Re: Fw: freeradius and ldap using chap

2010-02-22 Thread Eric Eric
When I remove ldap-Vpn from authenticate part error is:   rlm_chap: login attempt by test with CHAP password   rlm_chap: Could not find clear text password for user test Login incorrect (rlm_chap: Clear text password not available): [test] (from client vpntist port 128 cli 10.10.10.24) what is

Re: eap-ttls and eap-peap againts OpenLdap

2010-02-22 Thread John smith
Hi Fajar, I don't use ntlm_auth, i'd think was necessary when using a Active Directory, My version of samba is 3.0.24 I'm going to read about ntlm_auth option and i'll try it Thank you Nick 2010/2/22 Fajar A. Nugraha fa...@fajar.net On Mon, Feb 22, 2010 at 2:04 AM, John smith

default_eap_type in ttls configuraion in file eap.conf

2010-02-22 Thread ZHANG Gina
Hi! I have a question regarding to the default_eap_type setting for ttls configuration in file eap.conf. From TTLS protocol, it is not necessary to do authentication in the tunnel and it is the user who decides and initiates which eap type to use inside tunnel. What the default_eap_type is used

Authorization through inner identity

2010-02-22 Thread ZHANG Gina
Hi, Is it possible to do authorization through the identity in inner tunnel? Thanks, Gina Zhang - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Authorization through inner identity

2010-02-22 Thread Alan Buxey
Hi, Hi, Is it possible to do authorization through the identity in inner tunnel? check out the authorize {} section in the inner-tunnel virtual server in FreeRADIUS 2.x - thats what its there for alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Authorization through inner identity

2010-02-22 Thread ZHANG Gina
Alan, Thanks for the quick response! I did look there before I sent the first email. I think that I should add something In authorize section like update request. But I don't know the details. Could you advise? Thanks, Gina -Original Message- From:

Re: Authorization through inner identity

2010-02-22 Thread Alan Buxey
Hi, I did look there before I sent the first email. I think that I should add something In authorize section like update request. well, that all dependds on what you want to achieve. the current listed modules in tat section all behave as per normal and deal with the basic yes/no of

RE: Authorization through inner identity

2010-02-22 Thread ZHANG Gina
Alan, All I want to do is to use inner username to lookup the database table to authorize. Thanks, Gina -Original Message- From: freeradius-users-bounces+gina.zhang=alcatel-lucent@lists.freeradius. org [mailto:freeradius-users-bounces+gina.zhang=alcatel-lucent@lists.fre

Re: modules instantiation

2010-02-22 Thread Latha Krishnamurthi
Thankyou will try that. --- On Fri, 2/19/10, Alan DeKok al...@deployingradius.com wrote: From: Alan DeKok al...@deployingradius.com Subject: Re: modules instantiation To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Date: Friday, February 19, 2010, 6:07 PM Latha

Re: eap-ttls and eap-peap againts OpenLdap

2010-02-22 Thread Fajar A. Nugraha
On Mon, Feb 22, 2010 at 9:14 PM, John smith ohn...@gmail.com wrote: Hi Fajar, I don't use ntlm_auth, i'd think was necessary when using a Active Directory, My version of samba is 3.0.24 I'm going to read about ntlm_auth option and i'll try it IIRC, when you use peap-mschap, you need

rlm-ldap error for chap

2010-02-22 Thread Eric Eric
Hi I want to change authentication pap to chap. The users with clear passwords are in ldap server. but the is error with clear password in rlm-ldap radiusd -x Starting - reading configuration files ... Using deprecated naslist file.  Support for this will go away soon. Module: Loaded exec

Re: rlm-ldap error for chap

2010-02-22 Thread Fajar A. Nugraha
On Tue, Feb 23, 2010 at 1:32 PM, Eric Eric eric121...@yahoo.com wrote: Hi I want to change authentication pap to chap. The users with clear passwords are in ldap server. but the is error with clear password in rlm-ldap rlm_ldap: LDAP userPassword mapped to RADIUS Cleartext-Password is the

Re: modules instantiation

2010-02-22 Thread Doug Hardie
I tried to correct the wiki's description but was not able to do so. I can log in fine and it says I can edit the file. However, after making the changes save just gives a blank screen and the changes never appear in the text. In the modules2 file change: The xxx_instantiate module is