Re: load balancing radius with F5 devices

2013-10-09 Thread Michael Schwartzkopff
. But I don't think that you can configure this on the BigIPs. The RADIUS protocol is stateless, so there is no criteria in the application that a load balancer could use to balance inside the application. Greetings, -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de

Re: Authentication

2013-09-23 Thread Michael Schwartzkopff
reserved. 802 Limited. Registered in the UK. Company Number. 7962864. -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64, +49 (162) 165 0044 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263

Re: differentiate authoriztion/ authentication in separate ldap modules

2013-09-03 Thread Michael Schwartzkopff
helper program. http://deployingradius.com/documents/configuration/active_directory.html Greetings, -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64, +49 (162) 165 0044 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München

Re: Configuring the DHCP module to forward request to another Radius server.

2013-08-08 Thread Michael Schwartzkopff
the radius protocol, to get authorized, and get the IP address to respond with to the DHCP request. You want to try the DHCP relay agent feature implemented on every better router or layer 3 switch. Greetins, -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49

Re: TLS-Client-Cert-Expiration date format

2013-07-25 Thread Michael Schwartzkopff
..? Zulu time. Equals GMT. It's certainly not seconds since epoch or Jan 01 - 1601 which is seen in certain other operating systems. YYMMDDhhmmssZ -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64, +49 (162) 165 0044 Franziskanerstraße 15

Re: SNMP support for Free Radius

2013-07-18 Thread Michael Schwartzkopff
. FRv1. But you do not want to use that. -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64, +49 (162) 165 0044 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 Vorstand: Patrick Ben Koetter

Re: SNMP support for Free Radius

2013-07-18 Thread Michael Schwartzkopff
commands, i.e. radmin, and passes the results as SNMP protocol over the net. And mrtg, cacti or all the other monitoring systems do understand SNMP very well. -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64, +49 (162) 165 0044

Re: inactive users can authenticate

2013-06-28 Thread Michael Rigoni
the base_filter commented. I hope this helps, Michael On Fri, Jun 28, 2013 at 9:14 AM, Mathieu Simon mathieu@gmail.comwrote: G'day all, and thanks Phil for your hints (Arran I'd want to leave 3.0 as an option of last resort even though it's considered RC by now) ;-) try moving mschap after LDAP

Re: Service Provisioning Using AAA (FreeRadius)

2013-06-04 Thread Michael Schwartzkopff
BUT authorization. No. How can you authorize somebody without beeing sure who that user is. Only authentication provides that information. So you need authentication and authorization. -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64

RE: Failure authenticate using IPv6

2013-05-24 Thread Michael Sherman
Using global IPV6 addresses worked. Thanks for the help. Mike -Original Message- From: freeradius-users- bounces+michael.sherman=exfo@lists.freeradius.org [mailto:freeradius-users- bounces+michael.sherman=exfo@lists.freeradius.org] On Behalf Of Alan DeKok Sent: Friday, May

RE: Failure authenticate using IPv6

2013-05-23 Thread Michael Sherman
what does this do... client fe80::215:17ff:fed0:d278 { secret = test shortname = test-net nastype = other } ... ? alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Same :( radiusd: Loading

Failure authenticate using IPv6

2013-05-22 Thread Michael Sherman
HI All, I'm testing freeradius server version 2.2.0. Worked fine using IPv4. When I switched to IPv6 I got the following error: Ignoring request to authentication address :: port 1812 from unknown client fe80::215:17ff:fed0:d278 port 41189 Here is the entry from the clients.conf: client

Re: Any One-Time password system.

2013-05-14 Thread Michael Schwartzkopff
smartphone. See: http://sys4.de/en/blog/2013/03/16/otp-freeradius/ -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 Vorstand: Patrick Ben

Re: Any One-Time password system.

2013-05-14 Thread Michael Schwartzkopff
with consulting ;-) Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 Vorstand: Patrick Ben Koetter, Axel von der Ohe, Marc Schiffbauer

Re: Config for 802.1x use on network switches

2013-05-08 Thread Michael Schwartzkopff
Am Mittwoch, 8. Mai 2013, 12:29:44 schrieb Nikolaos Milas: On 7/5/2013 2:37 μμ, Michael Schwartzkopff wrote: http://vuksan.com/linux/dot1x/802-1x-LDAP.html Thank you Michael for your valuable feedback, esp. the link above. By the way, I've been pointed to: http://www.packetfence.org

Re: Config for 802.1x use on network switches

2013-05-07 Thread Michael Schwartzkopff
with 120.000 MAC addresses ... -- Mit freundlichen Grüßen, Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 Vorstand: Patrick Ben Koetter, Axel von der Ohe, Marc

Re: Cisco av-pair for NX-OS and IOS

2013-02-07 Thread Michael Schwartzkopff
to improve the situation. I am really looking forward when Cisco will implement it. Greetings, -- Michael Schwartzkopff -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 Vorstand: Patrick

Re: Active Directory + LDAP + groups for dynamic VLAN assignment

2013-01-10 Thread Michael Schwartzkopff
, -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Different BaseDN for User/Group Objects in rlm_ldap

2013-01-09 Thread Michael Schwartzkopff
the baseDN in the ldap module configuration of FR to dc=example,dc=org. -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: attribute type error

2013-01-08 Thread Michael Lecuyer
On 1/7/2013 22:48 PM, Yashaswini Sathyanarayana wrote: Hi , By default all standard attribute like user-name, user-password are of type 1 and length 1. But kineto attributes are of type 2 and length 2. So is there a way to make RFC-2865 dictionary that is added in free

Re: Lost user

2012-12-26 Thread Michael Schwartzkopff
you follow the accounting packets with tcpdump on the line? did you try to run your radius server in debug mode? -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius stops. Received HUP signal.

2012-12-06 Thread Michael Weissenbacher
that by default once a day in /etc/logrotate.d/freeradius. You should be fine by replacing /etc/init.d/freeradius reload with etc/init.d/freeradius restart in that file. Disclaimer: untested by me. In my case i upgraded to a more recent version. But this if far more hassle. hth, Michael - List info

Re: Problem with freeradius + openldap for AP authentication

2012-11-26 Thread Michael Schwartzkopff
attribute in your Access- Request packet. And according to the protocol compatibility matrix you mentioned, SSHA and *EAP will not work. -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13 signature.asc Description: This is a digitally signed

Re: FreeRadius Novice problems

2012-11-19 Thread Michael Schwartzkopff
and Also enable accounting) – how? No. not authenticated - no information in RADIUS. 3. GUI: is there a management GUI for FreeRadius and if so how do I install it? dialupadmin, daloradius. Please see the documentation of these packages. -- Dr. Michael Schwartzkopff Guardinistr. 63 81375

Re: Complex eduroam radius design

2012-11-13 Thread Michael Schwartzkopff
for the central one) EAP tunnel will end on the end system. Attributes from inside the tunnel can be copied to the outside RADIUS protocol. This attributes can be seen from the NAS. So they can react as configured. Greetings, -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98

Re: User authorize with Perl-Script

2012-10-30 Thread Michael Schwartzkopff
. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13 signature.asc Description: This is a digitally signed message part. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius AAA running in fail over mode

2012-10-15 Thread Michael Schwartzkopff
FreeRadius? Install freeradius. Nearly everything works out of the box. -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13 signature.asc Description: This is a digitally signed message part. - List info/subscribe/unsubscribe? See http

Re: freeRadius against Active Directory

2012-10-09 Thread Michael Schwartzkopff
, -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13 signature.asc Description: This is a digitally signed message part. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Cloud Radius Server

2012-09-27 Thread Michael Geary
Thank you all for your input. I would be managing the Radius servers hosted by like HostGator or Rackspace or someone like that. On Thu, Sep 27, 2012 at 4:39 AM, Phil Mayers p.may...@imperial.ac.ukwrote: On 09/26/2012 11:42 PM, Michael Geary wrote: Good Evening, We have several separate

Cloud Radius Server

2012-09-26 Thread Michael Geary
that if the Internet failed there, that no one on the separate networks would be able to authenticate. Has anyone had any experience with using a Radius server in the cloud to authenticate users? Thank you very much, -- Michael Geary GAW High-Speed Internet 72 Shaker Rd. Enfield, CT 06082 www.GAW.com http

Re: Reporting from logs

2012-09-25 Thread Michael Schwartzkopff
to get the interesting figures: http://wiki.freeradius.org/config/Status With a simple script/cronjob you can feed these data into a RRD and generate nice graphs. Greetings, -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13 signature.asc

Re: Radius Config and Router

2012-09-12 Thread Michael Schwartzkopff
not created. Thanks to assist According to you log you messed up your config. Please restore the users file with the help of the original file. Then add the correct entries copying the samples from the original file. Greetings, -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel

Re: Accounting pakets on layer 2

2012-08-24 Thread Michael Schwartzkopff
! Andreas - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html See section Security Settings - WPA-802.1x or section Security Settings - 802.1x of the ALLNET manual. -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304

Re: New FreeRADIUS Deployment

2012-08-16 Thread Michael Schwartzkopff
. Any recommendations to the backup policy? Ordinary backup solution of the SQL database. -- Dr. Michael Schwartzkopff Guardinistr. 63 81375 München Tel: (0163) 172 50 98 Fax: (089) 620 304 13 signature.asc Description: This is a digitally signed message part. - List info/subscribe

RE: Radius reject the request

2012-07-21 Thread Michael Hartwick
Pretty sure when you installed it the users file that is being used is not in your home directory. I am pretty sure that if you were to look in output.txt you would be able to see what users file is being used. Michael

RE: dalo(free)radius authentication problem

2012-07-11 Thread Michael Hartwick
Not sure why you are posting about daloradius on a FreeRADIUS list, but a 2 second look says you have the port numbers wrong. Michael -- Michael J. Hartwick, VE3SLQ mailto:hartw...@hartwick.com hartw...@hartwick.com

Auth-Type :- Reject in users file matches inner tunnel request but sends Access-Accept

2012-06-12 Thread Michael Gorven
and use_tunneled_reply to yes in the PEAP and TTLS sections, but this didn't make a difference. How do I actually reject an inner tunnel request? Michael -- http://michael.gorven.za.net PGP Key ID 1E016BE8 signature.asc Description: OpenPGP digital signature - List info/subscribe/unsubscribe? See http

Re: Auth-Type :- Reject in users file matches inner tunnel request but sends Access-Accept

2012-06-12 Thread Michael Gorven
and therefore went on the second line. Thank you for your assistance. Michael -- http://michael.gorven.za.net PGP Key ID 1E016BE8 signature.asc Description: OpenPGP digital signature - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: How to configure Solaris 10 Radius Authentication client.

2012-06-04 Thread Michael Hocke
. - - Michael -BEGIN PGP SIGNATURE- Version: PGP Desktop 10.0.3 (Build 1) Charset: windows-1252 wsBVAwUBT80NGZbfnpCg64TVAQHd4ggArN/0myf0kzlm1eSp+uMZuUl/s4Zi2Ua3 2nhocQZ6psuKwsDXphEkZqOeR5ZOjms8I3HiljLs8Cg6W7iE6ykFU0TRK8miG301 HQLWqHczFA/X4bDsHa8UH6do9Bvt9Nd6uDYn4ksrKJFCQabhTaVocECmOmXFLpUo

Address already in use but server is not running

2012-05-28 Thread Michael Aldridge
I recently had to install debian 6.0 on one of my servers after a hard drive crash, and while I had freeradius running before, I can't seem to get it running now. I ran sudo apt-get install freeradius and hit enter to accept the additional packages, and I also installed dialup admin with the

Re: Address already in use but server is not running

2012-05-28 Thread Michael Aldridge
I could if I knew how. manually sifting the output of lsof doesn't appear to include anything pertaining to that socket - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Address already in use but server is not running

2012-05-28 Thread Michael Aldridge
yep, killing the offending process worked just fine. thanks for the help! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Can't start server on mac OS X

2011-12-27 Thread Michael Aldridge
your were right, the directory didn't exist. It now loads correctly, I just have to get the server configured now in case anyone else has this problem, you have to have it writeable to the system user 'everyone' and the user that you are logged into the terminal as. - List

Server Starts, but rejects test user

2011-12-27 Thread Michael Aldridge
I set up the server with gracious help from the community, and now it starts without errors. The problem comes in trying to get the test user to work. The server simply replies with Access-Reject and awaits the next user. Here is the dump from radtest: DeepBlue:~ michaelaldridge$ radtest

Re: Server Starts, but rejects test user

2011-12-27 Thread Michael Aldridge
As requested: DeepBlue:raddb michaelaldridge$ radiusd -X FreeRADIUS Version 2.1.9, for host i386-apple-darwin10.8.0, built on Dec 9 2011 at 18:58:07 Copyright (C) 1999-2009 The FreeRADIUS server project and contributors. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A

Re: Server Starts, but rejects test user

2011-12-27 Thread Michael Aldridge
I feel stupid now, I was editing the wrong users file... - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

VMPS

2011-11-17 Thread Whitlow, Michael
All, I've got a Freeradius server I'm testing for VMPS. My mac2vlan file needs to be dynamically updated. Right now I have a cron job that does that and then stops/starts Freeradius so the new mac2vlan file is read. Is there a better way to do this? Thanks much, Mike - List

Re: Radius testing.

2011-11-17 Thread Michael Holstein
Anybody knows a tool to test radius performance? Vasco's radius simulator. It runs in Wine under Linux just fine. Regards, Michael Holstein Cleveland State University - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: LDAP/MSCHAP

2011-11-15 Thread Whitlow, Michael
I wanted to say thanks to everybody from this list who has given me a hand over the past few weeks. I have successfully configured Freeradius to authenticate 802.1X wireless clients from an AD domain and assign them the appropriate VLAN tag based on AD/LDAP group membership. Many thanks to

Certificate Validation Process

2011-11-15 Thread Whitlow, Michael
All, I have one minor issue to ask the group about. Using Freeradius to authenticate 802.1X wireless clients, I noticed that if I try to connect to the wireless network and I purposely put in a bad password I still get the popup to validate the server certificate. On the other radius

LDAP/MSCHAP

2011-11-10 Thread Whitlow, Michael
All, I am really close to a successful Freeradius implementation for 802.1X wireless using LDAP authentication on the back end. Here is what I have: - RADTEST / clear text Freeradius password from users file / WORKS GREAT - Windows XP 802.1X PEAP/MS-CHAPv2

RE: AD integration

2011-10-29 Thread Whitlow, Michael
@lists.freeradius.org] On Behalf Of Whitlow, Michael Sent: Friday, October 28, 2011 3:18 PM To: freeradius-users@lists.freeradius.org Subject: AD integration Hello, I just got Freeradius running on Ubuntu and have successfully configured integration Active Directory using Samba

AD integration

2011-10-28 Thread Whitlow, Michael
Hello, I just got Freeradius running on Ubuntu and have successfully configured integration Active Directory using Samba and NTLM_AUTH. When I run radtest against Freeradius and put in AD credentials, it is successful. My next goal is to configure Freeradius to assign 802.1X VLANs

RE:

2011-10-14 Thread Michael Hartwick
Check your NAS' documentation. The NAS sends that to FreeRADIUS to log. Michael -- Michael J. Hartwick, VE3SLQ hartw...@hartwick.com Hartwick Communications Consulting (519) 396

RE: Dynamic Attributes Based on NAS Type !

2011-10-08 Thread Michael Hartwick
It may not be pretty, but why not just sent all 3 sets of VSA's. If the NAS doesn't recognize it won't it just ignore the attribute? From: freeradius-users-bounces+hartwick=hartwick@lists.freeradius.org [mailto:freeradius-users-bounces+hartwick=hartwick@lists.freeradius.org] On Behalf

[no subject]

2011-09-29 Thread michael lamborn
http://bestserv.ae/go.php - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Odd issue with auth-type:ldap

2011-09-09 Thread Michael Holstein
Upgrade. This was fixed a long time ago. Thanks .. that worked. It's even referenced in the config. My google foo must have failed me searching the error to have not found that in the changelog. Cheers, Michael Holstein Cleveland State University - List info/subscribe/unsubscribe? See

Re: Windows Pre-Login Auth

2011-09-09 Thread Michael Holstein
account in the wireless properties (in XP). IIRC this was introduced when they finally fixed the supplicant in sp2. The credentials come across as COMPUTERNAME$ Regards, Michael Holstein Cleveland State University On Fri, 9 Sep 2011 09:00:32 -0500, Scott Hughes wrote: Hello all, I have

Re: LDAP Authentication bind as user issue

2011-09-09 Thread Michael Holstein
}})) .. } Cheers, Michael Holstein Cleveland State University - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Odd issue with auth-type:ldap

2011-09-08 Thread Michael Holstein
-type. TIA, Michael Holstein Cleveland State University - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

can policy.conf be used to create an access control list

2011-05-06 Thread michael lamborn
Hi, I am using version freeRadius 1.1.7. I am trying to create an access control list via radius, to prevent specific PC's/locations from accessing my network. Please see my policy.conf example below. My freeRadius server keeps sending an access-accept, when I try to login in from my

question re inner tunnel / virtual server

2011-04-24 Thread Michael Arndt
Hi *, i try to get a better grip in understanding the virtual server for inner eap tunnel. Please forgive if any of the following statements represents misunderstanding of concepts from my side. Which of the following statements describe the inner tunnel virtual server for EAP wrong / correct ?

no authenticate step ...

2011-04-07 Thread Michael Arndt
hello * i try to transfer a working configuration from an very old (1.x) freeradius version to a more recent radius version: FreeRADIUS Version 2.1.10, for host x86_64-pc-linux-gnu, built on Nov 14 2010 at 21:14:10 My problem: after authenticate against ldap and auth-type = ldap is set, no

Re: Strip off the domain part from the User-Name

2011-03-23 Thread Michael Lecuyer
The MSCHAPs include the given name when calculating the hashes. Stripping the domain will therefore not work. The client is using the domain\name in the hash and you're asking the server to use just the name. On 3/23/2011 15:08 PM, Thomas Wunder wrote: Hi, I'm currently trying to configure my

Re: The decoded content is not same as command in CoA

2011-01-12 Thread Michael Lecuyer
Perhaps the character value of the string for zero ('0') is 30 in hex (0x30). On 1/12/2011 23:33 PM, Xiaochen wrote: Dear all, I am using Fedora 12 + Freeradius to do some CoA tests. One is : AAA sends Disconnect request to Client. My packet.txt content is as: WiMAX-DM-Action-Code=0 But

multiple usergroups failing; freeradius 2.1.10 + Cisco-AVPairs

2010-12-15 Thread michael
Hi, During a rebuild of our Radius servers from an old freeradius 1.x install to 2.1.10, we've lost ability to push multiple usergroups to our Cisco LNS: MySQL: radcheck: id UserNameAttribute op Value 9791t...@realm Password:= {clear}somepass

Re: multiple usergroups failing; freeradius 2.1.10 + Cisco-AVPairs

2010-12-15 Thread michael
manually, it does pickup VRF-TEST and QOS-PROFILE usergroups, however looking at the above groupcheck/groupreply query, it is only running it for the first instance. bug perhaps in rlm_sql_mysql? -Michael On Thu, 16 Dec 2010 11:33:46 +1100, mich...@jarrett.id.au wrote: Hi, During a rebuild

Re: Re: LDAP auth success / User reject

2010-11-19 Thread Michael Arndt
failed. I resolved the reason, It was a Bug in the LDAP Tree of customer for this site, not noticed by me before. Michael - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

No NAS Port seen ?

2010-11-19 Thread Michael Arndt
Hello * -is the error belwo caused by fault of the NAS -or a stupid mistake of mine within setup ? rlm_radutmp: No NAS-Port seen. Cannot do anything. rlm_radumtp: WARNING: checkrad will probably not work! -other attributes are sent correctly -device is a lancom 315-agn TIA Micha -

LDAP auth success / User reject

2010-11-18 Thread Michael Arndt
=Stadt,dc=de,o=Organisation thx for any hints :-) I have anonymized the ldap Attributes Michael - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Re: LDAP auth success / User reject

2010-11-18 Thread Michael Arndt
Alan, Use -X. You've added an additional -x, which makes the output harder to read. ok, understood, attached below Thu Nov 18 11:20:52 2010 : Debug: rad_check_password: Found Auth-Type Reject Thu Nov 18 11:20:52 2010 : Debug: rad_check_password: Auth-Type = Reject, rejecting user

Re: Doubt - Freeradius + Ldap

2010-11-05 Thread Michael Lecuyer
There's many a slip 'twixt the cup and the lip I promise you'll want to kick yourself when you find the simple difference after so many messages. Many of us have the grace to go through this necessarily humbling exercise in private. On 2010-11-05 2:47 PM, Eduardo Moreira wrote: sorry, but

No authenticate method (Auth-Type) configuration found

2010-10-20 Thread Bereos OHG Michael Spinnenhirn
for request 0 Sending Access-Reject of id 13 to 172.16.20.10 port 42793 Waking up in 4.9 seconds. Cleaning up request 0 ID 13 with timestamp +7 Ready to process requests. Many Thanks. Michael - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: No authenticate method (Auth-Type) configuration found

2010-10-20 Thread Bereos OHG Michael Spinnenhirn
to the next request Waking up in 4.9 seconds. Cleaning up request 0 ID 105 with timestamp +20 Ready to process requests. What else could be wrong here? Alan DeKok schrieb: Bereos OHG Michael Spinnenhirn wrote: auth: No authenticate method (Auth-Type) configuration found for the request

Re: No authenticate method (Auth-Type) configuration found

2010-10-20 Thread Bereos OHG Michael Spinnenhirn
, with success. So it has to be a problem with the radclient on the openwrt box, doesn't it? Alan DeKok schrieb: Bereos OHG Michael Spinnenhirn wrote: The remote radclient gives the following debug output: rad_recv: Access-Request packet from host 172.16.20.10 port 56195, id=36, length User

Re: doubt regarding free-radius

2010-09-29 Thread Michael Bathe
-a freeradius pkgutil -i freeradius # if there are problems with generating certs following worked for me cd /opt/csw/etc/raddb/certs/ date ./random ./bootstrap radiusd -X Michael Am 29.09.2010 14:33, schrieb vijay: Hi, i saw your posting regarding segmentation-fault while run following

Re: Re: radius client / send NAS IP ?

2010-09-27 Thread Michael Arndt
Hello Alan, sorry, my fault :-) radclient saves my day, indeed i can send any attribute / value pair i like thanks for your help Micha - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

rlm_exec: Wait=yes but no output defined

2010-09-25 Thread Michael Arndt
Hello *, radiusd -X in different places announces rlm_exec: Wait=yes but no output defined. Did you mean output=none? Will freeradius fall back internally to output=none without inserting this attribut / value in the config ? Or should i mandatory add output=none ? TIA Micha - List

radius client / send NAS IP ?

2010-09-25 Thread Michael Arndt
Hello *, at the time beeing i have to use an old radius version for different reasons. freeradius-client-1.1.5-36 freeradius-devel-1.1.6-47 freeradius-1.1.6-47 freeradius-client-devel-1.1.5-36 freeradius-client-libs-1.1.5-36 for real logins at WLAN Hot Spot the DEFAULT NAS-IP-Address ==

Re: Re: radius client / send NAS IP ?

2010-09-25 Thread Michael Arndt
Nachricht - Subject: Re: radius client / send NAS IP ? Date: Sa 25 Sep 2010 15:01:49 CEST From: Alan DeKokal...@deployingradius.com To: FreeRadius users mailing listlt;freeradius-users@lists.freeradius.orggt; Michael Arndt wrote: is there a radtest client where i can send those attribute / value

Re: still not working (newbie for radius)

2010-09-19 Thread Michael Lecuyer
By the looks of it you have two problems. The User-Password name 'bob' isn't matched by the response Juniper-Local-User-Name 'labrat'. Perhaps ssh cares. Your broken client sends the identical packet for the new authentication attempt when it must send a brand new packet (different id, socket

Re: still not working (newbie for radius)

2010-09-19 Thread Michael Lecuyer
you were saying, this attribute of Juniper-Local-User-Name is not working? also you are right, for some reasons, every login attempt will have two more duplicated messages besides the first one. why is that? I am really new on this. thanks for the help... --- On Sun, 9/19/10, Michael Lecuyerm

Solved: interpret check-Item and change reply-item to set VLAN

2010-09-14 Thread Michael Bathe
of ldap-attribute is not correspond to the vlan name in our cisco switch at this time. LG Michael Am 13.09.2010 16:10, schrieb Alan DeKok: Michael Bathe wrote: is there any how_to or solution to interpret the ldap checkItem and change the replyItem (I think in inner-tunnel)? f.e

interpret check-Item and change reply-item to set VLAN

2010-09-13 Thread Michael Bathe
= 0xc38e1cad9590596e3902a46a40706ad8bde70f05bde110698b631b503c00f51b EAP-Message = 0x030a0004 Message-Authenticator = 0x Finished request 10. ... thanks and beste Gruesse Michael - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Construction of Response-Authenticator

2010-09-12 Thread Michael Lecuyer
No one here is going to do your homework for you. RFC 2865 is pretty clear on how this is calculated. A Message-Authenticator attribute in the response attributes will require more work. Perhaps you can get extra credit for figuring it out. On 2010-09-12 1:25 PM, Theresa Otte wrote: Hello,

Re: Of accounting data and security

2010-08-09 Thread Michael Lecuyer
TACACS+ uses an MD5 pad based on the session ID, shared secret, TACACS+ version, and packet sequence number. This is XOR'd over the packet. The pad is in multiples of the MD5 hash length. The header is sent plain text and includes the sequence number, the session ID and version number.

Re: Of accounting data and security

2010-08-09 Thread Michael Lecuyer
:01 PM, Michael Lecuyer m...@iterpacis.org mailto:m...@iterpacis.org wrote: TACACS+ uses an MD5 pad based on the session ID, shared secret, TACACS+ version, and packet sequence number. This is XOR'd over the packet. The pad is in multiples of the MD5 hash length. The header

Re: Master key and Pairwise Master Key encryption

2010-07-15 Thread Michael Lecuyer
I'm not sure it would help you to know how the Master Keys are generated or encoded - it's not simple. It's a process involving the accumulated TLS handshake messages, random number generation, various sorts of key exchanges, cryptographic hashes, and the PRF function described in the TLS

Re: speed of detail reader server

2010-06-22 Thread Michael Fowler
, but so far have not had the tuits to apply to the problem. I'm not sure I would recommend the proxy solution, but if you can manage it, it may be a reasonable stop-gap. -- Michael Fowler www.shoebox.net - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: dynamic assignment of VLANs from LDAP via freeradius to WLAN-Clients doesn't work properly

2010-05-27 Thread Michael Schwartzkopff
startup-config ? Greetings, -- Dr. Michael Schwartzkopff MultiNET Services GmbH Addresse: Bretonischer Ring 7; 85630 Grasbrunn; Germany Tel: +49 - 89 - 45 69 11 0 Fax: +49 - 89 - 45 69 11 21 mob: +49 - 174 - 343 28 75 mail: mi...@multinet.de web: www.multinet.de Sitz der Gesellschaft: 85630

Re: Looking for an editor for FreeRADIUS documentation

2010-05-18 Thread Michael Schwartzkopff
. Greetings, -- Dr. Michael Schwartzkopff MultiNET Services GmbH Addresse: Bretonischer Ring 7; 85630 Grasbrunn; Germany Tel: +49 - 89 - 45 69 11 0 Fax: +49 - 89 - 45 69 11 21 mob: +49 - 174 - 343 28 75 mail: mi...@multinet.de web: www.multinet.de Sitz der Gesellschaft: 85630 Grasbrunn

Re: Encrypted password with FR+LDAP+Wireless Network

2010-05-17 Thread Michael Lecuyer
The password is encoded for PAP (when a User-Password is present). Its the only authentication method that uses decodable passwords. FR is displaying it in plain text for your convenience. Inýcio Alves wrote: Good Morning to all. I would like if is possible use FR+LDAP with Use-Password

Re: VMPS logging

2010-05-09 Thread Michael Schwartzkopff
Am Montag, 3. Mai 2010 16:56:23 schrieb Alan DeKok: Michael Schwartzkopff wrote: Strange. I added a line Access-Accept = Accepted %{User-Name} But I only see entries from the Access-Request part of the linelog module. You have the reference line as Packet-Type? Change

RE: R: Re: R: Re: R: rlm_ippool: No available ip addresses in pool

2010-05-04 Thread Michael J. Hartwick
it is still in use. The best solution would be to fix the NAS to send the packets or fix the network to make sure they get delivered. Michael -- Michael J. Hartwick, VE3SLQ hartw...@hartwick.com

Re: VMPS logging

2010-05-03 Thread Michael Schwartzkopff
Am Montag, 3. Mai 2010 13:29:24 schrieb Alan DeKok: Michael Schwartzkopff wrote: Am Sonntag, 2. Mai 2010 12:22:57 schrieb Jens Link: I also got problems logging Access-Accept details through linelog. Is it possible at all? Yes... what's going wrong? Strange. I added a line Access

Re: VMPS logging

2010-05-02 Thread Michael Schwartzkopff
? rlm_linelog Either I'm to tired or to stupid to get it up an running. Is there an example on how to use it? thanks Jens hi, I also got problems logging Access-Accept details through linelog. Is it possible at all? thanks. -- Dr. Michael Schwartzkopff MultiNET Services GmbH Addresse

freeradius-1.1.7-sol10-x86-local from sunfreeware on solaris 10 x86

2010-04-20 Thread Michael Bathe
dictionary read_config_files: reading naslist Using deprecated naslist file. Support for this will go away soon. read_config_files: reading clients read_config_files: reading realms radiusd: entering modules setup Segmentation Fault (core dumped) Can somebody help me, please? best regards Michael

Re: NAS-IP vs srcIP

2010-04-01 Thread Michael Lecuyer
Plenty of reasons - but one you won't have control over even in CoA is that it could be proxied. The NAS-IPAddress is used in the CoA request packet to tell the NAS which client should receive the packet. Marlon Duksa wrote: Hi everyone - Can anyone think of a reason why the NAS-IP and the

Re: Radpostauth question

2010-03-28 Thread Michael Lecuyer
It's a one-way hash of the password. What you're seeing is the CHAP password value. Only PAP uses a reversible password. Sallai Janos wrote: Hi, Does anyone knows how I could save the CHAP password into radpostauth pass in a VISIBLE format, in mysql ? Actually I can correctly log both the

notifying another server on accounting

2010-03-05 Thread Michael Fowler
the readers. I cannot find a configuration example to support this, but would it be possible, and more importantly useful, to have multiple readers pointing to the same detail file? Any help or suggestions would be appreciated. Thanks. -- Michael Fowler www.shoebox.net - List info/subscribe

  1   2   3   4   5   6   7   8   9   10   >