FreeRADIUS as proxy to Windows IAS

2007-07-30 Thread Clive Gould
Hi I'd be grateful to hear from anyone out there who has got Freeradius (on a Linux box) running as a proxy server successfully validating usernames and passwords against a Windows IAS server using the MSChapv2 protocol. I have the Freeradius server up and running on CentOS 4.5, but can't get it

Re: Freeradius as a proxy to Windows IAS

2007-07-31 Thread Clive Gould
Hi Thanks for the replies to my posting yesterday. Perhaps I can explain the situation more clearly. My goal is to authenticate login to the digital repository DSpace against a Windows IAS server. I do not have physical access to the IAS server and cannot change it's shared secret. So far I

Re: Freeradius as a proxy to Windows IAS (Peter Nixon)

2007-07-31 Thread Clive Gould
packet from 10.200.0.2:1812 with invalid signature (err=2)! (Shared secret is incorrect.) Server rejecting request 0. Are there any characters (e.g. \) which must not be used in a shared secret with a Freeradius server? Best wishes Clive On Tue 31 Jul 2007, Clive Gould wrote: Hi Thanks

Re: Freeradius as a proxy to Windows IAS - Solved!

2007-07-31 Thread Clive Gould
Hi everyone Please ignore my postings about problems with IAS authentication. I have just read this in the FAQ: FreeRADIUS is limited to 16 characters for the shared secret. The shared secret on our IAS server is 25 characters long :-( Thanks anyway Clive - List

Re: Freeradius as a proxy to Windows IAS - not solved after all :-(

2007-07-31 Thread Clive Gould
Hi everyone Thanks for all the help and advice so far :-) I have installed freeradius 1.1.7 and get the appended message when I try to use it as a proxy between a Linux/Moodle/PHP radius client and a Windows IAS server. The shared secrets are definitely the same. The Linux/Moodle/PHP radius

Re: Freeradius as a proxy to Windows IAS - reserved characters in shared secret?

2007-08-01 Thread clive gould
Hi I've just been doing some research on the net and found this link on the GNU radius client reference page: http://www.gnu.org/software/radius/manual/html_chapter/radius_13.html#SEC262 It looks as if the radtest client has reserved characters. Does anyone know if this applies to shared

Re: Freeradius as a proxy to Windows IAS - reserved characters in shared secret?

2007-08-01 Thread clive gould
Hi Thanks once again for all the advice :-) Does anyone know if there some characters that are reserved i.e cannot be used in secret keys with a freeradius server. If so what are they? I've been experimenting with the radtest client and the freeradius server using local unix validation with

Re[2]: Freeradius as a proxy to Windows IAS - reserved

2007-08-01 Thread clive gould
Brilliant Thanks Claudia :-))) Putting the shared secret in single quotes 'se\cret' in radclient and in double quotes with the backslash escaped in clients.conf and proxy.conf se\\cret worked fine with the radtest and what's more this now works too: Linux VLE

HELP: Windows IAS / FreeRADIUS Proxy problem

2008-11-22 Thread clive gould
Can anybody help please? We use a FreeRADIUS proxy for authenticating DSpace with MS AD via MS IAS Our ITNS team have just rebuilt the IAS server after it suffered a hardware failure failed and since the rebuild it is now rejecting FreeRADIUS proxy requests. IAS will still respond to my Moodle