Re: radgroupreply do not read (read_grous directive)

2008-01-15 Thread tnt
OK, can we see database entries for a user (and group he belongs to) and the debug of the access request? Or should I get my crystal ball back from the polisher? Ivan Kalik Kalik Informatika ISP Dana 15/1/2008, Arlinelson Fernandes dos Santos [EMAIL PROTECTED] piše: Yes! I did. And I put

Switch from Static IP to IPpool

2008-01-15 Thread Grant Wright
Hi there Just a question, is this scenario possible from within freeRADIUS or should I just write a script to achieve it. I basically assign the connecting client a static IP address using the Framed-IP-Address attribute. Once he has reached his threshold (Receive-Limit) and gets

Re: Mysql error

2008-01-15 Thread Pablo Lucchetti
I added column im radacct and all it's Ok, thanks for your help. Pablo Marinko Tarlac wrote: Add that column in your radacct table. I had the same problem and it is solved (upgrade to 1.1.7 from 1.1.4 )... Check mysql sample file in sql dir. [EMAIL PROTECTED] wrote: Hi, Hi, I'm

Re: radgroupreply do not read (read_grous directive)

2008-01-15 Thread liran tal
Ivan, While you're at it, can you check up on my forth-coming paperwork grade for Statistics B class? :-) Regards, Liran. 2008/1/15 [EMAIL PROTECTED]: OK, can we see database entries for a user (and group he belongs to) and the debug of the access request? Or should I get my crystal ball

Re: Switch from Static IP to IPpool

2008-01-15 Thread Alan DeKok
Grant Wright wrote: Just a question, is this scenario possible from within freeRADIUS or should I just write a script to achieve it. You should probably write a script. This is not a common policy. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Failed MAKE on SLES10

2008-01-15 Thread liran tal
Hey David, How about trying a more recent FreeRADIUS version? If not, check that your libgdbm library is installed properly. Regards, Liran Tal. On Jan 15, 2008 3:39 PM, David W Bell [EMAIL PROTECTED] wrote: Anyone else seen this, and if so is there an easy fix, or do I need to find an

Failed MAKE on SLES10

2008-01-15 Thread David W Bell
Anyone else seen this, and if so is there an easy fix, or do I need to find an alternative libgdbm.so ? /home/belld/freeradius-1.0.4/libtool --mode=link gcc -release 1.0.4 \ -module -export-dynamic -g -O2 -D_REENTRANT -D_POSIX_PTHREAD_SEMANTICS -DOPENSSL_NO_KRB5 -Wall -D_GNU_SOURCE -DNDEBUG

Re: Failed MAKE on SLES10

2008-01-15 Thread David W Bell
That will teach me for following the advice to just get it from the server freeradius2.0.0 now installing :) Thanks David Hey David, How about trying a more recent FreeRADIUS version? If not, check that your libgdbm library is installed properly. Regards, Liran Tal. On Jan 15, 2008 3:39

Re: Support for RFC4372 (Chargeable User Identity)

2008-01-15 Thread Alan DeKok
Maja Wolniewicz wrote: According to RFC4372 CUI attribute in request can include a single NUL character, then your test if (%{Chargeable-User-Identifier}) { update reply { Chargeable-User-Identifier = } } evaluates to false. I've fixed this in CVS head

alan's book, or anything new on the horizon

2008-01-15 Thread Duane Cox
Hello I wonder if Alan ever released that book that he had talked about in 2006? Or did it become a collection of wiki pages? Is anyone working on a second revision to Hassell's O'Reilly RADIUS? Duane Cox - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: alan's book, or anything new on the horizon

2008-01-15 Thread Alan DeKok
Duane Cox wrote: I wonder if Alan ever released that book that he had talked about in 2006? Or did it become a collection of wiki pages? I'm up to 180 pages. There's more content than the O'Reilly book, by a long shot. However, I moved countries in 2007, and various factors meant I

sqlcounter continue after failed match

2008-01-15 Thread Etienne Pretorius
Hello List, I have managed to get sqlcounter working for tracking the octets in the accounting database. Could someone give me a hint as how I would say allow a user for group 'A' to use up their octets and if the user also belongs to group 'B' to then allow an addtional amount of octets

FW: Help Needed Please freeradius traffic limiting

2008-01-15 Thread Keith Dovale
Regards Keith Dovale http://www.hostworx.co.za/ From: Keith Dovale Sent: Tuesday, January 15, 2008 6:24 PM To: 'FreeRadius users mailing list' Subject: Help Needed Please freeradius traffic limiting Ok I need to do this and if someone could help I would appreciate it as I am

RE: Possible Spam : Low Spam probability - : sqlcounter continue after failed match

2008-01-15 Thread Keith Dovale
Hi Etienne, are you also limiting your users based on traffic usage ? Regards Keith Dovale -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Etienne Pretorius Sent: Tuesday, January 15, 2008 6:30 PM To: FreeRadius users mailing list Subject: Possible

Help Needed Please freeradius traffic limiting

2008-01-15 Thread Keith Dovale
FFs, Lol Hi List, Ok I need to do this and if someone could help I would appreciate it as I am new to this 1. I Need to limit users by traffic and NOT session time (I setup the monthly counters to check but the counters cannot go beyond 2,148,000,000 and they fail I think this

Re: Failed MAKE on SLES10

2008-01-15 Thread Peter Nixon
David You could alway use my nicely rolled SLES10 rpms from: http://ftp5.gwdg.de/pub/opensuse/repositories/network:/aaa/SLE_10/ I go to great lengths to make them. I wonder why more people don't bother using them... -Peter On Tue 15 Jan 2008, David W Bell wrote: That will teach me for

Re: radsqlrelay v1.7 on freebsd 6.3

2008-01-15 Thread David Wood
Hi Roy and everyone, In message [EMAIL PROTECTED], roy [EMAIL PROTECTED] writes Made these changes: line 53 my $FLOCK_STRUCT = 'l2is2'; line 62 my $packed = pack($FLOCK_STRUCT, $start, $len, 0, F_WRLCK, SEEK_SET); Still returns: error: Couldn't lock /home/radius/sql-relay.work: Invalid

eap-mschapv2

2008-01-15 Thread Indira Keesara
Does freeradius support eap-mschapv2 ? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

RE: eap-mschapv2

2008-01-15 Thread Josh Howlett
Yes - although only as a tunelled method inside EAP-PEAP (I think, I may be wrong). josh. -Original Message- From: [EMAIL PROTECTED] org [mailto:[EMAIL PROTECTED] eradius.org] On Behalf Of Indira Keesara Sent: 15 January 2008 20:31 To: freeradius-users@lists.freeradius.org

eap-mschapv2

2008-01-15 Thread Indira Keesara
I am using freeradius to test the eap-mschapv2. According to specs To the access-challenge reply radius should sent a access-success with the mppe keys. But what I see is to the reply radius is sending the access-challenge request again with mschap-success similar to the Eap-tls. I am

RE: eap-mschapv2

2008-01-15 Thread Indira Keesara
I am looking for EAP-MSCHAPv2 not inside the tunneled EAP-PEAP -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Josh Howlett Sent: Tuesday, January 15, 2008 3:34 PM To: FreeRadius users mailing list Cc: Josh Howlett Subject: RE: eap-mschapv2 Yes -

RE: eap-mschapv2

2008-01-15 Thread Indira Keesara
Here is the output Access-request Access-challenge Access-request Access-challenge Access-Request packet from host x.x.x.x port 1812, id=2, length=69 User-Name = user NAS-Identifier = 85 NAS-Port = 118751232 EAP-Message = 0x02090175736572

RE: eap-mschapv2

2008-01-15 Thread Josh Howlett
Post the debug ouput (radiusd -X). josh. -Original Message- From: [EMAIL PROTECTED] org [mailto:[EMAIL PROTECTED] eradius.org] On Behalf Of Indira Keesara Sent: 15 January 2008 20:36 To: freeradius-users@lists.freeradius.org Subject: eap-mschapv2 I am using freeradius to

RE: eap-mschapv2

2008-01-15 Thread Josh Howlett
auth: type EAP +- entering group authenticate rlm_eap: Request found, released from the list rlm_eap: EAP/mschapv2 rlm_eap: processing type mschapv2 +- entering group MS-CHAP rlm_mschap: Told to do MS-CHAPv2 for user with NT-Password rlm_mschap: adding MS-CHAPv2 MPPE keys

RE: eap-mschapv2

2008-01-15 Thread hamid benane
hello, are you using switch like NAS for your configuration. Because for my configuration, i done test over wiireless and its work beautifull. But when i try to use switch to authenticate win-xp client its not work. after the acces-request the server respond acces-reject. can you help me i use

RE: Help Needed Please freeradius traffic limiting

2008-01-15 Thread Edvin Seferovic
What are you using as NAS ?? Regards, E:S From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] g] On Behalf Of Keith Dovale Sent: Dienstag, 15. Jänner 2008 17:41 To: 'FreeRadius users mailing list' Subject: FW: Help Needed Please freeradius traffic limiting Regards Keith Dovale

RE: Help Needed Please freeradius traffic limiting

2008-01-15 Thread hamid benane
hello, i need help to authenticate win-xp client throw cisco3560 on freeradius-1.1.1. i use EAP-PEAP and my certificate is good. on wireless its work nice but not on lan wired area. i try tou authenticate user with simple password thanks

Re: radgroupreply do not read (read_grous directive)

2008-01-15 Thread Arlinelson Fernandes dos Santos
' rlm_acct_unique: Acct-Unique-Session-ID = a5e052f9f07c2f6f. ++[acct_unique] returns ok +- group preacct returns ok Processing the accounting section of radiusd.conf +- entering group accounting radius_xlat: '/usr/local/var/log/radius/radacct/7.7.7.1/detail-20080115' rlm_detail: /usr/local/var/log/radius

Re: radgroupreply do not read (read_grous directive)

2008-01-15 Thread tnt
accounting radius_xlat: '/usr/local/var/log/radius/radacct/7.7.7.1/detail-20080115' rlm_detail: /usr/local/var/log/radius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands to /usr/local/var/log/radius/radacct/7.7.7.1/detail-20080115 radius_xlat: 'Tue Jan 15 20:33:58 2008' ++[detail] returns ok

RE: Help Needed Please freeradius traffic limiting

2008-01-15 Thread tnt
1. Don't hijack other peoples topics. 2. http://wiki.freeradius.org/index.php/FreeRADIUS_Wiki:FAQ#It_still_doesn.27t_work.21 Ivan Kalik Kalik Informatika ISP Dana 15/1/2008, hamid benane [EMAIL PROTECTED] piše: hello, i need help to authenticate win-xp client throw cisco3560 on

Freeradius is unable to connect to Oracle Server through an Oracle client

2008-01-15 Thread Ripunjay
Hi, I have installed Oracle Client on a Linux Machine. Then I installed FreeRadius-1.1.4 Server on the same machine.I could succesfully create rlm_sql drivers for oracle. But even after supplying correct remote DB info in oraclesql.conf and sql.conf freeradius server is unable to connect to

Re: eap-mschapv2

2008-01-15 Thread Alan DeKok
Josh Howlett wrote: ... Sending Access-Challenge of id 3 to x.x.x.x port 1812 MS-CHAP2-Success = ... EAP-Message = ... That looks like a bug to me. It's a violation of RFC2548: No. The bug is different: EAP-MSCHAPv2 is *not* MS-CHAPv2. The MS-CHAP2-Success attribute

Re: eap-mschapv2

2008-01-15 Thread Alan DeKok
Indira Keesara wrote: I am using freeradius to test the eap-mschapv2. According to specs To the access-challenge reply radius should sent a access-success with the mppe keys. No. EAP-MSCHAPv2 does not supply MPPE keys. What spec are you reading that says it should? Alan DeKok.

Re: radgroupreply do not read (read_grous directive)

2008-01-15 Thread Arlinelson Fernandes dos Santos
-Unique-Session-ID = a5e052f9f07c2f6f. ++[acct_unique] returns ok +- group preacct returns ok Processing the accounting section of radiusd.conf +- entering group accounting radius_xlat: '/usr/local/var/log/radius/radacct/7.7.7.1/detail-20080115' rlm_detail: /usr/local/var/log/radius/radacct

Re: radsqlrelay v1.7 on freebsd 6.3

2008-01-15 Thread roy
Hi David/List, On Tue, 2008-01-15 at 17:19 +, David Wood wrote: sigh Sometimes blind code changes don't work out. Unfortunately I am flying blind, as I don't use radsqlrelay and I can't quickly concoct an environment for it. I think line 53 should actually be my $FLOCK_STRUCT =

Re: Possible Spam : Low Spam probability - : sqlcounter continue after failed match

2008-01-15 Thread Etienne Pretorius
Keith Dovale wrote: Hi Etienne, are you also limiting your users based on traffic usage ? Yes, I am. Kind Regards Etienne Pretorius http://www.kingsley.co.za Regards Keith Dovale -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Etienne

Re: Failed MAKE on SLES10

2008-01-15 Thread liran tal
Hey Peter, On Jan 15, 2008 6:15 PM, Peter Nixon [EMAIL PROTECTED] wrote: David You could alway use my nicely rolled SLES10 rpms from: http://ftp5.gwdg.de/pub/opensuse/repositories/network:/aaa/SLE_10/ I go to great lengths to make them. I wonder why more people don't bother using them...

Re: Freeradius is unable to connect to Oracle Server through an Oracle client

2008-01-15 Thread liran tal
Ripunjay, On Jan 16, 2008 3:20 AM, Ripunjay [EMAIL PROTECTED] wrote: Hi, I have installed Oracle Client on a Linux Machine. Then I installed FreeRadius-1.1.4 Server on the same machine.I could succesfully create rlm_sql drivers for oracle. But even after supplying correct remote DB info in

Re: Freeradius + portuguese characters in Active Directory

2008-01-15 Thread nikitha george
Please find the debug log below.. rlm_eap_ttls: Session established. Proceeding to decode tunneled attributes. +- entering group authorize ++[preprocess] returns ok expand: %{User-Name} - Catónio rlm_attr_rewrite: Added attribute Stripped-User-Name with value 'Catónio'

radwho radzap problem

2008-01-15 Thread Oguzhan Kayhan
Hello, I am using rlm_perl script for authentication. And logging radacct in sql. But it is strange that, i couldnt use radwho radzap radlast etc for a while.. had the error file not found etc.. So i manually created the files with touch. Now i can see theres records inside files, but still i cant