rlm_exec for acc

2004-11-23 Thread Jev
Hi all, I understand Exec-Program is being deprecated in users, but what about acct_users, can I call scripts for acc Start/Stops using the rlm_exec module? I played around with this, but I wasn't able to get any results, nor have I have any docs/examples for this... Any help greatly apprecia

Re: acct_user WARNING!'s after upgrade to 1.0.1

2004-11-23 Thread Jev
Alan DeKok wrote: Jev <[EMAIL PROTECTED]> wrote: [/usr/local/etc/raddb/acct_users]:18 WARNING! Check item "Exec-Program" ?found in reply item list for user "DEFAULT". ?This attribute MUST go on the first line with the other check items You probably didn't update the dictionaries. I'm sure I h

radgroupcheck and sql module return value

2004-11-23 Thread Vinod
Hi, I am trying to proxy to a remote server if the user is not found in the local database. To do this I added a DEFAULT Proxy-To-Realm in the users file and a failover entry to radiusd.conf: authorize { group { sql { notfound = 1 ok =retur

Re: peap - ldap - eDirectory

2004-11-23 Thread Alan DeKok
Daniel Hesse <[EMAIL PROTECTED]> wrote: > Hello to all. 2 weeks ago I downloaded fedora core 3, with the intention > of implementing 802.1x security for our wireless system. I'm not sure > how to find the version of freeradius I have $ radiusd -v > Maybe what I am expecting of the software is inc

Re: acct_user WARNING!'s after upgrade to 1.0.1

2004-11-23 Thread Alan DeKok
Jev <[EMAIL PROTECTED]> wrote: > [/usr/local/etc/raddb/acct_users]:18 WARNING! Check item "Exec-Program" > ?found in reply item list for user "DEFAULT". ?This attribute MUST go on > the first line with the other check items You probably didn't update the dictionaries. For now, you can ignor

acct_user WARNING!'s after upgrade to 1.0.1

2004-11-23 Thread Jev
Hi, I recently upgraded to freeradius 1.0.1 from 1.0. On start up I'm getting the error: files: acctusersfile = "/usr/local/etc/raddb/acct_users" files: preproxy_usersfile = "/usr/local/etc/raddb/preproxy_users" files: compat = "no" [/usr/local/etc/raddb/acct_users]:18 WARNING! Check item "Exe

peap - ldap - eDirectory

2004-11-23 Thread Daniel Hesse
Hello to all. 2 weeks ago I downloaded fedora core 3, with the intention of implementing 802.1x security for our wireless system. I'm not sure how to find the version of freeradius I have, only that it is stock in the latest release of fedora core 3. The radiusd.conf file has this if it helps radi

Proxy and Accounting

2004-11-23 Thread Khurram Jahangir
Hello All, I am using FreeRadius-1.0.1. The client is 802.1x client on windows XP with PEAP. The authenticator is an HP 2524 switch (10.0.1.20 in the log file). For me things are working fine with one radius server and AAA works pretty good and I can also check the simultaneous-use for a user.

checking NAS-Port-Type on freeradius

2004-11-23 Thread Luiz Gustavo Anflor Pereira
I want to check which port the client is using to get conected to. I am using freeradius, and testing with radclient. My test is: cat << EOF | radclient -x localhost auth testing123 User-Name = gollum User-Password = smeagol NAS-IP-Address = localhost NAS-Port-Type = 5 NAS-Port = 0 EOF and I w

radacct table empty

2004-11-23 Thread andremail82-radius
Hello folks,   I'm making a test with freeradius authenticating with an DB in MySQL. I have activate logs for the authentications and it create a directory for each nas in my network in the directory /usr/local/var/log/radius/radacct//, in this directory I have a lot of logs, but nothing in the DB.

RE: How to setup redundancy against password failure not just users (authorize/authenticate)?

2004-11-23 Thread Laxman Gajbhe
I tried this: Auth-Type LDAP { redundant { ldap unix } } Server does not seem to like redundant keyword in authenticate section. Any other ideas -Original Message- From: Kostas Kalevras [mailto:[EMAIL PROTECTED] Sent: Monda

Re: Unicode

2004-11-23 Thread Josh Howlett
Does this apply to the modules as well, or is Unicode support module dependent? No, there is *no* Unicode support anywhere in the server. What is supported is the ability to put non-ASCII data into any "string" attribute. It doesn't matter where that attribute is created or used, they all suppo

Re: Unicode

2004-11-23 Thread Alan DeKok
Josh Howlett <[EMAIL PROTECTED]> wrote: > > As of 1.0, it will seamlessly print, parse, and use any non-ASCII > > character in any "string" attribute. The only invalid character is '\000' > > Does this apply to the modules as well, or is Unicode support module > dependent? No, there is *no*

Re: how many records in radacct

2004-11-23 Thread Mike Sturdee
We have 25,053,381 in our MySQL radacct table. On Mon, 22 Nov 2004, Alexander Serkin wrote: Hello, how many records in radacct table do you manage to keep, guys? I see that radius stops working properly after about 15 accounting records in Oracle (9.2.0.4) database or ~3 in PostgreSQL 7.4.6

Re: rlm_ippool - not releasing ip addresses

2004-11-23 Thread Kostas Kalevras
On Tue, 23 Nov 2004, Mike O'Connor wrote: Hi Kostas I have had the detail file enable from day one :) do not trust databases for long term data. The port is different but there is a stop record in the rad detail file. What do mean? Is the port in the accounting stop different from the port in the

Re: how many records in radacct

2004-11-23 Thread Alexander Serkin
Kostas Kalevras wrote: On Tue, 23 Nov 2004, Alexander Serkin wrote: ... Well, how do you deal with stop records lost for some reason? There should be some tool to remove these stale records from active table. dialupadmin/bin/clean_radcct :-) dialup_admin is not an Oracle's friend yet? Will it?

Re: rlm_ippool - not releasing ip addresses

2004-11-23 Thread Mike O'Connor
Hi Kostas I have had the detail file enable from day one :) do not trust databases for long term data. The port is different but there is a stop record in the rad detail file. One comment is that if I run "freeradius -xx" and then send a stop record for an active IP but use a different NAS port

Re: how many records in radacct

2004-11-23 Thread Kostas Kalevras
On Tue, 23 Nov 2004, Alexander Serkin wrote: Kostas Kalevras wrote: On Tue, 23 Nov 2004, jesk wrote: ... 10,000,000 rows can be a lot depending on your candidate rows for each query and your available memory for caching. A more scalable structure (which i 'll start using on my installation) is

Re: how many records in radacct

2004-11-23 Thread Alexander Serkin
Kostas Kalevras wrote: On Tue, 23 Nov 2004, jesk wrote: ... 10,000,000 rows can be a lot depending on your candidate rows for each query and your available memory for caching. A more scalable structure (which i 'll start using on my installation) is this: Create a memory mapped table (HEAP ty

Re: how many records in radacct

2004-11-23 Thread Kostas Kalevras
On Tue, 23 Nov 2004, jesk wrote: Hello, how many records in radacct table do you manage to keep, guys? I see that radius stops working properly after about 15 accounting records in Oracle (9.2.0.4) database or ~3 in PostgreSQL 7.4.6. After that amount accounting records are not written into

Re: how many records in radacct

2004-11-23 Thread jesk
Hello, how many records in radacct table do you manage to keep, guys? I see that radius stops working properly after about 15 accounting records in Oracle (9.2.0.4) database or ~3 in PostgreSQL 7.4.6. After that amount accounting records are not written into table and FR (v1.0.1) claims abo

Re: clients.conf storage in ldap

2004-11-23 Thread Kostas Kalevras
On Tue, 23 Nov 2004, eric german wrote: I can try to port it in rlm_ldap.c but , I need some help on freeradius and in c language . first question : -I must patch rlm_ldap or an another module ?(the module reading clients.conf ? ) . - I don't know very well freeradius arch (one month ago) . thank

Re: clients.conf storage in ldap

2004-11-23 Thread eric german
I can try to port it in rlm_ldap.c but , I need some help on freeradius and in c language . first question : -I must patch rlm_ldap or an another module ?(the module reading clients.conf ? ) . - I don't know very well freeradius arch (one month ago) . thanks eric german --- Kostas Kalevras

Re: Unicode

2004-11-23 Thread Josh Howlett
--On Monday, November 22, 2004 16:59:31 -0500 Alan DeKok <[EMAIL PROTECTED]> wrote: Josh Howlett <[EMAIL PROTECTED]> wrote: Just out of curiousity, what do FreeRADIUS users from places that have non-ASCII characters do about non-Unicode support? Enforce usernames/passwords with ASCII-only characte

Re: how many records in radacct

2004-11-23 Thread Alexander Serkin
Thank you all for the hints. Really stupid was it not to create index on acctuniqueid. And 'explain' is my best friend ad finem seculorum. -- Alexander Kostas Kalevras wrote: On Mon, 22 Nov 2004, Alexander Serkin wrote: Hello, how many records in radacct table do you manage to keep, guys? I see tha

Re: rlm_ippool - not releasing ip addresses

2004-11-23 Thread LALOT Dominique
Kostas Kalevras a écrit : I have some scripts here which will process a ip pool file (using rlm_ippool_tool) against radwho or a radacct table, which I used to clean out rm_ippool's data every so often. The problem is that any non-FreeRADIUS modification of the database needs to be done while Fre