no response to Access-Challenge

2010-02-16 Thread Vieri
this delay? It's as if the conversation were out of sync or as if one side weren't listening. Could it be AP, the client supplicant, the wlan driver? If I were to use a packet sniffer like wireshark, what filter could I apply and what should I look for? Ideas are welcome. Thanks Vieri

wpa_supplicant on Windows takes a long time to auth via freeradius

2010-02-11 Thread Vieri
-Challenge it wakes up in 4.9 seconds. Is this normal? I'm attaching the log files of both Freeradius and wpa_supplicant in the hope that someone can help me understand what's making my client PC take so much time to connect to my wireless network. Thanks, Vieri freeradius.log.gz

only accept PEAP-MSCHAPv2 with EAP-TLS-Require-Client-Cert = Yes

2010-01-07 Thread Vieri
require both client certificates and username/password.) Thanks, Vieri - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

check_crl = yes leads to verify error:num=3:unable to get certificate CRL

2009-12-22 Thread Vieri
returned SSL: SSL_read failed in a system call (-1), TLS session fails. TLS receive handshake failed during operation Any ideas are greatly appreciated. Vieri - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

how to require client certificate with PEAP

2009-10-27 Thread Vieri
Windows XP to send the client certificate? Thanks, Vieri PS: Here are the relevant config files and debug log: FreeRADIUS Version 2.0.5, for host x86_64-pc-linux-gnu, built on Oct 1 2008 at 12:36:40 Copyright (C) 1999-2008 The FreeRADIUS server project and contributors. There is NO warranty

PEAP + EAP-TLS: client certificates

2009-10-22 Thread Vieri
, as expected. I'm wondering if I can *require* both a certificate on the client machine AND an AD user authentication. In other words, how can I *require* PEAP-EAP-TLS? (currently, my freeradius configuration seems to require PEAP OR EAP-TLS) Freeradius version: 2.0.5 Thanks, Vieri - List info

Re: PEAP + EAP-TLS: client certificates

2009-10-22 Thread Vieri
--- On Thu, 10/22/09, Ivan Kalik t...@kalik.net wrote: If I install a self-signed certificate on another Windows client and connect via EAP-TLS then I can connect without having to use an Active Directory user, as expected. I'm wondering if I can *require* both a certificate on the

Re: PEAP + EAP-TLS: client certificates

2009-10-22 Thread Vieri
--- On Thu, 10/22/09, Vieri rentor...@yahoo.com wrote: From: Vieri rentor...@yahoo.com Subject: Re: PEAP + EAP-TLS: client certificates To: freeradius-users@lists.freeradius.org Date: Thursday, October 22, 2009, 9:05 AM --- On Thu, 10/22/09, Ivan Kalik t...@kalik.net wrote: If I

Re: Windows client MS-chap auto-reauthentication

2009-10-19 Thread Vieri
cert. But I have to revoke it manually (CRL) as soon as I'm informed of the theft, which is usually a long and unreliable process. :-( Thanks anyway. Vieri - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Windows client MS-chap auto-reauthentication

2009-10-18 Thread Vieri
re-authenticates automatically and how to disable it? why Vista doesn't behave the same way? if installing SP3 on XP removes this feature? if somethng can be done on freeradius to discriminate manual logins from auto-logins? I'm running freeradius 2.0.5 on Linux. Thank you, Vieri

freeradius and active directory

2008-10-05 Thread Vieri
via AD is as expected. I'm just curious to know why these howtos suggest to specify a password server when using ads security in Samba. Thanks, Vieri - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread Vieri
-of='DOMAIN\\WIFI' password: NT_STATUS_OK: Success (0x0) Could it be a bug in the freeradius version I'm running? Can anyone please suggest how I can debug this (not a radius expert ;-) )? Regards, Vieri - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread Vieri
--- On Thu, 10/2/08, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: As with every other freeradius problem - when it doesn't work - debug (radiusd -X). That's how I'm running it. Does the list mind if I post the debug lines? - List info/subscribe/unsubscribe? See

Re: Freeradius, PEAP, Active Directory and --require-membership-of

2008-10-02 Thread Vieri
I forgot to mention that I already tried: with_ntdomain_hack = yes I'll try to post the relevant radiusd -X debug lines if the ML doesn't mind. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Roaming with WPA-Enterprise/Radius

2006-01-04 Thread DI PAOLA ., VIERI
and that seems to be "expensive". Is there a way of "caching" or "pre-authenticating" or "propagating authentication between APs"? Has anyone found a solution to this roaming problem in case one uses WPA-Enterprise/Radius? Regards, Vieri - L