Re: poptop - received RADIUS server response with invalid length

2007-11-15 Thread Alan DeKok
Ben Thompson wrote: Nov 14 11:26:12 nassrv3 pppd[15621]: rcvd [CHAP Response id=0x9 4166d4713ef8cec048e88644889a7fbcadcaef9a0709f7576bad0ce28f82ed7e5fb6e8c193a192bb00, name = ozw1] Nov 14 11:26:12 nassrv3 pppd[15621]: rc_check_reply: received RADIUS server response with

Re: Post-Auth REJECT - conditional sql

2007-11-15 Thread Alan DeKok
Rachel Primrose wrote: So, here is the order of operations: 1. User is trying to log in with [EMAIL PROTECTED] 2. The LNS first tries to authenticate the realm. It sends through an access request packet to our radius server with User-Name=realm.com, Service-Type=Dialout-Framed-User and

SHA-256

2007-11-15 Thread Zolotov, Eyal
Hello, Does free radius support SHA-256? Eyal. - Envara, Ltd. This e-mail and any attachments may contain confidential material for the sole use of the intended recipient(s). Any review or distribution by others is strictly

Re: SHA-256

2007-11-15 Thread Alan DeKok
Zolotov, Eyal wrote: Hello, Does free radius support SHA-256? For what? SSL? FreeRADIUS supports whatever OpenSSL supports. The CVS head (what will be 2.0) has better support for everything SSL than is in 1.1.x. I would suggest checking that, first. Alan DeKok. - List

Re: MD5 authentication

2007-11-15 Thread A . L . M . Buxey
Hi, I'm sorry again, I wouldn't have said authentication request but authentication SQL request made by the freeradius server to the SQL database. its a check item request in the SQL table item operator value MD5-Password := MD5-value read sql.conf for more details alan - List

Re: Change pam_auth NAS-IP Address in radius reuest.

2007-11-15 Thread Alan DeKok
Bryan wrote: I'm using the latest freeradius on Centos 4.5. I have several Centos 4.5 clients all using pam_auth_radius and LDAP. Everything is working but I wanted to know if there is a way to change the NAS-IP-Address that is sent by the clients. They all send back 127.0.0.1. I want to

Re: Does free radius support diameter? And If not is it easy to make it support diameter via modified the source code?

2007-11-15 Thread Peter Nixon
On Mon 12 Nov 2007, Liangliang Guo wrote: Hi: I have a node in my target system that has two interfaces of which one is diameter and the other is radius.So only radius protocol is supported does not meet the requirement.So does anybody know whether free radius support diameter or not(as far

Re: RADIUS Stress Test tool

2007-11-15 Thread Amr el-Saeed
Dear All, i know this is too late to say that :-) but , i used radclient to test my freeradius server i wanted to use the ( -p num Send 'num' packets from a file in parallel. ) thats my command ( radclient -f attr -p 100 localhost:1812 auth local ) this is the file attr ( User-Name =

Re: RADIUS Stress Test tool

2007-11-15 Thread Alan DeKok
Amr el-Saeed wrote: but , i used radclient to test my freeradius server i wanted to use the ( -p num Send 'num' packets from a file in parallel. ) thats my command ( radclient -f attr -p 100 localhost:1812 auth local ) ... but the request is done only once not 100 times !! Use -c

problem with certificate

2007-11-15 Thread [EMAIL PROTECTED]
Hello. I create mi certificate with openssl its version is openssl-0.9.7f-7.10. The configuration from eap.conf is eap { default_eap_type = ttls timer_expire = 60 ignore_unknown_eap_types = no

Re: Newbie question - number of radius requests per session?

2007-11-15 Thread Nathan Hay
Thanks for everyone's help. I have it working nicely now, but have one more situation I just started testing. I want to use the same radius servers to authenticate users on a different wireless network though a captive portal to the same eDirectory servers via LDAP. In order for the captive

Re: Newbie question - number of radius requests per session?

2007-11-15 Thread A . L . M . Buxey
Hi, Thanks for everyone's help. I have it working nicely now, but have one more situation I just started testing. I want to use the same radius servers to authenticate users on a different wireless network though a captive portal to the same eDirectory servers via LDAP. In order for

Re: problem with certificate

2007-11-15 Thread A . L . M . Buxey
hi, either the PATH defined is not correct or the files cannot be read by the radius daemon alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Users outside /etc/raddb/users

2007-11-15 Thread Rui Meireles
My problem is solved. Sorry for not posting here earlier. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of William Sent: sexta-feira, 9 de Novembro de 2007 19:13 To: FreeRadius users mailing list Subject: Re: Users outside /etc/raddb/users

Re: Cert Problem with EAP-TTSL, SecureW2 (1.0.5--1.1.7)

2007-11-15 Thread Martin Pauly
No DH gets initialized, but the cert problem remains. sorry for ma late response: I had indeed confused two files and included the wrong CA cert file. The supplicant was perfectly right in its complaint Thanks, Martin -- Dr. Martin Pauly Fax:49-6421-28-26994 HRZ Univ.

Re: Post-Auth REJECT - conditional sql

2007-11-15 Thread Rachel Primrose
Thanks Alan. Looks like we'll be implementing a solution in the database then. - Rachel On Nov 15, 2007 9:33 PM, Alan DeKok [EMAIL PROTECTED] wrote: Rachel Primrose wrote: So, here is the order of operations: 1. User is trying to log in with [EMAIL PROTECTED] 2. The LNS first

Dialup Admin

2007-11-15 Thread Scott
When I run these commands I get. mysql -uradius -p radius badusers.sql ERROR 1067 (42000) at line 4: Invalid default value for 'id' mysql -uradius -p radius userinfo.sql ERROR 1067 (42000) at line 4: Invalid default value for 'id' -- Scott Rodgers - List info/subscribe/unsubscribe?

Re: Change pam_auth NAS-IP Address in radius reuest. (Alan DeKok)

2007-11-15 Thread Bryan
Bryan wrote: I'm using the latest freeradius on Centos 4.5. I have several Centos 4.5 clients all using pam_auth_radius and LDAP. Everything is working but I wanted to know if there is a way to change the NAS-IP-Address that is sent by the clients. They all send back 127.0.0.1. I want

RE: Users outside /etc/raddb/users

2007-11-15 Thread tnt
It was not a joke. =D It would massively increase the number of lines of /etc/raddb/users, and it would become annoying to read/edit. I wasn't talking about the size in KB! =D Size iz not important (or so they say). Any text editor should be capable of finding and replacing text. There is no

running freeradius with xinetd....?

2007-11-15 Thread obi-wan
i have taken delivery of a RHEL server with FreeRadius installed and running from XINETD. _the radius sever is not performing as expected and spews the following ERROR to the log file; There appears to be another RADIUS server running on the authentication port 1645 when i attempt to dial and

Re: freeradius auto-vlan 3com switch 4500G

2007-11-15 Thread Krzysztof Olędzki
On 2007-11-11 18:27, Philippe Breton wrote: On Sun, 2007-11-11 at 17:37 +0100, Krzysztof Olędzki wrote: On 2007-11-10 17:30, Philippe Breton wrote: Did you setup your switch properly: domain (...) vlan-assignment-mode string Hard to give a 100% answer on this question. I believe I did with

Re: running freeradius with xinetd....?

2007-11-15 Thread Alan DeKok
obi-wan wrote: i have taken delivery of a RHEL server with FreeRadius installed and running from XINETD. That is wrong. Do not run FreeRADIUS under any inetd. _the radius sever is not performing as expected and spews the following ERROR to the log file; *There appears to be another