Re: FR2.1.3+LDAP+802.1x+PEAP

2009-11-13 Thread Caius
Hi Alan, your right in what you say, My conclusion is: i could go for EAP-TTLS + xsupplicant (there is also a windows version), then i dont need to weaken my server security, but i force the client to install a 3th party tool or as discuses with Ivan, i could make some rules, based on the

Re: Proxy to multiple servers in FR 2.1.7

2009-11-13 Thread Patric
Hi Craig, Thanks for you response. I have tried to implement this but Im going wrong somewhere. Below I will show my configuration, then the debug that shows what the server is doing. First my 2 detail files. modules/detail: --- detail detail-radrelay { detailfile =

Re: Proxy to multiple servers in FR 2.1.7

2009-11-13 Thread Alan DeKok
Patric wrote: Thanks for you response. I have tried to implement this but Im going wrong somewhere. Below I will show my configuration, then the debug that shows what the server is doing. ... sites-enabled/copy-acct-to-home-server: --- server

Re: Proxy to multiple servers in FR 2.1.7

2009-11-13 Thread Patric
Hi Alan, Thanks for responding, So now there is already a home_server_pool assigned to the default realm, but I continue and create a home_server entry for server B ... sites-enabled/copy-acct-to-server-B: --- server copy-acct-to-home-server {

Re: Learning Freeradius Server

2009-11-13 Thread Wagner Pereira
Hi, Kachin. This is a good place to start: http://freeradius.org And, trust me, read A LOT the man freeradius documentation. In other hand, maybe it's a good idea you start to test freeradius with the simplest way to authenticate: using /etc/passwd. I started to use the mysql authentication

Re: FreeRADIUS + Postgresql dies unexpectedly

2009-11-13 Thread Duarte Fonseca
Hi John, As long as the hammer does the job. At this stage although I'm aware that RPM packaging is much more powerful my lack of knowledge about it doesn't allow for a more sensible approach. Hopefully this will change time ;) thanks, Duarte 2009/11/12 John Dennis jden...@redhat.com: On

operator !* in update {}

2009-11-13 Thread Jakob Hirsch
Hi, according to unlang: !* Delete all occurances of the named attribute, no matter what the value. but when I want to use it like that: post-auth { Post-Auth-Type REJECT { update reply { Idle-Timeout !* 0

Re: Freeradius-Users Digest, Vol 55, Issue 58

2009-11-13 Thread Gilbert Lo
Thank you for your message. I am away until Nov 19th. I will respond to your message on my return . For urgent matters, please contact helpd...@stgeorges.bc.ca . Cheers, Gilbert Lo - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Compiling freeradius server with static libraries

2009-11-13 Thread kachin Agarwal
Hi, How to compile the freeradius server using static library function?? Thanx Regards, kachin Add whatever you love to the Yahoo! India homepage. Try now! http://in.yahoo.com/trynew- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Proxy to multiple servers in FR 2.1.7

2009-11-13 Thread Patric
Hi again, Alan DeKok wrote: sites-enabled/copy-acct-to-server-B: --- server copy-acct-to-home-server { Uh... you have TWO virtual servers with the same name. This isn't allowed. And this config isn't the same as what's shown in the debug log. Can

Re: Learning Freeradius Server

2009-11-13 Thread Rakotomandimby Mihamina
11/13/2009 01:30 PM, Wagner Pereira: In other hand, maybe it's a good idea you start to test freeradius with the simplest way to authenticate: using /etc/passwd. This is not the simplest way: using /etc/freeradius/users is _the_ simplest way. -- Architecte Informatique chez

Re: Learning Freeradius Server

2009-11-13 Thread Wagner Pereira
You're right, Rako-y. The file *users* uses the plain-text mode to authenticate users. -- Wagner Pereira PoP-SP/RNP - Ponto de Presença da RNP em São Paulo CCE/USP - Centro de Computação Eletrônica da Universidade de São Paulo http://www.pop-sp.rnp.br (11) 3091-8902 Rakotomandimby Mihamina

Re: operator !* in update {}

2009-11-13 Thread Alexander Clouter
Jakob Hirsch j...@plonk.de wrote: according to unlang: !* Delete all occurances of the named attribute, no matter what the value. but when I want to use it like that: post-auth { Post-Auth-Type REJECT { update reply { Idle-Timeout

Re: FreeRADIUS + Postgresql dies unexpectedly

2009-11-13 Thread Duarte Fonseca
Hi Alex, Again thanks for the help. 2009/11/12 Alexander Clouter a...@digriz.org.uk: You should also compile the whole thing with optimisations turned off and debugging symbols in there; you are not doing the former so it might make it more difficult to work out what is wrong:

Re: operator !* in update {}

2009-11-13 Thread Alan DeKok
Jakob Hirsch wrote: according to unlang: !* Delete all occurances of the named attribute, no matter what the value. but when I want to use it like that: The fix will be in 2.1.8. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: WiMAX-Capabilty proxy issue

2009-11-13 Thread Alan DeKok
Ramon J. Castillo wrote: I'm having an issue when proxying an access-request message between two WiMAX networks. I recently downloaded FR 2.1.8 and I'm in the middle of the messaging path. The home network is using EAP-TLS but it should be transparent for the proxy right? The issue is with

Re: operator !* in update {}

2009-11-13 Thread Jakob Hirsch
Alexander Clouter, 2009-11-13 13:03: /etc/freeradius2//sites/ui.site.conf[205]: Parse error after Idle-Timeout I get the same thing and kept meaning to file a bug report. I opted as a quick hack: update reply { Blar -= %{reply:Blar} } Thanks, that's clever! Also thanks to

Re: Proxy to multiple servers in FR 2.1.7 [Solved]

2009-11-13 Thread Patric
Hi once again Alan, I must apologize for my previous grasping at straws, it was not from lack of trying, just lack of knowledge... I have managed to figure it out thanks to your last comment Alan DeKok wrote: If you want the requests to be proxied to a DIFFERENT location, you will need to

Crash due to fr_packet_cmp

2009-11-13 Thread fabiana marvani
Hello , I have a big problem with my freeradius ... After some time with load the freeradius crashes We first noticed this crash with our plugins activated, but then we deactivated all plugins and used default configuration: /usr/local/etc/raddb/users: DEFAULT Auth-Type := Accept

Re: Microsoft: SmardCard or Certificate Auth

2009-11-13 Thread swatzy
Thanks a lot Alan... I'm going to try your suggestion... ;-) Alan DeKok-2 wrote: swatzy wrote: I'm trying to configure a FreeRadius server to perform a certification authentication from a Windows Laptop. I have follow the steps at

Re: FR2.1.3+LDAP+802.1x+PEAP

2009-11-13 Thread tnt
My conclusion is: i could go for EAP-TTLS + xsupplicant (there is also a windows version), then i dont need to weaken my server security, but i force the client to install a 3th party tool People also use SecureW2. Compare and see which one is better. or as discuses with Ivan, i could make

How to store multiple Cisco-AVPair to sql database

2009-11-13 Thread Mark Jones
As you can see in the below accounting packet there are multiple cisco-avpsir entries. how can i referecne the second and seccussive entries when trying to store them in and sql database. Fri Nov 13 10:56:23 2009 Acct-Session-Id = 004D8A64 Cisco-AVPair =

Re: Compiling freeradius server with static libraries

2009-11-13 Thread tnt
How to compile the freeradius server using static library function?? Read INSTALL file. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS + Postgresql dies unexpectedly

2009-11-13 Thread Alexander Clouter
Duarte Fonseca fonseca.dua...@gmail.com wrote: 2009/11/12 Alexander Clouter a...@digriz.org.uk: You should also compile the whole thing with optimisations turned off and debugging symbols in there; you are not doing the former so it might make it more difficult to work out what is wrong:

Re: WiMAX-Capabilty proxy issue

2009-11-13 Thread Ramon J. Castillo
Great !!! Thanks Alan Ramon From: Alan DeKok al...@deployingradius.com To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Fri, November 13, 2009 2:18:38 PM Subject: Re: WiMAX-Capabilty proxy issue Ramon J. Castillo wrote: I'm having

Re: usergroup and radgroupcheck problem!

2009-11-13 Thread Hamid Reza Hasani
It looks like you have edited sql queries and mixed user and group queries. Post the part of the startup debug with sql initializing. Ivan Kalik Kalik Informatika ISP Thanks for your response, I attached full log. Ya Ali Hamid Reza Hasani radius.log Description: Binary data - List

Re: DHCP in FR

2009-11-13 Thread Kassai Istvan
2009. 11. 12, csütörtök keltezéssel 12.00-kor Alan DeKok ezt írta: radiusd: Loading Virtual Servers server dhcp { modules { } # modules You CANNOT put the modules section into a server section. Nothing in the documentation or examples says that it is possible. I just