Re: Setting FreeRadius and Ldap. - Getting Educated Now

2009-08-28 Thread Steven Sprague
Ivan, Thanks for the url link to the missing documentation. Very helpful. Ldap is not going to work for EAP. Now I am facing a dilemma - deciding what WEP protocol to use based on my test setup. After reading the 'sites' and 'modules' files it seems that some WEP or EAP protocols are weaker

Re: Setting FreeRadius and Ldap. - Getting Educated Now

2009-08-28 Thread Ivan Kalik
Now I am facing a dilemma - deciding what WEP protocol to use based on my test setup. After reading the 'sites' and 'modules' files it seems that some WEP or EAP protocols are weaker than others, some not suggested for use. Here's what my test router and machines can handle. Router can

Re: Setting FreeRadius and Ldap. - Getting Educated Now

2009-08-28 Thread Alan Buxey
Hi, Now I am facing a dilemma - deciding what WEP protocol to use based on my test setup. After reading the 'sites' and 'modules' files it seems that some WEP or EAP protocols are weaker than others, some not suggested for use. dont use WEP. ever. Router can provide - WEP 40/128 shared

Re: Setting FreeRadius and Ldap. - User settings

2009-08-28 Thread Steven Sprague
Ivan, Based on your advice I need to set myself up as a user and start testing from my workstation. Since it seems I am missing the docs supplied in source (used packaged file) can you give me some guidance on minimum setting. 1. RADIUS server Shared Secret Where is the best place to set my

Re: Setting FreeRadius and Ldap. - Getting Educated Now

2009-08-28 Thread Steven Sprague
Thanks Alan, WPA Enterprise with AES, I will do some more reading to understand the benefits of AES. As for the older laptop - I choose this unit because if represents the oldest of technologies that will be accessing the network. This IBM Thinkpad uses a Cisco (Calexico) internal wireless card

Re: Setting FreeRadius and Ldap. - Getting Educated Now

2009-08-28 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 28/08/2009 16:50, Steven Sprague wrote: Thanks Alan, WPA Enterprise with AES, I will do some more reading to understand the benefits of AES. TKIP is semi-broken, in that you can do ARP poisoning attacks without needing the PMK. Were

Setting FreeRadius and Ldap.

2009-08-27 Thread Steven Sprague
Hello All My needs are simple. Use an exiting LDAP server to communicate with FreeRadius. After reading a number of sources (including the FAQ) I am a bit confused as to what is required? I will start out simple with WPA using LEAP - since all my client boxes can use it. Questions: Do I need

Re: Setting FreeRadius and Ldap.

2009-08-27 Thread Ivan Kalik
Questions: Do I need any special schema for ldap to use this plan? Y/N No. If NO, what other settings need to be set on the client, ldap and FreeRadius server for testing. Configure ldap module (raddb/modules/ldap, instructions in doc/rlm_ldap) and uncomment ldap in authorize section of

Re: Setting FreeRadius and Ldap.

2009-08-27 Thread Steven Sprague
tnt, Made the changes you suggested but could not locate the doc/rlm_ldap. Do you have any simple tests for the settings I changed? Steven -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. - List info/subscribe/unsubscribe? See

Re: Setting FreeRadius and Ldap.

2009-08-27 Thread Steven Sprague
tnt, I loaded FreeRadius in terminal using -X to see what is loading. Here's what comes back - you will notice one complaint below - in the rlm_ldap section: rlm_ldap: Over-riding set_auth_type, as there is no module ldap listed in the authenticate section. [r...@ns1 ~]# radiusd -X FreeRADIUS