Re: Authenticate all, based on NAS IP Addr ?

2003-11-26 Thread Oliver Graf
On Wed, Nov 26, 2003 at 02:48:53AM -0300, [EMAIL PROTECTED] wrote: Please, some one can giveme some idea about how get freeradius authenticate any request that comes from an specified NAS-IP ?. This NAS-IP-Address == 1.2.3.4 Auth-Type := Accept should do as radcheck. Oliver. -

Makefile.in?

2003-11-26 Thread
Hi! Have you seen the file Makefile.in in directory /src/modules/rlm_sql? I think it's better if TARGET = @targetname@ substitutes TARGET = rlm_sql? Thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Please accept my inclusion to the Mailing group

2003-11-26 Thread Oliver Graf
On Wed, Nov 26, 2003 at 02:22:14PM +0800, Radius User wrote: I am a new user of FreeRadius Server. I want to You're welcome. know how the clients make the access request. They (possibly) extract some information from the end-user, build a Access-Request packet and sent it to the radius

MS-CHAPv2 + LDAP

2003-11-26 Thread Andrej Brkic
Greetings to all the list readers, Running freeradius 0.9.3 and trying to make MS-CHAP work with LDAP, the setup is following: I have clients connecting to a pptp server with MPPE. MS-CHAPv2 is required for MPPE to work. Now since I have a LDAP database with all the users which is also used for

RE: Cisco h323 authentication

2003-11-26 Thread Sebastien HANUCHE
have a look ... maybe useful http://www.cisco.com/univercd/cc/td/doc/product/access/acs_serv/vapp_dev/vsa ig3.htm#129870 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of David Stanaway Sent: Tuesday, November 25, 2003 7:29 PM To: [EMAIL PROTECTED] Subject:

Intro to freeradius

2003-11-26 Thread Radius
Hi all, FreeRadius is new to me. I am looking for an brief introduction docfor freeradius that highlights what those files in /etc/raddb do for radiusd(eg, dictionary, mysql.conf .), while I am buying the radius book from O'Reilly. These days I have been trying to figure out what the

Re: Authentication process

2003-11-26 Thread ZORBADELOS KONSTANTINOS
At Tue, 25 Nov 2003 20:18:30 -0800 (PST), Mike Million wrote: [1 text/plain; us-ascii (7bit)] I am a novice here, so my question may sound pretty silly. I am trying to authenticate users through an Orinico AP-2500 WAP using an username a password. AP-2500 provides this portal page

Re: Intro to freeradius

2003-11-26 Thread Oliver Graf
On Wed, Nov 26, 2003 at 05:41:28PM +0800, Radius wrote: Attr-65470479 = 0x01 Attr-65470465 = 0x02 Attr-65470473 = 0x56 Attr-65470474 = 0x01 Attr-65470476 = 0x01 Attr-65470477 = 0x01 Attr-65470478 = 0x3fbf89ec Attr-65470466 =

Re: MS-CHAPv2 + LDAP

2003-11-26 Thread Giosuè Pacifico
Hi, you could include the samba schema in the ldap server using the ntPassword attribute for password. Use smbencrypt [string] to generate a NT Hash for testing. On samba site you should find more about automating this step in ldap-pdc docs. Better than nothing.. Bye Giosuè At 10.02 26/11/2003

Re: Postgresql Traffic Accounting Update

2003-11-26 Thread Peter Nixon
After checking back through the cvs history it seems that it has never been like this. I am currently out of the office on holiday, but I will certainly check this in in the near future. Cheers Peter David wrote: I had this problem with mysql and Dustin Doris mentioned the sql.conf file for

Re: MS-CHAPv2 + LDAP

2003-11-26 Thread Andrej Brkic
On Wed, Nov 26, 2003 at 12:12:54PM +0100, Giosuè Pacifico wrote: Hi, you could include the samba schema in the ldap server using the ntPassword attribute for password. Use smbencrypt [string] to generate a NT Hash for testing. On samba site you should find more about automating this step in

Re: Authenticate all, based on NAS IP Addr ?

2003-11-26 Thread Kevork
On Wed, Nov 26, 2003 at 02:48:53AM -0300, [EMAIL PROTECTED] wrote: Please, some one can giveme some idea about how get freeradius authenticate any request that comes from an specified NAS-IP ?. This NAS-IP-Address == 1.2.3.4 Auth-Type := Accept should do as radcheck. Oliver.

Re: MS-CHAPv2 + LDAP

2003-11-26 Thread Chris Wieringa
you could include the samba schema in the ldap server using the ntPassword attribute for password. Use smbencrypt [string] to generate a NT Hash for testing. On samba site you should find more about automating this step in ldap-pdc docs. Better than nothing.. Thanks, I will try that, but

Re: Authenticate all, based on NAS IP Addr ?

2003-11-26 Thread ZORBADELOS KONSTANTINOS
At Wed, 26 Nov 2003 09:24:15 -0300, Kevork wrote: On Wed, Nov 26, 2003 at 02:48:53AM -0300, [EMAIL PROTECTED] wrote: Please, some one can giveme some idea about how get freeradius authenticate any request that comes from an specified NAS-IP ?. This NAS-IP-Address == 1.2.3.4

Re: Postgresql Traffic Accounting Update

2003-11-26 Thread Didi Rieder
--On Wednesday, November 26, 2003 01:13:48 AM +0200 Peter Nixon [EMAIL PROTECTED] wrote: Thanks. I will check this into CVS tomorrow. I asked this list about this issue some week ago: http://www.mail-archive.com/[EMAIL PROTECTED]/msg21337.html http://www.mail-archive.com/[EMAIL

Tekbul internet Rehberi - iyi bayramlar.!

2003-11-26 Thread Tekbul Duyurular
Tüm islam aleminin Ramazan bayrami kutlu olsun.! Beraber nice bayramlara ... TEKBUL.COM Administrator http://www.tekbul.com --- Tekbul internet Rehberi - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Postgresql Traffic Accounting Update

2003-11-26 Thread David
I would agree that it should be changed as you propose. David David Blood Account Executive SpeedyQuick Networks, Inc Boise, Id www.speedyquick.net 208.284.5505 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Didi Rieder Sent: Wednesday, November 26, 2003

Re: Authenticate all, based on NAS IP Addr ?

2003-11-26 Thread Oliver Graf
On Wed, Nov 26, 2003 at 09:24:15AM -0300, Kevork wrote: On Wed, Nov 26, 2003 at 02:48:53AM -0300, [EMAIL PROTECTED] wrote: Please, some one can giveme some idea about how get freeradius authenticate any request that comes from an specified NAS-IP ?. This NAS-IP-Address == 1.2.3.4

Re: Intro to freeradius

2003-11-26 Thread Radius
Oliver, Thanks for your info. You are right. The NAS is using VSAs that not supported by freeradius. How does freeradius support VSA if VSAs are known? Can I simply change dictionary to match those VSAs? Thanks. Vincent - Original Message - From: Oliver Graf [EMAIL PROTECTED] To:

Re: Makefile.in?

2003-11-26 Thread Alan DeKok
=?GB2312?B?y9XP5g==?= [EMAIL PROTECTED] wrote: Have you seen the file Makefile.in in directory /src/modules/rlm_sql? I think it's better if TARGET = @targetname@ substitutes TARGET = rlm_sql? Yes. I've fixed it, thanks. Alan DeKok. - List info/subscribe/unsubscribe? See

RE: Cisco h323 authentication

2003-11-26 Thread David Stanaway
On Wed, 2003-11-26 at 03:24, Sebastien HANUCHE wrote: have a look ... maybe useful http://www.cisco.com/univercd/cc/td/doc/product/access/acs_serv/vapp_dev/vsa ig3.htm#129870 Thanks. I have been there, and I think my configuration is sufficient: aaa authentication login h323 group radius

LEAP

2003-11-26 Thread Cris Harrison
hi I just downloaded 0.93 no this is NOT how build etc.. only thing I need is RADIUS-LEAP Client that I can put on end uses desktop.. for a wireless network... any ideas... Cris Harrison www.phoenixcomm.net - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: LEAP

2003-11-26 Thread Alan DeKok
Cris Harrison [EMAIL PROTECTED] wrote: I just downloaded 0.93 no this is NOT how build etc.. only thing I need is RADIUS-LEAP Client that I can put on end uses desktop.. for a wireless network... any ideas... Google? Since you didn't say which platform you're using, it's difficult

Re: LEAP

2003-11-26 Thread Cris Harrison
At 10:07 AM 11/26/2003, Alan DeKok wrote: Cris Harrison [EMAIL PROTECTED] wrote: I just downloaded 0.93 no this is NOT how build etc.. only thing I need is RADIUS-LEAP Client that I can put on end uses desktop.. for a wireless network... any ideas... Google? Since you didn't say which

Re: 0.9.3 has been released

2003-11-26 Thread Nick Davis
Paul, Here is the email I am referring to: http://lists.cistron.nl/pipermail/freeradius-users/2003-July/021375.html The dependencies of concern are: freetype fonts, gtk, xfree86, xlibs. Those dep's were from debian Woody, I didn't actually test if those dependencies had been removed in Sarge

Re: Intro to freeradius

2003-11-26 Thread Oliver Graf
On Wed, Nov 26, 2003 at 11:18:05PM +0800, Radius wrote: Thanks for your info. You are right. The NAS is using VSAs that not supported by freeradius. How does freeradius support VSA if VSAs are known? Can I simply change dictionary to match those VSAs? The best is to create a dictonary file for

I need help

2003-11-26 Thread Jason Tres
I am a microsoft guy who is trying to learn linux, because I have to i freeradius on it. can anyone help me get started in the right direction. Any help is appreciated - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: MS-CHAPv2 + LDAP

2003-11-26 Thread 3APA3A
Dear Andrej Brkic, --Wednesday, November 26, 2003, 12:02:31 PM, you wrote to [EMAIL PROTECTED]: AB userPassword in the LDAP database is SHA1 encrypted and MS-CHAP need AB cleartext passwords and of course this is not working, is there any AB way of making this work without having cleartext

Re: I need help

2003-11-26 Thread Josh Howlett
Buy the O'Reilly RADIUS book. josh. On Wed, 2003-11-26 at 16:57, Jason Tres wrote: I am a microsoft guy who is trying to learn linux, because I have to i freeradius on it. can anyone help me get started in the right direction. Any help is appreciated - List info/subscribe/unsubscribe?

PostgreSQL

2003-11-26 Thread David Cadenas
Hi! I have a problem when I load the radiusd -X rlm_sql (sql): Driver rlm_sql_postgresql (module rlm_sql_postgresql) loaded and linked rlm_sql (sql): Attempting to connect to [EMAIL PROTECTED]:/radius rlm_sql (sql): starting 0 rlm_sql (sql): Attempting to connect rlm_sql_postgresql #0

Freeradius-Proxied-To not showing up in sql accounting

2003-11-26 Thread [EMAIL PROTECTED]
HI, I am using FreeRADIUS-0.9.1 primarily to proxy requests to other ISP's radius servers. I have 4 dial up accelerator servers that are acting as NAS's (clients to our radius server). I have added the vendors dictionary to FreeRADIUS and all seems to be working well, requests are proxied

Re: Freeradius-Proxied-To not showing up in sql accounting

2003-11-26 Thread Alan DeKok
[EMAIL PROTECTED] [EMAIL PROTECTED] wrote: I am currently in the process of setting up MySQL to handle the accounting records. Just about everything seems to working except I cannot get the attribute Freeradius-Proxied-To to write to my radacct table. Odds are that the attribute is added

Help with EAP/TLS config

2003-11-26 Thread John Furman
I am new to FreeRadius and 802.1x. I have had dealings with Livingston v1.xx v2.xx years ago in my days with an ISP. I am wondering if anyone has some pointers on how I should proceed from here. I am at a loss as to why this isn't working. Output and version info below. The intent of the

dialupAccess...

2003-11-26 Thread Rick Whitley
Is there a way to tell freeradius that the dialupAccess is an attribute in a user object and not radiusprofile? I am using eDirectory as my ldap server and the RADIUS-LDAPv3 schema file is not compatible. I do not have the experience at this point to rewrite the schema file and have been unable so

Re: 0.9.3 has been released

2003-11-26 Thread Bill Campbell
On Thu, Nov 20, 2003, Alan DeKok wrote: Bug reports are nice. Lack of notification is stupid. I'm running into a problem building 0.9.3 with MySQL support on FreeBSD 4.8 and on SuSE 9.0 Professional Linux. The problem is that the test for libmysqlclient fails with an undefined reference to

Re: Freeradius-Proxied-To not showing up in sql accounting

2003-11-26 Thread [EMAIL PROTECTED]
2. But when I use something like NTRadping to test the accounting start and accounting stop and send the additional attributes Freeradius-Proxied-To it gets written to both the master detail file and my radacct table. Find out what's different between the packets from the NAS, and the

Re: 0.9.3 has been released

2003-11-26 Thread Alan DeKok
Bill Campbell [EMAIL PROTECTED] wrote: Looking at the src/modules/rlm_sql/drivers/rlm_sql_mysql/configure.in file, I would think that $mysql_lib_dir should be at the beginning of the list of directories to check rather than the end. The mysql configuration succeeds with the attached patch.

Re: Freeradius-Proxied-To not showing up in sql accounting

2003-11-26 Thread Alan DeKok
[EMAIL PROTECTED] [EMAIL PROTECTED] wrote: I guess what has me stumped, is if it is showing up in the detail file then why wouldn't it show up sqltrace.sql ? When I use NTRadping, I add the Freeradius-Proxied-To = 111.222.111.222 and it is sent by NTRadping as a name/value pair and gets

Updates for broken VSA's.

2003-11-26 Thread Alan DeKok
I've updated the server so it can handle VSA's from broken vendors (who shall remain nameless). The attributes are now accepted by the server, and are Vendor-Specific, such as: Vendor-Specific = 0x0003616263 So the vendor 65535 (for testing) packs ASCII text into the attribute.

Re: Freeradius-Proxied-To not showing up in sql accounting

2003-11-26 Thread [EMAIL PROTECTED]
The request is logged to the accounting detail file, and THEN the FreeRADIUS-Proxied-To is generated, and the packet is proxied. Order is important. Since the packet was logged before it was proxied, there is no FreeRADIUS-Proxied-To attribute to log. OK, but the attribute is getting

Re: PostgreSQL

2003-11-26 Thread Peter Nixon
David Cadenas wrote: Hi! I have a problem when I load the radiusd -X rlm_sql (sql): Driver rlm_sql_postgresql (module rlm_sql_postgresql) loaded and linked rlm_sql (sql): Attempting to connect to [EMAIL PROTECTED]:/radius rlm_sql (sql): starting 0 rlm_sql (sql): Attempting to connect

Re: dialupAccess...

2003-11-26 Thread Kostas Kalevras
On Wed, 26 Nov 2003, Rick Whitley wrote: Is there a way to tell freeradius that the dialupAccess is an attribute in a user object and not radiusprofile? I am using eDirectory as my ldap server and the RADIUS-LDAPv3 schema file is not compatible. I do not have the experience at this point to

Election: America's Top Organizations -Multicultural Business Opportunities

2003-11-26 Thread Jill Hu
Title: Div2000.com Business Directory Press Release "Election for America's Top Organizations providing Multicultural Business Opportunities" Southport, CT November 24, 2003/DiversityBusiness.com/ The DiversityBusiness.com 4th

help me with cisco_pix525,freeradius and openldap?

2003-11-26 Thread jiang chong
hi, all,i am new to this list and freeradius.my environment is blow list: a cisco pix525 run as vpn. vpn authentication uses freeradius0.9.3 inside.the database of backend is OPENLDAP. who has such a solution? help me!!!help me!!! thank in advance regards, jiang

Can I use a .db for the password file?

2003-11-26 Thread Bill Brunton
I downloaded the latest freeradius 0.9.1. It looks like some dedicated individuals have done a lot of good work. What I would like to do is upgrade my primary, and secondary radius servers to freeradius. I will upgrade the secondary first, get things working there, and then upgrade the

accepting login authentication from a cisco NAS

2003-11-26 Thread Jason\(Website\)
Title: Message Hi all. I'am using a NAS - cisco 4500 router and trying to get it to use my freeradius installation on my RH8.0 box. Now i think i have the hosts file configured correctly Defines a RADIUS client. The format is 'client [hostname|ip-address]'## '127.0.0.1' is another name

Get country code from called station ID

2003-11-26 Thread Deepak Singhal
Can someone provide me with the logic of getting/stripping country code from the called-station-id in case of VOIP. Do the VOIP client needs to dial the number in some particular pattern. Regards Deepak Singhal

Re: Can I use a .db for the password file?

2003-11-26 Thread Oliver Graf
On Thu, Nov 27, 2003 at 12:09:29AM -0600, Bill Brunton wrote: I have looked throught the FAQ, the documentation and some of the files. What I would like to do is take the promary server /etc/password file, and the /etc/shadow file, and make a .db file of the usernames and passwords. Then I