Re: Debugging "No EAP session matching the State variable"

2013-09-16 Thread A . L . M . Buxey
Hi, > Sep 16 09:57:56 newdvlanb radiusd[15211]: rlm_eap: No EAP session > matching the State variable. turn on full debug for just a single User-Name or Calling-Station-Id (check radmin docs). whats your authentication clean-up/tidy up times - as if the clients dont respond then the session is cl

Debugging "No EAP session matching the State variable"

2013-09-16 Thread John Douglass
I run two freeradius servers (both 2.2.0 x86_64) with MySQL backends doing ntlm_auth (RHEL 6 Samba 3.6.9) for EAP-PEAP-MSChapV2 for our client devices. I have enabled the server debug using radmin (the debug file is HUGE so that is why I am not posting it along with). I have googled and re

Re: Freeradius + 2 x LDAP + VLAN

2013-09-16 Thread Miroslav Lednicky
Thank you, it works with simple modification (not too effective): ldap1 if (ok) { update reply { Tunnel-Type = VLAN Tunnel-Medium-Type = IEEE-802 Tunnel-Private-Group-Id = 1

Re: Last call for Version 2.2.1

2013-09-16 Thread Arran Cudbard-Bell
On 16 Sep 2013, at 16:08, Alan DeKok wrote: > a.l.m.bu...@lboro.ac.uk wrote: >> ..so many new features... thought 3.x was where the new features and dev >> work was going into ;-) > > Well, yes. 2.2.1 has a lot of tiny features that are minor code > changes. v3 is nearly everything re-writt

Re: Last call for Version 2.2.1

2013-09-16 Thread Alan DeKok
a.l.m.bu...@lboro.ac.uk wrote: > ..so many new features... thought 3.x was where the new features and dev work > was going into ;-) Well, yes. 2.2.1 has a lot of tiny features that are minor code changes. v3 is nearly everything re-written or updated. Those re-writes allow the addition of ma

Re: Freeradius 2.1.12 Second LDAP Server

2013-09-16 Thread A . L . M . Buxey
Hi, >Could not authenticate user Username%Password with plaintext password >challenge/response password authentication succeeded thats okay. means you couldnt do PAP and only MSCHAPv2 worked. expected for that command. >In this Step, i must edit the following line with this text in

Re: Last call for Version 2.2.1

2013-09-16 Thread A . L . M . Buxey
Hi, ..so many new features... thought 3.x was where the new features and dev work was going into ;-) PS has anyone tested it with MariaDB? Wondering if its 100% drop-in compatible? (I'm postgres myself but looks like MySQL is dying) alan - List info/subscribe/unsubscribe? See http://www.freerad

Re: Freeradius 2.1.12 Second LDAP Server

2013-09-16 Thread Alan DeKok
Beliars Fire wrote: > The next Step wbinfo -a *user*%*password *works too, but i`m getting > this Error-Message: > > /Could not authenticate user Username%Password with plaintext password/ > challenge/response password authentication succeeded > > Is this normal? How can I fix it? The Response se

RE: Freeradius 2.1.12 Second LDAP Server

2013-09-16 Thread Beliars Fire
Hi, thanks for the Help. Actually im decided to create a new VM and reinstall the complete Server. I`m following the complete How-To, but i`m getting two different Errors. The First One is this: It`s under the first Point: Configuring Authentification with Active Directory I`m startet the

Re: Last call for Version 2.2.1

2013-09-16 Thread Arran Cudbard-Bell
On 16 Sep 2013, at 13:44, Alan DeKok wrote: > The list of changes is large: Seems sort of small to me :) Here's the changelog: https://github.com/FreeRADIUS/freeradius-server/blob/v2.x.x/doc/ChangeLog Arran Cudbard-Bell FreeRADIUS Development Team - List info/subscribe/unsubscribe? See htt

Last call for Version 2.2.1

2013-09-16 Thread Alan DeKok
Unless there are any objections, we'll release 2.2.1 tomorrow. The list of changes is large: https://github.com/FreeRADIUS/freeradius-server/blob/v2.x.x/doc/ChangeLog Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Last call for Version 2.2.1

2013-09-16 Thread Alan DeKok
Unless there are any objections, we'll release 2.2.1 tomorrow. The list of changes is large: - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Windows Phone CA verification debugging

2013-09-16 Thread Mathieu Simon
Hi, 2013/9/16 > > we've had no problems with self-signed CA or with 3rd party CA and standard > RADIUS certificate BUT the certificate must have CRLDP (CRL distribution > point) > URL defined. that can either be at CA level or RADIUS level - or both. > > eg > > crlDistributionPoints = URI:http:/

Re: Windows Phone CA verification debugging

2013-09-16 Thread A . L . M . Buxey
Hi, >encountering some issues with those (yet quite rare) people with Windows >Phone 8 (WP8) systems. >WP8 devices are yet able to connect without (any) CA or common name >verification, but seem >to fail when I let them check the CA by choosing it from the device' CA >stor