Re: NTLM Auth Help

2009-06-04 Thread Rupert Finnigan
Hi All, After a bit of investigation and playing, I've made some changes to the rlm_mschap module that seems to have fixed my problem. It now no longer trims the machine authentication domain name, and so based on the ntlm_auth line from Alan DeKok's How-To on deployingradius.org will handle both

Re: NTLM Auth Help

2009-06-03 Thread Rupert Finnigan
Hi, Following up from this, I think I've discovered what the real problem here is. I think there's a problem with the MS-CHAP module The module looks in the username to find host/ at the beginning, and if it does then handles it differently. Whilst it sets the username section correctly, it

Re: ntlm_auth, universal principal name, multi-domain active directory, howto?

2009-06-03 Thread Rupert Finnigan
Hi Adam, I've been experimenting with something very similar recently. ntlm_auth can handle authentication in one of the follow: 1. --username = NetBIOS Domain Name\Username, no --domain parameter specified 2. --username = Username, --domain = NetBOIS Domain Name 3. --username = Username,

Re-compiling modules

2009-06-03 Thread Rupert Finnigan
Hi All, I'm *attempting* to recompile the rlm_mschap module with a quick mod to hopefully fix my host authentication domain extraction problems. Is this as simple as running make, and copying the resulting files to /usr/lib (on my system atleast)?? And if so, is it just the two files I need to

Re: NTLM Auth Help

2009-06-02 Thread Rupert Finnigan
Hi, 2009/6/2 a.l.m.bu...@lboro.ac.uk why? with recent versions of FreeRADIUS this just works(tm) with no rewriting needed - just ensure that the ntlm_auth line has the correct arguments and you have the ntdomain stuff turned on . I've tried, and can't make the default work. I've got

Re: NTLM Auth Help

2009-06-02 Thread Rupert Finnigan
Hi, 2009/6/2 a.l.m.bu...@lboro.ac.uk ah! multiple remote domains - not in a forest of trust? All in the same Forest Tree, yes - but it still appears to be unhappy as it can't work out which the domain the $PCNAME$ machine lives in. I can't really see anyway to resolve this, other

Re: Version 2.1.4 has been released

2009-03-10 Thread Rupert Finnigan
Hi, 2009/3/10 Alan DeKok al...@deployingradius.com The best new feature is one that has been needed for a long time. The (easy) ability to see debugging output from a live server. You can now do this via the raddebug command. Brilliant feature - however I needed to mod the shell

Re: Beating a dead horse, or freeradius 2.1.1 and active directory

2008-12-03 Thread Rupert Finnigan
Hi, I'm not sure if what you're doing is going to work.. You're trying to use MS-CHAP to handle terminal session logins, I think.. Most of the MS-CHAP advise given so far is to get EAP working from a client, say a XP laptop doing 802.1X to gain access to a switchport. Someone will definitely

Re: Beating a dead horse, or freeradius 2.1.1 and active directory

2008-12-03 Thread Rupert Finnigan
and author requests to active directory quite nicely. -- *From:* freeradius-users-bounces+blittle=skylight.com@ lists.freeradius.org [mailto:freeradius-users-bounces+blittlefreeradius-users-bounces%2Bblittle [EMAIL PROTECTED] *On Behalf Of *Rupert Finnigan *Sent

Re: Beating a dead horse, or freeradius 2.1.1 and active directory

2008-12-03 Thread Rupert Finnigan
the # authentication, the LDAP module sets itself to do # LDAP bind for authentication. # # THIS WILL ONLY WORK FOR PAP AUTHENTICATION. bit.. This might provide the answer you're looking for. Rupes 2008/12/3 Rupert Finnigan [EMAIL PROTECTED] Well

Re: Freeradius AUTH - Please Read!!!

2008-02-12 Thread Rupert Finnigan
On 12/02/2008, azizbaba [EMAIL PROTECTED] wrote: if your iptable service is running it is not see any info.You try iptables service stop for linux Not the best idea... Turn off the firewall and leave your box open for everyone/anyone to abuse?? If the iptables service is running (and it

Re: Creating rpm problem

2008-01-27 Thread Rupert Finnigan
On 27/01/2008, Laurent RAYSSIGUIER [EMAIL PROTECTED] wrote: Hello, I have a problem to create a rpm of freeradius-server-2.0.1. If i download tar.gz file and i try to create rpm, i've got this message : [EMAIL PROTECTED] ~]# rpmbuild -ta freeradius-server-2.0.1.tar.gz error: File

Re: radius attributes for cisco ip phone

2008-01-17 Thread Rupert Finnigan
On 17/01/2008, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: I have hp procurve 3500yl switches for which i use mac based authentication against radius server. The radius server should assign the vlan's. The pc that hangs behind the phone get the correct vlan, but the phone doesn't. Are you

Re: XP User/machine accounts

2008-01-16 Thread Rupert Finnigan
On 16/01/2008, Ian Begg [EMAIL PROTECTED] wrote: Hi Dont know if this is the correct place to ask but I have a problem. I have got freeradius working with eap/tls and can load the certs to XP laptops and connect. The problem I have is that if I log onto the laptop using a different user, no

Re: help

2008-01-12 Thread Rupert Finnigan
On 12/01/2008, adnan deura [EMAIL PROTECTED] wrote: hello i am given a project of installing freeRADIUS 1.1.7 on fedora core 7. i am unable to go next to the step radiusd -x kindly tell me some method to install it please help http://wiki.freeradius.org/Build#Building_RedHat_packages Same

Re: Configure Cisco Aironet 1130 with PEAP/Ms-Chap2

2007-12-19 Thread Rupert Finnigan
Hi, Might be talking rubbish, but think I can rememer my Cisco AP's defaulting to ports 1645 and 1646 for auth and accounting, whereas free-radius and radtest use 1812 and 1813. If I'm wrong please correct me, but might be worth checking? Rupes On 19/12/2007, Julian Stöver [EMAIL PROTECTED]

Re: TTLS authentication slow

2007-11-13 Thread Rupert Finnigan
Hi, Windows doesn't natively, but with the help of SecureW2 (http://www.securew2.com) it does quite well. Install it and select it as a EAP Type on the Authenication Tab when you setup your wireless connection. Cheers, Rupes On 13/11/2007, Artur Hecker [EMAIL PROTECTED] wrote: Allan, Maybe