RE: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Elie Hani
Thanks Michal,I will try this one, but still one more thing. To for the Freeradius to talk to the DHCP, there's a place where I should configure the DHCP's address. Where should I configure the DHCP address on the radius so the last one will use the DHCP's Ips. Thanks Elie -Original

UPDATE RADACCT problem

2006-07-26 Thread ravi reddy
Hi all I am using Freeradius-1.1.2 with SER for Accounting purpose every thing is going good til now, here i need some help regarding FreeRadius :- when acctstarts the radius server is writing the acctstart time stamp in radact table and when acct stops it again update radacct table by

Re: UPDATE RADACCT problem

2006-07-26 Thread Stefan Winter
Hi, radius_xlat: 'UPDATE radacct SET AcctStopTime = '2006-07-26 09:39:57', AcctSessionTime = '', AcctInputOctets = '', AcctOutputOctets = '', AcctTerminateCause = '', AcctStopDelay = '0', ConnectInfo_stop = '' WHERE AcctSessionId = '[EMAIL PROTECTED]' AND UserName = ' [EMAIL PROTECTED]' AND

Re: mysql libraries are there BUT not found

2006-07-26 Thread Rob Shepherd
Roger Thomas wrote: What I have done wrong? Please advise. -- Roger I just used --with-mysql-dir=/usr/local/mysql-5.0.21 and it worked. -- Rob Shepherd | Computer and Network Engineer | Technium CAST | LL57 4HJ [EMAIL PROTECTED] | 01248 675024 | 07776 210516 - List

Re: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Phil Mayers
Elie Hani wrote: Thanks Michal,I will try this one, but still one more thing. To for the Freeradius to talk to the DHCP, there's a place where I should configure the DHCP's address. Where should I configure the DHCP address on the radius so the last one will use the DHCP's Ips. What part of

Re: EAP doest work with Cisco Catalyst 2950?

2006-07-26 Thread Phil Mayers
Thai Duong wrote: I can be sure the client certificate has the Enhanced Key Usage showing Client Authentication (1.3.6.1.5.5.7.3.2). I have no way to verify whether the server certificate contains proper OID but here is openssl x509 -noout -text -in theserver.crt ...will show things like:

RE: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Elie Hani
Wel Phil, since ur not talking in a profession way, and since you feel that you are the expert in here, you don't have the right to answer me like that. If you know how to read, what part of this you did not understand Thanks Michal,I will try this one, but still one more thing. If you were so

AW: AW: AW: EAP-TTLS MD5 hashed Passwords in MySQLDatabaseforWPA-802.1xauth

2006-07-26 Thread Christian Poessinger
[EMAIL PROTECTED] wrote: [EMAIL PROTECTED] wrote: Please read the EARLIER messages in the debug log. It's obvious that the password was NOT read from SQL, so authentication will not work. Get the server to read the password from SQL. Debug log WILL SAY when the appropriate user

Re: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Stefan Winter
Hi, Thanks Michal,I will try this one, but still one more thing. To for the Freeradius to talk to the DHCP, there's a place where I should configure the DHCP's address. Where should I configure the DHCP address on the radius so the last one will use the DHCP's Ips. What part of no

RE: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Elie Hani
Thanks Stephan, I really appreciate it. As a matter of fact, if anyone in here has the full knowledge of the Radius, he wouldn’t be registered in this list. I'm not one of them, but I'm a ccie certificated and it was an insult. Anyways, thanks again Stephan -Original Message- From:

Re: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Josh Howlett
On 26 Jul 2006, at 10:27, Stefan Winter wrote: The RADIUS protocol doesn't interact with DHCP. FreeRADIUS doesn't do it. There is no place to configure any such thing. I'm sure I've seen at least a couple of other similar DHCP queries in the last couple of weeks. I wonder how difficult it

Re: rlm_eap_tls.so won't build.

2006-07-26 Thread Nicolas Baradakis
Lyle Tollefsen wrote: I'm new to freeradius and open source in general, so please bear with me. I'm having a problem with the rlm_eap_tls.so module not compiling, or installing, depending on whether I'm compiling from source, or apt-geting the package. The complaint is that Openssl is

Re: mysql libraries are there BUT not found

2006-07-26 Thread Nicolas Baradakis
Roger Thomas wrote: In /usr/local/mysql/lib/mysql I have: -rw-r--r--1 root mysql 11866 May 15 10:56 libdbug.a -rw-r--r--1 root mysql 40304 May 15 10:56 libheap.a -rw-r--r--1 root mysql 13536 May 15 10:56 libmerge.a -rw-r--r--1 root mysql

Re: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Stefan Winter
Hi Josh, I'm sure I've seen at least a couple of other similar DHCP queries in the last couple of weeks. I wonder how difficult it would be to add a simple DHCP client to FreeRADIUS? Thanks for the on-topic question, I was already fearing a flamewar coming up. I guess if you really want to

Re: EAP doest work with Cisco Catalyst 2950?

2006-07-26 Thread Thai Duong
--- Phil Mayers [EMAIL PROTECTED] wrote: openssl x509 -noout -text -in theserver.crt ...will show things like: X509v3 Key Usage: Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication ...the

Re: EAP doest work with Cisco Catalyst 2950?

2006-07-26 Thread Josh Howlett
On 26 Jul 2006, at 12:11, Thai Duong wrote: As you advise, I turned tracing on and found that the SSL handshake was not completed, the client kept sending Client Hello packet but got no response from the server. But when looking at Ethereal's dump file, I saw that the server actually sent its

Re: How to execute TWO OR MORE Sql statement?

2006-07-26 Thread Alan Lumb
Create a stored procedure in the database that contains all of the SQL queries necessary. Then call that stored procedure via sql.conf. This works fine with Postgres. MySQL 5 supports stored proceedures and functions, however I know that mysql proceedures can cause problems as they can/will

RE: How to reply Session-Timeout without password

2006-07-26 Thread 王世彦
Hi, Now I am a little confused. For user 005001, I not only want to check the Session-Timeout for accounting, but also want to check its password for authorization. Before you tell me the auth by IP address method, my conf is like this: 005001 Auth-Type := Digest, Password == 005001 Now my

Re: How to reply Session-Timeout without password

2006-07-26 Thread Stefan Winter
Hi! Now I am a little confused. For user 005001, I not only want to check the Session-Timeout for accounting, but also want to check its password for authorization. Before you tell me the auth by IP address method, my conf is like this: 005001 Auth-Type := Digest, Password == 005001 Now

RE: PEAP MSCHAPv2 - Novell eDir

2006-07-26 Thread O'Connell Catriona
Hi Josh, LDAP section appended: ldap { server = ldapsvr.nottingham.ac.uk port = 636 identity = cn=RADIUSadmin,o=university password = x basedn = o=university filter =

authenticating based on Nas-Port-Id

2006-07-26 Thread Colm Ennis
hi, i been using freeradius fastuser based authentication for several thousand adsl customers for the last year or so now and it has proved extremely reliable. in order to simplify customer setup and minimise lost password support etc id like to start authenticating users based on

RE: How to execute TWO OR MORE Sql statement?

2006-07-26 Thread Jurgen van Vliet
Im using stored procs to do a series of queries even with IF THEN ELSE structires, with variables being the result of a query and being used in other queries. Works like a charm for me with mysql5 and freeradius 1.1.2 In the sql.conf I just use as query something like call

Re: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Alan DeKok
Josh Howlett [EMAIL PROTECTED] wrote: I'm sure I've seen at least a couple of other similar DHCP queries in the last couple of weeks. I wonder how difficult it would be to add a simple DHCP client to FreeRADIUS? Perl modules exist to do 99% of that work. OTOH, I think these queries

Re: Binding FreeRadius to the DHCP Server

2006-07-26 Thread Alan DeKok
Elie Hani [EMAIL PROTECTED] wrote: I'm not one of them, but I'm a ccie certificated and it was an insult. You asked the same question. Repeatedly. You ignored every answer, and asked the same question again. And again. Every time someone on this list (including me) tried to help you, you

RE: ATTRIBUTE has invalid number (larger than 255)

2006-07-26 Thread Steven Stanek
Hi, Thanks for the help with this one... Yes, we have a two byte VSA field for the equipment I am working on. -steven -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] org] On Behalf Of Alan DeKok Sent: Monday, July 24, 2006 3:09 PM To: FreeRadius users mailing list

freeradius stop automatically

2006-07-26 Thread bishal
After upgrading freeradius 1.0.5 to version 1.1.2 on Freebsd 6 my radius server stop automatically with the following error essage. Wed Jul 26 01:30:08 2006 : Error: Discarding duplicate request from client pppoe-bhw:61882 - ID: 137 due to unfinished request 61 Wed Jul 26 01:30:08 2006 :

Re: ATTRIBUTE has invalid number (larger than 255)

2006-07-26 Thread Alan DeKok
Steven Stanek [EMAIL PROTECTED] wrote: Thanks for the help with this one... Yes, we have a two byte VSA field for the equipment I am working on. That should be possible to manage, which an appropriate modification to the dictionary. Can you email the dictionary to the list? We'll get it

Re: issues with peap + tlv part 1

2006-07-26 Thread Alan DeKok
Damon McDougald [EMAIL PROTECTED] wrote: Here is my dillema: rlm_eap_peap: EAPTLS_OK rlm_eap_peap: Session established. Decoding tunneled attributes. rlm_eap_peap: Received EAP-TLV response. rlm_eap_peap: Tunneled data is valid. rlm_eap_peap: Had sent TLV failure. User was

Re: issues with peap + tlv part 1

2006-07-26 Thread Damon McDougald
Yes, I have read the earlier debug message stating failure in mschapv2. I have tried not using mschapv2 and various other configs, but with no luck. I see this is a common issue that many people have encoutered but with vague answers and references. Has anyone put together an faq that is more

Re: issues with peap + tlv part 1

2006-07-26 Thread Alan DeKok
Damon McDougald [EMAIL PROTECTED] wrote: Yes, I have read the earlier debug message stating failure in mschapv2. That is the problem, not the message saying the authentication was rejected earlier in the session. I have tried not using mschapv2 and various other configs, but with no

Re: issues with peap + tlv part 1

2006-07-26 Thread Damon McDougald
I have gotten this to work with ntradping and radtest...just not windows ce client. It is an issue with mschapv2 and ntlmv2. --- Alan DeKok [EMAIL PROTECTED] wrote: Damon McDougald [EMAIL PROTECTED] wrote: Yes, I have read the earlier debug message stating failure in mschapv2. That

Re: EAP doest work with Cisco Catalyst 2950?

2006-07-26 Thread Thai Duong
--- Josh Howlett [EMAIL PROTECTED] wrote: Is there a RADIUS or EAP timer set on the switch? If it's set too low, the switch might be ignoring the Access- Challenge from the server. best regards, josh. Yup there're some timers on the switch but as far as I know they have no effect on

Re: mysql libraries are there BUT not found

2006-07-26 Thread Roger Thomas
Quoting Nicolas Baradakis [EMAIL PROTECTED]: Roger Thomas wrote: In /usr/local/mysql/lib/mysql I have: -rw-r--r--1 root mysql 11866 May 15 10:56 libdbug.a -rw-r--r--1 root mysql 40304 May 15 10:56 libheap.a -rw-r--r--1 root mysql 13536 May

LDAP password format

2006-07-26 Thread Roger Thomas
The password for my users are kept in the SHA format in my LDAP. Does that means that I have to tell radius.conf to use password_header = {sha} ? Please advise. -- roger --- Sign Up for free Email at http://ureg.home.net.my/