Ldap + freeradius... Again

2013-03-14 Thread fernando . sg1
*Lasts messages i make a lot of confusion and didnt sent to all group.* * * *now i've a problem, and this is making me crazy!* *i change the /module/LDAP and now i can authenticate using plaintext or when i use the passwordwith {crypt}* * * *but when i try to use {md5} this dont work!* *rad_recv:

Re: Ldap + freeradius... Again

2013-03-14 Thread Alan DeKok
fernando@gmail.com wrote: *now i've a problem, and this is making me crazy!* *i change the /module/LDAP and now i can authenticate using plaintext or when i use the passwordwith {crypt}* *but when i try to use {md5} this dont work!* You edited the configuration file and broke it.

Re: Ldap + freeradius... Again

2013-03-14 Thread fernando . sg1
sorry man, u didnt help. i tryed 1000 things and this actual configurations is the best i can make. why instead so be rude with me dont try to realy help me? like send me you default file or the orthers file to config? i dindt do anything without to fallow guides on internet. im trying to learn

Re: Ldap + freeradius... Again

2013-03-14 Thread Alan DeKok
fernando@gmail.com wrote: sorry man, u didnt help. I don't see why. i tryed 1000 things and this actual configurations is the best i can make. Nonsense. why instead so be rude with me dont try to realy help me? like send me you default file or the orthers file to config? Because

Re: Ldap + freeradius... Again

2013-03-14 Thread Arran Cudbard-Bell
On 14 Mar 2013, at 22:52, fernando@gmail.com wrote: Ok man, keep dont help too much, ill try again, the documentation dont helped before and i guess this will not help again... im keep saying dont need to be rude man, do you born everything? 2 months ago i never used a linux pc, now im

Re: Ldap + freeradius... Again

2013-03-14 Thread Alan DeKok
fernando@gmail.com wrote: Ok man, keep dont help too much, ill try again, the documentation dont helped before and i guess this will not help again... My suggestions work. Since you're not interested in following them, I don't know why you're on this list. im keep saying dont need to

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Alan Buxey
Please read the mailing list archives, this very question and setup is often mentioned alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Wassim Zaarour
Buxey a.l.m.bu...@lboro.ac.uk Date: Friday, April 20, 2012 9:30 AM To: Wassim Zaarour wassim.zaar...@navlink.com, freeradius-users@lists.freeradius.org freeradius-users@lists.freeradius.org Subject: Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails. Please read the mailing list archives, this very

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Fajar A. Nugraha
On Fri, Apr 20, 2012 at 2:09 PM, Wassim Zaarour wassim.zaar...@navlink.com wrote: Hi Alan, I went through the archives and did some changes but still getting the error, appreciate of you can help me a bit here. I think I read that the ldap request must be proxied to the inner tunnel for it

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Wassim Zaarour
On 4/20/12 10:15 AM, Fajar A. Nugraha l...@fajar.net wrote: On Fri, Apr 20, 2012 at 2:09 PM, Wassim Zaarour wassim.zaar...@navlink.com wrote: Hi Alan, I went through the archives and did some changes but still getting the error, appreciate of you can help me a bit here. I think I read

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Fajar A. Nugraha
On Fri, Apr 20, 2012 at 2:22 PM, Wassim Zaarour wassim.zaar...@navlink.com wrote: On 4/20/12 10:15 AM, Fajar A. Nugraha l...@fajar.net wrote: Long version: MSCHAPv2 (which also means PEAP-MSCHAPv2) needs either: - Cleartext-Password or NT-Hash available (in LDAP, sql, users file whatever), OR -

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Wassim Zaarour
Hi Farja, I just checked with the ldap admin and he told me passwords are stored with SHA encryption and not cleartext. ( can't change them to clear text) Does that means there is no way to make TTLS/PEAP/MSCHAPv2 work with it?? If I use TTLS/PAP from a Mac OS laptop, it works fine, but I'm

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Fajar A. Nugraha
On Fri, Apr 20, 2012 at 2:53 PM, Wassim Zaarour wassim.zaar...@navlink.com wrote: I just checked with the ldap admin and he told me passwords are stored with SHA encryption and not cleartext. ( can't change them to clear text) Figured as much :) Does that means there is no way to make

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Alan DeKok
Wassim Zaarour wrote: Hi Farja, I just checked with the ldap admin and he told me passwords are stored with SHA encryption and not cleartext. ( can't change them to clear text) Does that means there is no way to make TTLS/PEAP/MSCHAPv2 work with it?? If I use TTLS/PAP from a Mac OS

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread alan buxey
Hi, I just checked with the ldap admin and he told me passwords are stored with SHA encryption and not cleartext. ( can't change them to clear text) is this LDAP or AD? if its AD then you can bind your FreeRADIUS box to the AD as per docs on deployingradius.com - then it can use ntlm_auth to

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Wassim Zaarour
Thanks Alan for the link, I just ran to it few minutes back and its clear :) Guess I'm gonna have to settle for a third party supplicant since I can't change in the LDAP password storage config. Thanks also for the other Alan and Farja. On 4/20/12 11:15 AM, Alan DeKok

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-20 Thread Wassim Zaarour
It's Sun Directory Server, hence LDAP not AD. Thanks anyways :) On 4/20/12 11:18 AM, alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, I just checked with the ldap admin and he told me passwords are stored with SHA encryption and not cleartext. ( can't change them to clear text) is this

LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread Wassim Zaarour
Hi List, I have set up Freeadius 2.1.10 to authenticate with ldap. I have a cisco switch and using my Mac Laptop to connect. If I try to connect using ldap credentials the authentication fails, though the same credentials work if I use them with radtest on the localhost If I try to connect

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread Alan DeKok
Wassim Zaarour wrote: If I try to connect using ldap credentials the authentication fails, though the same credentials work if I use them with radtest on the localhost Read the debug output to see WHY the user is being rejected. This is documented in the FAQ, README, web pages, man page,

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread Wassim Zaarour
Thanks Alan, I have read what you mentioned, still can't figure it out, I guess the important part in the debug is: ERROR: No Authenticate method (Auth-Type) found for the request: Rejecting the user I configured the MAC OS TTLS/CHAP (earlier I tried TTLS/EAP and still it doesn't work) I

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread alan buxey
Hi, I have read what you mentioned, still can't figure it out, I guess the important part in the debug is: ERROR: No Authenticate method (Auth-Type) found for the request: Rejecting the user yes but we arent mind readers.the question will be 'why is no auth type found?' and the

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread Wassim Zaarour
On 4/19/12 3:31 PM, alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, I have read what you mentioned, still can't figure it out, I guess the important part in the debug is: ERROR: No Authenticate method (Auth-Type) found for the request: Rejecting the user yes but we arent mind

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread Alan DeKok
Wassim Zaarour wrote: Hi Alan, and thanks for your reply, I don't want to paste the output here coz its large, should I attach it or paste here anyways or?? You can follow instructions, or you can be unsubscribed and banned from the list. When we ask for the debug log TWICE, the response

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread Wassim Zaarour
On 4/19/12 4:18 PM, Alan DeKok al...@deployingradius.com wrote: Wassim Zaarour wrote: Hi Alan, and thanks for your reply, I don't want to paste the output here coz its large, should I attach it or paste here anyways or?? You can follow instructions, or you can be unsubscribed and banned

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread alan buxey
hi, quick look seems to show that you dont have a suitable authorise section in the inner tunnel. the tunnel gets started...your client rejects the default md5 the server sent - and EAP-TTLS gets done...the username/password gets sent but has nothing to go against so I suggest you add

Re: LDAP-FreeRadius-Cisco Switch-802.1x Fails.

2012-04-19 Thread Wassim Zaarour
Thanks Alan, it worked like a charm!! But it worked using TTLS/PAP, now Windows OS natively supports PEAP, and when I tried it with TTLS/PEAP it didn't authenticate and gave the following debug: I guess from the below what's important is this section . . . [eap] processing type mschapv2

RE: ldap+freeradius

2011-11-11 Thread suggestme
From: ml-node+s1045715n4979784...@n5.nabble.com To: samanaupadh...@hotmail.com Subject: Re: ldap+freeradius Hi, *Sorry for the confusion I made. I have put the name of LDAP server accordingly , not the localhost. Just for privacy I didn't put here.* okay Here is the output of radiusd

Re: ldap+freeradius

2011-11-11 Thread Alan Buxey
Hi, I configured FreeRadius for Authentication with Active Directory by following the steps as suggested by Alan's deployingradius.com. Everything is working successfully like Samba, Kerberos, ntlm_auth configuration, I can successfully join the domain as an administrator and also

Re: ldap+freeradius

2011-11-09 Thread suggestme
: http://freeradius.1045715.n5.nabble.com/ldap-freeradius-tp2781398p4978124.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap+freeradius

2011-11-09 Thread Alan DeKok
suggestme wrote: I searched throught the threads and found this thread exactly matching to my error I am getting. I am getting following error while debugging freeradius for using LDAP: /usr/local/etc/raddb/modules/ldap[29]: Failed to link to module 'rlm_ldap': file not found And the

Re: ldap+freeradius

2011-11-09 Thread suggestme
://freeradius.1045715.n5.nabble.com/ldap-freeradius-tp2781398p4978260.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap+freeradius

2011-11-09 Thread Alan DeKok
suggestme wrote: I tried the 3 steps that is suggested in FAQ, that isn't working. The steps in the FAQ assume that you built the server yourself from source. Did you? They also assume (step 1), that you read the output. That will tell you whether or not the required LDAP libraries and

Re: ldap+freeradius

2011-11-09 Thread suggestme
been made to users file adding LDAP user authentication. Thanks for the suggestions... -- View this message in context: http://freeradius.1045715.n5.nabble.com/ldap-freeradius-tp2781398p4978695.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info

Re: ldap+freeradius

2011-11-09 Thread John Dennis
On 11/09/2011 01:40 PM, suggestme wrote: The LDAP server was already configred in other machine by System Administrator. I am trying to link FreeRadius to that existing and already running LDAP server and authenticate the users using already configured attribute. I didn't download LDAP on this

Re: ldap+freeradius

2011-11-09 Thread suggestme
-tunnel[237]: Failed to load module ldap. /usr/local/etc/raddb/sites-enabled/inner-tunnel[237]: Failed to parse ldap entry. Thanks, -- View this message in context: http://freeradius.1045715.n5.nabble.com/ldap-freeradius-tp2781398p4978759.html Sent from the FreeRadius - User mailing list

Re: ldap+freeradius

2011-11-09 Thread Alan DeKok
suggestme wrote: *Sorry for the confusion I made. I have put the name of LDAP server accordingly , not the localhost. Just for privacy I didn't put here.* Here is the output of radiusd -X command: Which is the same error. Your problem is simple. We are trying to help you, and you are

Re: ldap+freeradius

2011-11-09 Thread Alan Buxey
Hi, *Sorry for the confusion I made. I have put the name of LDAP server accordingly , not the localhost. Just for privacy I didn't put here.* okay Here is the output of radiusd -X command: and there. bingo. libdir = /usr/local/lib/freeradius-2.1.10 urgh. why? really...why?

Re: ldap+freeradius

2011-11-09 Thread Alan DeKok
Alan DeKok wrote too quickly: But you need to posting the same question. If you do, you can be unsubscribed. You need to *stop* posting the same question. I think I might set up a bot to monitor the list. The same question 3 times from someone results in them being unsubscribed.

RE: ldap+freeradius

2011-11-09 Thread suggestme
suggestion where you were the one to give suggestion, I couldn't figure out how to solve that; and today I found this 'LDAP+Freeradius' thread with the same issue and posted here thinking I Might get quick response from the individual who already faced and solved this issue. My intention

Re: ldap+freeradius

2011-11-09 Thread Alan DeKok
Date: Wed, 9 Nov 2011 12:19:15 -0800 From: [hidden email] /user/SendEmail.jtp?type=nodenode=4979011i=0 To: [hidden email] /user/SendEmail.jtp?type=nodenode=4979011i=1 Subject: Re: ldap+freeradius Alan DeKok wrote too quickly: But you need to posting the same question

Re: multuple ldap freeradius ssid

2011-05-18 Thread seb2020
Switzerland -- View this message in context: http://freeradius.1045715.n5.nabble.com/Multiple-ldap-freeradius-ssid-tp4399529p4405854.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: multuple ldap freeradius ssid

2011-05-18 Thread Alexander Clouter
seb2020 girard@gmail.com wrote: I have test your solution like that : # defaults update reply { Tunnel-Type := VLAN Tunnel-Medium-Type := IEEE-802 Tunnel-Private-Group-Id := unauthorised Termination-Action := RADIUS-Request Session-Timeout := 300 Acct-Interim-Interval

multuple ldap freeradius ssid

2011-05-16 Thread seb2020
reply, and sorry for my english, I'm French ;) -- View this message in context: http://freeradius.1045715.n5.nabble.com/multuple-ldap-freeradius-ssid-tp4399529p4399529.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http

Re: multuple ldap freeradius ssid

2011-05-16 Thread Alexander Clouter
seb2020 girard@gmail.com wrote: I have a question. I already read how to make this, but I'm not sur if it works ! So, what do I want ? I have 2 SSID : students and an other staff. I want to have to ldap instance for authenticating my users. You really do *not* want to do this.

Re: multuple ldap freeradius ssid

2011-05-16 Thread seb2020
-tunel ? - From Switzerland -- View this message in context: http://freeradius.1045715.n5.nabble.com/Multiple-ldap-freeradius-ssid-tp4399529p4399886.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: multuple ldap freeradius ssid

2011-05-16 Thread seb2020
.1045715.n5.nabble.com/Multiple-ldap-freeradius-ssid-tp4399529p4399919.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: multuple ldap freeradius ssid

2011-05-16 Thread Alexander Clouter
seb2020 girard@gmail.com wrote: I will do what you say me ! I will make one SSID and check with the group my user with the OU of the user. My user is by example : user.group.locality.tree How I can retreive the numbers of letters in my loginname ? And this verification, I need to

Re: Request for opinion - central admin user server LDAP+FreeRADIUS

2009-08-15 Thread John Dennis
of them is huge (or impossible) work. So I thought a linux server LDAP+FreeRADIUS for authentication sounds quick, easy and good solution, or not? There is no problem with servers Linux and Windows servers can authenticate against radius. Most popular DB -s can do this also (Oracle, MySQL

Re: Request for opinion - central admin user server LDAP+FreeRADIUS

2009-08-10 Thread Peter Lambrechtsen
and all the devices are configured to authenticate users against this db. We have over 200 switches alone in our company so making user accounts in every single one of them and when this dude leaves to disable all of them is huge (or impossible) work. So I thought a linux server LDAP+FreeRADIUS

Re: Request for opinion - central admin user server LDAP+FreeRADIUS

2009-08-10 Thread Andres Kaaber
2009/8/10 Peter Lambrechtsen plambrecht...@gmail.com Have checked out Penrose from Safehaus. This Penrose looks really cool but it doesn't seem very active? Last update news is from 2007? and yes I'm into FOSS solutions :) Andres Kaaber - List info/subscribe/unsubscribe? See

Request for opinion - central admin user server LDAP+FreeRADIUS

2009-08-09 Thread Andres Kaaber
. So I thought a linux server LDAP+FreeRADIUS for authentication sounds quick, easy and good solution, or not? There is no problem with servers Linux and Windows servers can authenticate against radius. Most popular DB -s can do this also (Oracle, MySQL, PostgresSQL). I don't know about Cisco

Re: Request for opinion - central admin user server LDAP+FreeRADIUS

2009-08-09 Thread Padam J Singh
are configured to authenticate users against this db. We have over 200 switches alone in our company so making user accounts in every single one of them and when this dude leaves to disable all of them is huge (or impossible) work. So I thought a linux server LDAP+FreeRADIUS for authentication

Re: Request for opinion - central admin user server LDAP+FreeRADIUS

2009-08-09 Thread Stefan Winter
of them is huge (or impossible) work. So I thought a linux server LDAP+FreeRADIUS for authentication sounds quick, easy and good solution, or not? There is no problem with servers Linux and Windows servers can authenticate against radius. Most popular DB -s can do this also (Oracle, MySQL

Re: ldap+freeradius

2009-03-31 Thread David N'DAKPAZE
Please now i have a new problem; i use an Active Directory database and when i do a radtest, it is always access-reject like this: rad_recv: Access-Request packet from host 172.41.10.71 port 42678, id=153, length=61 User-Name = azerty5 User-Password = x

Re: ldap+freeradius

2009-03-31 Thread tnt
Please now i have a new problem; i use an Active Directory database and when i do a radtest, it is always access-reject like this: http://deployingradius.com/documents/configuration/active_directory.html Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

Re: ldap+freeradius

2009-03-30 Thread tnt
Please, I want to know which relation exist between /modules/ldap and rlm_ldap. What is the meaning of theses lines of the file /modules/ldap: #identity = cn=admin,o=My Org,c=UA #password = mypass basedn = o=My Org,c=UA filter = (uid=%{Stripped-User-Name:-%{User-Name}})

Re: ldap+freeradius

2009-03-30 Thread David N'DAKPAZE
I've configured Freeradius to use LDAP but when debug it I have This: Starting - reading configuration files ... including configuration file /usr/local/etc/raddb/radiusd.conf including configuration file /usr/local/etc/raddb/proxy.conf including configuration file

Re: ldap+freeradius

2009-03-30 Thread tnt
I've configured Freeradius to use LDAP but when debug it I have This: .. /usr/local/etc/raddb/modules/ldap[29]: Failed to link to module 'rlm_ldap': rlm_ ldap.so: cannot open shared object file: No such file or directory If you installed from the

Re: ldap+freeradius

2009-03-30 Thread David N'DAKPAZE
Please, I want to know which relation exist between /modules/ldap and rlm_ldap. What is the meaning of theses lines of the file /modules/ldap: #identity = cn=admin,o=My Org,c=UA #password = mypass basedn = o=My Org,c=UA filter = (uid=%{Stripped-User-Name:-%{User-Name}})

Re: ldap+freeradius

2009-03-30 Thread David N'DAKPAZE
please in the FAQ the error is about Mysql. I don't see what I must change in my configuration. 2009/3/30, t...@kalik.net t...@kalik.net: I've configured Freeradius to use LDAP but when debug it I have This: .. /usr/local/etc/raddb/modules/ldap[29]: Failed to link to module 'rlm_ldap': rlm_

Re: ldap+freeradius

2009-03-30 Thread tnt
please in the FAQ the error is about Mysql. Same applies to ldap. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap+freeradius

2009-03-30 Thread David N'DAKPAZE
I've done whath is said in the FAQ and now I have this problem: radiusd: Instantiating modules instantiate { /usr/local/etc/raddb/modules/exec[24]: Failed to link to module 'rlm_exec': rlm_exec.a: cannot open shared object file: No such file or directory Errors initializing modules

Re: ldap+freeradius

2009-03-30 Thread tnt
I've done whath is said in the FAQ and now I have this problem: radiusd: Instantiating modules instantiate { /usr/local/etc/raddb/modules/exec[24]: Failed to link to module 'rlm_exec': rlm_exec.a: cannot open shared object file: No such file or directory Errors initializing modules

Re: ldap+freeradius

2009-03-30 Thread David N'DAKPAZE
I am re-intalling freeradius and when I run make after ./configure --disable-shared I have this: ... /usr/bin/ld: attempted static link of dynamic object `/usr/lib/libltdl.so' collect2: ld returned 1 exit status rm -f .libs/radiusdS.o make[4]: *** [radiusd] Error 1 make[4]: Leaving directory

Re: ldap+freeradius

2009-03-30 Thread John Dennis
David N'DAKPAZE wrote: I am re-intalling freeradius and when I run make after ./configure --disable-shared I have this: Don't make matters worse by trying to defeat loadable modules. Go back and figure out why the loader can't find the modules. A good place to start is looking to see what

Re: ldap+freeradius

2009-03-25 Thread David N'DAKPAZE
please how must Iconfigure ldap for authentication? 2009/3/24 t...@kalik.net Please why crypt-passwords don't work in ths case? It has nothing to do with crypt. Password you have entered to log in and password that is stored in users file are not the same. Ivan Kalik Kalik Informatika

Re: ldap+freeradius

2009-03-25 Thread tnt
Read doc/rlm_ldap. Ivan Kalik Kalik Informatika ISP Dana 25/3/2009, David N'DAKPAZE lndakp...@gmail.com piše: please how must Iconfigure ldap for authentication? 2009/3/24 t...@kalik.net Please why crypt-passwords don't work in ths case? It has nothing to do with crypt. Password you

Re: ldap+freeradius

2009-03-25 Thread David N'DAKPAZE
I've read it but it is not very clear for me. 2009/3/25 t...@kalik.net Read doc/rlm_ldap. Ivan Kalik Kalik Informatika ISP Dana 25/3/2009, David N'DAKPAZE lndakp...@gmail.com piše: please how must Iconfigure ldap for authentication? 2009/3/24 t...@kalik.net Please why

Re: ldap+freeradius

2009-03-25 Thread David N'DAKPAZE
Me I have a database already (ldap) and i want to synchronize it with freeradius. 2009/3/25 David N'DAKPAZE lndakp...@gmail.com I've read it but it is not very clear for me. 2009/3/25 t...@kalik.net Read doc/rlm_ldap. Ivan Kalik Kalik Informatika ISP Dana 25/3/2009, David N'DAKPAZE

Re: ldap+freeradius

2009-03-25 Thread tnt
So what is unclear in the configuration file? Ivan Kalik Kalik Informatika ISP Dana 25/3/2009, David N'DAKPAZE lndakp...@gmail.com piše: Me I have a database already (ldap) and i want to synchronize it with freeradius. 2009/3/25 David N'DAKPAZE lndakp...@gmail.com I've read it but it is not

Re: ldap+freeradius

2009-03-25 Thread David N'DAKPAZE
It is the file i must configure or the ldap file which is in /raddb/modules/ldap 2009/3/25 t...@kalik.net So what is unclear in the configuration file? Ivan Kalik Kalik Informatika ISP Dana 25/3/2009, David N'DAKPAZE lndakp...@gmail.com piše: Me I have a database already (ldap) and i

Re: ldap+freeradius

2009-03-25 Thread tnt
It is the file i must configure or the ldap file which is in /raddb/modules/ldap raddb/modules/ldap is ldap module configuration file. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
Please it seems that ldap works only with pap.Is it true? tell me how to configure many clients (nas) in clients.conf 2009/3/23, Alan DeKok al...@deployingradius.com: David N'DAKPAZE wrote: Hello, Please I 'd to know how to use an ldap as a database of freeradius. I use

Re: ldap+freeradius

2009-03-24 Thread Michael Schwartzkopff
Am Dienstag, 24. März 2009 09:33:51 schrieb David N'DAKPAZE: Please it seems that ldap works only with pap.Is it true? tell me how to configure many clients (nas) in clients.conf Gamarjoobat, See the protocol and authentication server compatibility charts for more info.

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
My problem is that i have define 2 clients but radius works with only the first nas. please see the output of the radtest: Ignoring request to authentication address * port 1812 from unknown client 172.30.10.71 port 38509 Ready to process requests. Ignoring request to authentication address * port

Re: ldap+freeradius

2009-03-24 Thread Michael Schwartzkopff
Am Dienstag, 24. März 2009 10:50:58 schrieb David N'DAKPAZE: My problem is that i have define 2 clients but radius works with only the first nas. please see the output of the radtest: Ignoring request to authentication address * port 1812 from unknown client 172.30.10.71 port 38509 Ready to

Re: ldap+freeradius

2009-03-24 Thread tnt
Post your clients.conf and startup output of radiusd -X (before you send any requests). Ivan Kalik Kalik Informatika ISP Dana 24/3/2009, David N'DAKPAZE lndakp...@gmail.com piše: My problem is that i have define 2 clients but radius works with only the first nas. please see the output of the

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
I've put it in; the output of radiusd -X is: FreeRADIUS Version 2.1.3, for host i686-pc-linux-gnu, built on Mar 12 2009 at 17:24:19 Copyright (C) 1999-2008 The FreeRADIUS server project and contributors. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. You

Re: ldap+freeradius

2009-03-24 Thread tnt
I've put it in; the output of radiusd -X is: .. client GW-RADIUS { ipaddr = 172.30.3.121 require_message_authenticator = no secret = moov123 shortname = GW-RADIUS nastype = cisco } client 172.30.2.14 { ipaddr = 172.30.2.14

Re: ldap+freeradius

2009-03-24 Thread Michael Schwartzkopff
Am Dienstag, 24. März 2009 11:12:50 schrieb David N'DAKPAZE: client GW-RADIUS {         ipaddr = 172.30.3.121         require_message_authenticator = no         secret = moov123         shortname = GW-RADIUS         nastype = cisco  }  client 172.30.2.14 {         ipaddr = 172.30.2.14    

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
The server doesn't see it but i've put it; i don't it ignores it 2009/3/24 t...@kalik.net I've put it in; the output of radiusd -X is: .. client GW-RADIUS { ipaddr = 172.30.3.121 require_message_authenticator = no secret = moov123 shortname = GW-RADIUS

Re: ldap+freeradius

2009-03-24 Thread tnt
The server doesn't see it but i've put it; i don't it ignores it Put it where? In the clients.conf file listed in the debug? Or in some other clients.conf file server is not using! Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap+freeradius

2009-03-24 Thread tnt
I've add other clients in the client .conf but when i debug the server they don't appear in the output of radiusd -X. ii dont know why. Because that is not the file server is using. Read the debug - it lists which clients.conf file server is reading. Edit that one. Ivan Kalik Kalik Informatika

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
Excuse me, i know that it is that clients.conf the server is using because when i modify a client which appears in the debug output the server considers this changes and te debug output isn't the same 2009/3/24 t...@kalik.net I've add other clients in the client .conf but when i debug the

Re: ldap+freeradius

2009-03-24 Thread tnt
Post the debug *and* clients.conf. Mask the passwords this time. Ivan Kalik Kalik Informatika ISP Dana 24/3/2009, David N'DAKPAZE lndakp...@gmail.com piše: Excuse me, i know that it is that clients.conf the server is using because when i modify a client which appears in the debug output the

Re: ldap+freeradius

2009-03-24 Thread Michael Schwartzkopff
Am Dienstag, 24. März 2009 12:21:06 schrieb David N'DAKPAZE: I've add other clients in the client .conf but when i debug the server they don't appear in the output of radiusd -X. ii dont know why. radiusd knows the clients it displays during the debug output. Please recheck your setup WHERE

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
I've add other clients in the client .conf but when i debug the server they don't appear in the output of radiusd -X. ii dont know why. 2009/3/24 t...@kalik.net The server doesn't see it but i've put it; i don't it ignores it Put it where? In the clients.conf file listed in the debug? Or in

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
clients.conf: # -*- text -*- ## ## clients.conf -- client configuration directives ## ## $Id$ ### # # Define RADIUS clients (usually a NAS, Access Point, etc.). # # Defines a RADIUS client. # # '127.0.0.1' is another name

Re: ldap+freeradius

2009-03-24 Thread Laurent Besson
Le Tuesday 24 March 2009 12:33:40 David N'DAKPAZE, vous avez écrit : Excuse me, i know that it is that clients.conf the server is using because when i modify a client which appears in the debug output the server considers this changes and te debug output isn't the same 2009/3/24

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
yes. 2009/3/24 Laurent Besson l...@system-linux.net Le Tuesday 24 March 2009 12:33:40 David N'DAKPAZE, vous avez écrit : Excuse me, i know that it is that clients.conf the server is using because when i modify a client which appears in the debug output the server considers this changes

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
thank you, now it is ok 2009/3/24 David N'DAKPAZE lndakp...@gmail.com yes. 2009/3/24 Laurent Besson l...@system-linux.net Le Tuesday 24 March 2009 12:33:40 David N'DAKPAZE, vous avez écrit : Excuse me, i know that it is that clients.conf the server is using because when i modify a

Re: ldap+freeradius

2009-03-24 Thread tnt
Client RADIUS { .. That should be: client RADIUS { .. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: ldap+freeradius

2009-03-24 Thread Michael Schwartzkopff
Am Dienstag, 24. März 2009 12:51:31 schrieb David N'DAKPAZE: clients.conf: Client RADIUS { ipaddr= 172.30.1.10 # # secret and password are mapped through the secrets file. secret= xx shortname = RADIUS # # the following three fields are

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
I want to use crypt -passwords (pap) but Idon't know where to define it. Only cleartext-passwords are accepted. Can somebody help me 2009/3/24 t...@kalik.net Client RADIUS { .. That should be: client RADIUS { .. Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe?

Re: ldap+freeradius

2009-03-24 Thread Nicolas Goutte
Am 24.03.2009 um 18:00 schrieb David N'DAKPAZE: I want to use crypt -passwords (pap) but Idon't know where to define it. Only cleartext-passwords are accepted. Can somebody help me PAP needs cleartext passwords (see http://en.wikipedia.org/wiki/ Password_authentication_protocol ) Have a

Re: ldap+freeradius

2009-03-24 Thread tnt
I want to use crypt -passwords (pap) but Idon't know where to define it. Only cleartext-passwords are accepted. Can somebody help me For cypted passwords use attribute Crypt-Password: Crypt-Password := ... Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
Please which protocol more secure can i use with ldap as database? 2009/3/24 Nicolas Goutte nicolas.gou...@extragroup.de Am 24.03.2009 um 18:00 schrieb David N'DAKPAZE: I want to use crypt -passwords (pap) but Idon't know where to define it. Only cleartext-passwords are accepted. Can

Re: ldap+freeradius

2009-03-24 Thread Nicolas Goutte
Forget what I have written, see http://deployingradius.com/documents/ protocols/compatibility.html Am 24.03.2009 um 18:05 schrieb Nicolas Goutte: Am 24.03.2009 um 18:00 schrieb David N'DAKPAZE: I want to use crypt -passwords (pap) but Idon't know where to define it. Only

Re: ldap+freeradius

2009-03-24 Thread David N'DAKPAZE
I've use it but the authentication have failed SRV-RADIUS:/var/log# radtest steve testing localhost 1812 x Sending Access-Request of id 151 to 127.0.0.1 port 1812 User-Name = steve User-Password = x NAS-IP-Address = 172.30.10.71 NAS-Port = 1812 rad_recv:

Re: ldap+freeradius

2009-03-24 Thread Nicolas Goutte
Am 24.03.2009 um 18:15 schrieb David N'DAKPAZE: Please which protocol more secure can i use with ldap as database? As I wrote in the email as answer to my email (and an URL I missed to find the whole day as answer to your problems), see http://

  1   2   >