RE: FreeRadius and PostgreSQL configuration question

2005-06-15 Thread Shepherd, Dave
How much max_connections we should configure in a postgresql.conf file? [DLS ] I can't find this setting in the postgresql.conf file that I've got, but it does appear in the /usr/share/pgsql/postgresql.conf.sample file. I've checked 2 boxes one with 0.9.3 and the other with 1.0.2 installed and

Re: freeradius no longer accepts Crypt-Password after upgrade

2005-06-15 Thread Rens Houben
Argh. So I decided to try and wipe the thing, then do a clean install and just add in the correct values for sql.conf and the required tweaks to radiusd.conf, but I seem to have made the problem worse because now it claims it can't even find the user. Log output, intersparsed with the mysql

Re: freeradius no longer accepts Crypt-Password after upgrade

2005-06-15 Thread Rens Houben
In other news for Wed, Jun 15, 2005 at 10:08:05AM +0200, Rens Houben has been seen typing: Argh. Disregard, I'm an idiot. The No Auth-Type Found was because I'd forgotten to restore the huntgroups file. Now it's merely repeating the original error: auth: user supplied User-Password does NOT

checkval or proxy

2005-06-15 Thread Craig Hancock
Hello All General Question I am a freeradius system setup where I am authenticating 2 kinds of users 1) Authorized users: Authorized users are users who have are directly afflited with an organization and well be using the system indefintely. 2) Guest Users: Authorized users who are

Re: Generating freeradius 1.0.3

2005-06-15 Thread Paul Hampson
On Mon, Jun 13, 2005 at 01:43:36PM -0400, Software Development Group wrote: Running Debian, I have done a $ fakeroot dpkg-buildpackage -b on the freeradius 1.0.3 directory. I get a warning saying That should be dpkg-buildpackage -rfakeroot -b, although the above should also work... remember

RE: FreeRadius and PostgreSQL configuration question

2005-06-15 Thread NECTIS NetVoice Sales
You look wrong configurations. That file you look is a Postgres connection config for freeradius. I've ask for PostgreSQL database configuration which present in the PostgreSQL configuration folder /var/lib/psql/data/ Regards, -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

Re: Debian .deb Installation Version 1.0.2 Ca.all dosn' exist

2005-06-15 Thread Paul Hampson
On Tue, Jun 14, 2005 at 03:09:20PM +0200, Michael Langer wrote: Hi @all, i read some HowTo's for installing FreeRadius/PEAP and they have used the CA.all script to create the certificats. But i can't find this script after installing FreeRadius deb version 1.0.2 on my PC. I have to install

problem with freeradius and ldaps (Active Directory)

2005-06-15 Thread Roberto S. G.
Hi, I'm trying to configure freeradius (1.0.1) to use an ldaps server (without start_tls, it's an Active Directory). But I'm not able to obtain any response. In fact, the freeradius crashes with just a: rad_recv: Access-Request packet from host xxx.xxx.xxx.xxx:1074, id=88, length=29

RE: FreeRadius and PostgreSQL configuration question

2005-06-15 Thread Shepherd, Dave
Sorry, my mistake. Mine is set to the default (32) and works fine. When you say 100 concurrent do you mean connections or requests? Dave Shepherd Technical Support Manager Compass Group UK and Ireland T : +44 121 457 5037 F : +44 121 457 5038 M : +44 7767 274 087 -Original Message-

Re: Debian .deb Installation Version 1.0.2 Ca.all dosn' exist

2005-06-15 Thread Nicolas Baradakis
Michael Langer wrote: i read some HowTo's for installing FreeRadius/PEAP and they have used the CA.all script to create the certificats. But i can't find this script after installing FreeRadius deb version 1.0.2 on my PC. I have to install other packets ? Openssl is already installed. (After

RE: FreeRadius and PostgreSQL configuration question

2005-06-15 Thread NECTIS NetVoice Sales
Hi Dave, I think it will be 100 concurrent calls to switch. I do not know about how much connections and requests will be. Can you share your PostgreSQL configuration file please? I know it depend the server configuration, but your experience will be usefull. You email me direct. Regards, Serge

Re: Generating freeradius 1.0.3

2005-06-15 Thread Software Development Group
Yes, it generated .deb packages. I have run them and apparently they installed correctly but when I run the application I get an: radiusd.conf[2] Failed to link to module 'rlm_sqlcounter': /usr/lib/freeradius/rlm_sqlcounter.a: invalid ELF header error thou the module IS located in the directory

Re: 'authorize' module

2005-06-15 Thread Edgars Klavinskis
Alan, how to do authentication based on attribute checking (attr_compar or something like this)? I mean, if I am adding some atributes to config_items via rlm_passwd how to check those attributes in the authenticate section? User-Password is only checkd, nothing more. For example, I want to

Accounting ReceiveQueue

2005-06-15 Thread Edgars Klavinskis
In which case the accounting queue is getting so big (see below) while a authorization works perfect? Proto Recv-Q Send-Q Local Address Foreign Address State moon:~# netstat -l |grep radius udp0 0 *:radius*:* udp 100608 0 *:radius-acct

Accounting question

2005-06-15 Thread Joseph Abadi
Hello, I have a question regarding the way accounting is done. I configured freeradius 1.0.1 with openssl and mysql support on a Fedora Core 3 system. I'm using it with PEAP and TLS for wireless authentication. The authentication works fine, but the accounting packets are always missing the

Re: Accounting question

2005-06-15 Thread Martin Pauly
Hello, I think my question ist quite related to yours although we do EAP-TTLS, i.e. PAP inside the tunnel. I have a question regarding the way accounting is done. I configured freeradius 1.0.1 with openssl and mysql support on a Fedora Core 3 system. I'm using it with PEAP and TLS for

Re: FR eap-ttls , winxp client configuration

2005-06-15 Thread Alan DeKok
Bruno Quintas [EMAIL PROTECTED] wrote: I really not understanding how to use the options and if should i use them: copy_request_to_tunnel = no use_tunneled_reply = no These options are documented in the comments in eap.conf. Do you have specific questions about the documentation, or do

Re: Expiration Module

2005-06-15 Thread Alan DeKok
Jaco van Tonder [EMAIL PROTECTED] wrote: It is never sent. I use radtest and get no replyradtest simply sends the request again and again... OK. It works for me with the default reject_delay = 5. You've set it to 1, which is something I haven't tested. Try setting it BACK to the

Re: Debian .deb Installation Version 1.0.2 Ca.all dosn' exist

2005-06-15 Thread Alan DeKok
[EMAIL PROTECTED] (Paul Hampson) wrote: If you're working from the version in the Debian archive, I'll make an upload of 1.0.3 to address this by the weekend. If you're working from the release on the website, you'll have to grab the release_1_0 tree from CVS once I fix this. Could you also

Re: problem with freeradius and ldaps (Active Directory)

2005-06-15 Thread Alan DeKok
Roberto S. G. [EMAIL PROTECTED] wrote: But I'm not able to obtain any response. In fact, the freeradius crashes with just a: rad_recv: Access-Request packet from host xxx.xxx.xxx.xxx:1074, id=88, length=29 Discarding duplicate request from client localhost:1074 - ID: 88 It's not a

Re: 'authorize' module

2005-06-15 Thread Alan DeKok
Edgars Klavinskis [EMAIL PROTECTED] wrote: I mean, if I am adding some atributes to config_items via rlm_passwd how to check those attributes in the authenticate section? You don't. I don't understand why you would want to check them there. User-Password is only checkd, nothing more.

Re: Accounting question

2005-06-15 Thread Alan DeKok
Joseph Abadi [EMAIL PROTECTED] wrote: The authentication works fine, but the accounting packets are always missing the username and the IPs of client and NAS seem to be interchanged. See the FAQ. The server logs what the NAS sends it. If the NAS sends the wrong thing, the server logs it.

Re: FR eap-ttls , winxp client configuration

2005-06-15 Thread Bruno Quintas
Thanks for your feedback Alan, i'll try to be clearer: What changes should i do in the server to change the current setup EAP-TLS to EAP-TTLS? Based on the documents eap.conf: default_eap_type = ttls in eap section comment tls and uncomment ttls? The purpose of using ttls is to

RE: FR eap-ttls , winxp client configuration

2005-06-15 Thread King, Michael
Do not comment TLS. TLS is required to Make TTLS work. (TTLS uses the TLS section) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bruno Quintas Sent: Wednesday, June 15, 2005 2:24 PM To: FreeRadius users mailing list Subject: Re: FR eap-ttls

Re: FR eap-ttls , winxp client configuration

2005-06-15 Thread Alan DeKok
Bruno Quintas [EMAIL PROTECTED] wrote: What changes should i do in the server to change the current setup EAP-TLS to EAP-TTLS? Based on the documents eap.conf: default_eap_type = ttls in eap section comment tls and uncomment ttls? The howto's say that you need TLS to do TTLS.

Re: freeradius no longer accepts Crypt-Password after upgrade

2005-06-15 Thread Alan DeKok
[EMAIL PROTECTED] (Rens Houben) wrote: I've pasted a full trace log on http://hiryuu.systemec.nl/~shadur/freeradissues.txt ... rlm_sql (sql): No matching entry in the database for request from user [hecker] That's telling. mysql SELECT id,UserName,Attribute,Value,op FROM radcheck WHERE

no DB handles

2005-06-15 Thread Lucas Aimaretto
Hi all, I've seen many of these messages in the radius.log ... Wed Jun 15 15:10:23 2005 : Info: rlm_sql (sql): There are no DB handles to use! skipped 0, tried to connect 0 What does it mean ? How to solve this ? Best regards, Lucas -- No virus found in this outgoing message. Checked by

Re: Problem TTLS-LDAP

2005-06-15 Thread alfonso celestino
Thanks very much Alan, Now, I have a doubt. I am using EAP-TTLS to authenticate users 802.11, I need to add my users in the users file like that: User1 User-Password == passwd1 User2 User-Password == passwd2 But instead of storing in users file I would like to do to LDAP, it is possible to

Using Oracle AND MySQL

2005-06-15 Thread Tim Rich, Jr.
Title: Using Oracle AND MySQL freeRADIUS is part of our solution - the majority of our solution, including users resides in an Oracle database; however, we have been using MySQL for authenticate, authorize, and accounting. Of course, there is an overhead here where we programmatically keep

RE: no DB handles

2005-06-15 Thread Seferovic Edvin
Hi, increase the number of connections to the mysql db in your sql.conf ! # number of sql connections to make to server num_sql_socks = 15 Regards, Edvin Seferovic -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Lucas Aimaretto Sent: Mittwoch,

Re: Using Oracle AND MySQL

2005-06-15 Thread Alan DeKok
Tim Rich, Jr. [EMAIL PROTECTED] wrote: Can we authenticate and authorize in Oracle and account in MySQL? Yes. You will need to create two instances of the SQL module, one for Oraclem and one for MySQL. Then, rather than listing sql somewhere in radiusd.conf, you'd list sql_oracle, or

Re: Problem TTLS-LDAP

2005-06-15 Thread Alan DeKok
alfonso celestino [EMAIL PROTECTED] wrote: But instead of storing in users file I would like to do to LDAP, it is possible to do it? Without stopping using EAP-TTLS. Yes. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: no DB handles

2005-06-15 Thread Lucas Aimaretto
I've seen many of these messages in the radius.log ... Wed Jun 15 15:10:23 2005 : Info: rlm_sql (sql): There are no DB handles to use! skipped 0, tried to connect 0 What does it mean ? How to solve this ? Hi, increase the number of connections to the mysql db in your sql.conf !

RE: no DB handles

2005-06-15 Thread Lucas Aimaretto
I've seen many of these messages in the radius.log ... Wed Jun 15 15:10:23 2005 : Info: rlm_sql (sql): There are no DB handles to use! skipped 0, tried to connect 0 What does it mean ? How to solve this ? Hi, increase the number of connections to the mysql db in your

Freeradius make install error

2005-06-15 Thread synackrst
Hello, Any solution for this: #make install ... /usr/local/src/freeradius-1.0.3/install-sh -c -m 755 -s .libs/radiusd /usr/local/sbin/radiusd /usr/local/src/freeradius-1.0.3/install-sh -c -m 755 -s radwho /usr/local/bin strip: /usr/local/bin/#inst.420#: File format not

Re: no DB handles

2005-06-15 Thread Alan DeKok
Lucas Aimaretto [EMAIL PROTECTED] wrote: I only 9 seconds, 21 messages of this kind. And .. .do the unresponsive child have something to do ... ??? Yes. Your database is slow, and is not responding to FreeRADIUS in time. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Freeradius make install error

2005-06-15 Thread Carlos Martínez-Troncoso Cera
I had the same error installing freeradius 1.0.3 in Linux and Solaris, I saw that this version has bugs for install, and tried with 1.0.2 version and now everything is working, see the fixes for 1.0.3 and if none is for you, you can try with 1.0.2. Reggards, Carlos Martnez-Troncoso Cera

RE: Freeradius make install error

2005-06-15 Thread synackrst
://www.freeradius.org/list/users.html __ NOD32 1.1141 (20050615) Information __ This message was checked by NOD32 antivirus system. http://www.eset.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Timer...

2005-06-15 Thread synackrst
Thank you :) Regards, Paulo Leitao -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: terça-feira, 14 de Junho de 2005 21:57 To: FreeRadius users mailing list Subject: Re: Timer... synackrst [EMAIL PROTECTED] wrote: Anyone can help-me

Re: Problem TTLS-LDAP

2005-06-15 Thread Vladimir Vuksan
alfonso celestino wrote: Thanks very much Alan, Now, I have a doubt. I am using EAP-TTLS to authenticate users 802.11, I need to add my users in the users file like that: User1 User-Password == passwd1 User2 User-Password == passwd2 But instead of storing in users file I would like to do

Which module to use talk to Microsoft SQL Server 2000 ?

2005-06-15 Thread Aime
All, Which module can one use to accounting or authenticating with Microsoft SQl Server ? Thanks in advance --Aimé __ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com - List

RE: Which module to use talk to Microsoft SQL Server 2000 ?

2005-06-15 Thread synackrst
Hello You have to use mssql.conf instead sql.conf . And the driver is: driver = rlm_sql_freetds Regards, Paulo Leitao -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Aime Sent: quinta-feira, 16 de Junho de 2005 1:13 To:

RE: Which module to use talk to Microsoft SQL Server 2000 ?

2005-06-15 Thread Aime
Thanks you very much. I did not try the new version of freeradius yet. Is this library in the new version Freeradius 1.0.3 ? Can someone comments on the usage of the rlm_sql_freetds ? stability ? etc... --Aimé --- synackrst [EMAIL PROTECTED] wrote: Hello You have to use mssql.conf instead

Re: Which module to use talk to Microsoft SQL Server 2000 ?

2005-06-15 Thread Alan DeKok
Aime [EMAIL PROTECTED] wrote: Can someone comments on the usage of the rlm_sql_freetds ? stability ? etc... Don't use it. use rlm_sql_iodbc, instead. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

freeradius 1.0.4

2005-06-15 Thread Andrew Thompson
Hi, I maintain the FreeRADIUS port for FreeBSD and am holding off upgrading from 1.0.2 due to the imminent release of 1.0.4 (06 June). There doesn't seem to be any discussion on the mailing lists, is 1.0.4 due soon or should I upgrade to 1.0.3 in the interim? cheers, Andrew - List

Re: Generating freeradius 1.0.3

2005-06-15 Thread Paul Hampson
On Wed, Jun 15, 2005 at 10:24:23AM -0400, Software Development Group wrote: Yes, it generated .deb packages. I have run them and apparently they installed correctly but when I run the application I get an: radiusd.conf[2] Failed to link to module 'rlm_sqlcounter':

Re: freeradius 1.0.4

2005-06-15 Thread Paul Hampson
On Thu, Jun 16, 2005 at 03:29:05PM +1200, Andrew Thompson wrote: Hi, I maintain the FreeRADIUS port for FreeBSD and am holding off upgrading from 1.0.2 due to the imminent release of 1.0.4 (06 June). There doesn't seem to be any discussion on the mailing lists, is 1.0.4 due soon or should I

Re: freeradius 1.0.4

2005-06-15 Thread Andrew Thompson
On Thu, Jun 16, 2005 at 01:51:04PM +1000, Paul Hampson wrote: On Thu, Jun 16, 2005 at 03:29:05PM +1200, Andrew Thompson wrote: Hi, I maintain the FreeRADIUS port for FreeBSD and am holding off upgrading from 1.0.2 due to the imminent release of 1.0.4 (06 June). There doesn't seem to

Re: freeradius 1.0.4

2005-06-15 Thread Doug Hardie
On Jun 15, 2005, at 21:09, Andrew Thompson wrote: On Thu, Jun 16, 2005 at 01:51:04PM +1000, Paul Hampson wrote: On Thu, Jun 16, 2005 at 03:29:05PM +1200, Andrew Thompson wrote: Hi, I maintain the FreeRADIUS port for FreeBSD and am holding off upgrading from 1.0.2 due to the imminent

1.0.4 (Was: Debian .deb Installation Version 1.0.2 Ca.all dosn' exist)

2005-06-15 Thread Paul Hampson
On Wed, Jun 15, 2005 at 12:53:49PM -0400, Alan DeKok wrote: [EMAIL PROTECTED] (Paul Hampson) wrote: If you're working from the version in the Debian archive, I'll make an upload of 1.0.3 to address this by the weekend. If you're working from the release on the website, you'll have to grab