[How To] Freeradius 2.14 (PEAP – MSCHAP)

2009-03-10 Thread LEOSI
For thoses, who are interested by setting up PEAP/MSHCAP under Freeradius 2.14, I wrote a simple how-to. I hope it could help someone. :) INSTALLATION PROCESS: FREERADIUS 2.14 (PEAP – MSCHAP) === OS : === - Ubuntu Server 8.10 == SWITCH: == - HP 2600 == Pre-requires :

Re: [How To] Freeradius 2.14 (PEAP – MSCHAP)

2009-03-10 Thread LEOSI
A.L.M.Buxey wrote: one small quirk though, you say its for FR 2.14 - in fact, its for FR 2.1.3 - (2.1.4 isnt yet released) modified :) thx! -- View this message in context: http://www.nabble.com/-How-To--Freeradius-2.14-%28PEAP-%E2%80%93-MSCHAP%29-tp22433641p22434045.html Sent from the

Autz-type LDAP, Auth-Type MSCHAP possible ? (for vlan assignment)

2009-02-18 Thread LEOSI
Hi, I’m trying to set up Freeradius to use the LDAP module for the authorization and process authentication with MSCHAPv2. My goal is to assign vlans from some Organizational Units in AD. I wanted to use into the users files the argument “huntgroups” because it could check OU. Last time I tried

Re: Autz-type LDAP, Auth-Type MSCHAP possible ? (for vlan assignment)

2009-02-18 Thread LEOSI
tnt-4 wrote: So do it. You don't need to force any Auth or Autz types. Set up the group membership filter in ldap module. It will give you Ldap-Group which you can use to assign vlans: DEFAULT Ldap-Group == something some tunnel attributes DEFAULT Ldap-Group ==

Re: Autz-type LDAP, Auth-Type MSCHAP possible ? (for vlan assignment)

2009-02-18 Thread LEOSI
Remove that Autz-Type := Ldap Done. preprocess Autz-Type LDAP { ldap } Removed too. And the debug (a little bit long...) : Wed Feb 18 16:19:31 2009 : Debug: Listening on authentication address * port 1812 Wed Feb 18 16:19:31 2009 : Debug: Listening on accounting address * port 1813

Freeradius with OpenLDAP and AD.

2009-02-17 Thread LEOSI
Hi, I have several problems when I would like to link freeradius with AD using OpenLDAP. When I tried to test the binding of OpenLDAP to the AD with radtest, it responds Access-Accept (as you can see in the log after). But when I wanted to check with a real supplicant (under WinXP with