Need help on FreeRadius+OTP+OpenLDAP integration

2011-03-14 Thread pradyumna dash
Hi, I need a documentation on how to implement  FreeRadius+OTP+OpenLDAP, I have installed and configured FreeRadius+OpenLDAP before but never used OTP, and also would like to know how OTP will be configured with SASL and how does SASL auth store OTP parameters. Another problem am facing

Need help on FreeRadius+OTP+OpenLDAP integration

2011-03-14 Thread pradyumna dash
Hi, I need a documentation on how to implement  FreeRadius+OTP+OpenLDAP, I have installed and configured FreeRadius+OpenLDAP before but never used OTP, and also would like to know how OTP will be configured with SASL and how does SASL auth store OTP parameters. Another problem am facing

Re: Need help on FreeRadius+OTP+OpenLDAP integration

2011-03-14 Thread Nicolas Goutte
to implement FreeRadius+OTP+OpenLDAP, I have installed and configured FreeRadius+OpenLDAP before but never used OTP, and also would like to know how OTP will be configured with SASL and how does SASL auth store OTP parameters. Another problem am facing is, first there is an authentication

freeradius and openldap

2010-03-11 Thread omega bk
hello all, after all, my freeradius server is working so fine ( i'm glad) thanks for all of u taking time to help me. i can successfully authenticate my users in users file with Cleartext-Password. so know i'd like to authenticate my users through openldap, men that i won't put all my users in

Re: freeradius and openldap

2010-03-11 Thread omega bk
i just want to understand according to man 5 users, the DEFAULT Auth-Type = LDAP means that for all users reaching this entry, perform authentication against LDAP, process any following entries which may match. so why i got an unknown value LDAP for attribute Auth-Type ? knowing that in

Re: freeradius and openldap

2010-03-11 Thread omega bk
sorry but nobody has a clue? Regards 2010/3/11 omega bk omeg...@gmail.com i just want to understand according to man 5 users, the DEFAULT Auth-Type = LDAP means that for all users reaching this entry, perform authentication against LDAP, process any following entries which may

Re: Connecting freeRadius to openLDAP

2009-07-22 Thread Eric Bourkland
. Thanks, - Original Message - From: Ivan Kalik t...@kalik.net To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tuesday, July 21, 2009 6:51:45 PM GMT -05:00 US/Canada Eastern Subject: Re: Connecting freeRadius to openLDAP See if there is a way to somehow get

Re: Connecting freeRadius to openLDAP

2009-07-22 Thread Eric Bourkland
/Canada Eastern Subject: Re: Connecting freeRadius to openLDAP Is the easiest thing to do is to monkey with the openLDAP schema and add some cleartext password attributes? Yes, you should use radius schema with the radius server. Add the whole radius schema. Ivan Kalik Kalik Informatika ISP

Re: Connecting freeRadius to openLDAP

2009-07-22 Thread Alan DeKok
Eric Bourkland wrote: What would be the best solution since freeRadius currently can't get the password out of my openLDAP unless it is using PAP, it gets the password in the request via PEAP. PEAP doesn't work that way. Blame Microsoft. I would like to avoid having to tell everyone

Re: Connecting freeRadius to openLDAP

2009-07-22 Thread Mackey, Theral
The docs do tend to gloss over the bits about how to get the needed password into your LDAP store (besides just saying cleartext or LN/NT). First, check that the user you have setup for ldap to use has auth (not read) access to the userPassword attribute, which I think is true since you said

Connecting freeRadius to openLDAP

2009-07-21 Thread Eric Bourkland
I'm relatively new to freeRadius and I'm getting very frustrated trying to get it to Authenticate with my openLDAP, I'm sure it is a small configuration change but I can't find where it is and I'm beating my head against a wall. FreeRadius does not just work as the instructions imply. All I

Re: Connecting freeRadius to openLDAP

2009-07-21 Thread Phil Mayers
Eric Bourkland wrote: I can attach any of my config files but what I have done is rebuilt a whole new server RHEL4.7-ES, with freeRadius v2.1.6 installed. with In all probability, your LDAP database either: 1. Does not contain the plaintext password, or NT/LM hash. 2. Does not give the

Re: Connecting freeRadius to openLDAP

2009-07-21 Thread Eric Bourkland
to it with open passwords. Thanks, - Original Message - From: Phil Mayers p.may...@imperial.ac.uk To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tuesday, July 21, 2009 12:35:42 PM GMT -05:00 US/Canada Eastern Subject: Re: Connecting freeRadius to openLDAP Eric

Re: Connecting freeRadius to openLDAP

2009-07-21 Thread Ivan Kalik
Yes, I am trying to do MSCHAPv2 from the laptop. If the below is true why am I able to do a successful Radtest user password server 0 secret on the radius server? Because pap works with almost any encryption. Also, ldap bind as user authentication will work with pap request in case that ldap

Re: Connecting freeRadius to openLDAP

2009-07-21 Thread Eric Bourkland
- From: Ivan Kalik t...@kalik.net To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Sent: Tue, 21 Jul 2009 12:33:13 -0500 (CDT) Subject: Re: Connecting freeRadius to openLDAP Yes, I am trying to do MSCHAPv2 from the laptop. If the below is true why am I able to do

Re: Connecting freeRadius to openLDAP

2009-07-21 Thread Alan DeKok
Eric Bourkland wrote: below is my debug file. The interesting thing is when I am trying to do an ldap search it doesn't list the password attribute Are you using Active Directory? If so, please understand that it is NOT an LDAP server. You will need to use Samba to do authentication

Re: Connecting freeRadius to openLDAP

2009-07-21 Thread Eric Bourkland
Sent: Tuesday, July 21, 2009 4:21:57 PM GMT -05:00 US/Canada Eastern Subject: Re: Connecting freeRadius to openLDAP Eric Bourkland wrote: below is my debug file. The interesting thing is when I am trying to do an ldap search it doesn't list the password attribute Are you using Active

Re: Connecting freeRadius to openLDAP

2009-07-21 Thread Ivan Kalik
See if there is a way to somehow get an innter tunnel to use ttls/pap to connect to the ldap server and perfrom authentication that way since it appears that PAP authentication does work. But I don't know if there can be a change in crypt for the authentication from the client which uses

Freeradius with OpenLDAP and AD.

2009-02-17 Thread LEOSI
15:41:34 2009 : Info: Cleaning up request 1 ID 6 with timestamp +38 Tue Feb 17 15:41:34 2009 : Debug: Ready to process requests. -- View this message in context: http://www.nabble.com/Freeradius-with-OpenLDAP-and-AD.-tp22058186p22058186.html Sent from the FreeRadius - User mailing list archive

Re: Freeradius with OpenLDAP and AD.

2009-02-17 Thread tnt
Hi, I have several problems when I would like to link freeradius with AD using OpenLDAP. Look up http://deployingradius.com/documents/configuration/active_directory.html to see how to inegrate with AD for pap and mschap/PEAP. When I tried to test the binding of OpenLDAP to the AD with radtest,

Re: Freeradius with OpenLDAP and AD.

2009-02-17 Thread SDamron
Would Kerberos authentication work with AD and EAP, or am I thinking too early in the day? On Tue, Feb 17, 2009 at 8:55 AM, t...@kalik.net wrote: Hi, I have several problems when I would like to link freeradius with AD using OpenLDAP. Look up

Re: Freeradius with OpenLDAP and AD.

2009-02-17 Thread tnt
Would Kerberos authentication work with AD and EAP, or am I thinking too early in the day? No. Kerberos requires clear text passwords in the request. EAP-MD5 doesn't provide them. EAP-TTLS PAP will work - but native XP supplicant doesn't support that. You can get SecureW2 to do it. Ivan Kalik

Re: Freeradius with OpenLDAP and AD.

2009-02-17 Thread Alan DeKok
SDamron wrote: Would Kerberos authentication work with AD and EAP, or am I thinking too early in the day? It won't work. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Hosts restriction with FreeRadius and OpenLDAP

2009-01-29 Thread scouffa7
the accounts on the LDAP server (in a centralized manner). Is this possible, and how could I implement it? Thx for help, -- View this message in context: http://www.nabble.com/Hosts-restriction-with-FreeRadius-and-OpenLDAP-tp21726215p21726215.html Sent from the FreeRadius - User mailing list

Re: Hosts restriction with FreeRadius and OpenLDAP

2009-01-29 Thread tnt
I'm setting up a freeradius configuration for authenticating users on a number of technologies (pix, nokia, ...). Users accounts are stored in a backend OpenLDAP. I'm willing to allow users to authenticate to specific machines, that I would like to choose and administrer from the accounts on the

Certificate expired! (OpenSSL 0.9.8.b+Freeradius 1.1.3+Openldap structure)

2009-01-17 Thread Someone Youdontknow
Hi to all, Our root certificate is expired!!! We are unable to generate a VALID root certificate. Comparison HTML view is attached. You can see certain fields differences between them. Like; *Serial Number is zero ?!?! X509v3 Basic Constraints: * *CA:TRUE* * (The new one is

RE: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP

2008-11-13 Thread CJ O
Alan - Thank you. Making the change to the inner-tunnel worked. Regards CJ Date: Thu, 13 Nov 2008 08:44:07 +0100 From: [EMAIL PROTECTED] To: freeradius-users@lists.freeradius.org Subject: Re: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP CJ O wrote: Good Afternoon - I've read

Re: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP

2008-11-12 Thread tnt
In site-enable/default under authorize I've uncommented ldap. You don't need ldap there. Uncomment ldap in sites-enabled/inner-tunnel virtual server. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP

2008-11-12 Thread CJ O
Ivan - Thank you for your help. That change has allowed MS-Chapv2 to work from my tunnel. Since I've specified PEAP in the eap.conf, is it possible to use GTC too? Thanks CJ To: freeradius-users@lists.freeradius.org Subject: Re: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP Date: Thu

RE: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP

2008-11-12 Thread tnt
That change has allowed MS-Chapv2 to work from my tunnel. Since I've specified PEAP in the eap.conf, is it possible to use GTC too? Yes, you can use any eap method you want. default_eap_type will be tried first. If refused, server and suppicant will try to agree on another. It just means one

RE: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP

2008-11-12 Thread CJ O
Ivan - Thank you for your help. I removed the password_attribute field from modules/ldap and everything seems to be working with PEAP and GTC. Thank you again! CJ To: freeradius-users@lists.freeradius.org Subject: RE: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP Date: Thu, 13 Nov 2008 01

Re: FreeRadius 2.1.1 - OpenLDAP + NT hash + PEAP

2008-11-12 Thread Alan DeKok
CJ O wrote: Good Afternoon - I've read through a lot of threads and documents and have piced information together, however I am still having issues. We are running an OpenLDAP with the passwords encrypted. I know that PEAP requires the clear text password to be stored in the LDAP Server,

Integrating FreeRadius and Openldap: rlm_ldap not found error

2008-08-27 Thread Syed Anwarul Hasan
whether FreeRadius can authenticate against Openldap backend. Using the command, radtest hasan thales 192.168.1.131 1 testing123 And when I have done the above changes for OpenLdap and FreeRadius Integration. And Started FreeRadius Server using radiusd -X command. Please help me in this regard. SYED

Re: Integrating FreeRadius and Openldap: rlm_ldap not found error

2008-08-27 Thread Alan DeKok
Syed Anwarul Hasan wrote: I have done the following changes in the files below to test FreeRadius Server against a Openldap backend Please do not post the configuration files to the list. You've sent over a LOT of data, much of which is unchanged from the files that ship with the server.

Re: Integrating FreeRadius and Openldap: rlm_ldap not found error

2008-08-27 Thread Syed Anwarul Hasan
Ok,Alan. I will send debug o/p Short messages in future. SYED On Wed, Aug 27, 2008 at 11:58 AM, Alan DeKok [EMAIL PROTECTED]wrote: Syed Anwarul Hasan wrote: I have done the following changes in the files below to test FreeRadius Server against a Openldap backend Please do not post the

Re: Fw: Invalid user (rlm_ldap: Access Attribute denies access) -Digest Authentication With FreeRADIUS and OpenLDAP

2008-05-30 Thread Hoa But
Hello Ivan, Thank you very much for pointing out the dialupAccess attribute. I commented out the entry as it does not apply to my testing. After that FreeRADIUS and OpenLDAP are working together. Thanks again. Best regards, Hoa

Re: Freeradius 2.0.4 + OpenLDAP Problem (Cleartext-Password)

2008-05-29 Thread youness hsina
Hi all , sorry for my english! I configured a freeradius on the first machine , on the second machine i configured OpenLdap. i have configred freeraduis in order to communicate with openldap by editing the *users* file like this : *DEFAULT Auth-Type = LDAP Fall-Through = 1* now i want to test

Re: Freeradius 2.0.4 + OpenLDAP Problem (Cleartext-Password)

2008-05-29 Thread Alan DeKok
youness hsina wrote: now i want to test if freeradius can realy communicate with openldap but i don't know how ca i do this test. have any any ideas please. Run the server in debugging mode, as suggested in the FAQ, README, INSTALL, and daily on this list. Alan DeKok. - List

Re: Freeradius 2.0.4 + OpenLDAP Problem (Cleartext-Password)

2008-05-29 Thread Ivan Kalik
Type radtest on the radius server command line and you will get the parameters for testing. Ivan Kalik Kalik Informatika ISP Dana 29/5/2008, youness hsina [EMAIL PROTECTED] piše: Hi all , sorry for my english! I configured a freeradius on the first machine , on the second machine i configured

Re: Freeradius 2.0.4 + OpenLDAP Problem (Cleartext-Password)

2008-05-29 Thread youness hsina
i have already made a test in radius server with this commande : *#radtest test test localhost 0 test * it works correctly! But i have this user : login : yhsina password : yhsina in an ldap server . my question is how can i interogate my ldap server using this user *yhsina* in order to be

Re: Freeradius 2.0.4 + OpenLDAP Problem (Cleartext-Password)

2008-05-29 Thread youness hsina
i decommented all the lines who have relation with ldap in radiusd.conf file. here is ths radiusdconf file : ldap { server = iut-velizy.uvsq.fr # identity = ou=Manager,dc=iut-velizy,dc=uvsq,dc=fr # password = mypass basedn = ou=Manager,dc=iut-velizy,dc=uvsq,dc=fr filter =

Re: Freeradius 2.0.4 + OpenLDAP Problem (Cleartext-Password)

2008-05-29 Thread Ivan Kalik
# identity = ou=Manager,dc=iut-velizy,dc=uvsq,dc=fr # password = mypass No, you haven't. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius 2.0.4 + OpenLDAP Problem (Cleartext-Password)

2008-05-29 Thread Ivan Kalik
What you refer to as login is identity in ldap section of radiusd.conf. Ivan Kalik Kalik Informatika ISP Dana 29/5/2008, youness hsina [EMAIL PROTECTED] piše: i have already made a test in radius server with this commande : *#radtest test test localhost 0 test * it works correctly! But i

Fw: Invalid user (rlm_ldap: Access Attribute denies access) - Digest Authentication With FreeRADIUS and OpenLDAP

2008-05-29 Thread Hoa But
-Forwarded Message- From: Hoa But [EMAIL PROTECTED] Sent: May 29, 2008 12:13 PM To: freeradius-users@lists.freeradius.org Cc: [EMAIL PROTECTED] Subject: Invalid user (rlm_ldap: Access Attribute denies access) - Digest Authentication With FreeRADIUS and OpenLDAP Hello, Thank you

Re: Fw: Invalid user (rlm_ldap: Access Attribute denies access) -Digest Authentication With FreeRADIUS and OpenLDAP

2008-05-29 Thread Ivan Kalik
I am getting Invalid user (rlm_ldap: Access Attribute denies access) And a bit earlier in the debug you have: rlm_ldap: no dialupAccess attribute - access denied by default Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Fw: Invalid user (rlm_ldap: Access Attribute denies access) -Digest Authentication With FreeRADIUS and OpenLDAP

2008-05-29 Thread Hoa But
To: freeradius-users@lists.freeradius.org Subject: Re: Fw: Invalid user (rlm_ldap: Access Attribute denies access) -Digest Authentication With FreeRADIUS and OpenLDAP I am getting Invalid user (rlm_ldap: Access Attribute denies access) And a bit earlier in the debug you have: rlm_ldap

Freeradius 2.0.4 + OpenLDAP Problem (Cleartext-Password)

2008-05-20 Thread German Hernandez
Hello everybody!! I have FreeRADIUS 1.1.7 + openldap using EAP-PEAP authentication, perfectly working. Now, I want to use the same openldap database, but with FreeRADIUS 2.0.4, but I can't get success authentication. is it necesary additional parameters of configuration for Freeradius 2.0.4

Re: Freeradius and OpenLDAP authentication with hashed passwords

2008-04-01 Thread mel
mel wrote: In that case, something is *really* wrong with my setup and I have no idea why. I can only authenticate if the password in OpenLDAP is cleartext, but never if it's hashed. debug output, radiud.conf (modules ldap section), sites-enable/default follows. I managed to get the

Re: Freeradius and OpenLDAP authentication with hashed passwords

2008-04-01 Thread Alan DeKok
mel wrote: In that case, something is *really* wrong with my setup and I have no idea why. I can only authenticate if the password in OpenLDAP is cleartext, but never if it's hashed. debug output, radiud.conf (modules ldap section), sites-enable/default follows. You have edited the

Re: Freeradius and OpenLDAP authentication with hashed passwords

2008-04-01 Thread mel
Hi, authorize { preprocess ldap chap mschap suffix eap #files } See? You edited that. A lot. And broke it. You got that right - I've accidently/intentionally (I can't remember which) deleted pap. My bad. I have *no* idea why so many people install the

Re: Freeradius and OpenLDAP authentication with hashed passwords

2008-03-31 Thread Alan DeKok
mel wrote: I've managed to setup FreeRadius with OpenLDAP. The passwords however, are hashed (e.g. {SHA}) in LDAP. Authenticating directly to LDAP works, but it failed with Freeradius. What does that mean? If the password is in plain-text, authentication is successful. Well, yes

Re: Freeradius and OpenLDAP authentication with hashed passwords

2008-03-31 Thread mel
Hi, FreeRADIUS does that automatically... IF it receives a password in the Access-Request. If it doesn't receive a password in the Access-Request, what you want to do is impossible. See the web page for more explanations. A bit clearer now. So you're saying that I should use: radtest

Re: Freeradius and OpenLDAP authentication with hashed passwords

2008-03-31 Thread Alan DeKok
mel wrote: A bit clearer now. So you're saying that I should use: radtest testuser {SHA}... radiusserver 0 secret No. The *client* is not the *server*. The client sends a clear-text password to the server. The server looks up the user in a database, and (perhaps) finds a SHA hashed

Re: Freeradius and OpenLDAP authentication with hashed passwords

2008-03-31 Thread mel
Alan DeKok wrote: password to the server. The server looks up the user in a database, and (perhaps) finds a SHA hashed password. The server then SHA hashes the password supplied by the client, and compares it to the SHA password from the database. In that case, something is *really* wrong

Freeradius and OpenLDAP authentication with hashed passwords

2008-03-30 Thread mel
Hi all, I've managed to setup FreeRadius with OpenLDAP. The passwords however, are hashed (e.g. {SHA}) in LDAP. Authenticating directly to LDAP works, but it failed with Freeradius. If the password is in plain-text, authentication is successful. Question: What are the setting in FR

RE: Freeradius with OpenLDAP (Suse Enterprise 10) [SEC=UNCLASSIFIED]

2008-02-14 Thread Ranner, Frank MR
UNCLASSIFIED -Original Message- Looking at this it seems that the LDAP record is holding the password with a certain encryption and that Radius needs to be told to encrypt the password it has passed to it in that format. Anyone know what the LDAP encryption would be, and how

Re: Freeradius with OpenLDAP (Suse Enterprise 10) [SEC=UNCLASSIFIED]

2008-02-13 Thread David W Bell
Ranner, Frank MR wrote: UNCLASSIFIED Config as requested - I did uncomment and configure the identity section - is this not required? ldap { # # Note that this needs to match the name in the LDAP # server certificate, if you're

Re: Freeradius with OpenLDAP (Suse Enterprise 10) [SEC=UNCLASSIFIED]

2008-02-13 Thread David W Bell
David W Bell wrote: Ranner, Frank MR wrote: UNCLASSIFIED Config as requested - I did uncomment and configure the identity section - is this not required? ldap { # # Note that this needs to match the name in the LDAP # server

Re: Freeradius with OpenLDAP (Suse Enterprise 10) [SEC=UNCLASSIFIED]

2008-02-13 Thread David W Bell
David W Bell wrote: David W Bell wrote: Ranner, Frank MR wrote: UNCLASSIFIED Config as requested - I did uncomment and configure the identity section - is this not required? ldap { # # Note that this needs to match the name in the LDAP

RE: Freeradius with OpenLDAP (Suse Enterprise 10) [SEC=UNCLASSIFIED]

2008-02-12 Thread Ranner, Frank MR
UNCLASSIFIED Config as requested - I did uncomment and configure the identity section - is this not required? ldap { # # Note that this needs to match the name in the LDAP # server certificate, if you're using ldaps.

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-12 Thread Markus Krause
Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-12 Thread David W Bell
Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been set to be used for authenication during

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread Markus Krause
Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been set to be used for authenication during the SUSE install. This is proven by the ability to log in to the box, both locally and via SSH I installed freeRADIUS from the latest source and it is

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread Markus Krause
Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been set to be used for authenication during the SUSE install. This is proven by the ability to log in to the box, both locally

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread David W Bell
Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been set to be used for authenication during the SUSE install. This is proven by the ability to log in to the

Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread David W Bell
LDAP is installed and working out of the box, having been set to be used for authenication during the SUSE install. This is proven by the ability to log in to the box, both locally and via SSH I installed freeRADIUS from the latest source and it is working also. freeRADIUS seems unable to

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread David W Bell
Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been set to be used for authenication during the SUSE install. This is proven by the ability to log in to the box, both locally and via SSH I installed freeRADIUS from the

Re: Freeradius with OpenLDAP (Suse Enterprise 10)

2008-02-11 Thread Markus Krause
Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: Markus Krause wrote: Zitat von David W Bell [EMAIL PROTECTED]: LDAP is installed and working out of the box, having been set to be used for authenication during the SUSE install. This

Problem with Freeradius 1.1.2 OpenLDAP 2.3.20

2006-06-06 Thread Nicolas Martin
Hello everyone, I am trying to make Freeradius 1.1.2 work with OpenLDAP2.3.20 (I was previously able to make it work perfectly with MySQL). When I try to configure and compile Freeradius without any options, I receive a Segmentation Fault. When I try to configure it with --

Re: Problem with Freeradius 1.1.2 OpenLDAP 2.3.20

2006-06-06 Thread Nicolas Baradakis
En réponse à Nicolas Martin : checking for ldap_init in -lldap_r ... no checking for ldap.h ... no configure: warning : silently not building rlm_ldap configure: warning : FAILURE : rlm_ldap requires libldap_r ldap.h I am sure my paths are correct, I am sure I have the file ldap.h in my

Re: Problem with Freeradius 1.1.2 OpenLDAP 2.3.20

2006-06-06 Thread Nicolas Martin
Please look for error messages in src/modules/rlm_ldap/config.log -- Nicolas Baradakis The two main errors I can find are: /usr/bin/ld: cannot find -lldap_r collect2: ld returned 1 exit status configure: failed program was: #line 974 configure #include confdefs.h (3 times) and In

Re: Problem with Freeradius 1.1.2 OpenLDAP 2.3.20

2006-06-06 Thread Alan DeKok
Nicolas Martin [EMAIL PROTECTED] wrote: In file included from .../ldap.h:30 .../lber.h:29:24: lber_types.h: no such file or directory ... It is true that I don't have any lber_types.h file The LDAP headers are telling you they need that lber_types.h. If you don't have it, then nothing you

Re: freeradius 1.0.5 + openLDAP 2.3.17 ( with bdb ?? )

2006-02-01 Thread A . L . M . Buxey
Hi, HI Folks, Do anyone know which berkeley database version is compatible with openLDAP 2.3.17?? Im trying to compile the openldap2.3.17 with bdb-4.0 which is giving incompatibility error. Any earliest reply will be of great help. according to the openldap FAQ, the prerequisite

Re: freeradius 1.0.5 + openLDAP 2.3.17 ( with bdb ?? )

2006-02-01 Thread Dusty Doris
On Wed, 1 Feb 2006, sumi wrote: HI Folks, Do anyone know which berkeley database version is compatible with openLDAP 2.3.17?? Im trying to compile the openldap2.3.17 with bdb-4.0 which is giving incompatibility error. Any earliest reply will be of great help. I would recommend using BDB

Re: FreeRADIUS and OpenLDAP

2006-01-17 Thread Alan DeKok
Michael Schwartzkopff [EMAIL PROTECTED] wrote: If I use OpenLDAP to authorize / authenticate my users, what kinds of passwords can I store in LDAP? In 1.1.0, only one kind of password. I suggest clear. Is this controlled by the password_header configuation or does this only strip the

Re: FreeRADIUS and OpenLDAP

2006-01-16 Thread Phil Mayers
Michael Schwartzkopff wrote: Hi, If I use OpenLDAP to authorize / authenticate my users, what kinds of passwords can I store in LDAP? That question is inverted. The Radius auth type defines what data you *need* for that auth type, and thus what crypt you need to store. PAP - needs

FreeRADIUS and OpenLDAP

2006-01-15 Thread Michael Schwartzkopff
Hi, If I use OpenLDAP to authorize / authenticate my users, what kinds of passwords can I store in LDAP? clear, crypt, SSHA, SMD5, MD5, SHA, NTHASH, LMHASH? Is this controlled by the password_header configuation or does this only strip the header of the password? Is there any difference if

FreeRadius and Openldap authentication

2006-01-02 Thread [EMAIL PROTECTED]
Hello, I'm pretty new to ldap and radius, I try to put and 802.x authentication but I have difficulties setting it up correctly. Here is my problem: When I start the radtest binary: radtest test supersecret localhost 2 testing123 Here is the result: Sending

Re: FreeRadius and Openldap authentication

2006-01-02 Thread Zoltan A. Ori
On Monday 02 January 2006 05:46, [EMAIL PROTECTED] wrote: Here is my problem: When I start the radtest binary: radtest test supersecret localhost 2 testing123 rad_recv: Access-Reject packet from host 127.0.0.1:1812, id=45, length=20 You have set your server to do EAP.

RE: FreeRadius and Openldap authentication

2006-01-02 Thread S�bastien Cantos
[EMAIL PROTECTED] Network / System Manager Neopost DIVA -Message d'origine- De : [EMAIL PROTECTED] us.org [mailto:[EMAIL PROTECTED] freeradius.org] De la part de [EMAIL PROTECTED] Envoyé : lundi 2 janvier 2006 11:46 À : freeradius-users@lists.freeradius.org Objet : FreeRadius

Re: FreeRadius and Openldap authentication

2006-01-02 Thread Zoltan Ori
On Monday 02 January 2006 10:11, Robert WAKIM wrote: Thanks for the answer, I've tried radeapclient but it keeps segfaulting. I've browsed google to find a windows eap-md5 test client without any success. Sorry, I can't help with radeapclient. Do you have any advices on how to test the

Problem in using freeradius with openldap

2005-04-13 Thread richard Bai
I am using freeradius-1.0.2 to do peap authentication. I want to use openldap to be the central db storing the user account. I have configured the freeradius to use rlm_ldap module. But when the radius is started and receives the request from the client by inputing the user name and password, the

freeradius with openldap

2005-02-28 Thread helder martins
hello, i'm having problems when i try to authenticate an user using freeradius and ldap. i'm usind freeradius-1.0.1 and openldap-2.2.15 and i need someone to help me correctly configuring my radius server to authenticate against ldap database. thanks

Re: freeradius with openldap

2005-02-28 Thread Anderson Alves de Albuquerque
Send me your configuration. On Mon, 28 Feb 2005, helder martins wrote: hello, i'm having problems when i try to authenticate an user using freeradius and ldap. i'm usind freeradius-1.0.1 and openldap-2.2.15 and i need someone to help me correctly configuring my radius server

Re: Help:TLS connection between Freeradius and Openldap

2004-11-18 Thread Giulio Casella
tls_certfile= usr/local/freeradius/etc/raddb/radius-ssl-ldap/radius.crt You're missing the heading / in the above line. Bye, gc -- Giulio Casella [EMAIL PROTECTED] System and network manager Computer Science Dept. - University of Milano

Re: Help:TLS connection between Freeradius and Openldap

2004-11-18 Thread
I have modify the tls_certfile to tls_certfile=/usr/local/freeradius/etc/raddb/radius-ssl-ldap/radius.crt But still no success. The debug info is as follows: (Still TLS error) rad_recv: Access-Request packet from host 192.168.80.1:1812, id=31, length=135 NAS-IP-Address = 192.168.80.1

RE: Secure TLS connection between Freeradius and Openldap

2004-11-17 Thread Konstantin KABASSANOV
not match... Thanks all who tried to help me. Konstantin -Original Message- From: Konstantin KABASSANOV [mailto:[EMAIL PROTECTED] Sent: mardi 16 novembre 2004 15:46 To: '[EMAIL PROTECTED]' Subject: Secure TLS connection between Freeradius and Openldap Hello, I'm trying to establish

Secure TLS connection between Freeradius and Openldap

2004-11-16 Thread Konstantin KABASSANOV
Hello, I'm trying to establish a secure TLS connection between a Freeradius and an Openldap server. The openssl s_client -connect command successfully establishes a connection to the openldap server on the mentioned port with the following certificates, but when trying to bind from freeradius I

Freeradius and OpenLdap

2004-06-15 Thread Jawhar TAZI
Hi Everyboy, Does anybody know please why each time i am trying to create a new object radiusprofile in my directory of openldap i've got the message : 04:09:53 PM: Failed to add new entry cn=dial,ou=univ-montp3,c=fr Root error: [LDAP: error code 65 - no structural object class provided] I have

Re: Freeradius and OpenLdap

2004-06-15 Thread Michael Schwartzkopff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Am Dienstag, 15. Juni 2004 16:20 schrieb Jawhar TAZI: Hi Everyboy, Does anybody know please why each time i am trying to create a new object radiusprofile in my directory of openldap i've got the message : 04:09:53 PM: Failed to add new entry