Re: Mysql and usage of radgroupcheck

2006-11-16 Thread Anne-Mie Vandermeeren
On Tue, 14 Nov 2006, Fabiano Martins wrote: Date: Tue, 14 Nov 2006 22:50:02 -0200 From: Fabiano Martins [EMAIL PROTECTED] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Subject: Re: Mysql and usage of radgroupcheck Anne, The only diference from your table radgroup

Re: LDAP and mySQL

2006-11-16 Thread Stefan Winter
Hello, The second and more important problem is this: I configured my freeradius server, I can authenticate with my users ldap... but I configured my mysql server too, but I can't to authenticate with the mysql users... the access is denied... even when the user and password is correct... ho

Re: AW: freeradius and ntlm_auth howto

2006-11-16 Thread Stieven . Struyf
I finally managed to filter out the last issues with my setup. When i have more time i will post a small howto that worked for me. Although people on the list told me that there are plenty guides already, i couldn't find one that worked. Thanks everyone for all hints that helped me. Stieven

caching mechanisms and clean disconnect

2006-11-16 Thread Josh Shamir
Hi, I've a problem regarding the clean disconnect of a client and some caching mechanisms. I briefly illustrate my problem : My system is composed by freeradius and chillispot with WPA enterprise (LDAP as backend). When i connect a client 1 to my system all works fine, except for the time taked

Re: rewriting usernames

2006-11-16 Thread Christopher Carver
Quoting Kevin Bonner [EMAIL PROTECTED]: On Monday 13 November 2006 22:24, Christopher Carver wrote: Hello, How do I rewrite the value of the User-Name attribute based on Called-Station-Id? I need to do a series of these logical decisions and replace the username with

solved: (was: Re: build rpm packages on centOS)

2006-11-16 Thread Michael Messner
hey freeradius users, Michael Messner sagte: ... the original spec file wont work on centOS ... it breaks with errors of overwriting a README file which was created allready: ... doc/supervise-radiusd.txt doc/tuning_guide doc/variables.txt LICENSE COPYRIGHT CREDITS README

Re: PEAPv2 Server

2006-11-16 Thread Phil Mayers
[EMAIL PROTECTED] wrote: Microsoft implements something better known as PEAP v0 see: draft-kamath-pppext-peapv0-00.txt, “Microsoft’s PEAP v0 (Implemented in Windows XP SP1) July 2002, http://www.watersprings. org/pub/id/draft-kamath-pppext-peapv0-00.txt As far as I know, no-one implements

Re: Prompting for credentials

2006-11-16 Thread Phil Mayers
sak wrote: Configuration files are updated accordingly. Now RADIUS is working fine but the problem is user is prompted for username and password for the first time only. When user tries to connect next time it does not prompt for the credentials but uses the same username and password. What I

windows 2003 AD authentication with freeradius (for 802.1X)

2006-11-16 Thread Stieven . Struyf
All, I've been struggling to get AD authentication working the way i want it. I wanted users to autom. login to the wireless network with their windows(ad) account without needing to enter their passwords. I created this procedure with bits and pieces i found on the internet, hints i got on

Re: rewriting usernames

2006-11-16 Thread Michael Mitchell
Hi Chris, Christopher Carver wrote: Thanks for the reply, Kevin. You got me on the right track, but I still don't quite have it right. It seems as though the users file can only manipulate Kevin's solution uses the hints file, not the users file. You'll need to enable the preprocess

Re: windows 2003 AD authentication with freeradius (for 802.1X)

2006-11-16 Thread Michael Messner
thanks for the information, I work on nearly the same and I've created a link collection of most of the infos I've researched: http://community.fh-salzburg.ac.at/forum/index.php?showtopic=27 also I've a complete documetation writen via a wiki but for now I can't open it for everybody ...

logging to normal radius.log and syslog

2006-11-16 Thread Michael Messner
hey @all, for testing we write the complete debugging messages to syslog into a special file but with this method the loggin to the normal radius.log file won't work anymore! We start radiusd with daemontools and with these parameters: loggeropt=logger -p local6.info -t radiusd -s ARGS=-Afxyz

ldap attributes and spaces

2006-11-16 Thread Stefan Winter
Hi, I'm trying to retrieve some replyItems from an AD backend. It works fine as expected with most attributes, but there are some string attributes which contain spaces like displayName = aaa Restena, Fondation with ldap.attrmap RESTENA-Full-Name displayName (RESTENA-Full-Name

Re: rewriting usernames

2006-11-16 Thread Kevin Bonner
On Thursday 16 November 2006 04:56, Christopher Carver wrote: Quoting Kevin Bonner [EMAIL PROTECTED]: Not a crazy question at all. We used a hints file entry like: ... It seems as though the users file can only manipulate reply A/V pairs. Correct. The hints file can manipulate the request

Tsunami MP.11 5054-R base station and Tsunami MP.11 5054-R

2006-11-16 Thread Cameron Cowie
Hi all Is there anyone out there that works or has worked with the Tsunami base station / subscriber unit combo. I can get the base station to authenticate against my free radius server and it works beautifully, but when I get the subscriber unit to try to authenticate through the b/s it

RE: Prompting for credentials

2006-11-16 Thread Garber, Neal
Is it possible that the information is being cached on the client system? So can anyone help me? Windows XP caches credentials for PEAP. If you want it to reprompt, you'll need to delete a registry key (HKCU\Software\Microsoft\Eapol\UserEapInfo). See http://support.microsoft.com/kb/823731 for

Re: caching mechanisms and clean disconnect

2006-11-16 Thread Alan DeKok
Josh Shamir [EMAIL PROTECTED] wrote: When i connect a client 1 to my system all works fine, except for the time taked by authentication process, i'm using WinXP SP2 build-in supplicant. (How I can speed up this procedure?Could you suggest me some opensource supplicant?) SecureW2 is one, but

Re: windows 2003 AD authentication with freeradius (for 802.1X)

2006-11-16 Thread Alan DeKok
[EMAIL PROTECTED] wrote: I created this procedure with bits and pieces i found on the internet, hints i got on this list and some things i found out myself. I hope this saves some time to others(as this was a popular question the list/google, but i didn't found the complete solution that

Re: logging to normal radius.log and syslog

2006-11-16 Thread Alan DeKok
Michael Messner [EMAIL PROTECTED] wrote: for testing we write the complete debugging messages to syslog into a special file but with this method the loggin to the normal radius.log file won't work anymore! Because it's in debugging mode. Output goes to STDOUT, and not to radius.log. any

Re: logging to normal radius.log and syslog

2006-11-16 Thread Thor Spruyt
tail -F radius.log | logger - Original Message - From: Michael Messner [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Sent: Thursday, November 16, 2006 3:10 PM Subject: logging to normal radius.log and syslog hey @all, for testing we write the complete debugging

Re: rewriting usernames

2006-11-16 Thread Christopher Carver
Quoting Michael Mitchell [EMAIL PROTECTED]: Hi Chris, Christopher Carver wrote: Thanks for the reply, Kevin. You got me on the right track, but I still don't quite have it right. It seems as though the users file can only manipulate Kevin's solution uses the hints file, not the

redundant block in CVS 2006-11-16

2006-11-16 Thread [EMAIL PROTECTED]
/accounting_full/192.168.0.1/20061116' rlm_detail: /acct/freeradius/accounting_full/%{Client-IP-Address}/%Y%m%d expands to /acct/freeradius/accounting_full/192.168.0.1/20061116 radius_xlat: 'Thu Nov 16 19:15:44 2006' modcall[accounting]: module detail returns ok for request 14 modcall: entering group

Re: logging to normal radius.log and syslog

2006-11-16 Thread Michael Messner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Alan DeKok schrieb: Michael Messner [EMAIL PROTECTED] wrote: for testing we write the complete debugging messages to syslog into a special file but with this method the loggin to the normal radius.log file won't work anymore! Because it's in

Re: logging to normal radius.log and syslog

2006-11-16 Thread Michael Messner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thor Spruyt schrieb: tail -F radius.log | logger radius.log is empty! ca mIke - Original Message - From: Michael Messner [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Sent: Thursday, November 16, 2006 3:10 PM

Re: logging to normal radius.log and syslog

2006-11-16 Thread Alan DeKok
Michael Messner [EMAIL PROTECTED] wrote: Because it's in debugging mode. Output goes to STDOUT, and not to radius.log. sure, we need the possibility to analyze the files Then why are you running the server in debugging mode, with output goind to STDOUT? I think this would be very

Re: ldap attributes and spaces

2006-11-16 Thread Alan DeKok
Stefan Winter [EMAIL PROTECTED] wrote: I'm trying to retrieve some replyItems from an AD backend. It works fine as expected with most attributes, but there are some string attributes which contain spaces Either put quotes around the string, or hack rlm_ldap to pull the *entire* string from

Re: redundant block in CVS 2006-11-16

2006-11-16 Thread [EMAIL PROTECTED]
thanks, Razvan Radu Alan DeKok wrote: [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: 2006-11-16 and my accounting redundant group is processing the second module even if the first one is returning ok. why is detail_fail processed if sql returns ok ? It's a bug. I just committed a

radcheck entry issue

2006-11-16 Thread Sri
Hi, I need to add two users with same name, from different NASes/stations. I added the two groups for them in usergroup and corresponding entries in radcheck and radreply tables. So they look like this: usergroup: --- 1 Ronrobertdialup 2Ronrobert

RE: Prompting for credentials

2006-11-16 Thread sak
Thanks for ur help. I tried after deleting registry key and it works. Thanks again. Garber, Neal wrote: Is it possible that the information is being cached on the client system? So can anyone help me? Windows XP caches credentials for PEAP. If you want it to reprompt, you'll need to

Re: Prompting for credentials

2006-11-16 Thread sak
Thank you. Phil Mayers wrote: sak wrote: Configuration files are updated accordingly. Now RADIUS is working fine but the problem is user is prompted for username and password for the first time only. When user tries to connect next time it does not prompt for the credentials but uses