Re: No EAP-TLS with XP SP3 ?

2009-01-12 Thread A . L . M . Buxey
Hi, With XP SP3 the auth failed, I googled that FR 1.1.0 is not capable to do this, because SP3 is realizing the same 802.1x engine as Vista does. So I upgraded to 2.1.3 and compiled it on OpenSuse 10.1 without errors and the software runs without problems. But the auth still doesn't

Re: Error in test Freeradius

2009-01-12 Thread A . L . M . Buxey
Hi, Can someone help me? I'm sure someone can - please send output of 'radiusd -X' to this list as per the FAQ, the docs in the server and the many many such requests to this list alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Error in test Freeradius

2009-01-12 Thread A . L . M . Buxey
Hi, Hello Luciano, In below the result of command: I have a user in BD: do you read documents? is so, which document did you read to set this up? it should be ++--+-+++ | id | username | attribute | op | value |

Re: eap/tls freeradius openssl

2009-01-12 Thread A . L . M . Buxey
hi, did you follow the fedora/redhat quid as posted to this list - or did you just install openssl-devel and try the daemon again? if so, that wont work. you will need to rerun the ./configure and make steps again for the system to learn your got the SSL support installed..and thus compile in

Re: eap/tls freeradius openssl

2009-01-12 Thread A . L . M . Buxey
Hi, I installed the openssl and openssl-devel rpms and the freeradius SRPM with all dependency rpms... ..but before you ran your own version up? if so, you're still running your own version which radiusd will probably say /usr/local/sbin/radiusd you need to run the version the SRPMS would

Re: freeradius not start after upgrade from 1.1.7 to 2.1.0

2009-01-09 Thread A . L . M . Buxey
Hi, Hi all, i'm new on this ML. I've problem after upgrading from v1 to v2 the log section for freeradius v2 has changed a lot since version 1- so if you're using the same config file then it wont work. and using the same config file is VERY BAD what you need to do is backup your V1 config,

Re: Some help with etc_smbpasswd auth and eap ttls

2009-01-07 Thread A . L . M . Buxey
Hi, I have configured everything and gotten free radius to authenticate off /etc/samba/smbpasswd via the etc_smbpasswd module. The problem I have run into is when I switch the securew2 windows xp eap-ttls client to use the current logged on user credentials. Then, SecureW2 sends the

Re: rlm_perl - dbi - freetds works on radiusd -X but fails to sql connect in background

2009-01-07 Thread A . L . M . Buxey
hi, do you have eg SELINUX running on this system? if so, then it may be blocking access between the processes. check your selinux log (or change the mode to permissive and check logs!) and then edit the selinux config to allow operation alan - List info/subscribe/unsubscribe? See

Re: radiusd logs good passwords even when told not to?

2009-01-06 Thread A . L . M . Buxey
Hi, Background info: yes, ancient version Our /etc/raddb/radiusd.conf clearly states to not log passwords: # allowed values: {no, yes} # log_auth_badpass = no log_auth_goodpass = no correct - in the main log However it's logging good password auth's still.. no, this is the detail

Re: Freeradius process dies with some (bad?!) EAP requests

2009-01-06 Thread A . L . M . Buxey
Hi, and we're facing a strange and very critical problem. Occasionally radius server just dies with no apparent reason. When I look at I've had similar issues and would recommend upgrading to latest issue - many many EAP issues were addressed during the more to 2.1.x alan - List

Re: Radreply Table

2009-01-06 Thread A . L . M . Buxey
Hi, Hi! I have 2 freeradius servers running, one at 2.0.4 version and other at 2.0.5. On 2.0.4 i can use radreply without problem, but in 2.0.5 i can`t, the freeradius server don`t read the table. The two server have the same configuration. they talking to same database? are the

Re: radiusd logs good passwords even when told not to?

2009-01-06 Thread A . L . M . Buxey
Hi, I have no need for a details log the data stored in /var/log/radius.log is more than sufficient for me. So by commenting out detail { } in the radiusd.conf file should stop this? you will also need to remove the calls to that detail config in various other places in the config. I know

Re: NAS-Identifier and radgroupcheck table

2009-01-05 Thread A . L . M . Buxey
Hi, I recently posted a howto explaining how to implement huntgroups in SQL using unlang in 2.x, look in the mail archives. It also illustrates how to use the SQL huntgroups to control logon access based on the NAS. Perhaps I should put this on the wiki. certainly! things posted to this

Re: newbie new freeradius install fails to start...

2009-01-05 Thread A . L . M . Buxey
Hi, A different solution is to fix the bootstrap script to just run the commands directly. I've done that now. good call - a lot of people dont want/need devloper or build tools on their production servers. alan - List info/subscribe/unsubscribe? See

Re: somewhat ot: Check radius server name on linux supplicant

2009-01-05 Thread A . L . M . Buxey
hi, its down to the supplicant to have the option and ability to do these checks. Sure, most of them have a 'is cert okay'? option but if you've chosen to use a public auth then anyone else can get a cert signed by that auth and start playing around...which is a weakness. I'd certainly

Re: [HELP] FreeRadius and External Script

2009-01-05 Thread A . L . M . Buxey
Hi, When i start manually the script, we have: ./example.pl: line 26: use: command not found ./example.pl: line 29: syntax error near unexpected token `(' ./example.pl: line 29: `use vars qw(%RAD_REQUEST %RAD_REPLY %RAD_CHECK);' how are you running this script manually? looks like you're

Re: [HELP] FreeRadius and External Script

2009-01-05 Thread A . L . M . Buxey
Hi, Ok, now i think's that this script are started but i don't understand hit, he have a lot of sub but sub are not launched. if i understand, i put all of my perl script into the sub test_call no ? its quite easy. in the experimental.conf file you state which routines you would like to

Re: newbie new freeradius install fails to start...

2009-01-02 Thread A . L . M . Buxey
Hi, Maybe someone can guide me out of this maze. I have a new Fedora 10 install running on Dell intel platform. I installed freeradius.i386 0:2.1.3-1.fc10 package using yum installer. All I did before starting in debug mode was edit clients.conf and users file. I get this error at

Re: FreeRADIUS and Foxpro

2009-01-02 Thread A . L . M . Buxey
Hi, Hi, is there anybody having Foxpro as a backend database. Is this possible? Thanks for sharing your experiences. theres no native driver - ODBC would work - whether you'd need to have a PERL or Python wrapper etc to do the dirty work is another question altogether. alan - List

Re: Basic question on rlm_perl

2008-12-18 Thread A . L . M . Buxey
Hi, I have put perl as a module in my radiusd.conf file. I don't file the rlm_perl*.so file in /usr/local/lib/ where all the other rlm_*.so files are located. What am I missing? have you edited experimental.conf to enable PERL and have you included this file in the radiusd.conf or

Re: How to log failed auth attempts?

2008-12-18 Thread A . L . M . Buxey
Hi, The problem seems to be that when a bad password is the reject reason, the Reply-Message is just blank. yep - security reasons. why did I get rejected? ah, because the password was wrong. I'll just keep brute-forcing unti I get the password right.. alan - List

Re: Conf PEAP

2008-12-18 Thread A . L . M . Buxey
Hi, but, if I want the user´s don´t use certificates and only use user pass whit PEAP ¿is posible? - and how, exactly, does the EAP tunnel get set up if you dont have a common certificate to enable such a construct? you've got to have a CA - and, if done properly, you've got to have the

Re: EAP/MD5 with mysql authentication failed

2008-12-17 Thread A . L . M . Buxey
hi, dont set the default auth-type for users alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Duplicate IPs for Radius Clients with different secrets

2008-12-16 Thread A . L . M . Buxey
Hi, I'm not exactly sure. How does a RADIUS server work over the Internet? I'm not connecting the radius clients onto the same LAN. If a radius request comes in from the internet, would the server send responses to the Internet IP that it received it from (which I think would work for my

Re: Duplicate IPs for Radius Clients with different secrets

2008-12-16 Thread A . L . M . Buxey
Hi, Most of these locations will be using dynamic Internet IPs; I'm not sure hmm, in that case I'd advise you to use eg DynDNS , configure the FreeRADIUS to use DNS - and then use the new dynamic clients thing to do a lookup of the IP address v's hostname (a check table) to update the client

Re: Somewhat OT: Captive portal on acess points instead complex supplicant at level end user?

2008-12-14 Thread A . L . M . Buxey
hi, why go backwards when you have the right wireless technology in place? you need to look at the windows client end of things. I'd suggest looking at automating the setup..the best thing would be to have another wireless SSID (eg 'setup for XYZ' - where XYZ is your current SSID) - and have

Re: Building FreeRadius

2008-12-11 Thread A . L . M . Buxey
Hi, I didn't add any user neither password, in fact I followed what I read on the INSTALL file, it indicates to test with this command and I did. you are right - it doesnt. a small oversight I guess. however. reading any other installation and 'how it works' guide will clearly show how to add

Re: Slightly OT: Problem with Vista

2008-12-11 Thread A . L . M . Buxey
hi, which version of FreeRADIUS are you using? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Regarding Dynamic Vlan

2008-12-10 Thread A . L . M . Buxey
Hi, 1.) My Radius Server IP auth = 172.21.185.142, acct = 172.21.185.142 2.) User = alcatel , Domain = adilab.com 3.) User password = alcatel 4.) Authentication: 8021.X , through MD5-Challenge. If possible, kindly provide me the Radius Server COnfiguration for the above mentioned, details

Re: FreeRADIUS Server Version 2.1.2 has been released

2008-12-05 Thread A . L . M . Buxey
hi, having a problem compiling 2.1.2 with the same settings/options as 2.1.1 /bin/sh /usr/src/freeradius-server-2.1.2/libtool --mode=link gcc -release 2.2.0 \ -module -export-dynamic -o rlm_eap.la \ -rpath /usr/lib rlm_eap.lo eap.lo mem.lo rlm_eap.c eap.c mem.c

Re: Building Installing on Red Hat Systems (Was: Make error - Solved)

2008-12-02 Thread A . L . M . Buxey
Hi, There has been a fair amount of confusion over how to get FreeRADIUS packages for Fedora, RHEL, and CentOS, how to perform a build if a pre-built package is not available, and how to do some basic maintenance tasks. it would help immensely if Fedora, RHEL, CentOS et al actually

Re: Building Installing on Red Hat Systems (Was: Make error - Solved)

2008-12-02 Thread A . L . M . Buxey
Hi, The main download page on freeradius.org has a link to: http://koji.fedoraproject.org/koji/packageinfo?packageID=298 Which has RPMs of recent versions. But who reads the web page? your typical rh/fed/centos user would never visit the homepage of the program/utility they are

Re: Is FreeRADIUS 2.1.1 capable of handling NAI decorations

2008-12-02 Thread A . L . M . Buxey
hi, quick hack/fix would be to either 1) set 'prefix' to be } with this, anything before and including } (which may never appear as a realm or username) would be treated like a NT domain and be stripped off logically 2) use attr_rewrite or unlang to remove the {blah blah} stuff and set the

Re: vlan assign - 3com guest vlan

2008-12-02 Thread A . L . M . Buxey
Hi, Hi I put thin on the end of users.conf DEFAULT Auth-Type = Accept Fall-Through = Yes, Tunnel-Medium-Type = 6, Tunnel-Private-Group-Id := 250, Tunnel-Type = VLAN But the resultis still the same, i've got this in debug you need to comment out the line which

Re: Building Installing on Red Hat Systems (Was: Make error - Solved)

2008-12-02 Thread A . L . M . Buxey
Hi, The current version of FreeRADIUS in RHEL5/CentOS is 1.1.3. It is very unlikely the 1.1.3 version will ever be removed from RHEL5 because of the commitment for version stability in an enterprise distribution. On whoah. apart from the fact that 1.1.3 had so many bugs and doesnt work

Re: Centos 5.2 How To

2008-11-27 Thread A . L . M . Buxey
Hi, I have been struggling for days trying to get freeradius installed on Centos 5.2 i386, I get basic pap authentication working but when i try and use authentication with mysql as the db i get errors saying can't find module sql when running radiusd -X As soon as i uncomment sql in

Re: attr_filter issue

2008-11-27 Thread A . L . M . Buxey
Hi, hmm, I'm not sure at all that you can have multi line attr filter matches... ie if you have seperate entries for each allowed type - i think that the very last defined one is the one takenwhat you need to do is have a REGEX for the accetped types eg Trapeze-VLAN-Name ==

Re: Somewhat OT: Mac OS self asigned IP issues

2008-11-27 Thread A . L . M . Buxey
Hi, Through my experience, if you set the dhcp client id to anything (my personal favourite is 'cheese') on the Mac it suddenly bursts into life. Weird I know, but it seems to work... confirmed this behaviour myself - I'm not sure such information is widely known - but its very useful.

Re: SOS FreeRADIUS

2008-11-27 Thread A . L . M . Buxey
hi, Server FreeRADIUS: Bind address: * Port: 0. Must i use Listen options and add the real address? that is 192.168.1.14? you ust configure the listen options. as for using the real address, you should only need to do that if the device had multiple IPs and multiple NICS What about

Re: Centos 5.2 How To

2008-11-27 Thread A . L . M . Buxey
Hi, Just one comment from a system management point of view: if you run CentOS, meant as a stable production OS, you probably wants to care for not screwing up your system. Installing software without an RPM, especially software that already is provided by the distro itself, is the *worst*

Re: Centos 5.2 How To

2008-11-27 Thread A . L . M . Buxey
Hi, Or what else? Is just running ./confugure; make; make install (and not using RPMs at all) better than taking a Fedora src.rpm to start with? for some people, yes (though only so long as all the supporting libraries and dev packages have been installed via RPM first ;-) ) I've gone down

Re: MAC based auth

2008-11-26 Thread A . L . M . Buxey
Hi, now imho cisco switches don't support mac based authentication with freeRadius. They most certainly do. And when you study for your CCNA you will learn how. well, it depends on which Cisco switches you are talking about ;-) alan - List info/subscribe/unsubscribe? See

Re: configure error

2008-11-24 Thread A . L . M . Buxey
Hi, Hi again, It didn't make . It has returned errors. you need to have the readline dev/packages installed readline readline-devel alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS + Cisco Aironet WAP

2008-11-24 Thread A . L . M . Buxey
Hi, Hey, I know this is a bit off-topic, but I was wondering if anyone on the list might be able to help with configuring a Cisco Aironet WAP to authenticate wireless users against a FreeRADIUS server? I just followed the cisco docs for how to configure a Cisco autonomous AP to

Re: question

2008-11-24 Thread A . L . M . Buxey
Hi, Hi Alan - This is a wireless network. If you have a minute could you explain why this is different between `wireless' `wired' system? for wireless 802.1X the cert is used as part of the securing system to create keyed content to ensure the encryption of the data for wired 802.1X

Re: Capture the MAC address of VPN connecting devices in FreeRadius

2008-11-24 Thread A . L . M . Buxey
Hi, Hi Alan; In the Calling-Station-Id i get the device IP Address and not the MAC! luckily you dont get a phone number instead ;-) (RFC 2865) I'm wondering if theres a set in stone standard for Calling-Station-ID ie should it be a MAC or IP address? or am I being very hopeful? alan -

Re: VMPS - Initial project ideas

2008-11-03 Thread A . L . M . Buxey
Hi, I am just about to start a project to remove the VMPS system from an aging catalyst switch and i would like to investigate the possibilty of using FreeRadius for this. yep - no problem. grab the latest version of FreeRADIUS and use the VMPC functionality. fwiw, we migrated to the

Re: Suse SLES 10SP2 with freeradius 2.x

2008-10-28 Thread A . L . M . Buxey
Hi, found a 1.1.6-2.1 rpm and installed it. Now I will update to a newer version but there is no rpm for SLES 10 available. When I try to compile freeradius v. 2.x then there are problems with shared libraries they are not available in SLES. On a Opensuse 11.0 machine the 2.0.5 version

Re: Suse SLES 10SP2 with freeradius 2.x

2008-10-28 Thread A . L . M . Buxey
Hi, I have build the rpm's without errors. Before I had to edit the freeradius.spec file and comment out autoreconf. After radiusd -X I get the following errors: yep - you build it without openssl-devel package installed - it clearly says in the log rlm_eap: Ignoring EAP-Type/tls because

Re: users file auth failing

2008-10-28 Thread A . L . M . Buxey
Hi, I don't know how much of this was from clean up, but if possible you really really shouldn't use cn=Manager,dc=somedomain for this. It is generally concidered a no go to let anything use the directory manager. At our site I created a dedicated radiusd user who has exactly and only the

Re: Suse SLES 10SP2 with freeradius 2.x

2008-10-28 Thread A . L . M . Buxey
Hi, Interesting the getting page only links to the old 1.x versions - an omission? In any case you can just get the old 2.x from here ftp://ftp.freeradius.org/pub/freeradius/old/ getting an older version wont help - it'll also fail the OpenSSL stuff simply because its a compilation problem.

Re: mysql driver for debian

2008-10-25 Thread A . L . M . Buxey
Hi, ./configure make make install it is working fine, but i want to use mysql db i installed mysql and create radius db wiht schema and configure sql.conf files but radius -X says rlm_sql_mysql driver not found how too add mysql driver for debian system i tried to intall wiht apt-get

Re: error when using radtest

2008-10-24 Thread A . L . M . Buxey
Hi, Please i need your help for this error message i get when i want to use radtest utility. #radtest jerry cool 127.0.0.1:1812 0 testing123 which is mapped in /etc/hosts to some other addresses. you need to add 192.168.1.30 to your clients.conf - as 192.168.1.30 is the address you are

Re: Machine Authentication

2008-10-20 Thread A . L . M . Buxey
Hi, can you please give an example how to use unlang to stiick a $ to the username amusing. you even copied my typo/sticky key issue. I could spoonfeed you a recipe - but you'll blindly put it into your config without understanding it, what it does or why it might even open up huge security

Re: Freeradius not to read radgroupcheck table from MSSQL

2008-10-20 Thread A . L . M . Buxey
Hi, Hi Ivan, 1. Is there a place that I should tell Freeradius to use mysql/dialup.conf instead of mssql/dialup.conf? But I am really using MS SQL as database. no. if you use MSSQL then use MSSQL files - what you will need to do is edit mssql/dialup.conf so that the queries that

Re: Machine Authentication

2008-10-20 Thread A . L . M . Buxey
Hi, Nice if i can amuse you In german we say (Abwandlung eines bekannten Sprichworts) ein Beispiel sagt mehr als tausend Wörter sure. and another well-known proverb is 'give a man a fish and he can eat for a day, teach a man to fish and he can eat for ever' ie i can give you 3 lines of

Re: EAP bypass

2008-10-20 Thread A . L . M . Buxey
Hi, And without getting into too many details, there would be no easy way to change the access of the guest vlan or whatever terminology you want to use so that more network resources could be accessed. you cant change the guest VLAN access list or policy? pity. alan - List

Re: Error in the negotiations certificates

2008-10-20 Thread A . L . M . Buxey
Hi, ok, this is out when i write radiusd -X -x : just the one big X will do thanks okay, heres the issue Mon Oct 20 12:08:36 2008 : Debug: (Loaded rlm_eap, checking if it's valid) Mon Oct 20 12:08:36 2008 : Debug: Module: Linked to module rlm_eap Mon Oct 20 12:08:36 2008 : Debug:

Re: EAP bypass

2008-10-19 Thread A . L . M . Buxey
Hi, I would think that would work, I just don't know how to do that! It's really easy to create a module that returns ok or handled but, despite hours of pouring through the unlange manpages and documentation on rlm_example, rlm_perl, and rlm_exec, I cannot seem to create a module that

Re: Mschapv2 not working! Please help!

2008-10-17 Thread A . L . M . Buxey
Hi, [peap] TLS 1.0 Alert [length 0002], fatal access_denied TLS Alert read:fatal:access denied [peap] WARNING: No data inside of the tunnel. [peap] eaptls_process returned 7 [peap] EAPTLS_OK [peap] Session established. Decoding tunneled attributes. [peap] Tunneled data is invalid. [eap]

Re: Mschapv2 not working! Please help!

2008-10-17 Thread A . L . M . Buxey
Hi, I made them myself. Following were the commands I used. openssl genrsa -des3 -out ca.key 4096 openssl req -new -x509 -days 3650 -key ca.key -out ca.crt openssl genrsa -des3 -out server.key 4096 openssl req -new -key server.key -out server.csr openssl x509 -req -days 3650 -in

Re: Machine Authentication

2008-10-17 Thread A . L . M . Buxey
Hi, the username needs to have a $ - use unlang, for example to stiick a $ into stripped user name and use stripped user name for authentication alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Number of Clients

2008-10-15 Thread A . L . M . Buxey
Hi, Really ice, haven't seen radmin yet. Do you know how stable it is? - The example config file for the control listener states that it shouldn't be used in a production environment. 2.1.1 stability? far far more than any other 2.0.x release from experience here - hence its being used in

Re: SQL Query question

2008-10-15 Thread A . L . M . Buxey
Hi, No. But then authentication will fail too. I am not sure if buffered-sql virtual server will queue requests when sql connection fails. ...it does do here - the file just grows and grows until it can start putting things away again. You might want to look at setting up robust proxy

Re: Number of Clients

2008-10-15 Thread A . L . M . Buxey
Hi, here - hence its being used in production. so many fixes I wonder sometimes how we got away with 2.0.5 Ouch. ;-) I hope you didnt take that the wrong way - I was impressed with 2.0.5 - but 2.1.1 is a great piece of work and I would recommend people to give it a go. certainly we

Re: [awful patch] Multiple levels of TLS nesting is invalid.

2008-10-14 Thread A . L . M . Buxey
hi, hmmm, something about that process and flow doesnt sound right at all. alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Number of Clients

2008-10-14 Thread A . L . M . Buxey
Hi, Hi there, I'm graphing the stats of the configured clients we have. Currently I use something like snip echo Message-Authenticator = 0x00, FreeRADIUS-Statistics-Type = 35, FreeRADIUS-Stats-Client-Number = 21 | radclient 127.0.0.1:18120 status veryverysecret /snip to retrive

Re: ldap/krb5 auth and access point Authentication methods ?

2008-10-11 Thread A . L . M . Buxey
Hi, I'd like to use freeradius to auth. our users. I read that freeradius can use openldap and kerberos, so i suppose I will setup these for auth. - or just use one of them - decide which one to use and ensure clients are configured correctly Most of my Wi-Fi users will be Windows/Mac Os and

Re: eap md5 and cisco 1250 ap?

2008-10-11 Thread A . L . M . Buxey
hi, if you just install eg 2.1.1 straight over 2.0.5 then it will not have changed or tocuhed any of your existing/modified files in your raddb directory. if you want to 'make sure' then 'mv raddb raddb.old', 'make install' then, edit the raddb/* files again to what you need and re-run. alan -

Re: eap md5 and cisco 1250 ap?

2008-10-11 Thread A . L . M . Buxey
Hi, add user # grep jon /usr/local/etc/raddb/usersjon Cleartext-Password := password hmmm. try editing modules/pap and change auto_header to be 'yes' alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS and EDUROAM timeout issues

2008-10-09 Thread A . L . M . Buxey
Hi, This still means that requests will be sent to that home server,even if they're for an upstream realm that's dead. If there are multiple paths to the upstream realm, then those other paths won't be discovered. But there is no RADIUS routing protocol[1]. So that's that. s'funny

Re: FreeRADIUS and EDUROAM timeout issues

2008-10-09 Thread A . L . M . Buxey
Hi, This will happen. There is sufficient buy-in from large telcos that it's necessary. cool. it wasnt just me toking on the crack pipe too many times 8-) Stefan, you hearing this? and you be thinking I crazy :-) alan - List info/subscribe/unsubscribe? See

Re: Install error

2008-10-08 Thread A . L . M . Buxey
Hi, I have these fail alll over the place in my configure. Attached. read the WARNINGS - they are only WARNINGS and not failures. do you need any of the following? ./configure error configure: WARNING: snmpget not found - Simultaneous-Use and checkrad.pl may not work configure: WARNING:

Re: freeradius compiled again, same trouble with AD

2008-10-07 Thread A . L . M . Buxey
Hi, at the end of the output i see: /etc/openradius/raddb/users[1]: Parse error (check) for entry users: Unknown value ntlm_auth for attribute Auth-Type Errors reading /etc/openradius/raddb/users /etc/openradius/raddb/modules/files[7]: Instantiation failed for module files

Re: Conversion to Version 2

2008-10-06 Thread A . L . M . Buxey
Hi, No question about that. I read about all the new authentication features and its amazing how anyone can keep up with all that stuff. However, if converting my modules is going to be a big deal, I don't see any real advantage. it 'it works for me, i cant see why I should upgrade'

Re: Newbie question

2008-10-06 Thread A . L . M . Buxey
Hi, radiusd: FreeRADIUS Version 2.0.6, for host x86_64-unknown-linux-gnu, built 2.0.6 ? well, thats not the latest available version 2.1.1 is the latest and the default config files dont mention snmp.conf at all. if you install ver older versions then you *will* come across wierd issues

Re: Easy way to Convert Config

2008-10-05 Thread A . L . M . Buxey
Hi, Start off using 2.x with the 1.1.x configuration files. Then, fix everything it complains about. I would suggest to start with the supplied 2.x config file then read through your 1.1.x configs, note which modules you actually use and which you dont, and how they are configured and then

Re: Conversion to Version 2

2008-10-05 Thread A . L . M . Buxey
Hi, I have been using FreeRadius 1.x for a number of years. It has worked just fine. All I am using it for is to authenticate and authorize dial-in users (its about as simple as you can get). The only unusual item is I have a couple of fairly complex modules for authorization and

Re: MySQL tables for 2.1.1

2008-10-02 Thread A . L . M . Buxey
Hi, I've had to fix permissions on about ten files - various files in /usr/local/etc/raddb needed to be made readable by the radius of course you did - thats because you chose to run the radiusd daemon as 'radius'. its expected that you know how to do some basic UNIX stuff - and therefore set

Re: The client does not connect _*_*_*_

2008-10-02 Thread A . L . M . Buxey
Hi, Well, when I want to connect from the notebook to the network radius, asking me to configure the profile to the type of authentication, and so on. what set everything is ready and when I try to connect but does not connect to the server and are not recorded requests. What could be the

Re: Backtrace found in debug: FreeRadius 2.0.5 version

2008-09-25 Thread A . L . M . Buxey
Hi, How can I able to revert back to my earlier FreeRadius Version 2.0.5 to come out of this backtrace problem ? download 2.0.5 tarball from freeradius.org, extract it, build it, then install it. alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: 2.1.1 has been released

2008-09-25 Thread A . L . M . Buxey
Hi, Charlie B wrote: Awesome, can you tell where to find the freeradius-utils-2.1.1? I'm guessing that the debian folk have split FreeRADIUS up into 3 packages or somesuch - so the utils would contain radtest etc ? in this case, 2.1.1 utils would probably contain radmin. its very sick. alan

Re: 2.1.1 has been released

2008-09-25 Thread A . L . M . Buxey
Hi, Actually for Fedora/Redhat and yes it would contain radtest and now upgraded to radmin but I'm looking for the package, I looked to build the rpm from freeradius-server-2.1.1.tar.gz but was unable to for the utils, so thought I would ask to see were I could grab them FreeRADIUS has only

Re: ..::Errors initializing modules::..

2008-09-25 Thread A . L . M . Buxey
Hi, But I can't see that on the radiusd -X output, I've double checked everything with no luck. Even if I'm trying the radtest with a user that is on mysql the radius send a reject packet. I can see on the output that the password doesn't match but I tried with a new one getting the same

Re: 2.1.1 has been released

2008-09-25 Thread A . L . M . Buxey
Hi, i deleted the patch 01 line from the 00 file. but freeradius doesnt starts in normal mode.no errors,no open UDP,TCP port ( netstat -ntlp and netstat -nulp dont show nothing like 1812 ,1813 ) , but in debug mode it`s ok. its unable to read config files or unable to write to the logfile

Re: ..::Errors initializing modules::..

2008-09-25 Thread A . L . M . Buxey
Hi, Thanks for your help Alan, but the radius server was built with the --with-mysql variable with no luck. err, it builds by default with MySQL - no need for that configure flag. once again, I will ask you, read the output when you run the ./configure - dump it to a file if you cannot

Re: 2.1.1 has been released

2008-09-25 Thread A . L . M . Buxey
Hi, i`ve tried in a test environment with root uid/gid and no probs with read/write conf/log files. so it works ok in debug mode ( tested from another pc with ntradping ) . yes, i dont care about successful test with root in a test environment - what fails in the real environment? eg what

Re: freeradius 2.1.0 default mysql schema don't have nasidentifier table

2008-09-24 Thread A . L . M . Buxey
Hi, And I did exactly that. :-) Anyway, it would be a small change to the schema and queries... I also wouldn't mind having it in by default. But I don't care enough to submit a patch. I think the issue is an UPDATE/UPGRADE issue - if the queries are liek that by default - ie schema change -

Re: Raduisd -X No output

2008-09-24 Thread A . L . M . Buxey
Hi, Then I go to the XP system and connect to the Radius server ? And windows gives a message that it can't find a cert to the network linksys... There is no further output on the radius -X log. on the fedora box tcpdump -eqntl -i eth0 port 1812 or port 1812 check iptables - you might

Re: Filtering RADIUS request to only allow EAP-TTLS in a proxying-onlyserver?

2008-09-24 Thread A . L . M . Buxey
Hi, Ie, I would like to make sure that it will reject requests that come in from the outside with user+password stuff sent in cleartext. such requests will be missing many attributes. use unlang to check for the absence of those. alan - List info/subscribe/unsubscribe? See

Re: Fw: Re: Raduisd -X No output

2008-09-24 Thread A . L . M . Buxey
Hi, Alan good call...  I thought that I disabled all the firewall, SElinux during the install. Now I am working with the windows box XP Pro. I connects be still can't find a cert for the network linksys. ful debug log as per the FASQ, docs and countless posts on this ML. when you

Re: Filtering RADIUS request to only allow EAP-TTLS in a proxying-only server?

2008-09-24 Thread A . L . M . Buxey
Hi, One thing I'd like to achive in the EDUROAM-responsible RADIUS router (server) is to make sure that *only* EAP-TTLS requests are forwarded to the RADIUS server doing the real user authentication. the inner, or the whole request? if only the inner, then please note that this will break

Re: mod_radius error

2008-09-22 Thread A . L . M . Buxey
hi, specifically this isnt a mod_radius problem - its a 'how to configure apache for my distro' problem. ubuntu have split their config into 'enabled modules' which are then called into play read a suitable document to find how to get the module incorporated into your apache 2.2.x install eg

Re: Fwd: rlm-perl lc usernames

2008-09-22 Thread A . L . M . Buxey
Hi, thoughts on where to go from here to get this not to alter the username and just lc it but its not altering (apart from LC'ing it) - as your other post shows. throw the daemon some uppercased username (eg with 'radtest' tool) and check the debugging to see what you see from PERL alan -

Re: Fwd: rlm-perl lc usernames

2008-09-22 Thread A . L . M . Buxey
Hi, Hi Alan, it is lc'ing it, however it is also moving the r from the beginning of the username to the end of the username, which is what Im trying to stop ..and from what you've posted so far, I'd say it isnt moving it. wheres the other upper case tests and debug as per requested? alan -

Re: Fwd: rlm-perl lc usernames

2008-09-22 Thread A . L . M . Buxey
Hi, User-Name = \\raduser ^ ha. okay. with just a plain username you are safe, but with this windows case, you are dealing with \r - which is a special character. its getting borked elsewhere. to verify this use another username that cannot be a

Re: autentication against active directory does not work

2008-09-22 Thread A . L . M . Buxey
Hi, now im receiving this edit   ERROR: Unknown value specified for Auth-Type.  Cannot perform requested action. auth: Failed to validate the user.   WARNING: Unprintable characters in the password. ?  Double-check the shared secret on the server and the NAS! snip! you are still

Re: MySQL not in the default port

2008-09-20 Thread A . L . M . Buxey
Hi, Thanks man, it worked ... Sorry, I hadn't found any docs about this directive ... thats okay - you wouldnt have, its currently not documented anyway so far as i could quickly see. alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Fwd: rlm-perl lc usernames

2008-09-20 Thread A . L . M . Buxey
Hi, Nobody :( have any tidbits to help me isolate this, obviously its not the perl script but what is altering the username. hmmm, you play with user-name and yet you return MODULE_OK.surely you've played with attributes so *SHOULD* be sending MODULE_UPDATED alan - List

Re: Users can't authenticate through PEAP

2008-09-19 Thread A . L . M . Buxey
hi, whilst its great to see documentation available on other sites , please start with the freeRADIUS documentation - and , even better, read the files eg eap.conf alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

<    1   2   3   4   5   6   7   8   9   10   >