freeradius-1.1.1 with ldap credential caching

2006-06-22 Thread bright spark
Hi,Any one know does freeradius-1.1.1 support ldap credential caching? If so, how do i configure it ?Please reply me.Thanks,Andulo Patel - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PEAP Auth

2006-06-22 Thread Stefan Winter
Hi, Freeradius. I still get the same error message on startup regarding no file for TLS. I have searched the Debian site, the Freeradius site, and the web in general and cannot seem to find out how to fix this. Does anyone know? How should we? You don't even tell us what the error is.

Re: rlm_exec

2006-06-22 Thread Stefan Winter
Hi, does anyone knows what rlm_exec module does? it executes commands. You can feed it with AVPs via environment variables so that it does whatever magic you want it to. Greetings, Stefan Winter -- Stefan WINTER Stiftung RESTENA - Réseau Téléinformatique de l'Education Nationale et de la

Re: Change RAD_REPLY item in rlm_perl, not add a new pair

2006-06-22 Thread Boian Jordanov
On Tuesday 20 June 2006 19:05, Kenneth Marshall wrote: On Tue, Jun 20, 2006 at 11:05:04AM +0200, Bj?rn Mork wrote: Kenneth Marshall [EMAIL PROTECTED] writes: I am trying to use rlm_perl to append a number to one member of the reply packet using rlm_perl and the %RAD_REPLY hash. I am

Re: error: Installed (but unpackaged) files(s) found: on REDHAT Enterprise 4.0 (RHEL4) and FreeRadius 1.1.2

2006-06-22 Thread B Thompson
On Thu, Jun 22, 2006 at 12:32:32AM +0200, Tadej Bregar wrote: Hello, I'm struggling to build a RPM package on RHEL 4 also (based on freeradius.spec file), I have tried adding sed line as suggested in on of the previous posts and also suggested %doc lines, but with no success. How do i

Re: Proxy - EAP problems

2006-06-22 Thread Wladyslaw Pietraszek
Thanks for the hint. BTW do you have any links to info about how to implement magic Microsoft OID's - Google search did not give much :-( The authentication for the topology access-point - pdc (also freeradius) works and certificates for the proxy are generated in the similar way. I

Re: Proxy - EAP problems

2006-06-22 Thread B Thompson
On Thu, Jun 22, 2006 at 10:06:05AM +0200, Wladyslaw Pietraszek wrote: Thanks for the hint. BTW do you have any links to info about how to implement magic Microsoft OID's - Google search did not give much :-( There is a link to this article on the front page of the FreeRADIUS web site :-

freeradius + SQL Ldap

2006-06-22 Thread Guillaume Verdin
hi, I configure freeradius with Sql and ldap. The base ldap contains the login and the password of 15000 users and any other parameter. And I will wish to aply parameters with these users (but not in the base ldap, for example in the file users, or the base postgresql) The base postgresql

Re: Change RAD_REPLY item in rlm_perl, not add a new pair

2006-06-22 Thread Kenneth Marshall
On Thu, Jun 22, 2006 at 09:58:54AM +0300, Boian Jordanov wrote: Maybe passing a HASH ref for hash which contains the Operator key and the vp item too will be a good idea. For example $hash{'Tunnel-Id'} = visitor; $hash{'Operator'} = :=; $RAD_REPLY{'Tunnel-Id'} = \%hash; This way we

Re: rlm_exec

2006-06-22 Thread Leandro Pereira de Lima e Silva - ViaLink
Can I use it to delegate authentication and/or accounting to some other script outside freeradius? Thanks, Leandro. Stefan Winter escreveu: Hi, does anyone knows what rlm_exec module does? it executes commands. You can feed it with AVPs via environment variables so that it does

RE: Malfunctioning Nomadix

2006-06-22 Thread Rob Parker
Hi, I've seen this with our Nomadix USG and AG series devices as well - often the NSE will send requests multiple times, but I can never understand why. There are a few other bugs in the RADIUS code in Nomadix as well, for example I have never managed to get round robin working as I would expect

Is there a good guide to writing rlm modules

2006-06-22 Thread David Goodenough
I am a newbie to Radius, and need to implement some function that is not easily done by any of the existing modules. So I want to write my own, and being a Java programmer I chose JRadius as well we FreeRadius. I wrote a module but it is not taking my acceptance of the user i the authorize

Re: Proxy - EAP problems

2006-06-22 Thread Wladyslaw Pietraszek
Thanks to Allan and Ben for hints and link to documentation. Proxy server has had correct certificates and although new certificates has been installed the proxy still fails to authenticate. Proxy server certificate does include xpextensions and openssl x509 -in cert_file -noout -text gives

Re: Parse error freeradius-1.1.1

2006-06-22 Thread Lin Richardson
Everything looks good so far. Thanks for the help.You are welcome to send me testing needs and I'll accommodate as I can. May not be same day service, but I'd be happy to do it.Regards,Lin On 6/21/06, Stephen Gran [EMAIL PROTECTED] wrote: On Wed, Jun 21, 2006 at 02:06:02PM -0600, Lin Richardson

Resetting Accounting Records in MySQL

2006-06-22 Thread Dan Massey
Title: Resetting Accounting Records in MySQL Hi All I work for an isp, and we need to track the users data transfer by calendar month. I have FreeRadius/MySQL running on FreeBSD, the final task for me to do is work out how to force radius to start a new accounting record in the MySQL database

Re: rlm_exec

2006-06-22 Thread Alan DeKok
Leandro Pereira de Lima e Silva - ViaLink [EMAIL PROTECTED] wrote: Can I use it to delegate authentication and/or accounting to some other script outside freeradius? Can you read the documentation describing the module? I don't understand why the existing documentation isn't good enough.

RE: Re: PEAP Auth

2006-06-22 Thread Scott Hughes
The exact error is: rlm_eap: Failed to link EAP-Type/tls: rlm_eap_tls.so: cannot open shared object file: No such file or directory radiusd.conf[9]: eap: Module instantiation failed. The entire startup log is here: Starting - reading configuration files ... Using deprecated naslist file.

So how do you suppress

2006-06-22 Thread Walter Reynolds
From the changelog: * Added suppress configuration entry to rlm_detail, to suppress certain attributes (e.g. User-Password). This closes bug #359. So how do I actually suppress the user password from the detail log based on this? Looking at the rlm_detail file

Re: Resetting Accounting Records in MySQL

2006-06-22 Thread Alan DeKok
Dan Massey [EMAIL PROTECTED] wrote: I work for an isp, and we need to track the users data transfer by calendar month. I have FreeRadius/MySQL running on FreeBSD, the final task for me to do is work out how to force radius to start a new accounting record in the MySQL database which will allow

Re: PEAP Auth

2006-06-22 Thread Alan DeKok
Scott Hughes [EMAIL PROTECTED] wrote: rlm_eap: Failed to link EAP-Type/tls: rlm_eap_tls.so: cannot open shared object file: No such file or directory radiusd.conf[9]: eap: Module instantiation failed. If you're running debian, re-build the server from source. See the debian directory.

Re: PEAP Auth

2006-06-22 Thread Stefan Winter
Hi! rlm_eap: Failed to link EAP-Type/tls: rlm_eap_tls.so: cannot open shared object file: No such file or directory radiusd.conf[9]: eap: Module instantiation failed. Ah, thank you. That's much more enlightening. For some reason the TLS module was not compiled and installed. There was some

Re: So how do you suppress

2006-06-22 Thread Stefan Winter
Hi, So how do I actually suppress the user password from the detail log based on this? Looking at the rlm_detail file and I might as well be looking at a foreign language. I don't use this directive, so I might be wrong but my guess is: you don't need to look at the source of rlm_detail

Re: Re: PEAP Auth

2006-06-22 Thread Stephen Gran
On Thu, Jun 22, 2006 at 11:29:39AM -0500, Scott Hughes said: The exact error is: rlm_eap: Failed to link EAP-Type/tls: rlm_eap_tls.so: cannot open shared object file: No such file or directory radiusd.conf[9]: eap: Module instantiation failed. I assume this is Debian, since you said you

Beginner question

2006-06-22 Thread Khan
Hi to all, I just register to the ML as I'm looking for specific item in freeradius without being able to find any help. Even if google is supposed to be my friend, it was not in that cases ;) My first one is to use several root CA in an EAP-TLS config. There is a line for root CA List, but how

Re: rlm_exec

2006-06-22 Thread Leandro Pereira de Lima e Silva - ViaLink
Alan, sorry, but I couldn't find specific information about rlm_exec module in the documentation. If someone said that it could be used that way, my next question would be where can I find good documentation explaining how to work with this module. My intention really wasn't upset you.

how to configure NAI realms routing table

2006-06-22 Thread Dhaval Shah
Hi I have a question about how to use freeradius server as a proxy and configure a NAI realms based routing table to help incomming RADIUS packets to be forwarded to the correct next proxy towards the home AAA server. I also wanted to find out whether freeradius working as a proxy would

Re: So how do you suppress

2006-06-22 Thread Walter Reynolds
preprocess returns ok for request 0 radius_xlat: '/usr/local/var/log/radius/radacct/198.111.224.36/auth-detail-20060622' rlm_detail: /usr/local/var/log/radius/radacct/%{Client-IP-Address}/auth-detail-%Y%m%d expands to /usr/local/var/log/radius/radacct/198.111.224.36/auth-detail-20060622 modcall

Re: So how do you suppress

2006-06-22 Thread A . L . M . Buxey
Hi, So how do I actually suppress the user password from the detail log based on this? Looking at the rlm_detail file and I might as well be looking at a foreign language. you can, for example, do somthing like this in radiusd.conf # Write a detailed log of all accounting records

Re: Beginner question

2006-06-22 Thread Alan DeKok
Khan [EMAIL PROTECTED] wrote: My first one is to use several root CA in an EAP-TLS config. There is a line for root CA List, but how can I set 2 root CAs or more ? I tried to have the line several times and also separate the rootCAs file names by a comma (,). None of this attempts seems to

Re: rlm_exec

2006-06-22 Thread Alan DeKok
Leandro Pereira de Lima e Silva - ViaLink [EMAIL PROTECTED] wrote: sorry, but I couldn't find specific information about rlm_exec module in the documentation. radiusd.conf comes with voluminous comments saying what it does, and how to use it. Alan DeKok. - List

Re: So how do you suppress

2006-06-22 Thread Alan DeKok
. Think hard. From the debug log again: /usr/local/var/log/radius/radacct/198.111.224.36/auth-detail-20060622 Hmm.. maybe you want to go read that file, to see if it contains User-Password. Odds are it doesn, in fact, because you suppressed User-Password in the normal detail module

Re: Is there a good guide to writing rlm modules

2006-06-22 Thread Alan DeKok
David Goodenough [EMAIL PROTECTED] wrote: So I want to write my own, and being a Java programmer I chose JRadius as well we FreeRadius. I wrote a module but it is not taking my acceptance of the user i the authorize step, but rather send a rejection to the post_auth step. Read the debug

Debian TLS support

2006-06-22 Thread Scott Hughes
Hello, I think in my last reqest to the list I wasn't quite clear as to the information I was trying to find. I'll try again and sorry for any toes that were stepped on. When I install Freeradius (after installing OpenSSL) I get this message when starting Freeradius: rlm_eap: Failed to

Re: Beginner question

2006-06-22 Thread Benjamin Bennett
Khan wrote: My first one is to use several root CA in an EAP-TLS config. There is a line for root CA List, but how can I set 2 root CAs or more ? I tried to have the line several times and also separate the rootCAs file names by a comma (,). None of this attempts seems to work. What am I

Re: Debian TLS support

2006-06-22 Thread B Thompson
On Thu, Jun 22, 2006 at 03:36:52PM -0500, Scott Hughes wrote: Is there a HOWTO for example on how a person can do what I am trying to do? Have you tried downloading the source and running dpkg-buildpackage? -- Ben Thompson - List info/subscribe/unsubscribe? See

Re: how to configure NAI realms routing table

2006-06-22 Thread Stefan Winter
Any links to documentation on how to achieve this with freeradius would be appreciated. ? Have you taken a look at proxy.conf? Should all be there... Stefan -- Stefan WINTER Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche - Ingénieur de

Re: Debian TLS support

2006-06-22 Thread A . L . M . Buxey
Hi, When I install Freeradius (after installing OpenSSL) I get this message when starting Freeradius: you need to make sure you have openssl-devel package also installed. JUST having openssl is not enough (that only supplies the user tools and libraries) alan - List

Re: Is there a good guide to writing rlm modules

2006-06-22 Thread David Goodenough
On Thursday 22 June 2006 21:03, Alan DeKok wrote: David Goodenough [EMAIL PROTECTED] wrote: So I want to write my own, and being a Java programmer I chose JRadius as well we FreeRadius. I wrote a module but it is not taking my acceptance of the user i the authorize step, but rather send a

freeradius with AD

2006-06-22 Thread Kartthik Raghunathan
Am trying to join the freeradius machine to active directory, so i can authenticate the users against active directory. When i try to bind am getting the below error message: net join ADS -U username%password ads_join_realm: Operations error ADS join did not work, falling back to RPC... Joined

RE: error: Installed (but unpackaged) files(s) found: on REDHAT Enterprise 4.0 (RHEL4) and FreeRadius 1.1.2

2006-06-22 Thread Sandworm
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 -Original Message- How do i have to modify freeradius.spec file to build it successfully? Has anyone (besides Alberto Cruz) also managed to build RPM on RHEL 4? Thanky for any info, Tadej Bregar Hi Yes, I've successfully built on