configuration parameters for perl module in rlm_perl

2013-09-14 Thread Cornelius Kölbel
Hi list, is there are recommended way to pass configuration parameter to a rlm_perl module? My rlm_perl module, would need to have additional configuration parameters. I would like to avoid having the perl module read an additional configuration file. Is there a possibility to add such paramters

Re: configuration parameters for perl module in rlm_perl

2013-09-14 Thread Cornelius Kölbel
Am 14.09.2013 14:50, schrieb Alan DeKok: Cornelius Kölbel wrote: I would like to avoid having the perl module read an additional configuration file. Then edit the source code to rlm_perl, and add those features. Is there a possibility to add such paramters somewhere in the freeradius

Re: LinOTP

2013-08-13 Thread Cornelius Kölbel
or saving in any manner. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Cornelius Kölbel (Head of Product Management) http://www.lsexperts.de LSE Leading Security Experts GmbH, Postfach 100121, 64201 Darmstadt Tel: +49 6151 86086-252, Fax: -299, Mobil: +49 160

Re: Any One-Time password system.

2013-05-14 Thread Cornelius Kölbel
/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html -- Cornelius Kölbel (Head of Product Management) http://www.lsexperts.de LSE Leading Security Experts GmbH, Postfach 100121, 64201 Darmstadt Tel: +49 6151 86086-252, Fax: -299, Mobil: +49 160 96307089 Unternehmenssitz: Weiterstadt

Re: 2 Factor Authetication and EAP-GTC

2012-07-08 Thread Cornelius Kölbel
Hi Carl, This heavily depends on your OTP backend. The problem arises when the OTP is not passed to the radius server, which is the case with all challenge response protocols. Then the backend can not easily predict, which OTP value the user has entered--- due to time drifts (time based) or

Re: Multiple challenges to login

2012-05-14 Thread Cornelius Kölbel
Hello, I would take a look at the cookies in your browser. I could suspect that you got two cookies, the browser might not send the cookie for some internal URL, that gets called on your site. (maybe because it is not the fqdn but the IP). Then the cookie will not be sent and you need to

Re: Logrotate tool

2012-05-14 Thread Cornelius Kölbel
Hi, you could also try to use copytruncate This will not remove the current log file, but will copy the logfile and then try to truncate, so that you should not run into file handle issues. Kind regards Cornelius Am 14.05.2012 16:15, schrieb yagizozen: Hello everyone, As you

Re: Using freeRadius with OTP and gateway

2012-03-07 Thread Cornelius Kölbel
Hello Mercier, the interesting part about your idea is, that the user sends the SMS to authenticate, this avoids that you will have to pay for the SMS. Most solutions send the SMS with the OTP to the user, so that you - the provider - will have to pay for the SMS sending. Nevertheless you might

Returning Filter-Id based on LDAP group

2012-02-06 Thread Cornelius Kölbel
Hello list, I'd like to set the Filter-Id in the response based on an LDAP group. authorize { if ( Ldap-Group =~ /CN=group1,ou=groups,dc=company,dc=com/ ) { update control { Tmp-String-1 := group1 } } post-auth { update reply { Filter-Id

Re: Returning Filter-Id based on LDAP group

2012-02-06 Thread Cornelius Kölbel
Hi Phil, I thought so. But thanks a lot for clarifying this. Kind regards Cornelius Am 06.02.2012 17:21, schrieb Phil Mayers: On 06/02/12 15:53, Cornelius Kölbel wrote: ... but it seems that the ldap_groupcmp does not support pattern matching? Am I right or does anybody has another idea