Re: FR 2.0.3 gives duplicate NULL realm error

2008-04-08 Thread Alan DeKok
John Horne wrote: It seems that radiusd doesn't like the NULL realm after the DEFAULT. I swapped these two around, and radiusd started up fine. ? I can start up the server fine with those realms, in any order. I'm not sure why the 'radiusd -X' output gives as the very last line '} # realm

Re: Freeradius + CHAP

2008-04-08 Thread Ivan Kalik
Server debug please. Ivan Kalik Kalik Informatika ISP Dana 8/4/2008, SANDY KALUGDAN [EMAIL PROTECTED] piše: [EMAIL PROTECTED] SPECS]# radtest s sandy locahost 1645 testing123 radclient: Failed to find IP address for host locahost: Success - Original Message From: Ivan Kalik [EMAIL

Re: FR 2.0.3 gives duplicate NULL realm error

2008-04-08 Thread John Horne
On Tue, 2008-04-08 at 08:18 +0200, Alan DeKok wrote: John Horne wrote: It seems that radiusd doesn't like the NULL realm after the DEFAULT. I swapped these two around, and radiusd started up fine. ? I can start up the server fine with those realms, in any order. Yes, with 2.0.2 I had

Re: FR 2.0.3 gives duplicate NULL realm error

2008-04-08 Thread John Horne
On Tue, 2008-04-08 at 10:14 +0100, John Horne wrote: On Tue, 2008-04-08 at 08:18 +0200, Alan DeKok wrote: John Horne wrote: It seems that radiusd doesn't like the NULL realm after the DEFAULT. I swapped these two around, and radiusd started up fine. ? I can start up the server

Re: Freeradius + CHAP

2008-04-08 Thread SANDY KALUGDAN
Ivan, nice to see that you're always there to provide support. I've managed to have it working somehow. using nokia wifi enabled phones laptops. All throughout the sessions, I've been using Sony Ericsson's P1i to test the setup (Chillispot + Freeradius + Mysql). Now I'm checking the reason

Freeradius 2.0.3 - radtest utility

2008-04-08 Thread Jeff Green
Hi, Been using Freeradius for 5+ years now and I'd just like to say it's great software, many thanks to Alan et al for all their hard work ! I'm currently investigating moving from RHEL4 / Postgresql 8.1 / FR 1.1.6 to Centos5.1 / Postgresql 8.3 / FR 2.0.3 - fell down a couple of holes

Using tags (RFC2868)

2008-04-08 Thread Imri Zvik
Hi, I'm trying to use tags, in order to group tunneling attributes. I've tried adding them like that: Tunnel-Preference:0 += 10 Tunnel-Preference:1 += 10 But when running the radius in debug mode (-X -x), I see that the following is being returned to the NAS: Sending Access-Accept of id 74 to

Authenticate with FreeRadius + MySQL + PEAP

2008-04-08 Thread tiodacio
Hi, I'm using FreeRADIUS Version 1.1.6 for Freebsd 6.2 to authenticate Wi-Fi clients. Im using WPA2. My users are in a MySQL database and i'm using EAP-PEAP and mschapv2 for authentication. When i create a user test, for example, in the radcheck table and configure this user in a Windows XP

Re: Authenticate with FreeRadius + MySQL + PEAP

2008-04-08 Thread Ivan Kalik
Debug of the request? Ivan Kalik Kalik Informatika ISP Dana 8/4/2008, tiodacio [EMAIL PROTECTED] piše: Hi, I'm using FreeRADIUS Version 1.1.6 for Freebsd 6.2 to authenticate Wi-Fi clients. Im using WPA2. My users are in a MySQL database and i'm using EAP-PEAP and mschapv2 for

Re: Using tags (RFC2868)

2008-04-08 Thread Ivan Kalik
Shouldn't tunnel number go inside the value: Tunnel-Preference += :0:10 Tunnel-Preference += :1:10 Ivan Kalik Kalik Informatika ISP Dana 8/4/2008, Imri Zvik [EMAIL PROTECTED] piše: Hi, I'm trying to use tags, in order to group tunneling attributes. I've tried adding them like that:

Simultaneous use without DB

2008-04-08 Thread Eduardo Lima
I want to limit one access per user on freeradius 2.0.2 but I don't want to use a database. Is that possible? I red the topic FreeRadius V2.0.0 Simultaneous-Use Problems wrote on january, but the author uses mysql. I'm using PEAP authentication with server-side certificate on freeradius 2.0.2.

Re: Using tags (RFC2868)

2008-04-08 Thread Imri Zvik
On Tuesday 08 April 2008 17:02:33 Ivan Kalik wrote: Shouldn't tunnel number go inside the value: Tunnel-Preference += :0:10 Tunnel-Preference += :1:10 As far as I know, both should work. I tried both ways - didn't work :( I'm running version 2.0.3, by the way. Ivan Kalik Kalik

Re: Authenticate with FreeRadius + MySQL + PEAP

2008-04-08 Thread Ivan Kalik
modcall: entering group MS-CHAP for request 6 rlm_mschap: Told to do MS-CHAPv2 for [EMAIL PROTECTED] with NT-Password rlm_mschap: FAILED: MS-CHAP2-Response is incorrect Password is wrong. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

Re: Simultaneous use without DB

2008-04-08 Thread Ivan Kalik
It works without the database (accounting) by default. Remove Auth-Type System from user entry. Ivan Kalik Kalik Informatika ISP Dana 8/4/2008, Eduardo Lima [EMAIL PROTECTED] piše: I want to limit one access per user on freeradius 2.0.2 but I don't want to use a database. Is that possible? I

Stale Sessions

2008-04-08 Thread Shane McKinley
I have searched and searched, read the archives, etc. I feel that I may have a unique problem and just missing a piece of the puzzle. I have been running freeradius with a mysql database for over a year now. It is very stable and I am generally pleased. I have been having stale session issues

Re: Authenticate with FreeRadius + MySQL + PEAP

2008-04-08 Thread tiodacio
Ivan, Thats the problem, i have sure the password its not wrong. The users test and [EMAIL PROTECTED] have the same password. The first is authenticated, the second no. The problem is when my user has a domain and i need a domain because my radius will make proxy. I think thats some problem

Re: Stale Sessions

2008-04-08 Thread Bill Brunton
I am having the same problem. I am using: radiusd: FreeRADIUS Version 1.1.3, for host i686-redhat-linux-gnu, built on May 10 2007 at 12:30:17 on Centos 5.1. I only have about 150 users authenticating and I have plenty of CPU time and the server is in a datacenter with several DS3s so I

Re: ENV variables in external scripts

2008-04-08 Thread rsg
Hi, Isn't the functionality same whether it is rlm_perl or Exec-Program-Wait? I find the following in ../experimental.conf. //This is very similar to using # Exec-Program-Wait = /path/foo.pl, but it is persistent, # and therefore faster. // With rlm_perl can

Re: Freeradius 2.0.3 - radtest utility

2008-04-08 Thread Alan DeKok
Jeff Green wrote: Been using Freeradius for 5+ years now and I'd just like to say it's great software, many thanks to Alan et al for all their hard work ! Thanks. I've found that the radtest client in FR 2.0.3 isn't displaying the Accept / Reject message any more. However

Re: Authenticate with FreeRadius + MySQL + PEAP

2008-04-08 Thread Ivan Kalik
I think thats some problem with eap-peap, because when i use radtest to authenticate [EMAIL PROTECTED] the authentication proceeds. Is that password in the database encrypted or in clear text? Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

Re: Simultaneous use without DB

2008-04-08 Thread Eduardo Lima
I removed the Auth-Type Sustem from users, by it stills not working. Radwho command doesn't work either... Ivan Kalik [EMAIL PROTECTED] escreveu: It works without the database (accounting) by default. Remove Auth-Type System from user entry. Ivan Kalik Kalik Informatika ISP Dana 8/4/2008,

Re: ENV variables in external scripts

2008-04-08 Thread Ivan Kalik
With rlm_perl can external perl scripts be easily used as with Exec-Program-Wait ? Easier: http://wiki.freeradius.org/Rlm_perl Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Simultaneous use without DB

2008-04-08 Thread Ivan Kalik
Are you getting accounting packets from the NAS at all? Ivan Kalik Kalik Informatika ISP Dana 8/4/2008, Eduardo Lima [EMAIL PROTECTED] piše: I removed the Auth-Type Sustem from users, by it stills not working. Radwho command doesn't work either... Ivan Kalik [EMAIL PROTECTED] escreveu: It

Re: Authenticate with FreeRadius + MySQL + PEAP

2008-04-08 Thread tiodacio
Clear-text -- Início da mensagem original --- De: [EMAIL PROTECTED] Para: FreeRadius users mailing list freeradius-users@lists.freeradius.org Cc: Data: Tue, 08 Apr 2008 18:51:42 +0100 Assunto: Re: Authenticate with FreeRadius + MySQL + PEAP I think thats

Re: Authenticate with FreeRadius + MySQL + PEAP

2008-04-08 Thread Ivan Kalik
Try another client or JRadius Simulator. Ivan Kalik Kalik Informatika ISP Dana 8/4/2008, tiodacio [EMAIL PROTECTED] piše: Clear-text -- Início da mensagem original --- De: [EMAIL PROTECTED] Para: FreeRadius users mailing list freeradius-users@lists.freeradius.org

Re: FR 1.1.7 + AD 2003 + LDAP

2008-04-08 Thread Charlie B
Has no one else experienced this issue where reset password confuses WinXP? I really don't want to use IAS. Anyone ideas? Thanks - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Configuring multiple, chained EAP methods (i.e. EAP-TTLS-EAP-MD5-EAP-TNC)

2008-04-08 Thread ingo . bente
Hi, is it possible to configure multiple eap methods that must all be executed for a user? I.e., I am thinking of something like: - establish a TTLS tunnel - do EAP-MD5 for user authentication - do EAP-TNC for platform authentication Currently, I just managed to do either EAP-MD5 or EAP-TNC

assert failed event.c and perl performance

2008-04-08 Thread Julien Leloup
Hi, I'm running FreeRadius 2.0.3 under FreeBSD 6.3, in a proxy configuration. This server is using rlm_perl in a post-proxy phase to realize some operations on Access-Accept attributes, with the use of a MySQL database. The same configuration, in FreeRadius 2.0.1 worked fine, but when I