Group questions..several group memberships to one account. FreeRADIUS Version 2.1.10

2013-04-12 Thread Alexander Silveröhrt
Hello, Never played around with groups using rlm_sql and the default schema.. I am reading what i assume is saying that it should be possible to have several groups to a account and each group should be able to supply that specific groups radgroupreply attributes.. Number 4 below sure sounds

SV: Group questions..several group memberships to one account. FreeRADIUS Version 2.1.10

2013-04-12 Thread Alexander Silveröhrt
+alexander.silverohrt=itux...@lists.freeradius.org] För Alexander Silveröhrt Skickat: den 12 april 2013 09:33 Till: freeradius-users@lists.freeradius.org Ämne: Group questions..several group memberships to one account. FreeRADIUS Version 2.1.10 Hello, Never played around with groups using rlm_sql

SV: Group questions..several group memberships to one account. FreeRADIUS Version 2.1.10

2013-04-12 Thread Alexander Silveröhrt
...@lists.freeradius.org] För Alexander Silveröhrt Skickat: den 12 april 2013 09:41 Till: FreeRadius users mailing list Ämne: SV: Group questions..several group memberships to one account. FreeRADIUS Version 2.1.10 Sorry forget about priority i thought higher was first..Which it wasn’t.. Still is it possible

SV: perl examples

2013-04-08 Thread Alexander Silveröhrt
Since i was just in the making of some hooks using DBI I took some time to copy paste something that could be something towards the thing you wanted? This is just an example so don't take it to serious.. I also don't think you should do it as post_auth hook but a authorize hook so Don't forget

SV: disconected after one second

2013-04-04 Thread Alexander Silveröhrt
Hard to know what you missconfigured but...i can give you some usual suspects maybe.. Also can you post a show subscribers active all while trying to auth. Also debug with Term mon debug aaa rad-attr debug rad-packet Your forward policy looks wicked Forward-Policy == in:CLIPS-DEFAULT are you

SV: Freeradius several segfaults at heavy load and startup ?

2012-11-28 Thread Alexander Silveröhrt
[mailto:a.l.m.bu...@lboro.ac.uk] Skickat: den 28 november 2012 09:07 Till: Alexander Silveröhrt; freeradius-users@lists.freeradius.org Ämne: Re: Freeradius several segfaults at heavy load and startup ? -X runs as a single thread Is your perl multi-threaded? Does your PERL code deal with threads

SV: Freeradius several segfaults at heavy load and startup ?

2012-11-28 Thread Alexander Silveröhrt
Same here doesn't even start without LD_PRELOAD. -Ursprungligt meddelande- Från: freeradius-users-bounces+alexander.silverohrt=itux...@lists.freeradius.org [mailto:freeradius-users-bounces+alexander.silverohrt=itux...@lists.freeradius.org] För Johan Meiring Skickat: den 28 november

SV: SV: Freeradius several segfaults at heavy load and startup ?

2012-11-28 Thread Alexander Silveröhrt
meddelande- Från: alan buxey [mailto:a.l.m.bu...@lboro.ac.uk] Skickat: den 28 november 2012 10:46 Till: Alexander Silveröhrt Kopia: freeradius-users@lists.freeradius.org Ämne: Re: SV: Freeradius several segfaults at heavy load and startup ? Hi, And thanks for the reply. If you mean that my

SV: Freeradius several segfaults at heavy load and startup ?

2012-11-28 Thread Alexander Silveröhrt
] För Phil Mayers Skickat: den 28 november 2012 10:50 Till: freeradius-users@lists.freeradius.org Ämne: Re: Freeradius several segfaults at heavy load and startup ? On 11/28/2012 04:28 AM, Alexander Silveröhrt wrote: Hello, Wondered if anyone have any idea about below. If started with flag -X

Freeradius several segfaults at heavy load and startup ?

2012-11-27 Thread Alexander Silveröhrt
Hello, Wondered if anyone have any idea about below. If started with flag -X everything starts up ok but without -X then it crashes with these messages in the log.(atleast most of the time if one is persistent then it may well start up properly sometimes without the -X flag) As soon as it

Re: FreeRADIUS performance information (tuning, benchmark)

2012-07-24 Thread Alexander Gattin
On Tue, Jul 24, 2012 at 01:49:27PM +0100, Phil Mayers wrote: On 24/07/12 13:26, Andrei Petru Mura wrote: radperf -s -f ../users.csv -p 800 -a pap 10.3.1.1 auth radiussomething ... 0.1s : 3758 s: 5897 10s : 344 ... I would need a sever able to manage a much greater amount

Re: Reg: Different databases with single frerradius

2012-06-29 Thread Alexander Gattin
Hello, On Fri, Jun 29, 2012 at 03:13:45PM +0700, Fajar A. Nugraha wrote: or for different realms (e.g. all user @domain1 will read data from db1, while all user @domain1 will read data from db2). most probably he'd like to differentiate them by IMSI ranges. P.S. I don't know how to do this

Re: Reg: IMSI based authentication.

2012-06-26 Thread Alexander Gattin
Hello, On Tue, Jun 26, 2012 at 08:39:39AM +0100, Malla reddy Sama wrote: Now I want to do IMSI based authentication with radius. Please can anyone help me on how to do IMSI based authentication. Just use IMSI (3GPP-IMSI? Calling-Station-Id?) as User-Name, then insert Auth-Type := Accept line

Building FreeRADIUS on HP-UX B.11.31 ia64 (gcc, 32bit)

2012-06-22 Thread Alexander Gattin
Hello, There are 2 problems with HP-UX build (I use GNU gcc and native ld): 1. ld options '+b libdir' are passed without '-Wl,' prefix directly to gcc (not to ld): gcc -shared -Wl,+h -Wl,rlm_acctlog-2.1.12.so -Wl,+nodefaultrpath -o .libs/rlm_acctlog-2.1.12.so .libs/rlm_acctlog.o +b

Re: Building FreeRADIUS on HP-UX B.11.31 ia64 (gcc, 32bit)

2012-06-22 Thread Alexander Gattin
Hello, On Fri, Jun 22, 2012 at 12:16:00PM +0300, Alexander Gattin wrote: 1. ld options '+b libdir' are passed without '-Wl,' prefix directly to gcc (not to ld): gcc +b src/lib/.libs was in fact started by ./libtool: /comptel/ilink/src/freeradius-server-2.1.12/libtool --mode=link gcc

Re: RADIUS + LDAP authentication problem

2012-04-25 Thread Alexander Kulbiy
fails. I've posted full log of freeradius here: http://pastebin.com/ijf649gP Thanks in advance, Alexander - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: RADIUS + LDAP authentication problem

2012-04-25 Thread Alexander Kulbiy
Hello Alan, Finally I got it. I had to change client settings and now everything is fine. Thanks a lot, Alexander On Wed, Apr 25, 2012 at 3:45 PM, Alan DeKok al...@deployingradius.comwrote: Alexander Kulbiy wrote: Matthew, as I understood from link you've posted I have to use TTLS/GTC

optimize sqlippool scheme

2012-01-12 Thread Alexander Kosykh
slower with selects queries. Maybe some one have a good modification of ippool table or another changes of default scheme, and could share it? *Regards,* Alexander - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: optimize sqlippool scheme

2012-01-12 Thread Alexander Kosykh
One more question. Where can I take nas-type value to use it in user authorization? Radius take it from mysql nasinfo table at startup. I take it from DB every time subscriber try to authorize. Regards, Alexander. 2012/1/12 Fajar A. Nugraha l...@fajar.net On Thu, Jan 12, 2012 at 6:36 PM

Re: optimize sqlippool scheme

2012-01-12 Thread Alexander Kosykh
I have interim accounting value 10 minutes and IP lease time is 30 minutes. 2012/1/12 Phil Mayers p.may...@imperial.ac.uk On 01/12/2012 11:59 AM, Fajar A. Nugraha wrote: That's why having a dba is important. If you can't do it yourself, hire one. Or learn to be one. Depending on your

Simultaneous-use check but don't reject

2011-12-20 Thread Alexander Kosykh
and redirect them to Error page? Regards, Alexander. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Simultaneous-use check but don't reject

2011-12-20 Thread Alexander Kosykh
The question is not how to make captive portal on my NAS, the question is how do not reject customer, who reached max value of simultaneous-use? Regards, Alexander. 2011/12/20 Alan DeKok al...@deployingradius.com Alexander Kosykh wrote: I'm using Simultaneous-use := 1 and sql for check on my

Re: Simultaneous-use check but don't reject

2011-12-20 Thread Alexander Kosykh
I tried to do this in my config session { # radutmp # # See Simultaneous Use Checking Queries in sql.conf sql if (Post-Auth-Type == reject) { ok block_auth_error # my own policy } } but radius answer is reject whatever and pppoe didn't up 2011/12/21 Alan Buxey a.l.m.bu...@lboro.ac.uk Hi,

Re: Simultaneous-use check but don't reject

2011-12-20 Thread Alexander Kosykh
Hi. I knew how to make all you wrote above. I need to know how to accept customer, when sim-use rejected him. Regards, Alexander. 2011/12/21 Fajar A. Nugraha l...@fajar.net On Wed, Dec 21, 2011 at 5:29 AM, Fajar A. Nugraha l...@fajar.net wrote: On Wed, Dec 21, 2011 at 4:18 AM, Alexander

Re: Simultaneous-use check but don't reject

2011-12-20 Thread Alexander Kosykh
How to make checkrad, if disable all in session section? acct-stop packets is lost sometimes and sql think that customer is online, but he didn't. Regards, Alexander. 2011/12/21 Fajar A. Nugraha l...@fajar.net On Wed, Dec 21, 2011 at 12:56 PM, Alexander Kosykh avkos...@gmail.com wrote: Hi

Re: Simultaneous-use check but don't reject

2011-12-20 Thread Alexander Kosykh
Do you have some examples, which work fast to handle 10 AAA/second and check sim-use without freeradius standart methods? Regards, Alexander. 2011/12/21 Fajar A. Nugraha l...@fajar.net I belive I responded to a similar question yesterday (search the list archive). You just have to deal

Re: Workload in freeradius? platform

2011-10-14 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: Take your Senator to lunch this week. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Fast session resumption memory leak?

2011-10-13 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: Postage will be paid by addressee. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Mac access mixed ldap access same NAS

2011-10-06 Thread Alexander Clouter
documentation... Cheers -- Alexander Clouter .sigmonster says: I'm having fun HITCHHIKING to CINCINNATI or FAR ROCKAWAY!! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: avoiding ldap access in authorize

2011-09-30 Thread Alexander Clouter
://freeradius.1045715.n5.nabble.com/foreach-attribute-array-td2787874.html Cheers -- Alexander Clouter .sigmonster says: Guillotine, n.: A French chopping center. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS Beginner's Guide

2011-09-29 Thread Alexander Clouter
Alexander Clouter a...@digriz.org.uk wrote: The content is generally rather good, and aside from a few typos, the book is let only on some relatively *minor* points: [snipped] * unfortunately short EAP section, ignoring session resumption and why particular EAP methods meet

Re: rlm_perl

2011-09-29 Thread Alexander Clouter
useful things: http://wiki.freeradius.org/Rlm_perl ...and even less surprisingly it's the same as whats in src/modules/rlm_perl/example.pl. *sigh* Cheers -- Alexander Clouter .sigmonster says: Mongoose knghtbrd: and the meek shall inherit k-mart - List info/subscribe/unsubscribe? See http

Re: FreeRADIUS Beginner's Guide

2011-09-28 Thread Alexander Clouter
rather than a beginners guide...so I probably am being mean :) The price is reasonable, and if you are a complete newbie, it will get you on your feet. The book definitely does what it says on the tin and I would give it a 7 out of 10... Cheers -- Alexander Clouter .amongst says: Dibble's

Re: MySQL and FreeRADIUS environment.

2011-09-27 Thread Alexander Clouter
better when we ditched mysql Our experience has been that using MySQL pretty much guarantees you *will* be burnt...especially with the replication. Cheers -- Alexander Clouter .sigmonster says: I'm having a MID-WEEK CRISIS! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Need a little regex help

2011-09-17 Thread Alexander Clouter
to be crazy to use just basic regex. Cheers -- Alexander Clouter .sigmonster says: Tact, n.: The unsaid part of what you're thinking. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Pre release of 2.1.12

2011-09-02 Thread Alexander Clouter
Alexander Clouter a...@digriz.org.uk wrote: I've put some pre releases of 2.1.12 on the web site: http://git.freeradius.org/pre/ Priming up my end for a burn in... 24 hours later, still churning happily. Running 2.1.12 (bfe2c025). Cheers -- Alexander Clouter .sigmonster says

Re: Pre release of 2.1.12

2011-09-02 Thread Alexander Clouter
{ Acct-Interim-Interval := 3000 + %{rand:1200} } This would give me Acct-Interim-Interval set to 1hr+-10mins. As it is set now, I just got 1MB of journal recorded to file accounting data landing on my systems :) Cheers -- Alexander Clouter .sigmonster says: The chief cause

Re: Question regarding multivalued attributes in control list.

2011-09-02 Thread Alexander Clouter
] http://lists.cistron.nl/pipermail/freeradius-users/2011-June/msg00334.html -- Alexander Clouter .sigmonster says: An algorithm must be seen to be believed. -- D. E. Knuth - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Pre release of 2.1.12

2011-09-01 Thread Alexander Clouter
Alan DeKok al...@deployingradius.com wrote: I've put some pre releases of 2.1.12 on the web site: http://git.freeradius.org/pre/ Priming up my end for a burn in... Cheers -- Alexander Clouter .sigmonster says: And on the seventh day, He exited from append mode. - List info/subscribe

Re: Authentication probation for VLAN

2011-08-26 Thread Alexander Clouter
to mention that one chunk of the debug was for the outer layer, the other the inner auth :-/ Cheers -- Alexander Clouter .sigmonster says: Misfortunes arrive on wings and leave on foot. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Authentication probation for VLAN

2011-08-25 Thread Alexander Clouter
attributes, so drop the ':0' too): notice the if (Tunnel-Private-Group-Id == 5) { [stuff] } Cheers -- Alexander Clouter .sigmonster says: Do not apply to broken skin. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Realm parsing and \r = =0D

2011-08-24 Thread Alexander Clouter
if you want some help and think this could be getting off topic; although there are a *lot* of eduroam'ers here on the list. Cheers -- Alexander Clouter .sigmonster says: DIDI ... is that a MARTIAN name, or, are we in ISRAEL? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Want to silently discard the request if authentication module as?web?service client connecting to the web service server is down.

2011-08-10 Thread Alexander Clouter
this with what Alan already has pointed you to, do_not_respond in policy.conf, and you should be able to get to where you want to be. Cheers -- Alexander Clouter .sigmonster says: If you sow your wild oats, hope for a crop failure. - List info/subscribe/unsubscribe? See http://www.freeradius.org

Re: SSH to use CHAP

2011-08-10 Thread Alexander Clouter
be done; unless you can find a PAM RADIUS plugin that supports CHAP. You should use SSH public keys. If you want that centrally managed have a look at putting your users SSH keys into LDAP: http://freshmeat.net/projects/lpkfuse Cheers -- Alexander Clouter .sigmonster says: List at least two

Re: Returning attributes based on group membership using NTLM_AUTH

2011-08-09 Thread Alexander Clouter
reply off list, but I'm curious why you say e to PHP, and what you would use instead? Flamebait! I nearly fell for it. :) You have permission to Google-stalk me if you really want to know what I use. Cheers -- Alexander Clouter .sigmonster says: What soon grows old? Gratitude

Re: Want to silently discard the request if authentication module as web?service client connecting to the web service server is down.

2011-08-09 Thread Alexander Clouter
the responses other than the RLM_MODULE_OK and RLM_MODULE_REJECTED. http://wiki.freeradius.org/Modules2#Module+Return+Codes RLM_MODULE_FAIL looks like a better option to use, although it will not give you what you want; but it would enable you to use unlang to perform other tasks. Cheers -- Alexander

Re: Returning attributes based on group membership using NTLM_AUTH

2011-08-09 Thread Alexander Clouter
though. Cheers [1] TLS_CACERT /etc/ssl/certs/ca-certificates.crt [2] http://lists.cistron.nl/pipermail/freeradius-users/2005-December/msg00228.html and http://bytes.com/topic/php/answers/11274-use-php-authenticate-ad -- Alexander Clouter .sigmonster says: You are magnetic in your bearing

Re: Returning attributes based on group membership using NTLM_AUTH

2011-08-08 Thread Alexander Clouter
only search a sub-branch. I suspect the fix is nothing more than setting 'basedn' to ou=lusers,dc=my,dc=domain,dc=name. Cheers [1] http://www.php.net/manual/en/function.ldap-search.php#45388 -- Alexander Clouter .sigmonster says: Without fools there would be no wisdom. - List info/subscribe

Re: Freeradius closes

2011-08-08 Thread Alexander Clouter
normal (from my torrus[1] graphs). Will keep you posted if anything crops up...touch wood it seems okay. Cheers [1] http://torrus.org/ is amazing, especially combined with snmpd on hosts too -- Alexander Clouter .sigmonster says: HOST SYSTEM RESPONDING, PROBABLY UP... - List info/subscribe

Re: Cleanup Stale Sessions - needed?

2011-08-08 Thread Alexander Clouter
-users%2F+sql+session+clean Cheers -- Alexander Clouter .sigmonster says: Got a dictionary? I want to know the meaning of life. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius closes

2011-08-08 Thread Alexander Clouter
with the SNMP communitities and you quickly have five minutely graphs for *every* port on your network; and various server with SNMPd running. Simples -- Alexander Clouter .sigmonster says: Apathy is not the problem, it's the solution - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Using multiple authentication modules.

2011-08-04 Thread Alexander Clouter
overhead will like the rlm_perl. Without including your FreeRADIUS configuration there is very little anyone here can do to help you other than ask have you just tried using both modules? authorize { ... eap perl ... } authenticate { eap perl } Cheers -- Alexander

Re: num_answers_to_alive

2011-08-04 Thread Alexander Clouter
. If the system briefly came back and died then on attempt two or three you would have likely seen a failure. Hope I am explaining myself well :) Cheers -- Alexander Clouter .sigmonster says: BOFH excuse #256: You need to install an RTFM interface. - List info/subscribe

Re: Freeradius closes

2011-07-28 Thread Alexander Clouter
Alexander Clouter a...@digriz.org.uk wrote: I am though currently trying to pin down a bug where FreeRADIUS just closes it's-self down for no reason at all. I have run tcpdump during the clean shutdown, and see it is not malformed traffic causing the problem, RAM usage is normal, open

Re: Freeradius closes

2011-07-28 Thread Alexander Clouter
Fajar A. Nugraha l...@fajar.net wrote: On Thu, Jul 28, 2011 at 4:42 PM, Alexander Clouter a...@digriz.org.uk wrote: rad_recv: Status-Server packet from host 127.0.0.1 port 50412, id=38, length=38 [event.c:3002] Failed to insert event There seem to be a bunch of malloc()'s where

Re: Freeradius closes

2011-07-28 Thread Alexander Clouter
Alan DeKok al...@deployingradius.com wrote: Alexander Clouter wrote: rad_recv: Status-Server packet from host 127.0.0.1 port 50412, id=38, length=38 [event.c:3002] Failed to insert event Ouch. Indeed. It did only start to happen once I upgraded to 2.1.11 from 2.1.10. Of course I

Re: LDAP Groups and Dynamic VLAN assignment

2011-07-27 Thread Alexander Clouter
)? Is it possible to do this configuration in conjunction with redundant ldap configuration?? http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg71133.html Cheers -- Alexander Clouter .sigmonster says: Is there life before breakfast? - List info/subscribe/unsubscribe? See

Re: Freeradius closes

2011-07-27 Thread Alexander Clouter
there would be other grumblings on the list (or I have missed them and it's already fixed...). Cheers -- Alexander Clouter .sigmonster says: I can't stand squealers; hit that guy. -- Albert Anastasia - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: TTLS use_tunneled_reply and Mac OSX

2011-07-20 Thread Alexander Clouter
resumption? Also TTLS/MSCHAPv2 is possibly for you actually TTLS/EAP-MSCHAPv2 which means you get in effect an inner-inner tunnel if I remember correctly. Have a nosey at: http://www.mail-archive.com/freeradius-users@lists.freeradius.org/msg71026.html Cheers -- Alexander Clouter .sigmonster says

Re: General wiki rules

2011-07-15 Thread Alexander Clouter
existing content. Cheers -- Alexander Clouter .sigmonster says: I'm having a MID-WEEK CRISIS! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: vlan ldap radiusd

2011-07-15 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: Massachusetts has the best politicians money can buy. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: vlan ldap radiusd

2011-07-15 Thread Alexander Clouter
://www.soas.ac.uk/itsupport/personal-equipment/unauthorised-workstation.html -- Alexander Clouter .sigmonster says: Where do you think you're going today? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Stripped-User-Name Problems (Re: Unmatched ( or \(, and, ?more?broadly, setting Stripped-User-Name)

2011-07-15 Thread Alexander Clouter
the *inner* auth User-Name is realmless and making it's way out into outer.reply. When you use 'User-Name' in post-auth{} you will get reply:User-Name rather than request:User-Name if I remember correctly. The fix is to *reject* inner-authentications that are realm-less. Cheers -- Alexander Clouter

Re: vlan ldap radiusd

2011-07-15 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: fortune: not found - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Unmatched ( or \(, and, more broadly, setting Stripped-User-Name

2011-07-14 Thread Alexander Clouter
. :) Cheers -- Alexander Clouter .sigmonster says: Sauron is alive in Argentina! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: vlan ldap radiusd

2011-07-14 Thread Alexander Clouter
. :( Cheers [1] http://www.digriz.org.uk/lanwarden -- Alexander Clouter .sigmonster says: You are so boring that when I see you my feet go to sleep. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Yet another multiple SSID setup question

2011-07-13 Thread Alexander Clouter
instructions to connect to the wireless (and wired) network. It is also then trivial to put in 'eduroam'; if you use 'eduroam' from day one (*strongly* recommended to avoid pain down the road). Cheers -- Alexander Clouter .sigmonster says: Youth is the trustee of posterity. - List info/subscribe

Re: Yet another multiple SSID setup question

2011-07-12 Thread Alexander Clouter
} ... } Cheers -- Alexander Clouter .sigmonster says: Remember to say hello to your bank teller. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Wiki - Once upon a time there was documentation

2011-07-12 Thread Alexander Clouter
Gary Gatten ggat...@waddell.com wrote: RADIUS - Half the complexity of Diameter Don't encourage him... Cheers -- Alexander Clouter .sigmonster says: Life is NP-hard, and then you die. -- Dave Cock - List info/subscribe/unsubscribe? See http

Re: Tunneled-User-Name

2011-07-11 Thread Alexander Clouter
the inner name for resumed sessions As a bonus, the Auth-Type is extractable..if you use TLS cached sessions, then this will be EAP. Cheers -- Alexander Clouter .sigmonster says: It was Penguin lust... at its ugliest. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Running external programs

2011-07-07 Thread Alexander Clouter
://lmgtfy.com/?q=freeradius+exec Cheers -- Alexander Clouter .sigmonster says: Have no friends not equal to yourself. -- Confucius - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Running external programs

2011-07-07 Thread Alexander Clouter
* rihad ri...@mail.ru [2011-07-07 15:09:22+0500]: On 07/07/2011 12:28 PM, Alexander Clouter wrote: rihadri...@mail.ru wrote: Hi, all. We have some legacy software that ran under XTradius (xtradius.sourceforge.net). The important thing was to execute an external program for every auth

Re: Mac-Auth

2011-07-07 Thread Alexander Clouter
connected: https://su1x.swan.ac.uk/ Believe me, collecting and managing MAC addresses is not something I would wish on anyone. Cheers -- Alexander Clouter .sigmonster says: Ninety percent of baseball is half mental. -- Yogi Berra - List info/subscribe/unsubscribe

Re: Freeradius 2.1.10: authentication (uid and password) or (macaddress)?in LDAP

2011-07-07 Thread Alexander Clouter
. If the MAC address is not 'registered' then the client has to use an 802.1X authentication. Cheers -- Alexander Clouter .sigmonster says: When you don't know what to do, walk fast and look worried. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: pre-check OTP token

2011-07-04 Thread Alexander Clouter
-thingy ... } Cheers -- Alexander Clouter .sigmonster says: Good day for overcoming obstacles. Try a steeplechase. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius and IdenticalClients

2011-06-30 Thread Alexander Clouter
Y.Y.Y.Y Z.Z.Z.Z FR allows you to specify something like this on clients.conf X.X.X.0/24 using ipaddr and netmask I suspect you can use 'templates {}' too, we use it in proxy.conf, I cannot see why it could not be used in clients.conf too. Cheers -- Alexander Clouter .sigmonster says: You

Re: patch files for pam_radius - adding an 'Always Prompt' option for?one-time passcodes

2011-06-30 Thread Alexander Clouter
have added a pam option always prompt in the attached code.  This will force a WiKID passcode: prompt regardless of any previous password entry. This can be changed, of course. Better to lead with the OTP as then you fend off brute force and dictionary attacks. Cheers -- Alexander Clouter

Re: LDAP redundant with LDAP-Group within users file

2011-06-29 Thread Alexander Clouter
:= Reject -- Alexander Clouter .sigmonster says: Don't compare floating point numbers solely for equality. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: LDAP redundant with LDAP-Group within users file

2011-06-28 Thread Alexander Clouter
show :) Cheers -- Alexander Clouter .sigmonster says: You will have many recoverable tape errors. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

How to send empty value via radclient?

2011-06-27 Thread Alexander Kubatkin
it, i.e. NAS only received Context-Name and Framed-IP-Address, is this possible to send empty value? -- Alexander Kubatkin - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: How to send empty value via radclient?

2011-06-27 Thread Alexander Kubatkin
to terror vendor of my box. Just for clarify - this restriction applied to VSA attributes? or only standard? or whole attributes? -Arran Arran Cudbard-Bell a.cudba...@freeradius.org RADIUS - Half the complexity of Diameter -- Alexander Kubatkin - List info/subscribe/unsubscribe? See http

Re: Failed creating handler

2011-06-25 Thread Alexander Clouter
not need to install an experimental armel valgrind :) Cheers -- Alexander Clouter .sigmonster says: Expect the worst, it's the least you can do. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Multivalued (LDAP) Attributes and string matching, or regexes

2011-06-21 Thread Alexander Clouter
) -- Alexander Clouter .sigmonster says: BOFH excuse #138: BNC (brain not connected) - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Migrating to threaded rlm_perl

2011-06-20 Thread Alexander Clouter
restarts. Cheers [1] http://search.cpan.org/dist/BerkeleyDB/BerkeleyDB.pod -- Alexander Clouter .sigmonster says: BOFH excuse #192: runaway cat on system. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Migrating to threaded rlm_perl

2011-06-20 Thread Alexander Clouter
when rlm_perl fires up, afterwards your methods are called whenever required, pre-emptively. Cheers -- Alexander Clouter .sigmonster says: You mean you don't want to watch WRESTLING from ATLANTA? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: chain two authentication modules together

2011-06-20 Thread Alexander Clouter
madmatrix hailum...@gmail.com wrote: Alexander, one thing I'm still confused here is why we put otp and ldap all in authorization block in freeradius not the authentication? As I'm an idiot. They should also be present in the authenticate section. In authorise, your OTP python method

Re: chain two authentication modules together

2011-06-18 Thread Alexander Clouter
madmatrix hailum...@gmail.com wrote: Thanks a lot Alexander. I'm familiar with python. So rlm_python might a good choice for me. The main thing I want to do is to give remote vpn client a two-factor authentication. Depending on how your VPN works and what the clients can support, you

Re: chain two authentication modules together

2011-06-17 Thread Alexander Clouter
to recompile things as an example). Cheers -- Alexander Clouter .sigmonster says: Don't feed the bats tonight. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Multivalued (LDAP) Attributes and string matching, or regexes

2011-06-16 Thread Alexander Clouter
there...although I would recommend the users file with a bunch of fall throughs personally. Cheers -- Alexander Clouter .sigmonster says: All phone calls are obscene. -- Karen Elizabeth Gordon - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: If in post-auth

2011-06-15 Thread Alexander Clouter
} } } else { ... } The regex should extract a usable value when present. Cheers -- Alexander Clouter .sigmonster says: wok, n.: Something to thwow at a wabbit. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Proxy based on User-Name with regex

2011-06-11 Thread Alexander Clouter
a '/^$/'? Cheers -- Alexander Clouter .sigmonster says: Old programmers never die, they just become managers. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Alexander Clouter
which might already have a fix: http://git.freeradius.org/ Cheers -- Alexander Clouter .sigmonster says: He's just like Capistrano, always ready for a few swallows. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: One client, multiple NAS-Port-Types

2011-06-01 Thread Alexander Clouter
, not FreeRADIUS :) Cheers -- Alexander Clouter .sigmonster says: Them as has, gets. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Server Sertificate

2011-06-01 Thread Alexander Clouter
expecting to happen * what is actually happening Cheers -- Alexander Clouter .sigmonster says: You enjoy the company of other people. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: How to change ++[files] returns noop into ++[files] returns?reject

2011-05-24 Thread Alexander Clouter
the following to the end: DEFAULT Auth-Type := Reject I prefer to 'deny, allow' (in Apache speak), but you might prefer 'allow, deny'. Cheers -- Alexander Clouter .sigmonster says: Have a taco. -- P. S. Beagle - List info/subscribe/unsubscribe? See http

Re: freeradius redundancy

2011-05-24 Thread Alexander Clouter
-- Alexander Clouter .sigmonster says: BOFH excuse #350: paradigm shift...without a clutch - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Sidenote: WPA Enterprise configuration and troubleshooting guides

2011-05-24 Thread Alexander Clouter
Alan Buxey a.l.m.bu...@lboro.ac.uk wrote: go on, join eduroam. I got a @illinois.edu lurker this week here at soas.ac.uk :) Cheers -- Alexander Clouter .sigmonster says: Wagner's music is better than it sounds. -- Mark Twain - List info/subscribe

Re: freeradius redundancy

2011-05-23 Thread Alexander Clouter
having to buy an expensive and/or complicated load-balancer: http://www.digriz.org.uk/ha-ospf-anycast Cheers -- Alexander Clouter .sigmonster says: If you knew what to say next, would you say it? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: multuple ldap freeradius ssid

2011-05-18 Thread Alexander Clouter
-auth. Is that correct ? Without the output from 'radiusd -X', I cannot help you. Regards -- Alexander Clouter .sigmonster says: Am I accompanied by a PARENT or GUARDIAN? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: multuple ldap freeradius ssid

2011-05-16 Thread Alexander Clouter
for your reply, and sorry for my english, I'm French ;) We forgive you... ;) Cheers -- Alexander Clouter .sigmonster says: A modem is a baudy house. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

  1   2   3   4   5   6   >