Re: Freeradius2 and OSX clients no TLS

2011-03-06 Thread Phil Mayers
On 03/05/2011 04:46 PM, Guy wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I'm setting up Freeradius2 (FreeRADIUS Version 2.1.7) for WPA Enterprise 2, and I have it basically working. my iPhone/iPad are able to authenticate and connect via the base station. However my Mac (OSX 10.6

Re: Freeradius2 and OSX clients no TLS

2011-03-06 Thread Guy
On 6 Mar 2011, at 13:03, Phil Mayers wrote: On 03/05/2011 04:46 PM, Guy wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I'm setting up Freeradius2 (FreeRADIUS Version 2.1.7) for WPA Enterprise 2, and I have it basically working. my iPhone/iPad are able to authenticate and

Re: Freeradius2 and OSX clients no TLS

2011-03-06 Thread James J J Hooper
--On 6 March 2011 16:31:54 + Guy g...@britewhite.net wrote: On 6 Mar 2011, at 13:03, Phil Mayers wrote: On 03/05/2011 04:46 PM, Guy wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I'm setting up Freeradius2 (FreeRADIUS Version 2.1.7) for WPA Enterprise 2, and I have it

Re: Freeradius2 and OSX clients no TLS

2011-03-06 Thread Alan Buxey
Hi, I changed default_eap_type=md5 to default_eap_type=ttls and now the Macs are able to authenticate without Certs or any configuration on their side!! I'm guessing that MD5 isnt a valid 'ready ticked' EAP type by default. you would probably be okay putting eg default_eap_type=peap

decoupled accounting cron check

2011-03-06 Thread Alexander Clouter
Hi, For those out there using decoupled accounting, especially in an 'eduroam' environment, might find the following helpful. I receive a lot of random rubbish from the various NAS's deployed internationally send to my FreeRADIUS installation. Such moments of fun are accounting stop packets

Re: decoupled accounting cron check

2011-03-06 Thread Arran Cudbard-Bell
So does the detail reader read the packet, find that its invalid and then retry the same packet? -Arran On Mar 6, 2011, at 2:37 PM, Alexander Clouter wrote: Hi, For those out there using decoupled accounting, especially in an 'eduroam' environment, might find the following helpful. I

Re: decoupled accounting cron check

2011-03-06 Thread Alan DeKok
Alexander Clouter wrote: The unfortunate outcome means after a bad accounting packet, the mountpoint I use for recording my journal fills up until FreeRADIUS hangs with no warning (meanwhile FreeRADIUS works fine so it is not something trivially monitored by NAGIOS or such). 2.1.10 has

Re: decoupled accounting cron check

2011-03-06 Thread Alexander Clouter
Arran Cudbard-Bell a.cudba...@gmail.com wrote: So does the detail reader read the packet, find that its invalid and then retry the same packet? Yes...after waiting 30 seconds then retrying. For 'valid' packets, it is handy, as I get to fix my SQL, but there will come a point where is

How to know and limit the freeradius-client

2011-03-06 Thread Spacelee
I have pptp + ppp, l2tp + ppp, openvpn to connect to the same freeradius to authenticate, and my question is how to meet this need: I want to limit some user could just access pptp, some could just access l2tp, and some could just access openvpn. and is there any variable in freeradius to