Vista Authentication

2007-09-23 Thread Iain Ellis
Hello Are there any known gotcha's concerning Vista clients authenticating? I'm running 1.1.7 with my certificates compiled with xpextensions and I can't get a Vista client to go beyond Sending Access-Challenge when authenticating. XP clients are authenticating OK, just not Vista. I'm

Re: Vista Authentication

2007-09-23 Thread Alan DeKok
Iain Ellis wrote: Are there any known gotcha's concerning Vista clients authenticating? Not that I know of. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Support for SSO Active Directory PEAP-MS-CHAP-v2

2007-09-23 Thread rick wiltshire
Dear All, I need help with dot1x implementation in an Enterprise LAN. Our target is to authenticate and authorize users based on their identities (domain user names) as well as applying GPOs on users. Our authentication Backend is: Active Directory Our Authorization Accounting is done by:

Re: EAP (PEAP) MS-CHAPv2b how to

2007-09-23 Thread Piero Giobbi
Hi riky. I had exactly the same problem, upgrading to 1.1.7 solved my problem (debian package is only at 1.1.3, didn't get Cleartext-Password to work there either). Just upgrade, all of you whos not running 1.1.7!! : ) And why use :=? Not == (more secure)? Thx. On Sep 21, 2007, at

Re: Support for SSO Active Directory PEAP-MS-CHAP-v2

2007-09-23 Thread Alan DeKok
rick wiltshire wrote: All Clients are using WinXP supplicant. I managed to implement PEAPMS-CHAP with this setup however with users who have cached credentials on their PCs. If the user logs on the PC for the first time, he fails to reach the active directory to authenticate since the

Re: EAP (PEAP) MS-CHAPv2b how to

2007-09-23 Thread tnt
And why use :=? Not == (more secure)? Because Cleartext-Password is an internal server attribute that doesn't exist in the request. You are telling the server what's the password, not comparing it with something that is in the request. Ivan Kalik Kalik Informatika ISP - List

[newbie] radutmp question

2007-09-23 Thread Cheng-Lin Yang
Hi all, I have encountered a problem with radutmp. The information of my environment is a vpn service and auth with freeradius 1.1.7. The problem happened as below: 1. start up the radiusd 2. user abc connect to vpn, and I can use radwho to see abc user 3. shutdown radiusd 4. user disconnect from

Re: [newbie] radutmp question

2007-09-23 Thread tnt
Yes. Don't stop the server. ;-) Make sure radutmp is listed in session section of radiusd.conf (it is by default), NAS has the correct nastype in clients.conf and your checkrad script is working (properly). Ivan Kalik Kalik Informatika ISP Dana 23/9/2007, Cheng-Lin Yang [EMAIL PROTECTED]

Re: [newbie] radutmp question

2007-09-23 Thread Doug Hardie
On Sep 23, 2007, at 11:23, Cheng-Lin Yang wrote: Hi all, I have encountered a problem with radutmp. The information of my environment is a vpn service and auth with freeradius 1.1.7. The problem happened as below: 1. start up the radiusd 2. user abc connect to vpn, and I can use radwho to see

Re: [newbie] radutmp question

2007-09-23 Thread Cheng-Lin Yang
I got it, thank you.But I still wnat to know if this problem happened, is there any way to re-sync the radutmp file? or recheck each user is still online or not? 2007/9/24, [EMAIL PROTECTED] [EMAIL PROTECTED]: Yes. Don't stop the server. ;-) Make sure radutmp is listed in session section of

Re: [newbie] radutmp question

2007-09-23 Thread tnt
But I still wnat to know if this problem happened Read radius.log. If you see a line Ready to process requests. your server (re)started. is there any way to re-sync the radutmp file? Why? You can write an outside script that will poll the access servers, check that info against the radutmp and