clients.conf storage in ldap

2004-11-22 Thread eric german
hi , I m playing with freeradius and openldap . I ll manage all my radius system on ldap. I made a perl script whi reads radiusd.conf and rewrites on fly the clients.conf file . For this I added a new objectclass RadiusClient on my onpenldap . Do you kmow if somebody works in the same direction

Re: extendedKeyUsage = 1.3.6.1.5.5.7.3.1

2004-11-22 Thread Rok Papez
Hello Bilal. Dne petek 19 november 2004 09:02 je Bilal Shahid napisal(a): I am using FreeRADIUS to authenticate the XSupplicant using EAP-TLS. The certificates are being generated using the script CA.all. For the Server certificate, the TLS Web Server OID used is 1.3.6.1.5.5.7.3.1. Now

Bandwidth management Cisco

2004-11-22 Thread EROS
Thx for you answer it is very nice. But I don't know how to activate the virtual template feature on freeradius. By default it is activate on Cisco Secure ACS. Could you tell me ? sincerly -Message d'origine- De : [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] De la part de Andrea

Re: Realmbased Relaying

2004-11-22 Thread Nils Rønhovde
On Thu, 18 Nov 2004 16:12:51 +0200 (EET) Kostas Kalevras [EMAIL PROTECTED] wrote: On Wed, 17 Nov 2004, jesk wrote: Hello again, i have question about Relaying Accounting Data. We have a customer, which want to have all related accounting data of his realm. Is there a way to relay the

Re: Compile problem of last CVS version on FreeBSD 4.x

2004-11-22 Thread frad-u
Current CVS version also cannot be built on FreeBSD. Is where any way to fix the problem? Friday, November 19, 2004, 5:41:56 PM, [EMAIL PROTECTED] wrote: fuanr Tried on two FreeBSD 4.x box fuanr #gmake fuanr gmake[1]: Entering directory `/root/src/radiusd' fuanr Making all in libltdl... fuanr

Unicode

2004-11-22 Thread Josh Howlett
Does FreeRADIUS support Unicode? best regards, josh. -- --- Josh Howlett, Networking Digital Communications, Information Systems Computing, University of Bristol, U.K. 'phone: 0117 928 7850 email: [EMAIL PROTECTED]

Re: Bandwidth management Cisco

2004-11-22 Thread Kostas Kalevras
On Mon, 22 Nov 2004, EROS wrote: Thx for you answer it is very nice. But I don't know how to activate the virtual template feature on freeradius. By default it is activate on Cisco Secure ACS. The virtual template is something you configure on the cisco not freeradius Could you tell me ? sincerly

Re: clients.conf storage in ldap

2004-11-22 Thread Kostas Kalevras
On Mon, 22 Nov 2004, eric german wrote: hi , I m playing with freeradius and openldap . I ll manage all my radius system on ldap. I made a perl script whi reads radiusd.conf and rewrites on fly the clients.conf file . For this I added a new objectclass RadiusClient on my onpenldap . Do you kmow

hyperthreading on freebsd for freeradius threads

2004-11-22 Thread Tariq Rashid
i know this is a controversial topic but I dont' have a definitive answer. it would seem that using hyperthreading enabled CPUs, one would get slightly better performance from threaded applications such as FreeRadius. the underlying operating systems are freebsd 4.7+ and 5.3 (there was no

Re: Freeradius + MySQL + MD5 passwords

2004-11-22 Thread Kostas Kalevras
On Fri, 19 Nov 2004, Hamilton Vera wrote: Hi masters. I am looking for a tutorial/how-to to set up a radius server using freeradius and Mysql and MD5 passwords. Actually I have a Livingston Portmaster 3 authenticating users on my linux server. The authentication is based on MD5 passwords stored in

freeradius oracle crash

2004-11-22 Thread Nick 'TARANTUL' Novikov
I build freeradius-1.0.1 with rlm_sql_oracle. (Oracle 10g) After some time radius daemon crashed (segfault) Backtrace core file produced this output: #0 0x40154c97 in mallopt () from /lib/libc.so.6 #1 0x40153ef3 in malloc () from /lib/libc.so.6 #2 0x40b4dc1a in sltstidinit () from

Re: rlm_ippool - not releasing ip addresses

2004-11-22 Thread Kostas Kalevras
On Sun, 21 Nov 2004, Paul Hampson wrote: On Sat, Nov 20, 2004 at 10:51:32AM +1030, Mike O'Connor wrote: Thanks for you comments, I used you suggestion as a biases and have found that the accounting stop records do not always have the same port id. This means it does not match correctly and does

Re: COMPILATION ERROR

2004-11-22 Thread Eva Kolega
Janakan, Thanks a lot! It worked! I just deleted rlm_x99_token before configuration and everything was OK. What is more, it didn't complaint about mysql as it used to do before. Best Regards, Eva Kolega NOC - TEI of ATHENS Janakan Rajendran wrote:

Freeradius accounting problem

2004-11-22 Thread Yyc
hi all, I want to get user online time from detail files and calc money spend by user. So My questiong: Must I read acct detail file written by radius server? or There are some existing methods? Thank you. Regards Yyc

how many records in radacct

2004-11-22 Thread Alexander Serkin
Hello, how many records in radacct table do you manage to keep, guys? I see that radius stops working properly after about 15 accounting records in Oracle (9.2.0.4) database or ~3 in PostgreSQL 7.4.6. After that amount accounting records are not written into table and FR (v1.0.1) claims

Re: how many records in radacct

2004-11-22 Thread Thor Spruyt
Alexander Serkin wrote: I see that radius stops working properly after about 15 accounting records in Oracle (9.2.0.4) database or ~3 in PostgreSQL 7.4.6. After that amount accounting records are not written into table and FR (v1.0.1) claims about no DB handles to use. I see this with

RE: how many records in radacct

2004-11-22 Thread Anson Rinesmith
I have 1,736,884 in my current MySQL table. -Original Message- From: [EMAIL PROTECTED] [mailto:freeradius- [EMAIL PROTECTED] On Behalf Of Alexander Serkin Sent: Monday, November 22, 2004 1:11 PM To: [EMAIL PROTECTED] Subject: how many records in radacct Hello, how many records

Re: acct_users - Exec-Program not working

2004-11-22 Thread Marek
Hi Thor, thank you very much for replay, I will try to be more specific. I have freeradius 1.01 working on RedHat 9. It is working accepting users, creating detail files from few Cisco NAS boxes and START and STOP records are inserted into MySQL database. What I would like to do is to update

Re: Compile problem of last CVS version on FreeBSD 4.x

2004-11-22 Thread Alan DeKok
[EMAIL PROTECTED] wrote: Current CVS version also cannot be built on FreeBSD. Is where any way to fix the problem? See the list archives. It's a known problem. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Unicode

2004-11-22 Thread Alan DeKok
Josh Howlett [EMAIL PROTECTED] wrote: Does FreeRADIUS support Unicode? Not really. But sending binary data which just happens to be unicode may work. Alan Dekok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: hyperthreading on freebsd for freeradius threads

2004-11-22 Thread Alan DeKok
Tariq Rashid [EMAIL PROTECTED] wrote: it would seem that using hyperthreading enabled CPUs, one would get slightly better performance from threaded applications such as FreeRadius. Maybe. It all depends. however, there are those that recommend that HTT is not enabled as it reduces

Re: rlm_ippool - not releasing ip addresses

2004-11-22 Thread Mike O'Connor
Hi Paul Thanks for you email. I sat down this weekend and wrote the same type of tool. I find all the ip address which have been left active, read out of the radacct database a closed record for each ip address. Then use radclient to send a radacct stop record for each ip address but change the

Re: Unicode

2004-11-22 Thread Josh Howlett
Alan DeKok wrote: Josh Howlett [EMAIL PROTECTED] wrote: Does FreeRADIUS support Unicode? Not really. But sending binary data which just happens to be unicode may work. Just out of curiousity, what do FreeRADIUS users from places that have non-ASCII characters do about non-Unicode support?

Re: Unicode

2004-11-22 Thread Alan DeKok
Josh Howlett [EMAIL PROTECTED] wrote: Just out of curiousity, what do FreeRADIUS users from places that have non-ASCII characters do about non-Unicode support? Enforce usernames/passwords with ASCII-only characters? It would never do anything that crazy. :) As of 1.0, it will seamlessly

How to setup redundancy against password failure not just users (authorize/authenticate)?

2004-11-22 Thread Laxman Gajbhe
Hi, I need to setup failoverwith unix and ldap systems. In a failover document from freeradius, it seems easy to setup failover for authorize section but no way to specify failover for authenticate section. Once an authorize type is selected it seems that onlysingle authentication can

Re: how many records in radacct

2004-11-22 Thread Alexander M. Pravking
On Mon, Nov 22, 2004 at 10:10:53PM +0300, Alexander Serkin wrote: Hello, how many records in radacct table do you manage to keep, guys? About of 1.3M without any problem. I see that radius stops working properly after about 15 accounting records in Oracle (9.2.0.4) database or ~3 in

Re: How to setup redundancy against password failure not just users (authorize/authenticate)?

2004-11-22 Thread Kostas Kalevras
On Mon, 22 Nov 2004, Laxman Gajbhe wrote: Hi, I need to setup failover with unix and ldap systems. In a failover document from freeradius, it seems easy to setup failover for authorize section but no way to specify failover for authenticate section. Once an authorize type is selected it

RE: how many records in radacct

2004-11-22 Thread mmiranda
On Mon, Nov 22, 2004 at 10:10:53PM +0300, Alexander Serkin wrote: Hello, how many records in radacct table do you manage to keep, guys? About of 1.3M without any problem. Here, exactly 4,657,586, and growing, running on freebsd 4.8 , two 2.4 Ghz, 1024 MB ram , i havent done any tunning,

Unknown attribute Acct-Unique-Session-Id

2004-11-22 Thread Jev
Hi all, I'm getting the error: Unknown attribute Acct-Unique-Session-Id When receiving radius accounting packages. It I understand correctly the Acct-Unique-Session-Id is created by radius internally from the parameters specified for the acct_unique module. I changed the key value for the

Re: No Auth password from XP.

2004-11-22 Thread John Mulkerin
At 01:38 PM 11/21/2004, Sven Juergensen wrote: hi john, how does your entry in the 'users' file look like? i had a similar issue with peap. after i removed the 'auth-type := local' (not sure if this is the proper syntax) from the according user it worked. My looked just like that. I'll try it

Re: Unknown attribute Acct-Unique-Session-Id

2004-11-22 Thread Jev
I added Acct-Unique-Session-Id to my dictionary file, not sure why I didn't do this in the first place. What confuses me is that, It was a straight forward install, and I don't under stand why that attribute was not in the standard dictionary file from the get go... Anyway, working now! -Jev