Problem with CISCO WIRELESS CONTROLLER and RADIUS Authentication

2013-07-04 Thread Gustavo Vieira Oliveira
Hello! We have a Cisco Wireless Controller 5508 with Aironet 1041 APs. To make the AP authenticate with RADIUS we need to set the following command manually in the AP: - radius-server vsa send Which as explained by cisco does the following: Command Purpose Router(config)#

Re: Problem with CISCO WIRELESS CONTROLLER and RADIUS Authentication

2013-07-04 Thread Alan DeKok
is issued in the AP by cli If FreeRADIUS sends an Access-Accept, and the user isn't allowed on the network... blame the AP. Read the vendor's AP documentation to see what it needs in an Access-Accept. And I highly doubt that this flag is required for RADIUS authentication to work. Many other

Re: Problem with CISCO WIRELESS CONTROLLER and RADIUS Authentication

2013-07-04 Thread Arran Cudbard-Bell
On 4 Jul 2013, at 13:12, Gustavo Vieira Oliveira gusta...@sc.senai.br wrote: Hello! We have a Cisco Wireless Controller 5508 with Aironet 1041 APs. To make the AP authenticate with RADIUS we need to set the following command manually in the AP: - radius-server vsa send Which as

Re: Problem with CISCO WIRELESS CONTROLLER and RADIUS Authentication

2013-07-04 Thread Matthew Newton
Hi, This isn't a FreeRADIUS issue, and shouldn't really be on this list. However - On Thu, Jul 04, 2013 at 09:12:40AM -0300, Gustavo Vieira Oliveira wrote: We have a Cisco Wireless Controller 5508 with Aironet 1041 APs. We have the same, authenticating against FreeRADIUS. To make the AP

Re: Problem with CISCO WIRELESS CONTROLLER and RADIUS Authentication

2013-07-04 Thread Gustavo Vieira Oliveira
Yeah, i'm not saying it's a problem with RADIUS. I'm just asking trying to understand why it's happening and if there may be any workaround for this. Matthew, we have some remote places that we chose to authenticate locally with Radius. I'm guessing the configuration (radius-server vsa

Re: Problem with CISCO WIRELESS CONTROLLER and RADIUS Authentication

2013-07-04 Thread Alan Buxey
Those are VSA that you are getting from the NAS. You're WiFi kit is centrally managed so config is pushed from the controller alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RADIUS authentication using MS-CHAP - no cleartext password configured error

2013-02-06 Thread Deepti kulkarni
I have a windows client trying to set up L2TP tunnel with my linux router. The linux router talks with the RADIUS server. The authentication is failing because the request is using MS-CHAP and my server cannot handle MS-CHAP. I am not sure what is missing from the configuration on the server. I

Re: RADIUS authentication using MS-CHAP - no cleartext password configured error

2013-02-06 Thread Alan DeKok
Deepti kulkarni wrote: I have a windows client trying to set up L2TP tunnel with my linux router. The linux router talks with the RADIUS server. The authentication is failing because the request is using MS-CHAP and my server cannot handle MS-CHAP. I am not sure what is missing from the

dalo(free)radius authentication problem

2012-07-11 Thread Soul -
Dear ALL i was follow the guide from the following page with the command, but when testing, the Radius server is not responding. For the setup on the Ubuntu newest server.. -sudo apt-get update -sudo apt-get upgrade -sudo apt-get install mysql-server

RE: dalo(free)radius authentication problem

2012-07-11 Thread Michael Hartwick
[mailto:freeradius-users-bounces+hartwick=hartwick.com@lists.freeradiu s.org] On Behalf Of Soul - Sent: Wednesday, July 11, 2012 04:17 To: freeradius-users@lists.freeradius.org Subject: dalo(free)radius authentication problem Dear ALL i was follow the guide from the following page with the command, but when

How to configure Solaris 10 Radius Authentication client.

2012-06-04 Thread Alek Barsky
Hi Guys, I need to configure bunch of Solaris servers to use RADIUS PAM for Authentication/Authorization. I followed instructions in http://freeradius.org/pam_radius_auth/ and was able to configure Authentication portion of this task. There is one problem - the only way I can receive login

Re: How to configure Solaris 10 Radius Authentication client.

2012-06-04 Thread Alan DeKok
Alek Barsky wrote: There is one problem – the only way I can receive login shell on this box – if user already exists. That's how PAM works. It makes PAM rather a lot less useful. But that's PAM for you. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: How to configure Solaris 10 Radius Authentication client.

2012-06-04 Thread Michael Hocke
-BEGIN PGP SIGNED MESSAGE- On Jun 4, 2012, at 2:06 PM, Alek Barsky wrote: I need to configure bunch of Solaris servers to use RADIUS PAM for Authentication/Authorization. PAM only does authentication. After all, it stands for Pluggable Authentication Modules. I followed

Re: Radius authentication against LDAP question

2012-06-01 Thread g17jimmy
: 5de42704-ab1d-11e1-8e07-525400579da7 member: uid=newuser,cn=users,cn=accounts,dc=abc,dc=xyz -- View this message in context: http://freeradius.1045715.n5.nabble.com/Radius-authentication-against-LDAP-question-tp5713463p5713503.html Sent from the FreeRadius - User mailing list archive at Nabble.com

Re: Radius authentication against LDAP question

2012-06-01 Thread Alan DeKok
g17jimmy wrote: One question relating to this is about the /etc/raddb/users file- It doesn't seem to work as it's documented, Well... no. If I have a group set to be rejected based on its membership like this: DEFAULT Group=disabled, Auth-Type:=Reject radius doesn't even check for

Re: Radius authentication against LDAP question

2012-06-01 Thread g17jimmy
Cool, thanks for pointing that out. My brain filtered out the '==', been staring at this screen too long. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Radius-authentication-against-LDAP-question-tp5713463p5713505.html Sent from the FreeRadius - User mailing list

Radius authentication against LDAP question

2012-05-31 Thread Jimmy
How do I enable Freeradius to not only authenticate the a user but verify a specific attribute for the user? I've been going though the docs but this is escaping me. Thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Radius authentication against LDAP question

2012-05-31 Thread Nick Owen
In Thu, May 31, 2012 at 10:05 AM, Jimmy g17ji...@gmail.com wrote: How do I enable Freeradius to not only authenticate the a user but verify a specific attribute for the user? I've been going though the docs but this is escaping me. Thanks. - I'm not sure if this will help, but i have

Re: Radius authentication against LDAP question

2012-05-31 Thread g17jimmy
-- View this message in context: http://freeradius.1045715.n5.nabble.com/Radius-authentication-against-LDAP-question-tp5713463p5713481.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Radius authentication against LDAP question

2012-05-31 Thread g17jimmy
=xyz # search result search: 2 result: 0 Success # numResponses: 2 # numEntries: 1 Any ideas? Thanks. -- View this message in context: http://freeradius.1045715.n5.nabble.com/Radius-authentication-against-LDAP-question-tp5713463p5713483.html Sent from the FreeRadius - User mailing

RE: Free radius authentication with AD using ldap

2011-11-28 Thread Vikash Gounder
...@lists.freeradius.org] On Behalf Of Fajar A. Nugraha Sent: Monday, 28 November 2011 4:44 PM To: FreeRadius users mailing list Subject: Re: Free radius authentication with AD using ldap On Mon, Nov 28, 2011 at 12:29 PM, Vikashgounder vikash.goun...@acu.edu.au wrote: From the local radtest I can

Re: Free radius authentication with AD using ldap

2011-11-28 Thread Fajar A. Nugraha
On Tue, Nov 29, 2011 at 4:03 AM, Vikash Gounder vikash.goun...@acu.edu.au wrote: Hi Fajar, Thanks so much for replying. The debug log for local test against AD is attached: Listening on authentication address * port 1812 Listening on accounting address * port 1813 Listening on command

Re: Free radius authentication with AD using ldap

2011-11-28 Thread Vikash Gounder
So in this case what changes do I need to make in order for it to work. Sorry am bit lost right now. Thanks and appreciate it. Sent from my iPhone On 29/11/2011, at 10:22 AM, Fajar A. Nugraha l...@fajar.net wrote: On Tue, Nov 29, 2011 at 4:03 AM, Vikash Gounder vikash.goun...@acu.edu.au

Re: Free radius authentication with AD using ldap

2011-11-28 Thread Fajar A. Nugraha
On Tue, Nov 29, 2011 at 6:29 AM, Vikash Gounder vikash.goun...@acu.edu.au wrote: So in this case what changes do I need to make in order for it to work. Sorry am bit lost right now. http://deployingradius.com/documents/configuration/active_directory.html -- Fajar - List

Free radius authentication with active directory using leap module

2011-11-27 Thread Vikash Gounder
Hi, Would greatly someone's help on this. I need free radius to authenticate with using wpa. From the local radtest I can see, it is authenticating fine but when testing with a wpa device, this is the error m getting on the debug log: I just need it to work from wireless device, I think it is

Re: Free radius authentication with AD using ldap

2011-11-27 Thread Fajar A. Nugraha
On Mon, Nov 28, 2011 at 12:29 PM, Vikashgounder vikash.goun...@acu.edu.au wrote: From the local radtest I can see, it is authenticating fine but when testing ... and where is the debug log for that? with a wpa device, this is the error m getting on the debug log: It's quite informative,

radius authentication fallback from ldap to local

2011-05-07 Thread Chowdhury Satish-NVF476
Hi, I am trying to configure fallback of radius server form ldap to local file based authentication when the ldap server is not reachable. I have a wireless client which needs to be authenticated by the radius server on association. The wireless client uses EAP-PEAP authentication and

RE: radius authentication fallback from ldap to local

2011-05-07 Thread Chowdhury Satish-NVF476
Of Chowdhury Satish-NVF476 Sent: Saturday, May 07, 2011 12:51 PM To: freeradius-users@lists.freeradius.org Subject: radius authentication fallback from ldap to local Hi, I am trying to configure fallback of radius server form ldap to local file based authentication when the ldap server

Re: radius authentication fallback from ldap to local

2011-05-07 Thread Fajar A. Nugraha
On Sat, May 7, 2011 at 7:17 PM, Chowdhury Satish-NVF476 satish.chowdh...@motorolasolutions.com wrote: Hi, Got it resolved with following configuration Glad to hear it, thanks for sharing the solution. radiusd.conf authorize {         ldap {                  fail = 1      

Re: radius authentication support for telnet server.

2011-02-07 Thread vijay s sheelavantar
Thank you very very much Mr.Fajar. After making changes in /etc/pam.d/login it's working. authentication request is coming to freeradius server and authentication is successful. :) Thanks amp; Regards,Vijay S.- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

radius authentication support for telnet server.

2011-02-07 Thread vijay s sheelavantar
Thank you very very much Mr.Fajar. After making changes in /etc/pam.d/login it's working. authentication request is coming to freeradius server and authentication is successful. :)I need one more help, Please let me know the configuration file for FTP alo. i have crated a wu-ftpd file inside

Re: radius authentication support for telnet server.

2011-02-07 Thread Fajar A. Nugraha
On Mon, Feb 7, 2011 at 3:23 PM, vijay s sheelavantar s_vija...@rediffmail.com wrote: Thank you very very much Mr.Fajar. After making changes in /etc/pam.d/login it's working. authentication request is coming to freeradius server and authentication is successful. :) I need one more help,

radius authentication support for telnet server.

2011-02-06 Thread vijay s sheelavantar
Hello Friends,I want to authenticate telnet users using Free Radius server.nbsp;I have pam_radius_auth.so and configured it for ssh which is working fine.nbsp;For telnet alsonbsp;I have created a file /etc/pam.d/telnet nbsp;and trying to authenticate using freeRadius server. But it is not

Re: radius authentication support for telnet server.

2011-02-06 Thread Fajar A. Nugraha
On Sun, Feb 6, 2011 at 5:10 PM, vijay s sheelavantar s_vija...@rediffmail.com wrote: Hello Friends, I want to authenticate telnet users using Free Radius server. I have pam_radius_auth.so and configured it for ssh which is working fine. For telnet also I have created a file /etc/pam.d/telnet

Re: radius authentication support for telnet server.

2011-02-06 Thread vijay s sheelavantar
Hi Friends, I am trying to authenticate telnet users using free radius. on my system telnet is running as follows.ps -ef | grep xinetdroot 22737 1 0 10:52 ? 00:00:00 /usr/sbin/xinetd -reuseroot 22864 18178 0 10:57 pts/1 00:00:00 grep xinetd I have tried by creating telnet, xinetd

Re: radius authentication support for telnet server.

2011-02-06 Thread Fajar A. Nugraha
On Mon, Feb 7, 2011 at 8:54 AM, vijay s sheelavantar s_vija...@rediffmail.com wrote: I have tried by creating telnet, xinetd files in /etc/pam.d/ folder. I have included auth sufficient pam_radius_auth.so debug in these files. I have added this line to /etc/pam.d/other file also. I don't have

Re: Radius authentication problem.

2011-01-27 Thread Alan Buxey
Hi, vijay    Auth-Type := Local, Cleartext-Password == 123qwe, 1 ^ 2 1 is wrong. you dont need it. 2 is wrong, operator should be := , not == Above mentioned is my configuration. when i try to connect client with SSH it is not

Radius authentication problem.

2011-01-26 Thread vijay s sheelavantar
Hello Friends,I have intalled RADIUS server on one machine which has fedora 10. I have installed freeradius-server-2.1.10 on it(server machine IP 10.150.110.42). I have one more machine with redhat linux on which i have installed pam_radius-1.3.17(client machine IP 10.150.113.4). I have done

RE: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread Maurice James
@lists.freeradius.org] On Behalf Of John Dennis Sent: Wednesday, October 27, 2010 8:54 PM To: FreeRadius users mailing list Subject: Re: Wireless WPA2 enterprise Radius authentication On 10/27/2010 07:56 PM, Maurice James wrote: I will give it another try. I've been trying to the last hour to get the clear text

Re: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread Phil Mayers
On 28/10/10 11:48, Maurice James wrote: OK here are the logs from the latest test. As you will see the password is stored in cleartext, but still no dice The ldap module isn't running at all in the inner-tunnel virtual server AFACIT. You need to enable ldap in

Re: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread Sven Hartge
Phil Mayers p.may...@imperial.ac.uk wrote: On 28/10/10 11:48, Maurice James wrote: OK here are the logs from the latest test. As you will see the password is stored in cleartext, but still no dice The ldap module isn't running at all in the inner-tunnel virtual server AFACIT. You need to

Re: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread Phil Mayers
On 28/10/10 12:34, Sven Hartge wrote: Phil Mayersp.may...@imperial.ac.uk wrote: On 28/10/10 11:48, Maurice James wrote: OK here are the logs from the latest test. As you will see the password is stored in cleartext, but still no dice The ldap module isn't running at all in the

RE: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread Maurice James
-users@lists.freeradius.org Subject: Re: Wireless WPA2 enterprise Radius authentication Phil Mayers p.may...@imperial.ac.uk wrote: On 28/10/10 11:48, Maurice James wrote: OK here are the logs from the latest test. As you will see the password is stored in cleartext, but still no dice The ldap

Re: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread Sven Hartge
Phil Mayers p.may...@imperial.ac.uk wrote: On 28/10/10 12:34, Sven Hartge wrote: Phil Mayersp.may...@imperial.ac.uk wrote: On 28/10/10 11:48, Maurice James wrote: OK here are the logs from the latest test. As you will see the password is stored in cleartext, but still no dice The ldap

RE: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread Maurice James
[mailto:freeradius-users-bounces+midnightsteel=msn@lists.freeradius.org] On Behalf Of John Dennis Sent: Wednesday, October 27, 2010 8:54 PM To: FreeRadius users mailing list Subject: Re: Wireless WPA2 enterprise Radius authentication On 10/27/2010 07:56 PM, Maurice James wrote: I will give it another try. I've

RE: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread Maurice James
+midnightsteel=msn@lists.freeradius.org [mailto:freeradius-users-bounces+midnightsteel=msn@lists.freeradius.org] On Behalf Of Maurice James Sent: Thursday, October 28, 2010 4:37 PM To: 'FreeRadius users mailing list' Subject: RE: Wireless WPA2 enterprise Radius authentication OK gentlemen

Re: Wireless WPA2 enterprise Radius authentication

2010-10-28 Thread balaram velega
Radius authentication OK gentlemen, After many sleepless nights I finally got it working. I was almost in tears (lol) but its done. Full authentication and authorization for a mix of Windows7 x64/Vista x64 clients using WPA2 Enterprise, Freeradius, 389-DS(Fedora Directory Services). I

RE: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread Maurice James
] On Behalf Of Phil Mayers Sent: Tuesday, October 26, 2010 12:13 PM To: freeradius-users@lists.freeradius.org Subject: Re: Wireless WPA2 enterprise Radius authentication On 26/10/10 13:10, midnightsteel wrote: I'm running freeradius 2.1.9-1. I will run the debug test when I get home later

Re: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread Sven Hartge
Maurice James midnightst...@msn.com wrote: [ldap] looking for check items in directory... [ldap] userpassword - User-Password == {SSHA}5wzxRoUPX/rLkS9hY1HztczPN8u5m/dGDzKvdg== This will not work. You need a cleartext password. This SSHA-Hash is only good for PAP, any challenge response

RE: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread Maurice James
Hartge Sent: Wednesday, October 27, 2010 3:47 PM To: freeradius-users@lists.freeradius.org Subject: Re: Wireless WPA2 enterprise Radius authentication Maurice James midnightst...@msn.com wrote: [ldap] looking for check items in directory... [ldap] userpassword - User-Password == {SSHA

Re: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread John Dennis
On 10/27/2010 06:18 PM, Maurice James wrote: How do I do it? You were kindly given the answer previously by Maurice. But just to reinforce please review the compatibility information here: http://deployingradius.com/documents/protocols/compatibility.html The client is sending mschap, look

Re: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread Sven Hartge
Maurice James midnightst...@msn.com wrote: How do I do it? You need a password in the clear in your LDAP directory, not hashed. I use a different (self defined) attribute in my LDAP directory to do this and use ldap.attrmap to map this attribute (called gifb-NetzPassword in my schema) to the

Re: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread John Dennis
On 10/27/2010 07:11 PM, Sven Hartge wrote: You need a password in the clear in your LDAP directory, not hashed. I use a different (self defined) attribute in my LDAP directory to do this and use ldap.attrmap to map this attribute (called gifb-NetzPassword in my schema) to the required

RE: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread Maurice James
Of John Dennis Sent: Wednesday, October 27, 2010 7:44 PM To: FreeRadius users mailing list Cc: Sven Hartge Subject: Re: Wireless WPA2 enterprise Radius authentication On 10/27/2010 07:11 PM, Sven Hartge wrote: You need a password in the clear in your LDAP directory, not hashed. I use

Re: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread Sven Hartge
John Dennis jden...@redhat.com wrote: On 10/27/2010 07:11 PM, Sven Hartge wrote: You need a password in the clear in your LDAP directory, not hashed. I use a different (self defined) attribute in my LDAP directory to do this and use ldap.attrmap to map this attribute (called gifb-NetzPassword

Re: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread Sven Hartge
Sven Hartge s...@svenhartge.de wrote: slapcat (and a simple base64 decoder) is your friend. If you are using OpenLDAP or one of its derivate implementations, of course. Grüße, S° -- Sig lost. Core dumped. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread John Dennis
On 10/27/2010 07:56 PM, Maurice James wrote: I will give it another try. I've been trying to the last hour to get the clear text password policy to stick to a user. Every time I run the radius debug I see hashed value passed from LDAP. I have to search online for the instructions on how to get

RE: Wireless WPA2 enterprise Radius authentication

2010-10-27 Thread Maurice James
=msn@lists.freeradius.org] On Behalf Of John Dennis Sent: Wednesday, October 27, 2010 8:54 PM To: FreeRadius users mailing list Subject: Re: Wireless WPA2 enterprise Radius authentication On 10/27/2010 07:56 PM, Maurice James wrote: I will give it another try. I've been trying to the last hour

Re: Wireless WPA2 enterprise Radius authentication

2010-10-26 Thread Phil Mayers
On 10/26/2010 03:59 AM, midnightsteel wrote: Has anyone gotten Freeradius 2.x and LDAP (OpenLDAP, FDS, etc...) to properly authenticate users? I get the following in my radius log Auth: Login incorrect: [wii/via Auth-Type = EAP] (from client access port 0 via TLS tunnel) Auth: Login

RE: Wireless WPA2 enterprise Radius authentication

2010-10-26 Thread midnightsteel
To: midnightsteel Subject: Re: Wireless WPA2 enterprise Radius authentication On 10/26/2010 03:59 AM, midnightsteel wrote: Has anyone gotten Freeradius 2.x and LDAP (OpenLDAP, FDS, etc...) to properly authenticate users? I get the following in my radius log Auth: Login incorrect: [wii/via Auth

RE: Wireless WPA2 enterprise Radius authentication

2010-10-26 Thread Maurice James
@lists.freeradius.org] On Behalf Of Phil Mayers Sent: Tuesday, October 26, 2010 4:33 AM To: freeradius-users@lists.freeradius.org Subject: Re: Wireless WPA2 enterprise Radius authentication On 10/26/2010 03:59 AM, midnightsteel wrote: Has anyone gotten Freeradius 2.x and LDAP (OpenLDAP, FDS, etc

Re: Wireless WPA2 enterprise Radius authentication

2010-10-26 Thread Phil Mayers
On 26/10/10 13:10, midnightsteel wrote: I’m running freeradius 2.1.9-1. I will run the debug test when I get home later The funny thing is, it could be just 1 small setting that I missed. This is a pain. I have a Windows Vista/7 clients connecting to a cisco e3000 wireless router (WPA2

Wireless WPA2 enterprise Radius authentication

2010-10-25 Thread midnightsteel
about my configs. Access point using WPA2-Enterprise Freeradius 2.x 389-DS(Fedora LDAP) -- View this message in context: http://freeradius.1045715.n5.nabble.com/Wireless-WPA2-enterprise-Radius-authentication-tp3236494p3236494.html Sent from the FreeRadius - User mailing list archive

Radius Authentication failure

2009-07-21 Thread Vamsi Krishna Valiveti
Hi, I am using freeradius-server-2.1.4. I changed only the below files Users iss Auth-Type := Local, User-Password == iss123 Clients.conf client 13.0.0.5 { secret = AricentRadius shortname = fs nastype = other With the above changes I am getting error marked RED . Please help

Re: Radius Authentication failure

2009-07-21 Thread Nicolas Goutte
Am 21.07.2009 um 11:04 schrieb Vamsi Krishna Valiveti: Hi, I am using freeradius-server-2.1.4. I changed only the below files Users iss Auth-Type := Local, User-Password == iss123 Try to use Cleartext-Password := iss123 Passwords must be assigned ( := ) not compared ( == ). Also

Re: Radius Authentication failure

2009-07-21 Thread A . L . M . Buxey
Hi, I am using freeradius-server-2.1.4. I changed only the below files Users iss Auth-Type := Local, User-Password == iss123 dont set Auth-Type and change the Password entry. should be iss Cleartext-Password := iss123 alan - List info/subscribe/unsubscribe? See

Re: PAM-Radius authentication issue on Ubuntu 7.4: can not authenticate SSH users not present in /etc/passwd

2009-03-24 Thread Alan DeKok
Hu, Fengliang (Procurve Networking) wrote: I did some research from the website and some emails dated in 2006 said that PAM_Radius can only authenticate user accounts in /etc/passwd file. Is that right? Yes. There is no documented way in PAM to get UID/GID/etc from the PAM module (e.g.

PAM-Radius authentication issue on Ubuntu 7.4: can not authenticate SSH users not present in /etc/passwd

2009-03-19 Thread Hu, Fengliang (Procurve Networking)
Hi, I was trying to find a PAM-Radius mailing list and it seems that this is the best one. A Ubuntu 7.4 box needs to be configured such that SSH users will be authenticated against an external FreeRadius server. FreeRadius server version is 1.1.7-1build4. The Ubuntu box uses OpenSSH 4.3-p2

Radius authentication

2008-03-27 Thread Charnjit Sidhu
, as recommended by the developers, however they have not used radius authentication before. #!/usr/bin/perl use Authen::Radius; my $username = shift; my $password = shift; my $r = new Authen::Radius(Host = 'myserver', Secret = 'mysecret'); my $result = $r-check_pwd($username, $password); exit ($result

Re: Radius authentication

2008-03-27 Thread A . L . M . Buxey
Hi, I recieve an error in my log file of a missing Authen/Radius.pm file. I think this is a radius client perl module, does any one know where I can download this from, or wether there is a better solution, or I am doing somethin wrong, I am new to all this Radius authentication. as per

RE: Radius authentication

2008-03-27 Thread Charnjit Sidhu
server and secret anywhere else in the perl module? (never used perl module before). Charnjit From: [EMAIL PROTECTED] on behalf of [EMAIL PROTECTED] Sent: Thu 3/27/2008 9:55 AM To: FreeRadius users mailing list Subject: Re: Radius authentication Hi, I

Re: Radius authentication

2008-03-27 Thread A . L . M . Buxey
Hi, use Authen::Radius; my $username = shift; my $password = shift; my $r = new Authen::Radius(Host = 'myserver', Secret = 'mysecret'); my $result = $r-check_pwd($username, $password); exit ($result == 1) ? 0 : 1; I thought this should pass all the relevant radius parametres to

Re: Radius authentication

2008-03-27 Thread Alan DeKok
Charnjit Sidhu wrote: Have downloaded and installed Authen:: Radius module from cpan without any problems, I know get no errors in my log files but it still does not authenticate, I already have a auth_radius.pl script which is run to authenticate which looks like this: Sorry, but this

ldap+radius authentication problem

2008-03-25 Thread amir shrestha
Dear all, I have configured freeradius with ldap backed as given in http://freeradius.org/radiusd/doc/ldap_howto.txt. The user get authorized but the authentication failed. The detail output is here: Ready to process requests. rad_recv: Access-Request packet from host a.b.c.d:3272, id=0,

Re: ldap+radius authentication problem

2008-03-25 Thread Alan DeKok
amir shrestha wrote: I have configured freeradius with ldap backed as given in http://freeradius.org/radiusd/doc/ldap_howto.txt. The user get authorized but the authentication failed. ... rlm_ldap: bind as uid=abc,ou=users,ou=radius,dc=whitehouse,dc=edu/12345 to x.x.x.x:389 rlm_ldap:

Re: RADIUS Authentication

2007-06-22 Thread nguyenvinht
Infrastructure Services | ENG1 E1-1-08 University Of Sussex, Brighton EXT:01273 873900 | INT: 3900 - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- View this message in context: http://www.nabble.com/RADIUS-Authentication-tf3918468.html#a11257669 Sent from

Re: RADIUS Authentication

2007-06-21 Thread Peter Nixon
Yes. FreeRADIUS has been known to run on AIX but I don't think anyone is actively testing it on AIX at present. Please report any issues you have, and you are welcome to document the installation procedure and put it in the wiki :-) Regards Peter On Thu 21 Jun 2007, nguyenvinht wrote: By

Re: RADIUS Authentication

2007-06-20 Thread nguyenvinht
this message in context: http://www.nabble.com/RADIUS-Authentication-tf3918468.html#a11224860 Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: RADIUS Authentication

2007-06-15 Thread Peter Nixon
On Fri 15 Jun 2007, nguyenvinht wrote: Thanks Arran. How and where do I implement those codes in AIX RADIUS? Doable on AIX RADIUS? This is the FreeRADIUS mailing list. Please ask questions about other RADIUS servers elsewhere. -- Peter Nixon http://www.peternixon.net/ PGP Key:

RADIUS Authentication

2007-06-14 Thread nguyenvinht
how to accomplish this would be appreciated. Thanks. Vinh -- View this message in context: http://www.nabble.com/RADIUS-Authentication-tf3918468.html#a0867 Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org

Re: RADIUS Authentication

2007-06-14 Thread tnt
to accomplish this would be appreciated. Thanks. Vinh -- View this message in context: http://www.nabble.com/RADIUS-Authentication-tf3918468.html#a0867 Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: RADIUS Authentication

2007-06-14 Thread nguyenvinht
in context: http://www.nabble.com/RADIUS-Authentication-tf3918468.html#a11129084 Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: RADIUS Authentication

2007-06-14 Thread Arran Cudbard-Bell
nguyenvinht wrote: Thanks for replying. I want to implement this through RADIUS Server. Looking for some code modification or new attributes to accomplish the task. Vinh. tnt wrote: Allow everybody (who knows your secret) to use your radius server by entering 0.0.0.0/0 as client

Re: RADIUS Authentication

2007-06-14 Thread nguyenvinht
/users.html -- View this message in context: http://www.nabble.com/RADIUS-Authentication-tf3918468.html#a11130279 Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Radius authentication problems

2007-05-25 Thread Alan Dekok
sizo nsibande wrote: We are having a problem testing the authentication process on our radius box, please do not flame me, I am just trying to find out if any of you guys have ever maybe come across any such issue. There is no RADIUS traffic in that debug. I suggest asking the same question

Radius authentication problems

2007-05-24 Thread sizo nsibande
Goodmorow We are having a problem testing the authentication process on our radius box, please do not flame me, I am just trying to find out if any of you guys have ever maybe come across any such issue. Thanks in advance. snip May 24 14:09:52 allan snmpd[2435]: netsnmp_assert index == tmp

Re: PAM Radius Authentication

2007-04-19 Thread Reza Behroozi
Hi can u tell me how run radius with pam? thanks On 4/19/07, daniel [EMAIL PROTECTED] wrote: Ok, I have gotten pam_radius_auth.so to work and it is working well, however, is there any way to get it to create a UID when it receives an auth accept? At the moment I have to run adduser every time

Re: PAM Radius Authentication

2007-04-19 Thread Alan DeKok
daniel wrote: If I use LDAP to authenticate with PAM and freeradius authenticates against LDAP as well am I able to still store session details with LDAP? I believe so, yes. I am trying to integrate my current hotspot database with my terminals so that users can authenticate on either

Re: PAM Radius Authentication

2007-04-17 Thread daniel
Has anyone had any luck compiling pam_radius_auth on ubuntu? On Mon, 16 Apr 2007 15:13:49 +0200, Alan DeKok [EMAIL PROTECTED] wrote: daniel wrote: I am trying to set up unix authentication using radius. Does the pam module support the maximum session times. No, because PAM has no

Re: PAM Radius Authentication

2007-04-17 Thread Alan DeKok
daniel wrote: Has anyone had any luck compiling pam_radius_auth on ubuntu? $ apt-get install libpam0g-dev $ cd pam_radius $ make Does the pam module support accounting packets (ie. send accounting packet to radius when user logs on?) Yes. Alan DeKok. -- http://deployingradius.com

Re: PAM Radius Authentication

2007-04-16 Thread Alan DeKok
daniel wrote: Apr 15 22:03:51 bill sshd[7861]: PAM unable to dlopen(/lib/security/pam_radius_auth.so) Apr 15 22:03:51 bill sshd[7861]: PAM [dlerror: /lib/security/pam_radius_auth.so: undefined symbol: __stack_chk_fail_local] You've built the module with stack overflow checking turned on,

Re: PAM Radius Authentication

2007-04-16 Thread daniel
Alan, Thankyou, how do I build the module with stack overflow checking turned off, also what library do I need to link it to? Regards, Daniel Davis On Mon, 16 Apr 2007 11:15:59 +0200, Alan DeKok [EMAIL PROTECTED] wrote: daniel wrote: Apr 15 22:03:51 bill sshd[7861]: PAM unable to

Re: PAM Radius Authentication

2007-04-16 Thread Alan DeKok
daniel wrote: Thankyou, how do I build the module with stack overflow checking turned off, also what library do I need to link it to? I have no idea. Stack checking is part of your local system, not part of the module. Alan DeKok. -- http://deployingradius.com - The web site of

Re: PAM Radius Authentication

2007-04-16 Thread robinson santos
Alan, I dont know if someone could help me, i got FR working and authenticating in my AD. Here in my core switch a (Cisco 4507R) i have around 7 vlans, i was wondering if someone could explain to me how could i use FR and my switch to use a different vlan based in the user, and if is a guest

Re: PAM Radius Authentication

2007-04-16 Thread daniel
Alan, I am trying to set up unix authentication using radius. Does the pam module support the maximum session times. I am trying to set up a system where linux users authenticate against my existing radius hotspot system and they are forced to log out when their session expires. Regards,

Re: PAM Radius Authentication

2007-04-16 Thread Alan DeKok
daniel wrote: I am trying to set up unix authentication using radius. Does the pam module support the maximum session times. No, because PAM has no provisions for enforcing maximum session times. The setrlimit function call can enforce CPU time restrictions, but that is *not* clock time.

PAM Radius Authentication

2007-04-15 Thread daniel
Hi, I have been trying to set up the pam_radius_auth pam module to authenticate my users through my freeradius server. The radius server is working fine as I can get and Access-Accept packet with radtest and also my wireless hotspot authenticates fine through it. The problem I have is that

Re: some doubts, im newbie, radius authentication and mysql.

2007-03-25 Thread Alan DeKok
alex wrote: Only the first query looks to have a valid result. SELECT id, UserName, Attribute, Value, op FROM radcheck WHERE Username = '00:09:5b:65:98:b0' ORDER BY id After that the other queries doesnt have a valid answer, so the user uis rejected. My

some doubts, im newbie, radius authentication and mysql.

2007-03-24 Thread alex
Hey guys, we setup freeradius with mysql and radius manager 2. After the installation the mysql integration looks good. We add users and everything looks ok in the case of wireless users, they provide the mac address and here is where we have some doubts. If we add a user i can see that radius

Re: Pam radius authentication

2006-10-20 Thread danieldinu
Isn't there anyone who tried this implementation? Hi! if you are reffering to this line: account required pam_radius_auth.so debug than here is the explanation: The pam configuration can be: ... auth sufficient /lib/security/pam_radius_auth.so [options] ... accountsufficient

  1   2   >