Re: Proxy and Accounting

2004-11-25 Thread Khurram Jahangir
It is working for me now so please ignore this message. I had an entry in proxy.conf as follows which was the problem i think and when I took it away, the proxy server started sending accounting information to the other radius server. realm LOCAL { type = radius authhost = LOCAL accthost = LOCAL

Fwd: radius difficulty

2004-11-25 Thread Sanket Totala
Note: forwarded message attached. Yahoo! India Matrimony: Find your life partner online.---BeginMessage--- Hi all, I have the following difficulty with RADIUS My passwd file: /etc/passwd has the following entries root:x:504:504::/root/bin/bash

Difference between incorrect CHAP- or CLI-Authentification in log file

2004-11-25 Thread Beckers, Michael
Title: Difference between incorrect CHAP- or CLI-Authentification in logfile We're using FreeRADIUS V. 0.8.1 on SuSE 8.2 and we want to add CLI-Authentification. At the moment, in the logfile (log_auth = yes, log_auth_badpass = yes, log_auth:goodpass = yes) we can't differ between failed

Sorry, this time w/o HTML an Vcard :( - Difference between incor rect CHAP- or CLI-Authentification in logfile

2004-11-25 Thread Beckers, Michael
Title: Sorry, this time w/o HTML an Vcard :( - Difference between incorrect CHAP- or CLI-Authentification in logfile We're using FreeRADIUS V. 0.8.1 on SuSE 8.2 and we want to add CLI-Authentification. At the moment, in the logfile (log_auth = yes, log_auth_badpass = yes, log_auth:goodpass =

Re: radius difficulty

2004-11-25 Thread Alan DeKok
Sanket Totala [EMAIL PROTECTED] wrote: Now user r belongs to group demo. I want that the policy specified in the Filter-Id attribute of group demo be applicable to user r. I get that only when user r is present in the passwd file also, even if r has Auth-Type := Local. My passwd file is

Re: Sorry, this time w/o HTML an Vcard :( - Difference between incor rect CHAP- or CLI-Authentification in logfile

2004-11-25 Thread Alan DeKok
Beckers, Michael [EMAIL PROTECTED] wrote: We're using FreeRADIUS V. 0.8.1 on SuSE 8.2 and we want to add CLI-Authentification. I suggest you upgrade to 1.0.1, there are a LOT of bugs fixed in it. At the moment, in the logfile (log_auth = yes, log_auth_badpass = yes, log_auth:goodpass =

Re: Radius Authentication scheme

2004-11-25 Thread Alan DeKok
Antonio Martinez [EMAIL PROTECTED] wrote: On the other hand, since you support the draft Radius Extension for Digest Authentication (doc/rfc/draft-sterman-aaa-sip-00.txt) this means I have to figure out how to make it work without that patch. Not necessarily. Can you PLEASE say which NAS

ntlm_auth difficulty

2004-11-25 Thread Dudley Atkinson
Title: Message I cannot get ntlm_auth to work within freeradius, and I hopesomeone can point me to the right answer, since I've exhausted my ideas. ntlm_auth works manually. The snippet from radiusd.conf is: mschap { authtype = MS-CHAP use_mppe = yes require_encryption = yes

Segmentation fault (core dumped)

2004-11-25 Thread Rafael Gómez
Hi all Everytime I tried to run freeradius with SQL support I got the following message: Segmentation fault (core dumped) My radiusd.conf is the following: authorize { preprocess chap mschap suffix sql } authenticate { Auth-Type CHAP {

clients.conf NAS

2004-11-25 Thread David Luyens
Hi, a/ Am I correct that freeradius looks at the IP address of the IP header instead of the NAS-IP-Address in the clients.conf file? b/ is [/etc/init.d/freeradius reload] in a cronjob a good way to reload the clietns.conf file or is ther a setting inside freeradius that can do this Or any other

Re: ntlm_auth difficulty

2004-11-25 Thread Alan DeKok
Dudley Atkinson [EMAIL PROTECTED] wrote: When I run radiusd -X, I see: modcall: entering group Auth-Type for request 2 rlm_mschap: No User-Password configured. Cannot create LM-Password. rlm_mschap: No User-Password configured. Cannot create NT-Password. That's nice. What ELSE do

Re: clients.conf NAS

2004-11-25 Thread Alan DeKok
David Luyens [EMAIL PROTECTED] wrote: a/ Am I correct that freeradius looks at the IP address of the IP header instead of the NAS-IP-Address in the clients.conf file? The NAS-IP-Address isn't used for anything. The IP source address of the packet is what's looked up in clients.conf. b/

Re: radius difficulty

2004-11-25 Thread Sanket Totala
i have tried by creating my own group file and passwd file. But in any case a passwd file is required. can i not work without a passwd file sanket [EMAIL PROTECTED] wrote: Send Freeradius-Users mailing list submissions to[EMAIL PROTECTED]To subscribe or unsubscribe via the World Wide Web,

Re: rlm_eap_md5: User-Password is required for EAP-MD5 authentication

2004-11-25 Thread Chan Min Wai
Alan DeKok wrote: Chan Min Wai (System Administrator) [EMAIL PROTECTED] wrote: CLEAR text passwords are required for EAP-MD5. Crypt passwords will NEVER work. Anyway to make it work? somehow? No. It's impossible. I know this have been bugging you From Or since freeradius support LDAP

Deny access to group of users to a NAS with huntgroups.

2004-11-25 Thread Daniel
Hi How would I deny access to a NAS for a group of users. I am using LDAP user and groups and mysql for accounting with freeradius. I have some users that are part of nodialup group. I want to deny them access to a few of our access servers but allow access to the other access server on the

Re: rlm_eap_md5: User-Password is required for EAP-MD5 authentication

2004-11-25 Thread Paul Hampson
On Fri, Nov 26, 2004 at 02:01:00PM +0800, Chan Min Wai wrote: Alan DeKok wrote: Chan Min Wai (System Administrator) [EMAIL PROTECTED] wrote: CLEAR text passwords are required for EAP-MD5. Crypt passwords will NEVER work. Anyway to make it work? somehow? No. It's impossible. I know

Re: ntlm_auth difficulty

2004-11-25 Thread Chris Huang
Hi , All : Hope you guys don't mind I insert my first post in the midle of this topic. Regarding to the ntlm_auth, I do have the same issue. Learning from the list, I've managed to solve the shared lib relinking issue, configuring samba,winbind.NTLM_AUTH is also working from CLI.