Query to know radius disconnect request and Ack is supported in freeradius

2006-08-17 Thread Shankar Ganesh C
Hi All, Could some body help me to know whether Radius disconnect and Ackmessages are supported in free radius as defined in RFC 2822 ? The message ID are diconnet 40 adn Ack 41. Thanks and regards Shankar ganesh - List info/subscribe/unsubscribe? See

Query to know radius disconnect request and Ack is supported in freeradius

2006-08-17 Thread Shankar Ganesh C
Hi All, Could some body help me to know whether Radius disconnect and Ackmessages are supported in free radius as defined in RFC 2822 ? The message ID are diconnet 40 adn Ack 41. Thanks and regards Shankar ganesh - List info/subscribe/unsubscribe? See

Re: Change RAD_REPLY item in rlm_perl, not add a new pair

2006-08-17 Thread Boian Jordanov
On Wednesday 16 August 2006 18:09, Alex French wrote: Boina, That works fine for me (patching against a clean 1.1.2 tree) I've only tested == and := operators but they seem fine. Only one point to note; if you do not include an element in the hash with the same name as the attribute ( e.g.

Unknown user or bad password while using Free RADIUS PAM

2006-08-17 Thread Shteinberg-hirik, Jenny \(Jenny\)
Hi, Weuse Free Radius PAM_RADIUS_AUTH (version 1.3.16) intergrated into Linux from WindRiver distribution based on kernel 2.6.10 As Radius Server we use Internet Authentication Server from Win2000 Server. We can not receive authentication for user defined on the Radius Server. Here

Re: Oracle is not supported by radsqlrelay?

2006-08-17 Thread Nicolas Baradakis
Alexander Serkin wrote: Nicolas Baradakis wrote: Please create a patch with diff -u radsqlrelay.orig radsqlrelay and post it to the list. I'll add it in version 1.1.3. Here it is: --- radsqlrelay.orig2006-08-16 15:40:58.220277000 +0400 +++ radsqlrelay 2006-08-16

AcctSessionTime is inserting Null

2006-08-17 Thread raviprakash sunkara
Hi Users, So long back I'm mailing ... Now install Radius Server and client Freshly Actual My problem is THat ... In Accounting Part in . When I radius server recieve the Acc-status-type is Stop , AcctSessionTime is inserting NULL i.e 0 .. That is my problem Plz give hint to resolve

Help!

2006-08-17 Thread Shankar Ganesh C
Hi, Could some body help on my requirments.? Beloware my requirments. 1) When the radius server recives a accounitng start , accounting stop and Accounitng Intermediate update the free radius should pass on its attributes to another external funciton. 2) Based on the call back

Re: AcctSessionTime is inserting Null

2006-08-17 Thread Peter Nixon
On Thu 17 Aug 2006 16:00, raviprakash sunkara wrote: Hi Users, So long back I'm mailing ... Now install Radius Server and client Freshly Actual My problem is THat ... In Accounting Part in . When I radius server recieve the Acc-status-type is Stop , AcctSessionTime is inserting NULL

question about an output

2006-08-17 Thread Elie Hani
Hi; I have used this command to check the errors: Radiusd X A I had a list of outputs, but my question is the following: Do these outputs mean that the check up is passing on it, or theres an error on it? And Ive got this error: /etc/raddb/users[154]: Syntax error: Previous

Re: question about an output

2006-08-17 Thread Stefan Winter
/etc/raddb/users[154]: Syntax error: Previous line is missing a trailing comma for entry DEFAULT Basically, it is something in the config file, but is there a way to locate the error in this configuration file? How could this message be any more clear? What do you *think* you have to chack,

Re: AcctSessionTime is inserting Null

2006-08-17 Thread Peter Nixon
On Thu 17 Aug 2006 17:34, raviprakash sunkara wrote: Hi peter , Thanks for replying ... The NAS value is MY radius server ip... Really i don't Know that... What NAS value should take . You need to check the detail files (usually under /var/log/radius/radacct/x.x.x.x/) and see if there

Re: Query to know radius disconnect request and Ack is supported in freeradius

2006-08-17 Thread Alan DeKok
Shankar Ganesh C [EMAIL PROTECTED] wrote many times: Could some body help me to know whether Radius disconnect and Ack messages are supported in free radius as defined in RFC 2822 ? It's RFC 3576, not 2822. And FreeRADIUS doesn't support receiving them, but radclient will send them. And

Pretty easy question, I think? :D

2006-08-17 Thread Drew Weaver
I'm setting up a new AAA server here using freeradius. I am just attempting to get it to authenticate using /etc/passwd (unix style) and I am getting this error: Thu Aug 17 11:06:51 2006 : Debug: rad_check_password: Found Auth-Type System Thu Aug 17 11:06:51 2006 : Debug: auth: type System

Re: Unknown user or bad password while using Free RADIUS PAM

2006-08-17 Thread Alan DeKok
Shteinberg-hirik, Jenny \(Jenny\) [EMAIL PROTECTED] wrote: We use Free Radius PAM_RADIUS_AUTH (version 1.3.16) intergrated into Linux from WindRiver distribution based on kernel 2.6.10 As Radius Server we use Internet Authentication Server from Win2000 Server. Ugh. Both Radius clients (

Re: Help!

2006-08-17 Thread Alan DeKok
Shankar Ganesh C [EMAIL PROTECTED] wrote: 2) Based on the call back function or any other interface from external program the free radius should send a Accounting response message back based on the attributes value retrived from the other function. No attributes may be sent in an

Regarding using strcmp instead of memcmp

2006-08-17 Thread Ravi S M
Hi I am trying to run free radius code with purify , it is giving errors as UMR: Uninitialized memory read (13 times) in memcmp Reading 5 bytes from 0xffbdd108 on the stack (1 byte at 0xffbdd10c uninit). Address 0xffbdd108 is 4 bytes past start of local variable cs in function

Garbled class attribute?

2006-08-17 Thread Geoff Silver
I have a bunch of users which should have a class attribute returned upon successful authentication. Their entries look something like: bob NAS-IP-Address == 172.31.33.66, Hint==HasSlash Auth-Type:=Accept Class = OU=MY_CORP, Filter-Id = SPCCOLO_O, Split-Tunneling-Policy = 1,

Garbled class attribute?

2006-08-17 Thread Geoff Silver
I should note that when I set Class to be a string in the dictionary.rfc2865 file instead of a octets, I get: Class = 79wH1B2r7PSQjqBACDCXCIyPuDI= Which looks equally wrong to me. Original Message Subject: Garbled class attribute? Date: Thu, 17 Aug 2006 11:40:50 -0400 From:

Problem with character Ä in username/password

2006-08-17 Thread Velusamy, Vinodh
Hi, There seems to be a problem if the username/password contain the character Ä, when trying to authenticate via freeradius. rad_recv: Access-Request packet from host 127.0.0.1:33292, id=245, length=98 User-Name =

RE: question about an output

2006-08-17 Thread John Mylchreest
Agreed, it is clear and it does make sense, but did it warrant such a tactless reply? Anyways, I'm feeding the troll so I'll not be reading anymore of the thread. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Stefan Winter Sent: 17 August 2006 15:33

user specific settings in users file overwritten by DEFAULT settings?

2006-08-17 Thread Drew Weaver
I have a user specified in my users file like this: isdn Auth-Type = System Service-Type = Framed, Framed-Protocol = MPP, Framed-Routing = None, Ascend-Maximum-Time = 18000, Ascend-Idle-Limit = 900, Ascend-Assign-IP-Pool = 0, Ascend-Maximum-Channels = 2, Fall-Through = 1

Re: Problem with character Ä in username/passwor d

2006-08-17 Thread Alan DeKok
Velusamy, Vinodh [EMAIL PROTECTED] wrote: There seems to be a problem if the username/password contain the character Ä, when trying to authenticate via freeradius. No, go back and read the output again: rad_recv: Access-Request packet from host 127.0.0.1:33292, id=245, length=98

Re: Garbled class attribute?

2006-08-17 Thread Alan DeKok
Geoff Silver [EMAIL PROTECTED] wrote: I have a bunch of users which should have a class attribute returned upon successful authentication. Their entries look something like: bob NAS-IP-Address == 172.31.33.66, Hint==HasSlash Auth-Type:=Accept Class = OU=MY_CORP, Filter-Id

Re: user specific settings in users file overwritten by DEFAULT settings?

2006-08-17 Thread Alan DeKok
Drew Weaver [EMAIL PROTECTED] wrote: Can anyone tell me why the radius server is ignoring the isdn entry in the users file and instead returning the DEFAULT entry? It's not. The debug output you posted shows it IS matching the isdn entry, but that it is ALSO matching the later DEFAULT

Re: user specific settings in users file overwritten by DEFAULTsettings?

2006-08-17 Thread Stefan Winter
Hi, Can anyone tell me why the radius server is ignoring the isdn entry in the users file and instead returning the DEFAULT entry? All of your entries specify Fall-Through = 1 / Yes (which is the same, AFAIK). So, the entries of isdn get read, but then overwritten by the later DEFAULT

Re: Regarding using strcmp instead of memcmp

2006-08-17 Thread Alan DeKok
Ravi S M [EMAIL PROTECTED] wrote: I am trying to run free radius code with purify , it is giving errors as UMR: Uninitialized memory read (13 times) in memcmp=0D Reading 5 bytes from 0xffbdd108 on the stack (1 byte at 0xffbdd10c uninit). Address 0xffbdd108 is4 bytes past

Re: Pretty easy question, I think? :D

2006-08-17 Thread Alan DeKok
Drew Weaver [EMAIL PROTECTED] wrote: Thu Aug 17 11:06:51 2006 : Debug: rad_check_password: Found Auth-Type System Thu Aug 17 11:06:51 2006 : Debug: auth: type System Thu Aug 17 11:06:51 2006 : Debug: ERROR: Unknown value specified for Auth-Type. Cannot perform requested action. That

Re: Garbled class attribute?

2006-08-17 Thread Geoff Silver
Alan DeKok wrote: Geoff Silver [EMAIL PROTECTED] wrote: I have a bunch of users which should have a class attribute returned upon successful authentication. Their entries look something like: bob NAS-IP-Address == 172.31.33.66, Hint==HasSlash Auth-Type:=Accept Class =

Re: Garbled class attribute?

2006-08-17 Thread Geoff Silver
I always hate replying to my own problem, but I just figured this out. Turns out that we're proxying auth to a backend server, which was returning a garbled Class attribute, therefore *my* Class attribute wasn't being returned. I configured $confdir/attrs to filter it and it appears to work

Re: Garbled class attribute?

2006-08-17 Thread Geoff Silver
Stefan Winter wrote: It works for me, so my guess is that something else in your configuration is setting Class to that value. Okay, I'll bite - so what on earth might be causing that? I'm not doing any rewriting, and both the Filter-Id and the Split-Tunnel-List attributes come back as

Re: Garbled class attribute?

2006-08-17 Thread Alan DeKok
Geoff Silver [EMAIL PROTECTED] wrote: As a side note, I had to change the Class attribute in dictionary.rfc2865 to be a string, *not* octets. I changed: to make it work (and be readable), though I can't tell if that's just an oddity of the Cisco VPN 3000 and the way it was previously

Re: Garbled class attribute?

2006-08-17 Thread Geoff Silver
Ah ok. So it appears the network guys are doing something non-compliant with the RFCs around here. I hate that, but I'm not going to be able to change it either, so I'll just maintain a small patch for our environment. Thanks for clearing that up. Alan DeKok wrote: Geoff Silver [EMAIL

Re: rlm_proxy problems

2006-08-17 Thread Geoff Silver
Alan DeKok wrote: Geoff Silver [EMAIL PROTECTED] wrote: Red Hat Enterprise Linux 3.0. Also has the same build issues on my RedHat EL4.0 dev system. Weird. It works for me on FC4, and many other OSes. We were previously using FreeRADIUS 1.1.0, which built fine. IIRC, the problem

RE: Active Directory Users

2006-08-17 Thread Mohammad Abohelal
No ldap? Why?  The active directory services based LDAP.   Sorry I dont understand why... :-)   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Domingo Antonio Sent: Thursday, August 17, 2006 9:58 PM To: 'FreeRadius users mailing list' Subject: RES: Active

Re: Active Directory Users

2006-08-17 Thread Alan DeKok
Mohammad Abohelal [EMAIL PROTECTED] wrote: No ldap? Why? The active directory services based LDAP. Yes, for everything but passwords. Active directory does not supply passwords through LDAP. There is nothing you can do to mak eit supply passwords through LDAP. Use ntlm_auth. Alan

Re: More documentation on Auth-Type

2006-08-17 Thread Rohaizam Abu Bakar
Just managed to try ur 2nd suggestion... but giving below error in debug logs.. refer debug logs. ERROR: Unknown value specified for Auth-Type. Cannot perform requested action modules { ldap ldap1 { basedn = ou=RADIUS.. set_auth_type = yes } ldap ldapdialup1 { basedn

PAP/mysql/crypt stuff

2006-08-17 Thread Keith Woodworth
After working on this off and on for the last few days I believe I have gotten authentication working using a Crypt'd password stored in mysql but want to run this by to make sure I did it right. I setup a user in radcheck: tester | Crypt-Password | == | gmxwp4dfOcHAI In radgroupreply:

RE: Query to know radius disconnect request and Ack is supported infreeradius

2006-08-17 Thread Shankar Ganesh C
Hi Alan, Thanks for replying, sorry for the inconvenience caused. Regards Shankar ganesh -Original Message- From: [EMAIL PROTECTED] org [mailto:[EMAIL PROTECTED] eradius.org]On Behalf Of Alan DeKok Sent: Thursday, August 17, 2006 8:30 PM To: FreeRadius users mailing list Subject: Re:

Regarding using strcmp instead of memcmp

2006-08-17 Thread Ravi S M
Hi this is where the error is occurring in UMR ABR in the following files, While running with purify. Command-line: radiusd -X UMR: Uninitialized memory read (3 times) This is occurring while in: memcmp [rtlib.o] cf_expand_variables [conffile.c:369] p += strlen(p);

How to configure the Radius in SSH (22)

2006-08-17 Thread raviprakash sunkara
Hi Users, I Want to create the radius (AAA) for remote accessing By using the putty in SSHCan anyone Give the clues to me on That or any url or documentation .. plz for me in English... .. -- Thanks and Regards with cheersSunkara Ravi Prakash (LAMP