Re: FreeRadius radrelay and proxying the Realm attribute to the home_server

2011-12-16 Thread Matthew Newton
, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: VSA's and local dictionary

2011-12-20 Thread Matthew Newton
them again yourself. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe

Re: compiling freeradius 2.1.12 in Debian squeeze

2012-01-16 Thread Matthew Newton
it will build (may not be the actual fix, but gets it to build I'm not using rlm_sql). Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn

Microsoft PEAP-EAP-TLS support (certificate auth with SoH)?

2012-01-19 Thread Matthew Newton
to support a few additional options in their built-in supplicant, rather than just the couple of odd combinations that they want.) -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United

Re: Microsoft PEAP-EAP-TLS support (certificate auth with SoH)? - works!

2012-01-20 Thread Matthew Newton
Hi, It's working! On Fri, Jan 20, 2012 at 08:28:49AM +0100, Alan DeKok wrote: Matthew Newton wrote: Does anyone know if FreeRADIUS now supports Microsoft PEAP/EAP-TLS, i.e. when you select PEAP with Certificates in It's not a widely used feature. Obviously :-) SoH is the only reasonably

Re: Segfault in 2.1.10 backports version advice

2012-01-23 Thread Matthew Newton
) is trivial as all the Debian stuff is there to build your package for you :-). Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253

Re: Authenticating Laptop without a Certificate Installed

2012-01-24 Thread Matthew Newton
Validate server certificate. (Then think if this is the best way to do it, and consider installing the root certificate and ticking the box again.) Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester

Re: self-signed root CA

2012-01-25 Thread Matthew Newton
to distribute the CA cert (which we do) to the clients If you can easily push the certs out, I'd go for the more secure self-singned certs, as the main objection to it seems to be pushing out the CA cert. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network

Re: Verifying you are Joining the Active Directory Domain

2012-01-31 Thread Matthew Newton
:/home/sqauser# root@FreeRadius:/home/sqauser# wbinfo -u Error looking up domain users If you've only just joined the domain, you likely need to restart winbindd. But get your time synchronized properly first. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks

Re: Multi-domain AD and Users Who Aren't So Bright

2012-02-02 Thread Matthew Newton
be harder. I'm rather guessing here, but I wonder if LDAP searching the AD global catalogue (ports 3268/3269) would make this work with one search? But that's not really a FreeRADIUS issue. You'd probably be better finding a samba or AD list. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems

Re: Design question

2012-02-02 Thread Matthew Newton
up why, and a mini how-to at http://q.asd.me.uk/pet -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info

Re: Design question

2012-02-02 Thread Matthew Newton
On Thu, Feb 02, 2012 at 06:27:31PM -0600, Dan Letkeman wrote: On Thu, Feb 2, 2012 at 4:47 PM, Matthew Newton m...@leicester.ac.uk wrote: That will work, but you shouldn't. Create a different certificate for each client, and for the radius server, all signed by the same CA. This would

Re: Multi-domain AD and Users Who Aren't So Bright

2012-02-03 Thread Matthew Newton
Hi, On Fri, Feb 03, 2012 at 08:22:38AM +0100, NdK wrote: Il 02/02/2012 21:59, Matthew Newton ha scritto: /usr/bin/net ads search -P (mail=%{User-Name}) sAMAccountName|grep sAMAccountName|sed s/^[^ ]* // (maybe it's possible to do the same without using grep and sed, but it's been just

Re: Eduroam F-ticks and syslog

2012-02-05 Thread Matthew Newton
of the log string. Cheers, Matthew From 089c108c472a6a9d2a21ae86b41343b06274f95d Mon Sep 17 00:00:00 2001 From: Matthew Newton m...@leicester.ac.uk Date: Sun, 5 Feb 2012 23:05:27 + Subject: [PATCH] Add syslog_facility option to rlm_linelog --- src/modules/rlm_linelog/rlm_linelog.c | 86

Re: Multiple servers using Realms.

2012-02-05 Thread Matthew Newton
). Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: Freeradius rlm_pam

2012-02-11 Thread Matthew Newton
... Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: Radius Self Service

2012-02-16 Thread Matthew Newton
the mysql database. There's no need to have that running on the same box... Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn

Re: Radius Self Service

2012-02-16 Thread Matthew Newton
fields, and as such its much better to expand personal horizons than give in an hire someone. :-) My thoughts exactly. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH

Re: Freeradius and eduroam

2012-02-17 Thread Matthew Newton
study are possibly most useful to your question. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk

Re: Intermediate root CA issue

2012-02-22 Thread Matthew Newton
unnecessarily (doesn't often happen), but I didn't play to find out. But if importing the intermediate makes it work, that might help point you in the right direction. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University

Re: freeradius eap-ttls user/pass + cert

2012-02-23 Thread Matthew Newton
, I added earlier created client.pem, but server fails to authenticate with message unknown ca cert, I also tried to use ca.pem, but with negative result. The CA for client cert validation goes in CA_file - did you set that? Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect

Re: freeradius eap-ttls user/pass + cert

2012-02-23 Thread Matthew Newton
-- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: freerqdisu2 and peap-eap-tls

2012-02-27 Thread Matthew Newton
use of SoH. is there someone who tryed this method with freeradius2 ? is this supported ? I did it a few weeks ago, and wrote up the reasons for it, and examples. http://q.asd.me.uk/pet Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services

Re: Test Environment: Can PEAPv0 and PEAPv1 be setup together on the default instance?

2012-03-01 Thread Matthew Newton
and not recommended for production use. http://freeradius.org/features/eap.html So you need to look at configuring eap2, rather than eap. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH

Re: Test Environment: Can PEAPv0 and PEAPv1 be setup together on the default instance?

2012-03-01 Thread Matthew Newton
does not handle this gracefully. Last I saw (looking at the comments in the FR rlm_eap_peap source), PEAPv1 is not supported, only v0. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1

Re: RHEL Patches Broke FreeRADIUS

2012-03-03 Thread Matthew Newton
-- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Windows 7 prompting several times

2012-03-06 Thread Matthew Newton
of any windows trace files, that we could see. Unfortunately it's not easily repeatable. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact

Re: Windows 7 prompting several times

2012-03-06 Thread Matthew Newton
/responses etc - I forget the exact details now. Maybe Windows did automatically retry a couple of times, which tripped it up. (This is Cisco wireless LAN controllers - switches may be similar.) We still see it with this off (see in other e-mail) but much less often. Matthew -- Matthew Newton

Re: Conditional attributes with AD

2012-03-06 Thread Matthew Newton
-- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Conditional attributes with AD

2012-03-12 Thread Matthew Newton
groupmembership_filter = ((objectClass=group)(member=%{Ldap-UserDn})) groupmembership_attribute = memberOf Run in debug, look at what it's actually searching, match to the config file, tweak, rinse repeat. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services

Re: Windows 7 clients

2012-03-15 Thread Matthew Newton
, and I was actually doing something else, so it might not be correct. It just niggled me enough at the time to dig a bit deeper, and I put it down to the standard case of Windows being stupid, and moved on. I'd like to be proven incorrect. Thanks, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk

Re: generate a random value with unlang?

2012-03-21 Thread Matthew Newton
been released. ... * Added support for %{rand:...}, which generates a uniformly distributed number between 0 and the number you specify. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester

Re: 802.1x/EAP-TLS and MAC authentication via SQL with dynamic VLANs

2012-03-22 Thread Matthew Newton
.x arrives, there is a new feature that lets you do it in an eap-tls virtual server authorize section, but that's not available yet. Still, there should be no need for that unless you want to reject connections based on TLS certificate data, rather than just set the VLAN. Matthew -- Matthew

Re: openLDAP authorization with PAP authentication

2012-03-31 Thread Matthew Newton
section. Hint: put your whole config in version control (e.g. git) and then it makes it easy to go back to a working config when you break it. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester

Re: MSSCHAP auth + LDAP authorizaton

2012-04-03 Thread Matthew Newton
what it's doing, as usual. Use unlang in your inner-tunnel authorize section to check the ldap group, something along the lines of (very untested): if (!(Ldap-group == 'cn=group,dc=example,dc=com')) { reject } Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX

Re: windows 7 eap-tls authentication

2012-04-04 Thread Matthew Newton
WARNING: !! windows never responds. Ready to process requests. --- - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks

Re: Create a counter for Max-Single-Session

2012-04-04 Thread Matthew Newton
something like e.g. update reply { Session-Timeout := 600 } to cause the remote client to have to reauth after 600 seconds rather than the NAS default. Of course, you want some mechanism to deny them access when they come back asking for access the next time. Matthew -- Matthew Newton

Re: Can't get accounting radacct to work?

2012-04-04 Thread Matthew Newton
-- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Proxy radius

2012-04-05 Thread Matthew Newton
Hi, On Thu, Apr 05, 2012 at 02:36:25PM +0800, cktan wrote: Can the proxy radius return an additional attribute to NAS apart from the attribute return by the actual radius server? I've an update reply { ... } in the post-proxy section of your config. Matthew -- Matthew Newton, Ph.D. m

Re: atributing VLANs to roaming users

2012-04-05 Thread Matthew Newton
users vlan } } # Case for other realm - put on to visitors VLAN case { update reply { Tunnel-Private-Group-Id := eduroam visitor vlan } } } (I set Stripped-User-Realm earlier with unlang.) Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems

Re: Windows 7 prompting several times

2012-04-11 Thread Matthew Newton
://www3.uwic.ac.uk/English/News/Pages/UWIC-Name-Change.aspx - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks

Re: kill -HUP sometimes causes rlm_pap: mschap xlat failed

2012-04-12 Thread Matthew Newton
a problem. I'll dig a bit more, but the easy solution is to change the logrotate script to restart, rather than reload/HUP. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH

Re: kill -HUP sometimes causes rlm_pap: mschap xlat failed

2012-04-12 Thread Matthew Newton
On Thu, Apr 12, 2012 at 04:45:56PM +0200, Jan Weiher wrote: Am 12.04.2012 16:32, schrieb Matthew Newton: I'll dig a bit more, but the easy solution is to change the logrotate script to restart, rather than reload/HUP. Yes, that would be a solution for me as well, because when logrotate

Re: Some question about Athorization of FreeRadius.

2012-04-13 Thread Matthew Newton
, WISPr-Bandwidth-Max-Down = 200 in your users file (there are plenty of other ways to do this - unlang, sql, etc) will mean that all users get 1Mbit up and 2Mbit down. You can send these with different values per user if you want. Cheers, Matthew -- Matthew Newton, Ph.D. m

Re: kill -HUP sometimes causes rlm_pap: mschap xlat failed

2012-04-13 Thread Matthew Newton
where we used xlats for EAP/MSCHAPv2, but realise they are in the ntlm_auth line for the Challenge/Response. So, looking good so far - thanks Alan! Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester

Re: PATCH: Correct ldaps port number in stock config comments.

2012-04-13 Thread Matthew Newton
timeout = 4 -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: Setting up FreeRADIUS accounting with IP address logging

2012-04-14 Thread Matthew Newton
. Cheers Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: post-auth problem after update from 2.0.4 to 2.1.10

2012-04-16 Thread Matthew Newton
RADIUS goodness (although if you don't install the freeradius-mysql package you'll have to remove /etc/freeradius/modules/dhcp_sqlippool to get it to start). Matthew [0] http://notes.asd.me.uk/2012/01/27/compiling_freeradius_from_git_on_debian/ -- Matthew Newton, Ph.D. m...@le.ac.uk Systems

Re: Freeradius with Cisco Wireless Controller

2012-04-18 Thread Matthew Newton
the latter. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: using windows 8's builtin eap-ttls... Windows 8 bug

2012-04-19 Thread Matthew Newton
with EAP-TTLS/MSCHAP is also fine, as there is no Access-Challenge sent; it's a direct Access-Accept with EAP-Message 0x030a0004 (Success). As Alan noted, EAP-TTLS/EAP-MSCHAP-V2 also seems fine. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks

Re:Freeradius Access Requet ID

2012-04-20 Thread Matthew Newton
-auth { Post-Auth-Type REJECT { # here } } Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List

Re: passwd encrypted in user file

2012-04-20 Thread Matthew Newton
you use a 3rd party supplicant or Windows 8. Windows built-in only supports PEAP/MS-CHAPv2 for auth. The password has to be stored clear-text or as an NT hash. http://deployingradius.com/documents/protocols/compatibility.html This was posted to the list just earlier today. Matthew -- Matthew

Re: Building 2.1.12 on Debian Squeeze: Clean Error

2012-04-22 Thread Matthew Newton
dh_installinit --noscripts Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info

Re: ..::Change to MD5 passwords::..

2012-04-23 Thread Matthew Newton
, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: ..::Change to MD5 passwords::..

2012-04-23 Thread Matthew Newton
think it's been posted today so far... http://deployingradius.com/documents/protocols/compatibility.html Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help

Re: ..::Change to MD5 passwords::..

2012-04-23 Thread Matthew Newton
in error, please do not forward and destroy immediately. # - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX

Re: falling back to local auth and not ads

2012-04-24 Thread Matthew Newton
[mschap] FAILED: No NT/LM-Password. Cannot perform authentication. [mschap] FAILED: MS-CHAP2-Response is incorrect Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom

Re: falling back to local auth and not ads

2012-04-24 Thread Matthew Newton
be there. Matthew -Original Message- From: freeradius-users-bounces+amorris=cardiffmet.ac...@lists.freeradius.org [mailto:freeradius-users-bounces+amorris=cardiffmet.ac...@lists.freeradius.org] On Behalf Of Matthew Newton Sent: 24 April 2012 10:54 To: FreeRadius users mailing list

Re: RADIUS + LDAP authentication problem

2012-04-25 Thread Matthew Newton
{...} Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: Proxy Question

2012-04-25 Thread Matthew Newton
realm 'externalaaa' in your proxy.conf file, as normal. There must be many ways to do this. Another possibility in your users file - b...@bob.comProxy-To-Realm := 'whatever' DEFAULT Auth-Type := Reject Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX

Re: Cisco WLC - Freeradius Vlan assigment problem

2012-04-25 Thread Matthew Newton
. Ensure you have 'aaa override' enabled on each of the WLANs, otherwise it won't. It's at the top-left, second option down, of the far right tab in the WLAN GUI, if memory serves correctly. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T

Re: PEAP/MSCHAPv2 - Host Account Authentication Only

2012-04-25 Thread Matthew Newton
. Debugging Output: Not really useful - you showed radiusd -X, but stopped before any packets hit. Good job we can occasionally mind-read[0] ;) Cheers Matthew [0] Warning: mind reading is sub-optimal and often wrong. -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks

Re: PEAP/MSCHAPv2 - Host Account Authentication Only

2012-04-25 Thread Matthew Newton
. Gives more ways of verifying things look ok. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List

Re: Log-rotation FeeBSD 8.2

2012-04-30 Thread Matthew Newton
-- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: RE2: Log-rotation FeeBSD 8.2

2012-04-30 Thread Matthew Newton
are not the same thing. Read up on unix files and inodes. Could the same behavior be implemented to auto-rotation of FR2 logs? Send a HUP. It's the Right Thing. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester

Re: Backup and restore FR

2012-05-16 Thread Matthew Newton
of ways of copying files between two machines. If you're using a database, do whatever method that uses to copy data across. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United

Re: 2 Certs for 2 SSID (802.1x)

2012-05-18 Thread Matthew Newton
-Station-Id =~ /eduroam/) { or you may want something more like if (Called-Station-Id =~ /:eduroam$/) { to check that it ends in :eduroam Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester

Re: Test Client which supports PAP Access-Challenge

2012-05-21 Thread Matthew Newton
-- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Test Client which supports PAP Access-Challenge

2012-05-21 Thread Matthew Newton
, auth, status, etc. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe

Re: Test Client which supports PAP Access-Challenge

2012-05-21 Thread Matthew Newton
On Mon, May 21, 2012 at 02:23:12PM +0100, Matthew Newton wrote: Looks like radclient has support: Forget that - I've not had enough coffee yet today :) You need to respond to the challenge, not send one yourself... Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX

Re: Values for MySQL tables for pptpd ?

2012-05-23 Thread Matthew Newton
of it. But this is all mildly off-topic for FreeRADIUS... Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info

Re: Values for MySQL tables for pptpd ?

2012-05-23 Thread Matthew Newton
On Wed, May 23, 2012 at 02:02:02PM +0200, Alan DeKok wrote: Matthew Newton wrote: I'm not sure who looks after them now, or if they are maintained. I've just found radiusclient-ng, which looks more recent, but have no experience of it. But this is all mildly off-topic for FreeRADIUS

Re: rlm_perl added pairs disapear after eap authentication

2012-05-31 Thread Matthew Newton
on that. At this stage you know that setting the AVPs there works, so if it's broken it must be your perl code or rlm_perl settings :-) Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH

Re: Password Scrambled - Shared Secrets Match

2012-05-31 Thread Matthew Newton
. Then further down ... radiusd: Loading Clients client 127.0.0.1 { require_message_authenticator = no secret = testing123 shortname = localhost nastype = other } ... etc. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks

Re: accounting in syslog

2012-06-05 Thread Matthew Newton
Acct-Terminate-Cause = User-Request Acct-Session-Time = 77 Acct-Delay-Time = 0 Calling-Station-Id = 0.0.0.0 Called-Station-Id = 172.18.47.242 Cisco-AVPair = nas-update=true -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network

Re: Problems with Huntgroup

2012-06-05 Thread Matthew Newton
the module isn't being called when you've just added it, then the module is not being called and you're configuring things in the wrong place. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester

Re: Problems with Huntgroup

2012-06-06 Thread Matthew Newton
the module that checks huntgroups. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info

Re: Problems with Huntgroup

2012-06-06 Thread Matthew Newton
happen. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: Problems with Huntgroup

2012-06-07 Thread Matthew Newton
of id 192 to 10.129.85.1 port 39402 Finished request 0. End of Output -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith

Re: it's not disconnect users after Max-Daily-Session ends.

2012-06-10 Thread Matthew Newton
disconnected at the right time, then work out why the NAS isn't kicking the user off. and noting wrote in output of freeradius -X command You won't necessarily see anything in the output of freeradius, unless the NAS also sends an Accounting Stop at the same time. Matthew -- Matthew Newton, Ph.D

Re: Re : Re: EAP processing

2012-06-13 Thread Matthew Newton
and resources. This config stops that happening. In short, you generally just need to leave it alone and not worry about it. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom

Re: Auth-Type :- Reject in users file matches inner tunnel request but sends Access-Accept

2012-06-13 Thread Matthew Newton
. Then you won't be checking this stuff for the anonymous user in the outer anyway. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn

Re: Difference between local and external in inner-tunnel

2012-06-15 Thread Matthew Newton
-IP-Address, etc), then just check for membership of the huntgroup. Just rememeber Packet-Src-Ip-Address can't easily be spoofed, whereas attributed in the incoming packet can be. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T

Re: Problem with EAP-TLS and certificate

2012-06-18 Thread Matthew Newton
to load the private key in every format it can, but failing to understand any of them. There's generally not a problem with FreeRADIUS and wpa_supplicant (or eapol_test), so check your certificates. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks

Re: Freeradius not expanding %{User-Password} (EAP-TTLS with MD5 authentication)

2012-06-18 Thread Matthew Newton
to EAP-TTLS/PAP, for example, and try again. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info

Re: Configure FreeRadius to send CoA-ACK

2012-06-18 Thread Matthew Newton
No such virtual server coa ...and there's no virtual server configured to handle coa requests... } # server coa Sending CoA-NAK of id 0 to 10.42.154.231 port 35046 ...which is why you get a CoA-NAK. honestly I can't understand why CoA-NAK is sent. Really? Matthew -- Matthew Newton, Ph.D. m

Re: Freeradius 2 , TTLS/PAP, multiples questions

2012-06-19 Thread Matthew Newton
On Tue, Jun 19, 2012 at 03:02:09AM -0700, akkouche wrote: I try to configure TLS withPAP it does not work? http://wiki.freeradius.org/FAQ#It-still-doesn%27t-work%21 -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University

Re: FreeRadius/OpenLdap

2012-06-20 Thread Matthew Newton
= titi ... How many people need to tell you? Your shared secret is wrong. You send one password, and the RADIUS server sees a different one. Your shared secret is wrong. Check your shared secret matches in clients.conf and on your NAS. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems

Re: Reg: Accept the user without Mysql check.

2012-06-22 Thread Matthew Newton
On Fri, Jun 22, 2012 at 04:17:21PM +0100, Malla reddy Sama wrote: Please check once now. I am facing same problem.. Your netmask is wrong, or your subnet is wrong  client 172.20.0.0/24 { should probably be  client 172.20.68.0/24 { Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems

Re: Question on Cisco-AVPair = device-traffic-class=voice

2012-06-22 Thread Matthew Newton
On Sat, Jun 23, 2012 at 06:24:40AM +0800, John wrote: Is there a way that freeradius can tell it is a VOICE device?  Like ACS server: Cisco-AVPair = device-traffic-class=voice. man unlang update reply { cisco-avpair := device-traffic-class=voice } Matthew -- Matthew Newton, Ph.D. m

Re: Question on Cisco-AVPair = device-traffic-class=voice

2012-06-23 Thread Matthew Newton
other more useful manufacturers they use many different prefixes for their phones. That pushes you to have to use a database of some kind if you use their system (which thankfully we don't). Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network

Re: problem with multiple ldap

2012-07-07 Thread Matthew Newton
On Sat, Jul 07, 2012 at 07:10:49PM +0530, Prateek Kumar wrote: NAS-IP-Address so clients (using PEAP/MSCHAPv2) associating to particular ... Is there some thing I have missed ? set copy_request_to_tunnel=yes in the peap {} section of eap.conf Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk

Re: Duplicate clients entry segmentation fault after killing radius server

2012-07-20 Thread Matthew Newton
) and see what happens. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe

Re: Certificate validation checkbox - windows 7 wired

2012-07-24 Thread Matthew Newton
to you, but you've stopped responding. Can anybody shed any light please? Diff the configs certs for a start. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom

Re: Session-Timeout

2012-07-26 Thread Matthew Newton
state it is), it's the job of the NAS (the AP) to disconnect the user at the specified time. The user will keep working until the NAS kicks them off. As the user isn't being disconnected, it's the NAS that needs investigating. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect

Re: Acct-Status-Type

2012-07-29 Thread Matthew Newton
won't tell you if your user is still actually alive; you need a doctor for that. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn

Re: Acct-Status-Type

2012-07-30 Thread Matthew Newton
:-) Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith...@le.ac.uk - List info/subscribe/unsubscribe? See http

Re: linelog and accounting informations

2012-08-02 Thread Matthew Newton
server when it looses a client ? The NAS informs the RADIUS server; the RADIUS server doesn't request the information. So when a client is disconnected, the NAS notices and sends an appropriate Accounting packet. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks

Re: user(name) and EAP-TLS

2012-08-04 Thread Matthew Newton
or otherwise. c) backport the tls virtual server patch to 2.x - it's pretty simple. Cheers Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk

Re: Radius copy accounting

2012-08-06 Thread Matthew Newton
(see dictionary.freeradius.internal) and as such doesn't appear in any packets in transit. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Architect (UNIX and Networks), Network Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact

  1   2   3   >