external script collecting invironment variables

2005-08-22 Thread vicky
Hi all, I'm run a home made script whenever I receive an accounting- start, stop or alive. In the script I get the value of all the attributes set in the environment variables (example : val = getenv(USER_NAME) ). I want to count how many attributes contain no value (or doesn't not exist) so

Re: Acct-Session-Id too long

2005-08-22 Thread Stefan Winter
Hi, but one case as below, i received a long Acct-Session-Id ... and cannot fit into mysql... and problem to update Stop record... should I change column size from char32 to reasonable value ? I had the same problem some time ago and solved it by extending the allowed length for that

Server Certificate for use with Windows PEAP Clients

2005-08-22 Thread Ben Thompson
Hi I'd like to get certificates installed on two of our FreeRADIUS boxes to satisfy the requirements of the Windows built in PEAP client when it does it's Validate server certificate bit. I have read about the requirement for the certificate to include the Server Authentication

Acct-Session-Id too long

2005-08-22 Thread Rohaizam Abu Bakar
Dear all, FreeRADIUS 1.0.4 I'm using mysql to store accounting...especially to check simultaneous-use.. but one case as below, i received a long Acct-Session-Id ... and cannot fit into mysql... and problem to update Stop record... should I change column size from char32 to reasonable value

Re: Re: clients.conf problem

2005-08-22 Thread dev_null
Hello, I tried what you said but the server ignored both localhost 10.20.1.x requests. Could this be a bug in the 20050818 snapshot? The only way it works is when including both and only 10.20.1.0/24 10.20.1.100 but it wont' work if a third client is added. :( - Original Message

RE: How to Disable RADIUS user logins if 'Session-Timeout' falls below 0

2005-08-22 Thread Jaco van Tonder
Use the couter module – it does exactly what you want without triggers etc. Regards Jaco van Tonder   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: 17 August 2005 11:28 AM To: freeradius-users@lists.freeradius.org

Elapsed time billing.

2005-08-22 Thread sean
Hi everyone, Thanks to the advice and help I got from the list I now have a fully working FreeRadius server with MySQL. I can issue user names and passwords for set amounts of time e.g. 1 hour or 24 hours.What I'd like to do is issue names and passwords that will last for passed time e.g. one

Re: clients.conf problem

2005-08-22 Thread Michael Griego
There has been some reworking of the clients code recently in CVS. I haven't looked at it much yet as it was done by Alan, but, as with all of the CVS tree, it's still considered unstable code. --Mike dev_null wrote: Hello, I tried what you said but the server ignored both localhost

PAP configuration problem

2005-08-22 Thread Lee Bobby
hello,everyone, I have written a client which send RADIUS packet to my freeradius server.There is problem about the PAP,like this: .. modcall: group authorize returns ok for request 0 auth: No authenticate method (Auth-Type) configuration found for the request: Rejecting the user auth:

Windows Client Authentification bevore Domain logon

2005-08-22 Thread Krämer Armin
Hi, i sucessfully installed a Radius authentificated Network with EAP-TLS Authentifikation. But I cant get logon to my Domain Controller when themachines boot up.. Ok, I know this Problem is not new, but is there any chance to solve this problem without additional software like AEGIS?? Or is there

Re: mysql troubles

2005-08-22 Thread Lewis Bergman
Alan DeKok wrote: See the rlm_sql documentation. The '==' is a comparison operator. Use ':=' Must have been to late. Thanks again, Alan for your help. The issue is now resolved. -- Lewis Bergman Texas Communications 4309 Maple St. Abilene, TX 79602-8044 325-691-3301 800-299-6962 - List

Re: external script collecting invironment variables

2005-08-22 Thread Alan DeKok
vicky [EMAIL PROTECTED] wrote: I guess it is different when the attribute is sent without a value and when it is not sent at all. I would like to know what value contains in these two cases. Anyone? An attribute which is not in the packet will now exist in the environment variables. An

Re: Server Certificate for use with Windows PEAP Clients

2005-08-22 Thread Alan DeKok
Ben Thompson [EMAIL PROTECTED] wrote: I have read about the requirement for the certificate to include the Server Authentication (1.3.6.1.5.5.7.3.1) OID in the Enhanced Key Usage section and I would like to know if anyone else has had experience of this. Yes. Use it, it works. I have

Re: Elapsed time billing.

2005-08-22 Thread Alan DeKok
sean [EMAIL PROTECTED] wrote: Thanks to the advice and help I got from the list I now have a fully working FreeRadius server with MySQL. I can issue user names and passwords for set amounts of time e.g. 1 hour or 24 hours.What I'd like to do is issue names and passwords that will last for

Re: clients.conf problem

2005-08-22 Thread Alan DeKok
Michael Griego [EMAIL PROTECTED] wrote: There has been some reworking of the clients code recently in CVS. I haven't looked at it much yet as it was done by Alan, but, as with all of the CVS tree, it's still considered unstable code. I did some preliminary tests, but I'll try this case to

Re: Windows Client Authentification bevore Domain logon

2005-08-22 Thread Alan DeKok
=?iso-8859-1?Q?Kr=E4mer_Armin?= [EMAIL PROTECTED] wrote: Hi, i sucessfully installed a Radius authentificated Network with EAP-TLS Authentifikation. But I cant get logon to my Domain Controller when themachines boot up.. Ok, I know this Problem is not new, but is there any chance to solve this

Re: Server Certificate for use with Windows PEAP Clients

2005-08-22 Thread Ben Thompson
On Mon, 2005-08-22 at 12:12 -0400, Alan DeKok wrote: Ben Thompson [EMAIL PROTECTED] wrote: I have read about the requirement for the certificate to include the Server Authentication (1.3.6.1.5.5.7.3.1) OID in the Enhanced Key Usage section and I would like to know if anyone else has had

Re: Database field lengths for radacct and radpostauth

2005-08-22 Thread Alan DeKok
Thor Spruyt [EMAIL PROTECTED] wrote: You don't know the maximum length of the username and password of your roaming partners, but you need to store those as well into the database. The RFC's say that the passwords cannot be longer than 127 characters. But who pays attention to the specs?

Re: Database field lengths for radacct and radpostauth

2005-08-22 Thread Thor Spruyt
Alan DeKok wrote: The RFC's say that the passwords cannot be longer than 127 characters. Submitted bug 270 to correct. -- Groeten, Regards, Salutations, Thor Spruyt M: +32 (0)475 67 22 65 E: [EMAIL PROTECTED] W: www.thor-spruyt.com www.salesguide.be www.telenethotspot.be - List

AW: Windows Client Authentification bevore Domain logon

2005-08-22 Thread Armin Krämer
Okay, thanks for the answert, if anyone knows a client software which is free or cheap and supports this please mail me. I need it for ~300 Clients. Greeting Armin -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Alan DeKok Gesendet: Montag, 22.

More tha one dynamical VLAN.

2005-08-22 Thread Armin Krämer
Hi, i set up an EAP-TLS based Radius Server an want realize dynamical VLANS Port based with a Nortel BAystack 470 48T Switch. Is there any possiblility how i can give more than one VLANID dynamicaly to the switch? Wit one VLAn it works fine, but how can give a second ore third VLAN ID to th P same

Re: More tha one dynamical VLAN.

2005-08-22 Thread Alan DeKok
=?iso-8859-1?Q?Armin_Kr=E4mer?= [EMAIL PROTECTED] wrote: Hi, i set up an EAP-TLS based Radius Server an want realize dynamical VLANS Port based with a Nortel BAystack 470 48T Switch. Is there any possiblility how i can give more than one VLANID dynamicaly to the switch? Wit one VLAn it works

Re: EAP TTLS Certificate - Re-sending Access-Challenge

2005-08-22 Thread Alan DeKok
Michael Poser [EMAIL PROTECTED] wrote: But when i want to authenticate with securew2 or odyssey Client the authentication stopps after the first Access-Request: ... rad_recv: Access-Request packet from host 10.87.80.1:3072, id=151, length=117 Sending duplicate reply to client lancom-ap:3072 -

Re: freeradius 1.0.4 and Cisco WLSE

2005-08-22 Thread Pedro Ribeiro
Hello M.McNeil, I've tried it also, but after upgrade of WLSE to a new version it stopped working. Then I've configured the same AP (AP1231G) that I'm using as WDS master with the local RADIUS server for LEAP authentication and configured FreeRADIUS to proxy all the requests of WDS/WLSE