Re: Authenticate to eDirectory

2005-06-07 Thread Wolfgang Rosenauer
On 2005-06-06 at 22:04:41 -0400, [EMAIL PROTECTED] wrote (shortened): Hello! Well, now i am completely confused..I have tried to install openldap2 before on sles9/oes-linux and last time edirectory did not start and i had to reinstall from scratch. And again, when selecting the

Re: [Fwd: rlm_passwd realms]

2005-06-07 Thread Edgars
ok, thanks for the tip. Now receiving the following in debug screen (something with Auth-Type, but can't figure out what exactly): 1)with PAP Processing the authorize section of radiusd.conf modcall: entering group authorize for request 0 modcall[authorize]: module preprocess returns ok for

Re: passwords

2005-06-07 Thread Dean Mumby
Sarkis Gabriel wrote: check admin.conf # # can be one of crypt,md5,clear # general_encryption_method: clear ^ Dean Mumby wrote: Dean Mumby wrote: Hi all , firstly I installed 1.0.1-1 for centos 3.4 and then downloaded the latest 1.0.3 tar ball and

Re: NAS info + MySQL

2005-06-07 Thread Marcin Jessa
On Mon, 06 Jun 2005 21:41:22 -0400 Alan DeKok [EMAIL PROTECTED] wrote: Marcin Jessa [EMAIL PROTECTED] wrote: Web scripts get executed as the www user. That way I need to grand apache access to HUP radiusd and that can be done with sudo adding www user to the sudoers file and allowing it to

Re: make install error in Solaris 8, freeradius-1.0.3

2005-06-07 Thread Nuno Pais Fernandes
Hi, small FIX but it works: mv /usr/bin/strip /usr/bin/strip.old echo '#!/bin/bash' /usr/bin/strip echo 'exit' /usr/bin/strip chmod 755 /usr/bin/strip cd freeradius-1.0.3 make install mv -f /usr/bin/strip.old /usr/bin/strip Worked for me. Nuno Fernandes On Monday 06 June 2005 16:52, Alan

Re: make install error in Solaris 8, freeradius-1.0.3

2005-06-07 Thread Lei Chen
Dont't strip the binary files. :-), It's works. But it's a temporary method. --- Nuno Pais Fernandes [EMAIL PROTECTED]: Hi, small FIX but it works: mv /usr/bin/strip /usr/bin/strip.old echo '#!/bin/bash' /usr/bin/strip echo 'exit' /usr/bin/strip chmod 755 /usr/bin/strip cd

SASL bind for LDAP

2005-06-07 Thread Ekkehard Burkon
Hi, could not find anything in the docs. I need to bind to a LDAP server (Apple Open Directory) using a certain SASL mechanism. Is this possible with freeradius 1.0.3, if yes how? If no what else can I do? I just need it for authentication. Thought about pam_ldap. Any experiences? Thanks

Re: Re: Ip pool doesn't works properly

2005-06-07 Thread Simone Giovanardi
: '/freerad100/var/log/radius/radacct/83.216.176.254/auth-detail-20050607' rlm_detail: /freerad100/var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands to /freera d100/var/log/radius/radacct/83.216.176.254/auth-detail-20050607 modcall[authorize]: module auth_log returns ok

Re: Vendor specific attributes, tags

2005-06-07 Thread Metz, Frederic
Hi, so Alan, one more question: what is non-standard ?? maybe there was a misunderstanding. I have a usual vendor specific attribute, but in the beginning of the String field there is a tag of 1 byte. Isn't it right that you can put anything in the string field in case of vendor specific

Re: make install error in Solaris 8, freeradius-1.0.3

2005-06-07 Thread Garry Crothers
Nuno Pais Fernandes wrote: Hi, small FIX but it works: mv /usr/bin/strip /usr/bin/strip.old echo '#!/bin/bash' /usr/bin/strip echo 'exit' /usr/bin/strip chmod 755 /usr/bin/strip cd freeradius-1.0.3 make install mv -f /usr/bin/strip.old /usr/bin/strip Worked for me. Nuno Fernandes On

Trouble installing 1.0.3

2005-06-07 Thread Nicolas Ross
When I install 1.0.3, I get at the end : /var/dev/freeradius-1.0.3/install-sh -c -m 755 -s radwho /usr/local/bin strip: /usr/local/bin/#inst.22560#: File format not recognized gmake[4]: *** [install] Error 1 (...) My configure line is simply ./configure. I am on RH Linux 7.3, plain kernel

Re: Trouble installing 1.0.3

2005-06-07 Thread Wolfgang Rosenauer
On 2005-06-07 at 09:18:08 -0400, Nicolas Ross wrote (shortened): When I install 1.0.3, I get at the end : /var/dev/freeradius-1.0.3/install-sh -c -m 755 -s radwho /usr/local/bin strip: /usr/local/bin/#inst.22560#: File format not recognized gmake[4]: *** [install] Error 1 (...) My

Re: Re: Ip pool doesn't works properly

2005-06-07 Thread Dustin Doris
On Tue, 7 Jun 2005, Simone Giovanardi wrote: Hi, How can I configure FreeRADIUS to assign IP address dinamically with Ip Pool when there is a successful authentication from Cisco 7200 access server with FreeRADIUS 1.0.0? Like this it works sending out only 2 ip address...always

/usr/local/lib/rlm_eap_tls-1.0.2.so: undefined symbol: SSL_set_ms g_callback

2005-06-07 Thread JAUMOTTE JEAN-LOUIS
Hi everyone, I am working in Munich for authentication with SIP phones A XP PC is working fien with the IAS Now instead IAS I am trying the FreeRadius. but when the PC sends a "Access request", I receive an error I am working with the version 1.0.2 The TLS is opened in the EAP.conf.

Re: Trouble installing 1.0.3

2005-06-07 Thread Nicolas Ross
Thanks for pointing it out ! Nicolas - Original Message - From: Wolfgang Rosenauer [EMAIL PROTECTED] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tuesday, June 07, 2005 9:30 AM Subject: Re: Trouble installing 1.0.3 On 2005-06-07 at 09:18:08 -0400,

Simultaneous-Use

2005-06-07 Thread Blake
I am sorry to post but I am just not getting something right here. I have been running this freeradius server for quite some time with no problems. I have just now decided that I want to solve the Simultaneous-Use problem. I am using 1.0.2 and a mysql database located on another server. I

RE: make install error in Solaris 8, freeradius-1.0.3

2005-06-07 Thread maruna
Dear all, I tried the fix proffered below on redhat90 and it worked aruna -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Garry Crothers Sent: Tuesday, June 07, 2005 1:39 PM To: FreeRadius users mailing list Subject: Re: make install error in Solaris

Installing freeradius 1.0.3

2005-06-07 Thread Software Development Group
Hello, I am trying to install freeradius 1.0.3 in a machine running Linux ubuntu hoary OS. My questions are: 1. Will the following procedure work? tar xzf ~/freeradius-1.0.3.tar.gz cd freeradius-1.0.3 fakeroot dpkg-buildpackage -b sudo dpkg -i ../freeradius_1.0.3-0_i386.deb 2. Do I have to make

First time conf issues

2005-06-07 Thread Keith Pitcher
I've been using ICRadius for awhile and it's ran smoothly, but needed to upgrade to freeradius to do some WPA radius. It installed fine on a FreeBSD 4.11 system, reading the information in the MySQL Database. However I can't get it working and would like some help. if I start the server, when I

Question regarding SSH connection resets when auth via pam radius

2005-06-07 Thread Josh Blender
Hi, any help with this issue would be greatly appreciated: I have pam_radius_auth configured on redhat enterprise (just for sshd and login), and the authentication is working properly. Unfortunately, when I log in via SSH, after some time (fairly brief), the connection simply terminates. I get

Re: Vendor specific attributes, tags

2005-06-07 Thread Alan DeKok
Metz, Frederic [EMAIL PROTECTED] wrote: ... PLEASE don't CC me on posts to the list. I already get enough mail. If I get enough duplicates from someone, I just delete all of their messages unread. what is non-standard ?? maybe there was a misunderstanding. non-standard == not defined in

Re: /usr/local/lib/rlm_eap_tls-1.0.2.so: undefined symbol: SSL_set_ms g_callback

2005-06-07 Thread Alan DeKok
JAUMOTTE JEAN-LOUIS [EMAIL PROTECTED] wrote: Hi everyone, I am working in Munich for authentication with SIP phones Sounds great! /usr/local/lib/rlm_eap_tls-1.0.2.so: undefined symbol: SSL_set_msg_callback You have two versions of OpenSSL installed. FreeRADIUS uses one when it's built,

Re: Simultaneous-Use

2005-06-07 Thread Alan DeKok
Blake [EMAIL PROTECTED] wrote: I have been running this freeradius server for quite some time with no problems. I have just now decided that I want to solve the Simultaneous-Use problem. I am using 1.0.2 and a mysql database located on another server. I have followed everything that I can

Re: First time conf issues

2005-06-07 Thread Alan DeKok
Keith Pitcher [EMAIL PROTECTED] wrote: if I start the server, when I run radtest it only seems to send the User-Name. It will say Sending Access-Request, User-Name = kpitcher and will then get a rad_recv error. Are you willing to post the *exact* command you entered, and the *exact* output,

Re: NAS info + MySQL

2005-06-07 Thread Alan DeKok
Seferovic Edvin [EMAIL PROTECTED] wrote: I have been watching this from the beginning ;) It got really interesting now. Does anyone know about OMAPI support in DHCPd? It allows you to change the config ( for example - update a lease ) at the real time without a need to restart a server. As

Re: radrelay bug with large attributes

2005-06-07 Thread Alan DeKok
Simon Pasquier [EMAIL PROTECTED] wrote: I've checked the bug database and the latest version of radrelay.c in the CVS repository but I couldn't find anything. So I was wondering if a bug should be opened to track this issue? I'll fix the issue in 1.0.4, which should be released soon.

Re: WLAN Transport protocol

2005-06-07 Thread Alan DeKok
Joseph Abadi [EMAIL PROTECTED] wrote: The whole setup works fine when the wireless cards have the WLAN Transport protocol Installed. But we are also working with some 20 USB wireless adapters that don't come with the protocol and don't give us the option to install it. Those cards aren't able

Re: NAS info + MySQL

2005-06-07 Thread Alan DeKok
Marcin Jessa [EMAIL PROTECTED] wrote: I was hoping I would not need to explain it one more time. I am very clear on what you want, and why. What you're not clear on is my answers. It does not metter what kind of signal httpd sends to radiusd, it would still need to be able to execute the

Re: NAS info + MySQL

2005-06-07 Thread Alan DeKok
Marcin Jessa [EMAIL PROTECTED] wrote: One more thing about this solution is you would need to either run radiusd as root or chown radiususer:radiusgroup the radius configs in order to be able to HUP radiusd. Radius daemon is started as root and then switched to the unprivileged user defined

Re: Simultaneous-Use

2005-06-07 Thread Blake
Alan DeKok wrote: Blake [EMAIL PROTECTED] wrote: I have been running this freeradius server for quite some time with no problems. I have just now decided that I want to solve the Simultaneous-Use problem. I am using 1.0.2 and a mysql database located on another server. I have followed

RE: NAS info + MySQL

2005-06-07 Thread Seferovic Edvin
Hi, I must have missed that part. Where can I find some doc about OMAPI support in freeradius? Thank you in advance. Regards, Edvin Seferovic -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Dienstag, 07. Juni 2005 20:54 To: [EMAIL

link error in radiusd

2005-06-07 Thread software
I have clean compiled freeradius 1.0.3 for ubuntu hoary with mysql. I have put the radiusd.conf (includes sql.conf and sqlcounter.conf), sql.conf (with mysql as database type) and sqlcounter.conf in the /etc/freeradius directory. When running radiusd -X I get the following error:

Re: Simultaneous-Use

2005-06-07 Thread Alan DeKok
Blake [EMAIL PROTECTED] wrote: That may be my problem. Which file does that entry need to exist? Where in the file? doc/Simultaneous-Use Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: NAS info + MySQL

2005-06-07 Thread Alan DeKok
Seferovic Edvin [EMAIL PROTECTED] wrote: I must have missed that part. Where can I find some doc about OMAPI support in freeradius? sigh FreeRADIUS does not have OMAPI support. Like DHCPd, FreeRADIUS supports live updates of SOME configuration. FreeRADIUS does this by using *databases*

...traffic control with freeradius?

2005-06-07 Thread alexander
Hi Just a question: There any way to establish that a user (or group) connects at certain hours of the day only? For example: If Peter attempts to connect after 3:00 pm, the radius should reject the request; because Peter can connect only between 12:00 am and 3:00 pm. Thanks you.

RE: ...traffic control with freeradius?

2005-06-07 Thread Seferovic Edvin
LoginTime attribute Read the doc Regards, Edvin Seferovic -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Dienstag, 07. Juni 2005 22:47 To: freeradius-users@lists.freeradius.org Subject: ...traffic control with freeradius? Hi

Authenticate/Attributes based on NAS-IP-Address

2005-06-07 Thread N White
Using MySQL as a backend, is there any way to configure Authentication and Attribute (replies), based on the NAS-IP-Address sent to the FreeRADIUS server? Allow requests from NAS1 to authenticate and have certain attributes for users in that group and then allow requests from NAS2 to

Re: Authenticate/Attributes based on NAS-IP-Address

2005-06-07 Thread N White
/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ NOD32 1.1132 (20050607) Information __ This message was checked by NOD32 antivirus system. http://www.eset.com Ok, so is it possible for them to be a part of two groups? The reason I ask

Re: Authenticate/Attributes based on NAS-IP-Address

2005-06-07 Thread Alan DeKok
N White [EMAIL PROTECTED] wrote: Ok, so is it possible for them to be a part of two groups? The reason I ask is that if a customer logs in through NAS1, I want them to be assigned a dynamic IP, if they are logged in from NAS2, I want them to be assigned a static IP. Is this possible?

Re: Authenticate/Attributes based on NAS-IP-Address

2005-06-07 Thread Alan DeKok
N White [EMAIL PROTECTED] wrote: Yeah, but I want to use MySQL, not the users file. I don't use MySQL, sorry. If you want someone to give you the exact answer you're looking for, I suggest you hire a contracter. Alan Dekok. - List info/subscribe/unsubscribe? See

Re: Authenticate/Attributes based on NAS-IP-Address

2005-06-07 Thread N White
? See http://www.freeradius.org/list/users.html __ NOD32 1.1132 (20050607) Information __ This message was checked by NOD32 antivirus system. http://www.eset.com Well, thanks for the input. With MySQL, 1500 users is easier to maintain. Perhaps I should just run a second

Re: Copyright and GPL infringement in tinyPEAP

2005-06-07 Thread Alexandre Coninx
On Sun, Jun 05, 2005, Alan DeKok wrote: Your web site http:/www.tinypeap.com is distributing binaries built at least in part from code that is derived from the FreeRADIUS server project (http://www.freeradius.org). I refer you to the following URL's:

Re: Copyright and GPL infringement in tinyPEAP

2005-06-07 Thread Alan DeKok
Alexandre Coninx [EMAIL PROTECTED] wrote: Is there any news about this probable GPL infringement ? I would be glad to be informed of any news from the people from tinypeap.com. No news. We will keep people posted as we get more information. As of today, their provider has had 24hrs to

Re: Authenticate/Attributes based on NAS-IP-Address

2005-06-07 Thread Dustin Doris
On Tue, 7 Jun 2005, N White wrote: Well, thanks for the input. With MySQL, 1500 users is easier to maintain. Perhaps I should just run a second FreeRADIUS server for the second NAS. It means more equipment, but whatever it takes. -Nick You don't need to do that, you can do it with SQL in

Re: Authenticate/Attributes based on NAS-IP-Address

2005-06-07 Thread N White
to do. You can add groups into if you want but right now you probably won't need it. Hope that is helpful. Dusty Doris - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html __ NOD32 1.1132 (20050607) Information __ This message was checked by NOD32

Problem with [microsoft] stuff not working

2005-06-07 Thread Scott Gusler
Ok i'm not sure what all detail i need to give for this post but here goes I have a USR Hiperarc tc1000 and a portmaster 4 we migrated from steelbelt to freeradius for auth and accounting the problem comes in here, when i use freeradius with the portmaster it works perfect fine, as expected

Can a user be authenticated with MAC address and EAP/TLS

2005-06-07 Thread Jefri bin Dahari
Hi all, I try to authenticate my wireless user with MAC address and EAP/TLS simultaneously. I set my Cisco 1230 AP to authenticate 'with MAC address and EAP' and my wireless client as for EAP/TLS authentication because no special setting is needed for MAC authentication. However, the wireless