Hello all, When I run an ldd though, I see this: # ldd rlm_sql_mysql.so libmysqlclient.so.12 = not found libz.so.1 = /usr/lib/libz.so.1 (0x4000b000) libcrypt.so.1 = /lib/libcrypt.so.1 (0x40019000)

Re: rlm_exec: Wait=yes but no output defined

2005-03-31 Thread Paul Hampson
On Thu, Mar 31, 2005 at 11:33:00AM -0800, Rick Kunkel wrote: Heya all, I'm getting this warning when running. The longer version, in debuggin mode, is this: Module: Loaded exec exec: wait = yes exec: program = (null) exec: input_pairs = request exec: output_pairs = (null) exec:

Re: Running radiusd as the nobody user

2005-03-31 Thread Paul Hampson
On Thu, Mar 31, 2005 at 04:29:28PM -0600, Dennis Comeaux wrote: Our security team wants radiusd running as a secure user. I've attempted to run it as nobody by editing radiusd.conf but I get a bunch of permission denied errors: The debian build scripts (debian/rules and debian/*.postinst)

Re: FreeRADIUS and MySQL+SSL

2005-03-31 Thread Paul Hampson
On Fri, Apr 01, 2005 at 01:34:37AM +0200, Wolfram Schlich wrote: * Wolfram Schlich [EMAIL PROTECTED] [2005-03-19 13:11]: * Paul Hampson [EMAIL PROTECTED] [2005-03-19 04:56]: On Sat, Mar 19, 2005 at 03:52:52AM +0100, Wolfram Schlich wrote: * Wolfram Schlich [EMAIL PROTECTED] [2005-03-17

Re: No FreeRADIUS on Debian in the future ?

2005-03-30 Thread Paul Hampson
On Wed, Mar 30, 2005 at 06:28:46PM +, Mark Wasmer wrote: Today i've read the Debian-Weekly-News March 29th, 2005 and got worried : Build-Dependency against libtool 1.4. Andrew Pollock noticed that five packages still declare a build-dependency against libtool 1.4 which is orphaned and

Re: (Fwd) Problem using Freeradius and Mysql

2005-03-25 Thread Paul Hampson
On Fri, Mar 25, 2005 at 11:52:03AM +0100, Christoph Galuschka wrote: Hello, solved the problem myself. There seems to be a change in rlm_sql.c which causes the difference in translation of %. thanks and regards Christoph Galuschka --- Forwarded message follows --- From:

Re: FreeRADIUS and MySQL+SSL

2005-03-19 Thread Paul Hampson
On Sat, Mar 19, 2005 at 02:06:56PM +0100, Wolfram Schlich wrote: * Paul Hampson [EMAIL PROTECTED] [2005-03-19 04:56]: On Sat, Mar 19, 2005 at 03:52:52AM +0100, Wolfram Schlich wrote: * Wolfram Schlich [EMAIL PROTECTED] [2005-03-17 00:55]: * Wolfram Schlich [EMAIL PROTECTED] [2005-03-16

Re: FreeRADIUS and MySQL+SSL

2005-03-18 Thread Paul Hampson
On Sat, Mar 19, 2005 at 03:52:52AM +0100, Wolfram Schlich wrote: * Wolfram Schlich [EMAIL PROTECTED] [2005-03-17 00:55]: * Wolfram Schlich [EMAIL PROTECTED] [2005-03-16 09:05]: Hey guys, we would like to implement the following setup: - FreeRADIUS radiusd on machine A - MySQL

Re: Compiling freeradius 1.0.2 with mssql support

2005-03-16 Thread Paul Hampson
On Wed, Mar 16, 2005 at 01:46:09PM +0100, Achim Schmidt wrote: Hello, I'm stoill trying to compile freeradius-1.0.2 with mssql support and without mysql. Freetds is installed and working. I cant find that the lib is builded in the make run. Also i'm missing an other file. If I look into

Re: question about ippools

2005-03-10 Thread Paul Hampson
On Thu, Mar 10, 2005 at 11:31:48AM -0900, Terry J Fike Jr wrote: I'm wondering if it is possible to set up an ippool for a single user? Right now our users are flatfiled in the users file. anyone with a static has the info with their username, all the rest of the users get their ip

Re: question about ippools

2005-03-10 Thread Paul Hampson
On Thu, Mar 10, 2005 at 03:45:24PM -0900, Terry J Fike Jr wrote: It all depends on how you get the Pool-Name attribute added to the user's configuration attribute list. If it's added for one user when that user comes from a specific NAS, then only that user on that specific NAS will get an

Re: Packet of Disconnect

2005-03-02 Thread Paul Hampson
On Tue, Mar 01, 2005 at 12:52:52PM +1100, Mitchell, Michael J wrote: The information is in the PoD request. Kind of. From the NAS's perspecitive, the PoD only needs to contains the Acct-Session-Id. However obviously in order to proxy a request we at least need the NAS-IP-Address. I use

Re: Error: SSL_new in -lssl...no - went thru the docs and faq and google already before posting....

2005-02-27 Thread Paul Hampson
On Mon, Feb 28, 2005 at 12:05:33AM +1100, Michael Mitchell wrote: Thanks for the reply Stefan, I haven't tried linking freeRADIUS with static libraries yet, and I must admit I missed the --disable-shared in J.Ho's email. Well picked up... I'm guessing the problem stems from this part of the

Re: Undefined symbol with eaptls / freeradius 1.0.1 (debian)

2005-02-22 Thread Paul Hampson
On Tue, Feb 22, 2005 at 10:44:08AM +1100, Tom wrote: I've setup freeradius 1.0.1 on debian (sarge 2.6 kernel). I've included all the modules and set freeradius to use PEAP. When my authenticator passes the request over to the freeradius server I get (among other things): freeradius:

Re: Undefined symbol with eaptls / freeradius 1.0.1 (debian)

2005-02-22 Thread Paul Hampson
On Wed, Feb 23, 2005 at 10:24:45AM +1100, Tom wrote: Thanks very much for your reply I appreciate your help and I've just got a couple of followup questions. Just upgrading libtool won't work, as libtool 1.5 requires a more recent version of autoconf than is used in FreeRADIUS 1.0.1. As the

Re: rlm_ippool - reliance on NAS-Port parameter

2005-02-18 Thread Paul Hampson
On Fri, Feb 18, 2005 at 12:19:05PM -0500, Jeff Synnestvedt wrote: I'm a little confused as to the necessity of having the NAS-Port because wouldn't a normal accounting Stop packet have the IP address in it anyway which would tell rlm_ippool which IP to free up. And if the Stop packet is

Re: how can freeradius log the transaction and failed logins?

2005-02-05 Thread Paul Hampson
On Fri, Feb 04, 2005 at 08:59:54PM +0700, Marendra Nutriaji wrote: Hi all, I use Freeradius 1.0.1 dialupadmin, and mysql under Fedora core 2, nad Using Patton 2960 as my Nas. Everything works fine, except when my user failed logging in with any reason, freeradius didnot put those failed

Re: Disabling radwtmp/radutmp For Some Clients

2005-02-05 Thread Paul Hampson
On Fri, Feb 04, 2005 at 03:05:59PM -0800, A. Clausen wrote: I was wondering if there was a way I could disable writing to radutmp and radwtmp for some clients, or whether this is an all or nothing proposition. I think you can apply Post-Auth-Type (see the documentation) to this problem, but

Re: configure script nightmare with ucd-snmp

2005-02-01 Thread Paul Hampson
On Tue, Feb 01, 2005 at 06:59:36PM +1100, Mitchell, Michael J wrote: I'm attempting to build freeRADIUS 1.0.1 on Solaris 9 with ucd-snmp 4.2.6 I've been struggling to get the configure script to successfully recognise ucd-snmp and thus enable it for compilation in freeradius. I'm on Solaris

Re: radwtmp trouble

2005-01-19 Thread Paul Hampson
On Wed, Jan 19, 2005 at 01:11:55PM -0600, Sam wrote: I think there may be a problem in the way radwtmp is being written (at least in the Freeradius that ships with RedHat ES3). Testing: I copied a radwtmp file over from my old RedHat 7.2 server (running Cistron 1.6) and both last and radlast

Re: radutmp woes

2005-01-17 Thread Paul Hampson
On Sun, Jan 16, 2005 at 11:15:35PM -0600, Sam Morris wrote: Hello After much hair pulling I have Freeradius 1.0.1 working nearly 100%. But I'm having issues with radutmp (at least I think that's where the trouble lies). When I do a radlast, it says this: [EMAIL PROTECTED] radius]# radlast

Re: Dynamic IP addres on EAP/TLS session

2005-01-17 Thread Paul Hampson
On Mon, Jan 17, 2005 at 05:23:04PM +1100, Jacques VUVANT wrote: How Can I allow dynamic IP address for a EAP/TLS session. DHCP server on same machine as Freeradius, seems not to work. The DHCP server needs to be on the EAP gatekeeper (I forget the proper name, the thing that isn't the

Re: Dynamic IP addres on EAP/TLS session

2005-01-17 Thread Paul Hampson
On Mon, Jan 17, 2005 at 09:49:48AM -0600, Justin Guidroz wrote: I'm running Freeradius on the same server that also serves as my LDAP server, DHCP server, and DNS server, and I have had no problems getting DHCP addresses using EAP-TTLS or EAP-TLS. Does the EAP gateway thingy relay DHCP

Re: Solaris vs. Linux: eap - mschap - mschapv2 failure: smbencryptNT-pa ssword hash different for Sparc and Intel

2005-01-17 Thread Paul Hampson
On Mon, Jan 17, 2005 at 07:01:22PM +0100, [EMAIL PROTECTED] wrote: Ok, summary: 1. EAP on Solaris fails, EAP on Linux works. 2. Version problems with freeradius can be excluded, can we ? Try the current 1.0.2 snapshot from the CVS release_1_0 tree. This could be a bigendian/64 bit issue with

Re: character substitution

2005-01-15 Thread Paul Hampson
On Thu, Jan 13, 2005 at 11:55:40AM -0500, Brian Fennimore wrote: I'm having a problem with freeradius interpreting special characters incorrectly. It's translating the UTF-8 to some kind of quoted-printable form when it prepares the information for accounting. You could add the relevant bytes

Re: Debian testing = no PEAP/TLS/TTLS support?

2005-01-15 Thread Paul Hampson
On Sat, Jan 15, 2005 at 06:47:38AM +0100, Sven Juergensen wrote: the start/stop script of the debian freeradius package is faulty as well. let me know if you need a modified script and i'll mail it to you. Alternatively, file a bug report and then everyone can benefit from a fix to whatever's

Re: Debian testing = no PEAP/TLS/TTLS support?

2005-01-15 Thread Paul Hampson
On Sat, Jan 15, 2005 at 11:30:03AM +0100, pascal wrote: Hi, rlm_eap: Loaded and initialized type md5 rlm_eap: Loaded and initialized type leap gtc: challenge = Password: gtc: auth_type = PAP rlm_eap: Loaded and initialized type gtc rlm_eap: Failed to link EAP-Type/tls: rlm_eap_tls.so:

Re: reading other radius server's radutmp instead of using radrelay

2005-01-06 Thread Paul Hampson
On Thu, Jan 06, 2005 at 05:23:45PM +0800, Rohaizam Abu Bakar wrote: what is the setting related in order for radius to check database (insted of radutmp) in order to control single login (or Simultaneous use)... Put an instance of rlm_sql in the session stanza in radius.conf, and look in

Re: make fails because of libltdl

2004-12-30 Thread Paul Hampson
On Fri, Dec 31, 2004 at 01:33:45AM +0100, Thor Spruyt wrote: I downloaded lastest nightly build and the libltdl isssue is still there. [EMAIL PROTECTED] freeradius-snapshot-20041230]$ make gmake[1]: Entering directory `/home/thor/freeradius-snapshot-20041230' Making all in libltdl...

Re: rlm_mschap compilation error - Where to look ?

2004-12-29 Thread Paul Hampson
On Wed, Dec 29, 2004 at 10:37:20AM -0500, Alan DeKok wrote: Aime [EMAIL PROTECTED] wrote: When compiling Freeradius , i have the following error during rlm_mschap compilation. Where do I have to look ? The radius_exec_program function was changed yesterday. rlm_mschap wasn't updated,

Re: problems with radutmp

2004-12-24 Thread Paul Hampson
On Fri, Dec 24, 2004 at 09:39:58AM -0200, Luiz Gustavo Anflor Pereira wrote: I am using freeradius 1.0.1. Let me try to understand. If a client loses its connection, we can use radzap to comunicate with the NAS. Then it sends back a stop packet, and the login is released. Is that correct?

Re: regarding stale IP in ippool

2004-12-22 Thread Paul Hampson
On Wed, Dec 22, 2004 at 07:10:32PM +0100, Alfred H. Dahl wrote: If a Mikrotik pppoe-server stops, or the accounting-stop-packet from the pppoe-server does not reach the radius-server, the IP-address is not freed from the ip_pool, meaning we get stale sessions in the IP-Pool.

Re: problems with radutmp

2004-12-20 Thread Paul Hampson
On Mon, Dec 20, 2004 at 02:19:11PM -0200, Luiz Gustavo Anflor Pereira wrote: hello all I have a problema concerning radutmp. Here is the situation: The command radwho | grep 7969 gives me the output: rsf7969rsf7969 PPP 999 Fri 16:20 200.96.10 If i use the option -r,

Re: debian compile issues in conjunction with eap

2004-12-17 Thread Paul Hampson
On Fri, Dec 17, 2004 at 03:47:31AM +0100, Sven Juergensen wrote: and again, http://bugs.freeradius.org/show_bug.cgi?id=98 configuring with --disable-shared make halts at the message of my first email, something with the rlm_x99_token. some strace output: [..] [..]

Re: Execute a script at the end of a session

2004-12-16 Thread Paul Hampson
On Thu, Dec 16, 2004 at 09:12:59AM +, Santiago Balaguer García wrote: The action you proposed is create a new attribute, for instance, Exec-Program-End, and insert in the radreply table. For example, if I have this entries in this table:

Re: regarding stale IP in ippool

2004-12-16 Thread Paul Hampson
On Thu, Dec 16, 2004 at 09:34:21PM +0100, Alfred H. Dahl wrote: we have a problem with our IP-POOL. We run pppoe-servers from Mikrotik, and we assign IP to the client using freeradius 0.9.3. If a Mikrotik pppoe-server stops, or the accounting-stop-packet from the pppoe-server does

Re: rlm_eap_tls not built because OpenSSL not found

2004-12-10 Thread Paul Hampson
On Fri, Dec 10, 2004 at 03:02:54AM -0600, Tim Winders wrote: I have tried both 1.01 and cvs-20041209 with the same results. I would like to be able to use eap/tls, but, in the configure, I keep getting a warning that eap/tls will silently not be built because it requires OpenSSL. I have

Re: Execute a script at the end of a session

2004-12-10 Thread Paul Hampson
On Fri, Dec 10, 2004 at 09:23:12AM +, Santiago Balaguer García wrote: Hi, I am using RADIUS for more than 9 months and for each client a initial script is executed since the radreply table in MySQL has a field:

Re: Execute a script at the end of a session

2004-12-10 Thread Paul Hampson
On Fri, Dec 10, 2004 at 04:38:05PM +, Santiago Balaguer García wrote: I read acct_users and others files, but what I want to do is to add some register in the MySQL DB and can execute a different script to each user. Create yourself a new attribute, with the name of the script, create a

Re: regarding stale IP in ippool

2004-12-10 Thread Paul Hampson
On Fri, Dec 10, 2004 at 10:20:36AM +0100, Alfred H. Dahl wrote: we have a problem with our IP-POOL. We run pppoe-servers from Mikrotik, and we assign IP to the client using freeradius 0.9.3. If a Mikrotik pppoe-server stops, or the accounting-stop-packet from the pppoe-server does not reach

Re: Undefined symbol with eaptls / freeradius 1.0.1 (debian)

2004-12-07 Thread Paul Hampson
On Tue, Dec 07, 2004 at 03:16:47PM +0100, Julien CABESSUT wrote: I'm trying to set up a freeradius server on a debian box to authenticate wireless users. The current debian (sid) package for 1.0.1 doesn't include eap_tls, eap_ttls, nor eap_peap due to licensing issues - yet I needed them.

Re: migrating external programs from xtradius to freeradius

2004-12-07 Thread Paul Hampson
On Tue, Dec 07, 2004 at 12:40:41PM -0800, L.C. (Laurentiu C. Badea) wrote: Xtradius uses Auth-Type = External, freeradius appears to need Auth-Type = Accept with an external script. Not a big deal, just thought I should mention it because it is somewhat less intuitive (since after all, you

Re: installaion problem

2004-12-07 Thread Paul Hampson
On Wed, Dec 08, 2004 at 12:53:48PM +0800, Spades wrote: While installing Freeradius 1.0.1, i managed to run ./configure, however.. I'm unable to run 'make' in my Fedora Core 2. gives me error Any idea what went wrong? -- Making static dynamic in rlm_krb5... gmake[6]: Entering directory

Re: Postauth section skipped when rejected by external script

2004-11-30 Thread Paul Hampson
On Mon, Nov 29, 2004 at 08:53:30PM +0100, Thor Spruyt wrote: Hi, I have configured freeradius to check against a postgresql database and when the user is valid, execute an external script. (which works fine) I have configured freeradius to store authentication results in a postgresql

Re: Error rlm_eap_peap_1.0.1.so

2004-11-30 Thread Paul Hampson
On Tue, Nov 30, 2004 at 11:22:39AM +, [EMAIL PROTECTED] wrote: freeradius:relocation error:usr/local/lib/rlm_eap_peap_1.0.1.so:undefined symbol:eaptls_process I didn't understand the rest of the email, but this suggests your libltdl is too recent, and the cross-module linking used in 1.0.1

Re: rlm_eap_md5: User-Password is required for EAP-MD5 authentication

2004-11-25 Thread Paul Hampson
On Fri, Nov 26, 2004 at 02:01:00PM +0800, Chan Min Wai wrote: Alan DeKok wrote: Chan Min Wai (System Administrator) [EMAIL PROTECTED] wrote: CLEAR text passwords are required for EAP-MD5. Crypt passwords will NEVER work. Anyway to make it work? somehow? No. It's impossible. I know

Re: rlm_ippool - not releasing ip addresses

2004-11-20 Thread Paul Hampson
On Sat, Nov 20, 2004 at 10:51:32AM +1030, Mike O'Connor wrote: Thanks for you comments, I used you suggestion as a biases and have found that the accounting stop records do not always have the same port id. This means it does not match correctly and does not release the port. I do not see

Re: rlm_exec fail V reject

2004-11-18 Thread Paul Hampson
On Thu, Nov 18, 2004 at 05:14:47PM -0800, Jev wrote: Ok, great Paul, thank you! Is it this patch: http://lists.freeradius.org/archives/freeradius-users/2004/09/frm00132.html that you plan to apply? Is the patch in that post the most recent? I ask because I may attempt to apply and build

Re: Just getting started

2004-11-17 Thread Paul Hampson
On Thu, Nov 18, 2004 at 12:17:28AM -0600, Dallas Graves wrote: Ok, so I have looked all over the web but cant really find any good how-to articles on freeradius when it comes to setting up a dial-up server. Anyone have any links or even a book that might help? If you're looking at setting a

Re: error in compilation (make)

2004-11-11 Thread Paul Hampson
On Thu, Nov 11, 2004 at 04:46:25PM +0200, Eva Kolega wrote: Paul , Please do not off-list email me without asking first. My personal email archives are not available on the web (as far as I know) so any answer I give privately would have much less value than if I answer on-list. I enclose the

Re: list-related suggestion

2004-11-10 Thread Paul Hampson
On Wed, Nov 10, 2004 at 01:33:10PM -0500, Samuel Sullivan wrote: Hi. I joined this list about a week ago. A suggestion for whoever maintains the list...perhaps adding an identifying tag to the subject lines of list messages? Something like [freeradiuslist] or some-such. Something to make the

Re: error in compilation (make)

2004-11-09 Thread Paul Hampson
On Tue, Nov 09, 2004 at 05:49:56PM +0200, Eva Kolega at NTUA wrote: I have installed mysql-standard-4.0.21-sun-solaris2.9-sparc-64bit.tar.gz, Apache2, php4.3.9 and openldap. The problem is when I try to run make, though configure run ok, gcc: sql_mysql.c: linker input file unused because

Re: 802.1x and assigning IP address to the supllicant

2004-11-08 Thread Paul Hampson
On Tue, Nov 09, 2004 at 01:39:33AM +0200, iVAN G wrote: How do u do LAN 802.1x + IP leasing (dhcp,radius,supplicant) 802.1x via RADIUS. IP leasing via DHCP. They are configured completely independently. ]- yeah i know :) i was asking is there a way to combine both in a way

Re: Ippool Or DHCP Server.

2004-11-03 Thread Paul Hampson
On Wed, Nov 03, 2004 at 07:04:09PM +0800, Chan Min Wai wrote: I hope that radius server can talk to the DHCP server and tell the DHCP server what ip address to be allocate... Write a script in that adds the authenticated client's MAC address and the IP Address you've assigned to the DHCP

Re: Build problem on Debian 3

2004-11-02 Thread Paul Hampson
On Mon, Nov 01, 2004 at 12:22:04PM +0400, rashad wrote: Build process breaks down at following point: /usr/bin/ld: cannot find -lz Where is the problem? As I recall, libmysqlclient-dev was missing libz-dev as a dependancy in Debian/Woody. You'll need to install it yourself. -- Paul TBBle

Re: Ippool Or DHCP Server.

2004-11-02 Thread Paul Hampson
On Wed, Nov 03, 2004 at 02:19:21PM +0800, Chan Min Wai wrote: Dana Hudes wrote: On Wed, 3 Nov 2004, Chan Min Wai wrote: Go back to the defintion of RADIUS: Remote Authentication Dial-In User System. Now think. How do dialup users connect? They use SLIP/PPP. PPP has provision for sending

Re: Exec-Program output: freeradius not reading response?

2004-10-27 Thread Paul Hampson
On Tue, Oct 26, 2004 at 02:54:45PM -0700, Nate M wrote: I've done some troubleshooting of my own, and unsure if this is helpful or not, but the process appears to be hanging indefinitely until cleaned up within this section of threads.c (beginning line 1141). The line in particular it

Re: Exec-Program-Wait question and rlm_exec

2004-10-27 Thread Paul Hampson
On Tue, Oct 26, 2004 at 05:17:57PM +0300, Kostas Zorbadelos wrote: On Tue, Oct 26, 2004 at 10:20:48AM -0400, Alan DeKok wrote: Kostas Zorbadelos [EMAIL PROTECTED] wrote: First of all I have a question for Exec-Program-Wait. I need to run an external C program that expects in its

Re: Debian .rules file for building postgres support?

2004-10-24 Thread Paul Hampson
On Mon, Oct 25, 2004 at 01:31:06PM +1000, Tech wrote: Does anybody have a modified .rules file for building a 1.0.1 .deb with Postgres support? Thanks in advance. You'll find one in the freeradius 1.0.1 release on the FreeRADIUS website. -- Paul TBBle Hampson, on an alternate email client.

Re: Problem : segmentation fault

2004-10-08 Thread Paul Hampson
On Fri, Oct 08, 2004 at 06:28:17AM +, atul dhingra wrote: [Some HTML stuff] Please don't post HTML-only. Anyway, try OpenSSL 0.9.7... From memory it's required by something in there. Otherwise, after reading the mailing list rules, there's a document (bugs.txt?) which describes how to

Re: Exec-Program and iproute2

2004-10-06 Thread Paul Hampson
On Tue, Oct 05, 2004 at 04:59:13PM -0700, Ivo Petrov wrote: Thanks for advice but in radiusd.conf I wrote: user root group root and radiusd runs as root or that is not enough. I tried running simple script and it works, but when I change the script with the one that makes shaping then

Re: Exec-Program help

2004-10-06 Thread Paul Hampson
On Tue, Oct 05, 2004 at 05:02:55PM -0700, Ivo Petrov wrote: Thanks much but I need the script executed after successful authentication not before that. Any way thanks my simple script was executed correctly. You might want to look at rlm_exec, which gives better control on when the script is

Re: Net-SNMP Support

2004-10-06 Thread Paul Hampson
On Wed, Oct 06, 2004 at 02:48:30PM -, David wrote: I have been running FreeRadius version 1.0.0 with SNMP support enabled using UCD-SNMP. Will version 1.0.0 work with Net-SNMP now? No, but 1.1.0 does, as does the 1.0.0 and 1.0.1 Debian packaged versions (although it is disabled for

Re: Exec-Program and iproute2

2004-10-04 Thread Paul Hampson
On Sun, Oct 03, 2004 at 02:22:17AM -0700, Ivo Petrov wrote: Hi all, I'm trying to shape ppp+ interfaces after successful authentication using Exec-Program. radiusd runs as root, in mysql radreply table the last row for the user contains: Exec-Program = '/etc/ppp/shd %f'. Freeradius

Re: Exec-Program help

2004-10-04 Thread Paul Hampson
On Mon, Oct 04, 2004 at 02:20:49AM -0700, Ivo Petrov wrote: I have a problem using Exec-Program. I've put the line in radreply table (4,'test1','Exec-Program',':=','/path/script') but the script was not executed. Can anybody tell me why? script : #!/bin/bash ps aux | grep radiusd result

Re: ip pools question

2004-09-21 Thread Paul Hampson
On Wed, Sep 22, 2004 at 04:20:23AM -0700, Evren Yurtesen wrote: Hello, I want to use the freeradius ip pools. I just wonder something though ever ip pool name I define should be included in the accounting and post-auth sections? Its kind of confusing, whats the point of defining the

Re: debian packages for woody and sarge

2004-09-20 Thread Paul Hampson
On Mon, Sep 20, 2004 at 05:30:10AM -0700, Aime wrote: Thanks for the suggestion. Now i progressed a little bit compiling freeradius on Woody. The problem I am having now is about mysql . What library must be in place . libmysqlclient-dev I think... The one below looks right,.. What's the

Re: debian packages for woody and sarge

2004-09-19 Thread Paul Hampson
On Sun, Sep 19, 2004 at 08:24:13AM -0700, Aime wrote: OK. I did what you suggested but now I have problem with OpenSSL. It cannot find Openssl. But it is ther , I know. I just compiled Openssl on the machine. Do you also have the OpenSSL package? I'd suggest not building a local copy, but

Re: debian packages for woody and sarge

2004-09-18 Thread Paul Hampson
On Sat, Sep 18, 2004 at 05:40:02AM -0700, Aime wrote: Hello Marcus, Please can you layout here the steps you did to get freeradius compiled on Woody. I tried what you said in your mail (by commenting dh_installpam --name=radiusd ), but still get dependency problems about libsasl2-dev

Re: Status bug #122

2004-09-12 Thread Paul Hampson
On Sun, Sep 12, 2004 at 04:34:30PM +0200, Thor Spruyt wrote: Regarding bug #122, which actually isn't a bug, but rather an enhancement... Will the patch in bug #122 be apllied so the changes are in 1.0.1? The only justification I can see to put this into 1.0.1 is if it's invalid to have two

  1   2   >