Re: free radius 1.1.6 -eap-tls authentication

2007-05-14 Thread Alan DeKok
[EMAIL PROTECTED] wrote: Dear all I am using the same AP,same widows client and same root certificate for testing navis as well as free raduis .Root certificate is also installed. Is ther any clue in the debug message? No. If there was, you would have been told. All I know

PAM modules

2007-05-14 Thread Ouahiba MACHANI
Hi, Did there anyone who developped a PAM module that operate with radius server? my question is : 1- How does that work ?does it only allow configuration of predefined methodes or could we also programme new PAM module for new/customized authentication methode such as OTP (One Time Password)

How to add a prefix to User-Name before proxying to another RADIUS server?

2007-05-14 Thread Clark J. Wang
I have two RADIUS servers rad_1 and rad_2. For some users rad_1 needs to forward the requests to rad_2 and I want to add some prefix like `QA/' to User-Name before forwarding to rad_2. Does FreeRADIUS support that? And how to configure? Thanks. - List info/subscribe/unsubscribe? See

Re: PAM modules

2007-05-14 Thread Alan DeKok
Ouahiba MACHANI wrote: Did there anyone who developped a PAM module that operate with radius server? Have you looked at the freeradius.org web site? 1- How does that work ?does it only allow configuration of predefined methodes or could we also programme new PAM module for new/customized

PEAP authentication + LDAP attribute recovery

2007-05-14 Thread Manuel Sánchez Cuenca
Hi all, It is possible to configure freeradius to authenticate users using PEAP and then, for authenticated users, return some RADIUS attributes recovered from a LDAP server, such as Session-Timeout or Framed-IP-Address?. And in that case, how can I configure it? Thanks in adavance --

Re: PEAP authentication + LDAP attribute recovery

2007-05-14 Thread Kostas Kalevras
O/H Manuel Sánchez Cuenca έγραψε: Hi all, It is possible to configure freeradius to authenticate users using PEAP and then, for authenticated users, return some RADIUS attributes recovered from a LDAP server, such as Session-Timeout or Framed-IP-Address?. And in that case, how can I

Re: Freeradius-Users Digest, Vol 25, Issue 56

2007-05-14 Thread [EMAIL PROTECTED]
Ich bin am 14. Mai nicht im Haus und kann Ihre Nachricht erst am Dienstag den 15. Mai bearbeiten. In dringenden Fällen wenden Sie sich bitte an Herrn René Böhm (E-Mail: [EMAIL PROTECTED]). Mit freundlichen Grüßen Tobias Drollinger - List info/subscribe/unsubscribe? See

HUP stops radiusd

2007-05-14 Thread John Horne
Hello, This is a 'me too' message I'm afraid. From the list archives I saw: == Date: Mon, 02 Apr 2007 20:20:47 +0200 From: Alan DeKok aland at deployingradius.com Subject: Re: HUP in freeradius-1.1.5 + CVS results in process death. To:

Re: LDAP/RACF authentication error

2007-05-14 Thread Marc Giuliani
Can anyone help me on this? Hello, I am try to set up authentication for Oracle 10g (on Solaris) -- Radius (on Solaris)-- LDAP (on Z/os) -- Racf (on z/os)... i was able to get past my last error however now I am getting a no authentication method found type of error. Can anyone assist me?

Re: HUP stops radiusd

2007-05-14 Thread John Horne
On Mon, 2007-05-14 at 15:22 +0200, inverse wrote: In our case, using freeradius 1.1.6, if I HUP the radiusd process it crashes/stops. Running 'radiusd -X', the tail part shows: Mon May 14 13:38:54 2007 : Error: rlm_eap_tls: Error reading certificate file on HUP the radiusd process

Re: LDAP/RACF authentication error

2007-05-14 Thread Alan DeKok
Marc Giuliani wrote: Can anyone help me on this? Your first post had the server doing authentication against /etc/passwd, and the test user wasn't listed there. I have checked that the secret password matches on the LDAP server, radius server and Oracle... No. There is a shared secret

Re: MySQL Authentication

2007-05-14 Thread Joseph Sullivan
On 5/11/07 11:11 PM, Alan DeKok [EMAIL PROTECTED] wrote: Did you build the server on that machine, or did you build it on another machine and move the binaries over? I Built the server on this machine. It's a MAC specific problem. Other people running MACs don't see it, so maybe you

External script problem

2007-05-14 Thread Sándor Szabó
Hi! I have the following problem. I use FreeRadius v1.1.6 on an Ubuntu Edgy Linux I'd like to use authentication and accounting with an external PHP script. I think the radius server is configured well. The radius server send the request to the script, I can read it through the $_ENV

Re: MySQL Authentication

2007-05-14 Thread Alan DeKok
Joseph Sullivan wrote: I Built the server on this machine. Well, the error message seems to indicate that the module that was built doesn't match the machine you're running it on. I don't know how to fix that, sorry. Alan DeKok. -- http://deployingradius.com - The web site of the

Re: External script problem

2007-05-14 Thread Alan DeKok
Sándor Szabó wrote: I'd like to use authentication and accounting with an external PHP script. I think the radius server is configured well. The radius server send the request to the script, I can read it through the $_ENV variable, but there is the problem. In the request I have more

freeradius+mysql

2007-05-14 Thread Hermidio A. Rodrguez Chavez
Hellow friends I'm new user in freeradius, and I've installed in my server freeradius with mysql support,but i like to add ras user or test the server with someone user inside the Mysql DB , because in the docs i not see any info about it. i add the mysql server conf to the sql.conf file,

Cisco Access Points

2007-05-14 Thread Christian Ejlertsen
Hello to all I'm very new at this whole radius deal so I hope I can find a kind soul that could help me with this setup. I'm sorry if this is described somewhere I've been looking around and I don't seem to find this. For now i'm trying to get a very simple setup to work I have a Cisco

FreeRADIUS authfile equivalent

2007-05-14 Thread Steve Forman
Greetings, I'm attempting to migrate a RADIUS service from Interlink RADIUS to FreeRADIUS and am running into a bit of a problem I was hoping you could help out with. Basically, I have several different domains which would all be separated by an @ sign plus the name of the domain. What

RE: Cisco Access Points

2007-05-14 Thread Christian Ejlertsen
This is what I get. triagia ~ # radiusd -A -X Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /etc/raddb/proxy.conf Config: including file: /etc/raddb/clients.conf Config: including file: /etc/raddb/snmp.conf Config: including file:

MAC Authentication

2007-05-14 Thread Kevin J
Does anybody know if FreeRadius supports the MAC Authentication? If so, how? Thanks in advance, Kevin - Building a website is a piece of cake. Yahoo! Small Business gives you all the tools to get online.- List info/subscribe/unsubscribe? See

Re: MAC Authentication

2007-05-14 Thread KES
There was been a patch to mpd. It sets Caller-Id parametr. where Caller-Id is MAC address of caller station but this is NULL if caller is in other LAN Does anybody know if FreeRadius supports the MAC Authentication? If so, how? Thanks in advance, Kevin -

Re: MAC Authentication

2007-05-14 Thread Claudiu Filip
Kevin J Does anybody know if FreeRadius supports the MAC Authentication? Kevin J If so, how? Freeradius supports ANY kind of authentication, just be sure you can get the required information from the client. Run radiusd -sfX and if your NAS sends the MAC address in the request, you can use that

Freeside Modifications for FreeRADIUS

2007-05-14 Thread Matthew Neumark
Hello, I was wondering if anyone has any modifications that they are willing to share that they have done for freeradius. Such as added attributes and such when provisioning radius accounts. A good example is like Filter-ID for freeradius. I would like to be able to assign users to a specific

Re: MAC Authentication

2007-05-14 Thread Michael Schwartzkopff
Kevin J schrieb: Does anybody know if FreeRadius supports the MAC Authentication? If so, how? Thanks in advance, Kevin - Building a website is a piece of cake. Yahoo! Small Business gives you all the tools to get online.

Re: freeradius+mysql

2007-05-14 Thread tnt
Users file: user check1, check2 reply1, reply2 To use sql put check items in radcheck and reply items in radreply. Of course, configure sql.conf and uncomment sql in radiusd.conf. Ivan Kalik Kalik Informatika ISP Dana 14/5/2007, Hermidio A. Rodrguez Chavez [EMAIL

Inserting Authentication Packet Attribute at Post-Auth Packet

2007-05-14 Thread Erico Augusto
Hi, is it possible to insert an authentication attribute(from auth packet) to post-auth packet? - I'd like to insert the Authentication Packet : Calling-Station-Id:User-MAC at post-auth packet ... Thanks, Erico. __ Fale com seus amigos de

RE: freeradius+mysql

2007-05-14 Thread Hermidio A. Rodrguez Chavez
Friend, thanks for your reply but where I must add this line? Thanks in advance Hermidio I've configure sql in my radiusd.conf I try to add one users and try too to test with radtest, but not right for me!!! How I must add users ? Please help -Original Message- From: [EMAIL

Re: Freeside Modifications for FreeRADIUS

2007-05-14 Thread Alan DeKok
Matthew Neumark wrote: I was wondering if anyone has any modifications that they are willing to share that they have done for freeradius. Such as added attributes and such when provisioning radius accounts. A good example is like Filter-ID for freeradius. Filter-Id depends more on the NAS

Re: FreeRADIUS authfile equivalent

2007-05-14 Thread Alan DeKok
Steve Forman wrote: I'm attempting to migrate a RADIUS service from Interlink RADIUS to FreeRADIUS Good choice. Interlink went bankrupt a few years ago. The current version of the company is selling the old product, and not doing much else. and am running into a bit of a problem I

Re: HUP stops radiusd

2007-05-14 Thread Alan DeKok
John Horne wrote: ... In our case, using freeradius 1.1.6, if I HUP the radiusd process it crashes/stops. Running 'radiusd -X', the tail part shows: ... Mon May 14 13:38:54 2007 : Error: radiusd.conf[230] Auth-Type PAP already configured - skipping Mon May 14 13:38:54 2007 : Error:

Re: FR with MySQL - Stored Procedures

2007-05-14 Thread Alan DeKok
Thomas Martens wrote: I added your hack to my version too. I also don't get any errors till now. It seems to work with SP, and also normal SQL-querys. Sounds good to me. Here is the diff...so please, a FR developer take a look at it;) Nicolas is looking into it. It should be in 1.1.7

RE: freeradius+mysql

2007-05-14 Thread tnt
Post the output from radiusd -X (open 2 ssh windows - 1 for radtest and one for debug) so we can see what's going on. Also post your entries in radcheck and radreply. Ivan Kalik Kalik Informatika ISP Dana 14/5/2007, Hermidio A. Rodrguez Chavez [EMAIL PROTECTED] piše: Friend, thanks for your

RE: freeradius+mysql

2007-05-14 Thread Hermidio A. Rodrguez Chavez
Where's this entries entries in radcheck and radreply OK, here's the way as I'm add the user (I don't know if this way is Ok) mysql INSERT INTO radcheck VALUES (1,'jpeterson','Password','==','loco'); mysql INSERT INTO radreply VALUES (1,'jpeterson','Trapeze-VLAN-Name',':=','corp'); mysql INSERT

no session showed by radwho, but user still could not login

2007-05-14 Thread Trio Yulistianto
Hi all I'm newbie in freeradius, i've already installed freeradius-1.1.6, Mysql and MikroTik NAS. I'm configuring my radius 1 session for every 1 user : ++---+---+-+-+ | id | UserName | Attribute | op | Value |

RE: freeradius+mysql

2007-05-14 Thread tnt
If this is a new version of Freeradius (1.1.6) you should use Cleartext-Password and op := in radcheck. You are picking up Auth-Type System, most likely from users file - find entry: DEFAULT Auth-Type:= System and comment it out. I think that's stopping it now. Ivan Kalik Kalik Informatika ISP

RE: FR with MySQL - Stored Procedures

2007-05-14 Thread Gunther
That is great news! Alan DeKok wrote: Thomas Martens wrote: I added your hack to my version too. I also don't get any errors till now. It seems to work with SP, and also normal SQL-querys. Sounds good to me. Here is the diff...so please, a FR developer take a look at it;) Nicolas is

differen user for different hotspot

2007-05-14 Thread ArioS
Hi, Sorry for this noob question, i have 2 Hotspot area (mean have 2 hotspot gateway) on Area A and B and i have 1 mysql as databases.. is it possible to separate user for Area A dan B in 1 databases ? so if i created user for Area A then they couldn`t logon on Area B.. something like that..