Pre-paid VoIP documents

2004-02-24 Thread ROY
Can somebody point me to a document for billing/accounting pre-paid voip using the h323-credit-amount attribute? I'm having a hard time updating the radreply table after computing the debit amount. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: AlfaAriss Client Heeeeeeeeeeeeelp!!!!!!!

2004-02-24 Thread José Luis Solano
Hi Jean-Paul!!! I have your configuration in my freeradius-snapshot-20040222 but I have the following error: (see freeradius logs please). I don't understand the configuration of users file: #- # Connexion 801.x a0153 What is

Re: AlfaAriss Client Heeeeeeeeeeeeelp!!!!!!!

2004-02-24 Thread José Luis Solano
Note: With this user there is no logs about TTLS. any idea freeradius logs with 9991 EXISTS IN MY LDAP -- [EMAIL PROTECTED] raddb]# rad_recv: Access-Request packet from host 192.168.49.252:1225, id=1, length=144

Re: AlfaAriss Client Heeeeeeeeeeeeelp!!!!!!!

2004-02-24 Thread Jean-Paul Chapalain
Hi José, José Luis Solano wrote: Hi Jean-Paul!!! I have your configuration in my freeradius-snapshot-20040222 but I have the following error: (see freeradius logs please). I don't understand the configuration of users file: #- # Connexion

Re: AlfaAriss Client Heeeeeeeeeeeeelp!!!!!!!

2004-02-24 Thread José Luis Solano
hi jean-Paul, have you seen the freeradius logs and my LDAP configuration? How many attributes LDAP needs? How freeradius get the password? Thanks a lot and sorry if I ask a lot José Luis Solano SGI - Soluciones Globales Internet S.A. Delegación Regional Sur [EMAIL PROTECTED] (+34)

PEAP + XP + Freeradius 093 TLS : fatal access denied

2004-02-24 Thread Wilfried QUET
Hello, I have the following message in the radius.log rlm_eap_tls: TLS 1.0 Alert [length 0002], fatal access_denied I tried with intel adapter and cisco adapter. The result is the same. I tried with different ssl certificates but it's the same. Somebody can help me? Thanks Starting - reading

rlm_ippool + mysql problem

2004-02-24 Thread Javier Castillo Alcibar
Hello all!, I would like to config my freeradius server to store all the auth. info (also the acct. info) in a mysql database. I've deployed the database definition included with the freeradius source code, but it seems there is a problem with the rlm_ippool interaction: Module:

User disconnected based on total of packet size

2004-02-24 Thread Eden Santosong
Title: User disconnected based on total of packet size Dear All, In radius there is an attribut to limit user connection based on time (session-timeout attribut). If I want to provide connection To users based on number of packets they've downloaded, how could I do that ?. I have

probleme with eap_tls on freeradius-snapshot-200221028

2004-02-24 Thread Basile Mathieu
i use this howto http://www.impossiblereflex.com/9021x/eap-tls-HOWTO.htm to authenticate wifi users . i get the versions in this howto i am on a redhat 7.3 i can launch freeradius but when a AP try to authenticate i have /usr/local/sbin/radiusd relocation error

LDAP structure

2004-02-24 Thread José Luis Solano
Hi all, I use EAP/TTLS and a LDAP to store the users. What is the structure in my LDAP? do I need specific attributes in my LDAP (userPassword, etc)? do I need to change any schema files (RADIUS-LDAP.schema,RADIUS-LDAPv3.schema,RADIUS-SQL.schema)? Thanks in advance José Luis Solano SGI -

Re: rlm_ippool + mysql problem

2004-02-24 Thread Kostas Kalevras
On Tue, 24 Feb 2004, Javier Castillo Alcibar wrote: Hello all!, I would like to config my freeradius server to store all the auth. info (also the acct. info) in a mysql database. I've deployed the database definition included with the freeradius source code, but it seems there is a problem

Re: LDAP structure

2004-02-24 Thread Kostas Kalevras
On Tue, 24 Feb 2004, [iso-8859-1] Jos? Luis Solano wrote: Hi all, I use EAP/TTLS and a LDAP to store the users. What is the structure in my LDAP? do I need specific attributes in my LDAP (userPassword, etc)? do I need to change any schema files

CRL and/or OCSP for Certificates: what is the current status?

2004-02-24 Thread Patrick Mowry
Good day, I wish to use FreeRadius as the backend for EAP/TLS for a wireless network. I have everything working fine using a Netscape/iPlanet Certificate server. But I have not been able to deny access to a system with a revoked certificate. Searching the web I found an old e-mail about a

login scripts

2004-02-24 Thread Huebel, Tony
I was wondering if anyone else using freeradius had a problem with the windows clients not having their login scripts run (to map drives etc). It seems that with any sort of security (WEP or EAP-TLS with a RADIUS authentication server), the login script does not run when a user logs into windows.

Re: login scripts

2004-02-24 Thread Michael Griego
If you're using a machine on a Windows Domain, you must provide your client machine with a host certificate as well as any user certificates. If the PC does not have a host certificate as well, it will not be able to gain access to the network before attempting domain authentication. As such,

Re: Radius - Giganews

2004-02-24 Thread Alan DeKok
Natter [EMAIL PROTECTED] wrote: VENDORATTR 8226 Giganews-mbpm 101 [integer] where [integer] is the number of megabytes per month you want the customer to be capable of downloading. === I don't know where to put this or how to set the reply. $ man dictionary

EAP-TTLS and accounting

2004-02-24 Thread Rok Pape
Hello! Has anyone managed to solve the problem with anonymous user accounting ? Radiator uses perl scripts and MySQL database to correlate Accounting and Access-Accept messages. Is there an elegant way how to keep the database out of this ? I've only found this message:

Re: lcrypto/lssl error in make

2004-02-24 Thread Alan DeKok
Paul Blaich [EMAIL PROTECTED] wrote: Apologies for the long email. As you can see the configure completes ok, but it wont make. All you needed to quote was the last few lines with the error. Posting 100's of lines of everything works doesn't help. ~/freeradius-0.9.3./configure

Re: User disconnected based on total of packet size

2004-02-24 Thread Alan DeKok
Eden Santosong [EMAIL PROTECTED] wrote: time (session-timeout attribut). If I want to provide connection To users based on number of packets they've downloaded, how could I do that ?. You don't. I have searched all the attribut that could be used for disconnecting A user, one of them is

Re: probleme with eap_tls on freeradius-snapshot-200221028

2004-02-24 Thread Alan DeKok
Basile Mathieu [EMAIL PROTECTED] wrote: /usr/local/sbin/radiusd relocation error /usr/local/lib/rlm_eap_tls-0.8-pre.so undefined symbol SSL_set_msg_callback_arg if someone can help me i try with freeradius 0.9.3 and 0.9.3-3 and i try differents versions of openssl but without any success

Re: login scripts

2004-02-24 Thread Michael Griego
If you're using a machine on a Windows Domain, you must provide your client machine with a host certificate as well as any user certificates. If the PC does not have a host certificate as well, it will not be able to gain access to the network before attempting domain authentication. As such,

Re: Radius - Giganews

2004-02-24 Thread Alan DeKok
Natter [EMAIL PROTECTED] wrote: VENDORATTR 8226 Giganews-mbpm 101 [integer] where [integer] is the number of megabytes per month you want the customer to be capable of downloading. === I don't know where to put this or how to set the reply. $ man

EAP-TTLS and accounting

2004-02-24 Thread Rok Pape
Hello! Has anyone managed to solve the problem with anonymous user accounting ? Radiator uses perl scripts and MySQL database to correlate Accounting and Access-Accept messages. Is there an elegant way how to keep the database out of this ? I've only found this message:

Re: User disconnected based on total of packet size

2004-02-24 Thread Alan DeKok
Eden Santosong [EMAIL PROTECTED] wrote: time (session-timeout attribut). If I want to provide connection To users based on number of packets they've downloaded, how could I do that ?. You don't. I have searched all the attribut that could be used for disconnecting A user, one of them is

Re: probleme with eap_tls on freeradius-snapshot-200221028

2004-02-24 Thread Alan DeKok
Basile Mathieu [EMAIL PROTECTED] wrote: /usr/local/sbin/radiusd relocation error /usr/local/lib/rlm_eap_tls-0.8-pre.so undefined symbol SSL_set_msg_callback_arg if someone can help me i try with freeradius 0.9.3 and 0.9.3-3 and i try differents versions of openssl but without any success

Re: CRL and/or OCSP for Certificates: what is the current status?

2004-02-24 Thread Alan DeKok
Patrick Mowry [EMAIL PROTECTED] wrote: Is this patch still required or has this or something like it been added to the mainline code? Read doc/ChangeLog. Look for Certificate Revocation. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -

Re: lcrypto/lssl error in make

2004-02-24 Thread Alan DeKok
Paul Blaich [EMAIL PROTECTED] wrote: Apologies for the long email. As you can see the configure completes ok, but it wont make. All you needed to quote was the last few lines with the error. Posting 100's of lines of everything works doesn't help. ~/freeradius-0.9.3./configure

Re: login scripts

2004-02-24 Thread Michael Griego
If you're using a machine on a Windows Domain, you must provide your client machine with a host certificate as well as any user certificates. If the PC does not have a host certificate as well, it will not be able to gain access to the network before attempting domain authentication. As such,

Re: CRL and/or OCSP for Certificates: what is the current status?

2004-02-24 Thread Alan DeKok
Patrick Mowry [EMAIL PROTECTED] wrote: Is this patch still required or has this or something like it been added to the mainline code? Read doc/ChangeLog. Look for Certificate Revocation. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -

Re: Radius - Giganews

2004-02-24 Thread Alan DeKok
Natter [EMAIL PROTECTED] wrote: VENDORATTR 8226 Giganews-mbpm 101 [integer] where [integer] is the number of megabytes per month you want the customer to be capable of downloading. === I don't know where to put this or how to set the reply. $ man

Re: lcrypto/lssl error in make

2004-02-24 Thread Alan DeKok
Paul Blaich [EMAIL PROTECTED] wrote: Apologies for the long email. As you can see the configure completes ok, but it wont make. All you needed to quote was the last few lines with the error. Posting 100's of lines of everything works doesn't help. ~/freeradius-0.9.3./configure

Re: User disconnected based on total of packet size

2004-02-24 Thread Alan DeKok
Eden Santosong [EMAIL PROTECTED] wrote: time (session-timeout attribut). If I want to provide connection To users based on number of packets they've downloaded, how could I do that ?. You don't. I have searched all the attribut that could be used for disconnecting A user, one of them is

Re: probleme with eap_tls on freeradius-snapshot-200221028

2004-02-24 Thread Alan DeKok
Basile Mathieu [EMAIL PROTECTED] wrote: /usr/local/sbin/radiusd relocation error /usr/local/lib/rlm_eap_tls-0.8-pre.so undefined symbol SSL_set_msg_callback_arg if someone can help me i try with freeradius 0.9.3 and 0.9.3-3 and i try differents versions of openssl but without any success

RE: EAP-TTLS and accounting

2004-02-24 Thread Tom Rixom
Hi, Just return the inner username back to the access point with the = Access-Accept=20 message and the access point (if it followes standard procedure) will = return the Accounting request with the correct inner username. This has been tested on Cisco 1100 and 1200. Regards, Tom Rixom

EAP-TTLS error

2004-02-24 Thread José Luis Solano
hi all I feel I'm in the correct way, but I have an error, so help me please. I show you my freeradius error in the following lines. Note authorization step is correct but not authentication step. (if you need my radiusd.conf, please tell me and I will send you) Thanks freeradius logs

Re: LEAP with iPAQ 5450, Cisco 340 Series AP, and freeradius

2004-02-24 Thread Derek Orpen
On 21-Feb-2004 15:43 Alan DeKok wrote: | Derek Orpen [EMAIL PROTECTED] wrote: | In any case, I created a special build of freeradius that works with | the HP client and was able to complete my testing. Thanks for pointing | me in the right direction. | | That's what I'm here for. | | Can

Re: Freeradius-Users digest, Vol 1 #2893 - 16 msgs

2004-02-24 Thread Edmund C. Greene
The biggest thing I want here is real time updates. I have a process in place where people go to a web page and authenticate then their mac address is placed in our DHCP server. I would like to migrate this to radius to use MAC authentication. I would envision the client entries being stored

Thanks

2004-02-24 Thread José Luis Solano
Thanks, my freeradius runs. José Luis Solano

Hotspot nearing completion

2004-02-24 Thread Daniel Baughman
My install has come a long way and now I have nas AP's accepting querys, web site sign ups, credit cards accepted via ssl, postgresql radius server's performing logging and documentation of usage statistics. Now but one thing remains: How can I tell the NAS AP's to time out a user's

Re: AlfaAriss Client question

2004-02-24 Thread Hans Fiedler
I see where everyone can have it work with Windows XP, but my problem is with Windows 2000. I havn't been able to find a method for enabling WEP on a Cisco 350 without using the Cisco ACU instead of the Windows 801.X method. On the driver config the only things that are available are; Client

Re: Hotspot nearing completion

2004-02-24 Thread Alan DeKok
Daniel Baughman [EMAIL PROTECTED] wrote: How can I tell the NAS AP's to time out a user's connection after he has used his allotted minutes? See the Session-Timeout attribute. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Radius Start Errors

2004-02-24 Thread Tre Johnston
When I try and start radiusd I get the following error : Error :radiusd.conf[1771] Subsection of module instance call not allowed Does anyone know what this is exactly or how to fix it? Thanks! Tre Johnston - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Radius Start Errors

2004-02-24 Thread Alan DeKok
Tre Johnston [EMAIL PROTECTED] wrote: When I try and start radiusd I get the following error : Error :radiusd.conf[1771] Subsection of module instance call not allowed Does anyone know what this is exactly or how to fix it? It means you did something wrong. What does line 1771 of

RE: Radius Start Errors

2004-02-24 Thread Tre Johnston
Here is line 1772 in the config: accounting { And if I knew the product like you do I would be asking questions, let alone these questions cause I don't know exactly where to begin the troubleshooting. Tre -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of

Re: Radius - Giganews

2004-02-24 Thread Natter
I guess that is where I'm getting confused. I added it to my dictionary file: (ATTRIBUTE Giganews-mbpm 101 integer) and I added a new line to the radreply table: username: test attribute: Giganews-mbpm op: == value: 1 (to limit my user to 1 meg from Giganews) When I test this from a

how to return proper reply attributes per nas type

2004-02-24 Thread Kevin Jeoung
Hi, I am wondering if there is a way to return proper reply attributes per nas type. In short, I need to return some sort of pre-listed attributes not by users but by nastype. For example, I want to return some USR VSAs for a request from usrhiper type and Ascend VSAs for a request from

RE: CRL and/or OCSP for Certificates: what is the current status?

2004-02-24 Thread Patrick Mowry
Thanks, I found this in the CVS Snapshot changelog for anyone else searching the list archives. FreeRADIUS 1.0.0 ; $Date: 2004/02/19 18:37:11 $, urgency=low ... * EAP-TLS now checks Certificate Revocation List ... Thanks again, -Patrick -Original Message- From: Alan DeKok

Re: Radius - Giganews

2004-02-24 Thread Christopher Kotran
Natter, how much does GigaNews cost you? CK - Original Message - From: Natter [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Tuesday, February 24, 2004 4:02 PM Subject: Re: Radius - Giganews I guess that is where I'm getting confused. I added it to my dictionary file: (ATTRIBUTE

Re: Radius - Giganews

2004-02-24 Thread Natter
I don't know. I'm doing this for a local isp. Why? I think I got it working. I added this to the dictionary file: VENDOR Giganews 8226 ATTRIBUTE Giganews-mbpm101 integer Giganews I tested a user and after I got over a meg, it gave me a message that said I'm over my

Re: Hotspot nearing completion

2004-02-24 Thread Daniel Baughman
So from what I read it seems that I might be able to do something like this: in the postgresql.conf define a new variable like this: my_session_timeout = SELECT minutes_left from ${acct_tablex} where user = '%{SQL-User-Name}' Then back in the radiusd.conf do this for the session-timeout:

Re: Hotspot nearing completion

2004-02-24 Thread Albert Miles Enabe
"Daniel Baughman" [EMAIL PROTECTED] wrote: So from what I read it seems that I might be able to do something like this: in the postgresql.conf define a new variable like this: my_session_timeout = "SELECT minutes_left from ${acct_tablex} where user = '%{SQL-User-Name}' " Then back

Re: what mechanism does freeradius implementation of radiususe to authenticate a client

2004-02-24 Thread Daniel Baughman
if you have installed you should have a radiusd.conf file loaded with documentation. Most people store ther nas client info in the clients.conf and users info in a users file. Dan - Original Message - From: Sayantan Bhowmick To: [EMAIL PROTECTED] Sent: Tuesday,