Re: Freeradius-Users Digest, Vol 14, Issue 27

2006-06-07 Thread Gilbert Lo
I am on holiday between June 5 to June 9. I will return to my office on June 12. See you soon. Thanks, Gilbert Lo helpdesk at St. George's School - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: multiple Autz-Type

2006-06-07 Thread wekz
Thanks very much Phil. That works, I think it doesn't work in the hints file for the reasons you told me.Now I've got a new problem. I use the radiusGroupName for making the users belong to VLAN1, VLAN2 or VLAN3. So I enable groupmembership_attribute = radiusGroupNamebut I left

Re: Peap/leap/wap

2006-06-07 Thread A . L . M . Buxey
Hi, Does free radius support PEAP/LEAP 802.1x authentication? yes, of course it does. How can i configure it? I'd start by reading the documentation. Then you'd want to plan on how to implement it. make sure the required parts of, eg eap.conf are configured and make sure that the required

Re: multiple Autz-Type

2006-06-07 Thread wekz
OooI think I found the solution: in users-vlan i changed the lines for this DEFAULT ldap1-Ldap-Group==Local Tunnel-Type=VLAN, Tunnel-Medium-Type=6, Tunnel-Private-Group-Id=Local, Fall-Through = No DEFAULT ldap1-Ldap-Group==Invitados Tunnel-Type=VLAN, Tunnel-Medium-Type=6,

Re: Freeradius-Users Digest, Vol 14, Issue 28

2006-06-07 Thread Gilbert Lo
I am on holiday between June 5 to June 9. I will return to my office on June 12. See you soon. Thanks, Gilbert Lo helpdesk at St. George's School - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius-Users Digest, Vol 14, Issue 29

2006-06-07 Thread Gilbert Lo
I am on holiday between June 5 to June 9. I will return to my office on June 12. See you soon. Thanks, Gilbert Lo helpdesk at St. George's School - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Are possible multiple ntdomain realms??????

2006-06-07 Thread wekz
And if they are, what efect has with_ntdomain_hack=yes. Does it affect to all??Well, Hi you all I hope haven't been too direct ;)I'll getting more troubles as I do more complex configurations. I ask this because first I had to authenticate users by machine authentication. The users in this case

One radius and 4 pppoe/pptp servers

2006-06-07 Thread Mordor Networks
Hi allI have a small problem , i have a freeradius server with mysql backend and 3 pppoe server and one pptp server all the NAS'es pppoe/pptp server connect to the same radiusd and same mysql database , so when i add a user for exampe i added a user to server-one and his ip is 192.168.2.100 so

Re: One radius and 4 pppoe/pptp servers

2006-06-07 Thread Joe Maimon
Mordor Networks wrote: Hi all I have a small problem , i have a freeradius server with mysql backend and 3 pppoe server and one pptp server all the NAS'es pppoe/pptp server connect to the same radiusd and same mysql database , so when i add a user for exampe i added a user to server-one

Re: Storing in SQL, Procedure call

2006-06-07 Thread Marko Dinic
I never actually worked with MS SQL, so I'm suggesting methods that do work with other SQL servers. Try the PostgreSQL style : - If the function returns only a return code: SELECT sp_name() - If the function returns rows: SELECT * FROM sp_name(...) -- Best regards, Marko Dinic,

Authentification link with PEAP + PAM + LDAP

2006-06-07 Thread thomas hahusseau
Hello, Finally my boss is not interested in an PEAP authentication due to password and login stocked in clear in the OpenLDAP database, and he doesn't want to use the ntlm_auth to ask a Active Directory Server. So I wonder if that kind of authentication is possible. PEAP(MsCHAP) request --

Re: Storing in SQL, Procedure call

2006-06-07 Thread Troy Settle
Jackie Lau wrote: I tried both suggestions and still no luck. Any other suggestion on how to get a Stored Procedure to work with FreeRadius, unixODBC/FreeTDS and Microsoft SQL Server 2000? For some reason when trying to call a Stored Procedure rlm_sql module is trying to perform a query

Freeradius Simultaneous use and credit time

2006-06-07 Thread rom . diot
Hi, I'm installing an hotspot solution with chillispot + freeradius + openldap. I try to find a way, to limit simultaneous connection on my hotspot so a user can only login once on the same time. Does someone have try and implement this options on his configuration ? Secondly, i want my user can

Re: Freeradius-Users Digest, Vol 14, Issue 30

2006-06-07 Thread Gilbert Lo
I am on holiday between June 5 to June 9. I will return to my office on June 12. See you soon. Thanks, Gilbert Lo helpdesk at St. George's School - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Authentification link with PEAP + PAM + LDAP

2006-06-07 Thread Josh Howlett
On 7 Jun 2006, at 13:07, thomas hahusseau wrote: Hello, Finally my boss is not interested in an PEAP authentication due to password and login stocked in clear in the OpenLDAP database, and he doesn't want to use the ntlm_auth to ask a Active Directory Server. So I wonder if that kind of

ldap and MD5-Challenge

2006-06-07 Thread robiwan
Dear all, My Supplicant is a WinXP-Client, EAP-Type is MD5-Challenge. My Authenticator is a Cisco Catalyst 3750 I try to do a 802.1X Authentication for a user listet in a LDAP-database. When i do a MD5-Challenge it does not work. Do i have a problem with MD5-encrypted passwords? My

RE: peap authentication with active directory

2006-06-07 Thread King, Michael
-Original Message- From: On Behalf Of Kartthik Raghunathan A supplicant ie. win XP machine validates the identity and logon credentials against active directory using peap-mschapv2 randomly ie. every 30 mins or 60 mins. This disturbs the wireless connectivity often and am

Re: Freeradius-Users Digest, Vol 14, Issue 31

2006-06-07 Thread Gilbert Lo
I am on holiday between June 5 to June 9. I will return to my office on June 12. See you soon. Thanks, Gilbert Lo helpdesk at St. George's School - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Error

2006-06-07 Thread Ross Hosman
Hello all, I'm new to using freeradius but I've gone trhough and have read what I can and have googled for my problem and yet i still have not been able to solve it. Whenever I try to start freeradius i get this error. rlm_preprocess: Error reading /etc/raddb/huntgroups radiusd.conf[971]:

Re: Authentification link with PEAP + PAM + LDAP

2006-06-07 Thread Alan DeKok
thomas hahusseau [EMAIL PROTECTED] wrote: So I wonder if that kind of authentication is possible. PEAP(MsCHAP) request -- Freeradius server (extract the hashed password ) There is NO hashed password in MSCHAP. Extraction is IMPOSSIBLE. PAM is used as mediator to permit comparason with

Re: Error

2006-06-07 Thread Alan DeKok
Ross Hosman [EMAIL PROTECTED] wrote: I'm new to using freeradius but I've gone trhough and have read what I can and have googled for my problem and yet i still have not been able to solve it. Whenever I try to start freeradius i get this error. rlm_preprocess: Error reading

Re: ldap and MD5-Challenge

2006-06-07 Thread Alan DeKok
[EMAIL PROTECTED] wrote: I try to do a 802.1X Authentication for a user listet in a LDAP-database. When i do a MD5-Challenge it does not work. Do i have a problem with MD5-encrypted passwords? No. You have NOT configured LDAP to return a clear-text password to FreeRADIUS. Do that, and

Re: SecurID authentication

2006-06-07 Thread David Mitton
Darshak, SecurID uses a proprietary client/server protocol between it's clients and it's authentication servers. That protocol is implemented in a binary DLL (or equivalent on Unix) that is part of the distribution. All our own components use that mechanism to communicate with the auth

modcall[authorize] after Access-Accept

2006-06-07 Thread Ryan Melendez
Hello, I have both the realm and sql modules in my authorize section. After freeradius receives an Access-Accept it processes the authorize section. It is not clear to me why, but I assume this is intentional based on debug messages: Processing the authorize section of radiusd.conf modcall:

Re: modcall[authorize] after Access-Accept

2006-06-07 Thread Alan DeKok
Ryan Melendez [EMAIL PROTECTED] wrote: I have both the realm and sql modules in my authorize section. After freeradius receives an Access-Accept it processes the authorize section. See post_proxy_authorize. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Freeradius-Users Digest, Vol 14, Issue 32

2006-06-07 Thread Gilbert Lo
I am on holiday between June 5 to June 9. I will return to my office on June 12. See you soon. Thanks, Gilbert Lo helpdesk at St. George's School - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius Simultaneous use and credit time

2006-06-07 Thread A . L . M . Buxey
Hi, Hi, I'm installing an hotspot solution with chillispot + freeradius + openldap. I try to find a way, to limit simultaneous connection on my hotspot so a user can only login once on the same time. Does someone have try and implement this options on his configuration ? Secondly, i want

Install - Freeradius can't connect to MySQL

2006-06-07 Thread Cliff Hayes
Hello, Warning - newbie installing Freeradius. I get this in the radius.log even though the sql.conf has the correct host/user/password (and I can access MySQL from the command line using the same login criteria): Wed Jun 7 14:01:52 2006 : Info: rlm_sql_mysql: Starting connect to MySQL server

Re: Are possible multiple ntdomain realms??????

2006-06-07 Thread Phil Mayers
wekz wrote: And if they are, what efect has with_ntdomain_hack=yes. Does it affect to all?? Well, Hi you all I hope haven't been too direct ;) I'll getting more troubles as I do more complex configurations. I ask this because first I had to authenticate users by machine authentication. The

Re: Install - Freeradius can't connect to MySQL

2006-06-07 Thread A . L . M . Buxey
Hi, to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)' does this socket file exist? sounds very much like the classic 'socket not where you expect' issue. eg http://lists.cistron.nl/pipermail/freeradius-users/2004-July/034410.html alan - List info/subscribe/unsubscribe?

Re: Install - Freeradius can't connect to MySQL

2006-06-07 Thread N White
Cliff Hayes wrote: Hello, Warning - newbie installing Freeradius. I get this in the radius.log even though the sql.conf has the correct host/user/password (and I can access MySQL from the command line using the same login criteria): Wed Jun 7 14:01:52 2006 : Info: rlm_sql_mysql: Starting

Segmentation Fault

2006-06-07 Thread Joel Lindsay
Hi, I have been using free radius for months for testing. Today, if just started giving me segmentation faults. Nothing has changed on the NAS or in the configs for freeradius so I have no idea why it suddenly is crashing. Is there some way to track down whats causing the segmentation

RE: Install - Freeradius can't connect to MySQL

2006-06-07 Thread Cliff Hayes
Yes sir, sure does. It is the same as mentioned in /etc/my.cnf I also ran mysqladmin -p version to make sure Cliff -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of [EMAIL PROTECTED] Sent: Wednesday, June 07, 2006 2:42 PM To: FreeRadius users mailing list

RE: Install - Freeradius can't connect to MySQL

2006-06-07 Thread Cliff Hayes
That is correct. Here is an exerpt from sql.conf # Connect info server = localhost login = root password = ***the real password is in the file # Database table configuration radius_db = radius And I have already created the radius database

Re: Freeradius-Users Digest, Vol 14, Issue 33

2006-06-07 Thread Gilbert Lo
I am on holiday between June 5 to June 9. I will return to my office on June 12. See you soon. Thanks, Gilbert Lo helpdesk at St. George's School - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

FW: Install - Freeradius can't connect to MySQL

2006-06-07 Thread Cliff Hayes
Hello again, This may shed some light on the situation. When I run in debug mode with -x option, it looks like it may be connecting. Am I interpreting the output correctly? If so, is it normal to connect 5 times? Cliff Starting - reading configuration files ... Using deprecated naslist file.

More information in the post auth?

2006-06-07 Thread Troy Settle
I'm just about done converting to use freeradius exclusively, but have one more rather daunting task to get done. I need more information for failed logins. What variables are available that will tell me which check item failed and why? For example, if it's the password, how about access

Re: FW: Install - Freeradius can't connect to MySQL

2006-06-07 Thread Chris Carver
According to your output it is definitely connecting. 5 open connections to the mysql db is the default configuration. If you look in etc/raddb/sql.conf you'll see the variable 'num_sql_socks = 5' This is what controls the number of open connections. Chris Carver Network Engineer Cliff

Re: Segmentation Fault

2006-06-07 Thread Alan DeKok
Joel Lindsay [EMAIL PROTECTED] wrote: I have been using free radius for months for testing. Today, if just started giving me segmentation faults. Which version are you running? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: More information in the post auth?

2006-06-07 Thread Alan DeKok
Troy Settle [EMAIL PROTECTED] wrote: What variables are available that will tell me which check item failed and why? Debugging mode, and often not even that. What you're asking for is logging of *every* decision in the server, which is difficult expensive. For example, if it's the

FW: Install - Freeradius can't connect to MySQL

2006-06-07 Thread Cliff Hayes
Here's even more light: When I start freeradius by just typing radiusd on the command line, it connects to MySQL ok. But if I start it like I'm supposed to: service radiusd start, it doesn't. I'm using Fedora 5 with the latest freeradius.i386, freeradius-unixODBC.i386, and

Re: FW: Install - Freeradius can't connect to MySQL

2006-06-07 Thread Chris Carver
This doesn't really help your situation, but I've always thought just typing it on the command line, 'radiusd' or having it started automatically on boot was the way its supposed to be. Its also the way I've always know everyone else to do it too. What exactly does service do any

Re: Freeradius-Users Digest, Vol 14, Issue 34

2006-06-07 Thread Gilbert Lo
I am on holiday between June 5 to June 9. I will return to my office on June 12. See you soon. Thanks, Gilbert Lo helpdesk at St. George's School - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Exec-Program and length of arguments

2006-06-07 Thread Anton Maksimenkov
If I add to users file this: When I used exec-program all the attributes I wanted were in the environment. And how can I exploit it? I get only this: -- $ cat /home/engineer/acrad.sh #!/bin/sh printenv /tmp/exec-program-wait -- bob Auth-Type := Local, User-Password == bob