Re: rlm_eap_tls, no response from server

2004-10-01 Thread Alan DeKok
Lara Adianto [EMAIL PROTECTED] wrote:
 I did run the server in debugging mode. What I meant by the log is
 the debugging statement from running /radiusd -X -A.

  I'm sorry.  You posted ONE line out of the debug log, which showed
that the authentication failed.  The reason WHY it failed is contained
elsewhere in the debug log.

  Read the rest of the debug log to see why it failed, or post the
ENTIRE debug log to the list.

  Reading only one debug message out of 1000's is a guaranteed way to
not have the information you need to solve the problem.

  Alan DeKok.


- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


rlm_eap_tls, no response from server

2004-09-30 Thread Lara Adianto

Hi all,

I have a problem with rlm_eap_tls. The radius server doesn't seem to accept the access request from the access point, though the log file in the access point indicates that it has indeed sent an access request. 

First of all,
$ldd radiusd libcrypt.so.1 = /lib/libcrypt.so.1 (0x4001b000) libradius-0.9.3.so = /usr/local/lib/libradius-0.9.3.so (0x40048000)libltdl.so.3 = /usr/local/lib/libltdl.so.3 (0x4017f000) libdl.so.2 = /lib/libdl.so.2 (0x40186000) libnsl.so.1 = /lib/libnsl.so.1 (0x4018a000) libresolv.so.2 = /lib/libresolv.so.2 (0x401a1000) libpthread.so.0 = /lib/i686/libpthread.so.0 (0x401b3000) libc.so.6 = /lib/i686/libc.so.6 (0x401c8000) libcryptoki.so = /opt/Eracom/lib/libcryptoki.so (0x40303000)
 /lib/ld-linux.so.2 = /lib/ld-linux.so.2 (0x4000) libm.so.6 = /lib/i686/libm.so.6 (0x4031f000)

Is the above correct ?

Secondly, int the log file:
Info: Starting - reading configuration files ... Error: rlm_eap_tls: conf N ctx stored

Is the above normal ? I read on the previous post that this is normal with freeradius-0.9.3 (I know that freeradius-1.0.1 is out and more stable, but I'm sure that EAP/TLS can work with freeradius-0.9.3)

In http://www.missl.cs.umd.edu/wireless/eaptls/?tag=missl-802-1, it is said that EAP/TLS can only work with SNAP version of openssl-0.9.7. Is this right ?

Thanks for any reply,
lara
Alan DeKok [EMAIL PROTECTED] wrote:
Lara Adianto <[EMAIL PROTECTED]>wrote: Anyway, I've tried using freeradius-1.0.1 like what you have suggested, this time it complained about openssl/des.h:  Making static dynamic in rlm_x99_token...That module doesn't currently have a maintainter. If you're notusing it, delete the directory containing the module, and everythingelse will still work.Alan DeKok.- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html La vie, voyez-vous, ca n'est jamais si bon ni si mauvais qu'on croit- Guy de Maupassant -
		Do you Yahoo!?
Yahoo! Mail - Helps protect you from nasty viruses.

Re: rlm_eap_tls, no response from server

2004-09-30 Thread Alan DeKok
 Lara Adianto [EMAIL PROTECTED] wrote:
 I have a problem with rlm_eap_tls. The radius server doesn't seem to
 accept the access request from the access point, though the log file
 in the access point indicates that it has indeed sent an access
 request.

  I have no idea why you're looking in the log file, rather than
running the server in debugging mode, as suggested in the FAQ, README,
and daily on this list.

  Go run the server in debugging mode and READ the output.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


Re: rlm_eap_tls, no response from server

2004-09-30 Thread Lara Adianto
I did run the server in debugging mode. What I meant by the log is the debugging statement from running /radiusd -X -A. Alan DeKok [EMAIL PROTECTED] wrote:
Lara Adianto <[EMAIL PROTECTED]>wrote: I have a problem with rlm_eap_tls. The radius server doesn't seem to accept the access request from the access point, though the log file in the access point indicates that it has indeed sent an access request.I have no idea why you're looking in the log file, rather thanrunning the server in debugging mode, as suggested in the FAQ, README,and daily on this list.Go run the server in debugging mode and READ the output.Alan DeKok.- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html La vie, voyez-vous, ca n'est jamais si bon ni si mauvais qu'on croit-
 Guy de Maupassant -
		Do you Yahoo!?
Yahoo! Mail - 50x more storage than other providers!