Triple Play Service Accouting Suggestion

2007-04-13 Thread ram
Hi all iam planning to deploy DSL Services along with Triple play service I would like to use FreeRadius for my test application/ and performance well going to live environment could some suggest me. is this Free Radius can be used for this kind of application if this supports, can some one

Re: HELP: radtest fails local test

2007-04-13 Thread Jacob Jarick
Freeradius 1.1.3 smb.conf http://pastebin.ca/437671 radius.conf http://pastebin.ca/437670 clients.conf http://pastebin.ca/437668 eap.conf http://pastebin.ca/437667 krb5.conf http://pastebin.ca/437666 How do I configure the users file to authenticate against the AD, the howto I followed says u do

Re: Freeradius + AD2003 Authentication ERROR - Help please !

2007-04-13 Thread Jacob Jarick
ok will try another user, thanks again for the tips allan. On 4/13/07, Alan DeKok [EMAIL PROTECTED] wrote: Jacob Jarick wrote: I start the wireless connection on XP, enter in user and password, freeradius runs the ntlm_auth command but then it spits out this hge message. Its so big the

Re: 1.1.6 crashes on fedora 6

2007-04-13 Thread Jacob Jarick
there could be some libs lurking around, but for the moment I will stick with 1.1.3 until I resolve these authentication issues. My Job depends on it. On 4/13/07, Alan DeKok [EMAIL PROTECTED] wrote: Jacob Jarick wrote: *** glibc detected *** ./sbin/radiusd: double free or corruption ... Its

Re: HELP: radtest fails local test

2007-04-13 Thread Alan DeKok
Jacob Jarick wrote: How do I configure the users file to authenticate against the AD, the howto I followed says u do not need to configure the users file. If you're using PEAP, yes. If you're just using PAP, you need to tell the server what to do. I read the users.txt man page but it wasnt

Re: HELP: radtest fails local test

2007-04-13 Thread Jacob Jarick
smb.conf http://pastebin.ca/437671 radius.conf http://pastebin.ca/437670 clients.conf http://pastebin.ca/437668 eap.conf http://pastebin.ca/437667 krb5.conf http://pastebin.ca/437666 OK, some more googling :P and Ive turned up this intresting howto which I will be trialing:

Re: HELP: radtest fails local test

2007-04-13 Thread Jacob Jarick
Alan, Thanks so much for your advice mate. I got it going finally ! For people out there looking todo a similar setup here is my short mini howto: 1 Install Kerberos 2 Install OpenSSL 3 Install Samba 4 Follow the FreeRadius Tutorial for AD intergration:

Re: HELP: radtest fails local test

2007-04-13 Thread A . L . M . Buxey
Hi, and Ive turned up this intresting howto which I will be trialing: http://deployingradius.com/documents/configuration/active_directory.html yep -the official FreeRADIUS wiki/book combo from Alan D alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: 1.1.6 crashes on fedora 6

2007-04-13 Thread Nicolas Baradakis
Jacob Jarick wrote: *** glibc detected *** ./sbin/radiusd: double free or corruption (fasttop): 0x09f91ca8 *** === Backtrace: = /lib/libc.so.6[0xcbfefd] /lib/libc.so.6(cfree+0x90)[0xcc3550] /usr/local/lib/libltdl.so.3[0x3d55db]

Re: dialupadmin and php5 (was: FreeRADIUS 1.1.6 has been released)

2007-04-13 Thread Nicolas Baradakis
Markus Krause wrote: I just downloaded the 1.1.6 release via ftp and tried to build debian packages on Etch and rpms on SLES10, here is the almost successful story: ;-) Thanks for the feedback. i am not sure, debian etch (released on 8. april) contains both php4 and php5 and i think

Re: log on device directly in priviledged mode

2007-04-13 Thread Bjørn Mork
Molteni Davide [EMAIL PROTECTED] writes: Finally I successfully managed to log into the cisco switch (thanks to your help) using freeradius. Now I want that the radius users can directly enter into enable mode of the cisco device. I set this in the users file test Auth-Type := Local,

Re: LDAP changes between 1.01 and 1.1.5

2007-04-13 Thread Kostas Kalevras
O/H Alan DeKok έγραψε: Ryan Kramer wrote: I SUSPECT something might not be escaped in a manner the MS AD server likes, or maybe just the fact it has any escape sequences built in at all is what is causing it to toss it. No. As I have said already, the problem is that the LDAP

Re: Version 2.0 is a lot closer to reality...

2007-04-13 Thread Michael Mitchell
Arran Cudbard-Bell wrote: Techs will also want to test switches in new installs , and they won't like waiting a day for configuration changes to take effect like users won't like the service going down every hour , although we could stagger the server restarts In reality I expect

Re: assigning vlan based on NAS and LDAP field?

2007-04-13 Thread Kostas Kalevras
O/H Matt Ashfield έγραψε: HI all, We're using FR authenticating against LDAP to implement our wireless solution. Basically, we are looking at the LDAP field of record type and determining if it is a staff or a student, and assigning a vlan based on that. Pretty simple and it works. However,

Generating new EAP demo certs for freeradius

2007-04-13 Thread Andrea.Boo
Hi I have just install the package of freeradius using yum which is available for fedora 6. However, I found that the demo cert in the server for EAP is expired and can't be installed on my client. I'm trying to generate a new cert by using the script cert.sh. However, it seems that the package

Re: Segmentation fault on sigHUP

2007-04-13 Thread Kostas Kalevras
O/H Alan DeKok έγραψε: Milan Holub wrote: - we are keeping NAS entries in DB. Then the server should re-load them via reading the DB. - these entries are edited by operation guys via web interface - when a new NAS entry is added then we need to reload/restart freeradius

Re: LDAP changes between 1.01 and 1.1.5

2007-04-13 Thread Phil Mayers
the problem is with the groupmembership_filter. It contains the Ldap-UserDn attribute which gets xlated and escaped: (|((objectClass=GroupOfNames)(member=%{Ldap-UserDn}))((objectClass=GroupOfUniqueNames)(uniquemember=%{Ldap-UserDn}))) A DN usually contains commas which get escaped and break

rlm_sql: Bug in stripping output of dynamic strings {sql:...}

2007-04-13 Thread Milan Holub
Hi all, - latest CVS head - mysql Ver 14.7 Distrib 4.1.8, for pc-linux-gnu (i386) - FreeRADIUS Version 2.0.0-pre0, for host i386-pc-linux-gnu, built on Apr 13 2007 at 10:11:51 I'm using dynamic variables like {sql:sql statement} throughout my configuration to fetch data from the DB. For

Re: Segmentation fault for SNMP query

2007-04-13 Thread Milan Holub
Hi Kevin, On Thu, Apr 12, 2007 at 06:19:14PM -0400, Kevin Bonner wrote: Try http://bugs.freeradius.org/show_bug.cgi?id=150 I doubt that patch will still apply cleanly due to the many recent changes. I'll see if I can test the CVS head later today and submit a newer patch. It surprises

access-accept with exception

2007-04-13 Thread Wael ELLOUZE
Hello, My freeradius verify the login, password and all other attributes. My question is : Is it possible to access-accept all authentication that come with the attribute called-station-id= and how to do this exception Thanks in advance for your reply. - List info/subscribe/unsubscribe?

SNMP with 1.1.6 and Net-SNMP 5.3

2007-04-13 Thread Stefan Winter
Hi, trying for the first time to get SNMP working, and I have come to a point where I'm really startled why stuff doesn't work. I've configured FreeRADIUS 1.1.6 with SNMP, and it's printing out that it is starting up the SMUX connection. Then the snmpd refuses the SMUX connection. This would

Re: Generating new EAP demo certs for freeradius

2007-04-13 Thread Jacob Jarick
I downloaded the latest FR, compiled but didnt install then used the script to generate the needed certs, worked fine. On 4/13/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Hi I have just install the package of freeradius using yum which is available for fedora 6. However, I found that the

glibc double free or corruption still happening

2007-04-13 Thread Roberto Greiner
Hi, I've installed FreeRadius 1.1.6 to my Debian Etch box, trying to solve the 'glibc double free or corruption', but the error is still happening. To make sure that no old library was causing the problem, I searched for any file and folder which could be from the old freeradius (using locate

Re: glibc double free or corruption still happening

2007-04-13 Thread Nicolas Baradakis
Roberto Greiner wrote: I've installed FreeRadius 1.1.6 to my Debian Etch box, trying to solve the 'glibc double free or corruption', but the error is still happening. To make sure that no old library was causing the problem, I searched for any file and folder which could be from the old

Re: glibc double free or corruption still happening

2007-04-13 Thread Alan DeKok
Roberto Greiner wrote: I've installed FreeRadius 1.1.6 to my Debian Etch box, trying to solve the 'glibc double free or corruption', but the error is still happening. I'de love to know where it's coming from. I ran it on my system, and under valgrind, and say nothing. To make sure that

Re: SNMP with 1.1.6 and Net-SNMP 5.3

2007-04-13 Thread Kevin Bonner
On Friday 13 April 2007 08:53:26 Stefan Winter wrote: Hi, trying for the first time to get SNMP working, and I have come to a point where I'm really startled why stuff doesn't work. I've configured FreeRADIUS 1.1.6 with SNMP, and it's printing out that it is starting up the SMUX connection.

online users

2007-04-13 Thread Mordor Networks
i want to know how many user logged in mysql database/radius but it only show the number of user in my databse for example is says 61 logged out and 0 login so here is the problem //login users from// $login_users = ; what i have to write here ? which table i have to query? how i can fix that

Re: glibc double free or corruption still happening

2007-04-13 Thread Jacob Jarick
have u tried this which was suggested by Nicolas Baradakis [EMAIL PROTECTED] You could try to use the libltdl from Fedora instead of the one from the FreeRADIUS sources. $ ./configure --with-system-libtool On 4/13/07, Alan DeKok [EMAIL PROTECTED] wrote: Roberto Greiner wrote: I've

Re: assigning vlan based on NAS and LDAP field?

2007-04-13 Thread [EMAIL PROTECTED]
Message du 13/04/07 à 11h43 De : Kostas Kalevras A : [EMAIL PROTECTED], FreeRadius users mailing list Copie à : Objet : Re: assigning vlan based on NAS and LDAP field? O/H Matt Ashfield έγραψε: HI all, We're using FR authenticating against LDAP to implement our wireless

Re: glibc double free or corruption still happening

2007-04-13 Thread Roberto Greiner
Nicolas Baradakis wrote: Roberto Greiner wrote: I've installed FreeRadius 1.1.6 to my Debian Etch box, trying to solve the 'glibc double free or corruption', but the error is still happening. To make sure that no old library was causing the problem, I searched for any file and folder

Re: glibc double free or corruption still happening

2007-04-13 Thread Roberto Greiner
Roberto Greiner wrote: Nicolas Baradakis wrote: Roberto Greiner wrote: I've installed FreeRadius 1.1.6 to my Debian Etch box, trying to solve the 'glibc double free or corruption', but the error is still happening. To make sure that no old library was causing the problem, I

Re: online users

2007-04-13 Thread tnt
SELECT COUNT(*) FROM radacct WHERE AcctStopTime=0 That will give you the number of currently logged in users (according to the database). Ivan Kalik Kalik Informatika ISP Dana 13/4/2007, Mordor Networks [EMAIL PROTECTED] piše: i want to know how many user logged in mysql database/radius but it

RE: online users

2007-04-13 Thread Alex M
Be careful with\ just SQL Count (*) Some times NASes terminate local session without radius session termination (ex: nas was powered off) in this case you may have some users who technically logged in but that is not true! To avoid that you can select all users in the interwal between Current time

Re: online users

2007-04-13 Thread Mordor Networks
hi ivan thank you for your reply it tried this : $requet = SELECT COUNT(*) FROM radcheck WHERE AcctStopTime=0; $login_users = $requet and $login_users = SELECT COUNT(*) FROM radcheck WHERE AcctStopTime=0; still 0 , what im doing wrong? - List info/subscribe/unsubscribe? See

Re: online users

2007-04-13 Thread Graham Beneke
You need to be querying to radacct table - that is where you would find information on sessions. radcheck is generally only the static data regarding the users on your system. regards Graham Beneke Mordor Networks wrote: hi ivan thank you for your reply it tried this : $requet = SELECT

Re: online users

2007-04-13 Thread Mordor Networks
hi Graham yes sir i know but my question is how to do that im all new to all this.. thank you - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

WEP only client

2007-04-13 Thread Ian Truelsen
I have a client whose wifi adaptor (Linksys WUSB11) can only do wep key encryption and I was wondering whether it would be possible to use eap-tls or something similar given the restrictions. What is the most secure system that can be used with this type of adaptor? -- Ian Truelsen s/v Sting

Re: WEP only client

2007-04-13 Thread Stepan R.
Ian Truelsen wrote: I have a client whose wifi adaptor (Linksys WUSB11) can only do wep key encryption and I was wondering whether it would be possible to use eap-tls or something similar given the restrictions. What is the most secure system that can be used with this type of adaptor?

Re: rlm_sql: Bug in stripping output of dynamic strings {sql:...}

2007-04-13 Thread Alan DeKok
Milan Holub wrote: Unfortunately I'm getting the output stripped by last character(byte): instead of getting 37 for session_count I get 3, instead of getting 1563 for noresetcounterflat I get 156, instead of getting S3H for product_code I get S3. When the query returns 1 character I get empty