Re: Acct session ID shows 0

2012-05-15 Thread Fajar A. Nugraha
On Mon, May 14, 2012 at 10:23 PM, alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, I have one doubt in my Acct session id i had clients mac address then ssid and then session id.but in some of the Act session id it shows clients mac address then ssid and then 0.because of which i get huge Acct

change of acct_status type

2012-05-15 Thread Sharad P
hi, can I change ACCT_STATUS_TYPE to interim update.if yes.Please tell me the procedure. Thanks. -- View this message in context: http://freeradius.1045715.n5.nabble.com/change-of-acct-status-type-tp5709796.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List

Re: change of acct_status type

2012-05-15 Thread Fajar A. Nugraha
On Tue, May 15, 2012 at 1:06 PM, Sharad P sharadpanick...@gmail.com wrote: hi, can I change ACCT_STATUS_TYPE to interim update.if yes.Please tell me the procedure. AFAIK no. You should describe what you're trying to accomplish. It looks like you're trying to solve a problem, and arrive at a

Re: Specific User Trace and multiple radiusd instant

2012-05-15 Thread James J J Hooper
On 15/05/2012 02:34, 全球无线联盟 wrote: 2. We tried to run multiple radiusd at same server while the second failed. Can anyone advise how to configure the server to run multiple radiusd simultaneously? Why do you need to do this? FreeRADIUS has virtual-server functionality, so you can create

Re: change of acct_status type

2012-05-15 Thread Sharad P
Hi, I have a problem in which it shows huge acct session time.please see the logs below. on May 14 17:37:56 2012 NAS-IP-Address = 192.168.200.55 NAS-Identifier = E1C76A60846 Called-Station-Id = 00:06:5a:01:1b:d9 NAS-Port = 1 NAS-Port-Type =

Re: Specific User Trace and multiple radiusd instant

2012-05-15 Thread Fajar A. Nugraha
On Tue, May 15, 2012 at 1:21 PM, James J J Hooper jjj.hoo...@bristol.ac.uk wrote: On 15/05/2012 02:34, 全球无线联盟 wrote: 2. We tried to run multiple radiusd at same server while the second failed. Can anyone advise how to configure the server to run multiple radiusd simultaneously? Why do you

Re: Acct session ID shows 0

2012-05-15 Thread Sharad P
Hi, i have a radius server configured on my Pc and a AP connected to my PC.so there is no different NAS. and if the time is set wrong then why dont i get all acct-session-time wrong??In middle of some logs i see this type of absurd timings. -- View this message in context:

Re: change of acct_status type

2012-05-15 Thread Fajar A. Nugraha
On Tue, May 15, 2012 at 1:25 PM, Sharad P sharadpanick...@gmail.com wrote: Hi, I have a problem in which it shows huge acct session time.please see the logs below. This problem is not related whatsover to your previous question. Changing ACCT_STATUS_TYPE will not solve anything. on May 14

Re: Acct session ID shows 0

2012-05-15 Thread Fajar A. Nugraha
On Tue, May 15, 2012 at 1:29 PM, Sharad P sharadpanick...@gmail.com wrote: Hi, i have a radius server configured on my Pc and a AP connected to my PC.so there is no different NAS. your AP is the NAS and if the time is set wrong then why dont i get all acct-session-time wrong??In middle of

Re: return list

2012-05-15 Thread Alan DeKok
Luo, Frank Y.F. Mr. wrote: I have a senario, no ldap schema extension is wanted ( no ldap group or profile is wanted); we do use ldap authentication though; and it works fine. after authentication, we need to check one ldap attribute like vpn and and return class: ou={ldap vpn value} back

Re: Acct session ID shows 0

2012-05-15 Thread Sharad P
hi, can you tell from which time acct start time is calculated. here is the sample of logs. Acctstarttime is calculated from current date and Acct-Session-Time but 1970-01-01 is minimal possible value. This is sample for one client MAC address.you can see the date 1970-01-01. radacctid |

Re: Logrotate tool

2012-05-15 Thread yagizozen
Hello Guys, Thank you for your replies, I decided to use as u said copytruncate and it works well for me. It says that there can be some data loses between the copy and truncate proccesses but it will not be a problem for me. Thank you very much -- View this message in context:

Re: Acct session ID shows 0

2012-05-15 Thread Fajar A. Nugraha
On Tue, May 15, 2012 at 1:58 PM, Sharad P sharadpanick...@gmail.com wrote: hi, can you tell from which time acct start time is calculated. here is the sample of logs. If you mysql, see sql/mysql/dialup.conf. Acctstarttime is calculated from current date and Acct-Session-Time but ... which I

Re: Specific User Trace and multiple radiusd instant

2012-05-15 Thread alan buxey
Hi, 1. We know 'radiusd -X' will run the radius in debuge mode. With large amount user request, the debug information will be massive. It will be difficult to read one specific user authentication process. Can anyone advise how to debug a specific user's access process? raddebug

Post-crash investigations

2012-05-15 Thread Julien Cornuwel
Hi, I setup a cluster (Pacemaker) of two freeradius servers on CentOS 5.8 (freeradius 1.1.3). We use it for 802.1X: our switchs (HP Procurve) send it EAP challenges and it authenticates our users/hosts against an ActiveDirectory domain. It's been running smoothly for a month and stopped working

Re: Post-crash investigations

2012-05-15 Thread alan buxey
Hi, I setup a cluster (Pacemaker) of two freeradius servers on CentOS 5.8 (freeradius 1.1.3). with a version as hideously old as that (really! check the date it was released!) there could be one of many countless bugs you have hit. If you need (why?) the 1.1.x version then I would advise

Re:Specific User Trace and multiple radiusd instant(Tom Deng)

2012-05-15 Thread ????????????
Fajar, Yes. We're using Linux ES 5.4. We're leasing a virtual server from a vendor. While Linux ES 5.4 is the Linux server it can provide. Actually, it helped us. As we need PPTP VPN dailup for our application, the PPTP VPN installation on 5.4 is very smooth. While we can't make it work on

Re: Post-crash investigations

2012-05-15 Thread John Dennis
On 05/15/2012 06:58 AM, alan buxey wrote: Hi, I setup a cluster (Pacemaker) of two freeradius servers on CentOS 5.8 (freeradius 1.1.3). with a version as hideously old as that (really! check the date it was released!) there could be one of many countless bugs you have hit. RHEL 5.8

Re: Post-crash investigations

2012-05-15 Thread Julien Cornuwel
Thanks to both of you for taking the time to answer. I would strongly recommend you migrate to FR 2.1.12 - not only is it maintained, with latest features, bug fixes etc but it is also faster. Unfortunately, this is not an option. HPIDM3 (a radius plugin provided by HP) doesn't work with

Re: Post-crash investigations

2012-05-15 Thread Phil Mayers
On 15/05/12 13:21, Julien Cornuwel wrote: Thanks to both of you for taking the time to answer. I would strongly recommend you migrate to FR 2.1.12 - not only is it maintained, with latest features, bug fixes etc but it is also faster. Unfortunately, this is not an option. HPIDM3 (a radius

Re: Post-crash investigations

2012-05-15 Thread Alan DeKok
Julien Cornuwel wrote: I setup a cluster (Pacemaker) of two freeradius servers on CentOS 5.8 (freeradius 1.1.3). If you're stuck on 1.1.x, use 1.1.8. Really. Don't do ANYTHING else until you upgrade. It could be a solved bug. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Specific User Trace and multiple radiusd instant(Tom Deng)

2012-05-15 Thread Alan DeKok
全球无线联盟 wrote: 1. The output from the radmin is diffirent from Radius -X. While we consider radiusd -X output more helpful information. While radmin didn't. Then (a) submit a patch to fix the problem, or (b) live with using 'radiusd -X' 2. We like to filter the debug information for user 1

Anon repo access?

2012-05-15 Thread Brian Julin
Is anyone else getting this problem, or have I just managed to confuse git somehow? $ git pull origin master fatal: remote error: access denied or repository not exported: /freeradius-server.git $ git remote -v origin git://git.freeradius.org/freeradius-server.git (fetch) origin

Re: Anon repo access?

2012-05-15 Thread Phil Mayers
On 15/05/12 14:15, Brian Julin wrote: Is anyone else getting this problem, or have I just managed to confuse git somehow? I get the same: $ git clone git://git.freeradius.org/freeradius-server.git Cloning into 'freeradius-server'... fatal: remote error: access denied or repository not

Re: webauth and macauth

2012-05-15 Thread djura
Hi Phil, you were right my config was terrible...i started over and followed instructions from wiki on how to setup macauth and 8021x, now my config looks better, but i still have the issue as shown below. It says that mac address is not in authorised_macs but it is, 64-31-50-81-cb-2f

Re: Anon repo access?

2012-05-15 Thread Arran Cudbard-Bell
On 15 May 2012, at 15:32, Phil Mayers wrote: On 15/05/12 14:15, Brian Julin wrote: Is anyone else getting this problem, or have I just managed to confuse git somehow? I get the same: $ git clone git://git.freeradius.org/freeradius-server.git Cloning into 'freeradius-server'...

Re: webauth and macauth

2012-05-15 Thread Phil Mayers
On 15/05/12 14:38, djura wrote: Hi Phil, you were right my config was terrible...i started over and followed instructions from wiki on how to setup macauth and 8021x, now my config looks better, but i still have the issue as shown below. It says that mac address is not in authorised_macs but

Help about debug mode and python

2012-05-15 Thread Vladimir KOLLA
Hi, Thank you for your presentation at OSSIR today. As said, I've a technical question about the debug mode and Python. We are using python with LD_PRELOAD=/usr/lib/python2.6.so.1 in /etc/init.d/freeradius file But when we start FreeRadius in debug mode, it seems that the parameter is bypassed

Freeradius 100% cpu

2012-05-15 Thread Arianna Manlio
Hi, I'm running this version of FR: # freeradius  -v freeradius: FreeRADIUS Version 2.1.10, for host i486-pc-linux-gnu, built on Nov 14 2010 at 20:41:03 OS is: # cat /etc/debian_version 6.0.5 # uname -ar Linux 2.6.32-5-686 #1 SMP Sun May 6 04:01:19 UTC 2012 i686 GNU/Linux it's a VMware VM

Re: Freeradius 100% cpu

2012-05-15 Thread Phil Mayers
On 15/05/12 15:09, Arianna Manlio wrote: Hi, I'm running this version of FR: # freeradius -v freeradius: FreeRADIUS Version 2.1.10, for host i486-pc-linux-gnu, built on Nov 14 2010 at 20:41:03 Upgrade to 2.1.12 Why does this say i486? OS is: # cat /etc/debian_version 6.0.5 # uname -ar

Re: Specific User Trace and multiple radiusd instant(Tom Deng)

2012-05-15 Thread Fajar A. Nugraha
On Tue, May 15, 2012 at 6:20 PM, 全球无线联盟 2394263...@qq.com wrote: 1. The output from the radmin is diffirent from Radius -X. While we consider radiusd -X output more helpful information. While radmin didn't. well, your best option in that case is to use radiusd -X. You mentioned ixc

Re: webauth and macauth

2012-05-15 Thread djura
I've done the changes as stated in wiki, first i changed default file, added this section / --start of default file authorize { preprocess # mac auth part ##3 rewrite_calling_station_id

Re: Post-crash investigations

2012-05-15 Thread Julien Cornuwel
Will do. Thanks. 2012/5/15 Alan DeKok al...@deployingradius.com: Julien Cornuwel wrote: I setup a cluster (Pacemaker) of two freeradius servers on CentOS 5.8 (freeradius 1.1.3).  If you're stuck on 1.1.x, use 1.1.8.  Really.  Don't do ANYTHING else until you upgrade.  It could be a solved

Re: Post-crash investigations

2012-05-15 Thread Julien Cornuwel
Thank you. I'll try that as soon as I'm done upgrading to 1.1.8 2012/5/15 Phil Mayers p.may...@imperial.ac.uk: On 15/05/12 13:21, Julien Cornuwel wrote: Thanks to both of you for taking the time to answer. I would strongly recommend you migrate to FR 2.1.12 - not only is it maintained, with

Re: EAP/TTLS Auth problem

2012-05-15 Thread Steve Hopps
I was able to get this working, thanks for all your help everyone On Mon, May 14, 2012 at 4:51 PM, alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, Well I've been trying to follow the advice here and also what I've found online and in the configs. I attempted to revert to the 'default' config

Re: MSCHAP Errors

2012-05-15 Thread sgilmour
Hi, I have been unable to get a PEAP user to work, but I was able to get a TLS User to work. It keeps on failing for MSCHAP. I tried to change the mschap module settings but this made no difference. I am currently using samba 3.5 with active directory. Does my ntlm_auth path look correct? Thanks

Re: MSCHAP Errors

2012-05-15 Thread Alan Buxey
What does the server try to run when actually dealing with your client? radius -X will show you, you can then try running that command yourself. alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: webauth and macauth

2012-05-15 Thread Phil Mayers
On 15/05/12 15:56, djura wrote: I've done the changes as stated in wiki, Which wiki page? This page: http://wiki.freeradius.org/Mac%20Auth ...doesn't tell you to use your method. So you're looking at another page, or copying it from somewhere older. in users file i have entries looking

Re: Freeradius 100% cpu

2012-05-15 Thread Arianna Manlio
It's the default Debian package. I confirm that freeradius is the process taking 100% CPU. Thankyou very much. A Da: Phil Mayers p.may...@imperial.ac.uk A: freeradius-users@lists.freeradius.org Inviato: Martedì 15 Maggio 2012 16:22 Oggetto: Re: Freeradius 100%

Re: MSCHAP Errors

2012-05-15 Thread Gilmour, Scott
Thanks, I am Working on Upgrading my Ubuntu to the Ubuntu 12.04 LTS and then I will retry the PEAP Authentication I will keep you posted with my results. root@FreeRadius:/home/sqauser# radius -X No command 'radius' found, did you mean: Command 'radiusd' from package 'radiusd-livingston'

FreeRADIUS Installation on Windows Server 2008

2012-05-15 Thread dsumalabe
Hi, I tried installing the FreeRADIUS ver 1.1.7-r0.0.2 and MYSQL 5.5.23 in Windows 7 and it works OK and also the Accounting and Authentication work OK. Now I started installing it in Windows Server 2008. When installing FreeRADIUS in Windows Server 2008, the installation does not finish. When

FreeRADIUS Installation on Windows Server 2008

2012-05-15 Thread dsumalabe
-- View this message in context: http://freeradius.1045715.n5.nabble.com/FreeRADIUS-Installation-on-Windows-Server-2008-tp5710299p5710301.html Sent from the FreeRadius - User mailing list archive at Nabble.com.- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: FreeRADIUS Installation on Windows Server 2008

2012-05-15 Thread John Dennis
On 05/15/2012 02:36 PM, dsumalabe wrote: Hi, I tried installing the FreeRADIUS ver 1.1.7-r0.0.2 and MYSQL 5.5.23 in Windows 7 and it works OK and also the Accounting and Authentication work OK. Now I started installing it in Windows Server 2008. When installing FreeRADIUS in Windows Server 2008,

How to set attribute value as null means that

2012-05-15 Thread mimir
Hello, I want to add a custom attribute before replicate the accounting package with null value. I see that it is added successfully before replication, but when I check it on remote server, I can not see userid1 and userid2 attributes. Do you have any comment on this? [replicate] Replicating

Re: How to set attribute value as null means that

2012-05-15 Thread Arran Cudbard-Bell
On 15 May 2012, at 21:26, mimir wrote: Hello, I want to add a custom attribute before replicate the accounting package with null value. I see that it is added successfully before replication, but when I check it on remote server, I can not see userid1 and userid2 attributes. Do you have

[PATCH]es decrement client limit on socket timeout, saner tls sample conf, and a pasto

2012-05-15 Thread Brian Julin
Three patches versus master attached: The first puts a saner default config for radsec connections from clients, because in the dominant use-case for radsec clients (outside federation servers pointing to your IDP service) these connections are often nailed up by the client so if they timeout

Conditionally passing custom attributes

2012-05-15 Thread Chad Lensert
freeradius-server-utils-2.1.1-7.7.19.77 freeradius-server-libs-2.1.1-7.7.19.77 freeradius-server-2.1.1-7.10.1 Greetings all. I am trying to pass a list of custom attributes based on the information in the radius request. Originally, I tried matching on NAS-IP-Address as noted below, but it

Re: MSCHAP Errors

2012-05-15 Thread Alan DeKok
Gilmour, Scott wrote: I am Working on Upgrading my Ubuntu to the Ubuntu 12.04 LTS and then I will retry the PEAP Authentication I will keep you posted with my results. Upgrading won't help. root@FreeRadius:/home/sqauser# radius -X No command 'radius' found, did you mean: Command

Re: FreeRADIUS Installation on Windows Server 2008

2012-05-15 Thread Alan DeKok
dsumalabe wrote: Hi, I tried installing the FreeRADIUS ver 1.1.7-r0.0.2 and MYSQL 5.5.23 in Windows 7 and it works OK and also the Accounting and Authentication work OK. Now I started installing it in Windows Server 2008. When installing FreeRADIUS in Windows Server 2008, the installation does

Re: webauth and macauth

2012-05-15 Thread Alan DeKok
djura wrote: I've done the changes as stated in wiki, Apparently not. And you've made LOTS of changes. Don't do that. See man radiusd. Make ONE change. TEST IT. Then, IF IT WORKS, make another change. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Freeradius 100% cpu

2012-05-15 Thread Alan DeKok
Arianna Manlio wrote: It's the default Debian package. I confirm that freeradius is the process taking 100% CPU. $ man strace See what it's doing. Using 100% CPU means little without more information. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Help about debug mode and python

2012-05-15 Thread Alan DeKok
Vladimir KOLLA wrote: Thank you for your presentation at OSSIR today. You're welcome. It was nice to get to Paris for a while. As said, I've a technical question about the debug mode and Python. We are using python with LD_PRELOAD=/usr/lib/python2.6.so.1 in /etc/init.d/freeradius file

Re: Conditionally passing custom attributes

2012-05-15 Thread Alan DeKok
Chad Lensert wrote: freeradius-server-utils-2.1.1-7.7.19.77 freeradius-server-libs-2.1.1-7.7.19.77 freeradius-server-2.1.1-7.10.1 Why? 2.1.1 was released almost 4 years ago. Greetings all. I am trying to pass a list of custom attributes based on the information in the radius request.

Re: MSCHAP Errors

2012-05-15 Thread alan buxey
Hi, I am Working on Upgrading my Ubuntu to the Ubuntu 12.04 LTS and then I will retry the PEAP Authentication I will keep you posted with my results. I cant spoon feed you with all your required details - I have a day job too... if you use Ubuntu, then it uses a different name

Re: Help about debug mode and python

2012-05-15 Thread Phil Mayers
On 05/15/2012 10:12 PM, Alan DeKok wrote: I'm not sure why you need to preload the python library. It should be loaded automatically when you load the rlm_python library. It's more tricky, I'm afraid , due to some python idiocy :o( Basically, python modules (compiled as a .so) are not