Re: Terminate dsl ppp sessions daily

2013-10-14 Thread Arran Cudbard-Bell
. Calculate time difference between now at 04:00am and insert it into Session-Timeout? If your NAS doesn't implement Session-Timeout then you can use CoA/DM or SNMP. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Re: Terminate dsl ppp sessions daily

2013-10-14 Thread Arran Cudbard-Bell
On 14 Oct 2013, at 16:27, Volker Lieder v.lie...@uvensys.de wrote: Hi, we tried to calculate it via expr. How would you calculate it? Pretty sure the expiration module does exactly this. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe

Re: Problems with compiling freeradius on Ubuntu Linux

2013-10-12 Thread Arran Cudbard-Bell
with the build system, if one is defined and the other is not, then autoconf/the configure scripts are broken. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius 2.2.0 on Fedora and oracle module

2013-10-10 Thread Arran Cudbard-Bell
: WARNING: silently not building rlm_sql_oracle. configure: WARNING: FAILURE: rlm_sql_oracle requires: libclntsh libnnz. configure: creating ./config.status config.status: creating Makefile Please use version 3.0.0 the configure script is much better. http://freeradius.org/download.html Arran Cudbard

Re: freeradius 2.2.0 on Fedora and oracle module

2013-10-10 Thread Arran Cudbard-Bell
. all.mk is a make include not an actual make file. It should pick up that rlm_sql_oracle has been configured (even if it's not marked as stable) and build it. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Re: well almost got FR 3.0 to compile on OS X :-)

2013-10-10 Thread Arran Cudbard-Bell
drop OpenSSL in Mavericks and we can do a clean install without all the stupid deprecated pragmas from another package management system. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius 2.2.0 on Fedora and oracle module

2013-10-10 Thread Arran Cudbard-Bell
- Repeat the previous command which generated this error message. *sigh* -Arran -Original Message- From: freeradius-users-bounces+puzzel1982=gmail@lists.freeradius.org [mailto:freeradius-users-bounces+puzzel1982=gmail@lists.freeradius.org] On Behalf Of Arran Cudbard-Bell Sent

Re: freeradius 2.2.0 on Fedora and oracle module

2013-10-10 Thread Arran Cudbard-Bell
. :/ run the configure script in src/modules/rlm_sql/drivers/rlm_sql_oracle and post the output and config.log file. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Error messages in debug on 3.0

2013-10-10 Thread Arran Cudbard-Bell
On 10 Oct 2013, at 18:32, Phil Mayers p.may...@imperial.ac.uk wrote: I've just ported our config to 3.0 and I'm seeing a few error messages; they don't seem to be critical but are concerning me. Specifically I'm seeing: ERROR: Conditional evaluation failed due to internal sanity

Re: Error messages in debug on 3.0

2013-10-10 Thread Arran Cudbard-Bell
Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: unlang - delete attribute - !*

2013-10-09 Thread Arran Cudbard-Bell
. update reply { Aruba-Admin-Role -= %{reply:Aruba-Admin-Role} } Will delete the first instance. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: well almost got FR 3.0 to compile on OS X :-)

2013-10-09 Thread Arran Cudbard-Bell
On 9 Oct 2013, at 11:21, Alex Sharaz alex.sha...@york.ac.uk wrote: you don't know how hard it was to wait till the official release :-) A brew install talloc brew link talloc ./configure make make install ? Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List

Re: Freeradius 3 and DHCP

2013-10-09 Thread Arran Cudbard-Bell
On 9 Oct 2013, at 11:56, Rok Kosir rok.ko...@cosylab.com wrote: On 10/08/2013 07:09 PM, Arran Cudbard-Bell wrote: On 8 Oct 2013, at 17:44, Phil Mayers p.may...@imperial.ac.uk wrote: On 08/10/13 17:01, Rok Kosir wrote: authentication to mysql), when i run freeradius -X, i get

Re: FR3 Debugging Switches

2013-10-09 Thread Arran Cudbard-Bell
-enabled/tls[7]: You probably need to do 'radiusd -fxx -l stdout' for debugging The init scripts for debian (possibly RHEL too) trigger the latter one, as it runs a config check on restart (which bails out due to the error above). Ok that's a legitimate issue and should be fixed. Arran Cudbard

Re: FR3 Debugging Switches

2013-10-09 Thread Arran Cudbard-Bell
radsec. Isn't it required for doing any RADIUS over TCP? Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Managing Data Volume Control More Than 4GB FR CoovaChilli

2013-10-08 Thread Arran Cudbard-Bell
be an idea to add those to the internal dictionary to make it a bit easier. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Managing Data Volume Control More Than 4GB FR CoovaChilli

2013-10-08 Thread Arran Cudbard-Bell
is rejected way way too early. You also invented counter-type and check-unit config pairs. The server isn't magic, just because it doesn't error out, doesn't mean it knows about those config pairs or will use values assigned to them. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development

Re: Version 3.0.0 has been released

2013-10-08 Thread Arran Cudbard-Bell
/raddb/README.rst Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Managing Data Volume Control More Than 4GB FR CoovaChilli

2013-10-08 Thread Arran Cudbard-Bell
On 8 Oct 2013, at 15:40, Russell Mike radius@gmail.com wrote: Dear Arran C. Bell, Thank you very much, i am extremely grateful for your advise and guidelines for troubleshoot also. i am currently experimenting a different rlm_sqlcounter using CoovaChilli dictionary All-In-MB. In

Re: Freeradius 3 and DHCP

2013-10-08 Thread Arran Cudbard-Bell
On 8 Oct 2013, at 17:44, Phil Mayers p.may...@imperial.ac.uk wrote: On 08/10/13 17:01, Rok Kosir wrote: authentication to mysql), when i run freeradius -X, i get Segmentation Fault when it reaches dhcp listner. See doc/bugs. and skip to section 2. :) Arran Cudbard-Bell a.cudba

Re: Problem with Cisco WLC probes in FR 2.2.1

2013-10-07 Thread Arran Cudbard-Bell
, REDEBUG3, REDEBUG4), which most, if not all modules use to log errors. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problem with Cisco WLC probes in FR 2.2.1

2013-10-07 Thread Arran Cudbard-Bell
to upstream proxy servers, i'll echo Alan D's thoughts on this, and say that it's really the responsibility of a AAA routing protocol. Though yes, for eduroam checking next hop connectivity is probably useful. Maybe an xlat method which returns the state of a realm? -Arran Arran Cudbard-Bell

Re: radwho not working

2013-10-07 Thread Arran Cudbard-Bell
through my StrongSwan server, with the simple following command: # strongswan leases FreeRadius should be so easy! It is if you understand SQL, and don't insist on using arcane decade old modules and utilities. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team

Re: Version 3.0.0 has been released

2013-10-07 Thread Arran Cudbard-Bell
of OpenLDAP client library. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Version 3.0.0 has been released

2013-10-07 Thread Arran Cudbard-Bell
On 7 Oct 2013, at 23:23, Arran Cudbard-Bell a.cudba...@freeradius.org wrote: On 7 Oct 2013, at 23:00, Alan DeKok al...@deployingradius.com wrote: Brian Julin wrote: You guys are truly obsessed. I get exhausted just reading your commit logs. :-) It's what I do. I'm just

Re: What does FR 2.2.2 fix?

2013-10-04 Thread Arran Cudbard-Bell
Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: What does FR 2.2.2 fix?

2013-10-04 Thread Arran Cudbard-Bell
you be willing to try git head? I'll roll a v2.2.2_rc0 if it sweetens the deal any? It'd just be really good to know that that particular issue was fixed before rolling out 2.2.2 and then finding it was something else and having to roll 2.2.3 a few weeks later. -Arran Arran Cudbard-Bell a.cudba

Re: Problem with Cisco WLC probes in FR 2.2.1

2013-10-04 Thread Arran Cudbard-Bell
version of FR. We'll be releasing 2.2.2 very soon to fix various issues with unlang. In the mean time could you try the current v2.x.x HEAD to see if it resolves your issues? -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See

Re: What does FR 2.2.2 fix?

2013-10-04 Thread Arran Cudbard-Bell
but we are still seeing stalled module in core messages that we did not see with 2.2.0 Any chance you could connect to one of the running processes and generate a core? -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Re: Running RADIUS in permanent debug mode with rotating log

2013-10-03 Thread Arran Cudbard-Bell
will be lost. It's also dangerous in that if someone has messed with the configurations, or overwritten the radiusd/freeradius(debian) binary you'll experience an unexpected migration to the new binary/config on next restart. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List

Re: Wifi APs Models compatible with by username dynamic vlan assignment

2013-10-03 Thread Arran Cudbard-Bell
to search for in devices specifications ... Look for claimed compliance with RFC3580/RFC4675 in the specifications of your Access-Point. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Password gets changed while proxying

2013-10-02 Thread Arran Cudbard-Bell
by default. You should see that the home server now refuses to process the request, instead of continuing with a garbled password. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: lifetime of dynamic clients

2013-10-02 Thread Arran Cudbard-Bell
security and RADIUS cluster management. The way you're trying to do this is wrong. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: control flow in FreeRADIUS authorize section

2013-10-02 Thread Arran Cudbard-Bell
We want to stop executing the BUNCH OF UNLANG CODE in the first two cases (infected and tempsus), effectively doing something like a return. Where you have ok in the case stanzas, put ok { ok = return } -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team

Re: control flow in FreeRADIUS authorize section

2013-10-02 Thread Arran Cudbard-Bell
, but functional. this is pretty much what I was going to suggest. ugly, yes. but sometimes simple is best. and its much easier for a non unlang'y person to understand the logic! :) Nah, the appearance of obscurity is another mans job security :p Arran Cudbard-Bell a.cudba...@freeradius.org

Re: Access Request from HA rejected

2013-09-30 Thread Arran Cudbard-Bell
responsibility in authorize. I don't know enough about crazy WiMAX authentication, but i'd guess one of those SPI values needs to be cached from the previous round, and checked this round? Maybe someone who knows more can describe how it's meant to work. -Arran Arran Cudbard-Bell a.cudba

Re: No EAP session matching the State variable (and other various messages)

2013-09-30 Thread Arran Cudbard-Bell
performance tweaks, optimizations, etc?). I've optimized as best I can the SQL component. This all seems related to the samba/winbind/ntlm_auth. I'll let someone else answer that one :) Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See

EAP-AKA, EAP-AKA'

2013-09-25 Thread Arran Cudbard-Bell
Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius - DeadLock

2013-09-25 Thread Arran Cudbard-Bell
On 25 Sep 2013, at 20:08, Alisson alissongoncal...@bsd.com.br wrote: Hi, I have a lot of logs with deadlocks Those would be caused by a bug in your custom SQL queries? Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Re: Freeradius - DeadLock

2013-09-25 Thread Arran Cudbard-Bell
-trans Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: empty preacct and accounting section

2013-09-25 Thread Arran Cudbard-Bell
processing retransmitting RADIUS message ... #goes on for a while for IPSec, only twice for PPTP RADIUS is not responding Could you provide the full debug (radiusd -X). Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Re: empty preacct and accounting section

2013-09-25 Thread Arran Cudbard-Bell
Are you saying my default file has these sections as empty? Or that the vpn clients are sending empty data? Sections. As the Warning clearly states, sections. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Comp128-1,2,3 support in EAP-SIM

2013-09-24 Thread Arran Cudbard-Bell
to it's specification), but just algorithms 1-3 are still useful. [1] http://www.hackingprojects.net/2013/04/secrets-of-sim.html Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Comp128-1,2,3 support in EAP-SIM

2013-09-24 Thread Arran Cudbard-Bell
Note: Comp128-4 (milenage) is still unknown (please contact one of the developers if you have access to it's specification), but just algorithms 1-3 are still useful. Actually it's not, it's published in the 3GGP standards, neat :) Arran Cudbard-Bell a.cudba...@freeradius.org

Re: Comp128-1,2,3 support in EAP-SIM

2013-09-24 Thread Arran Cudbard-Bell
On 24 Sep 2013, at 18:12, Arran Cudbard-Bell a.cudba...@freeradius.org wrote: Note: Comp128-4 (milenage) is still unknown (please contact one of the developers if you have access to it's specification), but just algorithms 1-3 are still useful. Actually it's not, it's published

Re: can not initiate sim, no RAND1 attribute [eap] ERROR - Default EAP type sim failed in initiate [eap]

2013-09-23 Thread Arran Cudbard-Bell
the attributes required in the users file (files). -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: acct_unique ID algorithm

2013-09-20 Thread Arran Cudbard-Bell
for the rlm_acct_unique module, which were present in the request. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: The Operation of SQL module

2013-09-20 Thread Arran Cudbard-Bell
that other module need information from database (check attribute). Yes the *-Password attributes, e.g. SHA1-Password, Cleartext-Password etc... You need to retrieve a 'known good' or 'reference' password in authorize, to enable authentication. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS

Re: eap-ttls with SMD5-Password

2013-09-20 Thread Arran Cudbard-Bell
User-Passwords is database is stored with SMD5-Password attribute and when I'm trying it with EAP authentications fails and I get these messages in debug: http://deployingradius.com/documents/protocols/compatibility.html MD5/SMD5 requires the reference password be in cleartext. Arran Cudbard

Re: Active Directory authentication question

2013-09-18 Thread Arran Cudbard-Bell
. No, the easier way is to complete the certificate chain using the signing cert which created the client certs in the first place. This needs to be made available to the EAP-TLS module. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe

Re: reconnecting to mysql

2013-09-17 Thread Arran Cudbard-Bell
(or something else) is closing the connection after one query? Why don't you trace it and find out. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius2 + MySQL + Accouting

2013-09-17 Thread Arran Cudbard-Bell
Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius2 + MySQL + Accouting

2013-09-17 Thread Arran Cudbard-Bell
On 17 Sep 2013, at 19:02, Wederson Rodrigues weder...@vipvilhena.com.br wrote: I used radtest just to show the attributes that are returning. I'm using a debian (ppp) as NAS, with the enabled plugins: plugin rp-radius.so pppoe.so radattr.so Even better, RTFS. Arran Cudbard-Bell a.cudba

Re: Last call for Version 2.2.1

2013-09-16 Thread Arran Cudbard-Bell
On 16 Sep 2013, at 13:44, Alan DeKok al...@deployingradius.com wrote: The list of changes is large: Seems sort of small to me :) Here's the changelog: https://github.com/FreeRADIUS/freeradius-server/blob/v2.x.x/doc/ChangeLog Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS

Re: Last call for Version 2.2.1

2013-09-16 Thread Arran Cudbard-Bell
colours too, ooo look at the pretty colours. PS has anyone tested it with MariaDB? Wondering if its 100% drop-in compatible? It's 100% drop-in compatible from what I've seen. RE the death of MySQL: http://community.spiceworks.com/topic/299394-mysql-dying-a-slow-death Arran Cudbard

Re: FreeRadius DHCP against LDAP

2013-09-13 Thread Arran Cudbard-Bell
it the way I suggested I highly recommend you use V3.0.0 (release_branch_3.0.0 or master/HEAD) instead, as the list/attribute handling is much better. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org

Re: FreeRadius DHCP against LDAP

2013-09-13 Thread Arran Cudbard-Bell
official release. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Replicating to multiple servers.

2013-09-12 Thread Arran Cudbard-Bell
Replicate-To-Realm += Procera-SMP } replicate } Just be aware there's no retransmission, and any accounting responses received will be silently discarded. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Re: Building FreeRadius with custom LDAP libraries

2013-09-12 Thread Arran Cudbard-Bell
--with-rlm-ldap-lib-dir= --with-rlm-ldap-include-dir= Top level configure. Thanks, Nick - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Replicating to multiple servers.

2013-09-12 Thread Arran Cudbard-Bell
doesn't complain, doesn't mean that the config will actually be used. The config is parsed to an intermediary format. Only known config items and sections get any kind of validation. If the config is syntactically correct then the server will start. Arran Cudbard-Bell a.cudba...@freeradius.org

Re: Building FreeRadius with custom LDAP libraries

2013-09-12 Thread Arran Cudbard-Bell
On 12 Sep 2013, at 11:02, Nikolaos Milas nmi...@noa.gr wrote: On 12/9/2013 11:47 πμ, Arran Cudbard-Bell wrote: --with-rlm-ldap-lib-dir= --with-rlm-ldap-include-dir= Top level configure. Thanks Arran, It worked! I have built and installed the new RPMs and things are working OK

Re: Freeradius 2.1.12 Second LDAP Server

2013-09-12 Thread Arran Cudbard-Bell
On 12 Sep 2013, at 16:29, Arran Cudbard-Bell a.cudba...@freeradius.org wrote: It's like you're asking for flying lessons, and showing up with a bicycle. There's a bit of a disconnect somewhere. Not true, they make these awesome little fold up bikes you can chuck in the back

Re: Freeradius 2.1.12 Second LDAP Server

2013-09-12 Thread Arran Cudbard-Bell
.xyz.local ... } libldap handles failover. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius 2.1.12 Second LDAP Server

2013-09-12 Thread Arran Cudbard-Bell
It's like you're asking for flying lessons, and showing up with a bicycle. There's a bit of a disconnect somewhere. Not true, they make these awesome little fold up bikes you can chuck in the back of the plane. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team

Re: Freeradius + 2 x LDAP + VLAN

2013-09-12 Thread Arran Cudbard-Bell
Tunnel-Private-Group-Id = 2 } } } } Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Debug show cleartext password

2013-09-11 Thread Arran Cudbard-Bell
. Is there an option to do not show the fiedl User-Password in cleartext? no. I guess we should do something with it to make it FIPS compliant but it's not a big priority. You're welcome to submit a patch. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe

Re: Debug show cleartext password

2013-09-11 Thread Arran Cudbard-Bell
is no. dont run in debug if you dont want to see debug. Sure, but radtest should probably have a password argument where it does a secure read from stdin. FreeRADIUS shouldn't obfuscate passwords in debug, that'd be stupid. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team

Re: radclient error

2013-09-11 Thread Arran Cudbard-Bell
, or pipe them through to stdin. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius DHCP against LDAP

2013-09-11 Thread Arran Cudbard-Bell
as to prepare some type of deployment schedule. Define production-ready... Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius DHCP against LDAP

2013-09-11 Thread Arran Cudbard-Bell
On 11 Sep 2013, at 15:37, Nikolaos Milas nmi...@noa.gr wrote: On 11/9/2013 5:05 μμ, Arran Cudbard-Bell wrote: Define production-ready... Production-ready DHCP Server: A DHCP Server that can be used as such in a real-life, mission-critical, organizational environment, i.e. in a network

Re: free radius setup

2013-09-10 Thread Arran Cudbard-Bell
password or to a SHA1 password. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: free radius setup

2013-09-10 Thread Arran Cudbard-Bell
by a non-profit such as my college is. The majority of Universities in the UK and many smaller colleges implement Eduroam which require 802.1X authentication. It's not terribly expensive seeing as all the software is free... -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS

Re: [ANN] Version 3.0.0-rc1

2013-09-09 Thread Arran Cudbard-Bell
with a proper fix. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: [ANN] Version 3.0.0-rc1

2013-09-09 Thread Arran Cudbard-Bell
installation, which IMHO is always an extremely bad idea with any unpackaged software. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: problem with initial setup

2013-09-09 Thread Arran Cudbard-Bell
? Which doesn't support Cleartext-Password. I think you can use User-Password as a check item there, but I honestly can't remember. You might want to consider upgrading. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Re: my Radius goal radius and openldap.

2013-09-09 Thread Arran Cudbard-Bell
FQDN, or set a comma delimited list of servers in the 'server' config item, libldap handles the failover. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: my Radius goal radius and openldap.

2013-09-09 Thread Arran Cudbard-Bell
enough. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: smbencrypt calculates false hash for German umlauts and other non-ASCII letters

2013-09-07 Thread Arran Cudbard-Bell
-8, or any non-standard 16-bit encoding. So the calculation of the NT hash will depend on the character set... which is largely secret. This makes it very difficult to create the *correct* NT hash. Can't we assume src as UTF8 for NAI (RFC4282)? Arran Cudbard-Bell a.cudba...@freeradius.org

[ANN] Version 3.0.0-rc1

2013-09-06 Thread Arran Cudbard-Bell
to opaque request data and regular expressions * Fix heimdal krb5 build The tarball is available here: https://github.com/FreeRADIUS/freeradius-server/archive/release_3_0_0_rc1.tar.gz Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See

Re: Freeradius 2.2.0 - binaries not being installed ???

2013-09-05 Thread Arran Cudbard-Bell
On 5 Sep 2013, at 18:08, Ben ben+freerad...@list-subs.com wrote: Hi, Am I being stupid or what ? Yes. The main binary is called radiusd, not freeradius. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http

Re: FreeRADIUS Accounting Logging to Two Separate Locations Simultaneously

2013-09-05 Thread Arran Cudbard-Bell
the packet stream, let them do whatever they want with it. That's usually the easiest way to solve these sorts of issues. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: CLASS value in SQL xlat

2013-09-04 Thread Arran Cudbard-Bell
executing my PL/SQL function. Anyone knows what encode format it is? =octal ASCII value You can edit safe_characters in dialup.conf to include additional chars that you don't want to convert. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe

Re: differentiate authoriztion/ authentication in separate ldap modules

2013-09-04 Thread Arran Cudbard-Bell
? Yes. update control { LDAP-BaseDN !* ANY } open_ldap.authorize open_ldap Or the other way around to auth against AD. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: differentiate authoriztion/ authentication in separate ldap modules

2013-09-04 Thread Arran Cudbard-Bell
auth traffic, but may be a factor if your server(s) are heaving loaded. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap: multiple radius profiles

2013-09-02 Thread Arran Cudbard-Bell
Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius2 and sqlite

2013-09-01 Thread Arran Cudbard-Bell
the value of filename. If it's not working you may have a very old version of FreeRADIUS. You should try upgrading to the latest released version. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: FreeRadius DHCP against LDAP

2013-08-31 Thread Arran Cudbard-Bell
On 31 Aug 2013, at 13:49, Nikolaos Milas nmi...@noa.gr wrote: On 31/8/2013 12:03 πμ, Arran Cudbard-Bell wrote: 1. Is DHCP functionality supported against an LDAP Server (in v2.2.0)? Yes. 2. If so, is there a planned freeradius ldap schema change (in future versions) to include DHCP

Re: Freeradius2 and sqlite

2013-08-31 Thread Arran Cudbard-Bell
the connection to sqlite file? With the 'filename' config item, and you need to set database to 'sqlite' sql { database = 'sqlite' filename = 'path to sqlite file' } It's done properly in 3.0. It's sort of hacked into 2.x.x. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS

Re: Freeradius2 and sqlite

2013-08-30 Thread Arran Cudbard-Bell
how? Yeah it's the 'filename' config item in sql.conf. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius2 and sqlite

2013-08-30 Thread Arran Cudbard-Bell
however may not. version 3.0.0 has queries specifically for sqlite, so you may want to try that. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius DHCP against LDAP

2013-08-30 Thread Arran Cudbard-Bell
? No. But you're welcome to submit a pull request. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: range of mac addresses

2013-08-29 Thread Arran Cudbard-Bell
:= e806882925ce #Range of mac addresses: 94ebcd** Cleartext-Password := 94ebcd** DEFAULT User-Password =~ '^94ebcd[0-9a-f]{6}$', Auth-Type := Accept Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org

Re: brocade dictionnary on freeradius 2-2.1.7

2013-08-28 Thread Arran Cudbard-Bell
Brocade I've added brocade dictionaries to v2.x.x and master branches. Use one of those and it'll probably work. Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: how to limit the repeating ldap lookups

2013-08-28 Thread Arran Cudbard-Bell
not work if ( (EAP-Type == EAP-TLS) (EAP-Message !~ /^0x02([1-9a-f].|0[7-9a-f])00060d00$/) ) { default = return } Does anyone have a configuration which gets it down to a single LDAP query for PEAP? Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List

CISCO ASA VPN3000 dictionary

2013-08-28 Thread Arran Cudbard-Bell
a byte. For boolean does anyone know if they really mean a standard 32bit integer with the values 0/1, or if they're wanting a single byte with the values 0/1, or whether it's some other cisco craziness? -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List

Re: how to limit the repeating ldap lookups

2013-08-28 Thread Arran Cudbard-Bell
On 28 Aug 2013, at 15:01, Phil Mayers p.may...@imperial.ac.uk wrote: On 28/08/13 14:49, Arran Cudbard-Bell wrote: Does anyone have a configuration which gets it down to a single LDAP query for PEAP? What inner? MSHCAPv2 - I thought PEAPv0 was only MSCHAPv2? Arran Cudbard-Bell a.cudba

Re: how to limit the repeating ldap lookups

2013-08-28 Thread Arran Cudbard-Bell
On 28 Aug 2013, at 15:26, Matthew Newton m...@leicester.ac.uk wrote: On Wed, Aug 28, 2013 at 03:11:04PM +0100, Arran Cudbard-Bell wrote: On 28 Aug 2013, at 15:01, Phil Mayers p.may...@imperial.ac.uk wrote: On 28/08/13 14:49, Arran Cudbard-Bell wrote: Does anyone have a configuration

Re: how to limit the repeating ldap lookups

2013-08-28 Thread Arran Cudbard-Bell
On 28 Aug 2013, at 15:38, Phil Mayers p.may...@imperial.ac.uk wrote: On 28/08/13 15:11, Arran Cudbard-Bell wrote: On 28 Aug 2013, at 15:01, Phil Mayers p.may...@imperial.ac.uk wrote: On 28/08/13 14:49, Arran Cudbard-Bell wrote: Does anyone have a configuration which gets it down

Re: EAP logging

2013-08-27 Thread Arran Cudbard-Bell
. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org FreeRADIUS Development Team - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Mac Auth against LDAP

2013-08-26 Thread Arran Cudbard-Bell
On 24 Aug 2013, at 10:00, Nikolaos Milas nmi...@noa.gr wrote: On 23/8/2013 9:19 μμ, Arran Cudbard-Bell wrote: It'll either be in NAS-Port or NAS-Port-ID if the NAS is providing that information. Thanks Arran, It was NAS-Port indeed. Strangely enough, this is not included either

  1   2   3   4   5   6   7   8   9   10   >