Re: radexample.c
> > freeradius = Version 1.1.14 > > is there such a version? Sorry it was freeradius-client-1.1.4 just a typo :) Sucker-punch spam with award-winning protection. Try the free Yahoo! Mail Beta. http://advision.webevents.yahoo.com/mailbeta/features_spam.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Re: radexample.c
Hi, > freeradius = Version 1.1.14 is there such a version? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Re: radexample.c
Ibrar Ahmed wrote: >> Then the RADIUS code in radiusclient is buggy. > > Don't think so (I should be wrong rather than radiusclient) The error message from radiusd is pretty definitive. >> Can you say which version of radiusclient you are using? What CPU you >> are running this on? > > freeradius = Version 1.1.14 > freeradius client library version = Version 1.1.14 > OS = xubuntu 6.10 > > > When I have tried my same example with radiusclient_ng_kdev it works fine > now. I don't know whats > wrong with the freeradius client library. 1.1.14 was taken from radiusclient-ng, and has bugs. 1.1.15 of freeradiusclient has a number of bugs fixed, including 64-bit problems. Use that. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Re: radexample.c
> Then the RADIUS code in radiusclient is buggy. Don't think so (I should be wrong rather than radiusclient) > Can you say which version of radiusclient you are using? What CPU you > are running this on? freeradius = Version 1.1.14 freeradius client library version = Version 1.1.14 OS = xubuntu 6.10 When I have tried my same example with radiusclient_ng_kdev it works fine now. I don't know whats wrong with the freeradius client library. --ibrar Need Mail bonding? Go to the Yahoo! Mail Q&A for great tips from Yahoo! Answers users. http://answers.yahoo.com/dir/?link=list&sid=396546091 - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Re: radexample.c
Ibrar Ahmed wrote: ... > I was thinking this was a secret issue. But I have cross checked it on my > client and server side > both. Then the RADIUS code in radiusclient is buggy. Can you say which version of radiusclient you are using? What CPU you are running this on? Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Re: radexample.c
> > I have read the debug output it says "auth: Failed to validate the user". > > But when I have > tried > > same user/pass combination with radclient it works fine > I know it's a lot of information, but reading it is the ONLY way you > will solve the problem. I have read all the information care fully and I have also added alot of debug messages in radiusd. > > auth: No authenticate method (Auth-Type) configuration found for the > > request: Rejecting the > user > > auth: Failed to validate the user. > > WARNING: Unprintable characters in the password. ? Double-check the > > shared secret on the > server > > and the NAS! I was thinking this was a secret issue. But I have cross checked it on my client and server side both. Here is packet output from radclient application (Works) rad_recv: Access-Request packet from host 127.0.0.1:32844, id=223, length=49 User-Name = "bob" User-Password = "bob" Framed-Protocol = PPP Processing the authorize section of radiusd.conf and here is my radexample packet output (Do not works) rad_recv: Access-Request packet from host 127.0.0.1:32855, id=223, length=55 User-Name = "bob" User-Password = "\265\\VJ\250\\p\3515\216\230\3343\263HW" Service-Type = Authenticate-Only NAS-IP-Address = 127.0.0.1 Processing the authorize section of radiusd.conf > Perhaps following those instructions would be useful. Yup > Alan DeKok. > -- > http://deployingradius.com - The web site of the book > http://deployingradius.com/blog/ - The blog > - > List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html > Don't get soaked. Take a quick peek at the forecast with the Yahoo! Search weather shortcut. http://tools.search.yahoo.com/shortcuts/#loc_weather - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Re: radexample.c
--- Alan DeKok <[EMAIL PROTECTED]> wrote: > Ibrar Ahmed wrote: > > Thanks DeKok, > > > > I have read the debug output it says "auth: Failed to validate the user". > > But when I have > tried > > same user/pass combination with radclient it works fine > > > > Here is my debug output. > > I know it's a lot of information, but reading it is the ONLY way you > will solve the problem. I have read all the information care fully and I have also added alot of debug messages in radiusd. > > auth: No authenticate method (Auth-Type) configuration found for the > > request: Rejecting the > user > > auth: Failed to validate the user. > > WARNING: Unprintable characters in the password. ? Double-check the > > shared secret on the > server > > and the NAS! I was thinking this was a secret issue. But I have cross checked it on my client and server side both. Here is packet output from radclient application (Works) rad_recv: Access-Request packet from host 127.0.0.1:32844, id=223, length=49 User-Name = "bob" User-Password = "bob" Framed-Protocol = PPP Processing the authorize section of radiusd.conf and here is my radexample packet output (Do not works) rad_recv: Access-Request packet from host 127.0.0.1:32855, id=223, length=55 User-Name = "bob" User-Password = "\265\\VJ\250\\p\3515\216\230\3343\263HW" Service-Type = Authenticate-Only NAS-IP-Address = 127.0.0.1 Processing the authorize section of radiusd.conf > Perhaps following those instructions would be useful. Yup > Alan DeKok. > -- > http://deployingradius.com - The web site of the book > http://deployingradius.com/blog/ - The blog > - > List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html > The fish are biting. Get more visitors on your site using Yahoo! Search Marketing. http://searchmarketing.yahoo.com/arp/sponsoredsearch_v2.php - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Re: radexample.c
Ibrar Ahmed wrote: > Thanks DeKok, > > I have read the debug output it says "auth: Failed to validate the user". But > when I have tried > same user/pass combination with radclient it works fine > > Here is my debug output. I know it's a lot of information, but reading it is the ONLY way you will solve the problem. > auth: No authenticate method (Auth-Type) configuration found for the request: > Rejecting the user > auth: Failed to validate the user. > WARNING: Unprintable characters in the password. ? Double-check the shared > secret on the server > and the NAS! Perhaps following those instructions would be useful. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Re: radexample.c
Thanks DeKok, I have read the debug output it says "auth: Failed to validate the user". But when I have tried same user/pass combination with radclient it works fine Here is my debug output. [EMAIL PROTECTED]:freeradius-1.1.4$ src/main/radiusd -AXf Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /usr/local/etc/raddb/proxy.conf Config: including file: /usr/local/etc/raddb/clients.conf Config: including file: /usr/local/etc/raddb/snmp.conf Config: including file: /usr/local/etc/raddb/eap.conf Config: including file: /usr/local/etc/raddb/postgresql.conf main: prefix = "/usr/local" main: localstatedir = "/usr/local/var" main: logdir = "/usr/local/var/log/radius" main: libdir = "/usr/local/lib" main: radacctdir = "/usr/local/var/log/radius/radacct" main: hostname_lookups = no main: max_request_time = 30 main: cleanup_delay = 5 main: max_requests = 1024 main: delete_blocked_requests = 0 main: port = 0 main: allow_core_dumps = no main: log_stripped_names = no main: log_file = "/usr/local/var/log/radius/radius.log" main: log_auth = no main: log_auth_badpass = no main: log_auth_goodpass = no main: pidfile = "/usr/local/var/run/radiusd/radiusd.pid" main: user = "(null)" main: group = "(null)" main: usercollide = no main: lower_user = "no" main: lower_pass = "no" main: nospace_user = "no" main: nospace_pass = "no" main: checkrad = "/usr/local/sbin/checkrad" main: proxy_requests = yes proxy: retry_delay = 5 proxy: retry_count = 3 proxy: synchronous = no proxy: default_fallback = yes proxy: dead_time = 120 proxy: post_proxy_authorize = no proxy: wake_all_if_all_dead = no security: max_attributes = 200 security: reject_delay = 1 security: status_server = yes main: debug_level = 0 read_config_files: reading dictionary read_config_files: reading naslist Using deprecated naslist file. Support for this will go away soon. read_config_files: reading clients read_config_files: reading realms radiusd: entering modules setup Module: Library search path is /usr/local/lib Module: Loaded exec exec: wait = yes exec: program = "(null)" exec: input_pairs = "request" exec: output_pairs = "(null)" exec: packet_type = "(null)" rlm_exec: Wait=yes but no output defined. Did you mean output=none? Module: Instantiated exec (exec) Module: Loaded expr Module: Instantiated expr (expr) Module: Loaded PAP pap: encryption_scheme = "crypt" pap: auto_header = yes Module: Instantiated pap (pap) Module: Loaded CHAP Module: Instantiated chap (chap) Module: Loaded MS-CHAP mschap: use_mppe = yes mschap: require_encryption = no mschap: require_strong = no mschap: with_ntdomain_hack = no mschap: passwd = "(null)" mschap: ntlm_auth = "(null)" Module: Instantiated mschap (mschap) Module: Loaded System unix: cache = no unix: passwd = "(null)" unix: shadow = "(null)" unix: group = "(null)" unix: radwtmp = "/usr/local/var/log/radius/radwtmp" unix: usegroup = no unix: cache_reload = 600 Module: Instantiated unix (unix) Module: Loaded eap eap: default_eap_type = "md5" eap: timer_expire = 60 eap: ignore_unknown_eap_types = no eap: cisco_accounting_username_bug = no rlm_eap: Loaded and initialized type md5 rlm_eap: Loaded and initialized type leap gtc: challenge = "Password: " gtc: auth_type = "PAP" rlm_eap: Loaded and initialized type gtc mschapv2: with_ntdomain_hack = no rlm_eap: Loaded and initialized type mschapv2 Module: Instantiated eap (eap) Module: Loaded preprocess preprocess: huntgroups = "/usr/local/etc/raddb/huntgroups" preprocess: hints = "/usr/local/etc/raddb/hints" preprocess: with_ascend_hack = no preprocess: ascend_channels_per_line = 23 preprocess: with_ntdomain_hack = no preprocess: with_specialix_jetstream_hack = no preprocess: with_cisco_vsa_hack = no preprocess: with_alvarion_vsa_hack = no Module: Instantiated preprocess (preprocess) Module: Loaded SQL sql: driver = "rlm_sql_postgresql" sql: server = "localhost" sql: port = "" sql: login = "ibrar" sql: password = "" sql: radius_db = "radius" sql: nas_table = "nas" sql: sqltrace = yes sql: sqltracefile = "/usr/local/var/log/radius/sqltrace.sql" sql: readclients = no sql: deletestalesessions = yes sql: num_sql_socks = 5 sql: sql_user_name = "%{User-Name}" sql: default_user_profile = "" sql: query_on_not_found = no sql: authorize_check_query = "SELECT id, UserName, Attribute, Value, Op ??FROM radcheck ??WHERE Username = '%{SQL-User-Name}' ??ORDER BY id" sql: authorize_reply_query = "SELECT id, UserName, Attribute, Value, Op ??FROM radreply ??WHERE Username = '%{SQL-User-Name}' ??ORDER BY id" sql: authorize_group_check_query = "SELECT radgroupcheck.id, radgroupcheck.GroupName, ??radgroupcheck.Attribute, radgroupcheck.Value,radgroupcheck.Op ??FROM radgroupcheck, usergroup ??WHERE usergroup.Username = '%{SQL-User-Name}' AND usergroup.GroupName = radgroupcheck.GroupName ??ORDER BY radgroupcheck.id" sql: authorize_group_reply_qu
Re: radexample.c
Thanks DeKok, I have read the debug output it says "auth: Failed to validate the user". But when I have tried same user/pass combination with radclient it works fine Here is my debug output. [EMAIL PROTECTED]:freeradius-1.1.4$ src/main/radiusd -AXf Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /usr/local/etc/raddb/proxy.conf Config: including file: /usr/local/etc/raddb/clients.conf Config: including file: /usr/local/etc/raddb/snmp.conf Config: including file: /usr/local/etc/raddb/eap.conf Config: including file: /usr/local/etc/raddb/postgresql.conf main: prefix = "/usr/local" main: localstatedir = "/usr/local/var" main: logdir = "/usr/local/var/log/radius" main: libdir = "/usr/local/lib" main: radacctdir = "/usr/local/var/log/radius/radacct" main: hostname_lookups = no main: max_request_time = 30 main: cleanup_delay = 5 main: max_requests = 1024 main: delete_blocked_requests = 0 main: port = 0 main: allow_core_dumps = no main: log_stripped_names = no main: log_file = "/usr/local/var/log/radius/radius.log" main: log_auth = no main: log_auth_badpass = no main: log_auth_goodpass = no main: pidfile = "/usr/local/var/run/radiusd/radiusd.pid" main: user = "(null)" main: group = "(null)" main: usercollide = no main: lower_user = "no" main: lower_pass = "no" main: nospace_user = "no" main: nospace_pass = "no" main: checkrad = "/usr/local/sbin/checkrad" main: proxy_requests = yes proxy: retry_delay = 5 proxy: retry_count = 3 proxy: synchronous = no proxy: default_fallback = yes proxy: dead_time = 120 proxy: post_proxy_authorize = no proxy: wake_all_if_all_dead = no security: max_attributes = 200 security: reject_delay = 1 security: status_server = yes main: debug_level = 0 read_config_files: reading dictionary read_config_files: reading naslist Using deprecated naslist file. Support for this will go away soon. read_config_files: reading clients read_config_files: reading realms radiusd: entering modules setup Module: Library search path is /usr/local/lib Module: Loaded exec exec: wait = yes exec: program = "(null)" exec: input_pairs = "request" exec: output_pairs = "(null)" exec: packet_type = "(null)" rlm_exec: Wait=yes but no output defined. Did you mean output=none? Module: Instantiated exec (exec) Module: Loaded expr Module: Instantiated expr (expr) Module: Loaded PAP pap: encryption_scheme = "crypt" pap: auto_header = yes Module: Instantiated pap (pap) Module: Loaded CHAP Module: Instantiated chap (chap) Module: Loaded MS-CHAP mschap: use_mppe = yes mschap: require_encryption = no mschap: require_strong = no mschap: with_ntdomain_hack = no mschap: passwd = "(null)" mschap: ntlm_auth = "(null)" Module: Instantiated mschap (mschap) Module: Loaded System unix: cache = no unix: passwd = "(null)" unix: shadow = "(null)" unix: group = "(null)" unix: radwtmp = "/usr/local/var/log/radius/radwtmp" unix: usegroup = no unix: cache_reload = 600 Module: Instantiated unix (unix) Module: Loaded eap eap: default_eap_type = "md5" eap: timer_expire = 60 eap: ignore_unknown_eap_types = no eap: cisco_accounting_username_bug = no rlm_eap: Loaded and initialized type md5 rlm_eap: Loaded and initialized type leap gtc: challenge = "Password: " gtc: auth_type = "PAP" rlm_eap: Loaded and initialized type gtc mschapv2: with_ntdomain_hack = no rlm_eap: Loaded and initialized type mschapv2 Module: Instantiated eap (eap) Module: Loaded preprocess preprocess: huntgroups = "/usr/local/etc/raddb/huntgroups" preprocess: hints = "/usr/local/etc/raddb/hints" preprocess: with_ascend_hack = no preprocess: ascend_channels_per_line = 23 preprocess: with_ntdomain_hack = no preprocess: with_specialix_jetstream_hack = no preprocess: with_cisco_vsa_hack = no preprocess: with_alvarion_vsa_hack = no Module: Instantiated preprocess (preprocess) Module: Loaded SQL sql: driver = "rlm_sql_postgresql" sql: server = "localhost" sql: port = "" sql: login = "ibrar" sql: password = "" sql: radius_db = "radius" sql: nas_table = "nas" sql: sqltrace = yes sql: sqltracefile = "/usr/local/var/log/radius/sqltrace.sql" sql: readclients = no sql: deletestalesessions = yes sql: num_sql_socks = 5 sql: sql_user_name = "%{User-Name}" sql: default_user_profile = "" sql: query_on_not_found = no sql: authorize_check_query = "SELECT id, UserName, Attribute, Value, Op ??FROM radcheck ??WHERE Username = '%{SQL-User-Name}' ??ORDER BY id" sql: authorize_reply_query = "SELECT id, UserName, Attribute, Value, Op ??FROM radreply ??WHERE Username = '%{SQL-User-Name}' ??ORDER BY id" sql: authorize_group_check_query = "SELECT radgroupcheck.id, radgroupcheck.GroupName, ??radgroupcheck.Attribute, radgroupcheck.Value,radgroupcheck.Op ??FROM radgroupcheck, usergroup ??WHERE usergroup.Username = '%{SQL-User-Name}' AND usergroup.GroupName = radgroupcheck.GroupName ??ORDER BY radgroupcheck.id" sql: authorize_group_reply_qu
Re: radexample.c
Ibrar Ahmed wrote: > Hi, > > Any body tells me how I can get working radexample with freeradius. I am > getting this packat one > server > User-Name = "test" > User-Password = "[EMAIL PROTECTED]" > NAS-IP-Address = 255.255.255.255 > NAS-Port = 0 Read the debug output. It will tell you what's wrong. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
radexample.c
Hi, Any body tells me how I can get working radexample with freeradius. I am getting this packat one server User-Name = "test" User-Password = "[EMAIL PROTECTED]" NAS-IP-Address = 255.255.255.255 NAS-Port = 0 But When I am running radtest with same server configuration I get this packet User-Name = "test" User-Password = "PASSWORD" NAS-IP-Address = 255.255.255.255 NAS-Port = 0 and i am get authenticated. --ibrar Finding fabulous fares is fun. Let Yahoo! FareChase search your favorite travel sites to find flight and hotel bargains. http://farechase.yahoo.com/promo-generic-14795097 - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html