Child is hung for request … message

2013-03-07 Thread Alex Sharaz
Hi, I've just downloaded,compiled and installed the latest version of 2.2 (2.2.1?) from git.freeradius.org. Installed it on an internal server and things seemed to work o.k. I then upgraded another server that deals with our external ( eduroam) connectivity and within a few mins am seeing

Re: Child is hung for request … message

2013-03-07 Thread Olivier Beytrison
On 07.03.2013 11:32, Alex Sharaz wrote: Hi, I've just downloaded,compiled and installed the latest version of 2.2 (2.2.1?) from git.freeradius.org. Installed it on an internal server and things seemed to work o.k. I then upgraded another server that deals with our external ( eduroam)

Re: Child is hung for request … message

2013-03-07 Thread Alex Sharaz
Though you might say that. Running FR in debug mode now A On 7 Mar 2013, at 11:18, Olivier Beytrison oliv...@heliosnet.org wrote: On 07.03.2013 11:32, Alex Sharaz wrote: Hi, I've just downloaded,compiled and installed the latest version of 2.2 (2.2.1?) from git.freeradius.org. Installed

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Olivier Beytrison
On 07.03.2013 07:57, Iftakhul Anwar wrote: HI All, I just installed free radius server using apt-get on my ubuntu machine. Now i want to configure jradius on my freeradius server. I follow step by step from http://coova.org/JRadius/FreeRADIUS. Are you sure ? By default rlm_jradius is not

Re: Child is hung for request … message

2013-03-07 Thread A . L . M . Buxey
Hi, The server is basically proxying off auth requests to remote RADIUS servers. Is the above just telling me that the other end is taking a while to reply or is there some underlying issue? what is your retry time set to on the NAS kit? If your kit is expecting a reply in eg 3

Re: Child is hung for request … message

2013-03-07 Thread Alex Sharaz
On 7 Mar 2013, at 11:36, a.l.m.bu...@lboro.ac.uk wrote: Hi, The server is basically proxying off auth requests to remote RADIUS servers. Is the above just telling me that the other end is taking a while to reply or is there some underlying issue? what is your retry time set to on the

Re: Child is hung for request … message

2013-03-07 Thread A . L . M . Buxey
Hi, response_window = 5 thats a little low. the default provided with FreeRADIUS is 20 IIRC - and you need to ensure that theres correlation with the NAS alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Child is hung for request … message

2013-03-07 Thread Alex Sharaz
On 7 Mar 2013, at 12:15, a.l.m.bu...@lboro.ac.uk wrote: Hi, response_window = 5 thats a little low. the default provided with FreeRADIUS is 20 IIRC - and you need to ensure that theres correlation with the NAS o.k can't remember where I got that value, suspect it was

Re: Child is hung for request … message

2013-03-07 Thread Arran Cudbard-Bell
On 7 Mar 2013, at 06:21, Alex Sharaz alex.sha...@york.ac.uk wrote: Though you might say that. Running FR in debug mode now A If you can't reproduce it with -X, try with the -fxxl stdout incantation, -X will also force the server into single threaded mode, and this might be a locking issue.

Re: Freeradius 2.2.0 memory leak issue.

2013-03-07 Thread Alan DeKok
kao quadrantx wrote: i rebuild freeradius with the latest updated today (i noticed the userparse() in valuepair.c has updated) and the memory leak still the same. (same memory growth in VmRSS and same valgrind log.) OK. FR_TOKEN userparse(const char *buffer, VALUE_PAIR **list) Why?

Re: LDAP authorization

2013-03-07 Thread Alan DeKok
Matthew Ceroni wrote: I am using LDAP authorization. What I am looking to accomplish is to reject/deny (so not even attempt authentication) for disabled users. I am authentication against AD (use LDAP for authorize and ntlm for authentication). If I were to search for all none disabled

Re: Authentication Using Framed-IP-Address

2013-03-07 Thread Arran Cudbard-Bell
On 7 Mar 2013, at 09:50, Russell Mike radius@gmail.com wrote: Dear Alan. De. List Greetings May i please ask your opinion, if it possible to accept reject users base on Framed-IP-Address. Yes if the Framed-IP-Address is available in the request. There are however, no IP specific

Re: Authentication Using Framed-IP-Address

2013-03-07 Thread Russell Mike
Hi Arran, Thanks for the answer to my question. Nothing wrong to say thanks but perhaps to see it from that angle. Regards / RM -- On Thu, Mar 7, 2013 at 3:12 PM, Arran Cudbard-Bell a.cudba...@freeradius.org wrote: On 7 Mar 2013, at 09:50, Russell Mike radius@gmail.com wrote: Dear

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Iftakhul Anwar
Actually i install freeradius from apt-get , But i try configure jradius On Thu, Mar 7, 2013 at 6:27 PM, Olivier Beytrison oliv...@heliosnet.orgwrote: On 07.03.2013 07:57, Iftakhul Anwar wrote: HI All, I just installed free radius server using apt-get on my ubuntu machine. Now i want to

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Iftakhul Anwar
Actually i install freeradius from apt-get , But i try configure jradius following tutorial from http://coova.org/JRadius/FreeRADIUS How i can add this module to radius server if i using apt-get ? On Thu, Mar 7, 2013 at 10:55 PM, Iftakhul Anwar an...@meruvian.org wrote: Actually i install

EAP-TLS testing, occasional errors

2013-03-07 Thread Bertalan Voros
Hello All, I have configured a server to test EAP-TLS. Created the CA, a server and one client certificate. The same client certificate was then installed on three different devices; OSX, Windows 7 and an Android 4.2. All is well, all the devices can authenticate successfully, however, every

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Arran Cudbard-Bell
On 7 Mar 2013, at 10:55, Iftakhul Anwar an...@meruvian.org wrote: Actually i install freeradius from apt-get , Right, so jradius won't have been built. jradius support is going away, it will *NOT* be in Version 3 unless someone contributes a new version of the module which works with the

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Olivier Beytrison
On 07.03.2013 16:56, Iftakhul Anwar wrote: Actually i install freeradius from apt-get , But i try configure jradius following tutorial from http://coova.org/JRadius/FreeRADIUS How i can add this module to radius server if i using apt-get ? You can't. You have to compile it. experimental

Re: EAP-TLS testing, occasional errors

2013-03-07 Thread Phil Mayers
On 07/03/13 16:01, Bertalan Voros wrote: Has anyone seen this before? I see all kinds of weirdness from clients. Fundamentally, the problem is at the client - it didn't send a certificate - so you need to troubleshoot it there. - List info/subscribe/unsubscribe? See

RE: PHP MD5 with appended salt

2013-03-07 Thread René Klomp
 xlat are placeholders in strings, usually used for substituting attribute values, for example:     update reply { Reply-Message := Hello %{User-Name}  }    The %{User-Name} is an xlat expansion.    The xlat expansion %{md5:text} expands to an md5 hash of text. So you have

Re: PHP MD5 with appended salt

2013-03-07 Thread Alan DeKok
René Klomp wrote: Is there a better war to solve the loading of the sql module? If it do not include the else section, the %{sql:...} does not work. But if I place it outside the else or when the user enters the wrong password the database is queried twice. Add it to the instantiate

Re: PHP MD5 with appended salt

2013-03-07 Thread Olivier Beytrison
On 07.03.2013 17:15, René Klomp wrote: xlat are placeholders in strings, usually used for substituting attribute values, for example: Is there a better war to solve the loading of the sql module? If it do not include the else section, the %{sql:...} does not work. But if I place it

Release of Version 2.2.1

2013-03-07 Thread Alan DeKok
It's been a while since Version 2.2 was released, so it's time for the next release. I'd like to fix the reported memory leak issue, and then release it later next week. The changes are minor, and mostly cleanups and bug fixes. Please let me know if there are any issues. Alan DeKok. -

Re: LDAP authorization

2013-03-07 Thread Matthew Ceroni
That is what I tried. So I set base_filter = ((objectclass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) But what I am finding is whether the user is found and enabled, user is found but disabled, or user isn't found at the output (from radius debug) shows [ldap] user XX

Re: LDAP authorization

2013-03-07 Thread Alan DeKok
Matthew Ceroni wrote: That is what I tried. So I set base_filter = ((objectclass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) But what I am finding is whether the user is found and enabled, user is found but disabled, or user isn't found at the output (from radius debug) shows

Re: LDAP authorization

2013-03-07 Thread Matthew Ceroni
Alan: Yes, that works when run through ldapsearch. I was able to get the attribute checking working (added to dictionary, then ldap.attrmap) so I can now reject based on the value of an attribute. Thanks for the input on that. However, if the user isn't found in LDAP (Active Directory), how do

Re: LDAP authorization

2013-03-07 Thread Olivier Beytrison
On 07.03.2013 22:06, Matthew Ceroni wrote: Alan: Yes, that works when run through ldapsearch. I was able to get the attribute checking working (added to dictionary, then ldap.attrmap) so I can now reject based on the value of an attribute. Thanks for the input on that. However, if the user

Re: Freeradius-Users Digest, Vol 95, Issue 30

2013-03-07 Thread David Bird
The most recent (which hasn't changed in some time now) can be found: http://dev.coova.org/svn/cjradius/trunk/freeradius/rlm_jradius/rlm_jradius.c Cheers, David Date: Thu, 7 Mar 2013 11:02:17 -0500 From: Arran Cudbard-Bell a.cudba...@freeradius.org To: FreeRadius users mailing list

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Iftakhul Anwar
I try to configure with command : ./configure --with-experimental-modules=yes but i got error like bellow : if [ xrlm_cram != x ]; then \ /home/iam/Downloads/freeradius-server-2.2.0/libtool --mode=install /home/iam/Downloads/freeradius-server-2.2.0/install-sh -c -c \ rlm_cram.la

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Fajar A. Nugraha
On Fri, Mar 8, 2013 at 3:02 AM, Arran Cudbard-Bell a.cudba...@freeradius.org wrote: On 7 Mar 2013, at 10:55, Iftakhul Anwar an...@meruvian.org wrote: Actually i install freeradius from apt-get , Right, so jradius won't have been built. Actually, it should be available. That is, if you use

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Iftakhul Anwar
i've found rlm_jradius on src/modules. But after i ./configure and make and make install i can't found jradius modules on my radiusd installation. Then I try to configure with command : ./configure --with-experimental-modules=yes but i got error like bellow : if [ xrlm_cram != x ]; then \

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Iftakhul Anwar
I try to downgrade to freeradius-server-2.1.1 as following from http://coova.org/JRadius/FreeRADIUS But when i try to running radiusd on foregound i got error message like bellow : radiusd -X FreeRADIUS Version 2.1.1, for host x86_64-unknown-linux-gnu, built on Mar 8 2013 at 08:13:26 Copyright

Requirements for rlm_jradius in 3.0

2013-03-07 Thread Arran Cudbard-Bell
On 7 Mar 2013, at 17:54, David Bird w...@mac.com wrote: The most recent (which hasn't changed in some time now) can be found: http://dev.coova.org/svn/cjradius/trunk/freeradius/rlm_jradius/rlm_jradius.c Ok. The main issues with that code are: * It won't compile against current master branch.

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Fajar A. Nugraha
On Fri, Mar 8, 2013 at 12:30 PM, Iftakhul Anwar an...@meruvian.org wrote: I try to downgrade to freeradius-server-2.1.1 as following from http://coova.org/JRadius/FreeRADIUS But when i try to running radiusd on foregound i got error message like bellow : I'm running on ubuntu 12.04

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Iftakhul Anwar
Hi Fajar, What do you mean rebuilding source package ? i've recompile freeradius-server-2.1.1 from source code. But when i try to run, jradius still not found i try with some parameter in configure command = ./configure --with-experimental-modules=yes and i got error like above when i try

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Iftakhul Anwar
What is the right syntax for compile using experimental module ? I've try to ./configure --with-experimental-modules=yes then make and make install. But on i can't find jradius module in {installation folder}/modules i've also try ./configure --with-experimental-modules=rlm_jradius, but still

Re: Failed to load module jradius freeradius server

2013-03-07 Thread Fajar A. Nugraha
On Fri, Mar 8, 2013 at 2:16 PM, Iftakhul Anwar an...@meruvian.org wrote: What is the right syntax for compile using experimental module ? --with-experimental-modules I've try to ./configure --with-experimental-modules=yes then make and make install. But on i can't find jradius module in

SQL changes

2013-03-07 Thread Arran Cudbard-Bell
Hi All, A few changes to the SQL drivers. * Biggest change is there are now no longer any socket close/free functions in the driver API these are now all handled by talloc destructors. If you suspect sockets aren't being closed properly, run with the extra -x and it'll print out a message

Freeradius with either LDAP or Mysql Error lib not found

2013-03-07 Thread Iftakhul Anwar
Hi All I just try to config freeradius using either Mysql or LDAP. But i get same error like bellow : [errror Mysq] Fri Mar 8 13:44:46 2013 : Error: Could not link driver rlm_sql_mysql: rlm_sql_mysql.so: cannot open shared object file: No such file or directory Fri Mar 8 13:44:46 2013 :