Re: Problem with Cisco WLC probes in FR 2.2.1

2013-10-06 Thread Bruce Nunn
Thanks for the heads-up. I will look for this this coming weekend when I get 2.2.2 in production. Jonathan Gazeley jonathan.gaze...@bristol.ac.uk wrote: We've recently upgraded our radius servers from 2.1.12 (CentOS 6 packaged default) to 2.2.1 (latest stable from FR, built by hand). A

Re: SNMP support for Free Radius

2013-07-18 Thread Bruce Nunn
To get by the work of those kittens I set up a remote login to run radmin commands and parse the output so it is suitable for mrtg. It has worked well for me. Arran Cudbard-Bell a.cudba...@freeradius.org wrote: On 18 Jul 2013, at 08:43, manjunath uthappa ponnachana

Re: LDAP attribute mapping

2012-10-30 Thread Bruce Nunn
I pull out only the attributes I need and change ldap.attrmap to match my schema. Personally, I can live with either config method. Arran Cudbard-Bell a.cudba...@freeradius.org wrote: Quick poll. For 3.0 the ldap module will be moving away from using the ldap.attrmap file and instead use a

Re: PEAP/MSCHAP doesn't run post-auth in inner-tunnel for reject?

2012-05-19 Thread Bruce Nunn
For my installations I've disabled the EAP cache to make things work better. Only a few users noticed. Does anyone know if the same thing happens In the 3.0 branch? I was planning to put one of my production servers on the 3.0 code this Summer. Alan DeKok al...@deployingradius.com wrote: Phil

RE: Blackberry disabled server certificates query

2012-01-20 Thread Bruce Nunn
One of the annoying features of Blackberry devices is that the descriptions of the same CA certificate varies from device to device. Some devices, like my Storm2, seem to validate the CA even when that checkbox is selected. Since there are lots of CAs installed on Blackberry phones, setting up

Re: Best Practices - maximum NAS entries in clients.conf

2011-09-12 Thread Bruce Nunn
If the network your APs are on is physically secure, and you don't need accounting for individual APs, you can use netmasks to define clients in the clients.conf file. - Original Message - From: Sallee, Stephen (Jake) jake.sal...@umhb.edu To: freeradius-users

Re: Pre release of 2.1.12

2011-09-02 Thread Bruce Nunn
40,000 authentications in about 6 and a half hours. I use eap, eap-peap, ldap, mschap, files, sql (mysql), proxy, and postauth mostly. No problems. The files and sql modules are where I have my wildest modifications, but that is that not much compared to what some people on this list are doing.

Re: freeradius authentication stops working after some time...

2010-06-02 Thread Bruce Nunn
I run 2.1.8, server 2008 R2 and samba 3.5.2. It's something to do with winbind, but I have not nailed it down on my installation yet. Sent via Verizon Wireless -Original Message- From: Casartello, Thomas tcasarte...@wsc.ma.edu Date: Wed, 2 Jun 2010 08:28:23 To: 'FreeRadius users

Re: framedipaddress

2010-05-12 Thread Bruce Nunn
I manage a large Meru instalation. If you want to get an IP address logged with a user name or Mac address like Aruba does you can't do it unless you use the captive portal. And the captive portal only sends this info via syslog as u...@1.2.3.4. For the auditors at our site, we send the auth

Hints File Question

2009-12-27 Thread Bruce Nunn
Is this valid syntax for the hints file in version 2.1.7? I intend it to match anything up to and including \\ such as WINXP\\joeuser. DEFAULTPrefix =~ ^(.*[]+), Strip-User-Name = Yes Hint = CAMPUS Thanks. - List info/subscribe/unsubscribe? See

FR 2.1.7 and Hints File

2009-12-22 Thread Bruce Nunn
The problem I'm trying to solve relates to Windows users who leave that Automatically use my Windows login name and password property checked. At my site, we authenticate with PEAPv0/MSCHAPv2 with usernames and mschapv2 password hashes stored in an ldap database, not in a Windows Domain. I'd