Re: FreeRadius 1.13 support Dual Stack IPv4/IPv6 ?????

2006-09-18 Thread Stefan Winter
. It's a good habit to first read list archives, and only ask questions if the question wasn't answered before already. Greetings, Stefan Winter -- Stefan WINTER RESTENA Foundation - Réseau Téléinformatique de l'Education Nationale et de la Recherche RD Engineer 6, rue Richard Coudenhove

Re: FreeRadius 1.13 support Dual Stack IPv4/IPv6 ?????

2006-09-18 Thread Stefan Winter
Hi, Given that this appears to be a FAQ (Especially from SE Asia where they have IPv6 deployments) I have added it to the FAQ: Great! Please feel free to edit the entry for clarity :-) No need for that. I couldn't have said it any better. Oh, wait... :-) Stefan -- Stefan WINTER RESTENA

Re: IAS and Openser

2006-09-14 Thread Stefan Winter
aren't that far apart after all, it seems. Greetings, Stefan Winter -- Stefan WINTER RESTENA Foundation - Réseau Téléinformatique de l'Education Nationale et de la Recherche RD Engineer 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg email: [EMAIL PROTECTED]     Tel.:     +352 424409-1

Re: (Desperate) help setting up freeradius for use with eap-tls and win clients

2006-09-14 Thread Stefan Winter
, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1 http://www.restena.lu               Fax

Re: NT-PASSWORD--Re: Freeradius-Users Digest, Vol 17, Issue 47

2006-09-14 Thread Stefan Winter
rlm_sql: Failed to create the pair: Unknown attribute NT_Password |davide | NT_Password | := |781b0395cf9f8c1e5873eee5d28c38eb Shouldn't that be NT-Password (dash), not NT_Password (underscore)? Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education

Re: IAS e Openser

2006-09-13 Thread Stefan Winter
the authentication. This is easy, all you need to do is proxy all incoming requests to the IAS. See proxy.conf, read it, try it, and if doesn't work for you ask here again. But in English please, it's been quite a time since I had Spanish in school. Greetings, Stefan Winter -- Stefan WINTER RESTENA

Re: *****SPAM***** Using CVS, Unknown host cvs.freeradius.org. why happen error?

2006-09-13 Thread Stefan Winter
mail.starnetusa.net. [EMAIL PROTECTED] ~ $ are you sure you have configured your DNS resolution correctly? Greetings, Stefan -- Stefan WINTER RESTENA Foundation - Réseau Téléinformatique de l'Education Nationale et de la Recherche RD Engineer 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg email

Re: windowsXP+LDAP+freeradius

2006-09-07 Thread Stefan Winter
. The built-in supplicant (not recommended, but working) is using peap. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL

Re: windowsXP+LDAP+freeradius

2006-09-07 Thread Stefan Winter
PEAP, it would just be a little m,ore complicated than I outlined below (ntlm_auth, as the text you quoted suggested). Greetings, Stefan Winter == You cannot use PAM to answer PEAP/MS-CHAP requests. You must either have the plaintext password for the user, the NT

Re: XT Radius to Free Radius

2006-09-07 Thread Stefan Winter
-Timeout. If Exec-Program-Wait returns a non-zero exit status, access will be denied to the user. With a zero-exit status, access is granted. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de

Re: AP point support 802.1x but only with WPA

2006-09-04 Thread Stefan Winter
the AP for 802.1X + dynamic WEP, which is the poor man's variant of decent encryption with older devices. But without *any* encryption? Never seen that, sorry. Greetings, Stefan -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche

Re: Everything lookslike it works, but PC is not authentified

2006-09-01 Thread Stefan Winter
Web Server Authentication OID in the cert. Please read the various documentation about this topic that exists both here in the list archives and n HOWTOs throughout the web. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de

Re: LDAP authentication

2006-08-30 Thread Stefan Winter
in, that's beyond my experience. Maybe it's necessary to set Auth-Type to PAP in the users file manually then. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove

Re: LDAP authentication

2006-08-29 Thread Stefan Winter
password. Modify ldap.attrmap so that _your_ attribute is mapped into User-Name, not the default one. Stefan -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg

Re: LDAP authentication

2006-08-29 Thread Stefan Winter
Modify ldap.attrmap so that _your_ attribute is mapped into User-Name, not the default one. User-Password of course. -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359

Re: CHAP, LDAP and MS AD

2006-08-28 Thread Stefan Winter
not have to know anything about ntlm_auth. It just needs to talk MS-CHAP. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg - List

Re: PAP and authenticating via AD

2006-08-28 Thread Stefan Winter
want to switch to MS-CHAP: uncomment the ntlm_auth line in the mschap module to tell the FreeRADIUS server to actually use this connection. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de

Re: user specific settings in users file overwritten byDEFAULTsettings?

2006-08-18 Thread Stefan Winter
Hi, I'm probably wrong but didn't it used to be that the fall-through command was to tell the users file to continue processing if it didn't find a match? You're wrong. It was about continuing _even though_ it found a match. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau

Re: question about an output

2006-08-17 Thread Stefan Winter
, after reading this output, word by word? Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1

Re: user specific settings in users file overwritten by DEFAULTsettings?

2006-08-17 Thread Stefan Winter
matches. If you don't want that to happen, remove the Fall-Through line in the isdn user. Then processing will stop directly after isdn has matched, and its contents will be used. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de

Re: freeradius web manage

2006-08-13 Thread Stefan Winter
Would please anyone recommend for me any interface web package that allowes me to controll and manage freeradius users ? I'm on freebsd 6.1, mysql 4.1 ChilliSpot and freeradius. dialup_admin? Stefan -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education

Re: installation dirs on debian

2006-08-11 Thread Stefan Winter
Can someone point me to the right direction? There's a configure switch that allows you to specify the configuration directory. Stefan -- Stefan WINTER RESTENA Foundation - Réseau Téléinformatique de l'Education Nationale et de la Recherche RD Engineer 6, rue Richard Coudenhove-Kalergi L

Re: NTLM Authentication and send NAS-IP-Address param.

2006-08-11 Thread Stefan Winter
username Framed-IP-Address := 1.2.3.4 and make sure the files module is active in your configuration. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard

Re: Apple announces FreeRADIUS in Mac OSX Leopard

2006-08-11 Thread Stefan Winter
Wow! Congratulations! The only problem with this is: expect an incredible increase of number of questions on this list in 3... 2... 1... Stefan -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard

Re: FreeRadius - Setting IP addresses

2006-08-10 Thread Stefan Winter
I have a class C subnet set of IP addresses. How do I give people IP addresses when they authenticate against radius? Are we talking about wireless LAN auth here (answer: use a DHCP server after authenticaiton) or about PPP auth (answer: use ippools module)? Stefan -- Stefan WINTER

Answer

2006-08-08 Thread Stefan Winter
, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Bandwidth control...

2006-08-08 Thread Stefan Winter
defining the max bandwidth; the NAS documentation will tell you). How work? Send the bandwidth limitation attribute to the NAS along with the Access-Accept message. Tks so much Wlcme. Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la

Re: What attribute for password change?

2006-07-31 Thread Stefan Winter
. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1 http://www.restena.lu               Fax

Re: UPDATE RADACCT problem

2006-07-26 Thread Stefan Winter
contains the queries to be executed. Modify them to your liking. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel

Re: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Stefan Winter
are confused about how stuff works. This was the verbose version of what Phil answered. And to my best knowledge, he is completely right with it. Greetings, Stefan Winter (hoping that I have the right to answer to you, wherever your definition of having the right to answer you comes from) -- Stefan

Re: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Stefan Winter
attribute and that's it (leaving out all the really painful stuff with expiring leases, renewals and whatnot; it would be a non-trivial task). The remaining question really is: Why on earth would you _want_ to do that? rlm_ippool exists and works. Greetings, Stefan -- Stefan WINTER Stiftung

Re: How to reply Session-Timeout without password

2006-07-26 Thread Stefan Winter
. User 005001 is first caught with the first expression, but later overridden with the second one and thus needs to authenticate. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung

Re: How to reply Session-Timeout without password

2006-07-25 Thread Stefan Winter
it in the users file with NAS-IP-Address == your-b2bua-ns, Auth-Type := Accept Session-Timeout := whatever Do keep in mind that everyone who is authenticating via this IP address is *always* *accepted* Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau

Re: PEAP short question

2006-07-21 Thread Stefan Winter
Hi, I've been watching the logs and my question is why localhost takes part in the process. Inner workings of FreeRADIUS. The inner authentication (within the EAP TLS tunnel) counts as a new request, coming from localhost. Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau

Re: Need help setting up PEAP authentication

2006-07-20 Thread Stefan Winter
certificates, your certificate needs to have another OID present: Microsoft Web Client Authentication. So even if you don't validate the server credentials, you'll have to have an MS-friendly certificate on the client side. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau

Re: Need help setting up PEAP authentication

2006-07-19 Thread Stefan Winter
as the FAQ tells you and send a *complete* *debug* log. So does someone have a working freeradius configuration to share with me ? Or some tips to get it working ? I would exchange tipps for a decent debug log. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique

Re: 802.1x with mschap-radius-ldap with ssha-1 passwords

2006-07-18 Thread Stefan Winter
only bind if it has the user's password. When using MS-CHAP the password is already hashed when the server gets it, so how could he possibly perform the bind operation? Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la

Re: Confused about 'hints' file

2006-07-14 Thread Stefan Winter
it. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1 http://www.restena.lu

Re: Questions about debug output

2006-07-08 Thread Stefan Winter
into line 173 of the users file, and you will see what's in there. Nothing spectacular, I guess. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359

Re: Radius ip pool

2006-07-07 Thread Stefan Winter
, others _did_ have the same question. Reading the list archives would have helped. .1X authentication and DHCP have *nothing* to do with each other. If you have a DHCP server and it doesn't talk to your authenticated clients, that's a completely FreeRADIUS unrelated problem. Stefan -- Stefan

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-07 Thread Stefan Winter
want usernames to be important at all, use EAP-TLS. The client certificate will identify you, no matter what garbage you put into the user name. Captive portals are a step back with regards to security. Greetings, Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-07 Thread Stefan Winter
for the hardcore paranoid people, right. But if you are happy with SecureW2 and EAP-TTLS: that's perfectly fine. Thanks again for all your help - i'm feeling pretty happy with my setup now, Great! Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale

Re: unknown module eap error

2006-07-06 Thread Stefan Winter
. Install openssl and the corresponding development libraries (often called openssl-devel) and recompile the server. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi

Re: Radius ip pool service !!

2006-07-06 Thread Stefan Winter
Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-TTLS/PAP - LDAP for WPA2

2006-07-06 Thread Stefan Winter
. I've tried googling but haven't found a good guide that matches our setup.I can, of course, give more information if needed. Really? WPA2 is quite a wide-spread scenario. And using LDAP as backend is quite common as well. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau

Re: Problem of proxying Vendor Specific Attributes (VSA)!

2006-07-05 Thread Stefan Winter
that goes through. BTW: please ask via the mailing list. Others may have the same question. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E

Re: CHAP and Windows 2003 AD LDAP

2006-07-05 Thread Stefan Winter
, searching the archives and the FR website will help you get along. There's also a great tutorial on the topic, which is referenced here quite often by Charles Schwartz, see the archives for that one as well. Greetings, -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education

Re: Problem of proxying Vendor Specific Attributes (VSA)!

2006-07-05 Thread Stefan Winter
convince the server then. I wouldn't bet on it though. Further messages via private mail will be ignored, ask the _mailing list_. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard

Re: Diferent Session-Timeout depending on NAS

2006-07-03 Thread Stefan Winter
session timeout you like. Your problem is solved by that. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel

Re: Diferent Session-Timeout depending on NAS

2006-07-03 Thread Stefan Winter
default time and the NAS's IP address, let the perl script calculate the Session-Timeout and return that to the RADIUS server. Greetings, Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue

Re: not-logged off users... how to decide whether a user is connectedor not?

2006-07-02 Thread Stefan Winter
help. I guess reading Simultaneous Use in the documentation directory might help. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg

Re: Throttle On Cap

2006-07-01 Thread Stefan Winter
to the list in that case as well so that they can be incorporated into the next release. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg

Re: How to Disable user

2006-07-01 Thread Stefan Winter
Hi, i have Freeradius 1.0.5 and using MYSQL backend how can i disble a user from logging in? Add an entry in radcheck: Auth-Type := Reject Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de

Re: How to Disable user

2006-07-01 Thread Stefan Winter
what field do i put this into? Well, add a line into the MySQL table radcheck: UserName - the name of the guy to disable Attribute - Auth-Type op - := Value - Reject Fairly straightforward. Stefan -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de

Re: Throttle On Cap

2006-06-30 Thread Stefan Winter
I need some help with implementing Throttle on Cap Usage type feature for Could you elaborate a bit what this Throttle on Cap Usage is supposed to do? Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur

Re: Problem about Chap-Password and User-Password

2006-06-30 Thread Stefan Winter
, Stefan Winter Am Freitag, 30. Juni 2006 09:37 schrieb Kun Niu: Dear all, I've just installed freeradius 1.0.2 on my debian3.1 system. I've got two radius clients. One can be authorized normally and the other one failed to be authorized. Here's my log. Would anyone be kind enough to analyze

Re: Diferent Session-Timeout depending on NAS

2006-06-30 Thread Stefan Winter
IP address as attribute. If it doesn't, and is directly connected, use Client-IP-Address instead). That way, you can set Session-Timeout on a per-NAS basis. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche

Re: Freeradius advocacy needed for convincing corporate management

2006-06-28 Thread Stefan Winter
://www.freeradius.org/business/ Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1 http

Re: Mysql with crypted password

2006-06-27 Thread Stefan Winter
clear text passwords. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1 http

Re: Mysql with crypted password

2006-06-27 Thread Stefan Winter
-- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1 http://www.restena.lu               Fax:      +352

Re: EAP-MD5 with LDAP

2006-06-26 Thread Stefan Winter
Can I set Autz-Type in users? but leave EAP to set Auth-Type?? Sure. Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL

Re: EAP-MD5 with LDAP

2006-06-23 Thread Stefan Winter
. Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PEAP Auth

2006-06-22 Thread Stefan Winter
is. OMG, an error! is not enough to effectively help you. Please stick to the common, well-documented process of posting your log files. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung

Re: rlm_exec

2006-06-22 Thread Stefan Winter
Hi, does anyone knows what rlm_exec module does? it executes commands. You can feed it with AVPs via environment variables so that it does whatever magic you want it to. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la

Re: PEAP Auth

2006-06-22 Thread Stefan Winter
, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: So how do you suppress

2006-06-22 Thread Stefan Winter
things up. Greetings, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: how to configure NAI realms routing table

2006-06-22 Thread Stefan Winter
Any links to documentation on how to achieve this with freeradius would be appreciated. ? Have you taken a look at proxy.conf? Should all be there... Stefan -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de

Re: Eap/TLS Problem !!

2006-06-20 Thread Stefan Winter
are mentioned in chapter 10 (examples on cert generation earlier in the document); the server OID is the same for TTLS. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard

Re: Client Freeradius !!!

2006-06-20 Thread Stefan Winter
for your card that *do* support TTLS. *hint* SecureW2 *hint* Anyone Can help-me or give-me another solution... Here you are. BTW, adding unnecessary exclamation marks to the subject is not likely to make you friends. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau

Re: 3com wx - peap-mschapv2 - freeradius - mysql

2006-06-16 Thread Stefan Winter
, though. thank you very much for your help. I'll enjoy free wireless LAN if I ever come to Florence. That's enough of a a revenue :-) Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
\000: fix the NAS. It is not RFC-compliant then. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED

Re: freeradius post

2006-06-15 Thread Stefan Winter
with this unknown attribute. It the problem persists after fixing that one, please get back to the list. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
MUST be able to deal with embedded nulls. RADIUS implementers using C are cautioned not to use strcpy() when handling strings. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung

Re: PEAP

2006-06-15 Thread Stefan Winter
without certs on the client side. You will need one for your server though. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
. Which I told him in my previous reply. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel

Re: PEAP

2006-06-15 Thread Stefan Winter
certificate to identify itself to the clients. It does not have to be a from a real CA, you can generate one from openssl yourself. You just have to configure the client to accept the certificate that is presented by the server during authentication. Greetings, Stefan Winter -- Stefan WINTER

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
what client exactly this is... Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1 http

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
me again. Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel.:    +352 424409-1 http://www.restena.lu

Re: public secret and public radius server. Is it secure?

2006-06-15 Thread Stefan Winter
roaming service for the education and research community: http://www.terena.nl/activities/index.php?action=set_filtersfilters[topic_id]=2 Later on, it is hopefully good enough to be considered as worthy of getting an (informational?) RFC number at the IETF. Greetings, Stefan Winter -- Stefan

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
hack the vendor of that other strange NAS/RADIUS server to not artificially require an 8-Bit integer. I'm still interested in the name of the product that behaves like that. Just to make sure I won't accidently buy it. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
Stripped-User-Name = ppp1 Realm = example.com Since you _want_ the \000 to be sent, I don't see why it seems to work here? Maybe the only thing that would really give clarity about what is really happening is a pcap capture with ethereal or similar. Greetings, Stefan -- Stefan WINTER

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
into the MS-CHAP-Chellenge? Just to make sure it's not the notation or something, like that MS-CHAP-Challenge transmits the four characters 0,x,0,0. Or something similar. Still an ethereal capture would be great. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau

Re: \000 in octets attribute?

2006-06-15 Thread Stefan Winter
knowledge. Maybe someone with more karma can jump in here? Especially if it's even *desired* to generate \000 octet values... Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6

Re: 3com wx - peap-mschapv2 - freeradius - mysql

2006-06-14 Thread Stefan Winter
to it after it sees the server certificate. If you wish, send me the public part of the certificate via PM and I'll look if the required OIDs are in it. Greetings, Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung

Re: 3com wx - peap-mschapv2 - freeradius - mysql

2006-06-10 Thread Stefan Winter
were answered by the client. HTH, Stefan Winter -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg - List info/subscribe/unsubscribe? See http

Re: 3com wx - peap-mschapv2 - freeradius - mysql

2006-06-09 Thread Stefan Winter
if this might force Auth-Type Local. If it does, comment it out. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED]     Tel

Re: insering the 3 record in radius db my using openser+radius+mysql

2006-06-08 Thread Stefan Winter
for Tunnel Accounting 15 Reserved for Failed So, your NAS shouldn't even send 15: it's _reserved_. Conclusion: go get a sane NAS device. -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de recherche 6, rue Richard

Re: public secret and public radius server. Is it secure?

2006-06-06 Thread Stefan Winter
working on a formal specification of RadSec right now, of which I hope it will somehow find a way into the Informational RFC track. There is a lot more potential in it than the OSC Whitepaper suggests. It would be really great to get an implementation of this in FR. Greetings, Stefan Winter

SSL error using MS-CHAPv2 - new in 1.1.2

2006-06-06 Thread Stefan Winter
::lib(0):func(0):reason(0) Info: rlm_eap_mschapv2: Issuing Challenge Auth: Login OK: [EMAIL PROTECTED] (from client localhost port 0) these new errors in rlm_eap are somewhat intriguing. Anyone a clue? Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de

Re: SSL error using MS-CHAPv2 - new in 1.1.2

2006-06-06 Thread Stefan Winter
asking here. I ask because of the two lines below, which is _not_ business as usual. Oh, I should have mentioned initially: it's OpenSSL 0.9.8a. Unchanged in FR 1.1.1, but 1.1.1 didn't spit out these errors. Greetings, Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de

Re: 1.1.2 Build Problems - rlm_eap-1.1.2.soT - ld: skippingincompatible

2006-05-31 Thread Stefan Winter
don't _know_, but my guess is that this message is quite clear: get a shared .so of ltdl. Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E

Re: FreeRadius 1.1.1 and run-away CPU

2006-05-24 Thread Stefan Winter
Hi, Are you proxying requests? If so, try the patch from bug #331. Is this patch going into 1.1.2? Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359

Re: auth acct same port

2006-05-22 Thread Stefan Winter
source code modification. One of the early packet parsing checks is whether the ports match or not. Take away that check and it should work. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung

Re: Automatic redirection

2006-05-09 Thread Stefan Winter
Is there a way to redirect a authenticated user to a specific web address depending on there login information? Captive Portal -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove

Re: PLS Help I get no response for 2 monthe (missing User-nameattribute)

2006-05-08 Thread Stefan Winter
submitted some time ago because otherwise hints will ignore those acct packets without User-Name. Stefan -- Stefan WINTER RESTENA Foundation - Réseau Téléinformatique de l'Education Nationale et de la Recherche RD Engineer 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg email: [EMAIL PROTECTED

Re: PLS Help I get no response for 2 monthe (missing

2006-05-08 Thread Stefan Winter
that). In your case you may want to add your realm as attribute value, so that the packet later gets caught by the realm processing. Greetings, Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue

Re: ntlm_auth is not used by mschap

2006-05-04 Thread Stefan Winter
DSL - das All-Inclusive-Paket für clevere Doppel-Sparer, nur 44,85 € inkl. DSL- und ISDN-Grundgebühr! http://www.arcor.de/rd/emf-dsl-2 - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de

Re: ntlm_auth is not used by mschap

2006-05-03 Thread Stefan Winter
As this line tells you. Send a MS-CHAP request, and look what happens then. Stefan -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche Ingenieur Forschung Entwicklung 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg E-Mail: [EMAIL PROTECTED

Re: Version 1.1.1 stops responding

2006-04-10 Thread Stefan Winter
this morning, as Alan suggested elsewhere in the thread. I hope it will be responsive enough so I can keep it running for a few hours until the error eventually occurs... Greetings, Stefan -- Stefan WINTER RESTENA Foundation - Réseau Téléinformatique de l'Education Nationale et de la

Re: RADIUS stops responding after a while

2006-04-07 Thread Stefan Winter
a notification. Greetings, Stefan Winter -- Stefan WINTER RESTENA Foundation - Réseau Téléinformatique de l'Education Nationale et de la Recherche RD Engineer 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg email: [EMAIL PROTECTED]     Tel.:     +352 424409-1 http://www.restena.lu

<    1   2   3   4   5   >