Checkval weird issue with LDAP backend and PAM authentication

2010-11-22 Thread marco
some kind of mistake, but I really am not able to find it.Now are days I'm googling around and getting quite crazy - I hope that someone of you may help meThank you very much   Marco Carcano   Configuration files RADIUSD.CONF### prefix = /usr

Re: Checkval weird issue with LDAP backend and PAM authentication

2010-11-23 Thread marco
section altought checkval module module NAS returned notfound? I'm sure I did some kind of mistake, but I really am not able to find it. Now are days I'm googling around and getting quite crazy - I hope that someone of you may help meThank you very much Marco Carcano Configuration files

RE: Failing debuild

2004-07-01 Thread marco
This isn't a problem. You were right. Cause of error in deb creating is failure of relinking stage: *** Warning: Linking the shared library rlm_eap_peap.la against the loadable module *** rlm_eap_tls.so is not portable! gcc -shared .libs/rlm_eap_peap.o .libs/peap.o -Wl,--rpath

RE: Failing debuild

2004-07-01 Thread marco
gcc -shared .libs/rlm_eap_peap.o .libs/peap.o -Wl,--rpath -Wl,/usr/lib/freeradius -L/root/downloads/freeradi us-snapshot-20040629/debian/freeradius/usr/lib/freeradius -L/usr/lib/freerad ius -lradius -lrlm_eap_tls As time goes by, my hatred of libtool grows even more. It's turning a

RE: suse 9.1 experience - freeradius

2004-07-08 Thread marco
Just wondering if anyone else has tried running out-of-the-box freeradius and openssl versions on SuSE 9.1 pro and had any issues? A lot of problems using last snapshots (suse9.1 and debian sid): leaving enable shared lib. rlm_eap rlm_eap_ttls rlm_eap_peap disappear and get no linking.

RE: redhat spec file problem?

2004-07-26 Thread marco
i've changed the spec for the same reason. You can try it (see attachment), interesting ... where ? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Setting Up a Freeradius server

2004-08-25 Thread marco
Subject: Setting Up a Freeradius Server Date: Wednesday 25 August 2004 16:17 From: Marco Garro [EMAIL PROTECTED] To: FreeRadius [EMAIL PROTECTED] Hi all, i'm new to freeradius world. I'm trying to set up a FreeRadius server because I need eap-tls authentication in my WLAN. I'm using a BUFFALO

EAP and external authentication script

2005-02-10 Thread Marco
client wis-network port 31 cli 000cf102223f) Delaying request 8 for 1 seconds Finished request 8 Going to the next request rl_next: returning NULL --- What I'm doing wrong ? Thank you, -- Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP and external authentication script

2005-02-10 Thread Marco
the same with EAP? If I understood correctly PEAP, for example, tunnels an MSCHAP authentication. Where I can tell to freeradius to use a script to perform this authentication? I hope it's more clear now. Thank you for your support. -- Marco - List info/subscribe/unsubscribe? See http

Re: ippool problem

2004-06-08 Thread marco
Hi this is the debug with the error ippool: ip-index = /usr/local/etc/raddb/db.ipindex ippool: range-start = 192.168.1.1 IP address [192.168.1.1] ippool: range-stop = 192.168.3.254 IP address [192.168.3.254] ippool: netmask = 255.255.255.0 IP address [255.255.255.0] ippool: cache-size =

RE: Error: rlm_eap: No EAP session matching the State variable.

2010-04-12 Thread marco zamora
. Atentamente: Marco Zamora Date: Mon, 12 Apr 2010 10:07:26 +0530 Subject: Error: rlm_eap: No EAP session matching the State variable. From: a.rupes...@gmail.com To: freeradius-users@lists.freeradius.org Hi, I am using latest freeradius server (version 2.1.8). I have two authenticated

expired user accounts between two dates

2010-05-27 Thread Marco Jaraiz
hello, i want to use expiration module to validate user account, but i need check the expirtation between two dates, init and finish date. somebody help me. thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

proxy everyone

2010-07-20 Thread marco perugini
hi list! i'm setting up my freeradius architecture with a single proxy and multiple servers; here's my scenario: freeradius server # 1 - my own server [realm local.net] freeradius server # 2 - external server [realm ext.net] freeradius proxy - i know everything about users i proxy towards my

freeradius 2.1.10 DHCP not responding

2010-10-13 Thread Zietz, Marco
} dhcp { reject } } === Any hint appreciated! If you need extra info let me know. Thank you for your help! Cheers Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

DHCP with option 82 best practice

2010-10-18 Thread Zietz, Marco
can stop searching and start coding ;o) Any comment much appreciated! Cheers, Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Checkval weird issue with LDAP backend and PAM authentication

2010-11-25 Thread Marco Carcano
Marco Carcano Il giorno 23/nov/10, alle ore 16:25, John Dennis ha scritto: On 11/23/2010 08:33 AM, Alan DeKok wrote: marco wrote: Sorry Alan I've not realized that the logs had became a garbage :O( - maybe a webmail realted issue of my ISP. Now I Bcc myself to see how does it appear

Re: Checkval weird issue with LDAP backend and PAM authentication

2010-11-25 Thread Marco Carcano
this with quite a lot of other packages in ECK Il giorno 23/nov/10, alle ore 14:33, Alan DeKok ha scritto: marco wrote: Sorry Alan I've not realized that the logs had became a garbage :O( - maybe a webmail realted issue of my ISP. Now I Bcc myself to see how does it appear to recipients I

Re: Checkval weird issue with LDAP backend and PAM authentication

2010-11-26 Thread Marco Carcano
at the final race, ... I really do not understand why you cannot provide just an example - maybe I am a stupid, but I re-read more times unlang manual without beeing able to figure the right syntax Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Checkval weird issue with LDAP backend and PAM authentication

2010-11-26 Thread Marco Carcano
provided is an LDAP DN I tought it is not necessary to supply the LDAP URL because they are already provided in modules/ldap file Now I'm sure I have undestood absolutely nothing about this module Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Checkval weird issue with LDAP backend and PAM authentication

2010-11-26 Thread Marco Carcano
[*]} == % {NAS-Identifier} ) and if (%{ldap:ldap://127.0.0.1/CN=%{User- Name},OU=Users,DC=marcolinux,DC=local?eckAllowedServices}[*] == % {NAS-Identifier} ) but had no luck Marco Carcano just for info (for other users that may read this post in the future): I was wondering if it performed

Re: Checkval weird issue with LDAP backend and PAM authentication SOLVED with unlang

2010-11-26 Thread Marco Carcano
Good luck Marco Carcano - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Freeradius, EAP-PEAP, LDAP and users file...

2008-04-02 Thread Marco Gaiarin
, Ldap-Group == *, Auth-Type := Reject Reply-Message = Gruppo non autorizzato if i remove the last entry, user got authenticated. But users file was 'no match, no party'? What i'm missing? Thanks. -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66

Re: Freeradius, EAP-PEAP, LDAP and users file...

2008-04-02 Thread Marco Gaiarin
. good night. -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La Nostra Famiglia''http://www.sv.lnf.it/ Polo FVG - Via della Bontà, 7 - 33078 - San Vito al Tagliamento (PN) marco.gaiarin(at)sv.lnf.it tel +39-0434-842711 fax

Re: Freeradius, EAP-PEAP, LDAP and users file...

2008-04-03 Thread Marco Gaiarin
. -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La Nostra Famiglia''http://www.sv.lnf.it/ Polo FVG - Via della Bontà, 7 - 33078 - San Vito al Tagliamento (PN) marco.gaiarin(at)sv.lnf.it tel +39-0434-842711 fax +39-0434

Re: Freeradius, EAP-PEAP, LDAP and users file...

2008-04-03 Thread Marco Gaiarin
Mandi! Phil Mayers In chel di` si favelave... You are not running the default config. You've added the ldap module, so even though files doesn't match, ldap does. Perfectly clear. Reviewing all the stuff indeed now is clear, thanks. -- dott. Marco Gaiarin

Re: Expiration?

2008-04-29 Thread Marco Gaiarin
Thanks. -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La Nostra Famiglia''http://www.sv.lnf.it/ Polo FVG - Via della Bontà, 7 - 33078 - San Vito al Tagliamento (PN) marco.gaiarin(at)sv.lnf.it tel +39-0434-842711 fax

Expiration?

2008-04-29 Thread Marco Gaiarin
around, nor an expalnation if can be used and how on 'users' file. Speaking clearly: can i define in 'users' file some users with an explicit 'expiration date'? Someone can explain me how? Thanks. -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La

Re: Expiration?

2008-04-29 Thread Marco Gaiarin
. Boh, it is not a big trouble, only a little curiosity. ;) -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La Nostra Famiglia''http://www.sv.lnf.it/ Polo FVG - Via della Bontà, 7 - 33078 - San Vito al Tagliamento (PN

ldap and file authentication

2011-04-12 Thread Marco Kalmbach
hi @all, is it possible to provide ldap authentication and users file authentication at the same time on a radius server? On my radius server the ldap authentication works fine, additional I want to provide users file authentication, so I commented out the following lines: --radiusd.conf file

802.1x auth EAP-TLS problem

2011-06-28 Thread Marco Londero
verify ca.pem ca.pem: OK FP42A certs # openssl verify server.pem server.pem: OK FP42A certs # openssl verify 02.pem 02.pem: OK --- Any tips? Thank you! -- mandi, Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: [SOLVED] 802.1x auth EAP-TLS problem

2011-06-28 Thread Marco Londero
On Tue, 28 Jun 2011 10:28:45 +0200, Alan DeKok al...@deployingradius.com wrote: Use the correct certificates. I re-generated client certificate and signed it w/ CA one instead of server (default Makefile conf) and worked. Sorry for the noise. -- mandi, Marco - List info/subscribe/unsubscribe

Bind username to certificate

2011-06-28 Thread Marco Londero
Hi folks, is it possible to bind a SSL certificate (used for EAP-TLS auth) to a specific LDAP user instead of using user's LDAP-stored password? Thank you! -- mandi, Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Bind username to certificate

2011-06-28 Thread Marco Londero
On Tue, 28 Jun 2011 15:00:18 +0200, Alan DeKok al...@deployingradius.com wrote: See raddb/sites-available/default. Look for tls You will need to write your own policies to enforce this. FreeRADIUS provides the pieces, you need to put them together. Thank you, Alan. -- mandi, Marco - List

Re: [SOLVED] 802.1x auth EAP-TLS problem

2011-06-29 Thread Marco Londero
/certs/Makefile: --- client.crt: client.csr ca.pem ca.key openssl ca -batch -keyfile ca.key -cert ca.pem -in client.csr -key $(PASSWORD_CA) -out client.crt -extensions xpclient_ext -extfile xpextensions -config ./client.cnf --- -- mandi, Marco - List info/subscribe/unsubscribe? See

802.1x machine authentication patch help

2007-09-28 Thread Marco Casulli
Hi Jamie, Marco from BBC in london. I have read your message (http://lists.cistron.nl/pipermail/freeradius-users/2005-November/048576 .html related to the error when the radius is trying to authenticate in AD and I am getting exactly the same message. No logon workstation trust account

RE: 802.1x machine authentication patch help

2007-10-01 Thread Marco Casulli
Thanks for your reply Phil, However how is samba related to this error? This is an error coming from the AD server no able to authenticate a user. Thanks Marco -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Phil Mayers Sent: 01 October 2007 09:55

RE: 802.1x machine authentication patch help

2007-10-01 Thread Marco Casulli
] On Behalf Of Alan DeKok Sent: 01 October 2007 10:20 To: FreeRadius users mailing list Subject: Re: 802.1x machine authentication patch help Marco Casulli wrote: However how is samba related to this error? This is an error coming from the AD server no able to authenticate a user. If you're

web interface

2004-06-17 Thread Marco Marques
Hello all , I am using freeradius with mysql , is there any web interface that i can use to add and delete ( manage ) the user accounts in the sql server? Best regards Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Setting Up a Freeradius server

2004-08-25 Thread Marco Garro
At least it works! :-) Ciao, Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

VPN PPTP and freeradius will not work

2004-08-26 Thread Marco . Panek
:33 172.20.49.102 AAA: User panekm failed authenticati on. Failure Reason : Invalid user name or password my users config file is: panekm Auth-Type = Local, Password = 700isok in the logs from radius are no entrys. any idea ?? thx Regards / Grüße / Danke Marco Panek - List info/subscribe

Freeradius Traffic logging

2004-10-20 Thread Marco . Panek
Hello List we have freeradius1.0.1 and auth users via Domain. Thats all okay. With perl script radiusreport, i see all users with date and time. And now i will see the traffic. Any idea ?? What must i enabled in radius.conf or must i install an sql server? ThX Regards / Grüße / Danke Marco

Accounting freeradius

2004-10-26 Thread Marco . Panek
Regards / Grüße / Danke Marco Panek ... Smurfit Europa Carton GmbH Information Systems (IS) Tilsiter Straße 144 D-22047 Hamburg Tel:+49 (0)40 30901 191 Fax: +49 (0)40 30901 5191 [EMAIL PROTECTED] - List info/subscribe/unsubscribe

Traffic Logging in detail file

2004-10-26 Thread Marco . Panek
on accounting *:1813 Listening on proxy *:1814 Ready to process requests. Regards / Grüße / Danke Marco Panek ... Smurfit Europa Carton GmbH Information Systems (IS) Tilsiter Straße 144 D-22047 Hamburg Tel:+49 (0)40 30901 191 Fax: +49

radius + dhcp

2009-10-05 Thread marco perugini
hi list! i've two services: radius server and dhcp server. does anyone know if i can assign static address according to realm and not to mac? thanks in advance and best regards, marco -- 4IT S.r.l. Marco Perugini | system administrator

Re: Re: radius + dhcp

2009-10-06 Thread marco perugini
impossible? thanks in advance for your attention and sorry for my bad english, marco Alan DeKok ha scritto: marco perugini wrote: hi list! i've two services: radius server and dhcp server. does anyone know if i can assign static address according to realm and not to mac

raddebug before 2.1.4

2009-10-13 Thread marco perugini
hi list! my simple question is: is there a way to use the powerfull/wonderfull raddebug script with version 2.1.1? or the only way is to start the server with -x option? thanks and regards, marco -- 4IT S.r.l. Marco Perugini | system

Re: Re: raddebug before 2.1.4

2009-10-14 Thread marco perugini
thanks a lot for your feedback alan! you're so helpful.. so i'd have to restart my production server :( i guess i'm going to upgrade! marco Alan DeKok ha scritto: marco perugini wrote: hi list! my simple question is: is there a way to use the powerfull/wonderfull raddebug script

EAP session matching the State variable

2009-10-14 Thread marco perugini
hows me up in radius' debug; in about 20 min i succeed in reconnecting. i thought radius was stateless.. do you know if there is some config changes to do to avoid this trouble? thanks in advance for feedback, if there will be.. ;) marco -- 4IT S.r.l.

Re: Re: EAP session matching the State variable

2009-11-02 Thread marco perugini
Alan DeKok ha scritto: marco perugini wrote: hi list, i use freeradius [v 2.1.1] in wimax context and from yesterday this message is driving me crazy: "EAP session matching the State variable". That's "NO eap session matching..." here'

Re: Re: EAP session matching the State variable

2009-11-02 Thread marco perugini
thank a lot for your feedback alan! marco Alan DeKok ha scritto: marco perugini wrote: is there a way to restart eap session? is there some script to run to have EAP restarted from scratch? Your supplicant needs to re-start the EAP session. This is a question

EAP-MD5 Authentication problem

2005-12-26 Thread Marco Spiga
until we see a request. It work fine also with postgresql but I do not succeed to make this operation. You excuse me for my bad English Thanks -- ! Message from Marco ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

EAP-MD5 Authentication problem

2005-12-26 Thread Marco Spiga
until we see a request. It work fine also with postgresql but I do not succeed to make this operation. You excuse me for my bad English Thanks -- ! Message from Marco ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

EAP-MD5 Authentication problem

2005-12-26 Thread Marco Spiga
until we see a request. It work fine also with postgresql but I do not succeed to make this operation. You excuse me for my bad English Thanks -- ! Message from Marco ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: EAP-MD5 Authentication problem

2005-12-27 Thread Marco Spiga
On Mon, Dec 26, 2005 at 11:40:03AM -0500, Alan DeKok wrote: From: Alan DeKok [EMAIL PROTECTED] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org Date: Mon, 26 Dec 2005 11:40:03 -0500 Subject: Re: EAP-MD5 Authentication problem Marco Spiga [EMAIL PROTECTED] wrote many

Re: EAP-MD5 Authentication problem

2005-12-28 Thread Marco Spiga
Hello!!! I don't know why the 'radeapclient -s -xx 127.0.0.1 auth testing123 req.txt' command don't authenticate whith radiusd. The req.txt file contains: User-Name = test User-Password = password EAP-MD5-Password = password NAS-IP-Address = 127.0.0.1 NAS-Port = 10 EAP-Code = Response

Re: EAP-MD5 Authentication problem

2005-12-28 Thread Marco Spiga
, but it don't work. I attend trusting your re-enter from the vacation. Bye Marco From: Marco Spiga [EMAIL PROTECTED] Reply-To: FreeRadius users mailing list freeradius-users@lists.freeradius.org To: freeradius-users@lists.freeradius.org Subject: Re: EAP-MD5 Authentication problem Date

Re: EAP-MD5 Authentication problem

2005-12-28 Thread Marco Spiga
an other attempt --- Another info: FreeRADIUS Version 1.0.4 over FC4 --- Bye Marco On Wed, Dec 28, 2005 at 12:02:58PM -0500, Alan DeKok wrote: From: Alan DeKok [EMAIL PROTECTED] To: FreeRadius users mailing list freeradius-users@lists.freeradius.org

Re: EAP-MD5 Authentication problem

2005-12-28 Thread Marco Spiga
Marco Spiga [EMAIL PROTECTED] wrote: Still it does not work :-(( Go read the FAQ. See 5.10. It's directed specifically at your remark. Alan DEKok. Endured made!! I don't have include the output of radtest because I want to only qualify radiusd to use authentication EAP MD5

Re: EAP-MD5 Authentication problem. Resolved!!!

2005-12-29 Thread Marco Spiga
mailing list freeradius-users@lists.freeradius.org Date: Thu, 29 Dec 2005 02:22:19 -0500 Subject: Re: EAP-MD5 Authentication problem Marco Spiga [EMAIL PROTECTED] wrote: However as soon as installed freeradius I have tried radtest and it worked well, also whith users inserted in radcheck

Re: EAP-MD5 Authentication problem. Resolved!!!

2005-12-30 Thread Marco Spiga
mailing list freeradius-users@lists.freeradius.org Date: Thu, 29 Dec 2005 02:22:19 -0500 Subject: Re: EAP-MD5 Authentication problem Marco Spiga [EMAIL PROTECTED] wrote: However as soon as installed freeradius I have tried radtest and it worked well, also whith users inserted in radcheck

Nas emulator under linux

2006-01-03 Thread Marco Spiga
Hello!! Where I can find a linux-based nas authenticator in order to simulate vary types of authentications? Thanks Marco -- ! Messaggio da Marco ! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Dialupadmin and FreeRADIUS communication issues

2006-01-04 Thread Marco Huggenberger
Hi 2006/1/4, [EMAIL PROTECTED] [EMAIL PROTECTED]: version of OpenSSL and FreeRADIUS and installed Apache on the machine via What Apache Version? AFAIK DialAdmin works only with Apache 1.3.x and not with 2.0.x but don't maybe I'm wrong. Cheers Marco - List info/subscribe/unsubscribe? See

first FR configuration

2004-05-09 Thread Marco Marabelli
Hi all! I am settin up a FreeRadius server on a slack9.1 box; I need some help (links!) about the configuration of some files becouse I didn't find much at freeradius.org apart FAQ's Does exist a mini-howto or a step-by-step help on files configurations? Regards, Marco - List info/subscribe

ippool problem

2004-06-03 Thread Marco Marques
: module "main_pool" returns noop for request 0modcall: group post-auth returns noop for request 0 how can i solve this problem?? other question that i have is how to setup the users file to use a speciic pool? Best regards Marco

ip pool

2004-06-16 Thread Marco Marques
Hi All , i what to know if its possible to use ippools and sql?? i mean having a table with the ippools in the sql database best regards Marco Marques

Re: ip pool

2004-06-16 Thread Marco Marques
Marco Marques [EMAIL PROTECTED] wrote: i what to know if its possible to use ippools and sql?? i mean having a table with the ippools in the sql database Why? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html so i can assing ips from

accouting over more than one servers

2006-07-10 Thread Fretz Marco
AAA on a CISCO IOS to send periodically accounting infos to the radius server? thanks and kind regards marco fretz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

show logged in users

2006-07-10 Thread Fretz Marco
the router from our webinterface or some admin hosts can i be 100% sure that a user is logged in if there is no stop event? thanks and kind regards marco fretz - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRadius Autostart

2006-07-10 Thread Marco Fretz
we should really know your operating system. but on most systems you have to write a small rc script (shell scirpt) with a start and stop command. unter redhat you can hang in the script in your system with the tool chkconfig greets marco Wasif schrieb: Hi all, I have a simple question

Re: Operation of a radius server

2006-07-19 Thread Marco Fretz
hello dave i know the following: the clients dsl router establishes a pppoe connection with the NAS (my a cisco access router with pppoe support and authentification agains radius). the NAS needs the framed-ip, compression type, mtu, etc. from the radius. the radius is getting a request

Re: PHP + radius

2006-08-05 Thread Marco Fretz
hello what do you want to do with PHP and radius exactly? - authentificate in php against radius - administrate raidius server (user / accounting) with php interface? regards marco raviprakash sunkara schrieb: Hi Guys Happy friend ship day... ! I'm Working on Linux. box

rlm_sql: Password in Accounting Packet

2006-12-15 Thread Marco Stuhl
Hello, Is there a way to insert password in radacct table? Changing SQL query to insert %{User-Password} has no effect. I'm aware of the RFCs - is there any workaround for this? Thanks, Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: RE : rlm_sql: Password in Accounting Packet

2006-12-15 Thread Marco Stuhl
attribute then ? I agree on that one; still no workaround? Cheers, Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: RE : RE : rlm_sql: Password in Accounting Packet

2006-12-15 Thread Marco Stuhl
to see and check their past sessions. Since accounting (SQL schema) is based on unique username, I cannot make the distinction between users. Also, I've noted (in past FR versions, though) that it was possible for log files, since FR logged passwords there? Thanks, Marco On 12/15/06, Thibault Le

Re: RE : RE : RE : rlm_sql: Password in Accounting Packet

2006-12-15 Thread Marco Stuhl
is not unique (a must for SQL joins). Maybe there's some other attribute to look for? Cheers, Marco On 12/15/06, Thibault Le Meur [EMAIL PROTECTED] wrote: -Message d'origine- De :[EMAIL PROTECTED][mailto:[EMAIL PROTECTED]De la part de Marco Stuhl Envoyé : vendredi 15

unlang syntax issue

2012-06-29 Thread marco santantonio
User-Name !~ .*-guest$, Autz-Type := LDAP-2 but users file is case-sensitivewhat's the correct unlang syntax to do this??? many thanks marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Secure Storage and Transport of User Credentials

2012-07-11 Thread Marco Macala
. Did I get something wrong here? I am fairly new to RADIUS and therefore I don't know that much about it... Thanks in advance! Best regards, Marco Macala - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Secure Storage and Transport of User Credentials

2012-07-11 Thread Marco Macala
The problem is, that I do not trust the network and I don't want to store the password in plain. Also, isn't the NT Hash insecure beacuse it is easily cracked? Or am i mixing things up? 2012/7/11 alan buxey a.l.m.bu...@lboro.ac.uk Hi, is there a way to securely transport and store the

Re: Secure Storage and Transport of User Credentials

2012-07-11 Thread Marco Macala
if you dont trust the network then you will also need to looking at using TLS to transport things around - eg RADSEC or a VPN tunnel. isn't the point of PEAP that i don't need them because it is wrapped in an encrypted communication? as for NT hash - yes, there are security issues but only

Re: Secure Storage and Transport of User Credentials

2012-07-11 Thread Marco Macala
...@imperial.ac.uk On 11/07/12 14:04, Marco Macala wrote: if you dont trust the network then you will also need to looking at using TLS to transport things around - eg RADSEC or a VPN tunnel. isn't the point of PEAP that i don't need them because it is wrapped in an encrypted

Re: Huntgroups checking in MySQL radgroupcheck

2013-06-05 Thread Marco Marzetti
Il giorno mer, 05/06/2013 alle 09.14 -0400, Alan DeKok ha scritto: Marco Marzetti wrote: mysql SELECT * FROM radgroupcheck; ++---+++--+ | id | groupname | attribute | op | value| ++---+++--+ | 1

Re: Huntgroups checking in MySQL radgroupcheck

2013-06-06 Thread Marco Marzetti
Il giorno mer, 05/06/2013 alle 13.41 -0400, Alan DeKok ha scritto: Marco Marzetti wrote: Also, if i understand it correctly, it makes sense to me since == is a filtering operator while := add the attribute to the list for further checking Anyway, i've updated the record above

Re: Huntgroups checking in MySQL radgroupcheck

2013-06-07 Thread Marco Marzetti
Il giorno gio, 06/06/2013 alle 09.21 +0200, Marco Marzetti ha scritto: Il giorno mer, 05/06/2013 alle 13.41 -0400, Alan DeKok ha scritto: Marco Marzetti wrote: Also, if i understand it correctly, it makes sense to me since == is a filtering operator while := add the attribute

FreeRadius error LDAP Authentication

2013-07-19 Thread Marco Aresu
,dc=it filter = (uid=%{Stripped-User-Name:-%{User-Name}}) base_filter = (objectclass=groupofuniquenames) Thanks Marco Aresu - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Authorization failed in cisco switch

2013-07-22 Thread Marco Aresu
request Waking up in 4.9 seconds. Cleaning up request 0 ID 70 with timestamp +12 Ready to process requests. i don't understand when he tried to find the authorizaziont because if i add a comment in the row of the user in the Users file, i get the same error. Marco Aresu On 22 July 2013 16:37

Authorization failed in cisco switch

2013-07-22 Thread Marco Aresu
i receive the errore : Authorization Failed and during the debug i ve got : # Executing section post-auth from file /etc/raddb/sites-enabled/default +- entering group post-auth {...} [++[reply_log] returns ok ++[exec] returns noop Can someone help me? thanks Marco Aresu - List info/subscribe

Re: Authorization failed in cisco switch

2013-07-22 Thread Marco Aresu
the only file to edit for the authorization is the Users file? thanks Marco Marco Aresu On 22 July 2013 17:03, Alan DeKok al...@deployingradius.com wrote: Marco Aresu wrote: here the debug after authentication: If you're not going to follow instructions, you shouldn't be posting

Re: Authorization failed in cisco switch

2013-07-22 Thread Marco Aresu
i created two users on freeradius server and when i tried to login with the new user that is not specify in the USERS file i ve got the same error Authorization Failed I think that i am editing the wrong USERS file but the directory is /etc/raddb/users Marco Aresu On 22 July 2013 17:19

Re: Authorization failed in cisco switch

2013-07-23 Thread Marco Aresu
now i can logon into the switch but i can with all USERS. Where i can specify who can access to the switch? I add a rown in the USERS file user Auth-Type := Reject but nothing change. thanks Marco Marco Aresu On 23 July 2013 10:06, Martin Kraus lists...@wujiman.net wrote: On Mon, Jul 22

Debug show cleartext password

2013-09-11 Thread Marco Aresu
Thanks Marco Aresu - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

ippool with non-contiguous ip ranges

2008-07-25 Thread Marco C. Coelho
for the ip's netmask = 255.255.255.0 # cache-size: The gdbm cache size for the db # files. Should be equal to the number of ip's # available in the ip pool cache-size = 768 SNIP*** Thanks, Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Web Interface -- radius.cgi

2004-09-09 Thread Marco C. Coelho
and accounting?? If so do you have a copy that you modified? Thanks Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Web Interface -- radius.cgi

2004-09-09 Thread Marco C. Coelho
Kostas Kalevras wrote: On Thu, 9 Sep 2004, Marco C. Coelho wrote: I've searched the archives and didn't find much on web interfaces. We're trying to move from IC-Radius to FreeRadius. We looked at DialupAdmin and didn't think the interface would work well with our front office staff. Could

accounting errors with pppd

2004-09-23 Thread Marco C. Coelho
be appreciated Other Data: Mandrake 10.0 with all security patches Marco scratching his head. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: where do I set the shared Secret

2004-09-23 Thread Marco C. Coelho
If you have the default install: cd /usr/local/etc/raddb/clients.conf Marco Christopher F. Wilson wrote: I have solaris 8 and am running 1.0.1 I am going to try and get mac address authentication going for my 60+ Ornioco/Avaya Access points. But I cant seen to find where to set the shared secret

accounting errors with pppd

2004-09-24 Thread Marco C. Coelho
with no issues. It's only when it's authenticating PPP. Any thoughts or hints would be appreciated Other Data: Mandrake 10.0 with all security patches Marco scratching his head. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List info/subscribe/unsubscribe? See http

can radius pass a binary file

2004-11-17 Thread Marco C. Coelho
Using freeradius 1.0.1 I need to be able to pass a binary or text file to be parsed at the other end Are there any suggestions? Marco - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

problem with ip_pools

2008-09-30 Thread Marco C. Coelho
I ran out of IP space in my original IP_Pool, and since the next available addresses were non contiguous, I added a second pool. Here's the snippet of my radiusd.conf: The problem is that the first pool comes up and is used, but when it runs out of IP space, the second pool never gets used.

Re: problem with ip_pools

2008-09-30 Thread Marco C. Coelho
Please See Below: Alan DeKok wrote: Marco C. Coelho wrote: I ran out of IP space in my original IP_Pool, and since the next available addresses were non contiguous, I added a second pool. Here's the snippet of my radiusd.conf: Did you add main_pool2 to the post-auth accounting

Re: FW: FreeRadius

2008-10-01 Thread Marco C. Coelho
It complaining about time, not usage? Marco Marcel Grandemange wrote: I have a working FreeRadius installation used for PPPOE clients using a Mikrotik NAS (Essentialy Linux) I am using Freeradius to limit data a user can send/receive within a month and automatically reset it every

  1   2   >