RE: WLAN 802.1x FreeRadius with LDAP

2005-11-29 Thread King, Michael
-Original Message- Zoltan Ori wrote: You have ntlm_auth in your mschap configuration. You don't want that for LDAP. You don't need anything NT in that module. The default configuration had everything commented out but authtype = MS-CHAP. Start with that and then add what you

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-29 Thread Zoltan Ori
On Tuesday 29 November 2005 13:56, Christian Poessinger wrote: Nope, there is everything uncommented. I also tried to add this to the ldap.attrmap file: That's the problem everything is uncommented. Comment out ntlm_auth and with_ntdomain_hack. If you have plain text passwords, you aren't

RE: WLAN 802.1x FreeRadius with LDAP

2005-11-29 Thread Christian Poessinger
King, Michael wrote: Christian, That is what he is saying your problem is, everything is uncommented Sorry, with uncommented i ment that all is commented out. Sorry my fault. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-28 Thread Konne
hi ca somebody post a howto what describe the configuration: - peap/mschapv2 with ldap and freeradius - client configuration (M$ Windows XP, SecureW2) thx Zoltan A. Ori schrieb: On Sunday 27 November 2005 06:52, Christian Poessinger wrote: Yes, I'm trying to use PEAP, I have configured

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-28 Thread Zoltan Ori
On Monday 28 November 2005 04:31, Konne wrote: hi ca somebody post a howto what describe the configuration: - peap/mschapv2 with ldap and freeradius - client configuration (M$ Windows XP, SecureW2) thx There are many howtos available that can be found searching the mail archives

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-28 Thread Alan DeKok
Konne [EMAIL PROTECTED] wrote: ca somebody post a howto what describe the configuration: - peap/mschapv2 with ldap and freeradius - client configuration (M$ Windows XP, SecureW2) http://www.freeradius.org/doc/ contains multiple howto's. Alan DeKok. - List info/subscribe/unsubscribe

RE: WLAN 802.1x FreeRadius with LDAP

2005-11-28 Thread Christian Poessinger
Zoltan A. Ori wrote: On Sunday 27 November 2005 06:52, Christian Poessinger wrote: Yes, I'm trying to use PEAP, I have configured MS-CHAPv1 as described in many Howtos. MS-CHAP V2 is in the Howtos of PEAP that I have read. In any case, there is no mschap info in the tunnel which is

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-28 Thread Zoltan Ori
On Monday 28 November 2005 12:32, Christian Poessinger wrote: rlm_eap_peap: Had sent TLV failure, rejecting. Use the latest available drivers for your wireless adaptor. I've encountered many strange connectivity issues that are fixed with new drivers. If the supplicant is XP SP2 you may need

RE: WLAN 802.1x FreeRadius with LDAP

2005-11-27 Thread Christian Poessinger
Zoltan A. Ori wrote: Are you trying to use PEAP/MSCHAP-V2? I don't see any mschapv2 in your logs. Yes, I'm trying to use PEAP, I have configured MS-CHAPv1 as described in many Howtos. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-27 Thread Zoltan A. Ori
On Sunday 27 November 2005 06:52, Christian Poessinger wrote: Yes, I'm trying to use PEAP, I have configured MS-CHAPv1 as described in many Howtos. MS-CHAP V2 is in the Howtos of PEAP that I have read. In any case, there is no mschap info in the tunnel which is indicated in the error

WLAN 802.1x FreeRadius with LDAP

2005-11-26 Thread Christian Poessinger
Hello folks, I want to do a setup with a HP Procurve 520wl Access Point, OpenLDAP and FreeRadius with 802.1x and users in my LDAP backend. LDAP and Radius works fine, when i do a radtest user pass radius.domain.tld 0 secret i get an access accept package back. Now i configured my AP to use the

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-26 Thread Zoltan A. Ori
On Saturday 26 November 2005 08:50, Christian Poessinger wrote: rlm_eap_peap: Session established. Decoding tunneled attributes. rlm_eap_tls: TLS 1.0 Alert [length 0002], fatal access_denied TLS Alert read:fatal:access denied rlm_eap_peap: No data inside of the tunnel. rlm_eap:

RE: WLAN 802.1x FreeRadius with LDAP

2005-11-26 Thread Christian Poessinger
Zoltan A. Ori wrote: On Saturday 26 November 2005 08:50, Christian Poessinger wrote: rlm_eap_peap: Session established. Decoding tunneled attributes. rlm_eap_tls: TLS 1.0 Alert [length 0002], fatal access_denied TLS Alert read:fatal:access denied rlm_eap_peap: No data inside of the

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-26 Thread Zoltan A. Ori
On Saturday 26 November 2005 12:27, Christian Poessinger wrote: Zoltan A. Ori wrote: On Saturday 26 November 2005 08:50, Christian Poessinger wrote: rlm_eap_peap: Session established. Decoding tunneled attributes. rlm_eap_tls: TLS 1.0 Alert [length 0002], fatal access_denied TLS

RE: WLAN 802.1x FreeRadius with LDAP

2005-11-26 Thread Christian Poessinger
Zoltan A. Ori wrote: I'm not an expert and am often wrong, but I don't think FreeRADIUS is the problem here. Everything is working up to that point. Does it break at the same place every time? Double check the NAS and supplicant configurations. - List info/subscribe/unsubscribe? See

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-26 Thread Zoltan A. Ori
On Saturday 26 November 2005 13:58, Christian Poessinger wrote: Zoltan A. Ori wrote: I'm not an expert and am often wrong, but I don't think FreeRADIUS is the problem here. Everything is working up to that point. Does it break at the same place every time? Double check the NAS and

Re: WLAN 802.1x FreeRadius with LDAP

2005-11-26 Thread Alan DeKok
Christian Poessinger [EMAIL PROTECTED] wrote: I tripplechecked the configs and found nothing. As i said, radtest works fine. Ist this EAP thing. You haven't said what supplicant you're using. Also, it doesn't help that radtest works. radtest doesn't do EAP, so it's testing a completely

freeradius + peap + ldap

2005-10-10 Thread Yuri Francalacci
Hi, I have this environment: WinXP PEAP wireless client + linksys AP + freeradius 1.0.5 + openldap (with kerberos password) and I would like to setup the 802.1x peap authentication. Everything works well if I use users file for authenticating wireless client, but if I use ldap users, clients are

freeRadius with LDAP for MSCHAP mac auth

2005-09-23 Thread Seferovic Edvin
Hello everyone... Ive set up a freeradius server with LDAP backend for MSCHAP, but now I have to set up a mac based auth on the same server also with the same LDAP backend ( but the mac info is found in another subtree ). So I have made two ldap instances under modules including MSCHAP

Trying to setup FreeRadius w/ LDAP(ActiveDirectory), PEAP

2005-08-10 Thread Andrew Daniels
I'm probably over complicating this, and I've searched the archives for two days now, I've googled for twice that, and I can't seem to find a clear, howto on setting this up. Here's my goals: 1) Freeradius 2) EAP-TLS - PEAP (for secure, non-client certificate) 3) LDAP for user authentication

Re: Trying to setup FreeRadius w/ LDAP(ActiveDirectory), PEAP

2005-08-10 Thread Alan DeKok
Andrew Daniels [EMAIL PROTECTED] wrote: 1) Freeradius 2) EAP-TLS - PEAP (for secure, non-client certificate) 3) LDAP for user authentication AD isn't an LDAP server. At least, not for passwords, it isn't. You've got to use ntlm_auth. See radiusd.conf. Alan DeKok. - List

FreeRADIUS and LDAP

2005-07-18 Thread Matt Juszczak
Hi all, Our setup in LDAP right now is: ou=People,dc=domain,dc=net Under the Organizational Unit of People, we have our posixAccount users, which have valid UNIX uid's and have email accounts. However, not all of our Email users (ou=People) have radius accounts as well, and sometimes, user

Re: freeradius 1.0.4 ldap compilation

2005-07-05 Thread Marc-Henri Boisis-delavaud
the functions needed by FreeRADIUS. Or, the LDAP libraries aren't being found at compile-time. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/ users.html Do you preconise openldap 2.2.26 or 2.3.4 and with what options ? Marc - List info/subscribe/unsubscribe? See

Re: freeradius 1.0.4 ldap compilation

2005-07-05 Thread Alan DeKok
Marc-Henri Boisis-Delavaud [EMAIL PROTECTED] wrote: And what is the version of openldap recomended by freeradius ? Most versions should work. My guess is that the LDAP libraries are in a non-standard place, where your linker can't find them. Alan DeKok. - List info/subscribe/unsubscribe?

freeradius 1.0.4 ldap compilation

2005-07-04 Thread Marc-Henri Boisis-delavaud
This is my command to install freeradius from source on Suseinstallation de BerkeleyDB  4.3.28 NCcd build_unix    ../dist/configure --prefix=/opt/db --enable-static --disable-sharedmake PREFIX=/opt/db install                                       installation de openLDAP

Re: freeradius 1.0.4 ldap compilation

2005-07-04 Thread Alan DeKok
Marc-Henri Boisis-delavaud [EMAIL PROTECTED] wrote: /opt/freeradius/distrib.freeradius-1.0.4/src/modules/rlm_ldap/ rlm_ldap.c:2181: undefined reference to `ldap_unbind_s' Hmm... it looks like your version of OpenLDAP doesn't have the functions needed by FreeRADIUS. Or, the LDAP libraries

Re: freeradius 1.0.4 ldap compilation

2005-07-04 Thread Marc-Henri Boisis-Delavaud
needed by FreeRADIUS. Or, the LDAP libraries aren't being found at compile-time. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html And what is the version of openldap recomended by freeradius ? - List info/subscribe/unsubscribe? See http

freeradius and LDAP-V2

2005-04-21 Thread Frank Bonnet
Hello I'm new to the list :-) I am setting up a chillispot server to manage our future WiFi network and I wonder if the schemas given with the lastest freeradius ditribution as it is marqued for LDAP-v3 are OK for LDAP-v2 ? We actually use LDAP v2 ( openldap 2.0.27 ) as centralized auth system

Re: freeradius and LDAP-V2

2005-04-21 Thread Vladimir
Frank Bonnet wrote: I am setting up a chillispot server to manage our future WiFi network and I wonder if the schemas given with the lastest freeradius ditribution as it is marqued for LDAP-v3 are OK for LDAP-v2 ? We actually use LDAP v2 ( openldap 2.0.27 ) as centralized auth system and we do

Re: freeradius and LDAP-V2

2005-04-21 Thread Luis Daniel Lucio Quiroz
Le Jeudi 21 Avril 2005 07:53, Frank Bonnet a écrit : Hello I'm new to the list :-) I am setting up a chillispot server to manage our future WiFi network and I wonder if the schemas given with the lastest freeradius ditribution as it is marqued for LDAP-v3 are OK for LDAP-v2 ? We actually

Re: freeradius and LDAP

2005-03-03 Thread Beast
Thomas Simmons wrote: passwords must be encrypted even when sent inside our LAN. I would like to use mschap v2, but it seems that it will not work with LDAP, is this correct? If I cannot use mschap v2, is there another way to encrypt the passwords or use some sort of challenge authentication?

freeradius and LDAP

2005-03-02 Thread Thomas Simmons
I am in the process of setting up a Samba PDC. All user info is stored in LDAP. All users also have a matching SHAA hashed UNIX password that is also stored in LDAP. I have all of that set up and it's working fine. The other thing that I want to do is allow users to use this username and

Re: freeradius and LDAP

2005-03-02 Thread Alan DeKok
Thomas Simmons [EMAIL PROTECTED] wrote: When using PAP, the password is sent in clear text. Sent in what protocol? RADIUS does no such thing. The password is sent through the VPN to the firewall, so it's never exposed to the internet but passwords must be encrypted even when sent inside

Re: FreeRadius with LDAP

2005-02-18 Thread Michael Mitchell
dbx is your friend... But check to see that the ldap module actually built... unless you've got things installed in the default places, it can take a little work to get the ldap module to compile on Solaris... José Berenguer wrote: Hello! We are trying to authenticate the last version of

RE: FreeRadius with LDAP

2005-02-18 Thread Sébastien Cantos
PROTECTED] [mailto:[EMAIL PROTECTED] De la part de Michael Mitchell Envoyé : vendredi 18 février 2005 13:30 À : freeradius-users@lists.freeradius.org Objet : Re: FreeRadius with LDAP dbx is your friend... But check to see that the ldap module actually built... unless you've got things

Freeradius and LDAP

2005-02-18 Thread E L
I'm new to LDAP and Freeradius. I'm trying to find out if there is a way to configure Freeradius to get information from the LDAP database and assign it to one of the radius atributes(like Framed-IP-Address and Framed-IP-Netmask) for a uids that have any of that information in the LDAP database

Re: Freeradius and LDAP

2005-02-18 Thread Dustin Doris
On Fri, 18 Feb 2005, E L wrote: I'm new to LDAP and Freeradius. I'm trying to find out if there is a way to configure Freeradius to get information from the LDAP database and assign it to one of the radius atributes(like Framed-IP-Address and Framed-IP-Netmask) for a uids that have any

Re: Freeradius and LDAP

2005-02-18 Thread Luis Daniel Lucio Quiroz
You may want to read http://www.linuxchange.com/opendocs/howto/authentication/radius/index.es.html however it's on spanish LD - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius and LDAP

2005-02-18 Thread E L
Thanks Dustin. I'll give a try. Thanks to Luis too, but unfortunately is don't speak Spanish. Cris _ Express yourself instantly with MSN Messenger! Download today it's FREE!

FreeRadius with LDAP

2005-01-04 Thread Anderson Alves de Albuquerque
Now, I am using Freeradius with LDAP. My system GNUGK make authentication in the FreeRadius, after Freeradius look in tne LDAP server. My authentication is Okay, but Free Radius need to send to GNUGK the ALIAS. This ALIAS is telephone Number E.164. In debug option in Freeraius with -X I

Re: FreeRadius + AD/LDAP + basedn

2004-10-07 Thread Kostas Kalevras
On Thu, 7 Oct 2004, Michael Benton wrote: Hello, FreeRadius 1.0.1 Linux RHES3.1 Does anyone know how to configure the FreeRadius server to to a LDAP query on a Win2003 AD server, and to look at the whole AD tree ? We have for some unknown reason, multiple OU's with users in each, rather

RE: freeradius+poptop+LDAP+Samba

2004-08-27 Thread John H.
Ok Thor, I got a different email address cuz myway stinks. How do I verify my version of ppp, the rpm from poptop's page, has radius plugin? __ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread Thor Spruyt
Because the radiusclient wasn't compiled in. Grrr. -- Regards, Thor Spruyt E: [EMAIL PROTECTED] W: www.thor-spruyt.com M: +32 (0)475 67 22 65 - Original Message - From: John H. To: [EMAIL PROTECTED] Sent: Friday, August 27, 2004 7:45 AM Subject: Re: freeradius+poptop+LDAP+Samba

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread Thor Spruyt
John H. wrote: Ok Thor, I got a different email address cuz myway stinks. Hey nice :) How do I verify my version of ppp, the rpm from poptop's page, has radius plugin? find / -name radiusclient -- Regards, Thor Spruyt E: [EMAIL PROTECTED] W: www.thor-spruyt.com M: +32 (0)475 67 22 65 -

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread John H.
radiusclient dir not found. I don't understand why, though, I used the ppp straight from poptop's website. --- Thor Spruyt [EMAIL PROTECTED] wrote: John H. wrote: Ok Thor, I got a different email address cuz myway stinks. Hey nice :) How do I verify my version of ppp, the rpm from

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread John H.
Spruyt E: [EMAIL PROTECTED] W: www.thor-spruyt.com M: +32 (0)475 67 22 65 - Original Message - From: John H. To: [EMAIL PROTECTED] Sent: Friday, August 27, 2004 7:45 AM Subject: Re: freeradius+poptop+LDAP+Samba And can you tell me why I have no radiusclient dir? --- On Fri 08/27

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread John H.
Subject: Re: freeradius+poptop+LDAP+Samba And can you tell me why I have no radiusclient dir? --- On Fri 08/27, Thor Spruyt [EMAIL PROTECTED] wrote: From: Thor Spruyt [mailto: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Date: Fri, 27 Aug 2004 07:37:35 +0200 Subject: Re

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread Thor Spruyt
John H. wrote: Ok, I had to go in the plugins dir and make it myself, but I now have installed /etc/radiusclient So the only question is, what differently do I do for this section... since radius is using ldap? I assume you figured out how to configure pppd for radius :) Just a suggestion:

Re: freeradius vs ldap, improper password handling

2004-08-27 Thread Alan DeKok
Adam KOSA [EMAIL PROTECTED] wrote: After studying the tcpdump log between my freeradius and ldap server i realized that freeradius is requesting the password from ldap to authenticate the user. (Turned off SSL to be able to sniff.) Yes. LDAP stores passwords, and FreeRADIUS uses passwords

freeradius+poptop+LDAP+Samba

2004-08-26 Thread John H.
Sorry, the poptop mailing list is completely worthless... Ok, fedora core 1 machine Samba PDC auth w/LDAP Installed poptop ppptp server, installed freeradius... Installed freeradius 1.0, configured freeradius with the following page... http://devel.linvision.com/doc/lih/v0.4/radius.html I

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread Thor Spruyt
John H. wrote: Sorry, the poptop mailing list is completely worthless... http://poptop.sourceforge.net/dox/radius_mysql.html The radius.so plugin uses the settings from radiusclient, so make sure: /etc/radiusclient/servers contains the secret for your radius server(s) Like: localhost

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread Lucas Oliveira
Subject: Re: freeradius+poptop+LDAP+Samba John H. wrote: Sorry, the poptop mailing list is completely worthless... http://poptop.sourceforge.net/dox/radius_mysql.html The radius.so plugin uses the settings from radiusclient, so make sure: /etc/radiusclient/servers contains the secret

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread John H.
TECTED] To: [EMAIL PROTECTED] Date: Thu, 26 Aug 2004 20:11:56 +0200 Subject: Re: freeradius+poptop+LDAP+Samba John H. wrote:> Sorry, the poptop mailing list is completely worthless...http://poptop.sourceforge.net/dox/radius_mysql.htmlThe radius.so plugin uses the settings from radiusclient, so make

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread John H.
put in users file for ppp? --- On Thu 08/26, Lucas Oliveira < [EMAIL PROTECTED] > wrote: From: Lucas Oliveira [mailto: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Date: Thu, 26 Aug 2004 17:03:27 -0300 Subject: Re: freeradius+poptop+LDAP+Samba I have a problem just like yours, when

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread John H.
AIL PROTECTED] > wrote: From: Thor Spruyt [mailto: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Date: Thu, 26 Aug 2004 20:11:56 +0200 Subject: Re: freeradius+poptop+LDAP+Samba John H. wrote:> Sorry, the poptop mailing list is completely worthless...http://poptop.sourceforge.net/dox/radius_mysq

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread Thor Spruyt
Lucas Oliveira wrote: i dont know what to do.. In order to be able to configure pppd for radius, pppd should first be compiled with the radius module of course. Maybe that's your problem. -- Regards, Thor Spruyt E: [EMAIL PROTECTED] W: www.thor-spruyt.com M: +32 (0)475 67 22 65 - List

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread Thor Spruyt
: +32 (0)475 67 22 65 - Original Message - From: John H. To: [EMAIL PROTECTED] ; [EMAIL PROTECTED] Sent: Thursday, August 26, 2004 10:48 PM Subject: Re: freeradius+poptop+LDAP+Samba ok, i don't think this is correct for my configuration. I do not want to use mysql, I want to use LDAP

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread John H.
TED] > wrote: From: Thor Spruyt [mailto: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Date: Fri, 27 Aug 2004 07:37:35 +0200 Subject: Re: freeradius+poptop+LDAP+Samba I did't give you a walkthrough for exactly what you want to do of course.You stated that the problem was setting up pppd to use

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread Thor Spruyt
(0)475 67 22 65 - Original Message - From: John H. To: [EMAIL PROTECTED] Sent: Friday, August 27, 2004 7:23 AM Subject: Re: freeradius+poptop+LDAP+Samba Ok, I am not using mysql, but ldap(radius auth's to ldap), I tried to follow the directions on this page(you are supposed to change

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread John H.
And can you tell me why I have no radiusclient dir? --- On Fri 08/27, Thor Spruyt < [EMAIL PROTECTED] > wrote: From: Thor Spruyt [mailto: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Date: Fri, 27 Aug 2004 07:37:35 +0200 Subject: Re: freeradius+poptop+LDAP+Samba I did't gi

Re: freeradius+poptop+LDAP+Samba

2004-08-26 Thread John H.
] To: [EMAIL PROTECTED] Date: Fri, 27 Aug 2004 07:44:04 +0200 Subject: Re: freeradius+poptop+LDAP+Samba In order to have pppd use radius, it should be compiled with the radiusbrmodule.brIf you don't have the radiusclient on your system, then probably the modulebrwasn't compiled (which is the default

Re: How to configure freeRadius for LDAP authentication

2004-07-22 Thread Kostas Kalevras
On Thu, 22 Jul 2004, Carlos Tinajero wrote: Hello everyone, I'd like to set up freeRadius to talk to an LDAP server to authenticate VPN users. Can someone point to a how-to LDAP configuration doc. I am not familiar with Radius, so I need an easy-to-follow doc. (Embedded image moved to

Re: Question about Freeradius and LDAP

2004-07-08 Thread Kostas Kalevras
On Wed, 7 Jul 2004, Arthur EBEL wrote: Hi everybody, My freeradius operate very well with an openldap directory All ldap users stored in my basedn=ou=people,ou=personnels,dc=utt,dc=fr can be authenticated. I would like to add another basedn=ou=students,ou=personnels,dc=utt,dc=fr BUT I

Question about Freeradius and LDAP

2004-07-07 Thread Arthur EBEL
Hi everybody, My freeradius operate very well with an openldap directory All ldap users stored in my basedn=ou=people,ou=personnels,dc=utt,dc=fr can be authenticated. I would like to add another basedn=ou=students,ou=personnels,dc=utt,dc=fr BUT I don't want to give an access to all my tree

Re: Question about Freeradius and LDAP

2004-07-07 Thread Alexander M. Pravking
On Wed, Jul 07, 2004 at 09:00:00PM +0200, Arthur EBEL wrote: Hi everybody, My freeradius operate very well with an openldap directory All ldap users stored in my basedn=ou=people,ou=personnels,dc=utt,dc=fr can be authenticated. I would like to add another

Re: Question about Freeradius and LDAP

2004-07-07 Thread Mike Sturdee
how about setting up 2 ldap modules? ldap people { ... } ldap students { ... } Not sure if this would do it, just a suggestion. On Wed, 7 Jul 2004, Alexander M. Pravking wrote: On Wed, Jul 07, 2004 at 09:00:00PM +0200, Arthur EBEL wrote: Hi everybody, My freeradius operate very

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-22 Thread Christophe Saillard
Here's what I've to put in the users file to make it work : DEFAULT Auth-Type := PAP, Freeradius-Proxied-To == 127.0.0.1 User-Name = `%{User-Name}`, Fall-Through = no But now PEAP/MSCHAPv2 doesn't work... If you had read the debug log, you would see

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-22 Thread Alan DeKok
Christophe Saillard [EMAIL PROTECTED] wrote: When I do not set Auth-Type TTLS/PAP works with users stored in the users files, PEAP/Ms-chap-v2 works with users from LDAP storage, but TTLS/PAP from LDAP doesn't work And the debug log would tell you why. The FAQ also mentions something

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-21 Thread Rok Papez
Hello Christophe. Christophe Saillard pravi: And you set Auth-Type = EAP. DON'T DO THAT. I do that ;). I prefer to manualy set EAP when user tries to identify as [EMAIL PROTECTED]. Users are *NOT* allowed to use any other authentication method :). For the moment I've a running freeradius

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-21 Thread Christophe Saillard
Hi, Now I've a working TTLS/PAP with LDAP storage configuration ;-) Here's what I've to put in the users file to make it work : DEFAULT Auth-Type := PAP, Freeradius-Proxied-To == 127.0.0.1 User-Name = `%{User-Name}`, Fall-Through = no But now PEAP/MSCHAPv2

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-21 Thread Michael Griego
Try something like this for your check line: DEFAULT Freeradius-Proxied-To == 127.0.0.1, EAP-Message !* , Auth-Type := PAP --Mike On Mon, 2004-06-21 at 06:59, Christophe Saillard wrote: Hi, Now I've a working TTLS/PAP with LDAP storage configuration ;-) Here's what I've to put

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-21 Thread Alan DeKok
Rok Papez [EMAIL PROTECTED] wrote: And you set Auth-Type = EAP. DON'T DO THAT. I do that ;). I prefer to manualy set EAP when user tries to identify as [EMAIL PROTECTED]. Users are *NOT* allowed to use any other authentication method :). That's about the only time you should set it.

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-21 Thread Alan DeKok
Christophe Saillard [EMAIL PROTECTED] wrote: Now I've a working TTLS/PAP with LDAP storage configuration ;-) Here's what I've to put in the users file to make it work : DEFAULT Auth-Type := PAP, Freeradius-Proxied-To == 127.0.0.1 User-Name = `%{User-Name}`,

Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-18 Thread Christophe Saillard
Hello, For the moment I use Freeradius with EAP-TTLS and it works fine...now I'd like to get users credentials form an existing LDAP database. The LDAP server sends me a valable MD5 hashed password but I think something failed in my users file configuration. Does someone have such a working

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-18 Thread Rok Papez
Hi Christophe. Christophe Saillard pravi: For the moment I use Freeradius with EAP-TTLS and it works fine...now I'd like to get users credentials form an existing LDAP database. The LDAP server sends me a valable MD5 hashed password but I think something failed in my users file configuration.

Re: Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-18 Thread Christophe Saillard
Thanks for your help. I think I'm not far from the end but I still have problems. Here's the debug logs : [...] Fri Jun 18 14:11:17 2004 : Debug: rlm_ldap: performing search in dc=u-strasbg,dc=fr, with filter (uid=csaillard) request 6 done Fri Jun 18 14:11:31 2004 : Debug: rlm_ldap: Added

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-18 Thread Alan DeKok
Christophe Saillard [EMAIL PROTECTED] wrote: For the moment I use Freeradius with EAP-TTLS and it works fine...now I'd like to get users credentials form an existing LDAP database. The LDAP server sends me a valable MD5 hashed password but I think something failed in my users file

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-18 Thread Alan DeKok
Christophe Saillard [EMAIL PROTECTED] wrote: Fri Jun 18 14:11:31 2004 : Debug: rad_check_password: Found Auth-Type EAP ... Fri Jun 18 14:11:31 2004 : Debug: rlm_eap: Request not found in the list Fri Jun 18 14:11:31 2004 : Error: rlm_eap: Either EAP-request timed out OR EAP-response to an

Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-18 Thread Christophe Saillard
And you set Auth-Type = EAP. DON'T DO THAT. The eap.conf file has BIG HUGE COMMENTS saying DON'T DO THAT. It really means DON'T DO THAT. You're doing the exact opposite of what the documentation says, and as a result, it's not working. You might try following the recommendations of the

Re: Using Freeradius with LDAP storage and EAP-TTLS authentication

2004-06-18 Thread Alan DeKok
Christophe Saillard [EMAIL PROTECTED] wrote: Now I'd like to get credentials from an existing LDAP user storage instead of the Freeradius users file That shouldn't be a problem. (I store MD5 hashed password to have PAP compatibility). That will make CHAP MS-CHAP not work. The Ldap

Re: Freeradius+PAM+LDAP

2004-05-28 Thread Alan DeKok
Bill Thompson [EMAIL PROTECTED] wrote: I actually have the system working, but with one show stopping problem. I am able to authenticate through PAM, but certain attributes such as FilterId, SessionTimeout, and IdleTimeout are not being passed from PAM to radius. Why would they *ever* be

Freeradius+PAM+LDAP

2004-05-27 Thread Bill Thompson
using Debian Stable, so the packages are not the most recent, and some I had to build: PAM 0.72 LDAP 3.0 Freeradius 0.9.1 Any Ideas? - -BillT -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFAtny0uLPldPuWZnARAjj9AKDq7XwJemhRKVuBX8S/aU2jK3qQYQCeLLn0 V6F+h4inJzd0PDNex1hcpIw

<    1   2   3