RE: Reply VSA-s in Access-Reject

2006-08-30 Thread Shankar Ganesh C
Hi Yervand,

How to set VSA in Access-Reject reply ?
Is that adding dictionary files is enough or any other support needs to be
done?

Rgds,
Shankar ganesh

-Original Message-
From:
[EMAIL PROTECTED]
org
[mailto:[EMAIL PROTECTED]
eradius.org]On Behalf Of Yervand Petrosyan
Sent: Wednesday, August 30, 2006 10:56 AM
To: freeradius-users@lists.freeradius.org
Subject: Reply VSA-s in Access-Reject


Hello,

In 1.1.3 version Access-Reject doesn't return in reply
VSA attributes but it is works well in 1.0.1.
Something was changed?

Thanks in advance,
Yervand



__
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
-
List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Reply VSA-s in Access-Reject

2006-08-30 Thread Nicolas Baradakis
Yervand Petrosyan wrote:

 In 1.1.3 version Access-Reject doesn't return in reply
 VSA attributes but it is works well in 1.0.1.
 Something was changed?

Yes, because it was considered as a bug.
See http://bugs.freeradius.org/show_bug.cgi?id=207

I also note Vendor-Specific attributes aren't allow in Access-Reject
packets per RFC 2865. (section 5.44)
See http://www.ietf.org/rfc/rfc2865.txt

-- 
Nicolas Baradakis

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: Reply VSA-s in Access-Reject

2006-08-30 Thread Peter Nixon
On Wed 30 Aug 2006 12:13, Nicolas Baradakis wrote:
 Yervand Petrosyan wrote:
  In 1.1.3 version Access-Reject doesn't return in reply
  VSA attributes but it is works well in 1.0.1.
  Something was changed?

 Yes, because it was considered as a bug.
 See http://bugs.freeradius.org/show_bug.cgi?id=207

 I also note Vendor-Specific attributes aren't allow in Access-Reject
 packets per RFC 2865. (section 5.44)
 See http://www.ietf.org/rfc/rfc2865.txt

This is not the first time we have been asked this, and as it appears that 
some NASes used this behaviour, maybe we should make this rfc compliance a 
configurable option..

I have added a section to the FAQ:

http://wiki.freeradius.org/index.php/FreeRADIUS_Wiki:FAQ#VSA_in_Access-Reject

-- 

Peter Nixon
http://www.peternixon.net/
PGP Key: http://www.peternixon.net/public.asc


pgp2jfvDuFbzI.pgp
Description: PGP signature
- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Reply VSA-s in Access-Reject

2006-08-30 Thread Nicolas Baradakis
Yervand Petrosyan wrote:

 Really, it would be reasonably to have this option
 configurable.

As always, patches are welcome.

-- 
Nicolas Baradakis

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html