DHCP configuration on Free Radius

2006-07-13 Thread Elie Hani
Hi; Ive installed the Free Radius on FC4 OS, I need to know if its possible to configure DHCP on this server. I want that the dial up users take an IP from a pool, dynamically configured on the Radius server itself. If its possible, can you tell me the steps, otherwise, can you provide

Re: Segfault when loading a module in rlm_perl?

2006-07-13 Thread Boian Jordanov
On Wednesday 12 July 2006 20:13, Nikola Pavkovic wrote: Hello all, I'm expiriencing strange behaviour when starting freeradius using rlm_perl. When I include any module (for example DBI) inside my custom AAA script, i get a segfault. (Debian sarge, freeradius 1.1.2). Any hints are very

Re: DHCP configuration on Free Radius

2006-07-13 Thread Phil Mayers
Elie Hani wrote: I’ve installed the Free Radius on FC4 OS, I need to know if it’s possible to configure DHCP on this server. I want that the dial up users take an IP from a pool, dynamically configured on the Radius server itself. If it’s possible, can you tell me the steps, otherwise, can

removing domain data from user name

2006-07-13 Thread Yedidia Klein
Hello list, I'm using freeradius server as a radius server that forward the auth to an LDAP server, on a RH enterprise system (freeradius-1.0.1-1.1.RHEL3) I want one of my service providers to authenticate against this radius, After enabling some debug option I found that it sends me the

Re:- Authenticating user with FDS

2006-07-13 Thread Hariharan R
Yes, that method is working fine. Thank you very much for your help. Hariharan R wrote: Hi all, I am using FreeRADIUS1.1.1 with Fedora Directory server as a backend data store. Let us consider the scenario.. I have two servers, one is a mail server and another one is a proxy server.

Re: Segfault when loading a module in rlm_perl?

2006-07-13 Thread Nikola Pavkovic
On Thu, Jul 13, 2006 at 10:41:57AM +0300, Boian Jordanov wrote: On Wednesday 12 July 2006 20:13, Nikola Pavkovic wrote: Any hints are very welcome. Any traces are welcome :-) Boian, but it seems that we resolved the issue following the advices found at

Re: removing domain data from user name

2006-07-13 Thread Phil Mayers
Yedidia Klein wrote: Hello list, I'm using freeradius server as a radius server that forward the auth to an LDAP server, on a RH enterprise system (freeradius-1.0.1-1.1.RHEL3) I want one of my service providers to authenticate against this radius, After enabling some debug option I found

Re: removing domain data from user name

2006-07-13 Thread fvt3
I was able to strip the domain portion of it by having radius execute an external script. Here is what I have in radius to execute the external script.. ldapldap_ldap1 { server = identity = password = #basedn =

Freerad routing problem

2006-07-13 Thread Moustapha Ould Maouloud
Hello, I have in my LAN a ColubrisAccess Conroller (IP: 192.168.10.81, gw: 192.168.10.1/80.B.C.D) which I authenticate on a freeradiusvia Internet (IP offreerad server : 63.E.F.G). My server receives:rad_recv: Access-Request packet from host 80.B.C.D:10901, id=64,

Re: multiple post-auth sql queries, possible?

2006-07-13 Thread Duane Cox
Is it possible to run a module twice in one section... meaning can I run the sql module twice in the post-auth section ? I am thinking I could, but I would have to call it by a new name and then copy the lib files to also this new name. Thanks Duane Cox - Original Message -

RE: multiple post-auth sql queries, possible?

2006-07-13 Thread Jurgen van Vliet
Hi Duane If you use a DB backend that supports stored procedures (like mysql 5) you can make a procedure in your mysql server containing several queries. You can evenuse IF THEN ELSE structures, and call that procedure from post-authas a single query. like : postauth_query = "call

Re: removing domain data from user name

2006-07-13 Thread Yedidia Klein
thanks, this way did it. --yedidia fvt3 wrote: I was able to strip the domain portion of it by having radius execute an external script. Here is what I have in radius to execute the external script.. ldapldap_ldap1 { server = "" identity = ""

rlm_passwd usage

2006-07-13 Thread B Thompson
Hi We used to list all our fifty thousand usernames individually in the users file, but this made it quite large so following advice on this mailing list I decided to use rlm_passwd instead. This seems to work very well and the file size is much smaller. I have configured my passwd style users

Re: rlm_passwd usage

2006-07-13 Thread Alan DeKok
B Thompson [EMAIL PROTECTED] wrote: However, I would now like to restrict access to a particular NAS device to a particular set of users and I am not sure how best to go about this. Create a group, and put those users into that group, also using rlm_passwd. You could add a new file, or

(no subject)

2006-07-13 Thread Robert Dukes
Hello,Has anyone used Freeradius with AlvarionBreezeaccess to do accounting ? I am having a big issue get the theradiustounderstandtherodiosAttribs.Or there other ways to track user traffic. We are in Russia doing a chartity project for Russian Orpahs, So any help to resolve this issues would be a

Re: (no subject)

2006-07-13 Thread Alan DeKok
Robert Dukes [EMAIL PROTECTED] wrote: Has anyone used Freeradius with Alvarion Breezeaccess to do accounting ? I am having a big issue get the the radius to understand the rodios Attribs. Could you be more specific? I have a problem, how do I fix it? doesn't let anyone help you. Alan

Re: (no subject)

2006-07-13 Thread Robert Dukes
Sorry, Ok I use Alvarion Su radios that has radius accountingoption.buttheradiossendsomeVSAthatisnotreconizableintheradius. Breezenet/Breezecom/Alvarion VSA's. These NASs sendEthernet port data in VSAs (up to 11 per accounting request) but unfortunately dont use the same attribute numbers each

Re: (no subject)

2006-07-13 Thread Thor Spruyt
How about adding a dictionary will all 256 numbers? - Original Message - From: Robert Dukes To: FreeRadius users mailing list Sent: Thursday, July 13, 2006 9:26 PM Subject: Re: (no subject) Sorry, Ok I use Alvarion Su radios that has radius accounting option. but the radios send some

Confused about 'hints' file

2006-07-13 Thread Brenckle, Nicholas
I have an entry in the hints file, that when I uncomment, the authentication fails. And I can't figure out why. When/where during the process does the hints file come into play? Im watching everything under debug mode, and I can't figure it out Thank you! - List

Re: Alvarion attributes Re: (no subject)

2006-07-13 Thread Robert Dukes
This really sucks :) We invested so much into the gear here as our project is funding by caring people. So there is no way to get this done ah On 7/14/06, Alan DeKok [EMAIL PROTECTED] wrote: Robert Dukes [EMAIL PROTECTED] wrote: Breezenet/Breezecom/Alvarion VSA's. These NASs send Ethernet

Re: Confused about 'hints' file

2006-07-13 Thread Chris Carver
Brenckle, Nicholas wrote: I have an entry in the hints file, that when I uncomment, the authentication fails. And I can't figure out why. When/where during the process does the hints file come into play? Im watching everything under debug mode, and I can't figure it out Thank you!

Re: Alvarion attributes Re: (no subject)

2006-07-13 Thread Alan DeKok
Robert Dukes [EMAIL PROTECTED] wrote: This really sucks :) We invested so much into the gear here as our project is funding by caring people. So there is no way to get this done ah Try the patch below, which should work in 1.1.x. No guarantees... it just compiles, and I haven't

ntlm_auth - rlm_mschap: No User-Password configured. Cannot create NT-Password.

2006-07-13 Thread Peter de Groot
Please help I cannot see the problem after a day of reading the lists and googling... hopefully a fresh pair of eyes I am trying to authorize to the network via an ntlm_auth lookup against winbind using PEAP and MS-CHAP v2 etc etc Doing an ntlm_auth on the command line returns

Re: ntlm_auth - rlm_mschap: No User-Password configured. Cannot create NT-Password.

2006-07-13 Thread Alan DeKok
Peter de Groot [EMAIL PROTECTED] wrote: I am trying to autheticate against a different domain that than the samba server is joined to.. should be ok ?? Probably not. [EMAIL PROTECTED] raddb]# ntlm_auth --request-nt-key --domain=admin4182 --username=e2052982 password: NT_STATUS_OK:

Crypt-Password Problem

2006-07-13 Thread Gary . Blydenburgh
Excuse me if this has been asked before but I am having a hard time finding it in the archives. I have a script that builds a radius users file out of a htpasswd file, the password entries are encrypted. This worked great on a Redhat Enterprise AS 3 server running freeradius-0.9.3. I have since

Re: Crypt-Password Problem

2006-07-13 Thread Christopher Carver
Quoting [EMAIL PROTECTED]: Excuse me if this has been asked before but I am having a hard time finding it in the archives. I have a script that builds a radius users file out of a htpasswd file, the password entries are encrypted. This worked great on a Redhat Enterprise AS 3 server

Re: Crypt-Password Problem

2006-07-13 Thread Gary . Blydenburgh
[EMAIL PROTECTED] wrote on 07/13/2006 11:06:56 PM: Quoting [EMAIL PROTECTED]: Excuse me if this has been asked before but I am having a hard time finding it in the archives. I have a script that builds a radius users file out of a htpasswd file, the password entries are encrypted.

EAP-TTLS-PAP-LDAP

2006-07-13 Thread Rohaizam Abu Bakar
Trying to do EAP-TTLS-PAP with CRYPT passwd in LDAP.. The tunelling seems fine.. but up to comparing the password it will failed. Refer below logs config Some says (http://felipe-alfaro.org/blog/category/radius/) PAP is tunneled inside EAP-TTLS through EAP-GTC... Tried that as well..

Re: Freeradius-Users Digest, Vol 15, Issue 45

2006-07-13 Thread Kun Niu
But still, you can try as he said.:-( -- Message: 4 Date: Thu, 13 Jul 2006 23:16:35 -0400 From: [EMAIL PROTECTED] Subject: Re: Crypt-Password Problem To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Message-ID: [EMAIL PROTECTED]

ntlm_auth - rlm_mschap: No User-Password configured. Cannot create NT-Password.

2006-07-13 Thread Peter de Groot
eter de Groot [EMAIL PROTECTED] wrote: I am trying to autheticate against a different domain that than the samba server is joined to.. should be ok ?? Probably not. [EMAIL PROTECTED] raddb]# ntlm_auth --request-nt-key --domain=admin4182 --username=e2052982 password: NT_STATUS_OK: