RE: Syntax error converting datetime from character string

2007-03-13 Thread satish patel
Thank 4 your ans Can u tell me mssql support unix date time but one morething i got this problem sometime not every time i got this problem after 2 and 3 days and my radiusd goes down so is there problem regarding unix datetime Cory Robson [EMAIL PROTECTED] wrote:v\:*

RE : ldap groups + freeradius

2007-03-13 Thread Thibault Le Meur
Hi, I have 4 NAS-IP-Addresses. My users are split into 6 groups (some are in multiple groups): public, faculty, staff, student, vpn, and admin. I would like the users to get access to the NAS by virtue of being in a group. 192.168.1.1 admin 192.168.1.2 vpn

freeradius with mssql performance

2007-03-13 Thread satish patel
Dear guys anybody idea of freeradius with MSSQL compatibliy or performance issue ..which is best of method with radius MySql or MSSQL which one is best for radius performance $ cat ~/satish/url.txt System administrator ( Data Center ) please visit this site

Access-Challenge with Avaya

2007-03-13 Thread Romain Mercier
Hello ! I am having troubles with Avaya P334T switch. I am trying to authenticate users directly connected to ports of the switch. I have configured the switch well I think because the acces-request is sent to the radius but then the radius send an access-challenge to the switch and nothing

Mikrotik access and authentication with radius for the hotspot service

2007-03-13 Thread Elie Hani
Hi; I am configuring a hotspot server on mikrotik, but I want the authentication to be done with the freeradius server and not locally on the hotspot server. So is there any way to configure this? Thanks Elie Hani - List info/subscribe/unsubscribe? See

Re: FR supported attributes

2007-03-13 Thread PD
On 3/12/2007, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Wired chilli? The makers say: ChilliSpot is an open source captive portal or wireless LAN access point controller. It is used for authenticating users of a wireless LAN. Do you know something they don't? My first Chilli installation is

Re: FR supported attributes

2007-03-13 Thread PD
On 3/12/2007, Internet-Wifi Operador [EMAIL PROTECTED] wrote: Chillispot is a gateway, not matter if you passthrough with Wifi connection or wire connection, Chillispot not identify they. The litle diference is, if you use Expiration attribute Chillispot ignores it, so when the time is reach

Re: Mikrotik access and authentication with radius for the hotspot service

2007-03-13 Thread PD
Well, we are still on the development stage and mikrotik is one of the choosen NAS that will be used. As long as I know, mikrotik already explain how to use external radius server. See http://www.mikrotik.com/testdocs/ros/2.9/guide/aaa_radius.php CMIIW PD On 3/13/2007, Elie Hani [EMAIL

Re: Help with freeradius 1.1.5

2007-03-13 Thread adreas polyxronopoulos
Thanks for your help Alan, However i don't undestand what i have to do to fix this bug. Where can i found the branch_1_1 and what should i do it? If i download the freeradius-1.1.5 source again and compile it, it should work ? Thanks again , On Mon, 2007-03-12 at 16:23 +0100, Alan DeKok

Re: checkrad or sql base simultaneous-use

2007-03-13 Thread tnt
You can close all open sessions by altering AcctStopTime: UPDATE radacct SET AcctStopTime='whatever' WHERE AcctStopTime='1900-01-01 00:00:00' Or you can just delete them all (probably better if you are charging customers monthly and not by time online): DELETE FROM radacct WHERE

Re: Help with freeradius 1.1.5

2007-03-13 Thread A . L . M . Buxey
Hi, Thanks for your help Alan, However i don't undestand what i have to do to fix this bug. Where can i found the branch_1_1 and what should i do it? If i download the freeradius-1.1.5 source again and compile it, it should work ? no. it wont work as 1.1.5 is 1.1.5 and the patch is in

PPTP Vpn Client Static route

2007-03-13 Thread Gabriele Moroni
Hi all, I have a quesiton... I use freeradius v1.1.5 to authenticate pptp vpn users. Someone know what's the best way to destribute a list of route to insert on the clients routing table ? I have WinXp SP2 Clients and also MAC OSX Tnx for an answer Bye Gabriele

Re:Re: pptp + vpn + freeradius Acct-Status-Type Alive

2007-03-13 Thread Jóhann B. Guðmundsson
Since I finally solved this... It was possible yet not documented in the vpn docs ( poptop + freeradius + samba) I added ATTRIBUTE Acct-Interim-Interval 85 integer to /etc/radiusclient/dictionary and then added to /etc/raddb/users DEFAULT Realm == staff.example.com,Auth-Type :=

Re: authenticating multiple modules?

2007-03-13 Thread Tim Tyler
Ivan, No unfortunately it doesn't work that way, though I wish it did because that would be easy. I can't get system to authenticate with that config which works fine if I comment out the ldap line. Alan Dekok mentioned this: pull the password from LDAP, and let the server decide how

Re: Kerberos module config

2007-03-13 Thread Alan DeKok
John T. Guthrie wrote: Well, when all else fails, read the documentation. I just checked the wiki on the website, and it says that the answer to my question is yes. However, I went ahead and wrote a patch to the radiusd.conf.in file in the source code to add in ome documentation for

Re: authenticating multiple modules?

2007-03-13 Thread Alan DeKok
Tim Tyler wrote: Ivan, or others, Ok, I can't seem to find documentation on this. If I don't use the users file, I presume I should create the groups in the radiusd.conf file. How does one create a group for Students and Staff (syntax)? man rlm_passwd Can I assign Auth-Type =

Re: EAP-TTLS outer identity accounting

2007-03-13 Thread Alan DeKok
Sam Schultz wrote: I'm currently using EAP-TTLS PAP (via SecureW2) to authorize authenticate wireless clients against specific realms. Users are able to authorize authenticate properly, but the username in incoming accounting replies come in as 'anonymous@realmname'. You can set

Re: How to enable Freeradius to support a smart card with AES encryption algorithm?

2007-03-13 Thread Alan DeKok
yao guoxian wrote: Thanks,Alan. But I have a few questions. First, if I create a new attribute My-Aes-Password and include it in the Access-Requet packet, I should not include the attributes such as User-Password or Chap-Password.Is it right? Yes. The second question is

Re: EAP-TTLS outer identity accounting

2007-03-13 Thread Sam Schultz
On Tue, 13 Mar 2007 11:58:51 -0500 Alan DeKok [EMAIL PROTECTED] wrote: Sam Schultz wrote: I'm currently using EAP-TTLS PAP (via SecureW2) to authorize authenticate wireless clients against specific realms. Users are able to authorize authenticate properly, but the username in incoming

Re: EAP-TTLS outer identity accounting

2007-03-13 Thread Alan DeKok
Sam Schultz wrote: This should be solvable by adding something like 'User-Name = %{User-Name}' to the DEFAULT entries in the users file, correct? Yes. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List

Operators += don�t work !!!

2007-03-13 Thread Internet-Wifi Operador
I have a s sqlcounter Like Max-All-Session until 2 or 3 weeks ago when I did use this with '+=' operator it work prefect because add some time to the user. 2 or 3 days ago it stop to work Somebody any Idea? Fabián _ Get a FREE

Re: Kerberos module config

2007-03-13 Thread John T. Guthrie
On Tue, 2007-03-13 at 17:31 +0100, Alan DeKok wrote: John T. Guthrie wrote: Well, when all else fails, read the documentation. I just checked the wiki on the website, and it says that the answer to my question is yes. However, I went ahead and wrote a patch to the radiusd.conf.in file in