RE: mschapv2 and users file

2007-06-20 Thread Matt Cobb
, June 20, 2007 1:47 AM To: FreeRadius users mailing list Subject: Re: mschapv2 and users file Use Cleartext-Password and operator := That listing seems to be from the attempt with NT-Password. That entry should also use := as the operator. Ivan Kalik Kalik Informatika ISP Dana 20/6/2007, Matt

RE: mschapv2 and users file

2007-06-20 Thread Matt Cobb
Alan, I believe you that is can work - I just want to know how to configure it so it does :-) Here is the output: Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /etc/raddb/proxy.conf Config: including file: /etc/raddb/clients.conf

peap in users file?

2007-05-24 Thread Matt Ashfield
:56:47 2007 : Debug: auth: Failed to validate the user. Any advice is appreciated. Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Stops working all of a sudden

2007-05-05 Thread Matt Neumark
May 4 16:09:51 2007 : Error: rlm_radutmp: Logout entry for NAS mikrotik port 47337 has wrong ID Thanks, Matt Neumark - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Assign Vlan based on Inner Identity (was: Force Inner=Outer identity)

2007-05-03 Thread Matt Ashfield
Hi All I doubt my original post was doable, , it probably doesn't make sense to ask FR to be able to force Inner=Outer identity. In that case, would it be possible to perform authorization based on the Inner identity instead of the Outer identity? Matt [EMAIL PROTECTED] -Original Message

Force Inner=Outer identity

2007-05-02 Thread Matt Ashfield
. Makes user tracking quite difficult. Is there any way to force a users's outer identity to equal their inner identity? Thanks Matt Ashfield [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

problem with Dell connection manager?

2007-05-01 Thread Matt Ashfield
on a workaround? Thanks for any advice. Cheers Matt Ashfield [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Maximum Attribute Size

2007-04-30 Thread Matt Dunkin
Is there any maximum size for the value of an attribute? Thanks, Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: NAS not accepting the Access-Accept?

2007-04-24 Thread Matt Ashfield
Ok thanks! I am definitely seeing the NAS request Administrative-User in the Access-Request packet. I guess I wsen't returning it! Thanks for your help. Matt -Original Message- From: Alan DeKok [mailto:[EMAIL PROTECTED] Sent: April 24, 2007 3:21 AM To: [EMAIL PROTECTED]; FreeRadius

RE: restricting users access to clients?

2007-04-20 Thread Matt Ashfield
time deny all my 802.1x users because of the Reject statement? I'm a bit confused, so any help is appreciated. Cheers Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

suggestions for multiple vlans in hundreds of switches

2007-04-19 Thread Matt Ashfield
30 definitions like the ones above in my users file for EACH one of my NAS's. I'm sure there's a simpler way of doing things that I'm missing. Any advice is appreciated. Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: suggestions for multiple vlans in hundreds of switches

2007-04-19 Thread Matt Ashfield
I was afraid someone would say that! Haha Matt -Original Message- From: Donny Jekels [mailto:[EMAIL PROTECTED] Sent: April 19, 2007 10:57 AM To: [EMAIL PROTECTED]; FreeRadius users mailing list Subject: Re: suggestions for multiple vlans in hundreds of switches you could extend

RE: suggestions for multiple vlans in hundreds of switches

2007-04-19 Thread Matt Ashfield
to the edge. Matt Ashfield Network Analyst Integrated Technology Services University of New Brunswick (506) 447-3033 [EMAIL PROTECTED] -Original Message- From: robinson santos [mailto:[EMAIL PROTECTED] Sent: April 19, 2007 12:31 PM To: [EMAIL PROTECTED]; FreeRadius users mailing list

assigning vlan based on NAS and LDAP field?

2007-04-12 Thread Matt Ashfield
, but probably quite similar to what many EDU people are encountering. Any help/advice is greatly appreaciated. Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

timeouts through a firewall?

2007-04-05 Thread Matt Ashfield
to increase the timeout. Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

CRL List does not appear to work with Freeradius

2007-03-23 Thread Matt Harlum
Hey guys, I've been using freeradius for a while now, and i want to be able to revoke my certs, however when i have revoked them it can't find the CRL and as such nobody can log in - even people who have certs that are not revoked. i just get the following message, even thugh my crl.pem is

Double entries in Radacct

2007-03-16 Thread Matt Neumark
Hello, I have a MikroTik router that is passing accounting data to the freeradius database. I look in radacct and every entry is has duplicates with the exact same information. Does anyone know if this is the MikroTik causing this or freeradius? How do I fix this? Thanks, Matt Neumark - List

restricting users access to clients?

2007-03-14 Thread Matt Ashfield
in FreeRadius. I would assume that you'd specify in the clients.conf section which users are allowed access to that device, but in looking at the documentation for clients.conf, that doesn't seem to be the case. Any links/advice is appreciated. Thanks Matt [EMAIL PROTECTED] - List info/subscribe

RE: restricting users access to clients?

2007-03-14 Thread Matt Ashfield
Ok, the users file it is! Thanks! I guess I was hoping for a link to an example of some sort. Because the user who would be given access is not explicitly defined in the users file (the users is defined in LDAP), I'm not sure how to setup a rule for that person. Thanks again, Cheers Matt

EAP and System users?

2007-03-09 Thread Matt Ashfield
Hi, We've been working on having a setup that can authenticate users against LDAP via EAP (Chap) as well as System users. We can get it to do one or the other, but not both. Is it possible to do both? If so, how? Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http

RE: EAP and System users?

2007-03-09 Thread Matt Ashfield
individually. Meaning I can configure FR to authenticate System users. I can also configure FR to authenticate against LDAP. But we cannot seem to combine them and offer both options. Matt [EMAIL PROTECTED] -Original Message- From: Alan DeKok [mailto:[EMAIL PROTECTED] Sent: March 9, 2007

RE: guest acces?

2007-03-02 Thread Matt Ashfield
% positive I'm putting the password in correctly. The user baduser has a shell of /sbin/nologin. Would that account for any of this? Thanks Matt [EMAIL PROTECTED] -Original Message- From: Alan DeKok [mailto:[EMAIL PROTECTED] Sent: March 2, 2007 4:47 AM To: [EMAIL PROTECTED]; FreeRadius

guest acces?

2007-03-01 Thread Matt Ashfield
and I'm missing the reason why for that too! Any advice is appreciated. Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

group question

2007-02-27 Thread Matt Ashfield
also apply: DEFAULT Group == disabled, Auth-Type := Reject Reply-Message = Your account has been disabled But where do I specify that group disabled? Is that a group on my linux system or is that group defined within Radius, and if so, where? Thanks Matt [EMAIL PROTECTED] - List info

pap/peap confusion

2007-02-14 Thread Matt Ashfield
the comparison to LDAP stored passwords via MSCHAP as well? Thanks for any info. Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: EAP-PEAP/MS-ChapV2 password storing options

2007-02-13 Thread Matt Ashfield
Thanks for the link! BTW, I have nothing against SecureW2, but if we don't have to install an extra piece of software on 10,000 computers on campus, I'd like to avoid it! Matt -Original Message- From: Alan DeKok [mailto:[EMAIL PROTECTED] Sent: February 13, 2007 2:57 AM To: [EMAIL

EAP-PEAP/MS-ChapV2 password storing options

2007-02-12 Thread Matt Ashfield
-PEAP/MS-ChapV2 to work with FreeRadius, what are my options for storing the password in LDAP? Does it have to be clear-text? Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

a bit off-topic policy question

2007-01-08 Thread Matt Ashfield
and capture sensitive login information. Any advice/feedback is appreciated. Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

authenticating question

2006-10-25 Thread Matt Ashfield
that would be the ideal solution. Any suggestions are welcome. Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: authenticating question

2006-10-25 Thread Matt Ashfield
Thanks! Matt [EMAIL PROTECTED] -Original Message- From: Garber, Neal [mailto:[EMAIL PROTECTED] Sent: October 25, 2006 11:57 AM To: [EMAIL PROTECTED]; FreeRadius users mailing list Subject: RE: authenticating question We are trying to authenticate users based on the username/password given

Re: radutmp and/or SQL Accounting

2006-10-22 Thread Matt Harlum
, at 5:15 PM, Peter Nixon wrote: On Sat 21 Oct 2006 13:25, Matt Harlum wrote: Actually, is anyone able to confirm if the accounting is actually dependant on my hardware? because i'm thinking the RADIUS on my Access Point doesn't support the accounting functions. Yes. Your access point has

Re: radutmp and/or SQL Accounting

2006-10-21 Thread Matt Harlum
Actually, is anyone able to confirm if the accounting is actually dependant on my hardware? because i'm thinking the RADIUS on my Access Point doesn't support the accounting functions. On 21/10/2006, at 8:01 PM, Matt Harlum wrote: Hey guys, I've got my radiusd setup to work from an SQL

RE: assigning vlan based on LDAP attribute

2006-09-27 Thread Matt Ashfield
, Fall-Through = no But this doesn't seem to work. My staff users do not get assigned to vlan 2. Do I need to make a huntgroup for myAP? If there's a link to an overview or something, it would be much appreciated. Any help is appreciated. Thanks Matt [EMAIL PROTECTED] -Original

RE: RE : assigning vlan based on LDAP attribute

2006-09-27 Thread Matt Ashfield
-UserDn}))((objectClass=GroupO fUniqueNames)(uniquemember=%{Ldap-UserDn}))) You asked: * is your AP accepting Tunnel-Private-Group-Id=2 (I've got AP which uses other format). How do I check that? Thanks Matt -Original Message- From: Thibault Le Meur [mailto:[EMAIL PROTECTED] Sent

Re: Kill Users Connection

2006-08-11 Thread Matt Dunkin
All depends on the gateway/router. What are using? -Matt Dunkin fvt3 wrote: Hi, Is there a way to kill a user connection? I did some reading and I came across radkill. Can you use radkill with radius? If you can, where can you download ? Thanks in advance

Re: Unresponsive child

2006-08-09 Thread Matt Dunkin
Thanks for the suggestions guys... for now I think I have located the problem. I had the max servers set at 32. I bumped that number up to 64 and also cleaned up my perl script a little. Alan Lumb wrote: I do exactly the same thing as you - I get this problem from time to time (usually

Unresponsive child

2006-08-08 Thread Matt Dunkin
After some recent changes to my rlm_perl perl script I am getting the following messages all the time... Tue Aug 8 08:08:50 2006 : Error: WARNING: Unresponsive child (id 2966633392) for request 28 Tue Aug 8 08:08:50 2006 : Error: WARNING: Unresponsive child (id 2977528752) for request 27 Tue

Re: Unresponsive child

2006-08-08 Thread Matt Dunkin
prepare failed: handle 2 is owned by thread 9b19fc8 not current thread 9cfdac8 (handles can't be shared between threads and your driver may need a CLONE method added) at /usr/local/etc/raddb/modules/billing.pl line 214. Alan DeKok wrote: Matt Dunkin [EMAIL PROTECTED] wrote: After some

assigning vlan based on LDAP attribute

2006-07-28 Thread Matt Ashfield
userDepartment attribute equals HR into vlan 4? If so, could you give me a link to how to do that, or explain briefly? Thanks for your time, Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: 802.1x with mschap-radius-ldap with ssha-1 passwords

2006-07-18 Thread Matt Ashfield
by the authenticator to the ssha-1 password stored in ldap? Thanks Matt Ashfield Network Analyst Integrated Technology Services University of New Brunswick (506) 447-3033 [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: July 17, 2006 7:51 PM To: [EMAIL

RE: EAP-TTLS-PAP-LDAP

2006-07-18 Thread Matt Ashfield
{ encryption_scheme = sha1 } Cheers Matt Ashfield [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Phil Mayers Sent: July 15, 2006 8:09 AM To: FreeRadius users mailing list Subject: Re: EAP-TTLS-PAP-LDAP Rohaizam Abu Bakar wrote: Thanks

RE: RE : EAP-TTLS-PAP-LDAP

2006-07-18 Thread Matt Ashfield
CHAP { chap } Auth-Type MS-CHAP { mschap } unix # Auth-Type LDAP { # ldap # } eap } The first line in my users file for my Access Point is: DEFAULT Auth-Type = ldap Fall-Through = 1 Matt

Digest auth with LDAP

2006-07-17 Thread Matt
works : DEFAULT Auth-Type := digest, Digest-HA1 := 409e2df0ac3a755199a8a91817bb87b8 But it's works of course only for my login. How to do this for different login? Thank you for your help and sorry for my English! Sincerely, Matt -- View this message in context: http://www.nabble.com/Digest-auth

Re: mysql default install schema

2006-07-17 Thread Matt Manjos
ah, thank you very much. i kept grepping for db_mysql On 7/16/06, Alan DeKok [EMAIL PROTECTED] wrote: Matt Manjos [EMAIL PROTECTED] wrote: Hello, it's my first install of freeradius using mysql for auth and I must be going mental because I can't seem to find the default schema to import

Re: mysql default install schema (Matt Manjos)

2006-07-17 Thread Matt Manjos
Thank you, it loaded into the database fine. On 7/17/06, Kun Niu [EMAIL PROTECTED] wrote: Hi Matt, Here is the db_mysql.gz I copied from /usr/share/doc/freeradius/examples You can make some minor changes if you get warning when installing. Hope you good luck

802.1x with mschap-radius-ldap with ssha-1 passwords

2006-07-17 Thread Matt Ashfield
Hi All I'm trying to do 802.1x authentication using freeradius against an LDAP directory which stores the userPassword in an ssha-1 hash. My question is, is this possible? If so, how do I configure mschap for ssha-1 passwords? Thanks for your time/advice, Cheers Matt - List info/subscribe

RE: 802.1x with mschap-radius-ldap with ssha-1 passwords

2006-07-17 Thread Matt Ashfield
Matt Ashfield Network Analyst Integrated Technology Services University of New Brunswick (506) 447-3033 [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: July 17, 2006 4:00 PM To: [EMAIL PROTECTED]; FreeRadius users mailing list Subject: Re

mysql default install schema

2006-07-16 Thread Matt Manjos
/modules/rlm_sql/drivers/rlm_sql_mysql) and I still can't seem to find it anywhere. Where do I get the default schema from? Many Thanks, Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: mysql default install schema

2006-07-16 Thread Matt Manjos
hmm, there's a copy of the schema in the 1.0.5 source code. Is it safe to use this one, or is there a newer version somewhere? Thanks for reply, Matt On 7/16/06, Matt Manjos [EMAIL PROTECTED] wrote: Hello, it's my first install of freeradius using mysql for auth and I must be going mental

certificate requirements for EAP-PEAP using Radius-to-LDAP

2006-07-14 Thread Matt Ashfield
to have on my radius server for doing the NAS-radius conversation as well as the ldap authorization. Also, what certificates do I need for/from the LDAP server? Thanks Matt [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: an infamous LDAP-FreeRadius question

2006-07-12 Thread Matt Ashfield
. Thanks Matt [EMAIL PROTECTED] -Original Message- From: Zoltan Ori [mailto:[EMAIL PROTECTED] Sent: July 11, 2006 12:33 PM To: [EMAIL PROTECTED]; 'FreeRadius users mailing list' Subject: Re: an infamous LDAP-FreeRadius question On Tuesday 11 July 2006 10:10, Matt Ashfield wrote: When I

RE: an infamous LDAP-FreeRadius question

2006-07-11 Thread Matt Ashfield
seen quite a bit of threads concerning this but as mentioned in my initial email, they can be tough to follow. Thanks Matt Ashfield [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: July 10, 2006 4:51 PM To: [EMAIL PROTECTED]; FreeRadius users

RE: an infamous LDAP-FreeRadius question

2006-07-11 Thread Matt Ashfield
Actually, I only have the ldap -to- radius authentication when doing a radtest. There's no eap involved at that point. I think my issue of adding the EAP/802.1x stuff is where I'm hitting the snag. Matt Ashfield Network Analyst Integrated Technology Services University of New Brunswick (506) 447

an infamous LDAP-FreeRadius question

2006-07-10 Thread Matt Ashfield
for authentication against LDAP (not active directory) which has usernames and password stored on it in cleartext. Presumably I'd be using PEAP for this. If anyone has this or can give a hand offline from this mailing list, that would be much appreciated. Thanks Matt [EMAIL PROTECTED] - List info

Re: FreeRadios rlm_sql dumps if databaase server hiccups

2006-06-16 Thread Matt
Ok, Well with no answer to this question let me ask it another way... In the event of database (via ODBC) failure... is there a way I can make the radius server go into failsafe mode, and just authenticate anything? On 6/15/06, Matt [EMAIL PROTECTED] wrote: Hi, We use FreeRadius with unixODBC

Re: FreeRadios rlm_sql dumps if databaase server hiccups

2006-06-16 Thread Matt
' :) If your database is down you're out of business. There are much better 'failsafe' methods - search for fail-over in the FreeRadius documentation. Matt wrote: Ok, Well with no answer to this question let me ask it another way... In the event of database (via ODBC) failure... is there a way I can

Bug with multiple IPs?

2006-06-15 Thread Matt
I have freeradius running on a machine with 2 IPs. I have it binding to all available IPs. xxx.xxx.xxx.44 is the main IP of the machine xxx.xxx.xxx.26 is the secondary IP. (eth0:1) When a request comes in on .26 freeradius processes it and THEN sends the reply out .44! Is this the way it is

Re: Bug with multiple IPs?

2006-06-15 Thread Matt
AHHHA! I did *not* use with-udpfromto... DOH! On 6/15/06, Kevin Bonner [EMAIL PROTECTED] wrote: On Thursday 15 June 2006 13:20, Matt wrote: I have freeradius running on a machine with 2 IPs. I have it binding to all available IPs. xxx.xxx.xxx.44 is the main IP of the machine xxx.xxx.xxx

FreeRadios rlm_sql dumps if databaase server hiccups

2006-06-15 Thread Matt
Hi, We use FreeRadius with unixODBC and the rlm_sql to connect to a Microsoft SQL database. All works great... except if the SQL database goes down, firewall has the translate table, someone trips over a network cable anything that causes the connection between the radius and SQL to be

Logging ONLY failed authentication and not correct?

2005-12-29 Thread Matt
Hi two questions. #1 Is there a way to log only incorrect logins in radius.log and to ignore correct logins (so as to not fill up the log file)? #2 When I do get a login incorrect right now I get: Auth: Login incorrect (rlm_chap: Clear text password not available): [EMAIL

Re: After the manual's config, chap wont work with LDAP

2005-12-16 Thread Matt Juszczak
for that attribute. Chap is above pap, and chap is also in authenticate {}. The password is still showing up as blank when they dial up, before it even hits the LDAP server. Is there debugging output I could send you that might help with this? Regards, Matt - List info/subscribe/unsubscribe? See

After the manual's config, chap wont work with LDAP

2005-12-15 Thread Matt Juszczak
authentication.. so its obviously something with the config of freeradius. Thanks for any help! -Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius and Interim Packets

2005-12-05 Thread Matt
DeKok [EMAIL PROTECTED] wrote: Matt [EMAIL PROTECTED] wrote: Does anyone have experience with FreeRadius and Interim packets? Does it work ok? Any problems? How do you enable it? Yes. It works. You enable it by installing the server. Did you *try* it? Alan DeKok. - List info

Re: FreeRadius and Interim Packets

2005-12-05 Thread Matt
for it, that's why I'm asking these questions. On 12/5/05, Joe Maimon [EMAIL PROTECTED] wrote: Matt wrote: Ok, well now hold on a second. It's not simply the sending/receiving/logging of interim packets that determines whether or not the RADIUS server has interim packet support. For a RADIUS

FreeRadius and Interim Packets

2005-12-01 Thread Matt
Does anyone have experience with FreeRadius and Interim packets? Does it work ok? Any problems? How do you enable it? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius and Interim Packets

2005-12-01 Thread Matt
I have the server installed I haven't yet tried it. Ok that's what I was looking for. On 12/1/05, Alan DeKok [EMAIL PROTECTED] wrote: Matt [EMAIL PROTECTED] wrote: Does anyone have experience with FreeRadius and Interim packets? Does it work ok? Any problems? How do you enable

LDAP, FreeRadius, and Schema

2005-11-29 Thread Matt Juszczak
be used. Regards, Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Error with free radius, as5800, and ascend data types

2005-11-23 Thread Matt
Hi, We have this radius-reply-attribute in our radius configuration (free-radius): ip in forward tcp est However, when someone dials up to our as5800 it generates this error: rlm_sql: Failed to create the pair: failed to parse Ascend binary attribute: Unknown string est in IP data filter

Re: Error with free radius, as5800, and ascend data types

2005-11-23 Thread Matt
We are running FR version 1.0.5 And no, it doesn't seem to work in the users file syntax. On 11/23/05, Chris Parker [EMAIL PROTECTED] wrote: Cisco has an option to accept the non-standard Ascend attributes ( note, NOT the VSA's but the early Ascend attempt to use higher numbered standard

Re: Error with free radius, as5800, and ascend data types

2005-11-23 Thread Matt
Hrmm yeah.. see that after est? as in estnot est ? Yeah apparently there were a /n and a /r after it, which the database didn't show... ugh. On 11/23/05, Matt [EMAIL PROTECTED] wrote: Hi, We have this radius-reply-attribute in our radius configuration (free-radius): ip in forward

Re: Odd problem (FreeRadius 1.0.5 / MSSQL 2000 / Fedora Core 3)

2005-11-16 Thread Matt
For anyone else having this problem. We had to roll back our FREETDS install from 0.63 to 0.62.3. I'm not sure why the new version of FREETDS has an issue, but I know I was advised of this with asterisk as well. On 11/15/05, Matt [EMAIL PROTECTED] wrote: We have the exact same configuration

Odd problem (FreeRadius 1.0.5 / MSSQL 2000 / Fedora Core 3)

2005-11-15 Thread Matt
We have the exact same configuration working on another system, but have been unable to get it to work correctly on this Fedora Core 3 system. We are using rlm_sql to have FreeRadius talk to our MSSQL 2000 database. That works. The odd part is on the Fedora Core 3 system it seems to be having

Patch for Statistics page

2005-10-13 Thread Matt Vollmar
like sql_full_date_format in the admin.conf. Hope this helps someone. Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

(no subject)

2005-08-29 Thread Matt morris
Hello List, Thanks for the reply, Thor. So how do I setup freeradius to use rlm_perl then? Some pointers will be greatly appreciated. Thank you. Original Message: === Hello list, This has probably been asked a lot times before, but I just couldn't get the attributes values from

rlm_exec and retriving RAD_REQUEST attribute values

2005-08-24 Thread Matt morris
Hello list, This has probably been asked a lot times before, but I just couldn't get the attributes values from accounting request packets with my perl script. I am trying to do some database queries when I received stop accounting request packets, here are the relevant sections of my

FreeRADIUS and LDAP

2005-07-18 Thread Matt Juszczak
parameters as well? Thanks! -Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re:LDAP basedn context

2005-06-14 Thread Matt McFarlane
ldap_connections_number = 5 password_attribute = nspmPassword timeout = 4 timelimit = 3 net_timeout = 1 } matt... Is it possible to specify the basedn above where the users are actually located and have freeradius

FW: How to get Hint to match in users file

2005-06-14 Thread Matt Cobb
-Original Message- From: Matt Cobb Sent: Tuesday, June 14, 2005 2:07 PM To: '[EMAIL PROTECTED]' Subject: How to get Hint to match in users file What syntax do you use to get Hint to match in the users file? In Hint I have: DEFAULT Prefix == LOCKDOWN\\, Strip-User-Name = Yes

LDAP basedn context

2005-06-08 Thread Matt McFarlane
? Thanks. Matt McFarlane - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius-Users digest, Vol 1 #4631 - 12 msgs

2005-05-19 Thread Matt McFarlane
You can't use PEAP unless you have plaintext passwords stored in the LDAP or NT/LM password hashes. To use LDAP bind to authenticate you will need to use TTLS with PAP as inner tunnel authentication. This is how you can configure your clients to use TTLS+PAP The passwords are revealed

WinXP 802.1X/Radius/eDir (LDAP)

2005-05-18 Thread Matt McFarlane
Totally new to radius. I've installed freeradius 1.02 --with-edir on Suse 9. Attempting to use 802.1X auth from wireless user behind HP 420 AP using WinXP to an eDir tree via LDAP. When I use radtest the bind is successful. However when using the 802.1X supplicant I get the output below.

Re: freeradius with Gentoo Linux

2005-04-12 Thread Matt Baran
I've been using it on Gentoo since 0.9.3, using the ebuilds. I have our accounting info stored in MySQL and use LDAP for auth. What problems are you having? -Matt Bryce Porter wrote: I'm trying to, but it's being a PITA. If you get it to work, please let me know how. I had to force

Using Free Radius with Microsoft Stored Proccedures for Authentication

2005-02-22 Thread Matt
What exactly does freeradius expect back? For instance: authenticate_query = SELECT Value,Attribute FROM ${authcheck_table} WHERE UserName = '%{User-Name}' AND ( Attribute = 'User-Password' OR Attribute = 'Password' OR Attribute = 'Crypt-Password' ) ORDER BY Attribute DESC Or if I were

Re: SQL Stored Proc?

2005-02-21 Thread Matt
? ~ Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Radius Reload

2005-01-27 Thread Matt
I use this simple old script to restart freeRadius once our dialup person has edited the users file with a file editor on our server. What I want is for it to email a specific email address in the case of a typo being made in the users file and freeRadius could not be restarted. Can anyone

Re: eap-md5 with ldap backend

2005-01-25 Thread Matt Moore
Kostas - Thank you. I had misunderstood this section (obviously) in what I had read. The explanation below helps alot... All is working now. Thanks, Matt --- Kostas Kalevras [EMAIL PROTECTED] wrote: ... You are setting Auth-Type to LDAP. The ldap module does not perform authentication

eap-md5 with ldap backend

2005-01-24 Thread Matt Moore
:= LDAP But, how do I get EAP to work with ldap backend in this situation? Or am I missing something more fundamental? I have looked through the archives, but turned up only help on ldap or eap, not combining the two... any pointers? Thanks, Matt Moore

Re: eap-md5 with ldap backend

2005-01-24 Thread Matt Moore
are snippets from configs and the radiusd -X output for the failed eap request... Please let me know if more is needed. Thanks, Matt ldap.attrmap: checkItem User-Password userPassword radiusd.conf: modules { eap { default_eap_type = md5

RE: access-challenge question

2004-11-04 Thread Matt
. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Wednesday, November 03, 2004 10:45 PM To: [EMAIL PROTECTED] Subject: Re: access-challenge question Matt [EMAIL PROTECTED] wrote: First, I am new to the RADIUS protocol, and appreciate

access-challenge question

2004-11-03 Thread Matt
Hello, First, I am new to the RADIUS protocol, and appreciate your help. Im working with a python web-interface and a remote server running freeradius-current. Using the web-interface, Im trying to get the client to print very verbose information about the transaction with the server

Microsoft SQL?

2004-10-20 Thread Matt
Hi, What do I need to do to get freeradius to access Microsoft SQL server? Someone else in the list here said they use it to do stored procedures and the like, but I'm not showing freeradius shipping with Microsoft SQL support. - List info/subscribe/unsubscribe? See

Problem Compiling

2004-10-20 Thread Matt
Hi, Can anyone explain to me why I'm getting the error I am and the aborted compile? I'm compling on a fedora core 1 system. rlm_exec.c: In function `exec_xlat': rlm_exec.c:124: warning: unused parameter `func' rlm_exec.c: In function `exec_detach': rlm_exec.c:162: warning: passing arg 2 of

Re: Problem Compiling

2004-10-20 Thread Matt
I could use yum.. may actually ... I just usually like to compile from source... checking out the oreily book now. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

SQL Stored Proc?

2004-10-07 Thread Matt
Hi, Was wondering if free radius has the ability to run Microsoft SQL stored proccedures and do something depending on the result? Or to get attributes from a stored proccedure? ~ Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Trimming Off @mydomain.com

2004-07-31 Thread Matt
Is there anyway to have freeRadius trim off the @mydomain.com from the username when the user attempts to authenticate? I have a number of users that still try to use there full email address for there username and it could save me some tech support. Matt - List info/subscribe/unsubscribe

Re: Freeradius/mysql and strange username

2004-07-23 Thread Matt Harrison
On Fri, 23 Jul 2004 08:31:16 +1000, Paul Hampson [EMAIL PROTECTED] wrote: Add =24enabl15=24 as a user, or add $ to the list of safe characters in your SQL configuration file and add $enabl15$ as a user. Thank you. I had tried adding =24enab15=24 as a user, but it still didn't act right. I

Freeradius/mysql and strange username

2004-07-22 Thread Matt Harrison
=24'. mysql says that there is no matching username, and radiusd rejects the request. I tried adding the user $enab15$ and =24enab=24 into the database, but to no avail. Anyone have a suggestion? Thanks very much! Matt. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

random dh -- best practices for EAP-TLS ?

2004-06-02 Thread Matt Garretson
directly in radius.conf? (E.g. /dev/urandom , although i know people some people frown upon this.) Or does the staleness of the random data in those two files not matter? Any tips would be be greatly appreciated. TIA, -Matt - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Aplication of Free Radius Server

2004-03-07 Thread Matt Bailey
with an HTML splash screen (After doing some reading it almost sounds like you have to have proprietary client software on every computer that wants to authenticate???). What AP's (if any) have this functionality? Am I completely off base w/ my application of this Radius Server? Cheers, Matt

RE: [PATCH] Re: PEAP authentication very strange problem! PLEASE HELP

2004-01-17 Thread matt morris
currently have to run: ./configure --with-openssl-includes=/usr/include/ --with-openssl-libraries=/usr/lib/ It's only started happening recently, perhaps it's something weird in my setup, I'm too tired to care right now ;) Cheers, Mike On Thu, Jan 15, 2004 at 09:37:57AM -0500, matt morris wrote

<    1   2   3   >