option 82

2010-02-26 Thread Kevin Croes
Hi, I work at an ISP and we are looking at the possibility to use option 82 in FreeRADIUS. The other side is going to send us an ordernumber and then we want to send a configuration back (an ip address etc.). Been searching how to do this in FreeRADIUS, but haven't found much useful information.

Re: option 82

2010-02-26 Thread Alan DeKok
Kevin Croes wrote: I work at an ISP and we are looking at the possibility to use option 82 in FreeRADIUS. In what, DHCP? RADIUS? The other side is going to send us an ordernumber and then we want to send a configuration back (an ip address etc.). I have no idea what that means...

EAP-TLS with multiple CAs

2010-02-26 Thread Erik Norgaard
Hi: I have a working setup of FreeRADIUS for authentication EAP-TLS for my home wireless network with a home managed CA. Now, I would like to add support for certificates issued by other CAs. Is it possible to include various CA certificates, multiple CA_file statmentes or similar?

Re: option 82

2010-02-26 Thread Bryan Campbell
Google Radius DHCP client and start reading. :-) FWIW - This isn't a Freeradius question. b...@misn.com Alan DeKok wrote: Kevin Croes wrote: I work at an ISP and we are looking at the possibility to use option 82 in FreeRADIUS. In what, DHCP? RADIUS? The other side is going

list of allowed nas clients for realm

2010-02-26 Thread Matija Grabar
I am running FreeRADIUS Version 2.1.8 with mysql as backend database in lab environment. I am authenticating PPP customers from two different network segments behind two cisco NAS devices. All PPP customers are defined in single mysql database with realm suffixes @domain1 and @domain2.

Rejecting users without a realm

2010-02-26 Thread Mike Diggins
I couldn't find an answer to this question in the Archives. I have a FreeRadius Server (2.1.3) and would like it to reject *any* user that attempts login with a realm (u...@realm.com for example). I thought I could do something like this in the user file: DEFAULT Realm == NULL, Auth-Type :=

ntlm_auth and Server 2008 R2 issues

2010-02-26 Thread Walter Gould
We are having the same issue as noted here: http://lists.freeradius.org/pipermail/freeradius-users/2009-November/msg00664.html I am guessing there is no way to use LDAP for MSCHAP authentication? I have read other posts on the list that have said it won't work (which kind of makes sense to

Re: ntlm_auth and Server 2008 R2 issues

2010-02-26 Thread Alan DeKok
Walter Gould wrote: We are having the same issue as noted here: http://lists.freeradius.org/pipermail/freeradius-users/2009-November/msg00664.html See also https://bugzilla.samba.org/show_bug.cgi?id=6563 I am guessing there is no way to use LDAP for MSCHAP authentication? Exactly. I

Re: Rejecting users without a realm

2010-02-26 Thread Alan DeKok
Mike Diggins wrote: I couldn't find an answer to this question in the Archives. I have a FreeRadius Server (2.1.3) and would like it to reject *any* user that attempts login with a realm (u...@realm.com for example). I thought I could do something like this in the user file: DEFAULT Realm

Re: list of allowed nas clients for realm

2010-02-26 Thread Alan DeKok
Matija Grabar wrote: I am running FreeRADIUS Version 2.1.8 with mysql as backend database in lab environment. I am authenticating PPP customers from two different network segments behind two cisco NAS devices. All PPP customers are defined in single mysql database with realm suffixes

Re: EAP-TLS with multiple CAs

2010-02-26 Thread Alan DeKok
Erik Norgaard wrote: I have a working setup of FreeRADIUS for authentication EAP-TLS for my home wireless network with a home managed CA. Now, I would like to add support for certificates issued by other CAs. Is it possible to include various CA certificates, multiple CA_file statmentes or

Re: Authcheck table and groupreply table on two different databases

2010-02-26 Thread Alan DeKok
1839Paolo wrote: The easy think, the question: it’s possible to setup authcheck_table into a database/host and both groupcheck_table, groupreply_table into a different database/host? No. It’s easy to pull username/password from a proprietary database, just know where fields are; but I

Re: Wiki editing

2010-02-26 Thread Alan DeKok
sphaero wrote: Am I overlooking something? How do you edit the wiki. I can't find a way to register an account to edit wiki pages. You can't. Too many spammers. I was about to add some comments about the rlm_sql_iodb driver since everybody need to know the driver looks for the DSN in

Re: EAP-TLS with multiple CAs

2010-02-26 Thread Erik Norgaard
On 26/02/10 16:49, Alan DeKok wrote: Erik Norgaard wrote: I have a working setup of FreeRADIUS for authentication EAP-TLS for my home wireless network with a home managed CA. Now, I would like to add support for certificates issued by other CAs. Is it possible to include various CA

Re: ntlm_auth and Server 2008 R2 issues

2010-02-26 Thread Walter Gould
Alan DeKok wrote: Walter Gould wrote: We are having the same issue as noted here: http://lists.freeradius.org/pipermail/freeradius-users/2009-November/msg00664.html See also https://bugzilla.samba.org/show_bug.cgi?id=6563 Yes, I saw that one... I have read other posts on

Re: ntlm_auth and Server 2008 R2 issues

2010-02-26 Thread Johan Meiring
Alan DeKok wrote: have read other posts on the list that have said it won't work (which kind of makes sense to me). However, it sure would be nice to side step Samba on this issue. It's impossible. (for now) For now? -- Johan Meiring Cape PC Services CC Tel: (021) 883-8271 Fax: (021)

Re: ntlm_auth and Server 2008 R2 issues

2010-02-26 Thread Alan DeKok
Johan Meiring wrote: Alan DeKok wrote: have read other posts on the list that have said it won't work (which kind of makes sense to me). However, it sure would be nice to side step Samba on this issue. It's impossible. (for now) For now? Samba 4 will be a full member of an AD

FreeRadius 2.1.3 SQL error

2010-02-26 Thread Mike Diggins
First question, is the only way to get Accounting data from FreeRadius by using one of the supported databases (like msql)? Is there no way to just cut records to a text file or, ideally, syslog? Second question: I inserted the following sql configuration (supplied to me) into sql.conf but when I

Re: FreeRadius 2.1.3 SQL error

2010-02-26 Thread Alan Buxey
Hi, First question, is the only way to get Accounting data from FreeRadius by using one of the supported databases (like msql)? Is there no way to just cut records to a text file or, ideally, syslog? the details files - depends how you've configured your server! they would usually lurk in

Re: Wiki editing

2010-02-26 Thread Arran Cudbard-Bell
On Feb 26, 2010, at 8:33 AM, Alan DeKok wrote: sphaero wrote: Am I overlooking something? How do you edit the wiki. I can't find a way to register an account to edit wiki pages. You can't. Too many spammers. I was about to add some comments about the rlm_sql_iodb driver since

Re: ntlm_auth and Server 2008 R2 issues

2010-02-26 Thread Alan Buxey
Hi, Samba 4 will be a full member of an AD domain. It will have access to the NT hashed passwords. It will (presumably) be able to export them via LDAP, like a real LDAP server. oooh! yippee! anyway, regarding initial issue samba 3.4.3 might fix the issue but it must also be ntoed

Re: ntlm_auth and Server 2008 R2 issues

2010-02-26 Thread Walter Gould
Alan Buxey wrote: Hi, Samba 4 will be a full member of an AD domain. It will have access to the NT hashed passwords. It will (presumably) be able to export them via LDAP, like a real LDAP server. oooh! yippee! So help me out here - what exactly does that mean? And, how

FreeRADIUS Version 2.1.0 documentation

2010-02-26 Thread Dilip Patel
Where can I find documentation and training material for Free Radius Version 2.10 FreeRADIUS Version 2.1.0, for host x86_64-pc-linux-gnu Ubuntu 9.04. This is the only version that is available from Synaptics Package manager The current version 2.18 does not work in Ubuntu. I tried building

Re: FreeRADIUS Version 2.1.0 documentation

2010-02-26 Thread Alan DeKok
Dilip Patel wrote: Where can I find documentation and training material for Free Radius Version 2.10 FreeRADIUS Version 2.1.0, for host x86_64-pc-linux-gnu Ubuntu 9.04. The server comes with a doc directory. The current version 2.18 does not work in Ubuntu. I tried building the Debina

FreeRadius 2 w/ MySQL - Group check issue

2010-02-26 Thread Craig Schurr
I recently setup a freeradius 2 server with MySQL and I am having an issue where it doesn't appear to be doing group checks. If I have a user set to a group it doesn't appear to check the attributes set in that group:

Re: FreeRADIUS Version 2.1.0 documentation

2010-02-26 Thread Alan Buxey
Hi, Where can I find documentation and training material for Free Radius Version 2.10 FreeRADIUS Version 2.1.0, for host x86_64-pc-linux-gnu Ubuntu 9.04. there should be a doc directory supplied as part of the package - /usr/share/doc/ ?? This is the only version that is available from

Re: option 82

2010-02-26 Thread Arne Larsen
Kevin Croes wrote: Hi, I work at an ISP and we are looking at the possibility to use option 82 in FreeRADIUS. The other side is going to send us an ordernumber and then we want to send a configuration back (an ip address etc.). Been searching how to do this in FreeRADIUS, but haven't found