Re: EAP/TTLS Auth problem

2012-05-15 Thread Steve Hopps
I was able to get this working, thanks for all your help everyone On Mon, May 14, 2012 at 4:51 PM, alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, Well I've been trying to follow the advice here and also what I've found online and in the configs. I attempted to revert to the 'default' config

Re: EAP/TTLS Auth problem

2012-05-14 Thread Steve Hopps
We are using the correct password. There must be something broken causing the passwords not to match. That is what I'm looking for help to determine. On Fri, May 11, 2012 at 3:02 PM, Alan DeKok al...@deployingradius.com wrote: Steve Hopps wrote: I'm trying to use FreeRadius with OpenLDAP for

Re: EAP/TTLS Auth problem

2012-05-14 Thread Phil Mayers
On 14/05/12 15:07, Steve Hopps wrote: We are using the correct password. There must be something broken causing the passwords not to match. That is what I'm looking for help to determine. Send a full debug radiusd -X. The trimmed debug doesn't show enough info. However, at a guess, this line:

Re: EAP/TTLS Auth problem

2012-05-14 Thread Alan DeKok
Steve Hopps wrote: We are using the correct password. You can believe what the server sees. Or you can believe a fantasy. It's that simple. There must be something broken causing the passwords not to match. That is what I'm looking for help to determine. As Phil said, post the FULL

Re: EAP/TTLS Auth problem

2012-05-14 Thread Steve Hopps
I'll post the full log. It should be pulling from OpenLDAP. I had to censor the log in a few places, including the IP of the system I'm using to test, which I changed to 6.6.6.6 Thanks for helping me with this. FreeRADIUS Version 2.1.10, for host x86_64-pc-linux-gnu, built on Nov 14 2010 at

Re: EAP/TTLS Auth problem

2012-05-14 Thread Alan DeKok
Steve Hopps wrote: I'll post the full log. It should be pulling from OpenLDAP. I had to censor the log in a few places, including the IP of the system I'm using to test, which I changed to 6.6.6.6 And please check Phil's comment. It is *still* showing this: [pap] Using CRYPT password *

Re: EAP/TTLS Auth problem

2012-05-14 Thread alan buxey
Hi, We are using the correct password. There must be something broken causing the passwords not to match. That is what I'm looking for help to determine. WHERE are you using the correct password? if the client is being given the correct password, then where are the usernames and paswords

Re: EAP/TTLS Auth problem

2012-05-14 Thread Phil Mayers
On 14/05/12 15:58, Steve Hopps wrote: I'll post the full log. It should be pulling from OpenLDAP. I had to It's not. You haven't configured it to do that. Module: Instantiating module ldap from file /etc/freeradius/radiusd.conf ldap { server = localhost port = 389 Ok,

Re: EAP/TTLS Auth problem

2012-05-14 Thread Steve Hopps
Well I've been trying to follow the advice here and also what I've found online and in the configs. I attempted to revert to the 'default' config files for sites-enabled, as this project was dropped in my lap after months of another guy working on it and being frustrated, and I wasn't sure what

Re: EAP/TTLS Auth problem

2012-05-14 Thread alan buxey
Hi, Well I've been trying to follow the advice here and also what I've found online and in the configs. I attempted to revert to the 'default' config files for sites-enabled, as this project was dropped in my lap after months of another guy working on it and being frustrated, and I wasn't

EAP/TTLS Auth problem

2012-05-11 Thread Steve Hopps
I'm trying to use FreeRadius with OpenLDAP for authentication of some Nanostation M2 access points, but have had no luck getting it to work. When using rad_eap_test to experiment, I logged the following: Found Auth-Type = PAP # Executing group from file /etc/freeradius/sites-enabled/inner-tunnel

Re: EAP/TTLS Auth problem

2012-05-11 Thread Alan DeKok
Steve Hopps wrote: I'm trying to use FreeRadius with OpenLDAP for authentication of some Nanostation M2 access points, but have had no luck getting it to work. When using rad_eap_test to experiment, I logged the following: ... [pap] Passwords don't match ++[pap] returns reject Failed to