freeradius-client lib documentation

2011-07-11 Thread Kevin Lemonnier
Hello, I have to make an application using a RADIUS lib. I want to use the freeradius-client lib, but I can't find the documentation. I downloaded the bz2 archive as said on the wiki, and installed it, but I don't have any help with it, neither ad in the wiki. Is there a doc somewhere ? A

Re: Freeradius 2.1.10: authentication (uid and password) or (macaddress)?in LDAP

2011-07-11 Thread Maciej Łukasz Wojszkun
Hello, W dniu 7/7/11 9:26 PM, Alexander Clouter pisze: Maciej ??ukasz Wojszkun maciej.wojsz...@blstream.com wrote: (..) On a wired socket, with Cisco kit at least, you do get the option to try a MAC-auth first, and if the RADIUS server comes back with Access-Reject then the switch will

Re: freeradius-client lib documentation

2011-07-11 Thread Alan DeKok
Kevin Lemonnier wrote: I have to make an application using a RADIUS lib. I want to use the freeradius-client lib, but I can't find the documentation. I downloaded the bz2 archive as said on the wiki, and installed it, but I don't have any help with it, neither ad in the wiki. Is there a doc

MySQL Collation and Multiple Login Possibility Help

2011-07-11 Thread Deepak
Hi all, This is a chilli+FR implementation and running well. Today by accident, I found out that multiple login is possible for the same account. Although Attribute (User-Password) is treated case-sensitive, 'username' is not during authentication. To further clarify: = Original

MS-CHAP Auth fail, password cache ?

2011-07-11 Thread Bastien Semene
Hi list, I'm currently - trying to - set up a radius server. The backend used is MySQL. I'm using FreeRADIUS 2.1.11 on FreeBSD 8 During my tests, for the same user I used test password, then blabla password. Now, I use blabla and it's not working. instead test is still working ... I tested

Re: MySQL Collation and Multiple Login Possibility Help

2011-07-11 Thread Alan DeKok
Deepak wrote: Today by accident, I found out that multiple login is possible for the same account. Although Attribute (User-Password) is treated case-sensitive, 'username' is not during authentication. ... It seems like it has more to do with MySQL query. Quick googling revealed that query

Re: MS-CHAP Auth fail, password cache ?

2011-07-11 Thread Alan DeKok
Bastien Semene wrote: I'm currently - trying to - set up a radius server. The backend used is MySQL. I'm using FreeRADIUS 2.1.11 on FreeBSD 8 During my tests, for the same user I used test password, then blabla password. Now, I use blabla and it's not working. instead test is still working

Re: MS-CHAP Auth fail, password cache ?

2011-07-11 Thread Alexey Shildyakov
11.07.2011 15:06 пользователь Alan DeKok al...@deployingradius.com написал: Bastien Semene wrote: I'm currently - trying to - set up a radius server. The backend used is MySQL. I'm using FreeRADIUS 2.1.11 on FreeBSD 8 During my tests, for the same user I used test password, then blabla

Re: MS-CHAP Auth fail, password cache ?

2011-07-11 Thread Alan DeKok
Alexey Shildyakov wrote: I think he mean that only first password is worked. The second and third version of tye password for the same user aren't worked. Users have one password. You can't authenticate with any one of three passwords. The authentication protocols just don't work that way.

Re: MS-CHAP Auth fail, password cache ?

2011-07-11 Thread Alexey Shildyakov
11.07.2011 15:18 пользователь Alan DeKok al...@deployingradius.com написал: Users have one password. You can't authenticate with any one of three passwords. The authentication protocols just don't work that way. Think Bastien means this: 1. Start server, user has password password123. 2.

Re: MS-CHAP Auth fail, password cache ?

2011-07-11 Thread Bastien Semene
I express myself very badly, sorry. The configuration I put in my first mail is the current configuration, running, after restart. The debug and commands output are from the current - reloaded - configuration. There's only 1 entry in the radcheck table, and it's current password is blabla.

Re: MySQL Collation and Multiple Login Possibility Help

2011-07-11 Thread Deepak
 raddb/sql/mysql/dialup.conf Using the case sensitive version of query solved the problem. Thanks! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: MS-CHAP Auth fail, password cache ?

2011-07-11 Thread Alan DeKok
Bastien Semene wrote: I express myself very badly, sorry. The configuration I put in my first mail is the current configuration, running, after restart. The debug and commands output are from the current - reloaded - configuration. There's only 1 entry in the radcheck table, and it's

TTLS OSX Airport Connection Dropping

2011-07-11 Thread Matt Hopkins
I have a setup with four Linksys E4200 wireless routers all sharing the same SSID. All are configured to authenticate against the same freeradius server via WPA 2 enterprise. I have freeradius (2.1.7) setup to authenticate against activedirectory using ntlm_auth via TTLS and mschap. Android and

Re: MS-CHAP Auth fail, password cache ?

2011-07-11 Thread Bastien Semene
... that's it. I was blind while searching for a FreeRADIUS issue. I'm sorry for the lost time, anyway thank you for the answers. Le 11/07/2011 14:22, Alan DeKok a écrit : Bastien Semene wrote: I express myself very badly, sorry. The configuration I put in my first mail is the current

Tunneled-User-Name

2011-07-11 Thread d . thembiliyagoda
Hi, I am using EAP-TTLS and MSCHAPv2 to authenticate with FreeRadius server.How can I get the tunnelled User-Name (User-Name used in inner authentication phase) using unlang in FreeRADIUS server? Now I can only get the User-Name used for the outer authentication (ex: anonymous). Best Regards

Re: Tunneled-User-Name

2011-07-11 Thread Alan DeKok
d.thembiliyag...@lancaster.ac.uk wrote: I am using EAP-TTLS and MSCHAPv2 to authenticate with FreeRadius server.How can I get the tunnelled User-Name (User-Name used in inner authentication phase) using unlang in FreeRADIUS server? It's available in the inner-tunnel virtual server. Now I

Re: Tunneled-User-Name

2011-07-11 Thread d . thembiliyagoda
Thank you very much. Regards Champika On Mon, 11 July, 2011 4:06 pm, Alan DeKok wrote: d.thembiliyag...@lancaster.ac.uk wrote: I am using EAP-TTLS and MSCHAPv2 to authenticate with FreeRadius server.How can I get the tunnelled User-Name (User-Name used in inner authentication phase) using

Re: TTLS OSX Airport Connection Dropping

2011-07-11 Thread Alan DeKok
Matt Hopkins wrote: The error occurs in four macbook pro's tested. Sounds like a problem with the linksys APs. The site I'm at has multiple macbook pro's with 10.6.8 using TTLS, and they all work fine. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Tunneled-User-Name

2011-07-11 Thread Alexander Clouter
d.thembiliyag...@lancaster.ac.uk wrote: I am using EAP-TTLS and MSCHAPv2 to authenticate with FreeRadius server.How can I get the tunnelled User-Name (User-Name used in inner authentication phase) using unlang in FreeRADIUS server? Now I can only get the User-Name used for the outer

freeradius

2011-07-11 Thread Roldanis Pozo Disotuar
regards I wish I could use the freeradius that I have to determine the phone number originating the call and if this does not match the number on the database access denied Roldanis La calidad depende de EICMA, la decisión de usted - List

Re: TTLS OSX Airport Connection Dropping

2011-07-11 Thread Terry Simons
It wouldn't hurt to file a bug at bugreporter.apple.com. What version of firmware does your e4200 have? I have access to a unit that I can test with. - Terry On Mon, Jul 11, 2011 at 5:26 AM, Matt Hopkins thematthopk...@gmail.com wrote: I have a setup with four Linksys E4200 wireless routers

Re: freeradius

2011-07-11 Thread Alan DeKok
Roldanis Pozo Disotuar wrote: I wish I could use the freeradius that I have to determine the phone number originating the call and if this does not match the number on the database access denied Do you see the phone number in a RADIUS packet? If yes, check it. If no, it's impossible.

Re: freeradius

2011-07-11 Thread Roldanis Pozo Disotuar
regards The modem zyxel utilis are U-90E and I have caller ID enabled on phone lines, modems are served by portslave, but how to make Nose portslave ask for the numbers they call ara identify the origin of llmadas. Roldanis La calidad

Re: freeradius

2011-07-11 Thread Arran Cudbard-Bell
On Jul 11, 2011, at 8:25 PM, Roldanis Pozo Disotuar wrote: regards The modem zyxel utilis are U-90E and I have caller ID enabled on phone lines , modems are served by portslave, but how to make Nose portslave ask for the numbers they call ara identify the origin of llmadas. By reading

Tunneled-User-Name

2011-07-11 Thread d . thembiliyagoda
Hi, I edit the inner-tunnel virtual server configuration file and uncomment the example policy under post-auth section. update outer.reply { User-Name := %{request:User-Name} } But in Access-Accept still the User-Name is anonymous. Here is the debug output of the

Re: freeradius

2011-07-11 Thread Arran Cudbard-Bell
On Jul 11, 2011, at 8:37 PM, Roldanis Pozo Disotuar wrote: you could give me some items to help me solve this problem you could send the freeradius configuration files and portslave for review to see if I make a mistake and solocionarlo It looks like it should be possible, someone

Re: freeradius

2011-07-11 Thread Arran Cudbard-Bell
On Jul 11, 2011, at 9:00 PM, Roldanis Pozo Disotuar wrote: I understand perfectly, but could see the settings I used in freeradius to see if all is well There are no settings in FreeRADIUS which will make the portslave send the Caller ID. If you want us to check to see if the value is

Status of the project

2011-07-11 Thread Alan DeKok
This email is to keep everyone up to date with respect to the project. As people may have noticed, Arran Cudbard-Bell is now posting messages from the freeradius.org domain. Until now, I've been the only person with an address at freeradius.org. Arran is contributing on a number of

RE: Status of the project

2011-07-11 Thread Gary Gatten
Welcome Arran! I'm hoping your responses will contain all the witty banter and helpful criticism as Mr. DeKoks? :) -Original Message- From: freeradius-users-bounces+ggatten=waddell@lists.freeradius.org [mailto:freeradius-users-bounces+ggatten=waddell@lists.freeradius.org]

Re: Status of the project

2011-07-11 Thread John Dennis
On 07/11/2011 04:39 PM, Alan DeKok wrote: Please welcome Arran as a core contributor to FreeRADIUS. Welcome Arran!! Great to have another developer on board. We all extend our heartfelt thanks to you (and Alan of course). -- John Dennis jden...@redhat.com Looking to carve out IT costs?

Re: Status of the project

2011-07-11 Thread Marinko Tarlac
The famous sentence: Run the server in debugging mode as suggested in the FAQ, README, INSTALL, man page, and daily on the mailing list. Welcome Arran and best regards On 7/11/2011 10:44 PM, Gary Gatten wrote: Welcome Arran! I'm hoping your responses will contain all the witty banter and

Re: Status of the project

2011-07-11 Thread Arran Cudbard-Bell
On Jul 11, 2011, at 10:44 PM, Gary Gatten wrote: Welcome Arran! I'm hoping your responses will contain all the witty banter and helpful criticism as Mr. DeKoks? :) You need to rack up a considerable number of 'list hours' to be able to answer queries as deftly and succinctly as Alan.

rlm_sql and read_groups

2011-07-11 Thread Jacob Dawson
We're trying to get FreeRADIUS to get at the user info in our Oracle DB, and it does not appear to be respecting the read_groups = yes setting in sql.conf. Forex: [sql] WARNING: Deprecated conditional expansion :-. See man unlang for details [sql] ... expanding second conditional [sql]

Re: Default tables

2011-07-11 Thread Luke Hammond
Thanks Alan, i have another question regarding this. I have inported the schema.sql and i get 7 tables in the database. Am i to assume that this is all working? Just that i remeber a while ago i followed a tutorial for using Freeradius2 with daloRADIUS for management, and i had around 20

Yet another multiple SSID setup question

2011-07-11 Thread Nick Kartsioukas
I've been looking through the wiki and staring at the config files and I'm...confused. I've successfully gotten our Cisco WLC to authenticate against ActiveDirectory as well as a Sun LDAP server (just one at a time) via FreeRADIUS for a single test SSID, but now I'm trying to figure out how to