More Questions

2003-12-18 Thread Roy Wills
FreeRadius on another FreeBSD machine and have it set up to use MySQL for usernames and such (working). In MySQL I am using the default database structure and have not modified any of it except for users and such. Now for the questions: 1: I have read all the Doc's that come with radius

Re: More Questions

2003-12-18 Thread Nick Davis
1: I have read all the Doc's that come with radius and searche dthe web and still have not found how to log accounting info in radius. I have turned on log_auth, log_auth_badpass, and log_auth_goodpass in radiusd.conf. Having done this I am still not getting any accounting info in the database

Re: More Questions

2003-12-18 Thread Alan DeKok
Roy Wills [EMAIL PROTECTED] wrote: I have turned on log_auth, log_auth_badpass, and log_auth_goodpass in radiusd.conf. Having done this I am still not getting any accounting info in the database or log file. Am I missing something here? Your NAS needs to send accounting packets. Nothing

Re: More Questions

2003-12-18 Thread Alan DeKok
Nick Davis [EMAIL PROTECTED] wrote: I guess it might be a good idea to ask Alan to put sql as a commented option in the authorize and accounting sections of the radiusd.conf. Done. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: More Questions

2003-12-18 Thread Mike Ockenga
file. Am I missing something here? I guess it might be a good idea to ask Alan to put sql as a commented option in the authorize and accounting sections of the radiusd.conf. You need to add sql to your accounting section of radiusd.conf if you want it to write accounting info the

Re: Upgrade questions

2003-12-15 Thread Alan DeKok
Nick Marino [EMAIL PROTECTED] wrote: Can anyone point in the direction of the best way to upgrade to Freeradius version 0.9.3 from version FreeRADIUS Version 0.8-pre with out losing my current configuration? $ make install Read the output. It warns you in big letters that it hasn't changed

Re: Upgrade questions

2003-12-15 Thread [EMAIL PROTECTED]
--- Alan DeKok [EMAIL PROTECTED] wrote: Nick Marino [EMAIL PROTECTED] wrote: Can anyone point in the direction of the best way to upgrade to Freeradius version 0.9.3 from version FreeRADIUS Version 0.8-pre with out losing my current configuration? $ make install Read the output. It

Re: Upgrade questions

2003-12-15 Thread Alan DeKok
[EMAIL PROTECTED] [EMAIL PROTECTED] wrote: yeah I have done that exactly before and it did overwrite my config that is one of the reasons I am asking. That must have been a very old version of the server. The current version does not overwrite any files in raddb/ Alan DeKok. - List

Re: Upgrade questions

2003-12-15 Thread [EMAIL PROTECTED]
--- Alan DeKok [EMAIL PROTECTED] wrote: [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: yeah I have done that exactly before and it did overwrite my config that is one of the reasons I am asking. That must have been a very old version of the server. The current version does not overwrite

Re: Upgrade questions

2003-12-15 Thread Alan DeKok
[EMAIL PROTECTED] [EMAIL PROTECTED] wrote: So the config files are competely the same between versions? No. Are any modifications needed on the config files after the install or will 0.9.3 run with 0.8 pre config files? Maybe. What about new fields in the mysql database are they also

Upgrade questions

2003-12-14 Thread Nick Marino
Can anyone point in the direction of the best way to upgrade to Freeradius version 0.9.3 from version FreeRADIUS Version 0.8-pre with out losing my current configuration? currently FreeRADIUS Version 0.8-pre is being used to authenticate users dialing into a Lucent Max 6000. If there is any

newbie alert Freeradius, EAP-TTLS, and OpenSSL questions

2003-11-21 Thread Chris Woodfield
of questions: 1. EAP-TTLS is dependent on EAP-TLS, which requires a server cert. So far, I've been unable to successfully create a cert that freeradius likes. In the radiusd.conf file, there's an certificate_file argument, along with a CA_file argument. My understanding of the reason

Re: newbie alert Freeradius, EAP-TTLS, and OpenSSL questions

2003-11-21 Thread Alan DeKok
Chris Woodfield [EMAIL PROTECTED] wrote: 1. EAP-TTLS is dependent on EAP-TLS, which requires a server cert. So far, I've been unable to successfully create a cert that freeradius likes. In the radiusd.conf file, there's an certificate_file argument, along with a CA_file argument. My

Re: newbie alert Freeradius, EAP-TTLS, and OpenSSL questions

2003-11-21 Thread Chris Woodfield
See scripts/CA.all Ran this, and it appears that everything worked right up until the end, when I got these errors: Certificate is to be certified until Nov 20 23:34:06 2004 GMT (365 days) Sign the certificate? [y/n]:y failed to update database TXT_DB error number 2 + openssl pkcs12 -export

Re: Radius newbie questions

2003-11-17 Thread Artur Hecker
hi alan Put a page on the web, and mail the URL to the list. The EAP-TLS documents should really be included with the server, but they're large, and need minor updates... Alan DeKok. a propos, what happened to those example certificates i've once mailed you? are they by any chance

Re: Radius newbie questions

2003-11-17 Thread Alan DeKok
Artur Hecker [EMAIL PROTECTED] wrote: a propos, what happened to those example certificates i've once mailed you? are they by any chance included with the server now? if not: do you want me to recreate them with some other options? They're gathering dust somewhere... Send them to me

Re: Radius newbie questions

2003-11-15 Thread Ted Kaczmarek
Got it, I will put together some examples going forward for submissions to a newbie doc. joeuser Auth-Type := Local, Service-Type = NAS-Prompt-User, Acct-Authentic == RADIUS, Vendor-Specific == 1991, Foundry-Privilege-level

Re: Radius newbie questions

2003-11-15 Thread Alan DeKok
Ted Kaczmarek [EMAIL PROTECTED] wrote: Got it, I will put together some examples going forward for submissions to a newbie doc. Please do so! Where would one submit docs for newbies? Put a page on the web, and mail the URL to the list. The EAP-TLS documents should really be included

Radius newbie questions

2003-11-14 Thread Kaczmarek, Thaddeus
Title: Radius newbie questions I just ordered the radius book, and used to use Funk software a while back. I can get logged in via freeradius but can't seem to figure out how to get foundry-privilege-level == 0 to work. I get logged in with read only permissions. rad_recv: Access-Request

Two questions about ippool

2003-10-30 Thread Agustín Orviz Camblor
Hello everybody: We have up un running freeradius 0.9.2 with rlm_ippool and rlm_sql (MySQL). We want to use the same server to do the accounting too. We have a Nortel CVX 1800 with a L2TP tunnel against a ASN Bay Networks router. 1.- The ASN doesn't pass the nas port information

Re: Configuration questions for FreeRadius with EAP/TTLS and LDAP

2003-09-12 Thread Alan DeKok
Nic Bernstein [EMAIL PROTECTED] wrote: I can see from the comments in the radiusd.conf file how to tell the radius server where to find which certificate(s) to use for EAP/TLS operation, but how does one specify what certificate to use for (the initial TLS phase of) the EAP/TTLS operation?

Configuration questions for FreeRadius with EAP/TTLS and LDAP

2003-09-11 Thread Nic Bernstein
We are trying to configure freeradius-snapshot-20030911 to use EAP/TTLS with LDAP (OpenLDAP 2.0.27). I have a few questions, however. I can see from the comments in the radiusd.conf file how to tell the radius server where to find which certificate(s) to use for EAP/TLS operation, but how does

rlm_perl questions

2003-07-09 Thread Bruce Cook
I'm a little confused as to how I should be using the rlm_perl (CVS) module. I've created a module that does some calcs and creates a couple of new A/V pairs that I wish to pass on to the proxy'd server as well as the SQL module for accounting. The only way I can seem to access these variables

questions about v0.9 updates

2003-07-08 Thread Dave Mason
Hi, I just checked out the change list for 0.9 and have questions about a couple of items. * Changed default entry in the 'users' file to 'Auth-Type = System', to allow EAP and Digest authentication to work automagically. It looked like the first DEFAULT in the v0.8.1 users file was Auth-Type

Re: questions about v0.9 updates

2003-07-08 Thread Alan DeKok
Dave Mason [EMAIL PROTECTED] wrote: It looked like the first DEFAULT in the v0.8.1 users file was Auth-Type := System. Is the fix to drop the : or am I missing something? In v0.8.1 I comment this out and use a line like this: DEFAULT Auth-Type := EAP The issue with doing that is that

Set up questions

2003-06-25 Thread Alex Chen
I am trying to set up both FreeRadius server and client to run on RH Linux 8.0 (two machines) with MySQL as the backend DB. I have some questions I hope someone can answer. It's a big list but I think it is better than to post a lot of small questions and create too much mail traffic. If you know

Re: Questions about the += users file operator...

2003-06-24 Thread Alan DeKok
[EMAIL PROTECTED] wrote: I'm trying to understand the semantics of the += users file operator. It's not so much about '+=', as the users file doesn't allow you to do what you want to do lerxst Crypt-Password == KSi8a3j4oasdi, ES-Default-ID += V90LocalUser ... DEFAULT ES-Default-ID ==

Questions about the += users file operator...

2003-06-23 Thread freeradius
Hi, I'm trying to understand the semantics of the += users file operator. I'd like to use it to select a particular DEFAULT entry based on a locally-defined dictionary attribute, as follows... # # V.90 dial-up user # # ES-Default-ID and V90LocalUser are defined in a local dictionary # lerxst

More Dialup_Admin questions

2003-06-11 Thread Don Click
Guys - I am sure these have been asked/answered, but Im having a hard time finding how to correct my issue. If I click on online users from the Dialup Admin pages, I see the correct number of lines (when adding users connected and lines free). HOWEVER, when I goto the NAS (USR Total Control

Re: two thread management questions

2003-04-09 Thread Dave Mason
This is a multi-part message in MIME format. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: two thread management questions

2003-04-05 Thread Alan DeKok
Dave Mason [EMAIL PROTECTED] wrote: 1. This may be an easy one but it may be relevant to the next one, so I'll ask to be sure. For now, we only want one thread to service all client requests. I'm not sure why it would matter. Should I run configure with --with-threads=no, or should I

two thread management questions

2003-04-04 Thread Dave Mason
have two questions about the Freeradius threading mechansim. We have freeradius 0.8.1 running on Red Hat 7.2. 1. This may be an easy one but it may be relevant to the next one, so I'll ask to be sure. For now, we only want one thread to service all client requests. Should I run configure

Re: questions about sql

2003-03-24 Thread Kostas Kalevras
On Thu, 20 Mar 2003, Simon Son wrote: Hello I was checking sql.conf and wondering what simul_count_query and simul_verify_query do simul_count_query counts the active sessions of a user simul_verify_query verifies each of them if simul_count_query returns more active sessions than allowed.

Re: EAP/TLS certificates and server questions

2003-03-21 Thread Thomas Maenner
Thanks Artur, hopefully, you can help me with a couple of things here: When the 'root' certificate runs out, what should / can I do? - it looks like I can not extend it's lifetime? - will a re-creation invalid the client certificates? Does a distribution of the root.der file have to be safe?

Re: EAP/TLS certificates and server questions

2003-03-21 Thread Thomas Maenner
Hi, you were so right... and I am so blind... Artur Hecker wrote: hi Thanks to the EAP/TLS Howto, I was able to setup the radius server and get all the authentification I needed going. Now the script, which creates the root certificate, generates root.pem with a lifetime of 30 days. After

Re: EAP/TLS certificates and server questions

2003-03-19 Thread Artur Hecker
hi Thanks to the EAP/TLS Howto, I was able to setup the radius server and get all the authentification I needed going. Now the script, which creates the root certificate, generates root.pem with a lifetime of 30 days. After that authentification doesn't work, OK. Last month I recreated

Re: questions about checkrad

2003-03-19 Thread Alan DeKok
Simon Son [EMAIL PROTECTED] wrote: If checkrad can't be run (nastype is other), then the information in radutmp is believed, and enforces Simultaneous-Use. I use sql for session,So I was wondering if above statment is applied to sql as well. Yes. Alan DeKok. - List

Re: questions about checkrad

2003-03-19 Thread Kristina Pfaff-Harris
On Wed, 19 Mar 2003, Ed H wrote: Hello Alan, Where is nastype=other, defined? In the clients.conf or in checkrad.pl? clients.conf :-) K. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: questions about checkrad

2003-03-19 Thread Ed H
: questions about checkrad Date: Wed, 19 Mar 2003 18:37:39 + Hello Alan, Where is nastype=other, defined? In the clients.conf or in checkrad.pl? Ed From: Alan DeKok [EMAIL PROTECTED] Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: questions about checkrad Date: Tue, 18 Mar 2003 13:06:58

Re: EAP/TLS certificates and server questions

2003-03-19 Thread Thomas Maenner
Thanks Artur, Artur Hecker wrote: hi Thanks to the EAP/TLS Howto, I was able to setup the radius server and get all the authentification I needed going. Now the script, which creates the root certificate, generates root.pem with a lifetime of 30 days. After that authentification doesn't

questions about sql

2003-03-19 Thread Simon Son
Hello I was checking sql.conf and wondering what simul_count_query and simul_verify_query do If a return value of simul_count_query of a user is more than one(say 3), does this means this user has 3 simultaneous sessions? Regards SImon - List info/subscribe/unsubscribe? See

Re: questions about checkrad

2003-03-18 Thread Ed H
Hello Alan, If I have an NAS box proxying to me, then how do I use Simultaneous-Use in a MySQL setup? Does it use checkrad? Ed From: Alan DeKok [EMAIL PROTECTED] Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: questions about checkrad Date: Mon, 17 Mar 2003 19:30:45 -0500

Re: questions about checkrad

2003-03-18 Thread Alan DeKok
Ed H [EMAIL PROTECTED] wrote: If I have an NAS box proxying to me, then how do I use Simultaneous-Use in a MySQL setup? Does it use checkrad? NAS boxes don't do proxying. If a RADIUS server proxies requests to you, then 99 times out of 100, you don't have access to their NAS equipment,

Re: questions about checkrad

2003-03-18 Thread Ed H
directive. Ed From: Alan DeKok [EMAIL PROTECTED] Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: questions about checkrad Date: Tue, 18 Mar 2003 08:13:05 -0500 Ed H [EMAIL PROTECTED] wrote: If I have an NAS box proxying to me, then how do I use Simultaneous-Use in a MySQL setup? Does

Re: questions about checkrad

2003-03-18 Thread Alan DeKok
Ed H [EMAIL PROTECTED] wrote: How do I use Simultaneous-Use with a MySQL setup? See 'doc/Simultaneous-Use' in the latest CVS head. Do I have to have the radumtp enabled in the radiusd.conf file under the session {} directive? Right now I only have sql enabled under the session directive.

Re: questions about checkrad

2003-03-18 Thread Ed H
{ # Get an address from the IP Pool. #main_pool } Ed From: Alan DeKok [EMAIL PROTECTED] Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: questions about checkrad Date: Tue, 18 Mar 2003 09:36:58 -0500 Ed H [EMAIL PROTECTED] wrote: How do I use Simultaneous-Use

Re: Questions about proxying

2003-03-18 Thread Toni Mueller
Hi, On Mon, Mar 17, 2003 at 11:47:58AM +0100, Toni Mueller wrote: On Tue, Feb 04, 2003 at 03:21:09PM -0600, Chris Parker wrote: At 10:04 PM 2/4/2003 +0100, Jacques Caruso wrote: Without success (the server continues to proxy the request for local users, and thus rejects our local users).

Re: questions about checkrad

2003-03-18 Thread Alan DeKok
Ed H [EMAIL PROTECTED] wrote: I do. What about the radutmp in session {} directive? I use radutmp more than SQL, so I can't help much with SQL questions. Here is my current setup, and I can't get Simultaneous-Use to work: Grab the CVS snapshot from last night. It should have more

Re: questions about checkrad

2003-03-18 Thread Simon Son
{ acct_unique detail sql } # Session database, used for checking Simultaneous-Use. The radutmp module # handles this session { sql } Regards, Simon Message: 3 From: Alan DeKok [EMAIL PROTECTED] To: [EMAIL PROTECTED] .Subject: Re: questions about checkrad Date: Tue, 18 Mar

Re: questions about checkrad

2003-03-18 Thread Alan DeKok
Simon Son [EMAIL PROTECTED] wrote: I think what you said in this reply is the situation I am in. So if I can't use checkrad, Can you suggest what I should do to make Simultaneous-Use work If checkrad can't be run (nastype is other), then the information in radutmp is believed, and

Re: questions about checkrad

2003-03-18 Thread Simon Son
Simon Message: 2 From: Alan DeKok [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: questions about checkrad Date: Tue, 18 Mar 2003 13:06:58 -0500 Reply-To: [EMAIL PROTECTED] Simon Son [EMAIL PROTECTED] wrote: I think what you said in this reply is the situation I am in. So if I can't

EAP/TLS certificates and server questions

2003-03-17 Thread Thomas Maenner
Hello all, I have a couple of maybe OT questions on certificates (And I am relatively new to certificates and stuff...) Thanks to the EAP/TLS Howto, I was able to setup the radius server and get all the authentification I needed going. Now the script, which creates the root certificate

questions about checkrad

2003-03-17 Thread Simon Son
Hello All I am trying to make simultaneous use work. It seems that checkrad is the script that check multiple logins. The compnay I work for uses bigger ISP's access service And from what I gather their radius server is configured to proxy request on.So all the authentication request are

questions about checkrad

2003-03-17 Thread Simon Son
Hello All I am trying to make simultaneous use work. It seems that checkrad is the script that check multiple logins. The compnay I work for uses bigger ISP's access service And from what I gather their radius server is configured to proxy request on.So all the authentication request are

Re: questions about checkrad

2003-03-17 Thread Alan DeKok
Simon Son [EMAIL PROTECTED] wrote: what I want to know is this . When I tried to run checkrad manually ,checkrad gives out following output. checkrad nas_type nas_ip nas_port login session_id Can anyone tell me what do I put as nas_type? Nothing. Their radius server is run on Sun

newbie questions...installed, authenticated, now what?

2003-02-10 Thread Matt Ashfield \(UNB\)
Hi All, I've been asked to investigate the use of a Radius server as a means of authenticating users on our network. Namely wireless, but really, just broad user authentication. I've been reading up some of the documentation and have been following this list, and it has been helpful,

Dialup_admin questions

2003-02-05 Thread Andrew Staples
Admitted newbie to radius/freeradius, the book is on order. Freeradius is installed and working with mysql. However: 1. Even though I have uncommented Dialup-Access in user_edits.attrs, when editing a user, that field is not available. Is this because in sql.attrmap I have: checkItem

RE: Dialup_admin questions

2003-02-05 Thread Andrew Staples
-Original Message- Kostas Kalevras Dialup-Access is an attribute used by the ldap module. It is not implemented in the sql module, that's why the mapping is set to none. You could set Auth-Type to Reject instead. [snip] So, the badusers table is used to keep bad account

RE: Dialup_admin questions

2003-02-05 Thread Kostas Kalevras
On Wed, 5 Feb 2003, Andrew Staples wrote: -Original Message- Kostas Kalevras Dialup-Access is an attribute used by the ldap module. It is not implemented in the sql module, that's why the mapping is set to none. You could set Auth-Type to Reject instead. [snip] So, the

Re: Questions about proxying

2003-02-04 Thread Jacques Caruso
Le Lundi 3 Février 2003 14:22, Alan DeKok a écrit : The best thing to do would be to convince them that using a realm for logins would be the best thing. That's how everybody else in the world does it. Yes, I am well aware of that, but hey, I simply don't have the power to do that

Re: Questions about proxying

2003-02-04 Thread Chris Parker
At 10:04 PM 2/4/2003 +0100, Jacques Caruso wrote: Le Lundi 3 Février 2003 14:22, Alan DeKok a écrit : The solution would be to put all of *your* users into a Unix group. You can then do: DEFAULT Group == myusers, Auth-Type := System # NO fall-through! DEFAULT Proxy-To-Realm =

Re: Questions about proxying

2003-02-04 Thread Alan DeKok
Jacques Caruso [EMAIL PROTECTED] wrote: Huh... a Unix group ? Since I'm working on a SQL backend, that isn't possible, but all our local users are already in a group in the SQL DB. I've thus added the Auth-Type attribute to the groups' attributes list in the radgroupreply table. Here is the

Questions about proxying

2003-02-03 Thread Jacques Caruso
Hi, I have set up two FreeRADIUS (0.8.1, Debian packages recompiled) servers, with a MySQL replicating backend. Since we provide a local PoP for a national ISP, I need to proxy requests to their RADIUS server. The problem is, they don't use any realm for their users. The best solution would have

Re: Questions about proxying

2003-02-03 Thread Alan DeKok
Jacques Caruso [EMAIL PROTECTED] wrote: I have set up two FreeRADIUS (0.8.1, Debian packages recompiled) servers, with a MySQL replicating backend. Since we provide a local PoP for a national ISP, I need to proxy requests to their RADIUS server. The problem is, they don't use any realm for

Re: Questions about proxying

2003-02-03 Thread Miquel van Smoorenburg
In article [EMAIL PROTECTED], Alan DeKok [EMAIL PROTECTED] wrote: Jacques Caruso [EMAIL PROTECTED] wrote: I have set up two FreeRADIUS (0.8.1, Debian packages recompiled) servers, with a MySQL replicating backend. Since we provide a local PoP for a national ISP, I need to proxy requests to

Re: Dynamic IP addresses from FreeRadius questions

2003-01-21 Thread Andrei Koulik
Hello, Tuesday, January 21, 2003, 5:51:06 AM, Li Lin wrote: LL Hi, LL I am setting up the dynamic IP addresses from FreeRadius and I have some LL questions as follows. LL 1. I included the rlm_ippool into the Makefile and put dbm in the users LL file. It is good idea to leave only modules you

Re: Dynamic IP addresses from FreeRadius questions

2003-01-21 Thread Simon White
20-Jan-03 at 21:51, Li Lin ([EMAIL PROTECTED]) wrote : I am setting up the dynamic IP addresses from FreeRadius and I have some questions as follows. 1. I included the rlm_ippool into the Makefile and put dbm in the users file. I do not know why I still get the following an error message

radwho questions

2002-12-04 Thread Ray
Using: freeRadius 0.7.1 just a couple of trivial questions about radwho that i didn't see in the man page. is there any way (short of recompiling it) to change the width of some of the columns? ('from' is getting trimmed to just 3 of the 4 parts of the ip '10.123.45', and TTY is 999

Re: radwho questions

2002-12-04 Thread William Ragsdale
On Wed, 4 Dec 2002 11:18:40 -0600 Ray [EMAIL PROTECTED] wrote: Using: freeRadius 0.7.1 just a couple of trivial questions about radwho that i didn't see in the man page. is there any way (short of recompiling it) to change the width of some of the columns? ('from' is getting trimmed

Questions

2002-11-21 Thread Don Click
Hi folks. We have been using the freeradius/dailup admin combo for about a year now, and things seem to be running very smooth. I do have some questions about the diaup admin web interface. Not sure if this is the right place, but it seems that I saw somewhere that they are now part

Re: Questions

2002-11-21 Thread Kostas Kalevras
On Thu, 21 Nov 2002, Don Click wrote: Hi folks. We have been using the freeradius/dailup admin combo for about a year now, and things seem to be running very smooth. I do have some questions about the diaup admin web interface. Not sure if this is the right place, but it seems that I saw

Re: Questions

2002-11-21 Thread Ador Dauz
the configuration is in the radius.conf, please take a look, and if your using mysql, take a look also sql.conf. - Original Message - From: Don Click [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Friday, November 22, 2002 6:35 AM Subject: Questions Hi folks. We have been using

Re: Simultaneous-User Questions

2002-11-06 Thread WA Support
Hello, Run the radius server in debugging mode (-x) and see what the NAS actually sends to the server when a person tries to authenticate. That will show you the data you can use in the users file to help determine where packets get proxied. I believe the Called-Station-Id is sent only in

Re: Simultaneous-User Questions

2002-11-06 Thread Alan DeKok
WA Support [EMAIL PROTECTED] wrote: I will look at running freeradius in debug mode, but I would rather set debug flags in checkrad. Most of your questions about what happens, and when it happens, can be answered by running the server in debugging mode, and reading the output. Have you

Re: Simultaneous-User Questions

2002-11-06 Thread WA Support
rather set debug flags in checkrad. Most of your questions about what happens, and when it happens, can be answered by running the server in debugging mode, and reading the output. Have you looked into using realms? I read this in the duplicate-users documentation: Now, about now

Re: Simultaneous-User Questions

2002-11-06 Thread Alan DeKok
WA Support [EMAIL PROTECTED] wrote: Thank you for your suggestions. However, no one has responded to why I don't see any debugging traffic coming from checkrad. Is it not being called? Did you read my previous message, where I told you how to find out the answer? I don't understand why

RE: New EAP/TLS + MPPE WinXP HOWTO questions with creating Certificate Authority (CA)

2002-11-05 Thread McKay, Raymond
Augustine wrote: Where do your find Raymond Mckay's file? http://www.impossiblereflex.com/8021x/eap-tls-HOWTO.htm - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Simultaneous-User Questions

2002-11-05 Thread Alan DeKok
WA Support [EMAIL PROTECTED] wrote: What I am trying to do is support the case where I have a user at IPS1 with the same username as a user at IPS2. For general information about this situation, see: doc/duplicate-users From what I can read, freeradius just queries the CVX (in this case)

Re: Simultaneous-User Questions

2002-11-05 Thread CTA
On 5 Nov 2002, at 14:44, WA Support wrote: From: WA Support [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject:Re: Simultaneous-User Questions Send reply to: [EMAIL PROTECTED] mailto:freeradius-users-request;lists.cistron.nl

Re: Simultaneous-User Questions

2002-11-05 Thread WA Support
] To: [EMAIL PROTECTED] Subject:Re: Simultaneous-User Questions Send reply to: [EMAIL PROTECTED] mailto:freeradius-users-request;lists.cistron.nl?subject=subscribe mailto:freeradius-users-request;lists.cistron.nl?subject=unsubscribe Date sent

Re: Simultaneous-User Questions

2002-11-05 Thread Kevin Bonner
On Tuesday 05 November 2002 16:44, WA Support wrote: What I want to do is check for username and called-station-id. The NAS reporst this back to freeradius, since it is recorded in the detail file. It should be very simple to rework the source for freeradius, i.e., radiusd.c, and check for

Re: New EAP/TLS + MPPE WinXP HOWTO questions with creating CertificateAuthority (CA)

2002-11-03 Thread augustine tsai
David, read the error messages. look likes u are missing some of the files..eg. newcert..pem, tranda1.p12... where do your find Raymond Mckay's file? There is another EAP/TLS howto, http://www.freeradius.org/doc/EAPTLS.pdf Augustine David Tran wrote: To All, I've followed Raymond Mckay

New EAP/TLS + MPPE WinXP HOWTO questions with creating Certificate Authority (CA)

2002-11-02 Thread David Tran
To All, I've followed Raymond Mckay EAP/TLS MPPE WinXP(SP1) HOWTO step-by-step on my RedHat Linux 8. Everything works great except on Chapter 6 where I have run into problems with "Certficate Generation" where the CA.root scripts work but the CA.svr and CA.clt do not. Here are the errors

Dictionary questions

2002-11-01 Thread Nils Rønhovde
Hi, I have installed FR 0.7.1 on a Solaris 8 machine. I have some small problems that seems to be related to the dictionaries. When I connect to my Cisco AS5400, I get some accounting-attributes that the server doesn't understand, and prints like this: Attr-198 = \000\000\000\001 Attr-255 =

Re: Dictionary questions

2002-11-01 Thread Chris Parker
At 11:40 AM 11/1/2002 +0100, Nils Rønhovde wrote: Hi, I have installed FR 0.7.1 on a Solaris 8 machine. I have some small problems that seems to be related to the dictionaries. When I connect to my Cisco AS5400, I get some accounting-attributes that the server doesn't understand, and prints

Re: Binaries/Config Multi Realm questions

2002-10-21 Thread Alan DeKok
Tim D. McCracken [EMAIL PROTECTED] wrote: Alan, THANKS for all your help. I am sure that it gets to be a drag sometimes! This thing sure has lots of options and it takes awhile to figure it all out. I hope I can contribute something soon to the effort! I have the sql stuff working now.

RE: Binaries/Config Multi Realm questions

2002-10-21 Thread Tim D. McCracken
-Original Message- From: [EMAIL PROTECTED] [mailto:freeradius-users-admin;lists.cistron.nl]On Behalf Of Alan DeKok Sent: Saturday, October 19, 2002 6:20 PM To: [EMAIL PROTECTED] Subject: Re: Binaries/Config Multi Realm questions Tim D. McCracken [EMAIL PROTECTED] wrote: I

Re: Newbie: Three freeradius questions

2002-10-18 Thread Artur Hecker
i would have answered you the same but i thought that somebody around here perhaps knows the reason you seemed to want to know... it has to be openssl-0.9.7 or later but i don't know exactly which function is new. ciao artur Damjan wrote: 1. EAP/TLS support, what do I need to get this

Newbie: Three freeradius questions

2002-10-17 Thread Damjan
Hello everyone, I'm new to Freeradius but would like to use it to replace old billing solution. For now I only have three questions: I have downloaded and compiled freeradius 0.7.1. 1. EAP/TLS support, what do I need to get this support in freeradius. I've read [*] that it needs openssl-0.9.7

Re: Newbie: Three freeradius questions

2002-10-17 Thread Damjan
1. EAP/TLS support, what do I need to get this support in freeradius. I've read [*] that it needs openssl-0.9.7, isn't openssl-0.9.6g enough? [OT] Is there a way to check if openssl supports EAP/TLS Answering to myself :), well according to http://www.freeradius.org/radiusd/doc/rlm_eap

General questions

2002-09-25 Thread Thor Spruyt
Hi, I need a radius server for a project and I am comparing some opensource solutions. I read the docs and faqs of FreeRadius, but I'm still puzzled about the following: 1) For accounting requests, can FreeRadius proxy and store into a local mySql database ? 2) What mechanisms are

Re: General questions

2002-09-25 Thread Alan DeKok
Thor Spruyt [EMAIL PROTECTED] wrote: 1) For accounting requests, can FreeRadius proxy and store into a local mySql database ? Yes. Before proxying the packet, it can do local accounting. 2) What mechanisms are available to update a user's attributes in a mySql database when a acct-stop

Re: General questions

2002-09-25 Thread Thor Spruyt
You can edit the SQL queries yourself. Nothing like an external program I can call or something ? Thor. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: General questions

2002-09-25 Thread Alan DeKok
Thor Spruyt [EMAIL PROTECTED] wrote: You can edit the SQL queries yourself. Nothing like an external program I can call or something ? Sure, it can do that too. Read the 'features' web page... Alan DeKok. - List info/subscribe/unsubscribe? See

Re: General questions

2002-09-25 Thread Thor Spruyt
Ok, thanx. Thor. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius on Solaris Binaries and Questions

2002-09-10 Thread Alan DeKok
Tim D. McCracken [EMAIL PROTECTED] wrote: Per the web site instructions - I am asking if anybody has Solaris binaries that they would be willing to share. There aren't any packages for Solaris right now, sorry. Has anyone tested FreeRadius on Solaris 9 yet? Has anyone tested the

FreeRadius on Solaris Binaries and Questions

2002-09-05 Thread Tim D. McCracken
All, Per the web site instructions - I am asking if anybody has Solaris binaries that they would be willing to share. I need the entire package including the daemon, radclient and other utils. (I need 32 Bit Solaris on Sparc). I do plan to set up the source later, but at this time I would

freeradius+mysql questions please

2002-09-02 Thread Yu Zhang
I try to explain my questions clearly. I have setup freeradius successfully,and now I can receive accept packet by compiling configure files,such as users,clients Later,I setup mysql successfully.I think successfully,because I can load the database schema and use sql commands. Later,I

Re: freeradius+mysql questions please

2002-09-02 Thread Kostas Kalevras
On Mon, 2 Sep 2002, Yu Zhang wrote: I try to explain my questions clearly. I have setup freeradius successfully,and now I can receive accept packet by compiling configure files,such as users,clients Later,I setup mysql successfully.I think successfully,because I can load the database

Re: freeradius+mysql questions please

2002-09-02 Thread Atanu Das
: Monday, September 02, 2002 1:23 PM Subject: freeradius+mysql questions please I try to explain my questions clearly. I have setup freeradius successfully,and now I can receive accept packet by compiling configure files,such as users,clients Later,I setup mysql successfully.I think

  1   2   >