Re: 802.1x Issue

2012-12-03 Thread Alan Buxey
Hi, > Most times you will be able to get the native supplicant working given enough > prodding, but prodding on a large scale is unfeasable without some kind of > automated tool, because students are really really bad at following > instructions. oh yes, I agree with that - configuration deplo

Re: 802.1x Issue

2012-12-03 Thread Arran Cudbard-Bell
On 3 Dec 2012, at 17:31, Alan Buxey wrote: > Hi, > >> So would you recommend ? Your opinion above looks like you wouldnt do >> that, since it may not work. Kinda complicated, since we are an >> university, and need to work with everyone. > > we are a university and we avoid using any ext

Re: 802.1x Issue

2012-12-03 Thread Alan Buxey
Hi, >So would you recommend ? Your opinion above looks like you wouldnt do >that, since it may not work. Kinda complicated, since we are an >university, and need to work with everyone. we are a university and we avoid using any extra programs/utils to perform such duties (especially

Re: 802.1x Issue

2012-12-03 Thread Arran Cudbard-Bell
On 3 Dec 2012, at 17:17, Brekler Custodio wrote: > > > i'll repeat what was already said in this thread: > > > > > > "Old Windows systems need an extra supplicant to do other forms of EAP such > > as EAP-TTLS/PAP - eg open1X or SecureW2 - Windows 8 now natively supports > > such EAP methods

RE: 802.1x Issue

2012-12-03 Thread Brekler Custodio
> i'll repeat what was already said in this thread: > > > "Old Windows systems need an extra supplicant to do other forms of EAP such > as EAP-TTLS/PAP - eg open1X or SecureW2 > - Windows 8 now natively supports such EAP methods " Ohhh now i understand w

Re: 802.1x Issue

2012-12-03 Thread Alan Buxey
Hi, >Have you guys hear about SecureW2 ? >People from Cloudpath Networks said they can make it work MD5 hash >passwords on 802.1x with TTLS-PAP. >They said i can make it work aswell with EAP-TLS via certificates and PKI. >Is that correct ? Have anyone tested that before ? i'll

Re: 802.1x Issue

2012-12-03 Thread Phil Mayers
On 03/12/12 16:04, Brekler Custodio wrote: Have you guys hear about SecureW2 ? Yes. It's a supplicant (or plugin? I can't remember) with support for EAP-TTLS/PAP on older versions of windows. People from Cloudpath Networks said they can make it work MD5 hash passwords on 802.1x with TTLS-PA

RE: 802.1x Issue

2012-12-03 Thread Brekler Custodio
Have you guys hear about SecureW2 ?People from Cloudpath Networks said they can make it work MD5 hash passwords on 802.1x with TTLS-PAP.They said i can make it work aswell with EAP-TLS via certificates and PKI.Is that correct ? Have anyone tested that before ?

RE: 802.1x Issue

2012-11-30 Thread Brekler Custodio
> Rather than .bat + xml to do it, there are more user-friendly > front-ends available. The main eduroam one (but not limited to > eduroam of course) is su1x (http://sourceforge.net/projects/su1x/). > > I found that had too many features for my liking, and it does > confuse some of our users (

RE: 802.1x Issue

2012-11-30 Thread Brekler Custodio
Nice, but the thing is, our freeradius is working with a linux DB... IF it was an AD would be much easyer, since everything on Microsoft works fine with other Microsoft O.S.So we really need to make a new DB without MD5.But good to know about what you guys did there.

Re: 802.1x Issue

2012-11-30 Thread Alan Buxey
Hi, >Well, lets say its not possible... since we are an university, with >something about 600 conections every night, with lots of O.S working (70% we are a university with around 6500 concurrent wireless users and 5000 concurrent wired connections in the student residential network. >

Re: 802.1x Issue

2012-11-30 Thread Matthew Newton
On Fri, Nov 30, 2012 at 09:18:13PM +, Brekler Custodio wrote: > Its better to make a new DB with new passwords on EAP and use a > .bat + xml profile to configure windows notebooks. Rather than .bat + xml to do it, there are more user-friendly front-ends available. The main eduroam one (but not

RE: 802.1x Issue

2012-11-30 Thread Brekler Custodio
Well, lets say its not possible... since we are an university, with something about 600 conections every night, with lots of O.S working (70% windows), it would be kinda hard to configure every single computer with a software.Its better to make a new DB with new passwords on EAP and use a .bat

RE: 802.1x Issue

2012-11-30 Thread vazoumana fofana
Subject: RE: 802.1x Issue Date: Fri, 30 Nov 2012 16:23:46 + Is there any way a Microsoft Notebook authenticate using MD5 or PAP ?By default is only EAP (PEAP) or card/certificate, i need to know if there is anything you guys know that makes windows works on PAP or MD5...Im searching on

RE: 802.1x Issue

2012-11-30 Thread Brekler Custodio
Thanks Alan.On my research i found the same aswek as you said. I found this link...http://support.microsoft.com/kb/922574/en-us That teachs how to re-enable MD5, but didnt worked, so to solve the problem is simple, change our DB.Thanks a lot guys! - List

RE: 802.1x Issue

2012-11-30 Thread Brekler Custodio
Well, thanks both of you. Since im not designated to take care of DB i didnt knew about that.The problem was with Freeradius, my DB was correct.The problem was the following: when the prople gave me this Freeradius to test they edited the dialup.conf to add more attributes on the sql, so i just

Re: 802.1x Issue

2012-11-30 Thread Hoggins!
I haven't tested it, but I found XSupplicant (http://open1x.sourceforge.net/), and it seems to enable 802.11x authentication with PAP, even on e.g. Windows XP Home machines that don't support 802.11x out of the box. That's what they say anyway. Le 30/11/2012 17:23, Brekler Custodio a écrit : > Is

Re: 802.1x Issue

2012-11-30 Thread Alan DeKok
Brekler Custodio wrote: > Is there any way a Microsoft Notebook authenticate using MD5 or PAP ? For WiFi? No. > By default is only EAP (PEAP) or card/certificate, i need to know if > there is anything you guys know that makes windows works on PAP or MD5... No. > Im searching on internet ri

RE: 802.1x Issue

2012-11-30 Thread Brekler Custodio
Is there any way a Microsoft Notebook authenticate using MD5 or PAP ?By default is only EAP (PEAP) or card/certificate, i need to know if there is anything you guys know that makes windows works on PAP or MD5...Im searching on internet right now to see if i can find, anyways i leave the questio

Re: 802.1x Issue

2012-11-30 Thread Phil Mayers
On 11/29/2012 10:44 PM, Brekler Custodio wrote: rlm_sql_mysql: MYSQL check_error: 1054 received rlm_sql_getvpdata: database query error This should be clear. You've mangled the SQL queries or, more likely, not setup the SQL database right. - List info/subscribe/unsubscribe? See http://www.fr

Re: 802.1x Issue

2012-11-29 Thread Alan Buxey
Problem with the query. Run that query with mysql client and see what the output shows...and tell us what that entry for user looks like in radcheck table. Default sql configuration works alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

802.1x Issue

2012-11-29 Thread Brekler Custodio
Hi again people, so a week ago i posted here a problem with 802.1x i had and it turned to be all my users were MD5 password, so that was my problem.Today i created a new DB on a test server, changed on sql.conf and tested.Im getting this error, i tried to understand that, BUT im kinda a newbie