Re: Windows Client Authentification bevore Domain logon

2005-08-26 Thread User Test
System pocztowy Galtex S.A. informuje, iz Twoja wiadomosc zostala dostarczona Wiadomosc wygenerowana automatycznie przez system pocztowy uzytkownika belskia Prosze na ta wiadomosc nie odpowiadac. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: not to return the detault attributes in reject?

2005-08-26 Thread Thor Spruyt
kevin wrote: Still not sure how to handle with rlm_exec. Can anybody give me more details? Maybe another solution.. in users file TART with: DEFAULT Auth-Type := Reject Fall-Through = Yes kevin Thor Spruyt wrote: kevin wrote: How can I return Reject-Packet without

Re: Windows Client Authentification bevore Domain logon

2005-08-26 Thread Armin Krämer
Thanks for the answert Alan, but what do you mean that it should be made more prominent in EAP-Conf? Could you give me detailed instructions how i can get this OID to my certificates?ArminFreeRadius users mailing list freeradius-users@lists.freeradius.org schrieb am 25.08.05 17:35:11:Ben Walding

Re: salt-encrypted VSAs?

2005-08-26 Thread Bjørn Mork
Alan DeKok [EMAIL PROTECTED] writes: =?iso-8859-1?Q?Bj=F8rn_Mork?= [EMAIL PROTECTED] wrote: My problem seems to be that FreeRADIUS will only encrypt string or octet values, while Juniper has defined salt encrypted integer and ipaddr VSAs too. Try setting encrypt=2 for attribute 59. That

A cluster of freeradius servers

2005-08-26 Thread Angel L. Mateo
Hi, I want to deploy the next configuration: I have a proxy radius server (freeradius) who redirect its requests to another freeradius server. I have another freeradius server with the same configuration as this last one. What I want is to configure the proxy radius to proxy requests to

Re: A cluster of freeradius servers

2005-08-26 Thread Nicolas Baradakis
Angel L. Mateo wrote: I want to deploy the next configuration: I have a proxy radius server (freeradius) who redirect its requests to another freeradius server. I have another freeradius server with the same configuration as this last one. What I want is to configure the proxy radius to

Re: freeradius server not responding to radtest

2005-08-26 Thread Benedikt Panzer
Hello, do you have localhost with that shared secret in your clients.conf file? Is there a firewall blocking the requests? (nmap -sU -p 1812 localhost) Regards, Benedikt bratislava:/usr/local/etc/raddb# radtest test test localhost 0 test - List info/subscribe/unsubscribe? See

Re: freeradius server not responding to radtest

2005-08-26 Thread Ben Dowling
It is in clients.conf with the secret 'test'. Scanning it with -P0 shows that port 1812 is open|filtered, but scanning without -P0 shows host is down. Cheers, Ben Benedikt Panzer wrote: Hello, do you have localhost with that shared secret in your clients.conf file? Is there a firewall

PEAP issues

2005-08-26 Thread allan.borman
Hi All, Thanks for the previous help that everyone offered, I got the freeradius up and running. I can authenticate using a test account I created in the users file, using the radius itself and also using my VPN box. I set this server up originally to authenticate WI-Fi users usign 802.1x and

RE: PEAP issues

2005-08-26 Thread Bill Carr
Remove the Auth-Type Local From the guest account. Let freeradius figure out to do EAP on it's own. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of allan.borman Sent: Friday, August 26, 2005 12:32 PM To: FreeRadius users mailing list Subject: PEAP

Excluding non-NAS from simultaneous-use checks

2005-08-26 Thread Dan Siemon
I'm looking for a way to exclude some sources of RADIUS authentication requests from being subjected to the simultaneous-use checks. Basically we use RADIUS for more than just dialin, simultaneous-use is not applicable to these services. I found the following thread on the Cistron mailing

16 bit attr decoding..

2005-08-26 Thread Wesley Spadola
I am currently working with the CVS (1.1.0) HEAD version of FreeRADIUS. It is using the SQL module with the Lucent 16bit atributes turned on. To make sure we have the most attributes available, I have merged the Ascend dictionary (more specifically, the just the VALUEs), because the CVS

Re: MySQL radacct not updated

2005-08-26 Thread sean
Hi Thor, I'm just posting this to thank you for your help and let you know that it was appreciated and also to help anyone else with a similar problem to see the solution. In order to enable the accounting packets between Chilli and Radius I removed all of the pin holes in my ADSL modem and

Re: MySQL radacct not updated

2005-08-26 Thread Thor Spruyt
sean wrote: In order to enable the accounting packets between Chilli and Radius I removed all of the pin holes in my ADSL modem and instead set up a NAT default server pointing to my Radius/WEB/Jabber/POP/SMTP/SMPP/Apache server. This allows all of the trafic arriving to the ADSL modem to

Re: PEAP issues

2005-08-26 Thread Alan DeKok
allan.borman [EMAIL PROTECTED] wrote: This is where it fails. and the result is consistent with two different wireless manifacturer. the debug section is below. I like to thank anyone in advance for any suggestions or help that you may offer. ... rad_check_password: Found Auth-Type

Re: Excluding non-NAS from simultaneous-use checks

2005-08-26 Thread Alan DeKok
Dan Siemon [EMAIL PROTECTED] wrote: I'm looking for a way to exclude some sources of RADIUS authentication requests from being subjected to the simultaneous-use checks. Don't set Simultaneous-Use. Setting the RAS type to none appears to have no effect for FreeRADIUS. Is there another

Re: 16 bit attr decoding..

2005-08-26 Thread Alan DeKok
Wesley Spadola [EMAIL PROTECTED] wrote: Now, while I was testing this last week I was receiving: Lucent-Modem = v90/v34/v92/etc instead of this week: Lucent-Modem-Modulation = 1/2/18/etc The NAS sends those attributes, and FreeRADIUS logs them. Is there a possible reason it used code

Re: usage of exec to get LDAP value..

2005-08-26 Thread Alan DeKok
haizam [EMAIL PROTECTED] wrote: I've tried to map new attributes in ldap.attrmap but for every match in users file.. it will return both new attributes but the sessiontimeout still ruturn no value.. Yes. Did you read the rest of my response? Alan DeKok. - List

Re: freeradius server not responding to radtest

2005-08-26 Thread James Gruwell
Ben, Not sure if this is much help or not but what does your clients.conf file say? If you don't have your localhost address 127.0.0.1 in clients.conf then the server will not respond. I think it is usually an access reject message but you never know. I also noticed that you have no defined