Re: Re-writes required for proxied connections - HOWTO

2004-06-02 Thread Stephan Jaeger
Hi, Am Di, den 01.06.2004 um 23:10 Uhr +0100 schrieb paul hanson: Hi, I have the latest 0.93 available on SuSE Professional 9.1 and need to proxy in-bound requests based upon the called phone number. The most obvious way would be to add a realm name to the 'user name' and proxy based

radclient regression (from V1.60) ?

2004-06-02 Thread Geoffroy Arnoud
Hello, I am using radclient fom FreeRADIUS in CVS version 1.60. It works fine. I saw that radclient evolved to deal with several files / several requests per file. That's an interesting feature for what I need. Nevertheless, reading radclient.c (I haven't tested it yet), I think that a

Re: FreeRADIUS 1.0.0-pre1 released

2004-06-02 Thread Graeme Hinchliffe
On Tue, 1 Jun 2004 06:18:57 +1000 Paul Hampson [EMAIL PROTECTED] wrote: Ladies and gentlemen, We are proud to announce that the 1.0.0 release cycle for FreeRADIUS is entering its final stages. The first pre-release wide-area-test tarball is on the FreeRADIUS website:

Re: Help adding users

2004-06-02 Thread Frédéric EVRARD
Frédéric EVRARD wrote: Hi group Is there a guide somewhere on how to add users on FreeRADIUS ?? Im new to linux, and radius, and need a complete HOWTO on how to add users. Here's many howto for 802.1x/EAP-TLS with WinXP FreeRADIUS, maybe you will want to use an other EAP method, but I hope

Re: EAP/TLS win2000

2004-06-02 Thread Frédéric EVRARD
hi Artur, hi Frederic What do you want to say is that win2K is going to take EAP-Identity value in client certificate, before EAP-TLS challenge start ?? I don't think so, it doesn't work like that with Xsupplicant/FreeRADIUS and it's not describe like this in RFC. no. what i want to

Debian backport of FreeRADIUS-1.0.0-pre1 to woody

2004-06-02 Thread Graeme Hinchliffe
Hiya As the subject suggests. Anyone done a backport of this yet to woody? Thanks in advance -- - Graeme Hinchliffe (BSc) Core Internet Systems Designer Zen Internet (http://www.zen.co.uk/) ICQ 3842605 (link) Direct: 0845 058 9074 Main : 0845 058 9000 Fax : 0845 058

rlm_eap_ttls won't link in 1.0.0-pre0

2004-06-02 Thread Paul Hampson
Sorry, another stuff up by me. In testing, it built OK, but after the last minor change I made I didn't notice that it had stopped linking. The proposed fix is to replace rlm_eap_tls.la in Makefile.in with rlm_eap_tls.lo. This allows it to link, but I don't have a test load I can throw at it, so

Re: Debian backport of FreeRADIUS-1.0.0-pre1 to woody

2004-06-02 Thread Paul Hampson
On Wed, Jun 02, 2004 at 10:51:33AM +0100, Graeme Hinchliffe wrote: As the subject suggests. Anyone done a backport of this yet to woody? I haven't yet. There were some people doing 0.9 backports, dunno if they'll pick up the prereleases though. I don't intend to do a backport until we

BUG : Issue with listen { } and port number : BUG

2004-06-02 Thread Graeme Hinchliffe
Hiya Was very happy to see the listen { } stanza in version 1.0.0-pre1. however I suspect I have also discovered an issue with it. I initially tried the following config: port = 1645 listen { ipaddr = * port = 1645 type = auth } But freeRADIUS refused to start,

Bug in radclient

2004-06-02 Thread Geoffroy Arnoud
Hello, I think there is a bug in radclient (since v1.63?). I currently use radclient v1.60, and it works fine. I saw that new functionalities appeared, and I downloaded V1.72. Reading the radclient.c source file, I became a little plerplex about the '-i' feature, which allows to set the ID of

Re: BUG : Issue with listen { } and port number : BUG

2004-06-02 Thread Kevin Bonner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wednesday 02 June 2004 07:11, Graeme Hinchliffe wrote: Ideally I would like to only listen on the one port 1645. Comment out the main config port entry and only use the listen directive. This should do what you want. - - Kevin -BEGIN PGP

Re: BUG : Issue with listen { } and port number : BUG

2004-06-02 Thread Graeme Hinchliffe
On Wed, 2 Jun 2004 09:16:05 -0400 Kevin Bonner [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wednesday 02 June 2004 07:11, Graeme Hinchliffe wrote: Ideally I would like to only listen on the one port 1645. Comment out the main config port entry and only use

Re: BUG : Issue with listen { } and port number : BUG

2004-06-02 Thread Kevin Bonner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wednesday 02 June 2004 09:17, Graeme Hinchliffe wrote: I have tried this also (seems I missed it) and it behaves in the same was as if port = 0 is specified. You probably have the bind option enabled as well. Comment out both the 'bind=' and

Re: BUG : Issue with listen { } and port number : BUG

2004-06-02 Thread Kevin Bonner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wednesday 02 June 2004 09:38, Kevin Bonner wrote: You probably have the bind option enabled as well. Sorry, that's the bind_address option. - - Kevin -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.3 (GNU/Linux)

rlm_sqlcounter

2004-06-02 Thread Manjunath M Prabhu
hi all, i have been working on freeradius for quite sometime and have some doubts.. 1.As per rlm_sqlcounter document i have implemented almost everything.but i get this error radiusd.conf[1] Failed to link to module 'rlm_sqlcounter': rlm_sqlcounter.so: cannot open shared object file: No such

Re: BUG : Issue with listen { } and port number : BUG

2004-06-02 Thread Alan DeKok
Kevin Bonner [EMAIL PROTECTED] wrote: You probably have the bind option enabled as well. Comment out both the 'bind=' and the 'port=' options in radiusd.conf and it will use only what at you have configured in the listen directives. Which is what it says in the comments, just above the new

Freeradius capabilities

2004-06-02 Thread Hugo Chasqueira
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 (Please ignore any duplicates of this message) Hi, Someone is confronting me to choose between freeradius and another radius server. They claim the other radius server works better than freeradius. Their claims are the following: * Freeradius

Re: user with more than one NAS Server

2004-06-02 Thread Alan DeKok
Ahmad Cheikh Moussa [EMAIL PROTECTED] wrote: Is it possible to give a user more than one NAS Server in the first line ?? On the old livingston radius server you had to make two user entries, when ou tried to enable a user to dialin on more than one dialin server. It's pretty much the same

Re: Freeradius capabilities

2004-06-02 Thread Kostas Kalevras
On Wed, 2 Jun 2004, Hugo Chasqueira wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 (Please ignore any duplicates of this message) Hi, Someone is confronting me to choose between freeradius and another radius server. They claim the other radius server works better than

Re: Freeradius capabilities

2004-06-02 Thread Bob McCormick
I can verify that the latest CVS releases do indeed support PEAP and Active directory. I'm using it now to authenticate users to our Active Directory. All our users use PEAP using the supplicant built into WinXP service Pack1 and Windows 2000 service pack 4. For authenticating to Active

Re: Re-writes required for proxied connections - HOWTO

2004-06-02 Thread Gary McKinney
Alan, I am currently working on a php based front-end (so to speak) to allow configuration for freeradius's use of mysql database tables (modified for my specific use) and your response given below brought up a question I have read about the radcheck/radreply table entries in the mysql

netbios name in peap

2004-06-02 Thread Basile Mathieu
i configure peap on xp and when i dont use the session information all works fine but when i use the session information the user name which is sent is NETBOISNAME\\user if someone can help me thanks basile - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: netbios name in peap

2004-06-02 Thread Alan DeKok
Basile Mathieu [EMAIL PROTECTED] wrote: i configure peap on xp and when i dont use the session information all works fine but when i use the session information the user name which is sent is NETBOISNAME\\user Ok... so what's the problem? You can configure the server to strip off the

Re: documentation or option needed with other nastype and checkrad

2004-06-02 Thread Alan DeKok
Ted Cabeen [EMAIL PROTECTED] wrote: That's not a bad idea, but the problem is that I don't know the IPs that the requests will be originating from. The outsourced dialup provider has thousands of NASes across the US, and I don't have a list of every NAS they have. The NASes should be

Re: Re-writes required for proxied connections - HOWTO

2004-06-02 Thread Alan DeKok
Gary McKinney [EMAIL PROTECTED] wrote: I am currently working on a php based front-end (so to speak) to allow configuration for freeradius's use of mysql database tables Ok... what's wrong with dialup_admin? It's been around for as long as FreeRADIUS, many people use it, and it works with

Re: Re-writes required for proxied connections - HOWTO

2004-06-02 Thread Gary McKinney
Hi Alan, Nothing is wrong with dialup_admin - I just want to get my feet wet working with php and thought it would be a good real-world project [glutton for punishment I suppose]... I guess the best way for me to figure out how the radcheck works is to examine the sql query used by the code

xlat.c bug w.r.t. %{reply:Packet-Type}

2004-06-02 Thread freeradius
I've just upgraded to 1.0.0pre1 from a mid-March CVS build and noticed that expansion of %{reply:Packet-Type} in my post-auth config returns null/no longer works. My post_auth section from radiusd.conf says: post-auth { # log the request sql Post-Auth-Type REJECT {

Problems with no DB handles to use on 1.0.0-pre1

2004-06-02 Thread Matthew Schumacher
List, I have been getting a lot of There are no DB handles to use! skipped 0, tried to connect 0 errors on 1.0.0-pre1 even though I have 32 connections to the database. The database server is not having performance problems from what I can tell. I am only using simple insert queries from

Re: xlat.c bug w.r.t. %{reply:Packet-Type}

2004-06-02 Thread Alan DeKok
[EMAIL PROTECTED] wrote: I've just upgraded to 1.0.0pre1 from a mid-March CVS build and noticed that expansion of %{reply:Packet-Type} in my post-auth config returns null/no longer works. Cute. I've committed a fix to the CVS head, and it will be in 1.0.0. Alan DeKok. - List

random dh -- best practices for EAP-TLS ?

2004-06-02 Thread Matt Garretson
Hi, i've had EAP-TLS working well for a few weeks now, but am wondering about the most secure way to set up the dh and random files. Initially i just created static files using commands found in the list archives and/or the eap howto: openssl dhparam -text -5 -out /opt/radius/etc/dh 512 dd

Re: EAP/TLS win2000

2004-06-02 Thread Artur Hecker
hi Unless you tell it to use some other identity (there is a check box you can mark) I've tryed that, but nothing happened. sorry, i actually didn't mean to tell that windows would send messages in that case. actually, i don't know if it will send anything, it still needs the certificate for

radwho Acct-Status-Type = Alive

2004-06-02 Thread Adrian Griffin
I am running freeradius 0.9.2 (have not yet updated to 0.9.3). I've read through the FAQ and I didn't find anything, I also found no relevant info in the list archive for the last 6 months using 'alive' and 'radwho' as search terms