Re: Definitive Word on FreeRadius/LDAP/EAP Requirements

2009-06-26 Thread Arran Cudbard-Bell
server. It can with EAP-TTLS-PAP or anything else that provides a cleartext password. -- Arran Cudbard-Bell (a.cudbard-b...@sussex.ac.uk), Authentication, Authorisation and Accounting Officer, Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT

Re: Intermediate Certs in EAP-TLS - Confirmed Client-side Problem?

2009-06-27 Thread Arran Cudbard-Bell
Alan DeKok wrote: Aaron Mahler wrote: It is issued by GoDaddy and does trace back to a valid root cert that I've found exists by default on my OS X systems. This isn't a good idea for RADIUS systems. It means that the 802.1X clients will happily hand their credentials to

Re: Old password 'grace period'

2009-06-30 Thread Arran Cudbard-Bell
[JK] This works beautifully.I want to thank Arran and others for the quick response. Very much appreciated. Excellent. Glad to hear :) Thanks, Arran -- Arran Cudbard-Bell (a.cudbard-b...@sussex.ac.uk), Authentication, Authorisation and Accounting Officer, Infrastructure Services

Re: want to authorise but not authenticate

2009-07-08 Thread Arran Cudbard-Bell
=password for authorization AND a proper authentication can happen WITHOUT (hers a gotcha) the user doing something cute like putting their username in as their password! ;-) Slightly confused as to what you want... Try again without the caffeine ? Arran -- Arran Cudbard-Bell a.cudbard-b

Re: want to authorise but not authenticate

2009-07-08 Thread Arran Cudbard-Bell
Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG: 86FF A285 1AA1 EE40 D228 7C2E 71A9 25BB 1E68 54A2 - List info/subscribe/unsubscribe

Re: want to authorise but not authenticate

2009-07-08 Thread Arran Cudbard-Bell
on a different port that does the authorisation job only. its a little natty but seems the best way :-| Can't you bind the same virtual server to multiple IPs? Less duplication... Arran -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services

Re: make install without messing with previous configuration?

2009-07-15 Thread Arran Cudbard-Bell
Leighton Man wrote: Hi, I tar the entire raddb directory (from the level above), reinstall, and untar the original config over the top of the new one. That way I can keep multiple configs whilst experimenting and switch between them. Just move the raddb directory to /etc/raddb and change

Re: White papers: Scaling FreeRADIUS MySQL

2009-07-20 Thread Arran Cudbard-Bell
users to quickly and simply replicate the solution in their own environment. Read the guide, posted here: http://www.mysql.com/why-mysql/white-papers/mysql_wp_deploying_FreeRADIUS.php - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Arran Cudbard-Bell a.cudbard-b

Re: AW: EAP errors in 2.1.1

2009-08-06 Thread Arran Cudbard-Bell
? Arran -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG: 86FF A285 1AA1 EE40 D228 7C2E 71A9 25BB 1E68 54A2 - List info

Re: Mac based authentication

2009-08-10 Thread Arran Cudbard-Bell
mac address (calling-station-id) as username and password, so that client can authenticate directly. Please help me to configure freeradius so that i can implement that i explain before. Sure, see here http://wiki.freeradius.org/Mac-Auth Regards, Arran -- Arran Cudbard-Bell a.cudbard-b

Re: convert redius request to soap request

2009-08-11 Thread Arran Cudbard-Bell
shivashankar wrote: hi , give me assistence i new to freeradius how to convert radius request to SOAP request. is there any way to do this... Yes using rlm_perl or rlm_python, but there are no standard scripts to do this. In my experience Web Service APIs can be quite slow,

Re: freeradius2.1.6 module errors

2009-08-12 Thread Arran Cudbard-Bell
/users.html -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG: 86FF A285 1AA1 EE40 D228 7C2E 71A9 25BB 1E68 54A2 - List info/subscribe

Re: freeradius2.1.6 module errors

2009-08-12 Thread Arran Cudbard-Bell
It used to get angry when you did that -- On 12 Aug 2009, at 20:49, Alan Buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, default { accounting { if(Acct-Status-Type = 'stop'){ sql or edit the required dialup.conf for the chosen SQL solution and only have the STOP insert

Re: Problem with MAC authorization..(again)

2009-08-14 Thread Arran Cudbard-Bell
. But not with methods such as EAP-TTLS-MSCHAPv2 or EAP-PEAP. Regards, Arran -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG: 86FF

Re: PEAP / mschapv2 Error Messages

2009-08-14 Thread Arran Cudbard-Bell
themselves, then it'd be pretty easy to write a small web app to look through the failure codes and convert them into something humanly readable. Arran -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1

Re: Proxying accounting to create a 'tee'

2009-08-14 Thread Arran Cudbard-Bell
request is processed. This also has the advantage of buffering requests in case of the remote server goes down. For additional Tees into other DBs,Remote server just create additional detail writer/reader pairs. Regards, Arran -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems

Re: Proxying accounting to create a 'tee'

2009-08-17 Thread Arran Cudbard-Bell
vol...@ufamts.ru wrote: Alan DeKok wrote: What do you mean duplicate records? Alan DeKok. If home server does not respond, FR does not respond too - NAS repeats request - FR writes request data to SQL again. So we got two problems: 1) repeating requests 2) NAS does not receive

Re: segfault with regex and hint

2009-08-18 Thread Arran Cudbard-Bell
Hello! You using ProCurve NAS then? Or have other people started using Service-Type = 'Call-Check' to hint at Mac-Auth? -Arran Alan Buxey a.l.m.bu...@lboro.ac.uk wrote: It's that time of year to overhaul the cesspool that makes up my FreeRADIUS config files. I am running FreeRADIUS

Re: segfault with regex and hint

2009-08-19 Thread Arran Cudbard-Bell
two or so years ago...that is how long it's been in my config for. Ah, so that's who they were copying. It makes it easier to be sure the NAS really is requesting MAC-Auth when it includes that Service-Type attribute. Nice condition btw, very compact :) -Arran -- Arran Cudbard-Bell a.cudbard

Re: Proxying accounting to create a 'tee'

2009-08-21 Thread Arran Cudbard-Bell
to the next request WARNING: Marking home server 66.133.129.108 port 1813 as zombie (it looks like it is dead). Waking up in 0.8 seconds. - -Arran - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1

Re: Proxying accounting to create a 'tee'

2009-08-22 Thread Arran Cudbard-Bell
Fajar A. Nugraha wrote: On Sat, Aug 22, 2009 at 7:59 AM, Arran Cudbard-Bella.cudbard-b...@sussex.ac.uk wrote: On 21/08/2009 21:15, John Morrissey wrote: Is decoupled-accounting (writing all detail to disk and replaying it serialized with a detail listener) the only way to

Re: Proxying accounting to create a 'tee'

2009-08-24 Thread Arran Cudbard-Bell
queue. I haven't figured out how to solve this properly with the current setup, so it'd be good to see some discussion on list about it. - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University

Re: Proxying accounting to create a 'tee'

2009-08-25 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 24/08/2009 16:46, John Morrissey wrote: On Sat, Aug 22, 2009 at 01:59:00AM +0100, Arran Cudbard-Bell wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 21/08/2009 21:15, John Morrissey wrote: On Sun, Aug 16, 2009 at 10:11:02AM +0200

Re: Proxying accounting to create a 'tee'

2009-08-25 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 24/08/2009 13:56, Alan DeKok wrote: Arran Cudbard-Bell wrote: No, that'll get you the timestamp of when the packet was read back into the server. The only way to calculate the original received timestamp is to write the original Acct-Delay

Re: unlang: matching for 'Access-Accept'

2009-08-28 Thread Arran Cudbard-Bell
something like Proxy-Reply:Packet-Type, check man unlang for details. You didn't specify you were wanting to match a Proxied Accept in your original post. - -Arran - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08

Re: Setting FreeRadius and Ldap. - Getting Educated Now

2009-08-28 Thread Arran Cudbard-Bell
mandating WPA2-AES for this academic year. - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG: 86FF A285 1AA1 EE40 D228 7C2E 71A9

Re: Proxying accounting to create a 'tee'

2009-08-29 Thread Arran Cudbard-Bell
Alan DeKok wrote: Arran Cudbard-Bell wrote: Ideally there'd be a mechanism to remove Accounting-Requests after X number of attempts at proxying. At the moment were using a request expiry time based on the length of the period between the request being received and it being proxied

Re: Proxying accounting to create a 'tee'

2009-08-29 Thread Arran Cudbard-Bell
Alan DeKok wrote: Arran Cudbard-Bell wrote: Sure, want me to open one for the unlang rcode inheritance bug too? Yes, thanks. Done. Also you need to add the CSS files back in for the bug tracking system. Currently bugzilla is trying to load them from /bugzilla/skins/standard

Re: freeradius2.1.6| buffered-sql | acctstoptime problems

2009-09-02 Thread Arran Cudbard-Bell
Alan DeKok wrote: Ivan Kalik wrote: Counter? Write detail.work.counter onto the disk, increment it every time packet is processed and return to zero when detail.work is deleted. It will say how many packets to skip when radiusd is restarted. Hmm... OK. Or slightly differently:

Re: Pre-release of 2.1.7

2009-09-03 Thread Arran Cudbard-Bell
[2]: Leaving directory `/usr/local/src/freeradius-server-2.1.7/src' make[1]: *** [common] Error 2 make[1]: Leaving directory `/usr/local/src/freeradius-server-2.1.7' make: *** [all] Error 2 Will try OSX build shortly... Thanks, Arran - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems

Re: Pre-release of 2.1.7

2009-09-03 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Will try OSX build shortly... Builds fine with OSX Server 10.5.7: ./configure --prefix=/usr/local/freeradius-2.1.7 --with-dhcp --with-vmps=no --with-openssl --without-rlm_perl --enable-ltdl-install=no - -- Arran Cudbard-Bell a.cudbard-b

Re: Pre-release of 2.1.7

2009-09-03 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/09/2009 14:16, Alan DeKok wrote: Arran Cudbard-Bell wrote: ... gcc .libs/radiusdS.o -o .libs/radiusd .libs/acct.o .libs/auth.o .libs/client.o .libs/conffile.o .libs/crypt.o .libs/exec.o .libs/ .libs/modules.o: In function `setup_modules

What problem does the FreeRADIUS wiki have?

2009-09-07 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 As per title. - -Arran - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG

Re: What problem does the FreeRADIUS wiki have?

2009-09-07 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/09/2009 17:51, Arran Cudbard-Bell wrote: As per title. -Arran Whatever it was seems to have resolved itself. - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08

Re: Pre-release of 2.1.7

2009-09-08 Thread Arran Cudbard-Bell
that it doesn't break anything. What functionality does the patch add? Thanks, Arran - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT

Re: Pre-release of 2.1.7

2009-09-08 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 08/09/2009 17:11, Arran Cudbard-Bell wrote: On 08/09/2009 16:45, Garber, Neal wrote: It won't make 2.1.8. Please submit a bug report and attach the patch. My preference for the patch is to split it into 2-3 pieces. Bug # 17 created

Re: Pre-release of 2.1.7

2009-09-08 Thread Arran Cudbard-Bell
Alan DeKok wrote: Thor Spruyt wrote: I've been away from FR evolution for a while... I must say I'm really surprised what's possible now with 2.1.7 compared to 1.1.7 (still running in production), nice job! 2.1.x is amazing compared to 1.1.x. I'm sad every time I have to

Re: Pre-release of 2.1.7

2009-09-09 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 09/09/2009 13:07, Thor Spruyt wrote: - Oorspronkelijk bericht - Van : Arran Cudbard-Bell [mailto:a.cudbard-b...@sussex.ac.uk] Verzonden : woensdag , september 9, 2009 01:31 PM *clarifies* I'm sad whenever I see someone using

Re: First steps towards RadSec support

2009-09-18 Thread Arran Cudbard-Bell
systems... - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG: 86FF A285 1AA1 EE40 D228 7C2E 71A9 25BB 1E68 54A2 -BEGIN PGP

Re: EAP/TTLS + virtual_server woes

2009-10-02 Thread Arran Cudbard-Bell
Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG: 86FF A285 1AA1 EE40 D228 7C2E 71A9 25BB 1E68 54A2 -BEGIN PGP SIGNATURE

Re: Proxying accounting to create a 'tee'

2009-10-07 Thread Arran Cudbard-Bell
I settled on something similar to this. The outer server (processing requests from the NAS) uses redundant-load-balance to write round-robin across several (currently 5) detail files. Five detail listeners (one for each detail file) then feed data to their final destinations (remote

Re: wpa/wpa2 on logs

2009-10-14 Thread Arran Cudbard-Bell
Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX: +44 1273 873900 | INT: 3900 GPG: 86FF A285 1AA1 EE40 D228 7C2E 71A9 25BB 1E68 54A2 -BEGIN PGP SIGNATURE

Re: wpa/wpa2 on logs

2009-10-14 Thread Arran Cudbard-Bell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 14/10/2009 13:34, Sergio Belkin wrote: 2009/10/14 Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 13/10/2009 18:53, Sergio Belkin wrote: Hi, Is there a way to log if a supplicant is using

Re: wpa/wpa2 on logs

2009-10-15 Thread Arran Cudbard-Bell
really really can't support WPA2. - - We bit the bullet and turned off TKIP support on all Wireless networks at the beginning of September. So far we've had no real complaints. Arran - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services

Re: Windows client MS-chap auto-reauthentication

2009-10-18 Thread Arran Cudbard-Bell
Alan Buxey wrote: hi, XP caches successful connections - Vista does too IIRC so I'm not sure why you are seeing different behaviour.. anyhow..you can clear the credentials by blatting a registry on eg logout or login. the RADIUS server wont see the difference between std login and cached

Re: Windows client MS-chap auto-reauthentication

2009-10-18 Thread Arran Cudbard-Bell
The windows supplicant should remove cached credentials if you return an EAP-Failure before the EAP type is negotiated. * EAP Method signature.asc Description: OpenPGP digital signature - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Pre-release of Version 2.1.8

2009-12-06 Thread Arran Cudbard-Bell
Did you check the XLAT fixes in? I saw commits for a couple of fixes but not the modified code in xlat.c... i guess this version also solved ASSERT FAILED event.c[2682]: request-ev != NULL issue? - Original Message From: Bjørn Mork bj...@mork.no To: FreeRadius users mailing

Re: Handling proxied accounting updates that have been delayed

2009-12-07 Thread Arran Cudbard-Bell
Any advise or experiences would be much appreciated! Fix the SQL queries so that the right information goes into the DB. Note that the calculated times may be off by a second or two, due to limited time resolution. It may be worth updating the server to create a Acct-Start-Time

Re: Handling proxied accounting updates that have been delayed

2009-12-07 Thread Arran Cudbard-Bell
Ignore me... signature.asc Description: OpenPGP digital signature - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Accounting question

2009-12-15 Thread Arran Cudbard-Bell
David Peterson wrote: Here is the accounting packet information I am getting: rad_recv: Accounting-Request packet from host 172.16.4.2 port 1813, id=5, length=239 Acct-Status-Type = Start WiMAX-Beginning-Of-Session = 1 WiMAX-IP-Technology = Reserved-0

Re: Accounting question

2009-12-15 Thread Arran Cudbard-Bell
-Original Message- From: Arran Cudbard-Bell [mailto:a.cudbard-b...@sussex.ac.uk] Sent: Tuesday, December 15, 2009 10:56 AM To: David Peterson-WirelessConnections; FreeRadius users mailing list Subject: Re: Accounting question David Peterson wrote: Here is the accounting packet information I am

Re: unlang after chap returns reject

2009-12-16 Thread Arran Cudbard-Bell
- แลกหมื่นลิ้งคืในค ลิ๊กเดียว - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - -- Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk, Systems Administrator (AAA), Infrastructure Services (IT Services), E1-1-08, Engineering 1, University Of Sussex, Brighton, BN1 9QT DDI+FAX

Re: Accounting question

2009-12-17 Thread Arran Cudbard-Bell
records in a more general way, and you can still treat Class as opaque binary data. Hope this helps. - -Arran From: Arran Cudbard-Bell [a.cudbard-b...@sussex.ac.uk] Sent: Tuesday, December 15, 2009 5:32 PM To: David Peterson-WirelessConnections

Re: evaluated result is wrong

2009-12-20 Thread Arran Cudbard-Bell
I have a question regarding this debug log output. I'm a bit confused about this logic operations and the boolean result: Sun Dec 20 15:44:46 2009 : Info: ++? if (%{control:Tmp-Integer-4} = %{control:Tmp-Integer-5}) Sun Dec 20 15:44:46 2009 : Info:expand: %{control:Tmp-Integer-4} -

Re: evaluated result is wrong

2009-12-20 Thread Arran Cudbard-Bell
On 20/12/2009 17:40, Stephan Kirsten wrote: Arran Cudbard-Bell schrieb: I have a question regarding this debug log output. I'm a bit confused about this logic operations and the boolean result: Sun Dec 20 15:44:46 2009 : Info: ++? if (%{control:Tmp-Integer-4} = %{control:Tmp-Integer-5}) Sun

Re: evaluated result is wrong

2009-12-20 Thread Arran Cudbard-Bell
On 20/12/2009 17:46, Alan DeKok wrote: Stephan Kirsten wrote: I have a question regarding this debug log output. I'm a bit confused about this logic operations and the boolean result: signed 32-bit integer Sun Dec 20 15:44:46 2009 : Info:expand:

Re: MAC authentication bypass --- How am I supposed to edit?theusers file to include multiple MAC addresses??

2009-12-20 Thread Arran Cudbard-Bell
On 20/12/2009 22:44, Alan Buxey wrote: Hi, some would say that is a controversial MAC address regexp, but I guess you just do things differently 'up north' eh? :) hey, it was a quick hackup example to deal with the question. 'cheese112233xxyyzzTASTY' would even match

Re: MAC authentication bypass --- How am I supposed to?edit?theusers file to include multiple MAC addresses??

2009-12-21 Thread Arran Cudbard-Bell
On 21/12/2009 09:15, Alan Buxey wrote: Hi, yep - but a user could just as easily log in with the user-name of 00:11:22:33:44:55 ;-) Not when you say !EAP-Message too :) ...and how does that stop, lets just say for example, some user coming along with 802.1X configured on

Re: MAC authentication bypass --- How am I supposed to?edit?theusers?file to include multiple MAC addresses??

2009-12-21 Thread Arran Cudbard-Bell
On 21/12/2009 09:05, Alexander Clouter wrote: Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk wrote: the real answer is to get the vendors to sort their cheap shoddy kit out ;-) Ahem *Vendor :P - - Sorry I have to do it or they beat me :( dare I ask why you do

Re: MAC authentication bypass --- How am I supposedto?edit?theusers file to include multiple MAC addresses??

2009-12-24 Thread Arran Cudbard-Bell
Difan Zhao wrote: Hey guys, So I finally started configuring this *MAC auth bypass* thing... I am editing the *raddb/policy.conf* to include the *rewrite_calling_station_id* function/module however when I am trying to run the *radiusd –X* I got this error: /etc/raddb/policy.conf[72]:

Re: Rejecting User By their Calling-Station-Id (Mac Address)

2009-12-26 Thread Arran Cudbard-Bell
On 26/12/2009 08:05, Alex M wrote: Ok I still having trouble with this. Here is my code: if (Calling-Station-Id == %{sql: SELECT mac FROM `lrc_banlist` WHERE mac='%{Calling-Station-Id}'}) {

Re: Rejecting User By their Calling-Station-Id (Mac Address)

2009-12-26 Thread Arran Cudbard-Bell
On 26/12/2009 10:11, Alex M wrote: As suggested I just tried to replace operator = with := and even with == but reply message is not getting outputted :( Maybe I'm missing something? Try moving the reject to after the update stanza. I think a return code of reject stops the server processing

Re: Rejecting User By their Calling-Station-Id (Mac Address)

2009-12-26 Thread Arran Cudbard-Bell
. e.g. Authenticate { eap { reject = 1 } if(reject){ do more stuff... } } -Arran On Sat, Dec 26, 2009 at 1:16 PM, Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk mailto:a.cudbard-b...@sussex.ac.uk wrote: On 26/12/2009 10:11, Alex M wrote: As suggested I

Re: Recall: MAC authentication bypass --- How am Isupposedto?edit?theusersfile to include multiple MAC addresses??

2009-12-29 Thread Arran Cudbard-Bell
On 29/12/2009 14:45, Difan Zhao wrote: Difan Zhao would like to recall the message, MAC authentication bypass --- How am Isupposedto?edit?theusersfile to include multiple MAC addresses??. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html I've often wondered

Re: MAC authentication bypass --- How amIsupposedto?edit?theusersfile to include multiple MAC addresses??

2009-12-29 Thread Arran Cudbard-Bell
Should be: if(request:User-Password == %{request:User-Name}) { However when I try to run Radius I keep getting this error: Expected regular expression at: request:User-Password) /etc/raddb/sites-enabled/default[308]: Failed to parse if subsection. Errors initializing modules I

Re: Recall: MAC authentication bypass ---How?am?Isupposedto?edit?theusersfile to include multiple MACaddresses??

2009-12-30 Thread Arran Cudbard-Bell
?edit?theusersfile to include multiple MACaddresses?? Arran Cudbard-Bell a.cudbard-b...@sussex.ac.uk wrote: On 29/12/2009 14:45, Difan Zhao wrote: Difan Zhao would like to recall the message, MAC authentication bypass --- How am Isupposedto?edit?theusersfile to include multiple MAC

Re: OT: MS do I hate thee?

2009-12-30 Thread Arran Cudbard-Bell
On 30/12/2009 17:12, Alexander Clouter wrote: Difan Zhao difan.z...@guest-tek.com wrote: So I assume that none of you guys use MS Exchange server then... Do you guys all hate MS and support open source?? I am a windows guy but I am on your side!! I would not say 'hate', just find

Re: Reject Calling-Station-Id

2010-01-05 Thread Arran Cudbard-Bell
On 1/5/2010 5:58 AM, EasyHorpak.com wrote: Charles wrote: I am also facing the same problem - Need to blacklist range of IPs - Original Message - *From:* Neville mailto:n...@itsnev.co.uk *To:* freeradius-users@lists.freeradius.org

Re: Multiple Realms per NAS

2010-01-06 Thread Arran Cudbard-Bell
On 1/6/2010 12:13 PM, Nalin Mistry wrote: We have just installed FreeRADIUS and have basic functionality working for ISP and Hotspot applications. For the ISP application, we would like to specify the realms supported on a NAS basis. Is this feasible and how would one go about configuring

Re: A special user to matcheon all usernames

2010-01-15 Thread Arran Cudbard-Bell
On 15/01/2010 20:31, pang_jiacai wrote: Hi,all: I want to kown how to configure a special user to match all usernames .I just want to authorize sussessfully even though the username don't exist.this is for emergency while my database is destoryed,I will let all user pass through without

Re: EAP Session resumption reply attributes

2010-01-20 Thread Arran Cudbard-Bell
On 1/17/2010 8:37 AM, Alexander Clouter wrote: James J J Hooperjjj.hoo...@bristol.ac.uk wrote: In order to also return e.g. VLAN IDs (that could be computed from the inner User-Name in a non-session-resumption enabled config), I can move the config that sets the VLAN to the outer tunnel

Re: Radius packet ID

2010-01-25 Thread Arran Cudbard-Bell
On 1/23/2010 2:07 AM, Alan DeKok wrote: Padam J Singh wrote: Hi, The RADIUS packet has a 8 bit ID field. This ID field is used to track the requests both in the NAS and the RADIUS server. The question is, does the ID need to be unique between the NAS and RADIUS Server for all packet

Re: Setting up FreeRADIUS 2.0.4 with OpenLDAP backend to do wireless auth

2010-01-28 Thread Arran Cudbard-Bell
Alan DeKok wrote: Jonathan Amiez wrote: Therefore, I have again trouble in setting up this configuration. The problem is EAP/PEAP related, and I am not able to resolve it. Post the debug log into: http://networkradius.com/freeradius.html And look for the red text. Hmm

Re: Freeradius-Users Digest, Vol 23, Issue 13

2007-03-06 Thread Arran Cudbard-Bell
to use crypted password you'll need a authentication mechanism that supports reversible encryption, like PAP or GTC. -- Arran Cudbard-Bell ([EMAIL PROTECTED]) Authentication Authorisation Accounting Officer Unversity of Sussex | Infrastructure Services ++441273873900/ext:3900 - List info/subscribe

Re:

2012-01-16 Thread Arran Cudbard-Bell
or distribution is prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message and any attachments. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Arran Cudbard-Bell a.cudba...@freeradius.org

Re: LDAP Group assign to vlan after AD user authentication

2012-01-23 Thread Arran Cudbard-Bell
smart enough to figure out whether you passed in a DN as a group or just a groupname, so in theory if you have the filters and search depth set correctly you can just use Ldap-Group == mygroup. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http

Re: LDAP Group assign to vlan after AD user authentication

2012-01-24 Thread Arran Cudbard-Bell
On 24 Jan 2012, at 09:05, NdK wrote: Il 24/01/2012 08:48, Arran Cudbard-Bell ha scritto: But how do I set Tunnel-Private-Group-Id from an exec-ed script? Just execute it using a backticks expansion, store the result in Tmp-String-0 then use regular expression matches over the result

Re: Juniper Questions (MX/ERX)

2012-01-24 Thread Arran Cudbard-Bell
- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Arran Cudbard-Bell a.cudba...@networkradius.com Technical consultant and solutions architect 15 Ave. du Granier, Meylan, France +33 4 69 66 54 50 - List info/subscribe/unsubscribe? See http

Re: Mixed Environment Question

2012-01-30 Thread Arran Cudbard-Bell
, it's one of the fundamentals of the RADIUS protocol. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Mixed Environment Question

2012-01-30 Thread Arran Cudbard-Bell
@lists.freeradius.org] On Behalf Of Arran Cudbard-Bell Sent: Monday, January 30, 2012 1:18 PM To: FreeRadius users mailing list Subject: Re: Mixed Environment Question So far I have tested this on a Juniper ERX and it simply ignores the Cisco attributes, which was what I’m hoping for. It has

Re: Blocked user not disconnected for 12+ hours

2012-02-09 Thread Arran Cudbard-Bell
Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius and eduroam

2012-02-18 Thread Arran Cudbard-Bell
For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki

Re: Wimax with Free radius

2012-03-05 Thread Arran Cudbard-Bell
On 5 Mar 2012, at 12:28, Alan DeKok wrote: Mulindwa wrote: Hallo there, i have an issue with my wimax setup, am trying to have my users authenticate using the wonderful freeradius but still failing. Am suing WASN9970 and using freeradius 2.1.12, When i turn on radius using radius-X,

Re: Double-check the shared secret on the server and the NAS!

2012-03-05 Thread Arran Cudbard-Bell
/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Arran Cudbard-Bell a.cudba...@networkradius.com Technical consultant and solutions architect 15 Ave. du Granier, Meylan, France +33 4 69 66 54 50

Re: Authentification

2012-03-05 Thread Arran Cudbard-Bell
://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html Arran Cudbard-Bell a.cudba...@networkradius.com Technical consultant and solutions architect 15 Ave. du Granier, Meylan, France +33 4 69 66 54 50 - List info/subscribe

Re: Translation of Reply Messages

2012-03-06 Thread Arran Cudbard-Bell
On 7 Mar 2012, at 07:11, Tim White wrote: I'm wondering if anyone has worked out some way to translate reply messages easily? I'm guessing I probably need to make this happen on the GUI side of my application (Grase Hotspot), but what do other people do in a multi language environment?

Re: Is this a possible project?

2012-03-12 Thread Arran Cudbard-Bell
-Identifier attribute which you could use to distinguish between them. Otherwise most will include a Called-Station-ID attribute which *may* contain a Mac-Address associated with the Access point, you'll need what your Access Point sends. Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki

Re: HP-Command-String in sql accounting

2012-03-12 Thread Arran Cudbard-Bell
update packets. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Mac Auth Rewrite SSID Issue

2012-03-14 Thread Arran Cudbard-Bell
-Id =~ /^([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?([0-9a-f]{2})[-:]?(.*)?/i){ But you're the first one who's complained ;) Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info

Re: Prob web wiki.freeradius.org

2012-05-09 Thread Arran Cudbard-Bell
On 9 May 2012, at 09:51, Thomas Glanzmann wrote: Hello Alan, Torsten Lehmann wrote: http://wiki.freeradius.org/ (or faq) returns: Forbidden * Alan DeKok al...@deployingradius.com [2012-05-09 09:44]: It works for me. We upgraded the machine, and had a few problems with editing the

Re: Prob web wiki.freeradius.org

2012-05-09 Thread Arran Cudbard-Bell
the page, accessing is fine. But Arran seems to fix that. Yep working on it, expect some downtime today whilst I try and cleanup the ruby installation and Gollum... The upgrade to 12.04 has really messed things up. Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki

Re: Prob web wiki.freeradius.org

2012-05-10 Thread Arran Cudbard-Bell
by' link at the bottom of the page, as they're the company who's actually paying for the hosting ;) Apologies for the down time/ Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info/subscribe/unsubscribe? See http

Re: wiki problems...

2012-05-10 Thread Arran Cudbard-Bell
On 10 May 2012, at 15:41, Alan DeKok wrote: Paolo Barbato wrote: accessing http://wiki.freeradius.org return forbidden It works for me. Might be an intermediary cache misbehaving? Is it an nginx forbidden message or a tiny little non-descript one? -Arran Arran Cudbard-Bell a.cudba

Re: wiki problems...

2012-05-10 Thread Arran Cudbard-Bell
. To diagnose i'd need a packet trace of a request to the wiki server. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: wiki problems...

2012-05-10 Thread Arran Cudbard-Bell
Of Arran Cudbard-Bell Sent: 10 May 2012 14:53 To: FreeRadius users mailing list Subject: Re: wiki problems... On 10 May 2012, at 15:41, Alan DeKok wrote: Paolo Barbato wrote: accessing http://wiki.freeradius.org return forbidden It works for me. Might be an intermediary cache

Re: wiki problems...

2012-05-10 Thread Arran Cudbard-Bell
On 10 May 2012, at 16:40, Paolo Barbato wrote: On 10/mag/2012, at 16:18, Arran Cudbard-Bell wrote: On 10 May 2012, at 15:55, Paolo Barbato wrote: Glad to hear…it's has been working also for me in the past…now return forbidden…who has in charge that wiki ? Me. smile If it's

Re: wiki problems...

2012-05-10 Thread Arran Cudbard-Bell
Ok, just to let everyone know, that the 'Forbidden' error should now be fixed. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Anon repo access?

2012-05-15 Thread Arran Cudbard-Bell
'... fatal: remote error: access denied or repository not exported: /freeradius-server.git Fixed. Apologies; recently migrated to gitolite. -Arran Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info/subscribe/unsubscribe? See

Re: How to set attribute value as null means that

2012-05-15 Thread Arran Cudbard-Bell
On 15 May 2012, at 21:26, mimir wrote: Hello, I want to add a custom attribute before replicate the accounting package with null value. I see that it is added successfully before replication, but when I check it on remote server, I can not see userid1 and userid2 attributes. Do you have

Re: FR over TCP

2012-05-24 Thread Arran Cudbard-Bell
if it is possible and I can read and understand how. Thank you !! Yes - Google radsec. Arran Cudbard-Bell a.cudba...@freeradius.org Betelwiki, Betelwiki, Betelwiki http://wiki.freeradius.org/ ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

<    4   5   6   7   8   9   10   11   12   13   >