Re: Problem with Cisco WLC probes in FR 2.2.1

2013-10-07 Thread Scott Armitage
On 7 Oct 2013, at 02:30, Bruce Nunn ironr...@yahoo.com wrote: Thanks for the heads-up. I will look for this this coming weekend when I get 2.2.2 in production. Jonathan Gazeley jonathan.gaze...@bristol.ac.uk wrote: We've recently upgraded our radius servers from 2.1.12 (CentOS 6

Re: Problem with Cisco WLC probes in FR 2.2.1

2013-10-07 Thread Scott Armitage
the system as any other user. Yes, or immediately reject that user in the authorise section. Rejecting immediately just makes things more efficient, particularly if the wism is doing a check because it has marked the server as dead. Test it, see what happens. Regards Scott signature.asc

Re: rlm_perl not found

2013-06-28 Thread Scott Armitage
freeradius-perl Regards Scott signature.asc Description: Message signed with OpenPGP using GPGMail - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: string up CUI for visiting eduroam users

2013-03-19 Thread Scott Armitage
section? Regards Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Anyone implementing CUI on eduroam?

2013-03-14 Thread Scott Armitage
On 14 Mar 2013, at 17:01, Alex Sharaz alex.sha...@york.ac.uk wrote: Any UK eduroam free radius sites out there implementing CUI that I could talk to/test out my configs with? I have at Loughborough. What would you like to know? Regards Scott signature.asc Description: Message signed

Re: anonymous user when proxying

2013-02-13 Thread Scott Armitage
radius server to request a CUI from the IdP. However given how few sites implement CUI you won't get many responses. Regards Scott Armitage Hocine M hocine.maou...@free.fr wrote: Hi, Some user who are proxied (eduroam) are acconted with username = anonymous@realm I don't want to have anonymous

Re: Eduroam FreeRadius not working so well

2012-12-11 Thread Scott Armitage
# if (User-Name !~ /@\\./) { To call filter_username policy just add filter_username to your authorise section. Regards Scott Armitage - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

eap-mschapv2 and radius.log

2012-12-06 Thread Scott Armitage
of the result of the inner EAP. e.g: Thu Dec 6 11:10:55 2012 : Auth: Login OK: [scott] (from client pepsi port 0 cli 02-00-00-00-00-01 via TLS tunnel) Thu Dec 6 11:10:55 2012 : Auth: Login OK: [scott] (from client pepsi port 0 cli 02-00-00-00-00-01 via TLS tunnel) Thu Dec 6 11:10:56 2012

Re: eap-mschapv2 and radius.log

2012-12-06 Thread Scott Armitage
On 6 Dec 2012, at 11:33, Scott Armitage s.p.armit...@lboro.ac.uk wrote: All, I have noticed a behaviour in the logging and I'm not sure if it is misconfiguration on my part, misunderstanding of the expected behaviour or a bug. If I attempt to log in using EAP-MSCHAPv2 inside of an eap

Re: eap-mschapv2 and radius.log

2012-12-06 Thread Scott Armitage
On 6 Dec 2012, at 14:07, Scott Armitage s.p.armit...@lboro.ac.uk wrote: On 6 Dec 2012, at 11:33, Scott Armitage s.p.armit...@lboro.ac.uk wrote: All, I have noticed a behaviour in the logging and I'm not sure if it is misconfiguration on my part, misunderstanding of the expected

Re: I wanna post

2012-12-03 Thread Scott Armitage
On 3 Dec 2012, at 11:27, Primož Marinšek pmte...@gmail.com wrote: Please stop crapping up the mailing list. Only when people stop top posting ;-) see http://freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: what about mac spoofing

2012-11-23 Thread Scott Armitage
On 23 Nov 2012, at 17:17, pideil matthew matthew.pid...@free.fr wrote: But my wifi laptop can already be disconnected by spoofed packet ? Not if you use protected management frames IEEE 802.11w regards Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Tacacs+ Super-User issue.

2012-10-18 Thread Gilmour, Scott
. I even kill the freeradius process and still no luck. Anybody have any ideas? Scott # Created by Devrim SERAL(dev...@tef.gazi.edu.tr) # It's very simple configuration file # Please read user_guide and tacacs+ FAQ to more information to do more # complex tacacs+ configuration files. # # Put your

building FR3.0 jlibtool problem

2012-09-13 Thread Scott Armitage
]: *** [src] Error 2 make: *** [all] Error 2 Am I being an idiot? Regards Scott Armitage - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

How to Authenticate Users from Multiple IP Adresses Using the MySQL Tables

2012-09-11 Thread Scott Meyer
Using freeradius 2.1.8 The environment I am working in requires some users to be able to authenticate from multiple ip address and others from only one. How is this accomplished using the MySQL tables? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius, Calling-Station-Id

2012-09-05 Thread Scott Lambert
| ++---+---+++ | 284803 | test | Auth-Type | := | Accept | ++---+---+++ -- Scott LambertKC5MLE Unix SysAdmin lamb...@lambertfam.org - List info/subscribe/unsubscribe? See http

Re: dictionary.mikrotik patch

2012-08-22 Thread Scott Lambert
On Fri, Aug 17, 2012 at 07:56:37PM +, Scott Lambert wrote: Add Mikrotik attributes 16 - 22. http://wiki.mikrotik.com/wiki/Manual:RADIUS_Client#MikroTik_Specific_RADIUS_Attribute_Numeric_Values Hmm, I looked at the git master branch before submitting this patch. Today I looked to see

Re: dictionary.mikrotik patch

2012-08-22 Thread Scott Lambert
On Wed, Aug 22, 2012 at 06:27:53PM +0100, Arran Cudbard-Bell wrote: On 22 Aug 2012, at 18:21, Scott Lambert lamb...@lambertfam.org wrote: On Fri, Aug 17, 2012 at 07:56:37PM +, Scott Lambert wrote: Add Mikrotik attributes 16 - 22. http://wiki.mikrotik.com/wiki

dictionary.mikrotik patch

2012-08-20 Thread Scott Lambert
Add Mikrotik attributes 16 - 22. Not sure I got the types correct. I only need MikroTik-Address-List. Haven't used the rest. http://wiki.mikrotik.com/wiki/Manual:RADIUS_Client#MikroTik_Specific_RADIUS_Attribute_Numeric_Values -- Scott LambertKC5MLE

Re: Load-Balance VLAN assignment via unlang

2012-07-17 Thread Scott Armitage
(and return the clan select group from the radius server). Scott Armitage signature.asc Description: Message signed with OpenPGP using GPGMail - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PEAP Password

2012-07-13 Thread Scott Armitage
On 13 Jul 2012, at 18:26, Carl Pierre wrote: Hello: I would like to have FreeRADIUS check the user's submitted credentials before it even allows the Tunnel to even be set up. Is this a possibility? No. The point of the tunnel is to secure the credentials. Thanks Scott Armitage

Re: PEAP Password

2012-07-13 Thread Scott Armitage
On 13 Jul 2012, at 18:37, Scott Armitage wrote: On 13 Jul 2012, at 18:26, Carl Pierre wrote: Hello: I would like to have FreeRADIUS check the user's submitted credentials before it even allows the Tunnel to even be set up. Is this a possibility? No. The point of the tunnel

Re: Authenication with certifiactes

2012-07-03 Thread Scott Armitage
. It uses some crazy cryptography which avoids to need for certs. For some more background on deploying 802.1X have a read of this (http://www.ja.net/documents/publications/technical-guides/8021x-tg-web.pdf) Thanks Scott Armitage signature.asc Description: Message signed with OpenPGP using

Re: Help needed to configure FreeRADIUS for eduroam

2012-06-28 Thread Scott Armitage
at the eduroam wiki: https://confluence.terena.org/display/H2eduroam/How+to+deploy+eduroam+on-site+or+on+campus Thanks --- Scott Armitage, Loughborough University PGP.sig Description: This is a digitally signed message part - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Questions on the finer points of CUI

2012-06-28 Thread Scott Armitage
notice for a client, I'd want the CUI when contacting the home site of the user. Thanks Scott Armitage PGP.sig Description: This is a digitally signed message part - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

CUI accounting in policy.conf

2012-06-27 Thread Scott Armitage
2012 : Info: (13)? if (Chargeable-User-Identity (Chargeable-User-Identity != )) - FALSE Wed Jun 27 19:40:59 2012 : Info: (13) - policy cui.accounting returns ok I'm I being stupid or is this policy broken. thanks Scott Armitage signature.asc Description: Message signed with OpenPGP

Re: CUI accounting in policy.conf

2012-06-27 Thread Scott Armitage
On 27 Jun 2012, at 20:09, alan buxey wrote: Hi, should that be update request rather than update control? Thanks Alan, that works Scott signature.asc Description: Message signed with OpenPGP using GPGMail - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Php error with Dialup Admin and FreeBSD

2012-06-01 Thread Scott Lambert
would probably use the DaloRADIUS web interface instead of Dialup Admin. We populate the DB with scripts from our billing/provisioning system and just use Dialup Admin for read-only access to call logs for the occasional tech support calls. -- Scott LambertKC5MLE

Re: MSCHAP Errors

2012-05-15 Thread Gilmour, Scott
-- Scott Gilmour | SQA Engineer Enterasys Networks | A Siemens Enterprise Communications Company Office: 978.684.1236 Email: sgilm...@enterasys.com - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: load balancing and if statements

2012-03-27 Thread Scott McLane Gardner
This is the answer. Also, this is much easier than what I was trying to do. Thank you for the pointer, Alan. -Scott On 3/26/12 5:17 PM, Alan Buxey a.l.m.bu...@lboro.ac.uk wrote: hi, a quick glance at your question and i'd say you be better off using simple entries in the users file - simple

Re: load balancing and if statements

2012-03-27 Thread Scott McLane Gardner
I'd be surprised if using Ldap-Group in the user's file resulted in load balancing of the group membership queries to the LDAP servers. Does it? It does, actually. Or at least it appears to. The first time it used ldap2 and the second time it used ldap1. - List info/subscribe/unsubscribe? See

Re: load balancing and if statements

2012-03-27 Thread Scott McLane Gardner
Brian Julin wrote: I'd be surprised if using Ldap-Group in the user's file resulted in load balancing of the group membership queries to the LDAP servers. Does it? It doesn't. Alan DeKok. So, now I'm confused again. If this doesn¹t load balance, then how should I really be going about

Re: load balancing and if statements

2012-03-27 Thread Scott McLane Gardner
to do is not possible? -Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: load balancing and if statements

2012-03-27 Thread Scott McLane Gardner
So, is the documentation at http://wiki.freeradius.org/Load-balancing#Interaction+with+%22if%22+and+%22 else%22 incorrect, or is it only correct for the very latest version? -Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

load balancing and if statements

2012-03-26 Thread Scott McLane Gardner
) { reject } } If I can't use if statements in a load balance block, can anyone suggest another way to go about accomplishing what I want to do here? Thank you, Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Windows 7 clients

2012-03-15 Thread Scott McLane Gardner
Okay, I've finally got the server certificate sorted out, signed by GeoTrust and installed, but now I have another certificate problem. I believe this one is that the client doesn't recognize my ca.pem as being signed by a trusted authority. Do I need to get another root cert signed by GeoTrust?

Re: Windows 7 clients

2012-03-15 Thread Scott McLane Gardner
Is this the INTERMEDIATE CA that GeoTrust sent along with the server cert? On 3/15/12 8:25 AM, Scott McLane Gardner sgar...@uark.edu wrote: Okay, I've finally got the server certificate sorted out, signed by GeoTrust and installed, but now I have another certificate problem. I believe this one

Re: Windows 7 clients

2012-03-15 Thread Scott McLane Gardner
Okay, it is the INTERMEDIATE CA. Sorry for the noise. On 3/15/12 8:26 AM, Scott McLane Gardner sgar...@uark.edu wrote: Is this the INTERMEDIATE CA that GeoTrust sent along with the server cert? On 3/15/12 8:25 AM, Scott McLane Gardner sgar...@uark.edu wrote: Okay, I've finally got the server

Question about certs and Microsoft

2012-03-14 Thread Scott McLane Gardner
In the beginning of the cert documentation, it says: The Microsoft XP Extensions will be automatically included in the server certificate. Without those extensions Windows clients will refuse to authenticate to FreeRADIUS. But I use a certificate authority, so later on in the documentation,

Re: Question about certs and Microsoft

2012-03-14 Thread Scott McLane Gardner
Excellent, thank you. The default configuration does this. You shouldn't need to do anything. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Certificates not working

2012-03-14 Thread Scott McLane Gardner
Okay, I followed the instructions in the certs README, created the CSR and got a certificate from GeoTrust. When I install it and try to start the server, I get the following error messages: rlm_eap: SSL error error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt rlm_eap_tls:

Re: Certificates not working

2012-03-14 Thread Scott McLane Gardner
Just to get the server running, I tried moving all the things out of that directory, then doing the ./bootstrap thing and it still gives that error when trying to start the server. -Scott On 3/14/12 3:44 PM, Scott McLane Gardner sgar...@uark.edu wrote: Okay, I followed the instructions

Re: Certificates not working

2012-03-14 Thread Scott McLane Gardner
On 3/14/12 4:05 PM, Alan DeKok al...@deployingradius.com wrote: Scott McLane Gardner wrote: Okay, I followed the instructions in the certs README, created the CSR and got a certificate from GeoTrust. When I install it and try to start the server, I get the following error messages

Re: Certificates not working

2012-03-14 Thread Scott McLane Gardner
FreeRADIUS doesn't read OpenSSL configuration files. Alan DeKok. Gosh, I feel like a dummy. Thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Conditional attributes with AD

2012-03-13 Thread Scott McLane Gardner
-UserDn})) groupmembership_attribute = memberOf Run in debug, look at what it's actually searching, match to the config file, tweak, rinse repeat. Matthew Thank you! This was the pointer I needed to get this working. I'm sure I'll have lots more questions about other aspects soon. -Scott - List

How to reject users who don't match unlang

2012-03-13 Thread Scott McLane Gardner
I have the following in my sites-available/default: authorize { ... # Allow only NET Staff members to log into BAND and HAPF if (Ldap-Group == NET Staff (NAS-IP-Address == 192.168.6.5 || NAS-IP-Address == 192.168.6.4)) { update

Re: How to reject users who don't match unlang

2012-03-13 Thread Scott McLane Gardner
And of course I figured it out 2 minutes after writing this message. For posterity, the syntax was close. It's actually like this: elsif (NAS-IP-Address == 192.168.6.5 || NAS-IP-Address == 192.168.6.4) { reject = 1 } - List info/subscribe/unsubscribe? See

Re: How to reject users who don't match unlang

2012-03-13 Thread Scott McLane Gardner
On 3/13/12 1:24 PM, Alan Buxey a.l.m.bu...@lboro.ac.uk wrote: hi, i must be tiredi cant see how that is different to your first email! ;-) alan No, you're right, I didn't edit it. It's like you said, reject without the = 1 after it. I must be the one who is tired. Thank you for your

Re: Conditional attributes with AD

2012-03-12 Thread Scott McLane Gardner
Wireless,OU=PWHC,dc=example,dc=com memberOf: CN=UA: SecondaryAccount,OU=ManagedGroups,OU=Special Accounts,dc=example ,dc=com # search result search: 2 result: 0 Success # numResponses: 2 # numEntries: 1 Can anyone tell me what I'm doing wrong? Thanks, Scott - List info/subscribe/unsubscribe? See

Conditional attributes with AD

2012-03-06 Thread Scott McLane Gardner
LDAP auth? Thank you, -Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Conditional attributes with AD

2012-03-06 Thread Scott McLane Gardner
I found this thread which seems to do what I am asking, but I just don't know where to put this statement. http://lists.freeradius.org/pipermail/freeradius-users/2012-January/058458. html Any insight would be appreciated. -Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org

Re: Conditional attributes with AD

2012-03-06 Thread Scott McLane Gardner
You can configure AD as an LDAP server, and then do LDAP group checks. See the LDAP documentation for examples. Alan DeKok. I think the documentation is saying that LDAP can't be used with EAP. Is that what it's really saying? It's a little unclear since it says The solution is to use the

Re: Conditional attributes with AD

2012-03-06 Thread Scott McLane Gardner
I found this thread which seems to do what I am asking, but I just don't know where to put this statement. http://lists.freeradius.org/pipermail/freeradius-users/2012-January/058458 . html Any insight would be appreciated. Okay, I figured out where to put the if statement (in

unlang regex matching

2012-03-06 Thread Scott McLane Gardner
I'm having trouble getting unlang to match a string inside a larger string. I have a script that outputs a string of domain groups, like this: DOMN\Domain Users 2 DOMN\Wireless Users 2 DOMN\STUsers 2 DOMN\WOCL Wireless DOMN\WOCL Staff I have a unlang conditional written like this which I think

Re: unlang regex matching

2012-03-06 Thread Scott McLane Gardner
I'm having trouble getting unlang to match a string inside a larger string. I have a script that outputs a string of domain groups, like this: the debug output (radiusd -X) should show you all the values as things happen - and thus show you the comparison and how ita failing Alan Turns out

Re: Conditional attributes with AD

2012-03-06 Thread Scott McLane Gardner
} } This was frustrating to figure out, but a good learning experience. --Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Conditional attributes with AD

2012-03-06 Thread Scott McLane Gardner
On 3/6/12 3:55 PM, Fajar A. Nugraha l...@fajar.net wrote: On Wed, Mar 7, 2012 at 4:28 AM, Scott McLane Gardner sgar...@uark.edu wrote: If anyone cares, I got this working by calling a script that contained the following: That's odd. Did you properly setup the AD as LDAP server in raddb

Re: Conditional attributes with AD

2012-03-06 Thread Scott McLane Gardner
On 3/6/12 3:59 PM, Fajar A. Nugraha l...@fajar.net wrote: On Wed, Mar 7, 2012 at 4:57 AM, Scott McLane Gardner sgar...@uark.edu wrote: On 3/6/12 3:55 PM, Fajar A. Nugraha l...@fajar.net wrote: On Wed, Mar 7, 2012 at 4:28 AM, Scott McLane Gardner sgar...@uark.edu wrote: If anyone cares, I

ntlm_auth works but not radtest

2012-03-05 Thread Scott McLane Gardner
I'm attempting to follow the guide at http://deployingradius.com/ Things were going very well until I tried to set up Active Directory authentication. Testing with ntlm_auth, I get a success: $ ntlm_auth --request-nt-key --domain=MYDOMAIN --username=myuname --password=mypass NT_STATUS_OK: Success

Re: ntlm_auth works but not radtest

2012-03-05 Thread Scott McLane Gardner
Mon Mar 5 14:45:55 2012 : Debug: Exec-Program-Wait: plaintext: winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/run/samba/winbindd_privileged are set correctly. (0xc022) Did you spot this? This was definitely it. Thank you so much. -Scott

RE: Freeradius-Users Digest, Vol 82, Issue 33

2012-02-12 Thread Gilmour, Scott
Alan, I already have certificates created on my 2008 Server so I want to use those certificates on my Ubuntu Server without creating new ones. You mentioned my openssl configuration is wrong. Any suggestions on how I can fix the openssl configuration? Thanks Scott Message: 1 Date: Sun, 12 Feb

RE: Cetificates to Use with Ubuntu Server

2012-02-11 Thread Gilmour, Scott
Hi, I have Ubuntu Server installed and I have a Windows 2008 Server Certificate Authority When I type the openssl command I keep on getting this error: CA certificate and CA private key do not match Any help or suggestions would be appreciated. Thanks Scott Ps. I was able to get Samba

Verifying you are Joining the Active Directory Domain

2012-02-02 Thread Gilmour, Scott
and from what I Understand I should see it added as A computer on my Windows 2008 Server PC. But when I do a wbinfo -u I do not see my domain users listed. I was wondering if this is because we installed winbind4 rather than winbind? Thanks for everyones help, Scott root@FreeRadius:/etc/init.d

2008 Server Certificate Authority

2012-02-02 Thread Gilmour, Scott
of a good site or even a book that would explain how to accomplish this tasks. If somebody can point me in the right direction that would be great. Thanks Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Joining Active Directory Domain

2012-01-31 Thread Gilmour, Scott
lookup zone to the AD Doman. Add the AD Server to the resolv.conf and etc/hosts files. I am able to ping both servers. I am attempting to join my FreeRadius domain to my 2008 Server Active Directory Domain. Thanks Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Joining Active Directory Domain

2012-01-31 Thread Gilmour, Scott
to RPC... Unable to find a suitable server for domain SQA Unable to find a suitable server for domain SQA root@FreeRadius:/home/sqauser# Thanks for everyones feedback. I will continue to debug my issue. Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Verifying you are Joining the Active Directory Domain

2012-01-31 Thread Gilmour, Scott
but it is listed under computers. Is this correct? Thanks Scott root@FreeRadius:/home/sqauser# net ads join -U Administrator Enter Administrator's password: Using short domain name -- SQA Joined 'FREERADIUS' to realm 'SQA.net' [2012/01/31 15:44:15, 0] libads/kerberos.c:333(ads_kinit_password

Re: Radius Billing System

2011-11-19 Thread Scott Lambert
/developers.html -- Scott LambertKC5MLE Unix SysAdmin lamb...@lambertfam.org - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Windows Pre-Login Auth

2011-09-10 Thread Scott Hughes
-Original Message- From: freeradius-users- bounces+scott=renshawauto@lists.freeradius.org [mailto:freeradius- users-bounces+scott=renshawauto@lists.freeradius.org] On Behalf Of Commonn Systems Sent: Friday, September 09, 2011 4:54 PM To: freeradius-users@lists.freeradius.org

RE: Windows Pre-Login Auth

2011-09-10 Thread Scott Hughes
and still have the same results as above. Thanks, Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Windows Pre-Login Auth

2011-09-10 Thread Scott Hughes
-Original Message- From: Alan T DeKok [mailto:al...@freeradius.org] Sent: Saturday, September 10, 2011 12:22 PM To: sc...@renshawauto.net; FreeRadius users mailing list Subject: Re: Windows Pre-Login Auth Scott Hughes wrote: Thank you for the reply Arran. Yes, I did hard code

Windows Pre-Login Auth

2011-09-09 Thread Scott Hughes
for any insight you may have on either/both of these issues. Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Windows Pre-Login Auth

2011-09-09 Thread Scott Hughes
-Original Message- From: freeradius-users-bounces+scott=renshawauto@lists.freeradius.org [mailto:freeradius-users-bounces+scott=renshawauto@lists.freeradius.org] On Behalf Of Phil Mayers Sent: Friday, September 09, 2011 9:21 AM To: freeradius-users@lists.freeradius.org Subject: Re

RE: Windows Pre-Login Auth

2011-09-09 Thread Scott Hughes
-Original Message- From: freeradius-users-bounces+scott=renshawauto@lists.freeradius.org [mailto:freeradius-users-bounces+scott=renshawauto@lists.freeradius.org] On Behalf Of Phil Mayers Sent: Friday, September 09, 2011 9:31 AM To: freeradius-users@lists.freeradius.org Subject: Re

RE: Windows Pre-Login Auth

2011-09-09 Thread Scott Hughes
port 5136 cli mac address here) Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: Windows Pre-Login Auth

2011-09-09 Thread Scott Hughes
they finally fixed the supplicant in sp2. The credentials come across as COMPUTERNAME$ Regards, Michael Holstein Cleveland State University Also, would it be better to get the AD authentication working BEFORE I attempt to authenticate prior to login or is it the same either way? Thanks, Scott

RE: LDAP Authentication bind as user issue

2011-09-09 Thread Scott Hughes
-Original Message- From: freeradius-users-bounces+scott=renshawauto@lists.freeradius.org [mailto:freeradius-users-bounces+scott=renshawauto@lists.freeradius.org] On Behalf Of Michael Holstein Sent: Friday, September 09, 2011 10:30 AM To: FreeRadius users mailing list Subject: Re

RE: Windows Pre-Login Auth

2011-09-09 Thread Scott Hughes
-Original Message- From: freeradius-users- bounces+scott=renshawauto@lists.freeradius.org [mailto:freeradius- users-bounces+scott=renshawauto@lists.freeradius.org] On Behalf Of Phil Mayers Sent: Friday, September 09, 2011 10:39 AM To: freeradius-users@lists.freeradius.org

RE: Windows Pre-Login Auth

2011-09-09 Thread Scott Hughes
-Original Message- From: freeradius-users- bounces+scott=renshawauto@lists.freeradius.org [mailto:freeradius- users-bounces+scott=renshawauto@lists.freeradius.org] On Behalf Of Commonn Systems Sent: Friday, September 09, 2011 4:54 PM To: freeradius-users@lists.freeradius.org

TTLS use_tunneled_reply and Mac OSX

2011-07-20 Thread Scott Armitage
Hi, I have noticed that when authenticating using TTLS/MSCHAPv2 that the outer-identity is used in the RADIUS reply packet even if the use_tunneled_reply is set to yes for TTLS in eap.conf Does anyone know the reason for this? Thanks Scott Armitage PGP.sig Description: This is a digitally

Re: TTLS use_tunneled_reply and Mac OSX

2011-07-20 Thread Scott Armitage
On 20 Jul 2011, at 13:39, Phil Mayers wrote: On 20/07/11 11:26, Scott Armitage wrote: Hi, I have noticed that when authenticating using TTLS/MSCHAPv2 that the outer-identity is used in the RADIUS reply packet even if the use_tunneled_reply is set to yes for TTLS in eap.conf That's

Re: TTLS use_tunneled_reply and Mac OSX

2011-07-20 Thread Scott Armitage
On 20 Jul 2011, at 12:49, Alexander Clouter wrote: Scott Armitage s.p.armit...@lboro.ac.uk wrote: I have noticed that when authenticating using TTLS/MSCHAPv2 that the outer-identity is used in the RADIUS reply packet even if the use_tunneled_reply is set to yes for TTLS in eap.conf

Re: TTLS use_tunneled_reply and Mac OSX

2011-07-20 Thread Scott Armitage
On 20 Jul 2011, at 15:40, Phil Mayers wrote: On 20/07/11 14:27, Scott Armitage wrote: [ttls] Using saved attributes from the original Access-Accept Reply-Message = Authenticated by Test ORPS Ok, looking at the debug the reason this is happening is that you are doing TTLS/MSCHAP

How to setup Freeradius

2011-06-26 Thread Gilmour, Scott
anything else in order to get PEAP and TLS to work? Thanks Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS exiting with Signal 11 on FreeBSD

2010-12-13 Thread Scott Lambert
is logged in the 3 or 4 hundred lines before the exits? Any pattern in those messages? What is logged in /var/log/messages at those times? -- Scott LambertKC5MLE Unix SysAdmin lamb...@lambertfam.org - List info/subscribe/unsubscribe? See http

RE: New Install Problems

2010-09-29 Thread Scott Miller
Scott Miller wrote: Wondering if you happen to have a solution or work-around? $ ./configure --disable-libltdl-install --with-system-libtool That *may* work. The longer-term fix is removing libltdl libtool entirely. Modern systems all have sane compilers link systems

New Install Problems

2010-09-28 Thread Scott Miller
-2.1.10.so: could notread symbols: Invalid operationcollect2: ld returned 1 exit statusgmake[6]: *** [radeapclient] Error 1gmake[6]: Leaving directory `/home/scott/freeradius-server-2.1.10/src/modules/rlm_eap'gmake[5]: *** [rlm_eap] Error 2gmake[5]: Leaving directory`/home/scott/freeradius-server

RE: New Install Problems

2010-09-28 Thread Scott Miller
? Scott Miller - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius 2.1.8 works fine in DEBUG mode

2010-02-09 Thread Scott Lambert
was running as root and your 2.1.8 install is now running as a freeradius user, whatever that user might happen to be named. -- Scott LambertKC5MLE Unix SysAdmin lamb...@lambertfam.org - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

RE: Time connected

2009-10-29 Thread Scott Miller
'; Scott -Original Message- From: freeradius-users-bounces+srmiller=interbel@lists.freeradius.org [mailto:freeradius-users-bounces+srmiller=interbel@lists.freeradius.org] On Behalf Of Sergio Belkin Sent: Thursday, October 29, 2009 5:11 AM To: FreeRadius users mailing list Subject

Re: Simple username password text file

2009-08-05 Thread Scott Lambert
this type of format by using mysql? I think you are looking for modules/passwd. modules/smbpasswd is an example of how you would use it. -- Scott LambertKC5MLE Unix SysAdmin lamb...@lambertfam.org - List info/subscribe/unsubscribe? See http

Unlang authentication help

2009-06-25 Thread Scott Angus
that? And how would list the IP address in the files? Thanks for your help, Scott - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: WPA Enterprise, 802.1X, Freeradius, EAP Kerberos

2009-05-08 Thread Scott Sears
Alan, Thank you for your quick and kind response. On May 8, 2009, at 2:00 PM, Alan DeKok wrote: Scott Sears wrote: I cannot get all the pieces working together. Laptop-AP-Freeradius-Kerberos. It's impossible. Here is the thread which made me think it was possible, and led me

Re: WPA Enterprise, 802.1X, Freeradius, EAP Kerberos

2009-05-08 Thread Scott Sears
That's did it! I just needed to change settings on the supplicant. My freeradius config was OK. Thank you SO much. On May 8, 2009, at 2:45 PM, Ivan Kalik wrote: Is it *in any way* possible to securely authorize mobile supplicants through a wireless AP to a Freeradius server using a KDC for

Re: WPA Enterprise, 802.1X, Freeradius, EAP Kerberos

2009-05-08 Thread Scott Sears
to these concepts could not become useful members of the community without your help. You've made my week, and I hope that I can be helpful to someone in this regard in the future. Kindest regards, Scott On May 8, 2009, at 3:07 PM, Alan DeKok wrote: Scott Sears wrote: Here

Re: autostart script for FreeRADIUS

2009-03-31 Thread Scott Lambert
between launches. -- Scott LambertKC5MLE Unix SysAdmin lamb...@lambertfam.org - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: How to log failed auth attempts?

2008-12-17 Thread Scott Lambert
assembly required. I am not a FreeRADIUS developer, so this is speculation. -- Scott LambertKC5MLE Unix SysAdmin lamb...@lambertfam.org - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS vs Aradial RADIUS

2008-12-16 Thread Scott Lambert
... but I have no idea how to configure it... it like scares me because there are no manual to tell me step by step how to configure it to fit my needs and to feet my equipment Pay someone who know's FreeRADIUS a smaller sum to set it up and teach you how to maintain it. -- Scott Lambert

Windows CE domain

2008-10-22 Thread scott woodard
Hi, Free Radius 2.1 It is working just fine on Windows XP and Windows Mobile. However Windows CE is asking for a username and domain. On Windows XP and Mobile it is just asking for username and password. Here is the output from radiusd -x -X Wed Oct 22 06:56:19 2008 : Debug: ++[preprocess]

Re: Windows CE domain

2008-10-22 Thread scott woodard
: Windows CE domain To: freeradius-users@lists.freeradius.org Date: Wednesday, October 22, 2008, 6:31 AM List ntdomain under suffix in authorize. It should be enabled by default in realms module. Ivan Kalik Kalik Informatika ISP Dana 22/10/2008, scott woodard [EMAIL PROTECTED] piše: Hi, Free

  1   2   3   >