what is the is the encrypt password type?
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Nick
Marino
Sent: Sunday, July 25, 2004 4:17 PM
To: [EMAIL PROTECTED]
Subject: Re: dialup admin replacement
I tried it and no matter what username and password I
Hi,
I'm new to freeradius (and also to radius) and I've sucessfully setup EAP/TTLS
authentication (thanks for this great project). Now I need to be able to do
enforcement rules on my firewall per user basis (not only for authorization,
but also for measurement). Is there a way to get the client
Please download it from here http://www.issa.ps/dialup_admin/stat.tar.gz
Regards
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Johnno
Sent: Sunday, July 25, 2004 3:07 PM
To: [EMAIL PROTECTED]
Subject: Re: dialup admin replacement
I download this and
Same here, is there a way to disable the crypt part of things, I can only
comment out a little, but still cant get it working.
Barry
- Original Message -
From: Nick Marino [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 11:16 AM
Subject: Re: dialup admin replacement
I used the crypt function because all the password will be saved as crypted
password, if not please tell me I will tell you what to change at the
login2.php file
Regards
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Barry
Murphy
Sent: Sunday, July 25,
On Fri, 2004-07-23 at 17:54, Alan DeKok wrote:
Zdenek Pizl [EMAIL PROTECTED] wrote:
I don't know exactly what do I need to search, the optimal version how
to distinguish between groups of EAP/TLS and MAC users would be:
[0-9a-fA-F]{6}-[0-9a-fA-F]{6} Auth-Type := Local
DEFAULT Auth-Type
Amin wrote:
May I join development team of dailup_admin. I wish not to be a competitor
(as I am going to develop AAAadmin) but contributor to dailup_admin also.
i wish you can tell me more of this dmin off the list? i can be a beta
tester
or something more than that, how can i be of help
my guess is stop request packet has not been
received nor acknowledged on portmaster. are you using NTRadping?if yes, try
changing NAS port.
//milver
Hello, im using freeradius-1.0.0-pre3 and
postgresql as database backend.I got this error when implemeting
Simultaneous Use. Just reading
I'm using clear text passwords.
Thanks
Barry
- Original Message -
From: issa rabba' [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, July 27, 2004 5:12 AM
Subject: RE: dialup admin replacement
I used the crypt function because all the password will be saved as
crypted
ok I will
- Original Message -
From: Milver S. Nisay [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 12:33 AM
Subject: Re: dialup_admin (was Re: New Opensource project-AAAadmin )
Amin wrote:
May I join development team of dailup_admin. I wish not to be a
Ok no problem
Go to login2.php
Commet line 32
// $passwd = da_encrypt($passwd,$enc_passwd);
If this not work try this
Commet line 31, and 32
// $passwd = $FF_valPassword;
// $passwd = da_encrypt($passwd,$enc_passwd);
And change line 34
From
if
I want to know where I can find more about the AAAadmin priject
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Amit Gupta
Sent: Monday, July 26, 2004 2:01 PM
To: [EMAIL PROTECTED]
Subject: Re: dialup_admin (was Re: New Opensource project-AAAadmin )
ok I
On Sat, 24 Jul 2004, sarky wrote:
Hello all,
I am looking for a web interface which does what dialup admin does and allows
users to access it via there login/password and get all the information they require
download limits, what they have downloaded and so on.
You are actually describing
On Mon, 26 Jul 2004, Shannon Sariman wrote:
Hi Fellow FreeRadius Users,
I have freeradius-0.9.3 configured with MySQL and experimental modules on a
Linux RH 9.0 machine. I've been pulling my hair out trying to get a definite
working solution with rlm_sqlcounter to restrict dialup user
On Mon, 26 Jul 2004, Amit Gupta wrote:
May I join development team of dailup_admin. I wish not to be a competitor
(as I am going to develop AAAadmin) but contributor to dailup_admin also.
There's no special elite development team which you need to join. You either
send in patches or not.
Hello!
I solved this problem: I changed encryption_scheme from `md5' to `crypt'. ;-}
--
Best regards,
Sergei Koveshnikov.
Hi, im also using freeradius-1.0.0-pre3 + Postgres + pap + md5 without any
problem. Im using DIALUP_ADMIN to create user with md5 password.
- Original Message
Thats great!!!
Now just to add some functionality for a per month basis and bandwidth usage
info.
My users are charged on usage not time.
Barry
- Original Message -
From: issa rabba' [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, July 27, 2004 6:33 AM
Subject: RE: dialup admin
Ok, I will make another template for your uses, and you can change to that
template
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Barry
Murphy
Sent: Monday, July 26, 2004 2:58 AM
To: [EMAIL PROTECTED]
Subject: Re: dialup admin replacement
Thats
I face this problem before, it was Cisco IOS bug, and they fix the it, I
think you have to update your IOS
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Barry
Murphy
Sent: Monday, July 26, 2004 3:36 AM
To: [EMAIL PROTECTED]
Subject: Re: dialup admin
My problem is the poptop pptp server (with debian's ppp) is acting as the
NAS server for my wireless clients, so there is no IOS to update. Not many
people tend to be using pptp with radius and can answer this question.
Barry
- Original Message -
From: issa rabba' [EMAIL PROTECTED]
To:
On Mon, 26 Jul 2004, Gary McKinney wrote:
Kostas,
One thing I have noticed in going through the preceived user intuitiveness
( is that a word?) of the dialup_admin program is the links contained in the
different pages displayed tend to blend into the background and unless a
person using the
Hello all,
Im a newbie to Freeradius and Im
trying to find out how to append a realm to a username if one has not been
submitted based on a particular IP address of a NAS during authentication.
We are presently adding a previously existing domain to authenticate on our
radius server but
Hello,
I am running freeradius 0.9.3. I need to run an external program after
stop record arrives. I pass %{Acct-Unique-Session-Id}, %{User-Name} and
%{Calling-Station-Id} to this external program. according to this
username and callingnumber it does some calculations and should update
radacct
On Mon, Jul 26, 2004 at 10:56:47PM +1200, Barry Murphy wrote:
My problem is the poptop pptp server (with debian's ppp) is acting as the
NAS server for my wireless clients, so there is no IOS to update. Not many
people tend to be using pptp with radius and can answer this question.
Barry
I think development of AAAadmin has kicked discussion on what dialup admin
lacks and what need to be improved
- Original Message -
From: Kostas Kalevras [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 4:25 AM
Subject: Re: dialup_admin functional changes
On Mon, 26
I'm trying to build an rpm on fedora core 1 with the included redhat spec
file but not having much luck. I had to make symlink from
/usr/include/com_err.h - /usr/include/et/com_err.h to get the kerberos
stuff to compile. I also modified the header to include the prerelease
portion:
Name:
MD5
- Original Message -
From: issa rabba' [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 11:05 AM
Subject: RE: dialup admin replacement
what is the is the encrypt password type?
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
I am using md5 which is the default in radius.conf
- Original Message -
From: issa rabba' [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 12:12 PM
Subject: RE: dialup admin replacement
I used the crypt function because all the password will be saved as
crypted
Ok, when save the password at the database what interface you use, do send
the password to the encrypt function do you send a salt with the password?
If yes what is it?
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Nick
Marino
Sent: Monday, July 26,
Actualy I care i dont know about the rest, but i have been using
freeradius/dialup-admin for a while
and development just seem to have stoped on dialup-admin, hence i was loosing hope.
Sarky
Thanx
On Mon, 26 Jul 2004 11:48:05 +0300 (EEST), Kostas Kalevras wrote:
On Sat, 24 Jul 2004, sarky
just curious ..., what's a toddler? ;-)
congrulations from me to :)
regards
On Mon, 2004-07-26 at 14:15 +0100, Graeme Hinchliffe wrote:
On Thu, 2004-07-22 at 22:25, Alan DeKok wrote:
David [EMAIL PROTECTED] wrote:
I saw on the list last week that 1.0.0 was just about ready and I have
On Mon, 2004-07-26 at 09:14, Zdenek Pizl wrote:
On Fri, 2004-07-23 at 17:54, Alan DeKok wrote:
Zdenek Pizl [EMAIL PROTECTED] wrote:
I don't know exactly what do I need to search, the optimal version how
to distinguish between groups of EAP/TLS and MAC users would be:
On Mon, 26 Jul 2004, sarky wrote:
Actualy I care i dont know about the rest, but i have been using
freeradius/dialup-admin for a while
and development just seem to have stoped on dialup-admin, hence i was loosing hope.
1. It never stoped. Have you looked in the Changelog, or in the
I think poptop is able to disconnect the user automatically when the session
is lost.
- Original Message -
From: Barry Murphy [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 12:56 PM
Subject: Re: dialup admin replacement
My problem is the poptop pptp server (with
On Mon, 2004-07-26 at 14:25, Raimund Sacherer wrote:
just curious ..., what's a toddler? ;-)
:) a more mobile/noisey/destructive/stressful version of a baby :)
--
-
Graeme Hinchliffe (BSc)
Core Internet Systems Designer
Zen Internet (http://www.zen.co.uk/)
ICQ 3842605 (link)
Direct:
Hi,
I have freeradius 0.9.3 running with Postgresql database backend.
The only thing the radius checks is the password and then executes an
external script if authentication is ok.
The section in the users file is:
DEFAULT Auth-Type = Local
Exec-Program-Wait =
Might be caused by acct packets for the same sessions coming from different
IP addresses, which causes Client-IP-Address to have a different value.
- Original Message -
From: George Chelidze [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 1:37 PM
Subject:
On Mon, Jul 26, 2004 at 03:58:37PM +0200, Thor Spruyt wrote:
I have freeradius 0.9.3 running with Postgresql database backend.
The only thing the radius checks is the password and then executes an
external script if authentication is ok.
The section in the users file is:
DEFAULT
Follow-up: FreeRADIUS 1.0.0-pre2 seems to compile and install correctly
-Original Message-
From: Willey Kurt D
Sent: Friday, July 23, 2004 4:03 PM
To: [EMAIL PROTECTED]
Subject: x99_rlm.c error
Can anyone shed some light on this error??
Fedora Core 2, FreeRADIUS 1.0.0-pre3
#
Hi,
We are experiencing problems using the huntgroups file with freeradius-1.0.0-pre3.
Please note that the NAS-IP-Address is the same for both
huntgroups ie 217.15.97.19. Using different NAS-IP-Addresses works fine
Huntgroups file is as follows :-
streamgamers NAS-IP-Address ==
maybe a fault of mine for not going through the logs, when i look at patches
or release i always see it the same so i assumed that it is not active.
but now i know and as for an email asking for features never did cause of the above
reason but now i know.
Sarky
On Mon, 26 Jul 2004 16:28:54
Hallo,
We are using Orinoco AP600 accesspoint. This AP can do Radius MAC
Access control and EAP/802.1x Auth control.
The question is how have I configure the FreeRadius server to
distinguish between these two options.
I am not able to get it work. I am trying to distinguish these two cases
in
I haven't noticed it before. The AP sends the MAC in the Calling Station ID.
Tacio
On Monday 26 July 2004 08:11, Tacio Santos wrote:
Hi,
I'm new to freeradius (and also to radius) and I've sucessfully setup
EAP/TTLS authentication (thanks for this great project). Now I need to be
able to do
Got it...
The script has to output ,\n after each pair like so:
Acct-Interim-Interval = 600,
Idle-Timeout = 3600,
Session-Timeout = 171454526
Regards,
Thor.
- Original Message -
From: Paul Hampson [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 4:16 PM
Subject: Re:
Hi Barry,
Would it not be better to contact the maintainer of the pppd for the Debian
distribution and ask him/her why pppd is not sending the stop accounting packet to the
radius server when a connection is dropped (for whatever reason) That would fix
the problem the way it should be
Title: Checking SubjectAltName instead of CN
I've setup freeradius to authenticate users via EAP-TLS. To enforce security I'd like
to check the username contained in the client certificate. Is there a way to do it
based on the SubjectAltName instead of the CN?
The eap.conf knows only
issa rabba' [EMAIL PROTECTED] wrote:
I want to know where I can find more about the AAAadmin priject
The AAAadmin project is NOT part of FreeRADIUS.
Everyone, stop posting AAAadmin questions to this list. It should
have its own list, hosted elsewhere.
Alan DeKok.
-
List
On Fri, 23 Jul 2004, Daniel Epstein wrote:
Greetings all,
We run a freeradius-0.9.3 installation handling authentications for a
number of different NASs on our campus. The RADIUS servers are using
an openldap directory as the primary user credentials store. For a
number of reasons, we
issa rabba' [EMAIL PROTECTED] wrote...
( 1-2 sentences, followed by reams of quoted material. )
Can people PLEASE edit their posts, to NOT include all of the
previous messages in a thread? If you need to see the older
messages, read the archives.
Alan DeKok.
-
List
Hi,
I have a homeserver and a proxyserver running on the same machine, but on
different ports and different compilations (so they're actually independant
of each other).
When I run the homeserver with -X, it prints out the User-Password attribute
of the Access-Request packet, which I think is
Hi,
i've changed the spec for the same reason. You can try it (see
attachment), but you must tar the freeradius sources in directory
..-1.0.0, not - ..-1.0.0-pre3.
Cheers,
Simeon Penev
Dave Weis wrote:
I'm trying to build an rpm on fedora core 1 with the included redhat
spec file but not
On Mon, 26 Jul 2004, Thor Spruyt wrote:
Hi,
I have a homeserver and a proxyserver running on the same machine, but on
different ports and different compilations (so they're actually independant
of each other).
When I run the homeserver with -X, it prints out the User-Password attribute
of
i've changed the spec for the same reason. You can try it (see
attachment),
interesting ... where ?
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
- Original Message -
From: Kostas Kalevras [EMAIL PROTECTED]
On Mon, 26 Jul 2004, Thor Spruyt wrote:
Is there any way to prevent this from happening on the homeserver?
Use EAP-TTLS-PAP,MS-CHAP,CHAP as authentication protocol. That's something
the
client decides though.
In
marco wrote:
i've changed the spec for the same reason. You can try it (see
attachment),
interesting ... where ?
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Here it is:
Summary: High-performance and highly configurable RADIUS server
URL:
In the %files section I have change
# %doc doc/ChangeLog doc/README* todo/ COPYRIGHT INSTALL *
for
%doc %{_docdir}/freeradius-%{version}*/
Le lun 26/07/2004 13:05, marco a crit :
i've changed the spec for the same reason. You can try it (see
attachment),
interesting ... where ?
Hi list,
I didn't find the code related to eap-tls resumed handshake. Can you help me please in
that? I don't know if it is based on openssl resumed handshake of not. It seems not
clear to me.
Sincerely,
Badra
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
How ever it is done using dialup admin. Not sure will have to look through
the code and config files of dialupadmin and see. Not sure where to look.
- Original Message -
From: issa rabba' [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 5:47 PM
Subject: RE: dialup admin
On Jul 26, 2004, at 06:58, Thor Spruyt wrote:
Hi,
I have freeradius 0.9.3 running with Postgresql database backend.
The only thing the radius checks is the password and then executes an
external script if authentication is ok.
The section in the users file is:
DEFAULT Auth-Type = Local
Hi,
I am looking for a simple way for my users to go to a web
page and fill out a request for a cert and then we (admins)
can go to another page, verify the data and sign it. Any
ideas on this - of course with openssl integrated with
freeradius and SQL...
thanks
Kat
-
List
You can set the environment variable MYSQL_UNIX_PORT as follows:
export MYSQL_UNIX_PORT=/usr/mysql/mysql.sock
I'm not sure why the freeradius mysql client doesn't check my.cnf, but I had
the same issue and solved as above.
Regards,
Simon.
---
On Monday 26 July 2004 19:54, Masoud Safi wrote:
Now, I can not figure out where in my system is a reference to
'/var/lib/mysql/mysql.socke It is not in radiusd.conf, or sql.conf.
Any ideas?
well if you cant still find answers, you can try creating a soft link FROM
/var (where the sock file is being created) TO /usr
(where you want it to
I had the same problem (and some others) with the redhat spec file,
and here is what I did to fix it... these are diffs to the 1.0.0pre3
spec file in the redhat directory.
matt
diff freeradius.spec.orig freeradius.spec
5c5
Release: 1
---
Release: pre3
9c9
Source0: %{name}-%{version}.tar.gz
Anyone have a simple smb.conf they are willing to share for a
Samba3-ntlm_auth install incorporated with FreeRADIUS??
THANKS!!
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Poptop does disconnect the user however the radius server doesnt receive a
stop request.
Barry
- Original Message -
From: Thor Spruyt [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, July 27, 2004 1:49 AM
Subject: Re: dialup admin replacement
I think poptop is able to
For those of you (un)lucky enough to be searching for Cisco, PPPoE,
RADIUS, static IP addresses, and the like, here's the skinny.
1. Yes, Virginia, you can do static IP address via RADIUS, Cisco 7206,
and PPPoE for DSL-type applications. At least as of 12.2(24), and
possibly much
On Mon, 2004-07-26 at 10:12, Zdenek Pizl wrote:
We are using Orinoco AP600 accesspoint. This AP can do Radius MAC
Access control and EAP/802.1x Auth control.
The question is how have I configure the FreeRadius server to
distinguish between these two options.
Test for the
Im tried the latest dev of dialup_admin and i got
this warning and it doesnt show groups.
Warning: main(../lib/sql_group_info.php3): failed to open
stream: No such file or directory in
/usr/local/www/data-dist/dialup_admin/htdocs/show_groups.php3 on line
74Warning: main(): Failed
On Tue, 27 Jul 2004, apellido jr., wilfredo p. wrote:
Im tried the latest dev of dialup_admin and i got this warning and it doesnt show
groups.
Warning: main(../lib/sql_group_info.php3): failed to open stream: No such
file or directory in
On Mon, 26 Jul 2004 [EMAIL PROTECTED] wrote:
Hi,
I am looking for a simple way for my users to go to a web
page and fill out a request for a cert and then we (admins)
can go to another page, verify the data and sign it. Any
ideas on this - of course with openssl integrated with
freeradius
Hi,
I'm running poptop + freeradius + mysql and trying
to work out which dictionary file i'd use. I'm wanting to get some additional
info like Disconnect-Cause , tunnel end point etc and don't know if I can use
the Ascend dictionary file for this.
Any help would be appreciated.
Barry
Just update show_groups.php3, same error...
Warning: main(../lib/$config[general_lib_type]/group_info.php3): failed to
open stream: No such file or directory in
/usr/local/www/data-dist/dialup_admin/htdocs/show_groups.php3 on line 74
Warning: main(): Failed opening
find it at http://dmin.sourceforge.net
- Original Message -
From: "Alan DeKok" [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, July 26, 2004 9:22 AM
Subject: Re: dialup_admin (was Re: New Opensource
project-AAAadmin )
"issa rabba'" [EMAIL PROTECTED] wrote:
I want to
Hi,
I am using the Free-Radius Server (version 0.9.3) currently. I am using the
Unix authentication and it is working fine.
I want to use the CRAM authentication for my testing purpose. I searched over
the net and the mailing lists for any documentation. However, I was not able
to get much
74 matches
Mail list logo