RE: Wrong sequence of packets during re-authentication

2005-09-25 Thread Bilal Shahid
Hello again, Can someone please help me this? I am clueless as how to solve this problem. Thanks, Bilal -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bilal Shahid Sent: Friday, September 23, 2005 4:00 PM To: freeradius-users@lists.freeradius.org

Wrong sequence of packets during re-authentication

2005-09-23 Thread Bilal Shahid
Hello all, During my 802.1X Supplicant's re-authentication (using EAP-TTLS) with FreeRADIUS using DLINK switch, I face the following scenario: Sometimes during re-authentication, one of the FreeRADIUS's replies does not reach the DLINK switch. When DLINK's RADIUS timer expires, it re-starts

EAP-MD5 usage

2005-08-23 Thread Bilal Shahid
Hello, I have a question about EAP-MD5 usage. Would appreciate any help. I am using FreeRADIUS as the Authentication Server with Open1X Supplicant. When I set Supplicant Identity different from EAP-MD5 username, the RADIUS Server sends my Supplicant an Access-Reject. My questions are the

Session resumption

2005-04-19 Thread Bilal Shahid
Does FreeRADIUS v1.0.1 support session resumption (fast reconnect during reauthentication) for TLS, TTLS and PEAP? Thanks, Bilal _ Don't just search. Find. Check out the new MSN Search! http://search.msn.com/ - List

FreeRADIUS with different APs

2005-03-31 Thread Bilal Shahid
The NAS list in the FreeRADIUS shows some typical NAS's like Cisco, Portslave etc with which the FreeRADIUS works. I was wondering if the FreeRADIUS Server only works with the NAS's listed or the type of NAS doesn't matter? I ask this because I am having problems getting my 802.1X Supplicant

Strange Re-authentication problem

2005-03-17 Thread Bilal Shahid
Hi, Following is my testing environment: WPA Supplicant Proxim AP 600 (Access Point) FreeRADIUS Server 802.11i environment (802.1X, CCMP, 4-way handshake etc) Initial authentication of the Supplicant is taking place fine. But I am facing a strange issue during subsequent

802.11i

2004-12-13 Thread Bilal Shahid
Hi, Does FreeRADIUS support 802.11i? On a more general level; in the wireless environment, does the RADIUS Server (any RADIUS Server) need to support 802.11i or just the intervening Access Point with this support is required? Thanks, Bilal

Acct-Terminate-Cause = Port-Reinit

2004-12-12 Thread Bilal Shahid
Hi, I am getting my 802.1X XSupplicant authenticate with my Access Point using FreeRADIUS successfully, but after sometime (570 seconds) FreeRADIUS displays the following output and the authentication session discontinues: rad_recv: Accounting-Request packet from host 137.202.157.28:1027,

PEAP-EAP-MSCHAPv2

2004-12-06 Thread Bilal Shahid
Hi, I have a couple of questions. Would greatly appreciate any help. 1- I keep getting the following error rlm_eap_mschapv2: Response contains contradictory length 0 54 while using PEAP-EAP-MSCHAPv2 to authenticate the XSupplicant with FreeRADIUS. Following is the partial lof from FreeRADIUS run

extendedKeyUsage = 1.3.6.1.5.5.7.3.1

2004-11-19 Thread Bilal Shahid
Hi, I am using FreeRADIUS to authenticate the XSupplicant using EAP-TLS. The certificates are being generated using the script CA.all. For the Server certificate, the TLS Web Server OID used is 1.3.6.1.5.5.7.3.1. Now what the FreeRADIUS Server is actually sending out to the Client

-extensions in CA.all

2004-11-11 Thread Bilal Shahid
Hi, Following line is from the CA.all script provided by FreeRADIUS for generation of certificates: openssl ca -policy policy_anything -out newcert.pem -passin pass:whatever -key whatever -extensions xpclient_ext -extfile xpextensions -infiles newreq.pem My question is: Is the use of

Re: -extensions in CA.all

2004-11-11 Thread Bilal Shahid
PROTECTED] Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: -extensions in CA.all Date: Thu, 11 Nov 2004 12:10:07 -0500 Bilal Shahid [EMAIL PROTECTED] wrote: Is the use of -extensions here necessary for authenticating a Client to the FreeRADIUS Server using EAP-TLS/EAP-TTLS? a client

Re: -extensions in CA.all

2004-11-11 Thread Bilal Shahid
[EMAIL PROTECTED] Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: -extensions in CA.all Date: Thu, 11 Nov 2004 14:53:28 -0500 Bilal Shahid [EMAIL PROTECTED] wrote: I apologize if this question sounds silly but which type of Clients need the use of extensions and which type does