Re: intermediate CA authentication failing

2007-09-13 Thread mallika
Thank you very much for your reply.Which freeradius server version will support this facility.Because we are implenting it in our product.We are using CENT OS -kernel 2.4.20 .Is there any patches are available to upgrade freeradius.please help me. Alan DeKok-4 wrote: mallika wrote:

wholesale issue

2007-09-13 Thread Ashraf Al-Basti
Dear All, i want to setup a freeradius as a proxy radius for a wholesale, and want to limit the access by using the calling-station-id; so [EMAIL PROTECTED] can connect only from any calling-station-id that belong to isp1, (ex, 555111, 333222) and [EMAIL PROTECTED] can connect only from any

Re: Reply VSA Attributes in a list

2007-09-13 Thread Faqeer ALI
I hope you have understand my problem right, but i will try to re explain it. i want to add the vp list in a VSA like following. (the way that NTRadping utility sends the vps) VSA -vp -vp -vp This problem is my bottle line for me and i have to do it, because the client's application

Re: list problem?

2007-09-13 Thread Alan DeKok
Norbert Wegener wrote: Is there a problem with the list/mailserver? The archives show newer threads, where the last message I received from the list has been from September, 10. It arrived this mornig. The last day or two, messages appear to be somewhat slow. Alan DeKok. - List

Re: intermediate CA authentication failing

2007-09-13 Thread Alan DeKok
mallika wrote: Thank you very much for your reply.Which freeradius server version will support this facility. What part of my message was unclear? The most recent one. Read the web page. It's really not that hard. Because we are implenting it in our product. Could you explain why you

Re: Reply VSA Attributes in a list

2007-09-13 Thread Alan DeKok
Faqeer ALI wrote: i want to add the vp list in a VSA like following. (the way that NTRadping utility sends the vps) VSA -vp -vp -vp If you want them in that format, then add them in that format. The server doesn't re-order VSAs. And you *are* aware that the VALUE_PAIR

RE : LOGs of eap-tls authentication

2007-09-13 Thread HBA BOX
hello, To restart the radius I knew only one command which is service radiusd restart;all what you have to do when you are in debuce mode is stoping it by using service radiusd stop, then you can restart it . I hope that this can help you. regards habiba [EMAIL PROTECTED] a écrit

Terminate TLS and proxy PEAP

2007-09-13 Thread fuki
Hi At the moment I use FreeRADIUS to proxy eap peap mschapv2 request to a RADIUS server for authentication. The connecting machine submits in addition to the authentication information, some information about it's health state encrypted in the PEAP packets. Is there a possibility to decrypt the

RE: sometimes double records in radacct

2007-09-13 Thread Parham Beheshti
I’ve seen this happening too, We have some nases that are not on local network and they are sending packets on sometimes unstable networks(VPN,Internet)... I think what happens is that since the nas doesn't get the reply in the given time, it will resend the last packet... Sometimes interim

Re: Terminate TLS and proxy PEAP

2007-09-13 Thread Phil Mayers
On Thu, 2007-09-13 at 01:25 -0700, fuki wrote: Hi At the moment I use FreeRADIUS to proxy eap peap mschapv2 request to a RADIUS server for authentication. The connecting machine submits in addition to the authentication information, some information about it's health state encrypted in the

Re: Terminate TLS and proxy PEAP

2007-09-13 Thread Alan DeKok
Phil Mayers wrote: In particular if you are talking about the Vista built-in health check packets, that uses PEAPv2 which FreeRadius doesn't support, and you won't be able to terminate. I'm trying to get PEAPv2 patches from someone who claims they had it working a few years ago. Alan

Re: wholesale issue

2007-09-13 Thread tnt
You can use huntgroups: isp1 Realm == isp1realm Calling-Statin-Id = numbe1, Calling Station-Id = number2 Ivan Kalik Kalik Informatika ISP Dana 13/9/2007, Ashraf Al-Basti [EMAIL PROTECTED] piše: Dear All, i want to setup a freeradius as a proxy radius for a wholesale, and

RE : LOGs of eap-tls authentication

2007-09-13 Thread anoop_c
adresse mail ! Copiez vos mails vers Yahoo! Mail -- next part -- An HTML attachment was scrubbed... URL: https://lists.freeradius.org/pipermail/freeradius-users/attachments/20070913/866809ee/attachment-0001.html -- Message: 7 Date

Re: Terminate TLS and proxy PEAP

2007-09-13 Thread Phil Mayers
On Thu, 2007-09-13 at 11:01 +0200, Alan DeKok wrote: Phil Mayers wrote: In particular if you are talking about the Vista built-in health check packets, that uses PEAPv2 which FreeRadius doesn't support, and you won't be able to terminate. I'm trying to get PEAPv2 patches from someone

Re: RE : LOGs of eap-tls authentication

2007-09-13 Thread Phil Mayers
On Thu, 2007-09-13 at 14:40 +0500, [EMAIL PROTECTED] wrote: hi I am not able to start server by service radiusd restart command/. I used to start by simply typing radiusd command Pls anyone no the command to stop the server If you are on Unix, radiusd is just an ordinary process, which

Re: Terminate TLS and proxy PEAP

2007-09-13 Thread fuki
Phil Mayers wrote: On Thu, 2007-09-13 at 01:25 -0700, fuki wrote: You can certainly terminate the PEAP and still proxy the inner EAP-MSCHAP to another radius server; however as far as I am aware, FreeRadius doesn't yet have support for the various health state attributes, or for that

Re: Terminate TLS and proxy PEAP

2007-09-13 Thread Phil Mayers
On Thu, 2007-09-13 at 02:56 -0700, fuki wrote: Phil Mayers wrote: On Thu, 2007-09-13 at 01:25 -0700, fuki wrote: You can certainly terminate the PEAP and still proxy the inner EAP-MSCHAP to another radius server; however as far as I am aware, FreeRadius doesn't yet have support

Re: Terminate TLS and proxy PEAP

2007-09-13 Thread fuki
Phil Mayers wrote: On Thu, 2007-09-13 at 02:56 -0700, fuki wrote: Phil Mayers wrote: On Thu, 2007-09-13 at 01:25 -0700, fuki wrote: You can certainly terminate the PEAP and still proxy the inner EAP-MSCHAP to another radius server; however as far as I am aware, FreeRadius

RADIUS-LDAPv3.schema attribute description(s)

2007-09-13 Thread Turbo Fredriksson
Is there any documentation of the attributes in the LDAP schema? I'm trying to write a GUI manager for RADIUS (actually a 'plugin' to my http://phpQLAdmin.com) but I don't know how to write the lead text to the form... I took a look at the schema in 1.1.7, but that don't have any comments or

Re: intermediate CA authentication failing

2007-09-13 Thread inverse
On 9/13/07, mallika [EMAIL PROTECTED] wrote: Thank you very much for your reply.Which freeradius server version will support this facility.Because we are implenting it in our product.We are using CENT OS -kernel 2.4.20 .Is there any patches are available to upgrade freeradius.please help

Error while building

2007-09-13 Thread Sujatha Pelluru
Hi, I am getting the following error when i am tring to build the rpm files for the freeradius-1.1.7 Error is as below: error: Installed (but unpackaged) file(s) found: /etc/raddb/postgresqlippool.conf RPM build errors: Installed (but unpackaged) file(s) found:

IP Reverse DNS Resolution

2007-09-13 Thread Bruce Marriner
I currently have a IPSEC/L2TP setup that uses FreeRadis (for Active Directory auth). Radius is handing out the IP addresses to the clients. Is there a way to have it update my DNS server so it can create reverse-dns entries for them? - List info/subscribe/unsubscribe? See

RE : IP Reverse DNS Resolution

2007-09-13 Thread Thibault Le Meur
Hi, I currently have a IPSEC/L2TP setup that uses FreeRadis (for Active Directory auth). Radius is handing out the IP addresses to the clients. Is there a way to have it update my DNS server so it can create reverse-dns entries for them? Yes it is. In acct_users make a rule that run

Possible bug in !* operator handling?

2007-09-13 Thread Marcel De Boer
Hi! Today I noticed some strange problems on a number of RADIUS users in a test setup: I have a number of users in MySQL that contain a large number of attributes that should not occur in the Access-Request (i.e. attributes with the !* operator). When I tried to authenticate these users, I

Re: Possible bug in !* operator handling?

2007-09-13 Thread Marcel De Boer
Hi! Today I noticed some strange problems on a number of RADIUS users in a test setup: I have a number of users in MySQL that contain a large number of attributes that should not occur in the Access-Request (i.e. attributes with the !* operator). When I tried to authenticate these users, I

Re: FreeRADIUS 2.0.0-pre2 has been released

2007-09-13 Thread Jakob Hirsch
Quoting Alan T DeKok: Hi, After much waiting, 2.0.0-pre2 has been released. It contains MAJOR Wow, looks very nice! The unlang will probably will allow us to throw away some of our own modules. As I understand the virtual servers, it is possible to have all vservers listen to the same

OpenLDAP + FreeRADIUS Complete Solution

2007-09-13 Thread Mitch McCracken
When organizations grow, there becomes more and more systems that need to be maintained, and each may have different configurations and users which have access to them. Individually editing local config files gets old pretty fast for hundred of devices, and developing a unified and central

Re: OpenLDAP + FreeRADIUS Complete Solution

2007-09-13 Thread Kostas Kalevras
O/H Mitch McCracken έγραψε: When organizations grow, there becomes more and more systems that need to be maintained, and each may have different configurations and users which have access to them. Individually editing local config files gets old pretty fast for hundred of devices, and

RE: OpenLDAP + FreeRADIUS Complete Solution [sec=unclassified]

2007-09-13 Thread Ranner, Frank MR
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kostas Kalevras Sent: Friday, 14 September 2007 04:18 To: FreeRadius users mailing list Subject: Re: OpenLDAP + FreeRADIUS Complete Solution O/H Mitch McCracken έγραψε: When organizations grow,

Gigawords

2007-09-13 Thread Guilherme Franco
Hello, I'm using rlm_sql_log in freeradius 1.1.4. In order to correctly work with acct-input/ output gigawords, I've replaced '%{Acct-Input-Octets}' with '%{%{Acct-Input-Gigawords}:-0}' 32 | '%{%{Acct-Input-Octets}:-0}' in the rlm_sql_log conf, but this results in invalid queries like: update