2 database,1 radius server

2004-02-20 Thread Truong Manh Cuong
Title: Message HI all, I have a single server (stand alone) that run postgresql and freeradius service. Is it possible if I want to run freeradius and can control 2 database? (this server has 2 database; 1 for pre-paid user and 1 for post-paid user). if it is possible, how can I declare

Re: user password for LEAP

2004-02-20 Thread BLANCA FERRERO RODRIGUEZ
BLANCA FERRERO RODRIGUEZ [EMAIL PROTECTED] wrote: The communication between my AP and the server seems correct in the first messages, but when the AP replies to the server challenge, I can see several error messages. The first ones is this: ' No user-password or NT-Password configured

RE: 2 database,1 radius server

2004-02-20 Thread Truong Manh Cuong
Thanks a lot. Manh Cuong. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alex Kasatkin Sent: Friday, February 20, 2004 3:26 PM To: [EMAIL PROTECTED] Subject: Re: 2 database,1 radius server Hi! Truong Manh Cuong [EMAIL PROTECTED] wrote: HI all, I

RE: HELP!!!! Translate h323-setup/connect/disconnect to ...

2004-02-20 Thread Daniil I. Pimonenko
Hi! I'm using MSSql Wbr DaniiL I. Pimonenko Help me pls. How can I translate Translate h323-setup/connect/disconnect to normal sql like date? Now my VoIP proxy(Mera XPGK) send me Cisco VSA( 25): h323-setup-time=17:42:00.000 MSK Fri Feb 13 2004 How I can translate it

Re: HELP!!!! Translate h323-setup/connect/disconnect to ...

2004-02-20 Thread Norguhtar
Hi! I'm using MSSql Wbr DaniiL I. Pimonenko Help me pls. How can I translate Translate h323-setup/connect/disconnect to normal sql like date? Now my VoIP proxy(Mera XPGK) send me Cisco VSA( 25): h323-setup-time=17:42:00.000 MSK Fri Feb 13 2004 How I can

Authorize and Authenticate with FILES: auth: Failed to validate the user

2004-02-20 Thread José Luis Solano
Hi all!!! I have installed freeradius-snapshot-20040216 with redhat 9. I use AlfaAriss client under Windows XP, cisco pcmcia car on my laptop. I use FILES to authorize and authenticate, but TTLS don't run ok. any idea?? please help?? (Alan, Lionel, Jean-Paul, please) freeradius

Re: Authorize and Authenticate with FILES: auth: Failed to validate the user

2004-02-20 Thread José Luis Solano
Sorry, and my authorize and authenticate modules in radiusd.conf are: authorize { preprocess # Read the 'users' file files } authenticate { Auth-Type PAP { pap } } José Luis SolanoSGI - Soluciones Globales Internet S.A.Delegación Regional Sur[EMAIL PROTECTED](+34)

RE: HELP!!!! Translate h323-setup/connect/disconnect to ...

2004-02-20 Thread Daniil I. Pimonenko
Hi ALL! NO! I'm not use truggers. Wbr DaniiL I. Pimonenko Help me pls. How can I translate Translate h323-setup/connect/disconnect to normal sql like date? Now my VoIP proxy(Mera XPGK) send me Cisco VSA( 25): h323-setup-time=17:42:00.000 MSK Fri

[ DEVEL ] : problem in reply ticket ( in a new module ).

2004-02-20 Thread Olivier Houte
Hi all, I write a new module for freeradius like rlm_ippool. In this module, I choose among several Tunnel-Server-Endpoints. In the auth ticket, I can have a static TSE attribute, in this case, I make no change ( in the reply ticket ). But I could have a dynamic TSE, for example if I have :

How to Freeradius + EAP/TTLS

2004-02-20 Thread sagar.patil
Hi All, I am following notes at following link to implement EAP/TTLS with FREERADIUS. http://rbirri.9online.fr/howto/Freeradius_+_TTLS.html Alan Ur suggestion to pick up latest snapshot did worked and I could compile TTLS under src/modules/rlm_eap/types/rlm_eap_ttls/ I also

Re: Authorize and Authenticate with FILES: auth: Failed to validate the user

2004-02-20 Thread Jean-Paul Chapalain
Hi José, Look at the config of AlfaAriss client and UNSELECT Use anonymous user for outer authentication in Properties. Jean-Paul. José Luis Solano wrote: Hi all!!! I have installed freeradius-snapshot-20040216 with redhat 9. I use AlfaAriss client under Windows XP, cisco pcmcia car on my

Re: Compression

2004-02-20 Thread Alan DeKok
Nick Marino [EMAIL PROTECTED] wrote: What I dont understand is why people post negative remarks to people when they ask any question. Is that not the purspose of these types of list... The purpose of the list is to help people who are willing to do some work. Many people post questions

Re: Authenticate with NIS group

2004-02-20 Thread Alan DeKok
JAMIE CRAWFORD [EMAIL PROTECTED] wrote: Anyone authenticate users from a NIS group? For example johndoe is a member of the RAS group in /etc/group and should be the only one authenticated. The unix module can do this. See the Group attribute. Ive read in the archives of people doing this,

RE: AlfaAriss Client Heeeeeeeeeeeeelp!!!!!!!

2004-02-20 Thread Tom Rixom
Hello, If your LDAP back-end uses encrypted passwords certain authentication methods cannot be used as they PEAP-EAP-MSCHAPV2 for example requires either clear-text passwords or Microsoft NT HASH passwords. I am not sure about LDAP. Because SecureW2 1 sends over the password in the clear it

RE: AlfaAriss Client Heeeeeeeeeeeeelp!!!!!!!

2004-02-20 Thread Tom Rixom
Sorry about the previous email wasn't awake yet... here is a repost: Hello, If your LDAP back-end uses encrypted passwords certain authentication methods cannot be used. PEAP-EAP-MSCHAPV2 for example requires either clear-text passwords or Microsoft NT HASH passwords. I am not sure about

Account Interim

2004-02-20 Thread apellido
how do i enable account interim? what i should include in sql.conf query?

Port limit concurrency checks, wholesale accounting, and dealing with dead servers

2004-02-20 Thread Troy Settle
I've searched a bit on this, but am coming up empty handed so far. Can anyone point me in the right direction for enforcing port-limit as passed by the home server? I've come to the conclusion that depending on my wholesale customers to enforce concurrency limits is not getting me very far.

Account Interim

2004-02-20 Thread apellido
how do i enable account interim? what i should include in sql.conf query?

Re: Problem in Radius Proxy during FailOver --

2004-02-20 Thread Chris Brotsos
On Feb 20, 2004, at 6:41 AM, Alan DeKok wrote: Sudhagar Chinnaswamy [EMAIL PROTECTED] wrote: The failover doesn't work if the synchronous parameter is set to yes. Can someone explain this behaviour ? It's probably a bug in the server. I don't think that configuration has been well tested.

Re: dialup-admin and postgresql

2004-02-20 Thread Guy Fraser
[EMAIL PROTECTED] wrote: It would be nice to compile set of modifications needed for dialup_admin to work with postgresql. (Of course it would be even better that code is db independent :-) ) e.g. user_finger.php3 won't work because SELECT DISTINCT

Re: Access-Reject, how to auth-type - check password inpostgresql

2004-02-20 Thread Guy Fraser
[EMAIL PROTECTED] wrote: On Sat, Feb 14, 2004 at 05:21:17PM +0700, Truong Manh Cuong wrote: Please give me a sample in authorizw section ? or just add sql word into it ? Just add word sql betwen curly brackets of authorize section e.g. authorize { leave everything sql }

Re: Which Auth type with MySQL?

2004-02-20 Thread Guy Fraser
Check the archives, I covered this last week in detail for PostgreSQL, but you are see the same problem in MySQL. You don't need to have an Auth-Type entry in the users file or SQL entries. If you don't include an Auth-Type entry, then User-Password = 'cleartextpassword' and Crypt-Password =

Re: Sql Module doesn't load

2004-02-20 Thread Guy Fraser
Alan DeKok wrote: MaFai [EMAIL PROTECTED] wrote: But It never say Module:sql loaded.,and any other warning message. Of course not. You didn't tell the server *when* to use the SQL module. Go back read radiusd.conf. Look for the word sql. I try to change the user file,set the

Re: AlfaAriss Client Heeeeeeeeeeeeelp!!!!!!!

2004-02-20 Thread Kostas Kalevras
On Wed, 18 Feb 2004, Jean-Paul Chapalain wrote: Hi Alan, Alan DeKok wrote: Jean-Paul Chapalain [EMAIL PROTECTED] wrote: After many tests, for me the only EAP methods that run with Ldap is EAP/TTLS (PAP) (SecureW2 client). I suppose that all other methods use MS-CHAP(LEAP) or

RE: Problem in Radius Proxy during FailOver --

2004-02-20 Thread Sudhagar Chinnaswamy
| On Feb 20, 2004, at 6:41 AM, Alan DeKok wrote: | | Sudhagar Chinnaswamy [EMAIL PROTECTED] wrote: | The failover doesn't work if the synchronous parameter is set to | yes. Can someone explain this behaviour ? | |It's probably a bug in the server. I don't think that | configuration |

RE: Problem in Radius Proxy during FailOver --

2004-02-20 Thread Chris Parker
At 11:23 AM 2/20/2004, Sudhagar Chinnaswamy wrote: | On Feb 20, 2004, at 6:41 AM, Alan DeKok wrote: | | Sudhagar Chinnaswamy [EMAIL PROTECTED] wrote: | The failover doesn't work if the synchronous parameter is set to | yes. Can someone explain this behaviour ? | |It's probably a bug in

RE: user password for LEAP

2004-02-20 Thread GRodriguez
Maybe you could post the initial debug lines to see which users is being matched. One probability is that the default user is being matched, and not the one you have intended, if you are using leap for authentication, and assuming you have a right configuration file for FreeRadius, your line in

SQL Accounting

2004-02-20 Thread Daniel_Baughman
Ok I have the accounting publishing properly to my text files but the database isn't populating with accounting data, how do I tell it to do that? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: SQL Accounting

2004-02-20 Thread Daniel_Baughman
Whats more is the sqltrace file has valid querys. If i execute the querys in the sql trace file with the same account freeradius is using it populates the database just fine. Any suggestions? -- Original Message -- From: Daniel_Baughman [EMAIL PROTECTED]

a bug in the ippool.c

2004-02-20 Thread Anton Blajev
Hello there. I've posted previously before but noone got it as a bug. I'm using freebsd pptp+ppp+freeradius+mysql. I've tryed to setup ippool so I can get a dynamic assigned ips from the radius server. It worked just fine with radtest , I got right answer with the ip addres and all fine. But!

Re: a bug in the ippool.c

2004-02-20 Thread Paul Hampson
On Fri, Feb 20, 2004 at 08:25:08PM +0200, Anton Blajev wrote: Hello there. I've posted previously before but noone got it as a bug. I'm using freebsd pptp+ppp+freeradius+mysql. I've tryed to setup ippool so I can get a dynamic assigned ips from the radius server. It worked just fine with

Re: startup error?

2004-02-20 Thread Paul Hampson
On Fri, Feb 20, 2004 at 10:46:44AM -0700, Ryan Ghering wrote: First I'd like to say hi, new to the freeradius list here. And 2nd like to say thianks in advance for any help that can be provided for the problem below. I have a FreeBSD 5.0 server I've installed the port of freeradius as I

Re: startup error?

2004-02-20 Thread Alan DeKok
Ryan Ghering [EMAIL PROTECTED] wrote: after edited all the configs and getting things setup I get this error = when trying to start the radius server. Fri Feb 20 17:18:36 2004 : Error: /usr/local/etc/raddb/hints[28]: Parse = error (check) for entry DEFAULT: Unknown attribute Prefix ...

Re: a bug in the ippool.c

2004-02-20 Thread Alan DeKok
Anton Blajev [EMAIL PROTECTED] wrote: I took a look at the ippool.c and there is a if statement that returns noop if there is not NAS-Port. I think this should be considered as a bug in freeradius ipool... what would you say guys? The module could possible just use a key to assign IP

Re: Problem in Radius Proxy during FailOver --

2004-02-20 Thread Alan DeKok
Chris Brotsos [EMAIL PROTECTED] wrote: Isn't this actually correct? According to the DOCS, if Synchronous is set to Yes, then all of the other parameters should be set to 0. How will the server 'know' what the retry_delay, retry_count, and dead_time are? The server should have some

Re: a bug in the ippool.c

2004-02-20 Thread Chris Knipe
Anton Blajev [EMAIL PROTECTED] wrote: I took a look at the ippool.c and there is a if statement that returns noop if there is not NAS-Port. I think this should be considered as a bug in freeradius ipool... what would you say guys? The module could possible just use a key to assign IP

Re: a bug in the ippool.c

2004-02-20 Thread Alan DeKok
Chris Knipe [EMAIL PROTECTED] wrote: Slightly OT... But would the same be possible for radutmp? Yes, so long as you never intend to use checkrad.pl. I have tried (unsuccessfully) to use some arbitrary attr-rewrite and those kinda modules to try and force a NAS-Port = whatever, but that

Re: Port limit concurrency checks, wholesale accounting, and dealing with dead servers

2004-02-20 Thread Alan DeKok
Troy Settle [EMAIL PROTECTED] wrote: I've searched a bit on this, but am coming up empty handed so far. Can anyone point me in the right direction for enforcing port-limit as passed by the home server? I don't think you're supposed to enforce it. The NAS is supposed to enforce it. I've

Radius.pm

2004-02-20 Thread Brian Andrus
I am trying to get the Authen::Radius module to do accounting requests with Freeradius to no avail. Has anyone successfully gotten this to work? I keep getting an error from Freeradius: Error: Received Accounting-Request packet from x.y.z.12 with invalid signature! (Shared secret is

LEAP with iPAQ 5450, Cisco 340 Series AP, and freeradius

2004-02-20 Thread Derek Orpen
Hi, I'm having a problem getting LEAP to work with an iPAQ 5450, a Cisco 340 series AP and freeradius. I have PEAP working, but I need to get LEAP working as I need to reproduce a customer's problem. The AP responds correctly to the first challenge sent by freeradius. But freeradius doesn't

Re: required files

2004-02-20 Thread John De Villiers
Both threads.c and radiusd.c get compiled ( the .o file is generated ), but i think its during the linking where things fall over. My guess is that my .h files are located correctly, but then during linking the libraries arent found. Any idea what theyre called and where they should be located

Help with NOT running freeradius as root

2004-02-20 Thread JAMIE CRAWFORD
Hello, Is there anyway to run freeradius NOT as root on rh9.0 when it does pap authentication which needs to read my /etc/passwd and /etc/group files? I uncommented out the user=nobody and group=nobody and then had to chown of /usr/local/var/log/radius.log to nobody to get to start. Now it refuses

Re: Account Interim

2004-02-20 Thread apellido
Hello, ive included Accnt-Interim-Interval in radgroupreply table mysql select * from radgroupreply;++---+---++-+--+| id | GroupName | Attribute | op | Value | prio

Re: LEAP with iPAQ 5450, Cisco 340 Series AP, and freeradius

2004-02-20 Thread Alan DeKok
Derek Orpen [EMAIL PROTECTED] wrote: The AP responds correctly to the first challenge sent by freeradius. But freeradius doesn't seem to know what to do with the challenge from the AP. The AP isn't sending challenges... Sending Access-Challenge of id 231 to 209.47.155.132:1255

Re: AlfaAriss Client question

2004-02-20 Thread Alan DeKok
Hans Fiedler [EMAIL PROTECTED] wrote: I'm using EAP/TTLS and Freeradius with Cisco 1200 access points. When I test from Windows 2000 with a linksys wireless adapter with the AlfaAriss Client everything works OK, but when I use a Cisco 350 adapter everything works OK, except the WEP encryption

Re: required files

2004-02-20 Thread Alan DeKok
John De Villiers [EMAIL PROTECTED] wrote: Both threads.c and radiusd.c get compiled ( the .o file is generated ), but i think its during the linking where things fall over. My guess is that my .h files are located correctly, but then during linking the libraries arent found. I think

Re: Help with NOT running freeradius as root

2004-02-20 Thread Alan DeKok
JAMIE CRAWFORD [EMAIL PROTECTED] wrote: Is there anyway to run freeradius NOT as root on rh9.0 when it does pap authentication which needs to read my /etc/passwd and /etc/group files? That isn't the problem. The problem is the shadow files. See the comments in radiusd.conf on how to set up