RE: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-12-02 Thread Bohannan, Chad W
-Original Message- From: Bohannan, Chad W Sent: Thursday, December 01, 2005 11:27 AM To: 'charles schwartz'; 'FreeRadius users mailing list' Subject: RE: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial] Hello, I am attempting to have FR authenticate

RE: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-12-01 Thread Bohannan, Chad W
Hello, I am attempting to have FR authenticate administrative access for my Cisco gear against AD. The problem I am having is this. When I attempt to join the realm net ads join -U UID the command appears successful and from the AD side, the system has joined (visable in AD), however the

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-24 Thread Alan DeKok
Alhagie Puye [EMAIL PROTECTED] wrote: I have followed the steps in the howto and everything seems to work fine but FreeRADIUS is ignoring MS-CHAP. Debug logs? My question is...can I use Active Directory if I need to use attribute 25 on FreeRADIUS? What's attribute 25? If so, how do I

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-23 Thread Nicolas Baradakis
King, Michael wrote: Ignore the freeRADIUS package. Due to license restrictions, it cannot contain the binaries for OpenSSL. We have to use the source. Indeed. Download the latest release of freeRADIUS Unzip freeRADIUS Tar -zxvf freeradius-1.0.5.tar.gz Switch to the directory then

RE: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-23 Thread Alhagie Puye
, 2005 11:51 AM To: charles schwartz; FreeRadius users mailing list Subject: Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial] Hi Charles, thank you for that howto. A typo, that you might want to correct: On page 9 it should be --request-nt-key

RE: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-23 Thread Robin Mordasiewicz
On Wed, 23 Nov 2005, Alhagie Puye wrote: I have followed the steps in the howto and everything seems to work fine but FreeRADIUS is ignoring MS-CHAP. I'm using ntradpingmaybe that's a wrong utility for this instance. I don't think you can properly test this with NTRadPing, but I have

RE: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-23 Thread Alhagie Puye
] On Behalf Of Robin Mordasiewicz Sent: November 23, 2005 6:16 PM To: FreeRadius users mailing list Subject: RE: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial] On Wed, 23 Nov 2005, Alhagie Puye wrote: I have followed the steps in the howto and everything

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread Alan DeKok
charles schwartz [EMAIL PROTECTED] wrote: There are at least 2 ways to integrate AD: LDAP and NTLM. I've written a tutorial about how to do this with NTLM (winbind, ntlm_auth). The Windows supplicants are configured to work with PEAP and MSCHAPv2. Very nice. My only real comment is that

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread Robin Mordasiewicz
On Tue, 22 Nov 2005, charles schwartz wrote: A lot of people on this list would like to integrate Active Directory with FreeRADIUS in order to provide a transparent user authentication login process. There are at least 2 ways to integrate AD: LDAP and NTLM. I've written a tutorial about

RE: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread King, Michael
Hi Robin -Original Message- I have one Debian specific error rlm_eap: Failed to link EAP-Type/tls: rlm_eap_tls.so: cannot open shared object file: No such file or directory radiusd.conf[9]: eap: Module instantiation failed. it seems that the shared object is not shipped when

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread Norbert Wegener
Hi Charles, thank you for that howto. A typo, that you might want to correct: On page 9 it should be --request-nt-key -instead of –-nt-request-key and --username instead of -username. Norbert Wegener charles schwartz wrote: Hi list, A lot of people on this list would like to integrate

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread Robin Mordasiewicz
On Tue, 22 Nov 2005, charles schwartz wrote: Hi list, A lot of people on this list would like to integrate Active Directory with FreeRADIUS in order to provide a transparent user authentication login process. There are at least 2 ways to integrate AD: LDAP and NTLM. I've written a

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread Luca Corti
On Tue, 2005-11-22 at 14:10 -0500, Robin Mordasiewicz wrote: it seems that the shared object is not shipped when I did apt-get install freeradius Grab the latest CVS, install build-deps and use dpkg-buildpackage. It should work out-of-the-box. -- Luca Corti PGP Key ID 1F38C091 signature.asc

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread Alan DeKok
Robin Mordasiewicz [EMAIL PROTECTED] wrote: thanks for this. I change to use the /dev/random as per your tutorial but radiusd hangs. When I change the random_file back to the original then it works Yes. The random_file needed by the TLS module is a *pool* of random numbers. /dev/random and

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread Robin Mordasiewicz
On Tue, 22 Nov 2005, charles schwartz wrote: Hi list, A lot of people on this list would like to integrate Active Directory with FreeRADIUS in order to provide a transparent user authentication login process. There are at least 2 ways to integrate AD: LDAP and NTLM. I've written a

Re: Freeradius How to integrate Active Directory [AD Integration WindowsXP NTLM Tutorial]

2005-11-22 Thread Michael Griego
Actually, that's not completely true. Using /dev/random as the file argument for RAND_load_file when seeding the PRNG is recommended practice on systems that have it. The RAND_load_file call in the eap_tls code will only read at max 1048567 (1024 * 1024) bytes from the file, so it won't read