Re: rlm_preprocess inside radsqlrelay

2005-02-14 Thread ROY
On Mon, 2005-02-14 at 18:17 +0800, ROY wrote: > i've noticed it doesn't recognize some AVPairs even when i add them to a > custom dictionary such as the ff. Cisco AVP's: > > release-source > gw-rxd-cgn > gw-final-xlated-cgn > remote-media-address > > my dictionary.custom: > ATTRIBUTE remote

Ldap Group Attribute radiusGroupName

2005-02-14 Thread Chan Min Wai
Greeting, I've been trying to work out a way to disable unpaid users with a single disable radiusGroupName. But the doc and the resources is limited and I don't even see radiusGroupName in the log so I think it is not working with my configuration. I would like to know how to make

Re: Novell & eDirectory Press Release

2005-02-14 Thread Daniel Hesse
THIS IS THE MOST OUTSTANDING NEWS---2005 is starting out GRAND!!!   Daniel D. HesseTechnology AdministratorMethodist Manor Retirement Community712-732-1120 Ext.116   [EMAIL PROTECTED]>>> [EMAIL PROTECTED] 2/14/2005 4:27:29 PM >>>Alan DeKok wrote:> http://www.novell.com/news/press/archive/2005/02/

Re: NT hashed password in userPassword attribute.

2005-02-14 Thread Jason Howk
Maybe this will help: In eap_leap.c:219 there's an if statement looking for the normal password attribute. If that's not found according to the comments must be an NT-Password. The value that's being assigned to the ntpwdhash is coming from password->strvalue. I ran a test an in the normal ca

Re: Novell & eDirectory Press Release

2005-02-14 Thread Josh Howlett
Alan DeKok wrote: http://www.novell.com/news/press/archive/2005/02/pr05008.html Cool :-), congrats to all involved. Nice to see FR get some 'corporate' recognition. josh. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: NT hashed password in userPassword attribute.

2005-02-14 Thread Alan DeKok
Jason Howk <[EMAIL PROTECTED]> wrote: > No go. I put in some additional debug statements and recompiled > eap_leap and I'm seeing some interesting results. If I follow what is > described below, the output from the call to > eapleap_ntpwdhash()(eap_leap.c:198) is totally different if I revert

Re: Radius Timeouts

2005-02-14 Thread Dustin Doris
> On Mon, 14 Feb 2005, Dustin Doris wrote: > > > On Mon, 14 Feb 2005, Joe H wrote: > > > > > On Sat, 12 Feb 2005, energy wrote: > > > > > > > Sorry, I'm just a lurker on this list and certainly no expert. However, > > > > last > > > > time I saw someone mention this issue it had to do with log ro

Re: NT hashed password in userPassword attribute.

2005-02-14 Thread Jason Howk
No go. I put in some additional debug statements and recompiled eap_leap and I'm seeing some interesting results. If I follow what is described below, the output from the call to eapleap_ntpwdhash()(eap_leap.c:198) is totally different if I revert back to using the LDAP ntPassword attribute w

Re: Novell & eDirectory Press Release

2005-02-14 Thread Justin Guidroz
That's good news. On Mon, 14 Feb 2005 14:39:50 -0500 (EST), Alan DeKok <[EMAIL PROTECTED]> wrote: > http://www.novell.com/news/press/archive/2005/02/pr05008.html > > Alan DeKok. > > - > List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html > -- Justin Guidroz -

Re: Radius Timeouts

2005-02-14 Thread Joe H
On Mon, 14 Feb 2005, Dustin Doris wrote: > On Mon, 14 Feb 2005, Joe H wrote: > > > On Sat, 12 Feb 2005, energy wrote: > > > > > Sorry, I'm just a lurker on this list and certainly no expert. However, > > > last > > > time I saw someone mention this issue it had to do with log rotation. > > > Che

Novell & eDirectory Press Release

2005-02-14 Thread Alan DeKok
http://www.novell.com/news/press/archive/2005/02/pr05008.html Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: RADIUS and PPPoE

2005-02-14 Thread Julius Igugu
Roaring Penguin PPPoEColin O'Keeffe <[EMAIL PROTECTED]> wrote: I want a software one for linux.thanks for the helpOn Mon, 14 Feb 2005 08:39:37 -0800 (PST), Julius Igugu <[EMAIL PROTECTED]>wrote:> Mikrotik> > Colin O'Keeffe <[EMAIL PROTECTED]>wrote: > okay, so a PPPoE server is required to handl

AW: Always Accept

2005-02-14 Thread Daniel Walther
Hi, Thanks for your fast answer. And how do I need to configure the authentication schemes? Regards, Daniel -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Thomas MARCHESSEAU Gesendet: Montag, 14. Februar 2005 13:54 An: freeradius-users@lists.fre

Re: RADIUS and PPPoE

2005-02-14 Thread Colin O'Keeffe
I want a software one for linux. thanks for the help On Mon, 14 Feb 2005 08:39:37 -0800 (PST), Julius Igugu <[EMAIL PROTECTED]> wrote: > Mikrotik > > Colin O'Keeffe <[EMAIL PROTECTED]> wrote: > okay, so a PPPoE server is required to handle the requests. any > recommendation for a good one

error: rlm_radutmp: Logout entry for NAS ... port 0 has wrong ID

2005-02-14 Thread Florian Prester
Hi, what does this mean and what can I do about it? thanks florian -- -- Dipl. Inf. Florian Prester Network Administration Regionales RechenZentrum Erlangen Universitaet Erlangen-Nuernberg Germany Tel.: +499131 8527813 - List info/subscri

Re: configure can't find dbm headers

2005-02-14 Thread Alan DeKok
Christian Wiese <[EMAIL PROTECTED]> wrote: > Any Ideas, why configure can't find the libs? read config.log, it should have the errors in it. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: configure can't find dbm headers

2005-02-14 Thread Christian Wiese
Hi Alan, thank you for your reply. On Monday 14 February 2005 18:42, Alan DeKok wrote: > Christian Wiese <[EMAIL PROTECTED]> wrote: > > I want to build freeradius-1.0.1 from source, but have problems that > > configure can't find dbm library files, > > Do you have them on your system? Yep ... i

Re: Radius Timeouts

2005-02-14 Thread Dustin Doris
On Mon, 14 Feb 2005, Joe H wrote: > On Sat, 12 Feb 2005, energy wrote: > > > Sorry, I'm just a lurker on this list and certainly no expert. However, last > > time I saw someone mention this issue it had to do with log rotation. Check > > to make sure logs are not being rotated every hour. > > > >

Re: configure can't find dbm headers

2005-02-14 Thread Alan DeKok
Christian Wiese <[EMAIL PROTECTED]> wrote: > I want to build freeradius-1.0.1 from source, but have problems that > configure can't find dbm library files, Do you have them on your system? > neither if I specify the location with '--with-rlm-dbm-lib-dir=/usr/lib > --with-rlm-dbm-include-dir=/u

Re: NT hashed password in userPassword attribute.

2005-02-14 Thread Alan DeKok
Jason Howk <[EMAIL PROTECTED]> wrote: > rlm_attr_rewrite: Changed value for attribute NT-Password from > '{NT}8846F7EAEE8FB117AD06BDD830B7586C' to > '0x8846F7EAEE8FB117AD06BDD830B7586C' You should remove the {NT} header, and nothing more All of the code in the server which uses NT-Password w

Re: Restart Freeradius when file "users" is updated

2005-02-14 Thread Edgars
*Is there any way to configure Freeradius so that the updated file "users" is read without restarting Freeradius?* use DB * * ** *If not, do we need to configure Freeradius to obtain authorized users in the database instead?* yes Edgars All help is appreciated. Thanks! Dan Ha - Li

Re: NT hashed password in userPassword attribute.

2005-02-14 Thread Jason Howk
Kostas et al, I tried again and I'm not getting in either. Everyting looks right. freeRadius loads the password in the NT-Password attribute, and I re-write it to '0x'. It looks right but indicates that the failed challenge response. Can you see anything in here that doesn't look right? rad_re

Re: Radius Timeouts

2005-02-14 Thread Joe H
On Sat, 12 Feb 2005, energy wrote: > Sorry, I'm just a lurker on this list and certainly no expert. However, last > time I saw someone mention this issue it had to do with log rotation. Check > to make sure logs are not being rotated every hour. > > Anyway, just a thought. > The accounting logs ar

Re: RADIUS and PPPoE

2005-02-14 Thread Julius Igugu
MikrotikColin O'Keeffe <[EMAIL PROTECTED]> wrote: okay, so a PPPoE server is required to handle the requests. anyrecommendation for a good one ?On Sun, 13 Feb 2005 10:57:15 -0500, Alan DeKok <[EMAIL PROTECTED]>wrote:> Colin O'Keeffe <[EMAIL PROTECTED]>wrote:> > can I set up a dial-up icon that conn

Re: RADIUS and PPPoE

2005-02-14 Thread Colin O'Keeffe
okay, so a PPPoE server is required to handle the requests. any recommendation for a good one ? On Sun, 13 Feb 2005 10:57:15 -0500, Alan DeKok <[EMAIL PROTECTED]> wrote: > Colin O'Keeffe <[EMAIL PROTECTED]> wrote: > > can I set up a dial-up icon that connects to radius to authenticate a > > user

Re: Cisco WDS, WLSE and FreeRADIUS

2005-02-14 Thread Jeffrey C. Ollie
On Mon, 2005-02-14 at 13:55 +0100, Richard Timsit wrote: > On Fri, 2005-02-11 at 22:43, Jeffrey C. Ollie wrote: > > > > > However, I am still unable to get the WLSE to talk properly with the > > APs. I have recompiled with the patches mentioned above and the WDS AP > > shows that the WLSE is aut

radius -> radius

2005-02-14 Thread Dmitry S. Vlasov
Hello! How I can create following scheme: Two freeradius servers, called "A" and "B". 1) When User found but got Reject from server "A", "A" try to proxy this request to "B" or 2) When User not found on "A", "A" proxy request to "B". Thank you! -- === = Dmitry S. Vlaso

Re: Pppoe example

2005-02-14 Thread Doug Briden
Hi, my background is primarily Cisco but have experience with other Network vendors as well. Alan's note is correct the Radius server deals with the ppp authentication as defined with the routers AAA configuration. The PPPoe is declared firstly by enabling the PPPoe protocol on the routers in

Re: Pppoe example

2005-02-14 Thread Julius Igugu
Simply defining UserName and Password (and ignoring the other attributes) should work.   Take a looka at the 'Rate-Limit' radius attribute in the mikrotik documentation.Ross Tsolakidis <[EMAIL PROTECTED]> wrote: Hello,First time posting on this list, I'm sure this question has beenanswered but I co

configure can't find dbm headers

2005-02-14 Thread Christian Wiese
Hi list, I want to build freeradius-1.0.1 from source, but have problems that configure can't find dbm library files, neither if I specify the location with '--with-rlm-dbm-lib-dir=/usr/lib --with-rlm-dbm-include-dir=/usr/include'. configure log output: ---snip-

Re: Cisco WDS, WLSE and FreeRADIUS

2005-02-14 Thread Richard Timsit
On Fri, 2005-02-11 at 22:43, Jeffrey C. Ollie wrote: > > However, I am still unable to get the WLSE to talk properly with the > APs. I have recompiled with the patches mentioned above and the WDS AP > shows that the WLSE is authenticated but things still aren't working > properly (WLSE reports f

Re: Always Accept

2005-02-14 Thread Thomas MARCHESSEAU
Hi Daniel, something like that should works in users.conf DEFAULT Auth-Type := "Accept" Service-Type := "Framed", Framed-Protocol := "PPP", etc ... Regards Thomas MARCHESSEAU [EMAIL PROTECTED] wrote: Hi List I have a small question. Is there a possibili

Pppoe example

2005-02-14 Thread Ross Tsolakidis
Hello, First time posting on this list, I'm sure this question has been answered but I couldn't find a way to search the list. I'm setting up a Freeradius server to authenticate PPPOE, the nas units are Mikrotik Routers. I had a look at the examples in the 'users' file, but I could not work it ou

Always Accept

2005-02-14 Thread d . walther
Hi List I have a small question. Is there a possibility to configure Freeradius this way, that he will accept all authetication requests independet of the method? Thanks for your help. Best regards, Daniel - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

PEAP and "fatal unknown_ca"

2005-02-14 Thread Nicki de Wet
Hi, I also had the "unknown ca" error. I got this when using Linksys software for WUSB54G on my Windows 2000 machine as the supplicant. After switching to my XP machine, the error disappeared and everything worked as intended. Regards, Nicki de Wet - List info/subscribe/unsubscribe? See htt

main_pool

2005-02-14 Thread mlgjd
My FreeRadius is acting as proxy and it has a pool of ip's. If FR doesn't get an IP from main Radius then FR will assign IP from own main pool. My problem is that FR doesn't keep track of IP that it is assigning. Some users get same IP's. I would like to configure FR that when all ip's are taken,

Child process

2005-02-14 Thread Omar Garcia
Hi list,   One simple question, Why are there a lot of process when i start radiusd? Is one per BBDD connection? I have two different configurations of radiusd and each one uses different number of child process.       Thanks you  

Re: Ascend data filters in dialup admin

2005-02-14 Thread Kostas Kalevras
On Fri, 11 Feb 2005, Cris Boisvert wrote: Is their a way to add additional lines in the dialup admin to be able to modify ascend data filters for users. Currently I have the freeradius reply the filters based on what group I put the user in.. But some users don't get the default filters and need to

FreeRadius

2005-02-14 Thread Ashraf
Hello All , how i can manage bandwidth for free radius users Best Regards , Network Administrator Eng. Ashraf Moahmmed - EGH Virus Scan Sign This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -

Re: rlm_preprocess inside radsqlrelay

2005-02-14 Thread ROY
On Mon, 2005-02-14 at 11:37 +0200, Kostas Kalevras wrote: > > No. If you want to call modules, just use radrelay which will relay > accounting > records to the radius server, instead of sql. i've noticed it doesn't recognize some AVPairs even when i add them to a custom dictionary such as the f

Authenticate Mac Address

2005-02-14 Thread Alex
Hi all I have a question : I am using ser + freeradius + mysql. If there any possibility to authenticate on MAC Address. If yes, what kind of attribute to use, to add in radcheck table. Thank you for the reply. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: radsqlrelay: wrong acct-delay-time and acct-unique-session-id

2005-02-14 Thread ROY
On Mon, 2005-02-14 at 11:43 +0200, Kostas Kalevras wrote: > Please recheck your detail file. You 'll also find out there's a timestamp > attribute which signifies when the accounting record was received. Obviously, > if > you start radsqlrelay a few days after you 've received the records, the

Re: radsqlrelay: wrong acct-delay-time and acct-unique-session-id

2005-02-14 Thread Kostas Kalevras
On Mon, 14 Feb 2005, ROY wrote: Hi, I'm having a weird problem with radsqlrelay; it doesn't report the same Acct-Delay-Time and Acct-Unique-Session-Id as with the detail file when injecting into sql db. The attributes are defined on the dictionary and is A/V's are present on the detail file. -- que

Re: rlm_preprocess inside radsqlrelay

2005-02-14 Thread Kostas Kalevras
On Mon, 14 Feb 2005, ROY wrote: Hi again, Is there a way that rlm_preprocess can be called inside radsqlrelay? No. If you want to call modules, just use radrelay which will relay accounting records to the radius server, instead of sql. Thanks, Roy - List info/subscribe/unsubscribe? See http://www

Re: freeradius NAS-IP-Address

2005-02-14 Thread Stefan Winter
> User-A Auth-Type := Local, NAS-IP-ADDRESS == 1.1.1.1 > > User-B Auth-Type := Local, NAS-IP-ADDRESS == hostname > > If not, is there another attribute I have to use, in order to use > a hostname ? As the name "IP-Address" suggests it only can carry an IP-Address. If you want to send the hostnam