First-Login

2011-05-04 Thread Rtz Poknat
can u help me how can CAN I DO THIS in freeradius its like i want a certain user to be expired after x minutes since his first login thanks- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Adding Vendor Specific Attribute to the Access-Accept

2011-05-04 Thread normal ozone
Thanks for the reply. Correct me if I'm wrong but the NAS is the one sending authentication requests to the radius server? In my setup's case the one sending radius requests is a PC. I'm using the TinyRadius library. So technically I can use any of the radius attributes. I plan to use a

Re: Multiple ldaps (SSL) backends and only the first queried works.?Possible bug?

2011-05-04 Thread Daniele Albrizio
On 03/05/11 21:41, Alexander Clouter wrote: Daniele Albrizio albri...@univ.trieste.it wrote: I suspect the cacertfile attribute is not correctly re-instantiated and only the value of the first request is used to check against when instantiating a new ldaps connection. Without a doubt the

FR 2.1.x git + SoH: ASSERT FAILED xlat.c[1048]: outlen 0

2011-05-04 Thread James J J Hooper
Hi All, Sorry for the sketchy details We got an ASSERT FAILED xlat.c[1048]: outlen 0 with a PEAP user. The bit of the -X I have is as below, and the soh virtual server config is attached. I have no further details at the moment because the client has gone away (and I've disabled SoH in

Re: FR 2.1.x git + SoH: ASSERT FAILED xlat.c[1048]: outlen 0

2011-05-04 Thread Phil Mayers
On 04/05/11 10:42, James J J Hooper wrote: Hi All, Sorry for the sketchy details We got an ASSERT FAILED xlat.c[1048]: outlen 0 with a PEAP user. The bit of the -X I have is as below, and the soh virtual server config is attached. I have no further details at the moment because the client

Re: FR 2.1.x git + SoH: ASSERT FAILED xlat.c[1048]: outlen 0

2011-05-04 Thread Phil Mayers
On 04/05/11 10:42, James J J Hooper wrote: Hi All, Sorry for the sketchy details We got an ASSERT FAILED xlat.c[1048]: outlen 0 with a PEAP user. The bit of the -X I have is as below, and the soh virtual server config is attached. I have no further details at the moment because the client

Nexus Configurations

2011-05-04 Thread Darren Shaw
Good Morning I am new to this forum and to the workings of FreeRadius and I have a query around the Cisco Nexus family. Currently we have all our switches and routers authentication to FreeRadius and all seems to be working. The problem comes when I want to authenticate my Nexus 7K and 5K's.

Re: Multiple ldaps (SSL) backends and only the first queried works.?Possible bug?

2011-05-04 Thread Phil Mayers
On 04/05/11 09:37, Daniele Albrizio wrote: On 03/05/11 21:41, Alexander Clouter wrote: Daniele Albrizioalbri...@univ.trieste.it wrote: I suspect the cacertfile attribute is not correctly re-instantiated and only the value of the first request is used to check against when instantiating a new

Re: Nexus Configurations

2011-05-04 Thread David Mitchell
On May 4, 2011, at 4:48 AM, Darren Shaw wrote: Good Morning I am new to this forum and to the workings of FreeRadius and I have a query around the Cisco Nexus family. Currently we have all our switches and routers authentication to FreeRadius and all seems to be working. The problem

Re: FR 2.1.x git + SoH: ASSERT FAILED xlat.c[1048]: outlen 0

2011-05-04 Thread James J J Hooper
On 04/05/2011 11:24, Phil Mayers wrote: On 04/05/11 10:42, James J J Hooper wrote: [updated] returns updated +++- if ((Calling-Station-Id) %{Calling-Station-Id} =~ /^%{config:policy.mac-addr}$/i) returns updated +++ ... skipping else for request 750: Preceding if was taken ++- policy

Re: FR 2.1.x git + SoH: ASSERT FAILED xlat.c[1048]: outlen 0

2011-05-04 Thread James J J Hooper
On 04/05/2011 11:37, Phil Mayers wrote: On 04/05/11 10:42, James J J Hooper wrote: Hi All, Sorry for the sketchy details We got an ASSERT FAILED xlat.c[1048]: outlen 0 with a PEAP user. The bit of the -X I have is as below, and the soh virtual server config is attached. I have no further

[EAP-PEAP] PEAP Authentication failed

2011-05-04 Thread Khalid Staili
I am using freeradius in a wired network. Th authentication protocol I'm using is PEAP. I have configured the server like described in many different sites, but I have a problem. This is the debug output I have : rad_recv: Access-Request packet from host 192.168.0.1 port 1024, id=192, length=204

Re: Multiple ldaps (SSL) backends and only the first queried works.?Possible bug?

2011-05-04 Thread Tanjil Ahmed
Hi all is there anybody can tell me why my mikrotik ppp user sometimes authenticate fail on free radius? how to fix it? after few mins it will be oke... - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Multiple ldaps (SSL) backends and only the first queried works.?Possible bug?

2011-05-04 Thread Phil Mayers
On 05/04/2011 08:46 PM, Tanjil Ahmed wrote: Hi all is there anybody can tell me why my mikrotik ppp user sometimes authenticate fail on free radius? Please don't hijack an existing thread. Start a new one. how to fix it? after few mins it will be oke... You need to give us more

Re: [EAP-PEAP] PEAP Authentication failed

2011-05-04 Thread Phil Mayers
On 05/04/2011 08:27 PM, Khalid Staili wrote: I am using freeradius in a wired network. Th authentication protocol I'm using is PEAP. I have configured the server like described in many different sites, but I have a problem. This is the debug output I have : Most sites on the internet are

about FreeRadius+radiusmanager+mirkotik

2011-05-04 Thread Tanjil Ahmed
Dear All im really need help bout those issues some of my user trying to login Mikrotik but they cant first time.. Radius Server Reject thier query after fewmins they can able to login anybody can pls email with best configure of radiusd.conf of freeradius-server-2.1.8-dmamod-2 Note:im using

Re: [EAP-PEAP] PEAP Authentication failed

2011-05-04 Thread Khalid Staili
I think the configuration is correct, because I have an Access-Accept when I use an eapol_test to test my server locally (localhost client). But when I use wpa_supplicant with the same configuration in an other host using ubuntu 10.10, I have the error I have mentionned. 2011/5/4 Phil Mayers

RE: about FreeRadius+radiusmanager+mikrotik

2011-05-04 Thread Garber, Neal
some of my user trying to login Mikrotik but they cant first time.. You may find that it will be easier for people to help you if you provide specific details about the problems you are having and what you've done in an attempt to fix the problems. You should start by doing Internet searches

Re: about FreeRadius+radiusmanager+mikrotik

2011-05-04 Thread Tanjil Ahmed
Thanks for your quick Reply here is my Error rad_recv: Access-Request packet from host 10.10.0.2 port 48125, id=171, length=136 Service-Type = Framed-User Framed-Protocol = PPP NAS-Port = 8744 NAS-Port-Type = Ethernet User-Name = mizanes

Re: [EAP-PEAP] PEAP Authentication failed

2011-05-04 Thread Alan Buxey
hi, looks like your client is trying to use the wrong CA as part of the authentication. alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: about FreeRadius+radiusmanager+mikrotik

2011-05-04 Thread Alexander Clouter
Tanjil Ahmed tan...@tanjil.net wrote: after few mins he can able to login.. pls help me to solve this problem! ...only if you help us to help you. http://wiki.freeradius.org/index.php/FAQ#It_still_doesn.27t_work.21 http://wiki.freeradius.org/index.php/FAQ#Debugging_it_yourself