Re: Question about forum

2008-01-25 Thread A . L . M . Buxey
Hi, There is a history of this mailing list, but searching something is a nightmare. Imho forum would be great for that. Sent from my BlackBerry® wireless device forums suck imho alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Question about forum

2008-01-25 Thread Arran Cudbard-Bell
[EMAIL PROTECTED] wrote: Hi, There is a history of this mailing list, but searching something is a nightmare. Imho forum would be great for that. Sent from my BlackBerry® wireless device forums suck imho alan - List info/subscribe/unsubscribe? See

Re: Question about forum

2008-01-25 Thread JB
Nicholas Hall wrote: What's wrong with sharing your experiances with the list? Adding a forum will be just another place I'll have to check to get my FreeRADIUS fix. That's right, a forum wouldn't be a great idea. But this list shouldn't be a replacement for the Wiki either. So

rlm_perl and RLM_MODULE_REJECT

2008-01-25 Thread Jean-Michel Caricand
Hi, I have a question on rlm_perl and RLM_MODULE_REJECT. If in a function (post_proxy) I return RLM_MODULE_REJECT I can see this in log : modcall[post-proxy]: module perl1 returns reject for request 1 ... but my request is still accepted : Access-Accept not Access-Reject ! How to do that ?

Re: rlm_perl and RLM_MODULE_REJECT

2008-01-25 Thread Boian Jordanov
doesn't make sense to use RLM_MODULE_REJECT in post_proxy. May be you need pre_proxy ? From radius.conf file # # When the server decides to proxy a request to a home server, # the proxied request is first passed through the pre-proxy # stage. This stage can re-write the request, or decide

Re: Question about forum

2008-01-25 Thread Marinko Tarlac
Ok. Forum sometimes isn't a best solution. WIKI is a good option because you'll find all you need without to much off topic. On Jan 25, 2008 10:18 AM, JB [EMAIL PROTECTED] wrote: Nicholas Hall wrote: What's wrong with sharing your experiances with the list? Adding a forum will be just

Re: UserName, Password + MAC authentication using Cisco's BBSM 5.3

2008-01-25 Thread tnt
1. Use Cleartext-Password with =: as stated in the server documentation. 2. Post the output of radiusd -X. It's likely that the format for the MAC address is wrong. It can have : for delimiters or no delimiters at all. 3. That's not how you end user sessions on any device, Cisco or otherwise.

Re: rlm_perl and RLM_MODULE_REJECT

2008-01-25 Thread Jean-Michel Caricand
doesn't make sense to use RLM_MODULE_REJECT in post_proxy. May be you need pre_proxy ? From radius.conf file # # When the server decides to proxy a request to a home server, # the proxied request is first passed through the pre-proxy # stage. This stage can re-write the request, or

Re: Question about forum

2008-01-25 Thread Peter Nixon
We have a wiki. You are welcome to contribute... -Peter On Fri 25 Jan 2008, Marinko Tarlac wrote: Ok. Forum sometimes isn't a best solution. WIKI is a good option because you'll find all you need without to much off topic. On Jan 25, 2008 10:18 AM, JB [EMAIL PROTECTED] wrote: Nicholas Hall

Multiple accounting requests crash the server

2008-01-25 Thread Mother
Hi all, I am seeing a strange situation. I receive an accounting-stop request from a NAS, and FreeRADIUS (1.1.7 against Oracle) updates the corresponding radacct record. However, the NAS is not receiving the ack, and thus re-sends the stop request. On the second request, FreeRADIUS tries to

Re: rlm_perl and RLM_MODULE_REJECT

2008-01-25 Thread Boian Jordanov
Try with RLM_MODULE_FAIL in post_proxy Best Regards, Boian Jordanov SNE Orbitel - Next Generation Telecom tel. +359 2 4004 723 tel. +359 2 4004 002 On Jan 25, 2008, at 12:35 PM, Jean-Michel Caricand wrote: doesn't make sense to use RLM_MODULE_REJECT in post_proxy. May be you need

Re: rlm_perl and RLM_MODULE_REJECT

2008-01-25 Thread Jean-Michel Caricand
Le vendredi 25 janvier 2008 12:55, Boian Jordanov a écrit : Try with RLM_MODULE_FAIL in post_proxy Best Regards, Boian Jordanov SNE Orbitel - Next Generation Telecom tel. +359 2 4004 723 tel. +359 2 4004 002 On Jan 25, 2008, at 12:35 PM, Jean-Michel Caricand wrote: doesn't make sense

SSH-login authentication, using Active Directory credentials.

2008-01-25 Thread suraj shankar
Hi; For a long time now, I have been trying to unify the login credentials, in a heterogeneous environment. While I am aware of the few available options, I have decided against them, for varied reasons. In the last few days, I have been able to produce the effect which I desired, using

Re: eap and users file

2008-01-25 Thread tnt
users file and EAP-ttls + PAP schema can work togher? Yes. In 2.0.1 you can divert EAP requests to one virtual server, others to a different virtual server that will be doing ldap auth, ... Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

eap and users file

2008-01-25 Thread theSnail
I have only this entry in users file: DEFAULT Auth-Type := Accept raiudsd -X users: Matched entry DEFAULT at line 1 but it still try to authenticate against ldap. So the question is: users file and EAP-ttls + PAP schema can work togher? thanks -- View this message in context:

Re: Multiple accounting requests crash the server [update]

2008-01-25 Thread Mother
Update to the problem: the accounting-stop alternate query is actually an INSERT, not an UPDATE, by default, which actually surprises me, as in case of a duplicate packet, an INSERT into a properly unique-indexed table is doomed. I have now simply changed the -alt into an UPDATE query, so it

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread Vlad Sedov
That's a very valid point, however we do all the CPE configuration ourselves. Customer, as a rule, does not have access to the PPPoE settings. I think the message they would get is going to say something like There is a problem with your internet connection. Please call blahblahblah to resolve

Re: certificates in FR 2.0.1 on windows doesnt works

2008-01-25 Thread tnt
And that is good. Windows doesn't need to know who issued that certificate, only radius server does. Ivan Kalik Kalik Informatika ISP Dana 25/1/2008, orion [EMAIL PROTECTED] piše: its not a problem that windows says about the client certificate : the issuer of this certificate cannot be found

Re: Thank you and Diameter question

2008-01-25 Thread Alan DeKok
Raj Patel wrote: as anyone else been using it, I will be happy for some feedback Honestly, I've never seen much use for Diameter. Not that I'm biased, but I'd like to know what real-world problem it solves. Most requirements for diameter are political or commercial, not technical. Alan

Re: iCHAP?

2008-01-25 Thread Alan DeKok
Kevin J wrote: Does anybody know about iCHAP? Nope. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Thank you and Diameter question

2008-01-25 Thread Raj Patel
Hi People First thank you, I been reading this mailing list for some time and I found it great source of help I want to share some info with you and than ask a question We are slowly moving here into Java and starting to have Diameter requirements I found OpenBloX Java Diameter a great

iCHAP?

2008-01-25 Thread Kevin J
Does anybody know about iCHAP? Kevin, - Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: certificates in FR 2.0.1 on windows doesnt works

2008-01-25 Thread tnt
2)or only ca certificate + client certificate ? the second case the linkage between the ca and client doesnt exist ( as you said is the server the issuer of the client`s certificate ). Link is not needed. Server checks the client certificate to see if it's issued by the server (certificate).

Re: Force Auth-Type

2008-01-25 Thread Markus Moeller
Alan DeKok [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] Markus Moeller wrote: That was the only way I could get it to work. If I use update control anybody can login, whereas in my setup only a user who exits in ldap get AUth-Type set to LDAP all other users have an empty value

Re: one RADIUS server per realm setup

2008-01-25 Thread Wm. Josiah Erikson
I see. I can, indeed, remove Auth-Type := LDAP from the users file and it still works. Cool! However, the behavior described in the documentation is not what I'm seeing, and I'm still getting (contrary to what I said in my previous email) authorization requests not being proxied, even though

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread Vlad Sedov
Now that you mention it, the billing software _is_ getting replaced some time soon, but until then I have to hack radius as a workaround. Is it not possible to Fall-Through failed users to another section with its own pool and auth-type: accept? Vlad On Jan 25, 2008 12:16 PM, Andy

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread Andy Billington
Vlad, are the passwords changed _by the billing system_ for any other reason? You could use a trigger on the table to make a corresponding change on the usergroup when the billing system changes the password. Better though might just be to have a Expiry Due? column added to the users, and then

Re: SSH-login authentication, using Active Directory credentials.

2008-01-25 Thread Donny Jekels
Suraj, You're better of kerberizing your unix environment and join them with AD. this way your can have a fully single sign on environment. including samba file share without entering username and passwords. This is what you need to do. 1) install SFU3.5 on all your DC's 2) install openldap and

Re: Multiple accounting requests crash the server

2008-01-25 Thread Mother
Hi Alan, Thanks for your answers, mine inline below: Alan DeKok wrote: Mother wrote: I am seeing a strange situation. I receive an accounting-stop request from a NAS, and FreeRADIUS (1.1.7 against Oracle) updates the corresponding radacct record. However, the NAS is not receiving the ack, and

Re: SSH-login authentication, using Active Directory credentials.

2008-01-25 Thread suraj shankar
--- Alan DeKok [EMAIL PROTECTED] wrote: Any solution would have exactly the same security issues. Yes; I can understand and appreciate that. Thanks, Alan. Regards, suraj. Looking for last minute

Re: IP Pool defined, but radius does not hand out an IP address.

2008-01-25 Thread Alan DeKok
Andrew D Kirch wrote: You might try putting it at the top of radiusd.conf Done. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: SSH-login authentication, using Active Directory credentials.

2008-01-25 Thread tnt
Is there a better way, using radius? No. Once user is authenticated radius has nothing to do with them (you say that they can increase privileges after authentication). Can't you put them in jail. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

Re: Multiple accounting requests crash the server

2008-01-25 Thread tnt
#1: rad_recv: Accounting-Request packet from host X.X.X.X:46641, id=184, length=302 User-Name = blah NAS-Port = 2 NAS-Port-Type = Wireless-802.11 NAS-Identifier = XX NAS-IP-Address = X.X.X.X Acct-Status-Type = Stop Calling-Station-Id = MAC

Re: simple Ldap-group search

2008-01-25 Thread Markus Moeller
I think you need to use Ldap-Group instead of myldap-Ldap-Group or do you use do_xlat ? Markus cxu [EMAIL PROTECTED] wrote in message news:[EMAIL PROTECTED] Background: When a user associated with the ssid Guest, the user will authenticate against a FreeRadius server. If he has a

Re: certificates in FR 2.0.1 on windows doesnt works

2008-01-25 Thread Alan DeKok
orion wrote: the import of client.p12 is ok but it doesnt have a valid link it is ca-server-client What does that mean? and the details of the server certificate tells that is not authorized to issue certificates . Where does it say that? Which certificate tool are you using to look at

Re: SSH-login authentication, using Active Directory credentials.

2008-01-25 Thread suraj shankar
--- [EMAIL PROTECTED] wrote: Is there a better way, using radius? No. Once user is authenticated radius has nothing to do with them (you say that they can increase privileges after authentication). Can't you put them in jail. Yeah, I would eventually do that, if there is no 'better way'.

Re: one RADIUS server per realm setup

2008-01-25 Thread Alan DeKok
Wm. Josiah Erikson wrote: # Setting Auth-Type = LDAP is ALMOST ALWAYS WRONG. We # really can't emphasize this enough. Uh. OK. That's exactly what I'm doing, and it's working :) Then it works. It's fine. That message is for the majority of people who force LDAP to be

Sql_log against postgresql

2008-01-25 Thread Roy Walker
Have 2.0 running against a Postgresql database. The sql_log code looks like it functions differently than the sql statements in the postgres driver (stop packets are another insert instead of an update). Has anyone already changed out the sql lines match the way it works without sql_log, don't

Re: Multiple accounting requests crash the server

2008-01-25 Thread Alan DeKok
Mother wrote: I am seeing a strange situation. I receive an accounting-stop request from a NAS, and FreeRADIUS (1.1.7 against Oracle) updates the corresponding radacct record. However, the NAS is not receiving the ack, and thus re-sends the stop request. On the second request, FreeRADIUS

Re: eap and users file

2008-01-25 Thread Alan DeKok
theSnail wrote: I have only this entry in users file: DEFAULT Auth-Type := Accept raiudsd -X users: Matched entry DEFAULT at line 1 but it still try to authenticate against ldap. So the question is: Why haven't you posted the entire output from radiusd -X ? i.e. you configured

Re: SSH-login authentication, using Active Directory credentials.

2008-01-25 Thread Alan DeKok
suraj shankar wrote: I understand that pam_radius_auth 'encrypts' the password. But if a user has the privileges to change the /etc/raddb/server file (and point it to a freeradius server), wouldn't he/she be able to siphon off the credentials? Yes. Our setup would disallow direct 'root'

Re: Question about forum

2008-01-25 Thread tnt
Yes, write to Peter Nixon and he will help you. Ivan Kalik Kalik Informatika ISP Dana 25/1/2008, Marinko Tarlac [EMAIL PROTECTED] piše: I would like to register too. Is there any chance for this? On Jan 25, 2008 5:37 PM, JB [EMAIL PROTECTED] wrote: Peter Nixon wrote: We have a wiki. You

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread Alex Moen
So, what would be the difference between a customer who was disconnected, and one who cannot remember his/her password (yeah, this never happens, right?) There would be no differentiation, and customers who have simply forgotten their password may be upset when you tell then they are

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread Vlad Sedov
The only problem with this method is that our billing system is not (currently) capable of changing the usergroup when the account is suspended. All it does is change the password. Vlad On Jan 25, 2008 11:22 AM, Marinko Tarlac [EMAIL PROTECTED] wrote: radius will reply whatever you need but

Re: Question about forum

2008-01-25 Thread Marinko Tarlac
I would like to register too. Is there any chance for this? On Jan 25, 2008 5:37 PM, JB [EMAIL PROTECTED] wrote: Peter Nixon wrote: We have a wiki. You are welcome to contribute... Account creation/free editing seems to be deactivated... Bye, JB - List info/subscribe/unsubscribe? See

Re: rlm_perl and RLM_MODULE_REJECT

2008-01-25 Thread Alan DeKok
Jean-Michel Caricand wrote: Well. I made a lot of tests without success. I'm not yet able to REJECT a request in a post_proxy function, but that works fine in a authorize function. Does someone have ideas ? In 2.0, it looks like this isn't dealt with in src/main/event.c around line

Re: rlm_perl and RLM_MODULE_REJECT

2008-01-25 Thread Jean-Michel Caricand
Le vendredi 25 janvier 2008 12:55, Boian Jordanov a écrit : Try with RLM_MODULE_FAIL in post_proxy Best Regards, Boian Jordanov SNE Orbitel - Next Generation Telecom tel. +359 2 4004 723 tel. +359 2 4004 002 On Jan 25, 2008, at 12:35 PM, Jean-Michel Caricand wrote: doesn't make sense

Re: Question about forum

2008-01-25 Thread JB
Peter Nixon wrote: We have a wiki. You are welcome to contribute... Account creation/free editing seems to be deactivated... Bye, JB - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Hello, and a (hopefully) simple question

2008-01-25 Thread Vlad Sedov
Hey folks. Right now, we use freeradius to authenticate simple pap/chap PPP clients. When a username/password is rejected, radius simply send back a reject message to the NAS. Is it possible to change this behavior so that a failed auth attempt gets accepted with an alternate IP pool instead of

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread Marinko Tarlac
radius will reply whatever you need but you need to tell him what do you want. For example, if you're using mysql, when user account expires you can add him to specific group and group attributes you can set in radgroupreply table. (ip pool, tx, rx limit etc.) On Jan 25, 2008 6:18 PM, Vlad Sedov

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread JB
If it's just a message you want to display, you could use the Reply- Message attribute. Of course, your access controler would have to know how handle this attribute. JB Marinko Tarlac wrote: radius will reply whatever you need but you need to tell him what do you want. For example, if

RE: Hello, and a (hopefully) simple question

2008-01-25 Thread David Roze
A trigger on the password field is a workaround. What about if he wants to change a user's password or when it changes back to bring the connection back on? Changing the password is not the right way to reject a connection and everything possible should be done to change the software's behaviour.

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread Andy Billington
David - agreed. It's a workaround until the billing software can be modified (or replaced); in combination with an expiry_due check and also checking whether its the billing system that made the change though, its not a bad short-term workaround. Needs to be both of those checks though ;-) Andy

Re: certificates in FR 2.0.1 on windows doesnt works

2008-01-25 Thread orion
im using standart windows mmc. after import of the CA and Server certificates the server certificate links to the ca certificate ok CA certificate |- server certificate but when i import the client.p12 certificate the linkage is CA certificate |- server certificate |-

Re: certificates in FR 2.0.1 on windows doesnt works

2008-01-25 Thread orion
its not a problem that windows says about the client certificate : the issuer of this certificate cannot be found ? can the certificate be used in this case ? On 25/01/2008, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: 2)or only ca certificate + client certificate ? the second case the

Re: certificates in FR 2.0.1 on windows doesnt works

2008-01-25 Thread Alan DeKok
orion wrote: but when i import the client.p12 certificate the linkage is CA certificate |- server certificate |- client certificate in that moment the server part tells ( it not allow to issue certificate for others). There's no reason why the intermediate certificate

Re: certificates in FR 2.0.1 on windows doesnt works

2008-01-25 Thread Alan DeKok
orion wrote: its not a problem that windows says about the client certificate : the issuer of this certificate cannot be found ? Thank you for FINALLY posting the REAL error message. It helps to post the REAL error message, because you can then get a REAL solution. In this case, you

Re: Hello, and a (hopefully) simple question

2008-01-25 Thread tnt
Now that you mention it, the billing software _is_ getting replaced some time soon, but until then I have to hack radius as a workaround. So alter groups and not passwords. Is it not possible to Fall-Through failed users to another section with its own pool and auth-type: accept? Why? Just