Re: Res: Res: EAP-TTLS + Post-auth clear password

2007-03-23 Thread Alan DeKok
Erico Augusto wrote: as suggested, I'm working with exec module. radiusd.conf: ... exec { post-auth:User-Password = `%{exec:/usr/local/etc/raddb/jradius.forward}` wait = yes input_pairs = request } ... the content of

Re: PEAP/MSCHAPv2 and WinXP

2007-03-23 Thread Alan DeKok
Damian Davalos wrote: The only way I can get this setup to work, is if I import my root certificate onto my client machine. Otherwise, I get the typical Access-Request and Access-Challenge back and forth. Yes. My question: Is importing the root certificate onto your client necessary

Re: freeradius problem : need help

2007-03-23 Thread satish patel
check radwatch is runing or not is runing then kill radwatch it is for watching radiusd deamon for monitoring radius process elmalhi abdelghani [EMAIL PROTECTED] wrote: what means plaese this : There appears to be another RADIUS server running on the authentication port 1812 and if I typ for

Re: bandwidth and volume limit

2007-03-23 Thread satish patel
u can limit bandwith per users basis i am using cisco AV-pair attributes for limiting bandwidth for users upload and download u can see my document on last posted ans Alan DeKok [EMAIL PROTECTED] wrote: Mathieu Lemaitre wrote: HI all, I'm running freeradius 1.0.2 on a debian stable. For new

There appears to be another RADIUS server running on the authentication port 1812

2007-03-23 Thread elmalhi abdelghani
Hi, what means plaese this : There appears to be another RADIUS server running on the authentication port 1812. what i can do ? and i don´t found process radiud ? output of ps auxf: [EMAIL PROTECTED] radius]# ps auxf USER PID %CPU %MEMVSZ RSS TTY STAT START TIME COMMAND

Re: There appears to be another RADIUS server running on the authentication port 1812

2007-03-23 Thread Stefan Winter
what means plaese this : There appears to be another RADIUS server running on the authentication port 1812. what i can do ? and i don´t found process radiud ? output of ps auxf: Jeez. What a process table. And not at all relevant concerning port usage. try netstat -tunelup which gives

Re: There appears to be another RADIUS server running on the authentication port 1812

2007-03-23 Thread Stefan Winter
Hi, please reply to the list. And if you do contact me personally, my list of preferred languages is German, Luxembourgish, English, French, Spanish. French is fairly low down on this list, and may result in unexpected misunderstandings. Comments inline below. -- rebonjour

RE : There appears to be another RADIUS server runningon the authentication port 1812

2007-03-23 Thread Thibault Le Meur
# netstat -tunelup Aktive Internetverbindungen (Nur Server) Proto Recv-Q Send-Q Local Address               Foreign Address             State       Benutzer   Inode      PID/Program name   [...] udp        0      0 192.168.100.207:1812        0.0.0.0:*                               0

Re: PEAP/MSCHAPv2 and WinXP

2007-03-23 Thread apolyxrono
Hi Damian, I have configured freeradius for PEAP/MSCHAPv2 authentication, no client certificates, with a WinXP supplicant. When i created the certificates i studied these guides : http://www.linuxjournal.com/article/8095 , http://www.linuxjournal.com/article/8151. I copied the server

LDAP + groups problem

2007-03-23 Thread Angel L. Mateo
Hello, We are using freeradius with a ldap backend for my users. We have a few services authenticating against the radius server that need to filter some groups of users For users we have a posix schema: Our users has the posixAccount schema whith its main group in the attribute

freeradius unistalling

2007-03-23 Thread elmalhi abdelghani
Hi, how i can uninstall freeradius, i dont found make uninstall thank´s Abdelghani ELMALHI Devesestr. 1 45897 Gelsenkirchen Deutschland Tel. 00 49 176 65 84 38 50 - Découvrez une nouvelle façon d'obtenir des réponses à

Re : freeradius unistalling

2007-03-23 Thread Eshun Benjamin
make clean == Benjamin K. Eshun - Message d'origine De : elmalhi abdelghani [EMAIL PROTECTED] À : freeradius-users@lists.freeradius.org Envoyé le : Vendredi, 23 Mars 2007, 14h02mn 10s Objet : freeradius unistalling Hi, how i can

Problems with freeradius 1.1.5 (2.0.0) 20070322 with postgresql (SIGHUP = segmentation fault)

2007-03-23 Thread Claudiu Filip
Hello freeradius-users, I'm running Freeradius 20070322 snapshot with postgresql backend. (I tried older versions too) I have 3 questions for you, all related to $subject. Everything is working fine (the radius is getting the nas clients from the database, doing

What is the real meaning and use of cache-size in ippool declaration

2007-03-23 Thread Florin
Hi everyone, FreeRadius 1.0.1 here, the one which comes as standard with RHEL 4. I want to use a whole class B subnet (172.16.0.0/16) in an ippool declaration to assign IP addresses from. Now it is said that the cache-size parameter should be equal to the number of IP addresses in the pool.

Re : freeradius unistalling

2007-03-23 Thread elmalhi abdelghani
hi, but i found always my directory usr/local/etc/raddb regards! Abdelghani ELMALHI Devesestr. 1 45897 Gelsenkirchen Deutschland Tel. 00 49 176 65 84 38 50 - Découvrez une nouvelle façon d'obtenir des réponses à toutes

SUMMARY: ldap groups + freeradius

2007-03-23 Thread Karen R McArthur
Thank you to this list! I am posting snips from my users, radiusd.conf and huntgroup files that work. ** huntgroups ** admin NAS-IP-Address == 192.168.1.1 Session-Timeout = 60, Idle-Timeout = 30 public NAS-IP-Address ==

Re: RE : RE : RE : freeradius, ldap error - HELP ME!

2007-03-23 Thread peppeska
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 peppeska ha scritto: ma script to start pppoe-server is debian:~# cat start-pppoe2.sh #!/bin/bash MAX=250 BASE=10.67.7.1 NAT=10.67.7.0/24 MYIP=193.205.94.13 iptables -A INPUT -i eth0 -s $NAT -j DROP iptables -t nat -A POSTROUTING -s

Re: freeradius unistalling

2007-03-23 Thread Thor Spruyt
There is no uninstall and make clean just cleans the source tree. Use rpmbuild to make an rpm. - Original Message - From: elmalhi abdelghani To: FreeRadius users mailing list Sent: Friday, March 23, 2007 3:48 PM Subject: Re : freeradius unistalling hi, but i found always my directory

Res: Res: Res: EAP-TTLS + Post-auth clear password

2007-03-23 Thread Erico Augusto
- Mensagem original De: Alan DeKok [EMAIL PROTECTED] Para: FreeRadius users mailing list freeradius-users@lists.freeradius.org Enviadas: Sexta-feira, 23 de Março de 2007 3:54:41 Assunto: Re: Res: Res: EAP-TTLS + Post-auth clear password Erico Augusto wrote: All I can say is huh? You

Re: freeradius-1.1.5 and FC4

2007-03-23 Thread Ronaldo Zhou
I encountered the problem, too. On 3/21/07, Goke Aruna [EMAIL PROTECTED] wrote: I installed freeradius-1.1.4 in FC4 and i got all the compilation without error. However, when i tried to run the radiusd in debug mode i got the error below Can someone pls point out my problem to me. Goksie

RE: Re: New Server Build

2007-03-23 Thread Scott Hughes
Alan, The only thing in the database is the userid and password. I put nothing else in. I believe it has to do with my Default Auth-Type setting in the Users file. Thank you, Scott --- Original Message --- From: Alan DeKok[mailto:[EMAIL PROTECTED] Sent: 3/23/2007 1:39:03

RE: Re: New Server Build

2007-03-23 Thread Scott Hughes
Alan, Found the problem. The database was saving the password in some kind of hash instead of clear-text. Once I manually changed the password to clear-text, it I got an Auth-Accept response from the server. Now onto the EAP-TTLS client configurations. Thanks again Alan. Scott ---

What is the real meaning and use of cache-size in ippool declaration [resend]

2007-03-23 Thread Florin
Sorry guys, this is in fact a resend of a previous email, now using Thunderbird in an attempt to avoid sending HTML format message. Hope it'll be OK this time. ~~ Hi everyone, FreeRadius 1.0.1 here, the one which comes as standard with RHEL 4. I want to use a whole class B subnet

[no subject]

2007-03-23 Thread Jeremy Pastin
I am trying to set up EAP-TLS using FreeRadius, and I am using EJBCA to sign my certs. I have been able to get everything to work correctly except the CRL. I have created a directory /usr/local/etc/raddb/certs/crls where I am storing my CRL info. In this directory I have the certificate chain

CRL Signature failure

2007-03-23 Thread Jeremy Pastin
Sorry forgot a subject I am trying to set up EAP-TLS using FreeRadius, and I am using EJBCA to sign my certs. I have been able to get everything to work correctly except the CRL. I have created a directory /usr/local/etc/raddb/certs/crls where I am storing my CRL info. In this directory I

CRL List does not appear to work with Freeradius

2007-03-23 Thread Matt Harlum
Hey guys, I've been using freeradius for a while now, and i want to be able to revoke my certs, however when i have revoked them it can't find the CRL and as such nobody can log in - even people who have certs that are not revoked. i just get the following message, even thugh my crl.pem is