Re: Freeradius not releasing IPs from pool

2011-06-07 Thread Angel L. Mateo
Hello, I have found the problem... I have my freeradius servers being monitored by a system. This monitoring user was assigned to a pool, but it didn't send any stop account record, so IPs were never released. I have configured this user to not being assigned to any pool and the system

RE: Slow Mysql Queries

2011-06-07 Thread OzSpots - Carl Sawers
Thanks for the help Fajar, We wish to fix this in house so don't want to pay for a dba BUT we are not getting much closer to the issue though I have found that a lot of the tables are actually indexed I just didn't know where to look. PHPmyadmin runtime info states that  Select_full_join  

Re: Slow Mysql Queries

2011-06-07 Thread Fajar A. Nugraha
On Tue, Jun 7, 2011 at 2:38 PM, OzSpots - Carl Sawers c...@ozspots.com.au wrote: Thanks for the help Fajar, We wish to fix this in house so don't want to pay for a dba BUT we are not getting much closer to the issue though ... because you lack the skill of a DBA. I have found that a lot

Re: Slow Mysql Queries

2011-06-07 Thread Marinko Tarlać
One of the servers I maintain has 18 qps average and the load is 0.62,0.54,0.63 (1min, 5min, 15min) Beside the database and radius, that server is used for hundred other things and it works perfectly (1GB of RAM, dual core CPU) The point is not how much queries per second do you have. You can

Re: how to output that attribute value as raw data?

2011-06-07 Thread Alan DeKok
ichiro tanaka wrote: I've tried that beoame a %{Acct-Status-Type#} - 1. But, %{Packet-Type#} - . (%{Packet-Type} - Access-Accept) Packet-Type's type is INTEGER. Is freeradius internal attributes off the subject? Unfortunately, it doesn't work for Packet-Type. Maybe in a future release.

Same secret? (Noob question)

2011-06-07 Thread Lorenzo
Hi guys! I don't want to share the radius server secret whith determinate clients. So I choose to configure a radius server as a proxy, to link to the original server and the clients. The question is, the secret between the server and the proxy, and the on between the proxy and the clients, must

Multiple instance of an attribute in Access-Accept

2011-06-07 Thread Martin
Hi, I am trying to send in access accept an attribute two times, for example Packet-Flow-Descriptor but it seems that are mixed up or missing on the wire. I am using freradius 3.0 with Mysql This is the user definition: ++---+---+--+

Re: Same secret? (Noob question)

2011-06-07 Thread Phil Mayers
On 07/06/11 10:56, Lorenzo wrote: Hi guys! I don't want to share the radius server secret whith determinate clients. So I choose to configure a radius server as a proxy, to link to the original server and the clients. The question is, the secret between the server and the proxy, and the on

[no subject]

2011-06-07 Thread arpitha arpitha
which is the latest version of php_radius.dll and pls post a link to it. Advance thnks - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re:

2011-06-07 Thread Phil Mayers
On 07/06/11 12:19, arpitha arpitha wrote: which is the latest version of php_radius.dll and pls post a link to it. This is not a FreeRADIUS question. This is a PHP question. Please ask it on a PHP mailing list. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Multiple instance of an attribute in Access-Accept

2011-06-07 Thread Alan DeKok
Martin wrote: I am trying to send in access accept an attribute two times, for example Packet-Flow-Descriptor but it seems that are mixed up or missing on the wire. I am using freradius 3.0 with Mysql Use +=, not :=. See man unlang, or doc/rlm_sql Alan DeKok. - List

Re: freeradius 2.1.10 WARNING: Internal sanity check failed

2011-06-07 Thread joanroldan
Hi, After failing to set an EAP-MSCHAP environment with certificates by default, I have handled a production certified by a CA signer. With these certificates I do not get the warning of compatibility with Windows. But the warning which I opened this post appears again: Info: WARNING: Internal

Re: freeradius 2.1.10 WARNING: Internal sanity check failed

2011-06-07 Thread Alan DeKok
joanroldan wrote: Info: WARNING: Internal sanity check failed in event handler for request 1: Discarding the request! See http://git.freeradius.org/ and grab the v2.1.x branch Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Expand Ldap Attribute on Post-Auth section

2011-06-07 Thread Renan
So, according to this: http://wiki.freeradius.org/Attribute%20support%20by%20processing%20list I can only access the User-Name and Auth-Type at my custom exec module, and nothing else? I just want to access an LDAP value at my exec module without having to issue an external ldapsearch and

Re: Expand Ldap Attribute on Post-Auth section

2011-06-07 Thread Alan DeKok
Renan wrote: So, according to this: http://wiki.freeradius.org/Attribute%20support%20by%20processing%20list I can only access the User-Name and Auth-Type at my custom exec module, and nothing else? Uh, no. The wiki page needs to be reformatted. Each module has access to *all* of the

Re: Renaming during Machine Authentication

2011-06-07 Thread mjonesmcne
Is there any documentation someone can point me to on doing machine authentication with edirectory, or with an ldap backend? Thanks Mark -- View this message in context: http://freeradius.1045715.n5.nabble.com/Renaming-during-Machine-Authentication-tp4394421p4462448.html Sent from the

Re: Expand Ldap Attribute on Post-Auth section

2011-06-07 Thread John Center
Hi Alan, On 06/07/2011 01:30 PM, Alan DeKok wrote: Renan wrote: So, according to this: http://wiki.freeradius.org/Attribute%20support%20by%20processing%20list I can only access the User-Name and Auth-Type at my custom exec module, and nothing else? Uh, no. The wiki page needs to be

Re: Renaming during Machine Authentication

2011-06-07 Thread Alan DeKok
mjonesmcne wrote: Is there any documentation someone can point me to on doing machine authentication with edirectory, or with an ldap backend? Nope. The machine authentication passwords are normally controlled by Active Directory. Your role is to find out what password the machine is

Re: Expand Ldap Attribute on Post-Auth section

2011-06-07 Thread Alan DeKok
John Center wrote: We talked about this, there isn't any more content there. Someone needs to rewrite this page. mediawiki.freeradius.org should now work. The contents can be copied from there. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Wiki - Once upon a time there was documentation

2011-06-07 Thread Arran Cudbard-Bell
The FreeRADIUS mailing list doesn't have an official web frontend, it's mirrored by services like nabble which are in no way associated with the project. People just use their email client... Wikicloth (the media wiki parsing engine) sucks more than we'd anticipated. It often stops processing

Re: Expand Ldap Attribute on Post-Auth section

2011-06-07 Thread John Center
On 06/07/2011 02:22 PM, Alan DeKok wrote: John Center wrote: We talked about this, there isn't any more content there. Someone needs to rewrite this page. mediawiki.freeradius.org should now work. The contents can be copied from there. Still no more content, see

Re: Expand Ldap Attribute on Post-Auth section

2011-06-07 Thread Renan
Em 07-06-2011 14:30, Alan DeKok escreveu: You can't use RADIUS to query LDAP from an exec module. It's not a query per say, I would be acessing a variable that was already **set** by the LDAP module (That's why I specified it at ldap.attrmap). Each module has access to*all* of the

Re: Expand Ldap Attribute on Post-Auth section

2011-06-07 Thread Alan DeKok
Renan wrote: So all of the attributes are available except the ones that Ldap module fetched (for example: NT-Password, Password-With-Header, my custom defined: Aa, etc...). As a test, at my exec module I did: env /tmp/temp_file.txt to see wich variables are exported, here is the result:

Re: Expand Ldap Attribute on Post-Auth section

2011-06-07 Thread Arran Cudbard-Bell
On Jun 7, 2011, at 1:07 PM, John Center wrote: On 06/07/2011 02:22 PM, Alan DeKok wrote: John Center wrote: We talked about this, there isn't any more content there. Someone needs to rewrite this page. mediawiki.freeradius.org should now work. The contents can be copied from there.

Re: Problem with rml_sqlcounter with GigaByte datavolume

2011-06-07 Thread Hanno Schupp
Hi Yves, thanks for your response. I understand the difference between the storing gigawords in the database and the sqlcounter response. I do not speak C, but have no doubt that what you are saying is correct. I just find it hard to believe that FreeRadius has such a basic limitation, which it