Re: Help me with Access-Challenge configuration

2011-04-12 Thread Alan DeKok
GreenUA wrote: What methods? How i can configure it? If you don't know, you don't need Access-Challenges. I need to see how my client process challenge response. And i can't generate that message. If you're debugging a RADIUS client you wrote, then this isn't a FreeRADIUS question.

Re: Help me with Access-Challenge configuration

2011-04-12 Thread GreenUA
To Alan DeKok-2 Sorry, for my maybe inconsistent question. I try to explain: 1. If you're debugging a RADIUS client you wrote, then this isn't a FreeRADIUS question. It's freeRADIUS question because i need to configure freeRADIUS server 2. What methods? How i can configure it? If you

Re: Help me with Access-Challenge configuration

2011-04-12 Thread Alan DeKok
GreenUA wrote: 1. If you're debugging a RADIUS client you wrote, then this isn't a FreeRADIUS question. It's freeRADIUS question because i need to configure freeRADIUS server If you know so much more than we do, why are you asking questions on this list? 2. What methods? How i can

Re: Help me with Access-Challenge configuration

2011-04-12 Thread Stefan Winter
Hi, My simple question: How to configure freeRADIUS server so it replay access-challenge message on access-request from a client? Alan's problem with this simple question of yours is that it's not just simple, but simplistic. RADIUS can convey *many different* authentication protocols

Re: Help me with Access-Challenge configuration

2011-04-12 Thread GreenUA
Aa Stefan Winter-4, Thanks a lot, now i underspend how to configure my configuration It's what i need to hear! Have a nice day! -- View this message in context: http://freeradius.1045715.n5.nabble.com/Help-me-with-Access-Challenge-configuration-tp4296727p4297576.html Sent from the

Re: freeradius, how to cooperate with a wireless AP( system is linux, openwrt)

2011-04-12 Thread EasyHorpak.com
On 12/04/2554 12:20, xuyu wrote: Hi,I want to build a wireless network with radius server . server computer is ubuntu , wireless router is a linux system-openwrt.So i need to install something in the router,So what is it? Can somebody know something about it? please do me a favor. - List

Re: MS-CHAP-V2 with no retry

2011-04-12 Thread Alan DeKok
Phil Mayers wrote: With send_error = yes, the client just hangs (and in fact crashed my phone several times) Nice to know! Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-TLS + Symbian = weird behaviour

2011-04-12 Thread Zeus V Panchenko
some additional details: the same behaviour with different AP i use AP mostly under OpenWRT but now have tried Lynksys WAP54G which was working at the place where no problem found and now no it's no way to authorize via it ... any idea? -- Zeus V. Panchenko IT Dpt., IBS ltd

MAC Address and Username Binding on FreeRADIUS

2011-04-12 Thread syharash
Hi, My FreeRadius is working fine, my wireless clients are able to authenticate with username and password from the /etc/raddb/users file and dynamic vlan assignment is working fine too. Need to now configure to restrict a user to get authenticated only from a single mac address, so the dynamic

Radrealy and dynamic-sql-clients

2011-04-12 Thread Etienne Pretorius
Hello List. I am using the dynamic-sql-clients example in my freeradius server. I am keying off the %{Packet-Src-IP-Address} of the NAS sending the packets to two separate virtual servers on the same host. The problem comes, when I wish to radrelay - I end up having to pick one or the other

Different sql servers for separated authacc

2011-04-12 Thread c.schw...@funknetz.at
Hello, in a special setup we are using freeradius Version 1.1.3 (sql.conf v 1.41.2.2.2.2), on a debian x86 machine, which can't be upgraded to Version 2.0. I would like to check authorization against mysqldb1 and insert/update accounting in mysqldb2. Is it possible to use two independent

ldap and file authentication

2011-04-12 Thread Marco Kalmbach
hi @all, is it possible to provide ldap authentication and users file authentication at the same time on a radius server? On my radius server the ldap authentication works fine, additional I want to provide users file authentication, so I commented out the following lines: --radiusd.conf file

RE: unable to authenticate freeradius+AD

2011-04-12 Thread Yao Konou
SOS - is somebody around to HELP ME Yao Thierry Konou AMR SERVICES 11 Rue du Petit Châtelier CS90346 44303 NANTES CEDEX 3 Tel : 02 28 44 19 80 - Fax : 02 28 44 53 88 Site: http://www.amr-services.frhttp://www.amr-services.fr/ De :

AW: unable to authenticate freeradius+AD

2011-04-12 Thread Schaatsbergen, Chris
You have not configured ntlm_auth, see http://deployingradius.com/documents/configuration/active_directory.html Von: freeradius-users-bounces+chris.schaatsbergen=aleo-solar...@lists.freeradius.org [mailto:freeradius-users-bounces+chris.schaatsbergen=aleo-solar...@lists.freeradius.org] Im

How to add RADIUS users under OU=People

2011-04-12 Thread pradyumna dash
Hello, I need a help, What i want is instead of creating a OU called radius, i would like to add all radius users under OU=People, how to achieve this? I am not able to add a user with objectclass:radiusprofile, I tried changing radius schema to AUX but no luck. Please have a look at my LDIF

Freeradius and Microsoft NPS

2011-04-12 Thread Doty, Seth
I couldn't find anything in the archives with this error and i am fairly new to freeradius config anyway so i thought this would be a good start. We are looking to authenticate wireless users through freeradius and Microsoft NPS. Our outer authentication is PEAP and terminates at the radius

Authentication based on users and NAS

2011-04-12 Thread Sergio Belkin
Hi, It was easier than I thought, I simply had to add to /etc/raddb/users something like: steve Called-Station-Id == 00259c14066e,Cleartext-Password := password Still I had to solve 2 issues: The first one is that if I want steve to login through more than NAS I have to add one line like above

Re: Freeradius and Microsoft NPS

2011-04-12 Thread Phil Mayers
On 12/04/11 16:34, Doty, Seth wrote: I couldn't find anything in the archives with this error and i am fairly new to freeradius config anyway so i thought this would be a good start. We are looking to authenticate wireless users through freeradius and Microsoft NPS. Our outer authentication is

Re: MAC Address and Username Binding on FreeRADIUS

2011-04-12 Thread Christ Schlacta
SO far as I know, there is no good way to automatically add a mac address to a user entry, or an user entry to a mac80211 entry on first connect. the UNLANG to ensure that the mac address matches for a validated account is simple however, and you should have no issue figuring that out. see

RE: Freeradius and Microsoft NPS

2011-04-12 Thread Doty, Seth
The box is fedora 14 with freeradius from the repos. This the the output of the gdb log flle: Starting program: /usr/sbin/radiusd -X [Thread debugging using libthread_db enabled] Program received signal SIGSEGV, Segmentation fault. 0xb7fce31d in rbtree_find () from

EAP-PEAP-GTC User-Password never set

2011-04-12 Thread Carl Anderson
Hello All, I've been trying to get this seemingly simple implementation working for the past week to no avail. I've been scouring the search in an attempt to find someone with the exact same problem, yet haven't found anyone. Hopefully someone here can help. Here is my attempted implementation:

Re: MAC Address and Username Binding on FreeRADIUS

2011-04-12 Thread Thor Spruyt
Hi, You could use a huntgroup for the MAC addresses and then define what to do for that huntgroup. Thor. - Original Message - From: syharash syhar...@yahoo.com To: freeradius-users@lists.freeradius.org Sent: Tuesday, April 12, 2011 12:11:51 PM GMT +01:00 Amsterdam / Berlin / Bern /

Re: Freeradius and Microsoft NPS

2011-04-12 Thread Phil Mayers
On 04/12/2011 07:32 PM, Doty, Seth wrote: The box is fedora 14 with freeradius from the repos. This the the output of the gdb log flle: Can you install the freeradius-debuginfo RPM and do this again; the backtrace is partial/mangled. It looks like it may be dying in request_free in

Re: Different sql servers for separated authacc

2011-04-12 Thread Thor Spruyt
Hi, Read http://wiki.freeradius.org/Rlm_sql section Instances Regards, Thor. - Original Message - From: c schwarz c.schw...@funknetz.at To: freeradius-users@lists.freeradius.org Sent: Tuesday, April 12, 2011 1:36:17 PM GMT +01:00 Amsterdam / Berlin / Bern / Rome / Stockholm /

Re: ldap and file authentication

2011-04-12 Thread Thor Spruyt
Hi, Read http://wiki.freeradius.org/Fail-over Regards, Thor. - Original Message - From: Marco Kalmbach mc...@gmx.de To: freeradius-users@lists.freeradius.org Sent: Tuesday, April 12, 2011 3:24:35 PM GMT +01:00 Amsterdam / Berlin / Bern / Rome / Stockholm / Vienna Subject: ldap and

Re: How to add RADIUS users under OU=People

2011-04-12 Thread Thor Spruyt
Hi, Read http://wiki.freeradius.org/Rlm_ldap You might want to play with basedn and filter. Regards, Thor. - Original Message - From: pradyumna dash pradyumna_dash...@yahoo.co.in To: freeradius-users@lists.freeradius.org Sent: Tuesday, April 12, 2011 4:34:52 PM GMT +01:00 Amsterdam /

Re: Authentication based on users and NAS

2011-04-12 Thread Thor Spruyt
Hi, If you're going to use LDAP, then just add the Called-Station-Id to your search filter and add one or multiple attributes to match against in your LDAP entries. Regards, Thor. - Original Message - From: Sergio Belkin seb...@gmail.com To: FreeRadius users mailing list

Using user name from certificate.

2011-04-12 Thread Mrinal K
Hello everyone, I have been trying to check some parameters for authentication which needs the CommonName from the certificate. I realise that the value I need to access is cn_str(from source code) but it is not available for processing from the configuration file. Will defining in dictionary

Re: Using user name from certificate.

2011-04-12 Thread Alan DeKok
Mrinal K wrote: I have been trying to check some parameters for authentication which needs the CommonName from the certificate. I realise that the value I need to access is cn_str(from source code) but it is not available for processing from the configuration file. Will defining in dictionary

Re: EAP-PEAP-GTC User-Password never set

2011-04-12 Thread Alan DeKok
Carl Anderson wrote: So far the PEAP tunnel is created without a problem, but when it enters the EAP/gtc phase 2 it seems to only populate the User-Name attribute. The User-Password, Secret, PIN, and Offset values all expand as empty. As a result, phase 2 GTC authentication fails because the

Re: Radrealy and dynamic-sql-clients

2011-04-12 Thread Alan DeKok
Etienne Pretorius wrote: The problem comes, when I wish to radrelay - I end up having to pick one or the other virtual server. I was just wandering if there was a way for me to proxy these packets to the correct virtual server based on the attributes in them, namely NAS-IP-Address? Set

Re: How to add RADIUS users under OU=People

2011-04-12 Thread pradyumna dash
Hi Thor, Thanks for your reply. The rlm_ldap module is used for integration of FreeRADIUS with OpenLDAP, but am facing issues, while adding a user under OU=People with radiusprofile objectclass and radius attributes. If am adding another OU e.g RADIUS and trying to add users in it, it is

RE: EAP-PEAP-GTC User-Password never set

2011-04-12 Thread Carl Anderson
Well, that's a shame, but thank you very much for the reply, I appreciate it. It'll at least save me countless hours of fiddling around with the config to no avail. Cheers, Carl From: Alan DeKok-2 [via FreeRadius] [mailto:ml-node+4299802-2066596580-197...@n5.nabble.com] Sent: Wednesday,