on
their side.
My first and most important question is, is there a work-around perhaps
so I can get this customer live w/o them fixing their radius?
Should freeradius be accepting these connections, or is it in fact their
radius which is violating the spec?
--
Nathan Miller - [EMAIL PROTECTED]
VISP
will notify them that their radius server is definitely
violating the RFC. Thanks.
At 09:54 AM 2/25/2003 -0500, you wrote:
Nathan Miller
[EMAIL PROTECTED] wrote:
I am having a problem with a new client. Their radius server
is sending
back the requests I proxy to them using random ports. It
always arrives
' rather than a
specified port. This is correct
for many client protocols (mostly using TCP rather than UDP), but
definitely not for
RADIUS.
Tim
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On
Behalf Of Nathan Miller
Sent: Tuesday, February 25, 2003 2:06 PM
At 03:54 PM 1/28/2003 -0600, you wrote:
At 01:44 PM 1/28/2003 -0800, Nathan Miller wrote:
At 03:36 PM 1/28/2003 -0600, you wrote:
Don't include a NULL entry in your proxy.conf and it will then failover
to the next 'rlm_realm' module.
-Chris
Chris, Thanks for the prompt reply.. take a peek
authentication request to realm budget.net
Fri Jan 31 16:53:16 2003 : Debug: modcall[authorize]: module suffix
returns updated
- Nate
At 05:08 PM 1/31/2003 -0600, you wrote:
At 04:47 PM 1/31/2003 -0600, Chris Parker wrote:
At 02:37 PM 1/31/2003 -0800, Nathan Miller wrote:
At 03:54 PM 1/28/2003
Here's what I am trying to get freeradius-0.8.1 to do:
1. Request comes in looking like: FREDSISP#[EMAIL PROTECTED]
2. if exist (prefix), strip suffix and proxy
3. if not exist (prefix), proxy via suffix
4. if no match for suffix in proxy.conf, auth locally
Freeradius has support to do all
= DEFAULT
Tue Jan 28 12:48:56 2003 : Debug: rlm_realm: Authentication realm is LOCAL.
Now I can live w/o NULL, but I can't live w/o DEFAULT entry..
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies
Building The Nation's Largest Network of Successful ISPs.
-
List info/subscribe
match NULL but should not
match DEFAULT.
Let me take a look at that now.
-Chris
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies
Building The Nation's Largest Network of Successful ISPs.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
That's what I was hoping for..
any chance a coming release could have it's requirement omitted by default? =)
/var/log/radius.log.10:Mon Dec 23 17:25:23 2002 : Error:
/usr/local/etc/raddb/radiusd.conf[116]: Missing shortname for client:
xxx.xxx.xxx.x/24
the above error causes radiusd to
I seem to be having the same issue.. seems to happen randomly about once a
week on a production server running a simple perl backend for authentication.
snippet of log...
Thu Nov 14 15:26:38 2002 : Error: WARNING: Unresponsive child (id 65559)
for request 13464
Thu Nov 14 15:26:38 2002 : Error:
Total Hours: 13h42m
Average Online times: 1h01m per day,7h12m per week
Total Data transferred In/Out: 4.7M/27.5M
At 05:32 AM 1/16/2002 -0500, you wrote:
just usage data total hours
username total hours this month
Nathan Miller wrote:
if you'd
http://www.freeradius.org/list/users.html
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies - Building Better ISPs
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
mine does monthly reports.. at least how i need them to.
what exactly are you looking for?
At 03:12 PM 1/15/2002 -0500, you wrote:
Tried that one it does what we want but doesn't do a monthly report..
and I am not a scripter
- Original Message -
From: Nathan Miller [EMAIL PROTECTED
dial up accts
Nathan Miller wrote:
mine does monthly reports.. at least how i need them to.
what exactly are you looking for?
At 03:12 PM 1/15/2002 -0500, you wrote:
Tried that one it does what we want but doesn't do a monthly report..
and I am not a scripter
- Original Message
://www.freeradius.org/list/users.html
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies - Building Better ISPs
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Christmas for all!
Leo.
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies - Building Better ISPs
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Panic! This mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.309 / Virus Database: 170 - Release Date: 12/17/2001
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
--
Nathan Miller - [EMAIL PROTECTED]
VISP
not i
At 04:14 PM 12/18/2001 -0600, you wrote:
Is anyone else getting duplicate email from this list?
Thanks
Chris
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies - Building Better ISPs
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
not i g
At 04:14 PM 12/18/2001 -0600, you wrote:
Is anyone else getting duplicate email from this list?
Thanks
Chris
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies - Building Better ISPs
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
:
As a proxy or end RADIUS?
-Original Message-
From: Nathan Miller [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, December 11, 2001 3:16 PM
To: [EMAIL PROTECTED]
Subject: Re: Ready for Production Environment?
I'm running the 081101 snapshot production with a few tweeks
I hate to bring it up again; however, the last message never received a
response and this issue does seem to be an issue which has been reported
quite a few times in the past, and never recieved a valid response or fix
as yet to date.
Please see message dated: 11/29/01 Re: Realm
file in every connection attempt ?
do i neec exec-program or is radiusd -y? or enough ?
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies - Building Better ISPs
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
try change 'return T_INVALID;' to 'return -1' in 'userparse()' -
it's not working good too (possible type mismatch).
Mike.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
--
Nathan Miller - [EMAIL PROTECTED]
VISP Technologies - Building Better ISPs
At 10:53 AM 11/14/2001 -0500, you wrote:
Nathan Miller [EMAIL PROTECTED] wrote:
1. When received requests directly to the new freeradius machine from
either UUNet or other CHAP enabled provider, freeradius is _never_ sending
the CHAP-Challenge to the script nor logging it in the radius
At 04:30 PM 11/12/2001 -0500, you wrote:
Nathan Miller [EMAIL PROTECTED] wrote:
In that case, does it mean the values are being passed in HEX and not
Binary?
Yes. The values are passed exactly like they appear when printed in
debugging mode.
Looking at the data more closely, it does
At 04:30 PM 11/12/2001 -0500, you wrote:
Possible solutions:
1. A perl routine to convert octal - hex OR octal - binary for use in
md5 for comparing chap-password to digest.
2. Make freeradius truly send data in Hex rather than octal (I have a guy
working on this now, will submit patch
At 02:11 PM 11/8/2001 -0600, you wrote:
Uh oh.
Run the server with GDB:
gdb radiusd
...snipped...
(gdb) set args -x -x
(gdb) run
Now run your requests, then when it crashes:
(gbd) bt
And email the results to the list.
-Chris
For testing purposes, I have tried this using both Auth-Type :=
At 04:52 PM 11/8/2001 -0500, you wrote:
Nathan Miller [EMAIL PROTECTED] wrote:
Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread 1026 (LWP 1032)]
0x401edef0 in rad_mangle (data=0x80ba640, request=0x80c1d70)
at rlm_preprocess.c:154
154
At 06:56 PM 11/8/2001 -0500, you wrote:
I'd say there's a serious problem on your system somewhere. Have
you installed the server multiple times, from multiple versions? If
so, then the rlm_FOO may access data structures which no longer
exists.
Delete all binaries, and re-install.
I
29 matches
Mail list logo