Re: sql wont pass radtest

2010-05-27 Thread Alan DeKok
Robert Wilkinson wrote: I have uncommented all the SQL lines to no avail. No module is loaded. The debug log *clearly* shows which files it is reading, and which modules it is loading. It reads the SQL configuration files, but does *not* load the SQL module. Is it important to have a NAS

Re: EAP-TLS CN Check Question

2010-05-27 Thread Alan DeKok
David Mitchell wrote: I've encountered a similar issue I'm not sure how to deal with. Is there a place I can log any attributes of the certificate? Not at this moment. Patches are welcome. I log my accounting records via linelog, and as long as the configuration I end up with forces

Re: Re: still about how to return some attributes only inAccess-Accept packet

2010-05-27 Thread Alan Buxey
Hi, However, the filter does not work. Can anyone tell me what the problem is? do you not read my emails? really, I side with Alan here - why bother replying if you keep asking the wrong questions. yes, that # cannot be on the same line as handled - obviously that config wasnt checked

Re: Re: still about how to return some attributes onlyinAccess-Accept packet

2010-05-27 Thread WWF
hi Thanks a lot for your kindly help!!! It works now! Best Regards 2010-05-27 - Original Message - From: Alan Buxey To: weiw...@126.com,FreeRadius users mailing list Sent: 2010-05-27, 16:34:08 Subject: Re: Re: still about how to return some attributes onlyinAccess-Accept packet

expired user accounts between two dates

2010-05-27 Thread Marco Jaraiz
hello, i want to use expiration module to validate user account, but i need check the expirtation between two dates, init and finish date. somebody help me. thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: expired user accounts between two dates

2010-05-27 Thread Thibault Le Meur
Le 27/05/2010 10:46, Marco Jaraiz a écrit : hello, i want to use expiration module to validate user account, but i need check the expirtation between two dates, init and finish date. somebody help me. As you already may know the expiration module only works for expiration date. When I

RE: Restricting certain users access to certain NAS devices

2010-05-27 Thread Whitmarsh Mark (Leeds Teaching Hospitals NHS Trust)
Sorry, I should have mentioned I already tried man rlm_passwd and couldn't figure it out. I've been through it again and have made the following changes: 1. created a file /etc/raddb/path_group path_group:user1,user2,user3,user4,user5 2. Added the following to /etc/raddb/dictionary ATTRIBUTE

github wiki

2010-05-27 Thread Robert Wilkinson
Hello Alan, I want to thank you for your services. Not just for myself but for everyone that you assisted over the years it seems. You are a tireless soldier. I have visited github made some notes on the Wiki there. I am dedicated to streamlining the process of installing FR. The present system

Re: github wiki

2010-05-27 Thread Alan DeKok
Robert Wilkinson wrote: I want to thank you for your services. Not just for myself but for everyone that you assisted over the years it seems. You are a tireless soldier. I have visited github made some notes on the Wiki there. I am dedicated to streamlining the process of installing FR.

Re: Restricting certain users access to certain NAS devices

2010-05-27 Thread Alan DeKok
Whitmarsh Mark (Leeds Teaching Hospitals NHS Trust) wrote: Sorry, I should have mentioned I already tried man rlm_passwd and couldn't figure it out. I've been through it again and have made the following changes: 1. created a file /etc/raddb/path_group

dynamic assignment of VLANs from LDAP via freeradius to WLAN-Clients doesn't work properly

2010-05-27 Thread Meister, Frank
Hello, we have freeradius-2.1.8 running, with openldap-2.3.43 as backend. in ldap we have three attributes (radiusTunnelMediumType=IEEE-802, radiusTunnelType=VLAN, and radiusTunnelPrivateGroupId=[vlan-id]), freeradius maps the ldap-attributes to radius-attributes. We have three vlans, one for

Re: dynamic assignment of VLANs from LDAP via freeradius to WLAN-Clients doesn't work properly

2010-05-27 Thread Alan DeKok
Meister, Frank wrote: after assigning the 1st VLAN on our cisco aironet 1242 accesspoints to the SSID - clicking Apply, assigning the 2nd VLAN - click Apply, assigning the 3rd VLAN, click Apply it works fine. (I mean manual assigning VLANs using web-interface) ? This has nothing to do with

Re: dynamic assignment of VLANs from LDAP via freeradius to WLAN-Clients doesn't work properly

2010-05-27 Thread Michael Schwartzkopff
Am Donnerstag, 27. Mai 2010 18:42:29 schrieb Meister, Frank: Hello, we have freeradius-2.1.8 running, with openldap-2.3.43 as backend. in ldap we have three attributes (radiusTunnelMediumType=IEEE-802, radiusTunnelType=VLAN, and radiusTunnelPrivateGroupId=[vlan-id]), freeradius maps the

Re: EAP-TLS CN Check Question

2010-05-27 Thread David Mitchell
Alan DeKok wrote: David Mitchell wrote: I've encountered a similar issue I'm not sure how to deal with. Is there a place I can log any attributes of the certificate? Not at this moment. Patches are welcome. I log my accounting records via linelog, and as long as the configuration I

Re: RADDB 2.1.7 and /etc/shadow

2010-05-27 Thread sbchem
shrug It's an error produces (sic) by the PAM subsystem. Ask them what it means. Sigh It turns out the error is caused by a typo in the radiusd file provided in /redhat/radiusd-pam, NOT by the pam subsystem. In fact, the pam subsystem was merely reporting the error in the freeradius file.

Re: Accounting to MySQL not working

2010-05-27 Thread Alan Buxey
hi, according to the debug: +- entering group accounting {...} [detail]expand: /var/log/freeradius/radacct/%{Client-IP-Address}/detail-%Y%m%d - +/var/log/freeradius/radacct/192.168.1.10/detail-20100527 [detail] /var/log/freeradius/radacct/%{Client-IP-Address}/detail-%Y%m%d expands

Re: RADDB 2.1.7 and /etc/shadow

2010-05-27 Thread John Dennis
On 05/27/2010 04:51 PM, sbchem wrote: shrug It's an error produces (sic) by the PAM subsystem. Ask them what it means. Sigh It turns out the error is caused by a typo in the radiusd file provided in /redhat/radiusd-pam, NOT by the pam subsystem. In fact, the pam subsystem was merely

Option 82 parse problems.

2010-05-27 Thread Anton
Good day. I'm trying to set freeradius like dhcp server with option 82 parsing and SQL data lookup. Now I use versions 2.1.8 and 2.1.9 with exactly the same configs and there is no SQL configuration yet, only default dhcp config with my test diff (see below). I have two questions for now: 1.