Re: Time based billing

2008-12-03 Thread [EMAIL PROTECTED]
These situations are often in the VoIP billing world. If the rate changes during a call there is little you can do in a prepaid billing system (in a postpaid situation this is not a problem). You have to choose either to bill your customer with the rate that is valid at the beginning of the

Re: Time based billing

2008-12-03 Thread [EMAIL PROTECTED]
... but I use it on a production system and it works like a charm. Sebo PL wrote: I think it could be done by some special DB function. You can write one in plpgsql, then you can exec it using the sql radius module. 2008/12/3 [EMAIL PROTECTED] mailto:[EMAIL PROTECTED] [EMAIL PROTECTED] mailto

New RADIUS book - Nuevo libro de RADIUS

2008-10-21 Thread [EMAIL PROTECTED]
Saludos a todos (Hi everybody) He descubierto el lanzamiento de un nuevo libro de RADIUS en la Web: www.radiusdoc.com (Parece muy interesante) I've discovered a new RADIUS book in the website: www.radiusdoc.com (It appears to be very interesting and helpful). Francisco Montes Ahora

Re: freeradius ippool issue

2008-07-17 Thread [EMAIL PROTECTED]
? Perhaps you have a dhcp | server running as well and that one is allocating IPs. | | Ivan Kalik | Kalik Informatika ISP | | | Dana 16/7/2008, [EMAIL PROTECTED] [EMAIL PROTECTED] piše: | | Hi, i'm new with freeradius, and i have a few issues with ip allocation |from a mysql database. The server it's

Re: freeradius ippool issue

2008-07-17 Thread [EMAIL PROTECTED]
of id 28 to 192.168.1.1 port 37704 Ivan Kalik wrote: | Run the server in debug mode (radiusd -X) and see what's in the | Access-Accept packet. | | Ivan Kalik | | | Dana 17/7/2008, [EMAIL PROTECTED] [EMAIL PROTECTED] piše: | | in radius.conf i have status_server = yes and no other references

Re: freeradius ippool issue

2008-07-17 Thread [EMAIL PROTECTED]
to 192.168.1.1 port 37704 Paul Alan DeKok wrote: | [EMAIL PROTECTED] wrote: | | INSERT INTO radpostauth (username, pass, | reply, authdate) VALUES ( | ~ 'gogu', 'gogu123', | ~ 'Access-Accept', '2008-07-17 11:45

Re: freeradius ippool issue

2008-07-17 Thread [EMAIL PROTECTED]
the file at http://alexandrunet.ro/radius_log; and it now has the full log from the time the user connects. Alan DeKok wrote: | [EMAIL PROTECTED] wrote: | sry for the bad output, but this ware the lines with Access-Accept, | this is the whole thing: | - the whole log it's at http://alexandrunet.ro

Re: freeradius ippool issue

2008-07-17 Thread [EMAIL PROTECTED]
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 :) yes that's what it was thank you for your help. I'm sorry you had a bad day my friend. Paul. Alan DeKok wrote: | [EMAIL PROTECTED] wrote: | sorry about that, you have a good point, i just restarted the server and | i forgot i did not try

Re: freeradius ippool issue

2008-07-17 Thread [EMAIL PROTECTED]
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 there is not dhcp running on that server, and there is no dhcprelay. I supposed it's the radius default, i don't know if that makes any sense to you:), anyways i will dig more. Thank you. [EMAIL PROTECTED]:/usr/local/etc/raddb# ps -aux | grep dhcp

Re: freeradius ippool issue

2008-07-17 Thread [EMAIL PROTECTED]
begin here also at one point. Again sry you had a bad day. Paul. Alan DeKok wrote: | [EMAIL PROTECTED] wrote: | there is not dhcp running on that server, and there is no dhcprelay. I | supposed it's the radius default, | | No. | | If RADIUS doesn't assign an IP address, then something else you've

freeradius ippool issue

2008-07-16 Thread [EMAIL PROTECTED]
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, i'm new with freeradius, and i have a few issues with ip allocation from a mysql database. The server it's functional, it's running with a pppoe server, authentication goes ok, the user gets authenticated with the values from mysql tables, but i

radius user disconnection and same account multiplication problem in radacct

2008-07-08 Thread [EMAIL PROTECTED]
A new doubt. Is there anyway to safe disconnet an user from the radius server, in a way that it auto disconnects him from the nas (a pppoe server)? And about that Packet of Disconnect, is it still working? I forgot to cite the version I'm using, and considering the message was sent on weekend,

Problem with account multiplication in radacct

2008-07-04 Thread [EMAIL PROTECTED]
Hi again, I solved the last trouble with ippool.db using the sqlippool instead. But I got a new shining problem. :) Now, almost everything seems to be working fine. Almost, cause I have some account multiplication in the radacct table. Only a few users are doing that. And the multiplication

Re: Multiple radius servers on one machine

2008-06-13 Thread [EMAIL PROTECTED]
If I do decide to run multiple radius daemons, how can I tell the application server running pptpd and xl2tpd, which both authenticate ppp sessions via radius, to use radius server1 for pptpd and radius server2 for xl2tpd? On Thu, Jun 12, 2008 at 9:12 PM, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote

help EAP-TNC

2008-06-12 Thread [EMAIL PROTECTED]
Hi all, I'm working in setting up a basic scenario which involves 3 components: a client using Xsupplicant a AP making use of hostapd and a Radius server using FreeRadius ;). I'm trying to probe the EAP-TNC method but i have received this message from the FreeRadius server: rlm_eap:

Multiple radius servers on one machine

2008-06-12 Thread [EMAIL PROTECTED]
I have two applications that authenticate via radius. These applications require separate radius conf files, log files, users files, etc. How can I run two distinct radius servers on one server to serve these applications? Also, these applications run on one server, so how can I have their server

Re: Multiple radius servers on one machine

2008-06-12 Thread [EMAIL PROTECTED]
might i suggest using virtual machines, instead of messing around with multiple instances. (radius is rather non resource intensive) If I can avoid it, I would not like to mess around with virtual machines. On Thu, Jun 12, 2008 at 8:11 PM, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: I have two

rlm_ippool fail

2008-06-05 Thread [EMAIL PROTECTED]
Hi all. I had a freeradius server 1.1.7 running up with some errors when doing updates in radacct (mysql) some hours after it just started. Since then, I decided to upgrade to 2.0.4. But now, it refuses to start with the error rlm_ippool: Failed to open file $(raddbdir)/db.ippool: No such file

Re: rlm_ippool fail

2008-06-05 Thread [EMAIL PROTECTED]
Does the file exist? FreeRADIUS is at the mercy of the OS here. If the OS says no such file or directory, it means no such file or directory. No amount of playing with the FreeRADIUS configuration will make the file suddenly exist. Does the db.ippool file exist? Alan DeKok. You are suposed to

Re: Freeradius and Active directory

2008-05-21 Thread Janec(ek [EMAIL PROTECTED]
Hi. Because we can authenticate against AD only (not only, but...) using MS-CHAP, I had to extend the system to its final form (I don't know any MS-CHAP testing utility): [WinXP] - [AP] - [FreeRadius] - [AD server] (ie. I'm using wireless interface in Windows to connect to AP and

802.1x maschine auth with SSL?

2008-03-25 Thread [EMAIL PROTECTED]
Heya, i'm a bit stuck. My xp box should auth with ssl cert - works ok so far. But how to assign vlan? When doing this with user, i put my user + pass into users file - works. But for ssl cert? I want my xp box authentificated by ssl cert and after that, my user should logon to his vlan. So that i

Re: 802.1x maschine auth with SSL?

2008-03-25 Thread [EMAIL PROTECTED]
Hi, thanks for replys! i'm very sorry, there is a little missunderstanding :( Switch works ok so far, so nothing needs to be done there. My client is xp box with logon client which can do maschine auth and prompt the user for his name and pass... So i use ssl to auth the maschine (has a general

Re: Rewriting Attributes with Freeradius

2008-03-17 Thread [EMAIL PROTECTED]
Hi there! On Mon, Mar 17, 2008 at 9:56 AM, Alan DeKok [EMAIL PROTECTED] wrote: [EMAIL PROTECTED] wrote: I want my freeradius to rewrite the vlan attributes for cetrain clients. From what... to what? Do you have examples? Sure, thanks for your time btw! My Main Office has three different

Re: Rewriting Attributes with Freeradius

2008-03-17 Thread [EMAIL PROTECTED]
Tunnel-Private-Group-ID := 23 ? Thanksalot! 2008/3/17 Ivan Kalik [EMAIL PROTECTED]: users file: DEFAULT NAS-IP-Address == office switch/router IP, Ldap-Group == admin Tunnel-Private-Group-ID := 23 Same for special group and ID of 2. Just make sure you don't

Re: Rewriting Attributes with Freeradius

2008-03-17 Thread [EMAIL PROTECTED]
Hi! mh, ok, sounds bad - what happens if 1000 users re-connect to the network.. will i get 1000 forked perl scripts..? And how should the script look like/get implemented? Thanksalot! 2008/3/17 Ivan Kalik [EMAIL PROTECTED]: I don't think so. It's a reply attribute so the check won't match. You

Re: Rewriting Attributes with Freeradius

2008-03-17 Thread [EMAIL PROTECTED]
Hi there, On Mon, Mar 17, 2008 at 4:49 PM, Ivan Kalik [EMAIL PROTECTED] wrote: mh, ok, sounds bad - what happens if 1000 users re-connect to the network... Ldap is likely to be much more of a problem than a perl script. For that reason its a cluster :D And how should the script look

Rewriting Attributes with Freeradius

2008-03-16 Thread [EMAIL PROTECTED]
Hi there, i looked around and found nothing which really helped, so i'll ask you :) I want my freeradius to rewrite the vlan attributes for cetrain clients. Setup is like having all users in my ldap, with vlan etc. and all is working fine so far. Now i have an office which has other vlans due to

proxied connection - please example

2008-01-07 Thread [EMAIL PROTECTED]
Hi Alan, thank you for your quick answer. Please send me some example about this proxy configuration. Rgdrs, Radim Hi, Everything work OK, Ovislink send request to FreeRadius server, FreeRadius send Access-Request to IAS (mschapv2) IAS send Access-Accept, but Ovislink received

problem with certificate

2007-11-15 Thread [EMAIL PROTECTED]
Hello. I create mi certificate with openssl its version is openssl-0.9.7f-7.10. The configuration from eap.conf is eap { default_eap_type = ttls timer_expire = 60 ignore_unknown_eap_types = no

wpa_supplicant

2007-11-06 Thread [EMAIL PROTECTED]
= [EMAIL PROTECTED] certs]# radiusd -X Starting - reading configuration files ... reread_config: reading radiusd.conf Config: including file: /etc/raddb/proxy.conf Config: including file: /etc/raddb/clients.conf Config: including file: /etc/raddb

Fwd: clients linux

2007-10-22 Thread [EMAIL PROTECTED]
Hi. I want work with linux clients (fedora core 4), but how i do for that the client linux question for a login and panssword for that it connect to the net. Should I install an additional program for my client lunix asking for authentication?. Liset Vizcardo

Setting a conditional variable

2007-10-20 Thread [EMAIL PROTECTED]
Hi everyone! I'm trying to set a conditional variable in my sql.conf. According to value of %{NAS-Port-Type} my variable (i.e. MYVAR) should be assigned to value returned by different programs through 'exec' module. I couldn't find any examples how to do it. So I will appreciate if someone

clients linux to freeradius

2007-10-18 Thread [EMAIL PROTECTED]
Hello. How do I do for that my clients linux (fedora core 4) soliciten autenticarse ante el servidor freeradius antes de conectarse a la red. Should I install an additional program for my client lunix asking for authentication?. Or is only necessary in some file modoficacion sde linux,

Freeradius logging w/syslog

2007-10-17 Thread [EMAIL PROTECTED]
Hi Alan, Ok, seems the default install is dated that comes with CentOS 4.4... I've upgraded to FreeRADIUS Version 1.1.7 now and logging seems to be working but I'd like to be able to get more usable data. I nthe /etc/syslog.conf file I have this entry: # .* will log all messages in the same

Re: Using freeradius and 802.1x for dynamic VLAN

2007-10-16 Thread [EMAIL PROTECTED]
you certainly arent checking that the VLAN is 2 - and if it isnt then fail the authentication. i can understand what you are trying to do...but do do THAT sort of thing you will need to use checking attributes, not setting attributes. you should find that the port which carlos is

Freeradius logging w/syslog

2007-10-16 Thread [EMAIL PROTECTED]
Hi all, I'm running freeradius 1.0.1 on CentOS 4.4 and I'm trying to get the radius to log to a syslog server. I followed the example Syslog_HOWTO but its not working. I was hoping that someone else might know the answer / fix. Thanks in Advance, - List info/subscribe/unsubscribe? See

Re: Using freeradius and 802.1x for dynamic VLAN

2007-10-15 Thread [EMAIL PROTECTED]
Hi, carlos Auth-Type = EAP, User-Password == carlos I remove the parte indicated carlos User-Password == carlos The problem continue i did thefollowing: In my swich I form three vlan 2,3,4 After I signed ip to the vlans and ports too. This is all

Using freeradius and 802.1x for ssign VLAN X

2007-10-12 Thread [EMAIL PROTECTED]
Hi, I use freeradius-1.0.4-1.FC4.1 version in a PC Linux Fedora Core 4. I form the file uses: lucy Auth-Type := EAP, User-Password == lucy Service-Type = Framed-User, Tunne-type = VLAN, Tunnel-medium-type = IEEE-802, Tunnel-Private-Group-Id = 2 I have

Re: configure MSCHAPV2 authentication protocol

2007-10-11 Thread [EMAIL PROTECTED]
you seem to have EAP commented out. if you want to use EAP/802.1x then that isnt going to help... - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Using freeradius and 802.1x for dynamic VLAN

2007-10-11 Thread [EMAIL PROTECTED]
Hello, I use freeradius-1.0.4-1.FC4.1 version in a PC Linux Fedora Core 4. This radius server authenticates to user in function to his login and key, if the information is correct the radius server must send to user to the vlan 2 according to forms in the file users of the radius server.

How to get a Radius Client for Radius Server in Red Hat Enterprise Linux ES 3

2007-09-12 Thread [EMAIL PROTECTED]
hi all,can any one please tell me where can i get radius client for radius server suitable to Red Hat Enterprise Linux ES 3.Also please give the details of different types of radius clients available for radius server in Red Hat Linux ES 3.Also please tell me how to install and configure the

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-04 Thread [EMAIL PROTECTED]
basic and what should I do if i need to add more attribute? For example, the accounting packet do not include the full username i.e. [EMAIL PROTECTED] Looking for your advice. rad_recv: Accounting-Request packet from host 61.4.124.254:56195, id=35, length=155 Acct-Session-Id = "-000

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-04 Thread [EMAIL PROTECTED]
Hi Alan, Read the hostapd documentation. Nothing much the documentation about the attributes. If the User-Name in the Access-Request was [EMAIL PROTECTED], it looks like a bug in hostapd. If he User-Name in the Access-Request was user, then hostapd is functioning correctly

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-03 Thread [EMAIL PROTECTED]
ldap: timeout = 4 ldap: timelimit = 3 ldap: identity = "cn=Manager,dc=." ldap: tls_mode = no ldap: start_tls = no ldap: tls_cacertfile = "(null)" ldap: tls_cacertdir = "(null)" ldap: tls_certfile = "(null)" ldap: tls_keyfile = "(null)" ldap:

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-03 Thread [EMAIL PROTECTED]
rns ok for request 4 rad_check_password: Found Auth-Type LDAP auth: type "LDAP" ERROR: Unknown value specified for Auth-Type. Cannot perform requested action. auth: Failed to validate the user. Login incorrect: [[EMAIL PROTECTED]] (from client localhost port 0 cli 00-14-a5-d9-09-07) T

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-03 Thread [EMAIL PROTECTED]
Optical Communication Engineering S/B 19, Jalan Semangat, 46200 Petaling Jaya, Selangor Darul Ehsan Tel: +60 3 76808000 EXT:1205 Fax: +60 3 76808010 H/P: +60 12 9033077 email: [EMAIL PROTECTED] - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-03 Thread [EMAIL PROTECTED]
module "eap" returns fail for request 4 modcall: group authenticate returns fail for request 4 auth: Failed to validate the user. New ldif : dn: uid=user, ou=People, dc=ocesb, dc=com, dc=my, dc=. mailLocalAddress: [EMAIL PROTECTED] givenName: Tan Chee accountStatus: active

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-03 Thread [EMAIL PROTECTED]
with L2 switch as NAS, a login record will be there. What make this happen? radius_xlat: 'INSERT into radpostauth (id, user, pass, reply, date) values ('', '[EMAIL PROTECTED]', 'Chap-Password', 'Access-Accept', NOW())' Regards [EMAIL PROTECTED] wrote: Hi Alan, After try to remove the Auth

Re: Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-03 Thread [EMAIL PROTECTED]
Dear Alan, I try 2 different type of wireless NASs but still didn't insert the record into table. Is that mean the wireless NAS by default do not send accounting info or do not have this kind of function? Regards Alan DeKok wrote: [EMAIL PROTECTED] wrote: ... However, I do

Freeradius + LDAP + EAP-TTLS with PAP cannot login

2007-07-02 Thread [EMAIL PROTECTED]
Hint == "SLIP" Framed-Protocol = SLIP DEFAULT Realm == "ocesb.com.my", Autz-Type := LDAP1, Auth-Type := LDAP1 user.ldif dn: uid=user, ou=People, dc=ocesb, dc=com, dc=my, dc=. mailLocalAddress: [EMAIL PROTECTED] givenName: Tan Chee accountStatus: active radiusClass: 0x0

Re: Freeradius-Users Digest, Vol 26, Issue 20

2007-06-07 Thread [EMAIL PROTECTED]
Ich bin am Freitag den 8. Juni nicht im Haus und kann Ihre Nachricht erst am Montag den 11. Juni bearbeiten. In dringenden Fällen wenden Sie sich bitte an Herrn René Böhm (E-Mail: [EMAIL PROTECTED]). Mit freundlichen Grüßen Tobias Drollinger - List info/subscribe/unsubscribe? See http

Re: Freeradius-Users Digest, Vol 25, Issue 117

2007-05-25 Thread [EMAIL PROTECTED]
Ich bin am 25. Mai nicht im Haus und kann Ihre Nachricht erst am Dienstag den 29. Mai bearbeiten. In dringenden Fällen wenden Sie sich bitte an Herrn René Böhm (E-Mail: [EMAIL PROTECTED]). Mit freundlichen Grüßen Tobias Drollinger - List info/subscribe/unsubscribe? See http

Re: Freeradius-Users Digest, Vol 25, Issue 99

2007-05-21 Thread [EMAIL PROTECTED]
Ich bin am 21. Mai nicht im Haus und kann Ihre Nachricht erst am Dienstag den 22. Mai bearbeiten. In dringenden Fällen wenden Sie sich bitte an Herrn René Böhm (E-Mail: [EMAIL PROTECTED]). Mit freundlichen Grüßen Tobias Drollinger - List info/subscribe/unsubscribe? See http

Re: Freeradius-Users Digest, Vol 25, Issue 56

2007-05-14 Thread [EMAIL PROTECTED]
Ich bin am 14. Mai nicht im Haus und kann Ihre Nachricht erst am Dienstag den 15. Mai bearbeiten. In dringenden Fällen wenden Sie sich bitte an Herrn René Böhm (E-Mail: [EMAIL PROTECTED]). Mit freundlichen Grüßen Tobias Drollinger - List info/subscribe/unsubscribe? See http

RE: [how] installing

2007-04-23 Thread [EMAIL PROTECTED]
www.deployingradius.com or yum install freeradius vi /etc/raddb/* or wget ftp://ftp.freeradius.org:/pub/radius/freeradius-1.1.6.tar.bz2 tar -xjvf freeradius-1.1.6.tar.bz2 cd freeradius-1.1.6 ./configure make make install vi /etc/raddb/* seriously, your question is just SO open. alan -

Re: assigning vlan based on NAS and LDAP field?

2007-04-13 Thread [EMAIL PROTECTED]
Message du 13/04/07 à 11h43 De : Kostas Kalevras A : [EMAIL PROTECTED], FreeRadius users mailing list Copie à : Objet : Re: assigning vlan based on NAS and LDAP field? O/H Matt Ashfield έγραψε: HI all, We're using FR authenticating against LDAP to implement our wireless

kill -HUP

2007-04-12 Thread [EMAIL PROTECTED]
Hi all, I use freeradius 1.0.1. I did a script that do a kill - HUP of radiusd when someone add a NAS in the nas Mysql table. It seems to work. But i see freeradius 1.1.6 correct a bug about HUP. Can you tell me if i'm impacted by the bug corrected in 1.1.6 Thank you for your help Thomas- List

Freeradius-mysql and freeradius 1.1.5

2007-03-19 Thread [EMAIL PROTECTED]
Hi, i have installed freeradius 1.1.5 on debian machine now how i can install freeradius-mysql package? When i try 'apt-get install freeradius-mysql' this is the error: Some packages could not be installed. This may mean that you have requested an impossible situation or if you are using the

Re: freeradius ldap connector

2007-03-09 Thread [EMAIL PROTECTED]
= forbidden. Waking up in 4 seconds... Message du 06/03/07 à 11h58 De : Michael Mitchell A : FreeRadius users mailing list Copie à : Objet : Re: freeradius ldap connector [EMAIL PROTECTED] wrote: I notice that Freeradius tries 6 times to find a user in my LDAP directory when this user

Re: freeradius ldap connector

2007-03-09 Thread [EMAIL PROTECTED]
OK thanks Message du 09/03/07 à 09h52 De : Alan DeKok A : [EMAIL PROTECTED], FreeRadius users mailing list Copie à : Objet : Re: freeradius ldap connector [EMAIL PROTECTED] wrote: you can see the debug. there are 7 searches for an uid that doesn't exist in the ldap directory

password in debug mode

2007-03-08 Thread [EMAIL PROTECTED]
Hi, is there a mean not te see passwords in freeradius debug mode (radiusd -X) ? thanks Thomas- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

freeradius ldap connector

2007-03-06 Thread [EMAIL PROTECTED]
Hello, I use freeradius 1.0.1 LDAP connector to request a LDAP directory. I notice that Freeradius tries 6 times to find a user in my LDAP directory when this user doesn't existe. Is there a mean to make freeradius tries only one time ? Thanks Thomas- List info/subscribe/unsubscribe? See

Re: freeradius ldap connector

2007-03-06 Thread [EMAIL PROTECTED]
... Message du 06/03/07 à 11h58 De : Michael Mitchell A : FreeRadius users mailing list Copie à : Objet : Re: freeradius ldap connector [EMAIL PROTECTED] wrote: I notice that Freeradius tries 6 times to find a user in my LDAP directory when this user doesn't existe. err

PAM_RADIUS

2007-02-23 Thread [EMAIL PROTECTED]
Hi, I'd like to know if FreeRadius Pam_RADIUS is still up to date ? Do you have any suggest to make it work with Red Hat Entreprise Linux 4 ? Thanks, Thomas- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PAM_RADIUS

2007-02-23 Thread [EMAIL PROTECTED]
OK authentication works but not accounting whereas i have in etc/pam.d/system-auth : account sufficient /lib/security/$ISA/pam_radius_auth.so any idea why my REDHAT does not send any accounting ? Thomas Message du 23/02/07 à 17h39 De : [EMAIL PROTECTED] A : freeradius-users

Cisco enable authentication on freeradius and mysql

2007-02-16 Thread [EMAIL PROTECTED]
I am trying to authenticate Cisco enable password requests via freeradius (1.1.3.) on a mysql (5.0.26) database. As per http://wiki.freeradius.org/Cisco, the router tries to authenticate user $enab15$ but it doesn't get matched on mysql query because '$' gets escaped to '=24' radius_xlat:

Re: VPN authentication from Windows Vista

2007-02-09 Thread [EMAIL PROTECTED]
MS-Chap is in RFC 2433 (Oct 1998) MS-Chap V2 is in RFC 2759 (Jan 2000) see also Microsoft Specific RADIUS attributes - RFC 2548 (Mar 1999) Dave. Original Message From: [EMAIL PROTECTED] Date: Feb 9, 2007 6:01 To: FreeRadius users mailing list[EMAIL PROTECTED] org Subj: Re: VPN

Re: ldap { fail=1}

2007-01-11 Thread [EMAIL PROTECTED]
Message du 10/01/07 à 15h38 De : Alan DeKok A : [EMAIL PROTECTED], FreeRadius users mailing list Copie à : Objet : Re: ldap { fail=1} [EMAIL PROTECTED] wrote: i'm using freeradius 1.0.1 from Red Hat entreprise 4. You SHOULD upgrade: http://freeradius.org/security.html

Re: ldap { fail=1}

2007-01-10 Thread [EMAIL PROTECTED]
Message du 10/01/07 à 15h38 De : Alan DeKok A : [EMAIL PROTECTED], FreeRadius users mailing list Copie à : Objet : Re: ldap { fail=1} [EMAIL PROTECTED] wrote: i'm using freeradius 1.0.1 from Red Hat entreprise 4. You SHOULD upgrade: http://freeradius.org/security.html

ldap { fail=1}

2007-01-09 Thread [EMAIL PROTECTED]
Hi, i'm using freeradius 1.0.1 from Red Hat entreprise 4. my radius server is connected to a ldap directory to store users and to a mysql database to store NAS I want the radius server to authenticate users thanks to the users file even if the ldap directory is not reachable and the radius

postgresql or mysql

2007-01-03 Thread [EMAIL PROTECTED]
Hi, i'd like to know which DB (postgresql or mysql) you advice me, to store accounting and see it thanks to the GUI dailupadmin ? can i find the same freeradius features with this 2 DB ? i don't see 2 features , in postgresql.conf: - readclients = yes -Default profile that i see in

dailup admin and badusers

2006-12-29 Thread [EMAIL PROTECTED]
hi, i don't understand why dialup admin need its own sql table badusers and a script to get bad logins whereas rejected users can be found in the freeradius table radpostauth ? Regards, Thomas- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

huntgroups, sql and dialup admin

2006-12-21 Thread [EMAIL PROTECTED]
hi, i configured freeradius using configuration files( user, huntgroups, clients, ...). it works great. now i 'd like to be able to manage my radius server with the web GUI dailup admin. my issue is that i don't see how i can put a nas ip in a huntgroup with this GUI. Can i have my nasip list

sql and password

2006-12-21 Thread [EMAIL PROTECTED]
Hi, i'd like to athenticate user in ldap and put them in groups using sql. so i don't want to check their password in the radcheck table. my issue is that i don't see how not to check the password using the web GUI dialup admin ? thanks for your help regards jey Message du 21/12/06 à

differentiating radius attribute

2006-12-01 Thread [EMAIL PROTECTED]
Hi everybody, I'm using freeradius to authenticate and authorize users to cisco switches/routers/FW. My issue is that i want to do aaa for 3 things on the same device: device administrators login (telnet), for 802.1x EAP/MD5 (, and to manage firewall FWSM ACLs (radius attribute in the

RE: RADIUS PAP-SecurID Access-Challenge

2006-11-28 Thread [EMAIL PROTECTED]
I'm sorry, The other day I said that there is nothing unusual about SecurID RADIUS authentication. I'm so used to EAP, I forgot about the PAP auth with a SecurID value as a password. If the RSA Authentication Manager, finds that the token is in New Pin or Next Tokencode mode, it will issue

failed query postgresql driver

2006-11-17 Thread [EMAIL PROTECTED]
hello, I am trying to use the redundant feature of freeradius and I do not understand why the sql module (postgresql driver) returns ok when a query fails. from radiusd -X rlm_sql (sql): Reserving sql socket id: 61 rlm_sql_postgresql: Status: PGRES_FATAL_ERROR rlm_sql_postgresql: Error

redundant block in CVS 2006-11-16

2006-11-16 Thread [EMAIL PROTECTED]
hello, I am trying to switch from cvs version 2006-08-24 to cvs version 2006-11-16 and my accounting redundant group is processing the second module even if the first one is returning ok. why is detail_fail processed if sql returns ok ? Is something (I do not find in doc / changelog)

Re: redundant block in CVS 2006-11-16

2006-11-16 Thread [EMAIL PROTECTED]
thanks, Razvan Radu Alan DeKok wrote: [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: 2006-11-16 and my accounting redundant group is processing the second module even if the first one is returning ok. why is detail_fail processed if sql returns ok ? It's a bug. I just committed

Re: PEAPv2 Server

2006-11-15 Thread [EMAIL PROTECTED]
why you would build a server for it if you don't have a client? Dave. Original Message From: [EMAIL PROTECTED] Date: Nov 15, 2006 14:49 To: FreeRadius users mailing list[EMAIL PROTECTED] org Subj: Re: PEAPv2 Server MURAT SEZGIN [EMAIL PROTECTED] wrote: I am trying to implement a PEAP

dialup_admin+ldap+sql

2006-11-10 Thread [EMAIL PROTECTED]
Hi, I saw that dialup_admin can use ldap or SQL to manage users. I'd like to know if i can, using dialup-admin: 1- authenticate users with ldap and add in the radius server answer per user attributesthat are stored in my sqlDB. 2- authenticate users with ldap and add in the radius server answer

openldap+freeradius+Cisco

2006-10-27 Thread [EMAIL PROTECTED]
Hi, I'm tryingto authenticate and authorize Cisco routers administrators But not the autorization (privilege level).so not wheni add "aaa authorization exec default group radiusvrf if-authenticated"to the cisco router to be able to manage privileges with radius. to make it work, i think i need to

Re: openldap+freeradius+Cisco

2006-10-27 Thread [EMAIL PROTECTED]
27/10/06 à 10h27 De : "[EMAIL PROTECTED]" <[EMAIL PROTECTED]> A : freeradius-users@lists.freeradius.org Copie à : Objet : openldap+freeradius+Cisco Hi, I'm tryingto authenticate and authorize Cisco routers administrators But not the autorization (privilege level).so not wheni a

vendor attribute in radius-accept message

2006-08-31 Thread [EMAIL PROTECTED]
Hi. How to configure freeradius to send vendor specif attribute in a radius-accept message based on eap-tls? ___ Mutui a tassi scontati da 30 banche. Richiedi online e risparmia. Servizio gratuito.

freeradius and mysql fails

2006-05-23 Thread [EMAIL PROTECTED]
hello, i was wondering what sql tables i need to have. Im trying to setup freeradius with mysql and i cant get out. i've got the following tables: radius (12) * Browse badusers * Browse mtotacct * Browse nas * Browse radacct * Browse radcheck * Browse radgroupcheck

Re: auth-reject with attributes

2006-03-01 Thread [EMAIL PROTECTED]
thanks for your reply, if it is not planned to be a configuration parameter for this feature can you please tell me when the change took place and which file is affected, so I can put it back on ? thanks again, Razvan Radu Alan DeKok wrote: [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: I

auth-reject with attributes

2006-02-28 Thread [EMAIL PROTECTED]
hello, I have tried to upgrade to the latest cvs version and I have noted that reply attributes are no longer sent with auth-reject messages. is this correct ? is there a configuration option to re enable sending of reply attributes with auth-reject messages ? thanks, Razvan Radu - List

SNMP apparently not working with FreeRadius 1.0.1 and above on Centos 4.2

2006-01-25 Thread [EMAIL PROTECTED]
Hi, I am new to this list, though I've been using FreeRadius 0.9.3 for a few years now. My present goal is to get a newer version of FreeRadius (running on Centos 4.2) to work with snmp. Though I have carefully followed the snmp setup instructions as documented in radiusd.conf and snmp.conf, I

FreeRadius and Openldap authentication

2006-01-02 Thread [EMAIL PROTECTED]
userPassword:: e1NIQX1jTWc1Y3dTazFuUEdMZW56UUw5UEdpV1pHSVU9 ou: ou=mind-techno,dc=fr objectClass: top objectClass: person objectClass: pilotPerson objectClass: radiusProfile janetMailbox: [EMAIL PROTECTED] sn: test cn: test The SLDAPD conf file: access to dn=cn=.*,dc=fr attr=userPassword

Client-IP-Address in detail files

2005-12-19 Thread [EMAIL PROTECTED]
hello, I have recently upgraded from CVS version as of 2005-02-19 with the one from 2005-12-17 and I no longer get the Client-IP-Address attribute in the files produced by the detail module. on the other hand the Client-IP-Address attribute is expanded correctly in sql querys. is there

Re: Client-IP-Address in detail files

2005-12-19 Thread [EMAIL PROTECTED]
see in line comments please. Alan DeKok wrote: [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: is there something different ? how can I add Client-IP-Address attribute back to the detail files ? For now, source code patches. I am interested to know if this is the intended

hints and huntgroups ?

2005-11-28 Thread [EMAIL PROTECTED]
Hello all! can anyone help me out with a template for the file hints as well as huntgroups? as far as i know those files are not needed if the accounting is done via sql. i still have got issues if i try disable the preprocessing for those files. anyone got any sugestions for me ?

Manage Multiple Pools

2005-10-09 Thread [EMAIL PROTECTED]
Hello, i have freeradius 1.0.5. installed and running. I would like to use two Ip pools for my users. i have 3 ip Pools: - 1. 192.168.1.1-10 - 2 192.168.1.50-60 - 3 192.168.1.150-160 I would like that whe the first poll is full, the radius continue with the second pool and when this is full

Re: PEAP without credentials

2005-09-16 Thread [EMAIL PROTECTED]
Hello, Hi, is there a way, to tell the freeradius to accept an incoming peap request, without asking for user credentials, or to accept any credentials? No, I don't think so. Currently needed to use the credentials guest/guest. It would be simpler to accept any credentials,

problem with Auth-Type DIGEST

2005-09-01 Thread [EMAIL PROTECTED]
hello, I am using digest auth and I want to upgrade from cvs version (2005-02-19) to cvs version (2005-09-01). everything seems to be ok except that the digest auth does not work anymore. I have noticed, in debug mode (radiusd -X), the following differences between the two versions: =

Re: Proxying both EAP and non-EAP requests for the same realm to different servers.

2005-07-21 Thread [EMAIL PROTECTED]
Hi, I want to proxy requests to different servers, based on their authentication type - though they belong to the same realm. How do I make EAP request for a realm go to one server and non-EAP requests for the same realm go to another server? I think you could try to proxy every

Re: Problem on installing Version 1.0.3 on RedHat 9.0

2005-07-05 Thread [EMAIL PROTECTED]
Hi, gcc -g -O2 -D_REENTRANT -D_POSIX_PTHREAD_SEMANTICS -DOPENSSL_NO_KRB5 -Wall -D_GNU_SOURCE -DNDEBUG -I../.. -I../../../../include -I'/usr/include' -c sql_mysql.c -o sql_mysql.o sql_mysql.c:39:20: errmsg.h: No such file or directory sql_mysql.c:40:19: mysql.h: No such file

Error compiling freeradius-snapshot-20050511

2005-05-13 Thread Stefano Martini \[EMAIL PROTECTED]
Hi all, I downloaded freeradius-snapshot-20050511 and I have to compile it on a debina 3.1 i386 system with gcc-3.3.5. The make process fails with the following error: In file included from rlm_sql.c:36: /usr/include/unistd.h:1021: warning: redundant redeclaration of `ctermid' in same scope

freeradius and postgres

2005-05-13 Thread Stefano Martini \[EMAIL PROTECTED]
Hi all, I'm using freeradius-1.0.2 on a debina 3.1 i386 platform with gcc-3.3.5. I compiled the radius server, without errors, and want to use a postgres database for authentication. The tables of the database have been created with the file

(no subject)

2005-05-08 Thread [EMAIL PROTECTED]
Hello, I have a problem and I hope that You can help me, please!? I want use (Free)RADIUS for AAA on IPv6. Only one router, one RADIUS server and one user. User(IPv6 address) connect with Telnet to Router(IPv6 address) Questions: Can RADIUS solve this problem? Can be RADIUS on Linux with IPv6

  1   2   >