Re: FR + AD host/ machine/ workstation authentication

2007-07-09 Thread Jacob Jarick
If you wish to split hairs over a single line in my email that you purposefully skewed the meaning off by all means be that guy. Should you have anything constructive at all to offer the conversation please do, however petty criticisms are not welcome though. On 7/9/07, Alan DeKok [EMAIL

Re: FR + AD host/ machine/ workstation authentication

2007-07-09 Thread Jacob Jarick
Fussy config file = petty criticism ? If so deal with it you will hear far worse I'm sure. Why not be honest ? and admit that all your really after is to continue the conflict we hard several months ago. So can we drop it please? If nothing else this is counter productive. I'm very surprised

Re: FR + AD host/ machine/ workstation authentication

2007-07-09 Thread Jacob Jarick
my 2n comment was referring to my current project (ntlm auth + conditional auth if ldap Field dialupaccess =1 On 7/9/07, Jacob Jarick [EMAIL PROTECTED] wrote: On 7/9/07, Alan DeKok [EMAIL PROTECTED] wrote: Jacob Jarick wrote: Fussy config file = petty criticism ? When it's clear that

Re: FR + AD host/ machine/ workstation authentication

2007-07-08 Thread Jacob Jarick
If it's not clear, you don't understand how the configuration files work. Well yes Alan, thats why I was asking for help on the subject If I was 100% on the subject I wouldnt request conformation or information would I ? Ah, yes. There's nothing quite like asking for help and insulting the

Re: FR + AD host/ machine/ workstation authentication

2007-07-08 Thread Jacob Jarick
Phil A.L Thanks alot for this new information I have to rebuild my network again (big shift around at work) and test again. On 7/7/07, Phil Mayers [EMAIL PROTECTED] wrote: As per my previous emails, you can see the rlm_mschap is doing the expansion correctly without Novells hack: modcall:

Re: FR + AD host/ machine/ workstation authentication

2007-07-07 Thread Phil Mayers
On Fri, 2007-07-06 at 10:22 +0100, [EMAIL PROTECTED] wrote: Hi, quick question, should machine authentication work if I follow the howto on a base system or will I need to add attr_rewrite's as suggested in the novell howto. you will need to do the attr_rewrites or the host name wont

Re: FR + AD host/ machine/ workstation authentication

2007-07-07 Thread Phil Mayers
On Fri, 2007-07-06 at 14:14 +0800, Jacob Jarick wrote: Im after some documentation on setting up host authentication on freeradius (or an example config). This url here looks like what I need http://support.novell.com/docs/Tids/Solutions/10100693.html but their instructions are pretty lousy

Re: FR + AD host/ machine/ workstation authentication

2007-07-07 Thread Phil Mayers
As per my previous emails, you can see the rlm_mschap is doing the expansion correctly without Novells hack: modcall: entering group MS-CHAP for request 6 rlm_mschap: No User-Password configured. Cannot create LM-Password. rlm_mschap: No User-Password configured. Cannot create

FR + AD host/ machine/ workstation authentication

2007-07-06 Thread Jacob Jarick
Im after some documentation on setting up host authentication on freeradius (or an example config). This url here looks like what I need http://support.novell.com/docs/Tids/Solutions/10100693.html but their instructions are pretty lousy For machine-based authentication or user based

Re: FR + AD host/ machine/ workstation authentication

2007-07-06 Thread Jacob Jarick
I trigger machine logon attempt by booting the laptop or logging out of an active session (both seem to work). Near as I can tell the xp machine floods the radius server with authentication attempts. All seem to fail but the last one but it has no effect the machine does not connect to the

Re: FR + AD host/ machine/ workstation authentication

2007-07-06 Thread A . L . M . Buxey
Hi, This url here looks like what I need http://support.novell.com/docs/Tids/Solutions/10100693.html but their instructions are pretty lousy For machine-based authentication or user based authentication, modify the RADIUSD.CONF file by adding the following lines: doesnt say where or what

Re: FR + AD host/ machine/ workstation authentication

2007-07-06 Thread Alan DeKok
Jacob Jarick wrote: This url here looks like what I need http://support.novell.com/docs/Tids/Solutions/10100693.html but their instructions are pretty lousy For machine-based authentication or user based authentication, modify the RADIUSD.CONF file by adding the following lines: doesnt say

Re: FR + AD host/ machine/ workstation authentication

2007-07-06 Thread Jacob Jarick
config on client follows exactly what the howto reccomends with the 1 change of checking authenticate as computer when computer information is available. Which as you can see does attempt to auth. The cert options are set as in this picture:

Re: FR + AD host/ machine/ workstation authentication

2007-07-06 Thread Jacob Jarick
quick question, should machine authentication work if I follow the howto on a base system or will I need to add attr_rewrite's as suggested in the novell howto. On 7/6/07, Jacob Jarick [EMAIL PROTECTED] wrote: config on client follows exactly what the howto reccomends with the 1 change of

Re: FR + AD host/ machine/ workstation authentication

2007-07-06 Thread Alan DeKok
[EMAIL PROTECTED] wrote: ... those parts can go pretty much anywhere in the main config file - eg stick them at the end of the file. Nope. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FR + AD host/ machine/ workstation authentication

2007-07-06 Thread A . L . M . Buxey
Hi, quick question, should machine authentication work if I follow the howto on a base system or will I need to add attr_rewrite's as suggested in the novell howto. you will need to do the attr_rewrites or the host name wont be munged properly alan - List info/subscribe/unsubscribe? See

Re: FR + AD host/ machine/ workstation authentication

2007-07-06 Thread A . L . M . Buxey
Hi, those parts can go pretty much anywhere in the main config file - eg stick them at the end of the file. Nope. sorry, yes - they must go into the config file BEFORE they are instantiated before a module. ie if you are calling them from authorize, then put them into the config