Re: Learning Freeradius Server

2009-11-13 Thread Rakotomandimby Mihamina
11/13/2009 01:30 PM, Wagner Pereira: In other hand, maybe it's a good idea you start to test freeradius with the simplest way to authenticate: using /etc/passwd. This is not the simplest way: using /etc/freeradius/users is _the_ simplest way. -- Architecte Informatique chez

Re: FreeRadius with 3COM

2009-11-11 Thread Rakotomandimby Mihamina
11/11/2009 01:42 PM, Rafael Fernandes: So, if anyone have any idea to help me. http://www.google.com/search?q=3com+forum -- Architecte Informatique chez Blueline/Gulfsat: Administration Systeme, Recherche Developpement +261 33 11 207 36 - List

Re: [Fwd: Re: [Fwd: I need some help with freeradius 2.0.4]]

2009-11-11 Thread Rakotomandimby Mihamina
11/11/2009 08:12 PM, Wagner Pereira:: I think this picture Uh??? Your computer doesnt let you copy/paste as text MySQL output??? -- Architecte Informatique chez Blueline/Gulfsat: Administration Systeme, Recherche Developpement +261 33 11 207 36 -

Re: Cannot upgade to 2.1.7

2009-11-10 Thread Rakotomandimby Mihamina
11/10/2009 11:35 AM, kachin Agarwal:: I think i vefound the problem. it is not able to find the gdbm.h file from /usr/include. Why dont you just reply to, instead of creating a new mail? Why dont you install the freeradius bundled with you distribution? -- Architecte Informatique chez

Re: Freeradius-Users Digest, Vol 55, Issue 38

2009-11-10 Thread Rakotomandimby Mihamina
11/10/2009 03:33 PM, Peter Carlstedt:: *_Changes in control:_* [...] _*Changes in rules*_: [...] You could just have used 'patch -Naur' (or something similar) For you other questions: Ask on the debian-mentors mailing list. -- Architecte Informatique chez Blueline/Gulfsat:

Re: Freeradius set up help

2009-11-09 Thread Rakotomandimby Mihamina
11/10/2009 06:10 AM, Horchem Gary:: let me try to send this again the last one I sent the list server said it was too large 'freeradius -X' output shows us: - how you configured your freeradius - debug output You'd better give us 'freeradius -X' output, using something like

Re: acct_postgresql+auth_ldap

2009-10-13 Thread Rakotomandimby Mihamina
10/09/2009 04:05 PM, José Johnny RANDRIAMAMPIONONA:: Thank u guys! Please keep us in touch. and if you kept some history of what you've done, I am interested in. -- Architecte Informatique chez Blueline/Gulfsat: Administration Systeme, Recherche Developpement

Re: acct_postgresql+auth_ldap

2009-10-09 Thread Rakotomandimby Mihamina
10/09/2009 01:58 PM, José Johnny RANDRIAMAMPIONONA:: Hi all, I d like to know if someone has already tried to do the accounting (only accounting) thing with postgres and authentication with OpenLdap? I am going to try that. Not yet, but I will. and I think it's globally about: auth {

Re: rlm

2009-09-30 Thread Rakotomandimby Mihamina
09/30/2009 03:35 AM, José Johnny RANDRIAMAMPIONONA: I solved the problem. I think It ll better to put it in a tutorial or something(I ll do it)! Please, yes. I inted to switch AUTH to LDAP and keep PGSQL for ACCT, your feedback is important to me. -- Architecte Informatique chez

Re: rlm

2009-09-28 Thread Rakotomandimby Mihamina
09/28/2009 07:32 AM, José Johnny RANDRIAMAMPIONONA:: I posted this problem a week ago I think the best thing is first not to setup from sources. Give a try to _packages_. they are pretty good for If your distribution does not include packages for that, then change distribution. :-) --

Re: your mail

2009-09-28 Thread Rakotomandimby Mihamina
09/28/2009 03:09 PM, Alan Buxey: FreeRADIUS can handle several hundred AAA per second without issues..but you put something in its way that is slow - LDAP lookup, kidding troll LDAP lookup is always fast ;-) Slowness is only for relational stuff / -- Architecte Informatique chez

Re: account expiration attribute

2009-09-26 Thread Rakotomandimby Mihamina
09/25/2009 03:46 PM, Ivan Kalik: Why, oh why, do people trawl the internet for outdated and inaccurate Ivan, this is just the result of: http://www.google.com/search?q=radius+expiration+attribute (the results ranking may differ, we are not near) I usually tend to make the web search before

Re: account expiration attribute

2009-09-25 Thread Rakotomandimby Mihamina
09/24/2009 12:03 PM, Ivan Kalik:: What RADIUS attribute would suit to account expiration? Expiration. I cannot find its documentation (its syntax) A hint: http://www.open.com.au/pipermail/radiator/2008-July/014935.html But not more... A help? -- Architecte Informatique chez

Re: account expiration attribute

2009-09-25 Thread Rakotomandimby Mihamina
09/25/2009 02:59 PM, Rakotomandimby Mihamina:: 09/24/2009 12:03 PM, Ivan Kalik:: What RADIUS attribute would suit to account expiration? Expiration. I cannot find its documentation (its syntax) http://www.portmasters.com/tech/docs/pdf/radius-release20.pdf In RADIUS 1.16, if a user record

account expiration attribute

2009-09-24 Thread Rakotomandimby Mihamina
Hi all, What RADIUS attribute would suit to account expiration? the context: - prepaid users must regularily add credit to his account - big credit - big validity extension - small credit - small validity extension - no account removal, just auth reject if validity date passed Credit adding

Encryption (Was: known good error)

2009-09-24 Thread Rakotomandimby Mihamina
09/24/2009 04:12 PM, wessam seleem:: Note that I changed my real password and its encryption to secure my data. By the way, As far as I know (And I might know nothing), encryption _is_ because guessing the password from it's encrypted hash is _not_ possible. -- Architecte Informatique

Re: Failed to link to module rlm_ldap

2009-09-24 Thread Rakotomandimby Mihamina
09/24/2009 04:54 PM, José Johnny RANDRIAMAMPIONONA: I rebuild it and ( ./configure --prefix=/usr/local/freeradius-server.2.1.6/) and it seems that there is library problem(I had this kind of problem in the past, but I forgot what I did to fix it). What packages are installed? Didn't you miss

Re: using SQL, where is Session-Timeout updated?

2009-09-18 Thread Rakotomandimby Mihamina
09/18/2009 12:51 PM, Ivan Kalik:: You need sqlcounter (counter.conf) for that. Found. but no UPDATE query in it. Oddly enough, counter doesn't update anything - it COUNTS. OK, Attached is my 'default' file, and the 'freeradius -X' output. the counter (in counter.conf) is: sqlcounter

Re: using SQL, where is Session-Timeout updated?

2009-09-18 Thread Rakotomandimby Mihamina
09/18/2009 05:41 PM, Ivan Kalik:: sqlcounter dailycounter { counter-name = Daily-Session-Time check-name = Max-Daily-Session reply-name = Session-Timeout sqlmod-inst = sql key = User-Name reset = daily query = SELECT SUM(AcctSessionTime - \

Re: Simultaneou-Use := 1

2009-09-12 Thread Rakotomandimby Mihamina
09/11/2009 07:02 PM, Ivan Kalik:: Because of legacy application requiring exotic schema, we are obliged to play with it. The problem is I cannot have ++--+++---+ | id | UserName | Attribute | op | Value |

Simultaneou-Use := 1

2009-09-11 Thread Rakotomandimby Mihamina
Hi all, Using Freeradius v2 We use only PGSQL (no users file) and a custom schema Just an example: authorize_check_query = SELECT * FROM f_authorize_check_query2('%{SQL-User-Name}','%{User-Password}' = We play much with FUNCTIONs in PGSQL. Because of legacy application requiring exotic

mix user storage

2009-09-08 Thread Rakotomandimby Mihamina
Hi all Using freeradius 2.x for AAA, is it possible to mix LDAP and xxxSQL? I mean one of those cases (the only difference is about the credit): case #1: LDAP: - username - password - MAC Address - NAS (the user is tied to that NAS) - credit (credit left)

usename + password + MAC address

2009-09-07 Thread Rakotomandimby Mihamina
Hi all, On a Radius version 2.x, we would like to tie an user to a MAC address. The auth key would then be the username, password and MAC address (Calling Station ID). Where is the right place to do that? - On the freeRadius? (any hint, please?) - In the PGSQL behind? (using some FUNCTION, I

Re: radius server 2.1.6 not storing data in radacct table..help

2009-08-21 Thread Rakotomandimby Mihamina
08/21/2009 12:14 PM, shivashankar:: rlm_sql_oracle: execute query failed in sql_query: ORA-01400: cannot insert NULL into (RADIUSUSER.RADACCT.GROUPNAME) [...] in radacct table we have GROUPNAME is not null.. Alow it (GROUPNAME) to be NULL? -- Architecte Informatique chez

dumping radius queryies

2009-08-19 Thread Rakotomandimby Mihamina
Hi all, I am on the way to migrate a freeRadius V1 to a V2. I would like to log the queries submitted to the running V1, so thaht I could test them via 'radclient' to the V2, before switching to production stage. So, on a V1.4, what kind of loggin should I enable in order to have a dump of all

Session-Timeout for unlimited?

2009-08-18 Thread Rakotomandimby Mihamina
Hi, (Using freeRadius v2) We have prepaid users, where the freeradius server should answer with some non null integer Session-Timeout. We have also postpaid users, where the session should be unlimited. What is the Session-Timeout value corresponding to unlimited? Thank you. --

Re: Filter or restrict on NAS

2009-08-04 Thread Rakotomandimby Mihamina
08/03/2009 05:00 PM, Ivan Kalik: Yes, there are a few ways to do that. But what is bad NAS doing in the clients.conf in the first place? Or do you want to tie users to devices? Yes, the goal is to tie a user to a specific NAS. To tie the user to a single device you need just NAS IP, for

LDAP (Was: urgent)

2009-08-04 Thread Rakotomandimby Mihamina
The output seems relatively obvious. FreeRADIUS tries to contact the LDAP server, and then everything stops. Install an LDAP server that works. There is really a need of more LDAP-FreeRadius beginner documentation :-P -- Architecte Informatique:

Re: urgent

2009-08-04 Thread Rakotomandimby Mihamina
08/04/2009 07:16 PM, RANDRIAMAMPIONONA José Johnny:: U are right! It works with the userfile! I don't know exactly what's wrong because the LDAP server works with another application: it means that maybe the problem is in the configuration! (I followed the faq!) Help! Now then its more about:

Filter or restrict on NAS

2009-08-03 Thread Rakotomandimby Mihamina
Hi all, Configuration (Debian packaged): - freeradius 2.0.4 - pgsql 8.3 When AUTHing and ACCounTing, the FreeRADIUS makes some SQL queries containing the NAS information. Currently, on our system, the query SELECTs a function and depending on that NAS information brought in the query we answer

Re: rlm_ldap not found

2009-07-30 Thread Rakotomandimby Mihamina
07/29/2009 03:32 AM, RANDRIAMAMPIONONA José Johnny:: Hi everyone, I have a problem concerning my configuration and I am wondering if somebody can help me. *freeradius-server-2.1.6* is installed without warning on* CentOS v5.3* ...configured on localhost and tested. Everything's OK. You should

:=, == and =

2009-07-24 Thread Rakotomandimby Mihamina
Hi all, In a users file, I have for example: # DEFAULTGroup == disabled, Auth-Type := Reject #Reply-Message = Your account has been disabled. # [...] # steve Cleartext-Password := testing #Service-Type = Framed-User, #Framed-Protocol = PPP, #

Re: :=, == and =

2009-07-24 Thread Rakotomandimby Mihamina
07/24/2009 11:14 AM, Rakotomandimby Mihamina:: # DEFAULT Group == disabled, Auth-Type := Reject # Reply-Message = Your account has been disabled. - in the DEFAULT, I would like append 'Simultaneous-Use := 1' [1], but what is the syntax if i want multiple DEFAULTSs Not clear. I meant: I

same login pass pair, different behaviour.

2009-07-24 Thread Rakotomandimby Mihamina
Hi all, I have these users in my PGSQL table username | pwd --+- u_3 | pwd_3 u_one | pwd_one u_two | pwd_two When testing with radtest: miham...@rktmb:~$ radtest u_one pwd_one radius20 10 cot357 Sending

Re: same login pass pair, different behaviour.

2009-07-24 Thread Rakotomandimby Mihamina
07/24/2009 05:00 PM, Ivan Kalik:: username | pwd --+- u_3 | pwd_3 u_one | pwd_one u_two | pwd_two That's not freeradius schema. Yes, I know, that table was not to show my current schema. Our current one is: id | username | attribute |

FR1 - FR2: authenticate_query

2009-07-23 Thread Rakotomandimby Mihamina
I am in the process of migrating from freeradius v1.4 to v2 I am running Debian Lenny, all installed from packages. I am first trying to merge the configuration. I use Postgresql behind. In the v1: ### #

Re: Guide: Upgrading to version 2

2009-07-23 Thread Rakotomandimby Mihamina
07/23/2009 10:13 AM, Alan DeKok: I need to decide what else to do with the document. Knowing how many people are interested in it is a first step. I am interested in. I just asked my boss if he would be tempted on buying: Waiting for some answer... --

using (finding) mysql

2009-07-23 Thread Rakotomandimby Mihamina
Hi, I would like my freeradius to use PG SQL (no UNIX /etc/passwd nor users flat file) in /etc/freeradius/sites-enabled/default [...] # Pull crypt'd passwords from /etc/passwd or /etc/shadow, # using the system API's to get the password. If you want # to read

Re: Guide: Upgrading to version 2

2009-07-23 Thread Rakotomandimby Mihamina
07/23/2009 10:43 AM, Rakotomandimby Mihamina: Waiting for some answer... I got: Ready to buy it. (dunno what reasonnable is) -- Architecte Informatique: Administration Systeme, Recherche Developpement + 261 32 11 401 65 Pensez

using (finding) mysql

2009-07-23 Thread Rakotomandimby Mihamina
(some MTA problems... re send) Hi, I would like my freeradius to use PG SQL (no UNIX /etc/passwd nor users flat file) in /etc/freeradius/sites-enabled/default [...] # Pull crypt'd passwords from /etc/passwd or /etc/shadow, # using the system API's to get the password. If you

Re: using (finding) mysql

2009-07-23 Thread Rakotomandimby Mihamina
07/23/2009 11:34 AM, a.l.m.bu...@lboro.ac.uk: looks like you havent got $INCLUDE sql.conf uncommented in your radiusd.conf Yes. How could I missed it, i grep'd with attention... Queries now reach the PG SQL server. Thank you. -- Architecte Informatique:

login / password

2009-07-23 Thread Rakotomandimby Mihamina
Hi, Our passwords are stored as clear text in a postgresql database. The attached file tends to show CHAP is looking for something I dont understand. Would you have any suggestion? What's that no known good passwdord that might fail authentication? testing with radtest give the correct auth

subject of emails....

2009-07-22 Thread Rakotomandimby Mihamina
07/22/2009 02:03 PM, Hanno Schupp:: When replying, please edit your Subject line so it is more specific than Re: Contents of Freeradius-Users digest... -- Architecte Informatique: Administration Systeme, Recherche Developpement

radtest for accounting

2009-07-16 Thread Rakotomandimby Mihamina
Hi all, radtest alows me to bascally test account (login, pass,...). I would like to test the logout process now: what radtest friend is the one to use? Thank you. PS: I need it because at logout I have to process the remaining credit of the user. -- Architecte

Re: simple test,, how to go on?

2009-07-01 Thread Rakotomandimby Mihamina
07/01/2009 02:53 PM, Rakotomandimby Mihamina:: [...] rlm_pap: login attempt with password mihamina rlm_pap: Using CRYPT encryption. rlm_pap: Passwords don't match ++[pap] returns reject [...] The question: What Have I got to put in the Cleartext-Password attribute in users in order to have

freeradius on 64 bits

2009-06-19 Thread Rakotomandimby Mihamina
Hi all, I see FreeRADIUS is Debian packaged for amd64 http://packages.debian.org/search?keywords=freeradiussearchon=namessuite=allsection=all Are there limitations or known bugs about using it on x86_64 (intel/amd only)? -- Architecte Informatique: Administration Système, Recherche et

supported encryption

2009-06-02 Thread Rakotomandimby Mihamina
Hi all, At the moment, our FreeRaduis(v1.x) is looking up users in a PGSQL database, with clear username and clear password in the fields. We would like to switch it to FreeRadius (v2.x) and by the way, crypt (SHA, just crypt(),...) the password in the Database. What encryption is supported by