RE: Freeradius + Alvarion 4Motion specify filter-id value in access-accept from value in user conf file ?

2011-06-01 Thread Hahusseau, Thomas
Hello, My Wimax device require MPPE keys to be sent in access accept if I change that setting in module/wimax from no to yes the wimax don't connect anymore. My problem is not getting my Wimax device connected it's already done. My problem is that I want specific values of Filter-Id attribute

Wiki - once upon a time there was documentation

2011-06-01 Thread den2k
Hi to all, what happened to the contents of the wiki? A lot of stuff is missing, for example http://wiki.freeradius.org/Operators now has nothing more than a few badly explained examples and the table of the operators is missing. Also I couldn't find a lot of stuff that I'm sure there was on the

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Phil Mayers
On 01/06/11 10:28, den2k wrote: Hi to all, what happened to the contents of the wiki? A lot of stuff is missing, for example http://wiki.freeradius.org/Operators now has nothing more than a few badly explained examples and the table of the operators is missing. Also I couldn't find a lot of

wiki login returning 500

2011-06-01 Thread Phil Mayers
I'm getting: HTTP Error 500 (Internal Server Error): An unexpected condition was encountered while the server was attempting to fulfil the request. ...when I try to log in using the GitHub referral/login thing; the error is from this URL:

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread den2k
2011/6/1 Phil Mayers p.may...@imperial.ac.uk On 01/06/11 10:28, den2k wrote: Hi to all, what happened to the contents of the wiki? A lot of stuff is missing, for example http://wiki.freeradius.org/Operators now has nothing more than a few badly explained examples and the table of the

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Phil Mayers
On 01/06/11 10:57, den2k wrote: Example? Right now the operators one. Also users and huntgroups were better descripted before, now there is just some brief introduction and nothing more. It was the lack of any explanation that I was referring to as lack of material (I'm not an English

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Alan DeKok
den2k wrote: what happened to the contents of the wiki? A lot of stuff is missing, for example http://wiki.freeradius.org/Operators now has nothing more than a few badly explained examples and the table of the operators is missing. Click on the edit link. The content is still there, it is

Re: wiki login returning 500

2011-06-01 Thread Alan DeKok
Phil Mayers wrote: I'm getting: HTTP Error 500 (Internal Server Error): An unexpected condition was encountered while the server was attempting to fulfil the request. ...when I try to log in using the GitHub referral/login thing; the error is from this URL:

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Alan DeKok
den2k wrote: Right now the operators one. Also users and huntgroups were better descripted before, now there is just some brief introduction and nothing more. It was the lack of any explanation that I was referring to as lack of material (I'm not an English native-speaker so I make some

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Phil Mayers
On 01/06/11 11:17, Phil Mayers wrote: On 01/06/11 10:57, den2k wrote: Example? Right now the operators one. Also users and huntgroups were better descripted before, now there is just some brief introduction and nothing more. It was the lack of any explanation that I was referring to as lack

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread den2k
2011/6/1 Alan DeKok al...@deployingradius.com den2k wrote: what happened to the contents of the wiki? A lot of stuff is missing, for example http://wiki.freeradius.org/Operators now has nothing more than a few badly explained examples and the table of the operators is missing. Click

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Johan Meiring
On 2011/06/01 12:17 PM, Phil Mayers wrote: ...in which the migration technique was discussed, and help was requested to reformat documents which had not migrated seamlessly. - Is the old wiki accessable anywhere so one can help to manually transfer info? -- Johan Meiring Cape PC Services

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Phil Mayers
On 01/06/11 11:54, Johan Meiring wrote: On 2011/06/01 12:17 PM, Phil Mayers wrote: ...in which the migration technique was discussed, and help was requested to reformat documents which had not migrated seamlessly. - Is the old wiki accessable anywhere so one can help to manually transfer

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Alan DeKok
Johan Meiring wrote: Is the old wiki accessable anywhere so one can help to manually transfer info? $ git clone git://wiki.freeradius.org/wiki.freeradius.org.git That gets you *all* of the content. You can't push changes, but you can paste the results into the edit page. Alan DeKok. -

Freeradius not releasing IPs from pool

2011-06-01 Thread Angel L. Mateo
Hello, I have a problem with my pools in freeradius. The problems is that it is not releasing IPs from the pools. At least, not all of them, so after a while my users can't connect because the pool is full. I check that it is not releasing IPs because I get (I have replaced usernames with

RE: Freeradius + Alvarion 4Motion specify filter-id value in access-accept from value in user conf file ?

2011-06-01 Thread David Peterson
I just use Framed-Filter-Id = profilename in the reply. When you added: update reply { WiMAX-FA-RK-Key = 0x00 WiMAX-MSK = %{reply:EAP-MSK} Filter-Id = Profile1 } That replies with only 1 filter ID.

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread John Center
Hi, I've been updating some of the wiki pages to fix the formatting, etc. Arran put together a list of pages that were a priority at http://wiki.freeradius.org/New-Wiki. Are there other pages that people wish to have done next? (I'll try to fix the Operators page tonight. I fixed the

Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Simon L.
Hi, my freeradius works as a proxy, terminates eap and proxy the request with mschap to another freeradius. When Passing reply from proxy back into the tunnel the proxy quits with a segmentation fault. This happens, with little difference, when sending the accept or reject back to NAS.

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Simon L.
ok now i found this: https://lists.freeradius.org/pipermail/freeradius-users/2011-April/msg00295.html This means, i should download the latest freeradius from git master branch? Simon Simon L. schrieb: Hi, my freeradius works as a proxy, terminates eap and proxy the request with mschap to

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Alan DeKok
Simon L. wrote: ok now i found this: https://lists.freeradius.org/pipermail/freeradius-users/2011-April/msg00295.html This means, i should download the latest freeradius from git master branch? Use the v2.1.x branch. It will become 2.1.11 soon. Alan DeKok. - List

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Simon L.
Alan DeKok schrieb: Simon L. wrote: ok now i found this: https://lists.freeradius.org/pipermail/freeradius-users/2011-April/msg00295.html This means, i should download the latest freeradius from git master branch? Use the v2.1.x branch. It will become 2.1.11 soon. Alan

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Phil Mayers
On 01/06/11 15:45, Simon L. wrote: ok now i found this: https://lists.freeradius.org/pipermail/freeradius-users/2011-April/msg00295.html This means, i should download the latest freeradius from git master branch? No, v2.1.x Beware: I have since been informed that there is still a potential

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Alexander Clouter
Simon L. fantasn...@ki.tng.de wrote: I hope anyone got this before and can give a solution. Please have a look in my debug log attached. Going to need some GDB lovin' too. http://freeradius.org/radiusd/doc/bugs If you are compiling from source, I recommend you go with the git version

One client, multiple NAS-Port-Types

2011-06-01 Thread DaveA
Hello, I am looking for some guidance on configuring clients that will send requests with different NAS-Port-Type’s. Devices: HP Procurve, Cisco, Aruba wireless controllers Possible NAS-Port-Types: Ethernet, Virtual, Wireless, Async Ex., for an HP procurve switch, the possibilities will be: 1.

Re: Wiki - once upon a time there was documentation

2011-06-01 Thread Arran Cudbard-Bell
John, It's ok, I fixed it this morning. Thanks for your help with the other pages and your continued conversion efforts :) Cheers, Arran On Jun 1, 2011, at 5:51 AM, John Center wrote: Hi, I've been updating some of the wiki pages to fix the formatting, etc. Arran put together a list of

Re: One client, multiple NAS-Port-Types

2011-06-01 Thread Alan DeKok
DaveA wrote: In this case, I would like to send CLI and 802.1x requests to different virtual servers, because I accomplish #1 painlessly with ldap, and #2 gets more complicated with ads and eduroam in the mix. I have read through clients.conf and do not believe it can be done there. Where

Re: One client, multiple NAS-Port-Types

2011-06-01 Thread Alexander Clouter
DaveA daldw...@uwaterloo.ca wrote: I am looking for some guidance on configuring clients that will send requests with different NAS-Port-Type???s. Devices: HP Procurve, Cisco, Aruba wireless controllers Possible NAS-Port-Types: Ethernet, Virtual, Wireless, Async Ex., for an HP procurve

Re: One client, multiple NAS-Port-Types

2011-06-01 Thread Arran Cudbard-Bell
On Jun 1, 2011, at 10:53 AM, Alexander Clouter wrote: DaveA daldw...@uwaterloo.ca wrote: I am looking for some guidance on configuring clients that will send requests with different NAS-Port-Type???s. Devices: HP Procurve, Cisco, Aruba wireless controllers Possible NAS-Port-Types:

Re: One client, multiple NAS-Port-Types

2011-06-01 Thread Alan DeKok
Arran Cudbard-Bell wrote: You can do an internal proxy, but last time I checked multiple chained internal proxies were broken (I tried something very similar a few years ago). You can proxy to one virtual server. But that request can't be proxied again. It's too awkward to deal with that.

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Alan DeKok
Phil Mayers wrote: No, v2.1.x Beware: I have since been informed that there is still a potential segfault if the remote proxy returns an Access-Reject. I haven't had time to test this yet. I'd like to release 2.1.11 soon. Maybe next week? Alan DeKok. - List

Server Sertificate

2011-06-01 Thread Lubenski, Zeev [GCS]
We use EAP-TLS method, but in the Server Hello message don't want to send the certificate. How can it be disabled - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Server Sertificate

2011-06-01 Thread Lubenski, Zeev [GCS]
We use EAP-TLS method, but in the Server Hello message don't want to send the certificate. How can it be disabled - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Server Sertificate

2011-06-01 Thread Lubenski, Zeev [GCS]
We use EAP-TLS method, but in the Server Hello message don't want to send the certificate. How can it be disabled - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Server Sertificate

2011-06-01 Thread Phil Mayers
On 06/01/2011 08:28 PM, Lubenski, Zeev [GCS] wrote: We use EAP-TLS method, but in the Server Hello message don’t want to send the certificate. How can it be disabled It can't. EAP-TLS requires a server certificate and a client certificate. Neither are optional, and neither can be disabled.

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Phil Mayers
On 06/01/2011 07:32 PM, Alan DeKok wrote: Phil Mayers wrote: No, v2.1.x Beware: I have since been informed that there is still a potential segfault if the remote proxy returns an Access-Reject. I haven't had time to test this yet. I'd like to release 2.1.11 soon. Maybe next week? Well

RE: Server Sertificate

2011-06-01 Thread Lubenski, Zeev [GCS]
Paul In the RFC 5216 I see: The EAP server will then respond with an EAP-Request packet with AP-Type=EAP-TLS. The data field of this packet will encapsulate one or more TLS records. These will contain a TLS server_hello handshake message, possibly followed by TLS certificate This leads to

Re: Server Sertificate

2011-06-01 Thread Phil Mayers
On 06/01/2011 09:07 PM, Lubenski, Zeev [GCS] wrote: Paul In the RFC 5216 I see: The EAP server will then respond with an EAP-Request packet with AP-Type=EAP-TLS. The data field of this packet will encapsulate one or more TLS records. These will contain a TLS server_hello handshake message,

RE: Server Sertificate

2011-06-01 Thread Lubenski, Zeev [GCS]
Paul Thanks a lot Regards Zeev -Original Message- From: freeradius-users-bounces+zlubensk=lgsinnovations@lists.freeradius.org [mailto:freeradius-users-bounces+zlubensk=lgsinnovations@lists.freeradius.org] On Behalf Of Phil Mayers Sent: Wednesday, June 01, 2011 3:15 PM To:

Re: Segmetation fault: [eap] Passing reply from proxy back into the tunnel

2011-06-01 Thread Phil Mayers
On 06/01/2011 09:00 PM, Phil Mayers wrote: I'll try to test the Access-Reject thing tomorrow; I'm betting it'll be a trivial fix. Huh. It works just fine for me on v2.1.x HEAD. I'll try to dig out the email where someone said it was faulty (IIRC they said they'd emailed you also Alan). I

Re: Server Sertificate

2011-06-01 Thread Alexander Clouter
Lubenski, Zeev [GCS] zlube...@lgsinnovations.com wrote: This leads to believe that certificate is not mandatory ? ...which leads us to wonder why you want to use EAP-TLS? Probably best to answer: * what is it you are trying to do * how are you trying to accomplish it * what are you

Can't get checkrad to be called

2011-06-01 Thread Dan Brisson
I was wondering if someone could help me determine why checkrad isn't being called. I've followed the directions in the doc/Simultaneous-Use but still cannot get checkrad to fire off when I login. It will check radutmp, but never reaches out to my NAS with checkrad, as evidenced here from