Re: Compiling 1.1.3

2006-11-23 Thread Matthew Green
Hello, I delete the source directory, done a 'make clean', re-ran the configure script and done a make again but I still get the same error. So which directory are you referring to? Thanks Mat On 22/11/06 17:02, Alan DeKok [EMAIL PROTECTED] wrote: Matthew Green wrote: Hello, I am trying

FreeRadius working as proxy Radius for RSA ACE Server

2006-11-23 Thread Luis
Hi there, Is there anyone with experience with FreeRadius working as proxy for the RSA ACE Server? Regards. -- Luis [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Script to auth. users and control the remote phone number used

2006-11-23 Thread Luis
Hi again, Can anyone tell me if it is possible to control the authentication process using the remote telephone number used by the user? Thanks again :D -- Luis [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Script to auth. users and control the remote phone number used

2006-11-23 Thread Cihan DEMİR
Hi, Yes it is possible. Try to add Calling-Station-Id parameter. Cihan. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Luis Sent: Thursday, November 23, 2006 1:32 PM To: freeradius-users@lists.freeradius.org Subject: Script to auth. users and control

Re: Script to auth. users and control the remote phone number used

2006-11-23 Thread James Wakefield
Luis wrote: Hi again, Can anyone tell me if it is possible to control the authentication process using the remote telephone number used by the user? Thanks again :D Hi Luis, You can conditionally authorize users based on phone numbers, yes, if the NAS provides you that information, which

Radius attributes and APs

2006-11-23 Thread Manuel Sánchez Cuenca
Can anybody tell me any Access Point which understand and enforce some radius attributes returned by freeradius, such as Session-Timeout. Thanks in advance. -- - Manuel Sanchez Cuenca Departamento de Ingenieria de la Informacion y las Comunicaciones Facultad de

Re: Compiling 1.1.3

2006-11-23 Thread Matthew Green
Found the directory you were talking about. Thanks for the help. M On 23/11/06 09:43, Matthew Green [EMAIL PROTECTED] wrote: Hello, I delete the source directory, done a 'make clean', re-ran the configure script and done a make again but I still get the same error. So which directory are

Using different authentication methods according to realm

2006-11-23 Thread Romain Guilleret
Hi, We are are currently moving our RADIUS server from Radiator to Freeradius. With Radiator, you can select the authentication method used, according to realm. In our case, each realm is authenticated using MySQL, but with a different database according to the realm. HOw can I do the same

Re: Script to auth. users and control the remote phone number used

2006-11-23 Thread Luis
Hi, the problem is that I want to control the access not only based in the username and the password but also using the remote telephone number used by the user to do the call. So, if the phone number is from Spain it doesn´t matter if the username and the password are correct, radius should

Ippool howto questions..

2006-11-23 Thread Collen Blijenberg
Hello, just some basic questions about the Ippool. if i'm right, the ippool option, is for handing out IP's to clients ?! (right ??) you could call it DHCP (right??) how can i setup the dns gateway and proxy options in a ippool... Cheers.. Collen.. - List info/subscribe/unsubscribe?

Re: Compiling 1.1.3

2006-11-23 Thread Matthew Green
Hello, I have been able to compile install radius but when I try a run it I get the following error: Thu Nov 23 16:18:57 2006 : Error: radiusd.conf[1585] Failed to link to module 'rlm_exec': dlopen(/usr/local/lib/rlm_exec-1.1.3.so, 9): Symbol not found: _debug_flag Referenced from:

Re: FreeRadius working as proxy Radius for RSA ACE Server

2006-11-23 Thread Alan DeKok
Luis wrote: Hi there, Is there anyone with experience with FreeRadius working as proxy for the RSA ACE Server? Yes. RSA ACE is just a re-branded Funk server. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog -

Re: Radius attributes and APs

2006-11-23 Thread Alan DeKok
Manuel Sánchez Cuenca wrote: Can anybody tell me any Access Point which understand and enforce some radius attributes returned by freeradius, such as Session-Timeout. Access points implement RADIUS, so they understand RADIUS attributes. Do you have a more specific question? Alan DeKok.

Re: Compiling 1.1.3

2006-11-23 Thread Matthew Green
Hello, Found the answer at: http://lists.cistron.nl/pipermail/freeradius-devel/2006-August/010208.html Mat On 23/11/06 16:22, Matthew Green [EMAIL PROTECTED] wrote: Hello, I have been able to compile install radius but when I try a run it I get the following error: Thu Nov 23

Re: Using different authentication methods according to realm

2006-11-23 Thread Alan DeKok
Romain Guilleret wrote: We are are currently moving our RADIUS server from Radiator to Freeradius. With Radiator, you can select the authentication method used, according to realm. In our case, each realm is authenticated using MySQL, but with a different database according to the realm.

Re: Ippool howto questions..

2006-11-23 Thread Alan DeKok
Collen Blijenberg wrote: if i'm right, the ippool option, is for handing out IP's to clients ?! (right ??) you could call it DHCP (right??) No. how can i setup the dns gateway and proxy options in a ippool... There is no standard RADIUS attribute to set DNS servers. And I have no idea

Re: Compiling 1.1.3

2006-11-23 Thread Alan DeKok
Matthew Green wrote: Hello, I have been able to compile install radius but when I try a run it I get the following error: Thu Nov 23 16:18:57 2006 : Error: radiusd.conf[1585] Failed to link to module 'rlm_exec': dlopen(/usr/local/lib/rlm_exec-1.1.3.so, 9): Symbol not found: _debug_flag

Re: trivial problem?

2006-11-23 Thread Alan DeKok
Yans van Horn wrote: ... Thats for sure. According to docs: There's no need to quote the documentation here. This should prevent _any_ user from authenticating, but ajax, revoked certs allow access. Maybe. I don't use SQL, so I can't really say. That's at least strange or above config

Re: Radius attributes and APs

2006-11-23 Thread Manuel Sanchez Cuenca
Alan DeKok escribió: Manuel Sánchez Cuenca wrote: Can anybody tell me any Access Point which understand and enforce some radius attributes returned by freeradius, such as Session-Timeout. Access points implement RADIUS, so they understand RADIUS attributes. Do you have a more

Re: Radius attributes and APs

2006-11-23 Thread Alan DeKok
Manuel Sanchez Cuenca wrote: Alan DeKok escribió: Do you have a more specific question? But not all APs enforce the Radius attributes. For example the Linksys wrt54g doesn't takes into account the session timeout attribute. So, can you tell me any AP which enforces this attribute, and

Re: trivial problem?

2006-11-23 Thread Yans van Horn
Alan DeKok [EMAIL PROTECTED] wrote: Uh... do we have a business relationship I'm unaware of? If you want a consultant to configure your system for you, please see the support link on freeradius.org. You are right, we do not have a bussiness agreement. And I was not asking for configuring

Re: trivial problem?

2006-11-23 Thread Alan DeKok
Yans van Horn wrote: What is most dissapointing is Your cynism and rudeness, Ah, yes. That's the standard complaint when I point out you have the option to learn for yourself, or to pay someone to do the work for you. Alan DeKok. -- http://deployingradius.com - The web site of the

Re: trivial problem?

2006-11-23 Thread Yans van Horn
Alan DeKok [EMAIL PROTECTED] wrote: Yans van Horn wrote: What is most dissapointing is Your cynism and rudeness, Ah, yes. That's the standard complaint when I point out you have the option to learn for yourself, or to pay someone to do the work for you. I wonder, if in Canada, ie. when

Re: trivial problem?

2006-11-23 Thread Alan DeKok
Yans van Horn wrote: I'm MTB passionate, and i'm happy to help people with technical problems or just needing advice. Remind me which open source project you've been supporting for free for nearly the past decade? Alan DeKok. -- http://deployingradius.com - The web site of the book

Re: very long regular expression...

2006-11-23 Thread Phil Mayers
Norbert Grochal wrote: I want to disallow login to access points for every hosts that are not in my network. So at the end of /usr/local/etc/raddb/users file I put regular expression that checks if Calling-Station-Id IS NOT in list of my hosts... DEFAULT Auth-Type := REJECT,

Re: trivial problem?

2006-11-23 Thread Yans van Horn
Alan DeKok wrote: Yans van Horn wrote: I'm MTB passionate, and i'm happy to help people with technical problems or just needing advice. Remind me which open source project you've been supporting for free for nearly the past decade? You have to broaden Your mind, not everyone have to be

Re: EAP abort in the middle of conversation [SOLVED+suggestion]

2006-11-23 Thread Stefan Winter
But I would like to suggest to add at least EAP-Message and State in the default attrs file that's shipped. This was really an ugly caveat. Fixed, thanks. Hm, while you're at it: I also added MS-MPPE-Recv-Key =* ANY, MS-MPPE-Send-Key =* ANY, MS-CHAP-MPPE-Keys =*