Re: Long Access time

2007-05-09 Thread Josh Shamir
The packets are making it to the supplicant, so I don't think there's a problem with the AP or anything else. It's a supplicant issue. The strange problem is that the long authentication time are about the same for Win XP build-in supplicant and MAC OS X supplicant. What kind of changes can

Long Access time

2007-05-08 Thread Josh Shamir
Hi all, I have implemented Freeradius with LDAP, all works without error but when the user log in the access time is too log (about 3,5 minutes). This access time isn't platform depended (we use Windows and Mac client). These are the log: proxy.conf proxy server { synchronous = yes

Re: Long Access time

2007-05-08 Thread Josh Shamir
On 5/8/07, Alan DeKok [EMAIL PROTECTED] wrote: Perhaps you could explain what you mean by that. What's a long access time? Excuse my english. I mean the time that passed between the user sends login information and the success authentication by the supplicant. Which doesn't include

Re: Long Access time

2007-05-08 Thread Josh Shamir
On 5/8/07, Alan DeKok [EMAIL PROTECTED] wrote: Sounds like the supplicant or access point has issues. It can be an access point problem? About the communication with Coovachilli or Radius? Or proxy.conf bad configured? Which doesn't include a final Access-Accept, or Access-Reject. Here it

Strange random disconnection (Lost-Carrier)

2007-03-01 Thread Josh Shamir
Hello, some of my users have a strange problem; randomly, they have been disconnected after a few minutes get authenticated. Searching in log file, i've seen that the problem is Lost Carrier Wed Feb 28 09:16:24 2007 : Debug: Nothing to do. Sleeping until we see a request. rad_recv:

On IEEE 802.1x roaming

2007-02-28 Thread Josh Shamir
Hello, I'm using FreeRADIUS with Coova Chilli in proxy mode with IEEE 802.1Xauthentication (PEAP auth. method to be more specific). In my network there are 6 Access Point that use TKIP as security protocol. Now I need that the Supplicants can do roaming between the Access Points. The IEEE 802.1X

WPA Guest support

2006-11-24 Thread Josh Shamir
Hi, I am interested in the fact that also the users who are not registered can visit a few sites. I would to know if the last stable version of freeradius support the WPA Guest feature for 802.1x captive portal implemented by Coova chilli. And if so what kinds of modifications I must do in the

Re: caching mechanisms and clean disconnect

2006-11-17 Thread Josh Shamir
On 11/16/06, Alan DeKok [EMAIL PROTECTED] wrote: And what does the output of radiusd -X say? Is it rejecting the user? When I login with the same user (on the same machine), after a disconnection, if I want reconnect immediatly freeRADIUS receive the first request and it accept the user

caching mechanisms and clean disconnect

2006-11-16 Thread Josh Shamir
Hi, I've a problem regarding the clean disconnect of a client and some caching mechanisms. I briefly illustrate my problem : My system is composed by freeradius and chillispot with WPA enterprise (LDAP as backend). When i connect a client 1 to my system all works fine, except for the time taked

Re: WPA authentication works only with MacOS clients

2006-10-17 Thread Josh Shamir
It works!Thanks.Josh Shamir - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

WPA authentication works only with MacOS clients

2006-10-16 Thread Josh Shamir
Hello all, I'm using WPA with EAP-TTLS and PEAP with a MacOS .Authentication works fine (even if enough slowly). The problem is that I can't authenticate WinXP client. I've readed that for using EAP-TTLS are required some other supplicant like SecureW2. Is SecureW2 required also for PEAP? Thanks

Re: WPA authentication works only with MacOS clients

2006-10-16 Thread Josh Shamir
On 10/16/06, Stefan Winter [EMAIL PROTECTED] wrote: Hi Josh,No, the built-in supplicant works. But then your server cert needs to havethe TLS Web Server Authentication OID, otherwise the supplicant will refuseto authenticate. This special surprise brought to you by: Microsoft :-) Hi Stefan,thank

Re: WPA authentication works only with MacOS clients

2006-10-16 Thread Josh Shamir
Hi, I can't use NT-hash because I use PAP and I need clear-text password. However I've generated server-side certificates with CA.all script with standart xpextension: [ xpclient_ext] extendedKeyUsage = 1.3.6.1.5.5.7.3.2 [ xpserver_ext] extendedKeyUsage = 1.3.6.1.5.5.7.3.1 Can I modify this OID

Re: WPA authentication works only with MacOS clients

2006-10-16 Thread Josh Shamir
Hi Jason,I want to use PEAP.So I can use PEAP on a WinXP SP2 client without any other supplicant, using his native supplicant.The problem is that with native WinXP supplicant the authentication process failed, and freeradius server give me an error regarding certificates. The strange thing is that