Re: Problem with username and passowrd

2004-04-14 Thread Markus Ebel
Hi Alan If RADIUS is sending an Access-Accept, then the NAS is rejecting them. Look at the responses which don't get a LAN Security Error, and compare them to the responses which do get a LAN Security Error. Make the bad ones similar to the good ones, and it should work. Sorry, but

Re: User with 2 profiles but different simultaneous-use in each

2004-04-14 Thread Kostas Kalevras
On Wed, 7 Apr 2004, Kostas Zorbadelos wrote: At Tue, 6 Apr 2004 12:14:59 +0300 (EEST), Kostas Kalevras wrote: Dear Kostas first of all thanks for your answer. I don't have this module compiled in the binary versions I compiled. I saw its source code however inside src/modules. Is it an

Re: problems with ldap + ssl + eap-ttls

2004-04-14 Thread Alan DeKok
David Hart [EMAIL PROTECTED] wrote: I remain where I was originally. If I use openssl from the RedHat distribution as the default and mangle the Makefiles for eap-tls and eap-ttls to use the newer libraries, eap and ldap authentication work happily together, but I can't secure the ldap

Re: problems with ldap + ssl + eap-ttls

2004-04-14 Thread Michael Griego
On Wed, 2004-04-14 at 10:16, Alan DeKok wrote: I think this will require a few more patches to the server, as OpenSSL isn't thread-safe (I don't know why...) Has switching to OpenSSL thread-safe callbacks as opposed to protecting OpenSSL calls with a mutex ever been explored? -- --Mike

Re: Proxying PEAP/MSCHAP

2004-04-14 Thread Alan DeKok
Bob McCormick [EMAIL PROTECTED] wrote: If I include both of these lines: DEFAULTFreeRADIUS-Proxied-To =* 127.0.0.1, Proxy-To-Realm := LOCAL Hmm... I think that should have been !* instead of =*. Then the myrealm radius server does receive a request from the proxy, but issues the

Re: Proxying PEAP/MSCHAP

2004-04-14 Thread Bob McCormick
Woohoo!!! I think I finally got it to work! I put the following in the eap.conf file: peap { # The tunneled EAP session needs a default # EAP type which is separate from the one for # the non-tunneled

PAP and CHAP on same system

2004-04-14 Thread Bob Ross
I hope this can be done. After 9 years we started to expand services using realms for wholesale dialup out of our area. They require us to use CHAP. We have been PAP. They first told us it was PAP but after we went to set up it's CHAP. We have mysql loaded on the server but doesn't run correct,

Re: PAP and CHAP on same system

2004-04-14 Thread Alexander Lunyov
Hello Bob, Wednesday, April 14, 2004, 8:56:43 PM, you wrote: BR Is it possible for the CHAP server to send the request to the PAP server for BR authentication on the system files? It is not possible by design of CHAP. CHAP stands for this (simplified) scheme: 1. client send request

Re: PAP and CHAP on same system

2004-04-14 Thread Alan DeKok
Bob Ross [EMAIL PROTECTED] wrote: After 9 years we started to expand services using realms for wholesale dialup out of our area. They require us to use CHAP. We have been PAP. They first told us it was PAP but after we went to set up it's CHAP. FreeRADIUS doesn't care. If you have a

Re: PAP and CHAP on same system

2004-04-14 Thread Bob Ross
CVS?, never used it. - Original Message - From: Alan DeKok [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Wednesday, April 14, 2004 10:57 AM Subject: Re: PAP and CHAP on same system Bob Ross [EMAIL PROTECTED] wrote: After 9 years we started to expand services using realms for

Re: PAP and CHAP on same system

2004-04-14 Thread Bob Ross
This turns out to be a bit of trouble to maintain the list when users have to be locked because of no payment or other things. FreeRADIUS doesn't care. If you have a clear-text password in a local database, it will do PAP/CHAP, or whatever else is in the request. - List

Re: PAP and CHAP on same system

2004-04-14 Thread Alan DeKok
Bob Ross [EMAIL PROTECTED] wrote: CVS?, never used it. Did I tell you to use CVS? See the web page for details on what the CVS snapshot is, and where to get it. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PAP and CHAP on same system

2004-04-14 Thread Bob Ross
Of course not. Never meant to imply that you did. I had no idea what it was and was just letting you know I never used it, or what ever it was. I had no idea if it was a program or other. Bob - Original Message - From: Alan DeKok [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Wednesday,

different pools for user with and without traffic

2004-04-14 Thread Alexander Lunyov
Hello freeradius-users, I want freeradius to assign different IP addresses (from different networks) according to traffic balance of users. It means that if user have no traffic left for this month, freeradius will give him IP address from 192.168.222.0/24, and if user still have a

Re: Need a way to limit users to X number of hours per month.

2004-04-14 Thread Michael Griego
Take a look at the rlm_counter and rlm_sqlcounter modules. If you have installed the server, you can do a man rlm_counter and get an idea of how to use this module for what you need. On Wed, 2004-04-14 at 14:57, William Ragsdale wrote: Greetings, I need a way to limit a user to X hours per

Restring User to a NAS/Colubris network

2004-04-14 Thread carlos collart
Hi, I love Freeradius-MySQL-Dialupadmin ... It fixed my problem in a very inexpensive way have a SuSE 8.2 BOX running Freeradius0.9.3,MySQL 3.23.55-Max, Apache2 and I want: -validate a Username only with the NAS-IP-Address For example the username hotel can only access to the hotspot1(NAS-IP)