Re: Release date for 1.1.0/CVS?

2005-08-19 Thread Alexander Serkin
Alan DeKok wrote: Wesley Spadola [EMAIL PROTECTED] wrote: Is there any news of a approximate release date for the 1.1.0 line of FreeRADIUS? When it's ready. Hopefully in the next month or so. will there be a feature of configurable key for rlm_ippool database search? Which bugs

EAP OTP

2005-08-19 Thread Juan Daniel Moreno
Hello everyone, I am interested in EAP protocols with OTP (one time password). I would like to configure my freeradius 1.0.4 to be able to authenticate passwords which has been created with Shawan's method and an external key. Can anybody help me? Thank you, Juan Daniel MORENO - List

Re: FR suddenly doesn't respond any more and eats all cpu

2005-08-19 Thread Benedikt Panzer
Hello again, this time the error (you know, no response and full cpu load) occured and at least I found something in the normal logfile: Fri Aug 19 09:22:02 2005 : Error: rlm_ldap: All ldap connections are in use Fri Aug 19 09:22:03 2005 : Error: rlm_ldap: ldap_search() failed: Timed out

Required Clarification

2005-08-19 Thread raghavendra.sadaramachandra
Hi All, As I am using freeRADIUS I would like to know few of the following things. 1) What is the maximum length of username and password allowed in freeRADIUS ? 2) What is the maximum number of users allowed to authenticate? I mean, how many users does it maintains in its

RE: mod_auth_radius values

2005-08-19 Thread Ayres G.J.
Hi, I have written a php script that lists the request and response headers, the result of which is below: Request Headers Accept: */* Accept-Language: en-gb Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) Host: xx Connection:

Re: Required Clarification

2005-08-19 Thread Benedikt Panzer
Hello, I'm not really experienced with FR, but maybe this is enough to help you. 3) How does it maintains database does it uses SQL, if so ? whether it provides any alternative to maintain database of username and password ? for example like by using files….. etc. FR is able to store

[solution] Received unexpected tunneled data after successful handshake

2005-08-19 Thread Waba
Hello, I was stuck for a bit on this error message before finding the solution, so I thought I'd share and get it into the list archives for future reference. Context: Trying to get WindowsXP 802.1X supplicants to be authenticated on a FreeRADIUS server. After a successful TLS handshake, the

Re: FR suddenly doesn't respond any more and eats all cpu

2005-08-19 Thread Benedikt Panzer
Hi, I really enjoy answering to myself ;-) I found the problem is not on the ldap server side but really in FR (configuration?). And it's a matter of the number of RADIUS requests: two clients quering FR at the same time don't cause problems for me, but when three clients query it FreeRADIUS

Re: FR suddenly doesn't respond any more and eats all cpu

2005-08-19 Thread Nicolas Baradakis
Benedikt Panzer wrote: Also I tested the switch -s and just the same, the error doesn't occur then. Back in normal mode (without -x or -s) FR crashes again, with one of both switches it doesn't. Strange to me. Is this normal for you experts? I have no idea what's causing the problem. You

Re: mod_auth_radius values

2005-08-19 Thread Alan DeKok
Ayres G.J. [EMAIL PROTECTED] wrote: Ive read through mod_auth_radius-2.0.c and it appears the cookie is a MD5 hash of the users information. So, is it possible to get the information from the cookie? No. The username/password IS in the header. Alan DeKok. - List

Re: FR suddenly doesn't respond any more and eats all cpu

2005-08-19 Thread Alan DeKok
Benedikt Panzer [EMAIL PROTECTED] wrote: Fri Aug 19 09:22:02 2005 : Error: rlm_ldap: All ldap connections are in use Fri Aug 19 09:22:03 2005 : Error: rlm_ldap: ldap_search() failed: Timed out while waiting for server to respond. Please increase the timeout. It looks like your LDAP server

radius cache?

2005-08-19 Thread Tariq Rashid
hi - i wonder what people's thoughts are on a radius cache that sits in frotn of a set of real radius servers and responds quickly with a set of cached reply attributes from a previous query? this may even be worthwhile even if the caching only applies to rejected queries - so that bad requests

Re: Issues authenticating vs 2003 AD

2005-08-19 Thread Tim P
I have read the docs, maybe I am just missing where there example was, I see the entries commented but not for what I need I guess (or I missed). I have reconfigured radiusd.conf again to see it I can authenticate and am still having trouble Can you look at these configs and tell me where you

Re: FR suddenly doesn't respond any more and eats all cpu

2005-08-19 Thread Benedikt Panzer
Hello, I have no idea what's causing the problem. You might try with the option '-f' too, like in bug #100. you're right, that really sounds similar. Unfortunately, the switch -f doesn't help me. That's no as bad, since I can use -s or -x. Nevertheless thanks a lot for the hint! best

Re: radius cache?

2005-08-19 Thread Alan DeKok
Tariq Rashid [EMAIL PROTECTED] wrote: i wonder what people's thoughts are on a radius cache that sits in frotn of a set of real radius servers and responds quickly with a set of cached reply attributes from a previous query? In the CVS head, see rlm_caching. It does exactly this. Alan

Re: Issues authenticating vs 2003 AD

2005-08-19 Thread Alan DeKok
Tim P [EMAIL PROTECTED] wrote: I have reconfigured radiusd.conf again to see it I can authenticate and am still having trouble Can you look at these configs and tell me where you see issues? The client is doing CHAP. You have configured the MSCHAP module to use ntlm_auth. CHAP is not

Re: freeradius 1.0.4 and Cisco WLSE

2005-08-19 Thread jck-freeradius
On Thu, Aug 11, 2005 at 07:02:19PM -0400, Alan DeKok wrote: [EMAIL PROTECTED] wrote: I am trying to speak between my Freeradius server and a Cisco WLSE. I am seeing EAP timeouts while WLSE is trying to authenticate through Freeradius. Short summary: the supplicant is broken.

Re: freeradius 1.0.4 and Cisco WLSE

2005-08-19 Thread Alan DeKok
[EMAIL PROTECTED] wrote: I am stuck using WLSE. Are there plans on an official fix in Freeradius, to work with whatever is broken in WLSE? As I said: it's changing the EAP ID in a broken way, which means that the AP doesn't add the State attribute from the previous challenge. Fixing

802.1x and LDAP

2005-08-19 Thread Cian Phillips
Greetings. I am extremely green to both 802.1x and radius and am trying to set this system up quickly as students arrive on campus in a couple of weeks so please forgive me if I ask questions that have been answered or exist in the documentation. I need to authenticate windows and osx

Re: FR suddenly doesn't respond any more and eats all cpu

2005-08-19 Thread Thor Spruyt
Nicolas Baradakis wrote: Benedikt Panzer wrote: Also I tested the switch -s and just the same, the error doesn't occur then. Back in normal mode (without -x or -s) FR crashes again, with one of both switches it doesn't. Strange to me. Is this normal for you experts? I have no idea what's

Re: 802.1x and LDAP

2005-08-19 Thread Thor Spruyt
Cian Phillips wrote: Many of the settings are the default. The settings I have changed have been from several online tutorials none of which talked about both 802.1x and LDAP. Seems to me you didn't search well enough... http://www.google.com/search?hl=nlq=freeradius+802.1x+ldap+howto --

freeradius 1.0.4 and Cisco WLSE

2005-08-19 Thread M.McNeil
Hello, I am having an issue getting Cisco's WLSE 2.11 to successfully authenticate with FreeRadius 1.0.4. I read where Alan DeKok stated that the supplicant is broken, and was wondering if this is something Cisco has to fix with the WLSE? or is there a way for me to fix the supplicant?

Re: 802.1x and LDAP

2005-08-19 Thread Cian Phillips
Sorry, I should have mentioned the pages I have already tried to follow. http://www.bughost.org/ipw/docs/freeRadius_configuration_HOWTO.TXT http://www.kevan.net/cisco_freeradius_tls_peap_auth.php http://mattzz.dyndns.org/twiki/bin/view/Projects/ FreeRadiusAuthentication

Re: 802.1x and LDAP

2005-08-19 Thread Alan DeKok
Cian Phillips [EMAIL PROTECTED] wrote: With each of these I still have the problem where the Access-Request packet doesn't contain a User-Password attribute. I am guessing that there is something very fundamental that I am not understanding.. like there isn't supposed to be a

FR with MySQL. Proxying and repeated entries

2005-08-19 Thread Paolo Rotela
Hi. Sorry if this is a dumb thing, but I've searched a lot and din't find any solution to this problem. I'm using freeradius (versions 0.9.3, 1.0.0 and 1.0.4) with MySQL 3.23 and 4.1.7 (different mappings between FR and My) I have some clients to wich I'm proxying requests to some realms.

Re: Issues authenticating vs 2003 AD

2005-08-19 Thread Alan DeKok
Tim P [EMAIL PROTECTED] wrote: I understand you have said that repeatedly what I am asking is where is that chap coming from? As I've also said repeatedly, the client sends the authentication request to the server, and the server does not, and can not control what authenticate type the client

Re: FR with MySQL. Proxying and repeated entries

2005-08-19 Thread Alan DeKok
Paolo Rotela [EMAIL PROTECTED] wrote: With this one, Access-* packets go OK, but when the NAS (Cisco AS5300) sends an Accounting-Request to that realm and I proxy it to the home server, it sends me an Accounting-Response with an (I think) irregular attribute: Message-Authenticator (Ext.

Re: 802.1x and LDAP

2005-08-19 Thread Kris Benson
FreeRadius users mailing list freeradius-users@lists.freeradius.org on August 19, 2005 at 10:54 -0800 wrote: With each of these I still have the problem where the Access-Request packet doesn't contain a User-Password attribute. I am guessing that there is something very fundamental that I am

Bug #256 should go into 1.0.5

2005-08-19 Thread Thor Spruyt
http://bugs.freeradius.org/show_bug.cgi?id=256 It's a really big mistake and only a 1-line change! -- Groeten, Regards, Salutations, Thor Spruyt M: +32 (0)475 67 22 65 E: [EMAIL PROTECTED] W: www.thor-spruyt.com www.salesguide.be www.telenethotspot.be - List info/subscribe/unsubscribe? See

Re: EAP OTP

2005-08-19 Thread Alan DeKok
Juan Daniel Moreno [EMAIL PROTECTED] wrote: I am interested in EAP protocols with OTP (one time password). FreeRADIUS doesn't support EAP-OTP. As always, patches are welcome. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Release date for 1.1.0/CVS?

2005-08-19 Thread Alan DeKok
Alexander Serkin [EMAIL PROTECTED] wrote: will there be a feature of configurable key for rlm_ippool database search? It's already in the CVS head, so yes. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FR suddenly doesn't respond any more and eats all cpu

2005-08-19 Thread Alan DeKok
Benedikt Panzer [EMAIL PROTECTED] wrote: Then I started to enable debugging mode again (-x) and noticed, that FR doesn't crash any longer! It sounds like something in the server is failing to deal with threading issues properly. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Bug #256 should go into 1.0.5

2005-08-19 Thread Alan DeKok
Thor Spruyt [EMAIL PROTECTED] wrote: http://bugs.freeradius.org/show_bug.cgi?id=256 It's a really big mistake and only a 1-line change! The program isn't in 1.0.5. I've added the patch to the CVS head. Alan DeKok. - List info/subscribe/unsubscribe? See

Howto make eap-peap accounting

2005-08-19 Thread freeradius
Hello all How to make freeradius support eap-peap accounting Thanks you. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

mysql troubles

2005-08-19 Thread Lewis Bergman
Versions: FreeRADIUS Version 1.0.4, for host , built on Aug 19 2005 at 12:44:42 mysql Ver 14.7 Distrib 4.1.12, for pc-linux-gnu (i686) using readline 4.3 mysql server version: 4.1.12-max Trouble: Per FAQ, started with the simple plain users file auth, which works. Moved to mysql which does not.