Well, I figured something out since I posted the message...
I put both authenticate and authorize into "radiusd.conf" for x99_token,
and now can have users with auth-type "x99_token".
According to debug info, authentication takes place with correct module.
Though I get "reject" it's another issue, because of DES keys etc.
Now I'm waiting for Cryptocard trial license... Somebody told here there
is a way to get DES key from ST-1 token file, do you know is that
feasible?

Thanks anyway,
Alex

> -----Original Message-----
> From: [EMAIL PROTECTED] 
> [mailto:[EMAIL PROTECTED] On Behalf Of 
> Artur Hecker
> Sent: Friday, August 15, 2003 5:27 PM
> To: [EMAIL PROTECTED]
> Subject: Re: X9.9 Auth-Type
> 
> 
> 
> i'm not sure, but it looks like this module has an authorize 
> section. perhaps you should leave the auth-type := local and 
> put the x99 instance in the authorize section of the config 
> file so it can set it automatically?? did you try it?
> 
> ciao
> artur
> 
> 
> 
> > Alex Dron wrote:
> > 
> > Hi,
> > I wonder how to configure X99 authentication (i.e. for Cryptocard). 
> > What I suppose to set in "Auth-Type" in "users" file for such user?
> > 
> > In comments to "x99.conf" I see next:
> > (Auth-Type := x99_token)
> > 
> > However, there is no such type in the Dictionary... and 
> server refuses 
> > to start. The only suitable type I found in the dictionary is 
> > "ActivCard". Is that it?
> > 
> > I don't have any hardware token, but I want to test 
> > "Challenge/Response" logic for one particular RADIUS client. I 
> > understand that rlm_x99_token is that what I have to use. I 
> have set 
> > up "radiusd.conf" to use "x99.conf", and "x99passwd" for 
> some user of 
> > type "cryptocard-d8-rs". Now I guess I have to add this user to 
> > "users", but what I should specify for auth-type?
> > 
> > I'm using 0.9.0 on Linux RH 7.3, and have the latest OpenSSL 
> > libraries.
> > 
> > Thanks,
> > Alex
> > 
> 
> -- 
> Artur Hecker
> artur[at]hecker.info
> 
> - 
> List info/subscribe/unsubscribe? See 
> http://www.freeradius.org/list/users.html
> 


- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to