Update warning

2010-11-05 Thread Maurice James
If you update from FreeRadius 2.1.9x to 2.1.10x your server might fail to start if the sample virtual server in the proxy.conf file is uncommented. I learned that the hard way Description: MCITP(rgb)_1084_1085 Description: https://exams.giac.org/images/logos/giac_silver_small.gif GIAC

Re: PEAP w/ freeradius to LDAP storing ntPassword not working

2010-11-05 Thread schilling
I asked the ldap admin to change the format of the ntPassword to prepend with 0x, now radius -X get the right hash, but it still have no known good password was found in LDAP. Nevertheless, the authorization is ok. What is the right format to put in our ldap ntPassword attribute? Should I ignore

EAP proxy (documentation) issue

2010-11-05 Thread Edgar Fuß
While setting up proxying for EAP, I ran into the issue that only the first packet was proxied to the home server. Fortunately, I found the explanation in the list archive that the ok = return line in the eap configuration section of the default virtual server leads to the files section not

Re: 20k r/s hardware requirements

2010-11-05 Thread Alan DeKok
Eichinger, Rene (NSN - AT/Wien) wrote: I need to figure out hardware requirements for a freeradius installation for ~20.000 requests per second. Is this the right place to get this information? As your colleague was told in private email, that question is impossible to answer. It's too

samba version

2010-11-05 Thread MONTFORD, AUSTIN
Is there a particular version of samba that runs better than others for ntlm_auth? I have a ubuntu lucid test server that authenticates wireless users fine using ntlm_auth on initial logins, but randomly it will start failing reauth attempts on laptops that have been logged in for a while. I

Re: Doubt - Freeradius + Ldap

2010-11-05 Thread Eduardo Moreira
sorry, but where i checked the shared secret? in clients.conf? if yes, secret is ok! thanks for any help. On 11/04/2010 09:51 AM, eduardo moreira wrote: SOrry about this mail Josip, but i checked again my clients.conf, and i put conf here for u see. clients.conf client 127.0.0.1 {

Re: Doubt - Freeradius + Ldap

2010-11-05 Thread Phil Mayers
On 11/05/2010 06:47 PM, Eduardo Moreira wrote: sorry, but where i checked the shared secret? in clients.conf? Yes if yes, secret is ok! No it isn't; look at the packet: Mon Nov 1 15:06:16 2010 : Debug: Ready to process requests. rad_recv: Access-Request packet from host 10.12.60.19

Re: Doubt - Freeradius + Ldap

2010-11-05 Thread Michael Lecuyer
There's many a slip 'twixt the cup and the lip I promise you'll want to kick yourself when you find the simple difference after so many messages. Many of us have the grace to go through this necessarily humbling exercise in private. On 2010-11-05 2:47 PM, Eduardo Moreira wrote: sorry, but

Re: Doubt - Freeradius + Ldap

2010-11-05 Thread John Dennis
On 11/05/2010 03:06 PM, Phil Mayers wrote: On 11/05/2010 06:47 PM, Eduardo Moreira wrote: sorry, but where i checked the shared secret? in clients.conf? Yes if yes, secret is ok! No it isn't; look at the packet: Mon Nov 1 15:06:16 2010 : Debug: Ready to process requests. rad_recv:

Re: Doubt - Freeradius + Ldap

2010-11-05 Thread Eduardo Moreira
Thanks john , i install in debian server, default config, apt-get install Directory is: /etc/freeradius ; Sorry, im newbie, but before i configure ldap module freeradius work, after configure ldap module, no way to connect, certain my problem stays with module ldap, authentication ...

Re: PEAP w/ freeradius to LDAP storing ntPassword not working - resolved

2010-11-05 Thread schilling
I am able to have peap/mschpv2 work with ldap nt hash. radtest -t mschap will not work for peap/mschapv2, the real windows supplicant, wireless access point will work. The format in ldap is not relevant, w/ or w/o the preceding 0x will work. The configuration I changed from default are the

RE: freeradius and Cisco VPN IPSEC profiles authentication

2010-11-05 Thread Jevos, Peter
Hi How can I skip to the second DEFAULT if the first DEFAULT doesn't pass ? So if request comes from the 10.1.1.2 and user doesn't pass through authentication, it should be forwarded to another DEFAULT ( with the vpn_auth_name authentication). Now it stops at the first DEFAULT DEFAULT