RE: Replies on port 1029

2004-06-25 Thread Brian Andrus
Well it is very odd to me. The proxy requests to me from another freeradius are failing because the response is being sent back on a different port than they were sent on. All The Best, Brian Andrus Millenia Internet Services, Inc. -Original Message- From: [EMAIL PROTECTED]

RE: mysql not loading and linking -- segmentation fault

2004-06-25 Thread Manjunath M Prabhu
hi alan, i am using debian linux 3.0(woody)and this is the core dump output i get when i run radiusd with mysql.i am using freeradius-1.0.0-pre1. gdb /usr/local/sbin/radiusd /usr/local/etc/raddb/c ore GNU gdb 5.3-debian Copyright 2002 Free Software Foundation, Inc. GDB is free software, covered

freeradius-1.0.0-pre2, mysql, clients.conf

2004-06-25 Thread Jean Frontin
Morning, I saw there was a talbe named nas. Is it the mirror of clients.conf file ? Does freeradius use it to administrate clients ? In this table there is a column named nasname is it the equivalent of clients in clients.conf file ? Have a good day Jean Frontin System team I R I T Université

RE: Replies on port 1029

2004-06-25 Thread Paul Hampson
From: Brian Andrus Sent: Friday, 25 June 2004 4:01 PM Well it is very odd to me. The proxy requests to me from another freeradius are failing because the response is being sent back on a different port than they were sent on. What does the packet dumper say, at your end of the link? --

Re: dialup_admin question.

2004-06-25 Thread apellido jr., wilfredo p.
under admin.conf # Default values for the various user limits in case the counter module # is used to impose such limits. # The value should be the user limit in seconds or none for nothing counter_default_daily: change for whatever daily limit you want counter_default_weekly: change for

Re: Replies on port 1029

2004-06-25 Thread Thor Spruyt
What is failing? Is FreeRadius ignoring the response packets or do they not arrive? - Original Message - From: Brian Andrus [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Friday, June 25, 2004 8:00 AM Subject: RE: Replies on port 1029 Well it is very odd to me. The proxy requests to me

Re: dialup_admin question.

2004-06-25 Thread Kostas Kalevras
On Fri, 25 Jun 2004, apellido jr., wilfredo p. wrote: under admin.conf # Default values for the various user limits in case the counter module # is used to impose such limits. # The value should be the user limit in seconds or none for nothing counter_default_daily: change for whatever

Re: AW: Instanciated ldap_groupcmp()

2004-06-25 Thread Kostas Kalevras
On Fri, 25 Jun 2004 [EMAIL PROTECTED] wrote: Ah. But the module still registers a callback for LDAP-Group, even if one already exists. That should probably be double-checked... The only way for the ldap module to know if ldap-group has been registered is to keep a

RE: Replies on port 1029

2004-06-25 Thread Nico.Baggus
Wha?? No it doesn't. FTP opens a _second_ connection for data, but telnet and HTTP both use the existing TCP connection for data back to the client. And an IP connection is defiened by five things: (local address, local port, remote address, remote port, and protocol (TCP)) These

Re: A question about multiple radius attribute tagging

2004-06-25 Thread Nicolas Baradakis
[EMAIL PROTECTED] wrote : Does any one know how to set multiple tags in a RADIUS record. See the operator += -- Nicolas Baradakis - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

no detailed log in eap/tls

2004-06-25 Thread diego . valzelli
Hello, I'm doing test with eap-tls beetween a WinXP Client and a Linux server. When I type 'radiusd -X -A' everything seems to be ok, and the client receives an EAP-Success. I have uncommented in radiusd.conf all the istructions about 'logging' but I have not a detailed log of all accounting

Re: eap_ttls and eap_peap linking problem SOLVED

2004-06-25 Thread Mack
SOLVED -- sort of Using CVS snapshopt 20040625, still had same problem. Using ./configure --with- system-libtool did not work either...same results. Using ./configure --disable-shared results in an error free make and make install. Now, radiusd runs fine. Configured eap_ttls and it seems

Re: no detailed log in eap/tls

2004-06-25 Thread Alain Perry
Le ven 25/06/2004 à 13:52, [EMAIL PROTECTED] a écrit : Hello, I'm doing test with eap-tls beetween a WinXP Client and a Linux server. When I type 'radiusd -X -A' everything seems to be ok, and the client receives an EAP-Success. I have uncommented in radiusd.conf all the istructions about

Re: eap_ttls and eap_peap linking problem SOLVED

2004-06-25 Thread Alain Perry
thoughts/comments as to advantages/disadvantages of enabling/disabling shared libs? I'm probably not the best here to answer that, but my first guess would be with security issues. If openssl is updated by your package management system because of a security hole or anything, you will have to

Re: Fw: EAP-SIM - reply code 0 unknown

2004-06-25 Thread Simeon Penev
Alan DeKok wrote: Simeon Penev [EMAIL PROTECTED] wrote; rlm_eap: Underlying EAP-Type set EAP ID to 0 rlm_eap: reply code 0 is unknown, Rejecting the request. Try the following patch: http://lists.freeradius.org/pipermail/freeradius-devel/2004-June/007261.html If it works, please say so,

Re: Replies on port 1029

2004-06-25 Thread Alan DeKok
Brian Andrus [EMAIL PROTECTED] wrote: Well it is very odd to me. The proxy requests to me from another freeradius are failing because the response is being sent back on a different port than they were sent on. You already said that, and I already responded, telling you how to debug the

Re: FreeRADIUS-1.0.0pre3 crash at SIGHUP

2004-06-25 Thread Alan DeKok
Brent Hetherwick [EMAIL PROTECTED] wrote: I am using FreeRADIUS-1.0.0pre3 with the MySQL backend. I have the threaded server enabled, and I'm currently using 128 max threads with a database connection pool of 64, although I have changed these numbers quite a bit in my testing. Having read

Re: mysql not loading and linking -- segmentation fault

2004-06-25 Thread Alan DeKok
Manjunath M Prabhu [EMAIL PROTECTED] wrote: i am using debian linux 3.0(woody)and this is the core dump output i get when i run radiusd with mysql.i am using freeradius-1.0.0-pre1. ... 3330 lensym = LT_STRLEN (symbol) + LT_STRLEN (handle-loader-sym_prefix) Welcome to libtool hell.

Re: no detailed log in eap/tls

2004-06-25 Thread Alan DeKok
[EMAIL PROTECTED] wrote: I'm doing test with eap-tls beetween a WinXP Client and a Linux server. When I type 'radiusd -X -A' everything seems to be ok, and the client receives an EAP-Success. I have uncommented in radiusd.conf all the istructions about 'logging' but I have not a detailed log

Re: eap_ttls and eap_peap linking problem SOLVED

2004-06-25 Thread Alan DeKok
Mack [EMAIL PROTECTED] wrote: Using ./configure --disable-shared results in an error free make and make install. Now, radiusd runs fine. Configured eap_ttls and it seems to work fine so far, to. Must have been a problem with my version of libtool (1.5.2). libtool 1.5.2 is not

Post-Auth for Access-Accept not called with LEAP

2004-06-25 Thread Htin Hlaing
Hi, I have the following set up in my radiusd to get auth results. With other EAP types like peap, ttls, etc. I get Access-Accepts also logged in the reply_log. For LEAP, I am not getting it. From debug run, I don't see post-auth getting called at all. How can I fix to get the post-auth

Re: dialup_admin question.

2004-06-25 Thread Amedzekor Kafui
edit the the conf/admin.conf in the dialup-admin directory. Look for default settingsShannon Sariman [EMAIL PROTECTED] wrote: Hi All,How can I change or customise the default Daily Limits of 4 hours per day,to some other value of my liking, (under Subscription Analysis) for aparticular user, under

Re: eap_ttls and eap_peap linking problem SOLVED

2004-06-25 Thread Mack
Alain, Thanks for clearing it up for me. Sounds like shared is the way to go. I'll look into using an older version of libtool that will work with freeradius so I can use shared. thanks, mack On 25 Jun 2004 at 14:14, Alain Perry wrote: thoughts/comments as to advantages/disadvantages of

Re: eap_ttls and eap_peap linking problem SOLVED

2004-06-25 Thread Mack
Alan, Yep, that's what I figured. What's the highest version of libtool that freeradius supports, and what version did you use in your tests? Are there any plans for freeradius to support a more current version of libtool (i think latest stable is 1.5.6)? thanks, mack On 25 Jun 2004 at

mysql query log only.

2004-06-25 Thread Mike Sturdee
Is it possible to have mysql accounting log the query statement (yes i know this part is possible) but NOT connect to the sql server? I need to take the mysql box down for maint and was thinking this would be the best possible way to not lose any records. -Mike - List

how to save binary values in MySQL radreply table

2004-06-25 Thread Dave Mason
Hi, My apologies if this has been answered before but I didn't see anything. This is basically a MySQL question. I need to save MS-MPPE attributes in the radreply table. Those have a binary value. According to the schema, Value is a varchar(253). Can I just copy the binary value to a

RE: Post-Auth for Access-Accept not called with LEAP

2004-06-25 Thread Htin Hlaing
Hi, Forgot to mention, I am using the 1.0.0 pre3 release. Thanks, Htin -Original Message- From: [EMAIL PROTECTED] [mailto:freeradius- [EMAIL PROTECTED] On Behalf Of Htin Hlaing Sent: Friday, June 25, 2004 8:10 AM To: [EMAIL PROTECTED] Subject: Post-Auth for Access-Accept not

Re: how to save binary values in MySQL radreply table

2004-06-25 Thread Alan DeKok
Dave Mason [EMAIL PROTECTED] wrote: My apologies if this has been answered before but I didn't see anything. This is basically a MySQL question. I need to save MS-MPPE attributes in the radreply table. Those have a binary value. Which is why they're of type octets in the dictionary.

Re: Advices needed

2004-06-25 Thread Alain Perry
Le jeu 24/06/2004 à 19:06, Alan DeKok a écrit : Use EAP-TLS, EAP-TTLS, or EAP-PEAP. Yep, that's what I finaly planned. Then EAP-TLS is probably not worth it. Okay, so, that only leaves me with EAP-TTLS and EAP-PEAP That's not how wireless works. It sets up an encryption key used to

RE: Post-Auth for Access-Accept not called with LEAP

2004-06-25 Thread Htin Hlaing
Hi, The attached patch allows me to get the post-auth called in Access-Accept when LEAP is used. In the rad_authenticate routine from auth.c returns without going further to call rad_postauth if the called to rad_check_password returns with RLM_MODULE_HANDLED. In the eap_compose routine, the

RE: FreeRADIUS-1.0.0pre3 crash at SIGHUP

2004-06-25 Thread Brent Hetherwick
Alan DeKok wrote: Ok... where does it die, and why? According to the logs, it appears to die as FreeRADIUS is restarting. Why, I have no idea. If you have a little more information, like a core dump backtrace, that would help significantly. I had thought about that issue when I built

RE: FreeRADIUS-1.0.0pre3 crash at SIGHUP

2004-06-25 Thread Htin Hlaing
I had thought about that issue when I built FreeRADIUS, but I didn't see an obvious option to enable core dumps, and I haven't found any when it dies. I believe I have the environment set to allow full corings, but I may have missed an option in FreeRADIUS to dump core when it dies. Is there

Accounting details logging problem

2004-06-25 Thread Simeon Penev
= 2a923e8df47cc921. modcall[accounting]: module acct_unique returns ok for request 5 radius_xlat: '/var/log/radius/radacct//detail-20040625:20' rlm_detail: /var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d:%H expands to /var/log/radius/radacct//detail-20040625:20 modcall[accounting]: module

Re: how to save binary values in MySQL radreply table

2004-06-25 Thread Dave Mason
True - I need to figure out how to reverse the process. That is, I need to send something like 0xed5e as my attribute value. For now I'll just use VSA as the attribute because it's not encrypted. If I set the value in radreply to ed5e, the server returns 65643565 to the client, as you would

RE: Problems with configurable_failover

2004-06-25 Thread Roy, Daniel
preprocess returns ok for request 7 Fri Jun 25 14:53:42 2004 : Debug: modsingle[authorize]: calling auth_log (rlm_detail) for request 7 Fri Jun 25 14:53:42 2004 : Debug: radius_xlat: '/usr/local/var/log/radius/radacct/207.181.118.125/auth-detail-20040625' Fri Jun 25 14:53:42 2004 : Debug

radclient problem, apparent limit of resend count to 256

2004-06-25 Thread David Stanaway
Hi, I am having some problems with using radclient to test some modifications to the radiusd. radclient -f testpacket -c 1000 10.13.77.78 -q acct s3cr3t This only logs 256 accounting packets. I think it is to do with the requestid looping. This also does not work: n=1000;i=0; time while [ $i

Re: how to save binary values in MySQL radreply table

2004-06-25 Thread Gary McKinney
Dave, You may want to check out MySQL 4.x - there is a hex() function to return a hexidecimal representation.. gm... - Original Message - From: Dave Mason [EMAIL PROTECTED] To: freeradius mailing list [EMAIL PROTECTED] Sent: Friday, June 25, 2004 2:30 PM Subject: Re: how to save binary

how to run radiusd with high debug info but in background

2004-06-25 Thread Ernesto Freyre
Hi admins! Please I would want to know how to run radiusd with high debug info but in background? Thank you for your reply. Ernesto Freyre Ramírez Área de Operaciones Red Privada Virtual S.A. Av. Paseo de la República 4675 - Lima 34 Telf.: (511) 241-4122 Anexo 2245 Fax: (511) 446-8135 Visítenos

Re: how to run radiusd with high debug info but in background

2004-06-25 Thread Kiran
To run a process in background use at the end of the process shell radiusd -X if you don't want to see the output but want the output to a file, redirect the o/p using shell radiusd -X logfile.txt --- Ernesto Freyre [EMAIL PROTECTED] wrote: Hi admins! Please I would want to know how to

Re: how to run radiusd with high debug info but in background

2004-06-25 Thread Paul Hampson
On Fri, Jun 25, 2004 at 05:13:39PM -0700, Ernesto Freyre wrote: Hi admins! Please I would want to know how to run radiusd with high debug info but in background? Instead of -X, use the individual switches... -X is simply a convinient shortcut for -sfxxyz -l stdout so take the -f out, and it'll

Subject: Re: dialup_admin question.

2004-06-25 Thread Shannon Sariman
Hi People, Thanx for the great help! Appreciate it! Kostas Kalevras [EMAIL PROTECTED] wrote: You obviously also need to configure the counter module. dialupadmin will just report the user limits not impose them. Which counter module are you referring to? There is an rlm_counter and an