Re: revoking ca certificates

2006-06-04 Thread K. Hoercher
e paths do work here. Checking with absolute ones led to the following caveat: if you combine the needed cr's in one file by concatenating c_rehash does only generate one hashname link by virtue of 'openssl crl [...] -hash' providing only (the first?) one. Adding the appropriately

Re: need help from FR gurus.

2006-06-09 Thread K. Hoercher
On 6/9/06, Abul Monsur Mannan <[EMAIL PROTECTED]> wrote: rlm_sql (sql): "/usr/local/src/freeradius-1.1.1/src/modules/rlm_sql/drivers/rlm_sql_mysql" is NOT an SQL driver! radiusd.conf[14]: sql: Module instantiation failed. radiusd.conf[1798] Unknown module "sql". radiusd.conf[1727] Failed to pars

Re: NAS table fields

2006-06-09 Thread K. Hoercher
On 6/9/06, Cliff Hayes <[EMAIL PROTECTED]> wrote: For example, in the clients.conf file, the only required fields are SECRET and SHORTNAME. In the NAS table, SHORTNAME is optional (can be NULL), and NASNAME cannot be NULL. So, do I copy what I had in the clients.conf SHORTNAME into the NAS tabl

Re: freeradius and certs

2006-06-23 Thread K. Hoercher
above) you need. So depending on what you're actually trying to achieve, you only need a subset of the3x3-matrix you listed. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius-1.1.1 with CRL configuration

2006-07-12 Thread K. Hoercher
different files and rehash again or alternatively provide the necessary symlinks yourself, by script or whatever suits you. But this is not a freeradius an esp. no -devel problem, please check openssl docs. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list

Re: Need help setting up PEAP authentication

2006-07-19 Thread K. Hoercher
provide the debug output as mentioned in various docs. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Droping clients from radius (they are connected into radius but they are not connected in their houses)

2006-07-21 Thread K. Hoercher
lem you are refering to. Best regards K .Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Droping clients from radius (they are connected into radius but they are not connected in their houses)

2006-07-21 Thread K. Hoercher
h information about your problem as possible. best regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: issues with peap + tlv part 1

2006-07-27 Thread K. Hoercher
for whatever purpose that fits. But please stop throwing allegations about issues whith mschapv2 and ntlmv2 (whatever that might be, at least it's not part of freeradius). regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: help

2006-08-02 Thread K. Hoercher
Hi, you must be kidding or maybe you confounded the pertinent mailing lists or... Provided there really is a problem with freeradius, please enlighten us as to the debugging output of _it_ not just the nice but offtopic one from hostapd. regards K. Hoercher - List info/subscribe/unsubscribe

Re: Freeradius + OpenLDAP - user password problem

2006-08-03 Thread K. Hoercher
mming from false assumptions on your side). 4. Whatever you test with radtest does not relate to EAP-PEAP/MSCHAP. Please restart your efforts with unchanged default configuration files. Alter them step-by-step according to the information you were already given. And, sorry, don't whip a dead horse

Re: Missing Attributes

2006-08-07 Thread K. Hoercher
n the pertinent tables, wherefore you should contemplate the information contained in the default users file. Actually, Alan didn't say you have to use it. *g* HTH K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: a question about settings for EAP-TLS authentication

2006-08-07 Thread K. Hoercher
certs/random are accessible? It's just a quick shot, I could only check against 1.1.2 which stops with some intelligible message when one or the the other is missing at this stage. Otherwise a backtrace might be helpful. HTH K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius + OpenLDAP - user password problem

2006-08-22 Thread K. Hoercher
le to read the client certificate (which is unneeded as you already noted). If so, it' s not an "error" with respect to freeradius eap etc. As you didn't provide meaningful output one cannot be sure of course... regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius + OpenLDAP - user password problem

2006-08-22 Thread K. Hoercher
le to read the client certificate (which is possible but unneeded as you already noted). If so, it' s not an "error" with respect to freeradius eap etc. As you didn't provide meaningful output one cannot be sure of course... regards K. Hoercher - List info/subscribe/unsubs

Re: PEAP/MSCHAPv2 authentication problems

2006-08-23 Thread K. Hoercher
after the challenge was sent out. That looks curious. As your included data got truncated on the list you might consider resending it as attachment or use a pastebot and provide the link. Maybe you could provide some sniffing on the wireless part (via wireshark et al). That might be instruc

Re: Freeradius + OpenLDAP - user password problem

2006-08-23 Thread K. Hoercher
e radius server might be helpful here too. I'll refrain from looking into that as long as I have to play some sort of detective to even get to know what is going on on your installation. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Eap-Tls Problem

2006-08-23 Thread K. Hoercher
ggestion. Something along this line should apply to your /etc/X1/jagger.pem. ah and yes, just the default users file would suffice. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP PEAP, unable to load certificate

2006-08-24 Thread K. Hoercher
On 8/25/06, Nick Larsen <[EMAIL PROTECTED]> wrote: tls: certificate_file = "(null)" You have to fill in this information. See the comment in eap.conf above the pertinent line. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: PEAP/MSCHAPv2 authentication problems

2006-08-25 Thread K. Hoercher
t reoccur, would you please check for the OID's in your certificates windows thinks are the proper ones. And something Alan mentioned about a ms knowledgebase hint concerning xp sp2 having problems with non-MS radius servers. (I'm looking for it myself atm) HTH K. Hoercher - List info/s

Re: EAP-TLS multi clients

2006-08-29 Thread K. Hoercher
url's where to download those informations. Please don't try to put some digested information into an line mangling mua or an eventually similar way of making it unnecessary hard to look into it for those trying to help. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-TLS multi clients

2006-08-29 Thread K. Hoercher
CA. So I'd suggest looking at openssl.org for further information (looking at the scripts might give you some starting point though). Basically you are to issue (unique) client certs (modelled to the one CA.all gave you) to other users either by acting as your own CA or using some commercial CA.

Re: Freeradius + OpenLDAP - user password problem

2006-08-29 Thread K. Hoercher
andshake failure:s3_pkt.c:837: So your client wasn't able to fiind a correct CA certificate for the cert freeradius had sent before. Please see to provide those. If in doubt, check with dummy ones to be created by CA.all script. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: sqlcounter

2006-08-29 Thread K. Hoercher
On 8/29/06, Fabiano Martins <[EMAIL PROTECTED]> wrote: I've benn searching with no sucess about this... It's frustrating... there is no documents about. Perhaps the looking into the very obscure doc/rlm_sqlcounter file helps, although it' not "DOC" for some stran

Re: FreeRADIUS crashes after EAP/PEAP authentication

2006-08-29 Thread K. Hoercher
Well, the *full* output would have been helpful (including the startup messages). And a backtrace from the coredump. HTH K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius + OpenLDAP - user password problem

2006-08-30 Thread K. Hoercher
e, because _it_ cannot find a CA certificate. What you are talking about is the freeradius side of things which looks alright at first glance. And if you don't get it to work, please first check with demo certficates to be generated by the CA.all script. hth K. Hoercher - List

Re: EAP-TLS multi clients

2006-08-31 Thread K. Hoercher
ately to your needs, is considered not very nice. hth K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Difference between Auth-type=System and Auth type=Local

2006-08-31 Thread K. Hoercher
re the contents of users file do contain information as to those Auth-Types. And to forestall further problems, please keep in mind: http://deployingradius.com/documents/configuration/auth_type.html regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: certificate issue

2006-08-31 Thread K. Hoercher
ficate issues) to provide a known (almost always) working set of generation tools, I'm contemplating a few improvements just now. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: why radacctid is the primary key of radacct table instead of acctuniqueid ?

2006-08-31 Thread K. Hoercher
ue but isn't guaranteed to be so (at least in default setup). regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Everything lookslike it works, but PC is not authentified

2006-09-01 Thread K. Hoercher
t the supplicant sends. What is "host/vinfo-t1" supposed to be? regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problems getting eap-mschapv2 working.

2006-09-04 Thread K. Hoercher
would you please follow the various FAQ, hints in doc etc. and provide a debug output. Oh, and btw a quick test with 1.1.3 shows that at least with that, the statement about the (unconditional) need for configuration of the main mschap module doesn't hold. regards K. Hoercher - List inf

Re: Everything lookslike it works, but PC is not authentified

2006-09-04 Thread K. Hoercher
check for the CN. Afaik you might strip it by using the with_ntdomain_hack directive. Further changes changes depend on the eap type you want to use. I have already asked about that. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Everything lookslike it works, but PC is not authentified

2006-09-04 Thread K. Hoercher
he road. (For the time being you don't need anything set there, esp no User-Password, as we, just now, can guess, you don't want eap-peap) regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Problems getting eap-mschapv2 working.

2006-09-04 Thread K. Hoercher
Hi, just to avoid confusion: On 9/4/06, K. Hoercher <[EMAIL PROTECTED]> wrote: Oh, and btw a quick test with 1.1.3 shows that at least with that, the statement about the (unconditional) need for configuration of the main mschap module doesn't hold. That's nonsense, I just mes

Re: WPA/RADIUS Problems

2006-09-06 Thread K. Hoercher
e places contain lots of information about) freeradius in debian is not linked against it. Ok, enough for now. :) regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: XT Radius to Free Radius

2006-09-07 Thread K. Hoercher
fixing that, I retried with users file again and then it behaved as wanted, allowing on exit code 0, denying on other codes (ok, just tested -1). hth K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-Problem

2006-09-20 Thread K. Hoercher
angen.de. Do you intend to use machine authentication? If so, what does a succesful request look like? Note, that it seems to only find matching DEFAULT entries, so peap would be impossible, as no User-Password is known to freeradius. Otherwise, you should check your XP setup to use the intended

Re: freeradius stops with hostapd

2006-09-21 Thread K. Hoercher
use = NAS-Reboot Processing the preacct section of radiusd.conf modcall: entering group preacct for request 0 Which version of hostapd is that? Perhaps it might me useful to forego the accounting (comment out the lines auth_server_* in hostapd.conf) for the moment and check if the remaining p

Re: Freeradius + OpenLDAP - user password problem

2006-09-22 Thread K. Hoercher
again) the usual suspects: oid's in certs on supplicant, reception of Access-Request there, time, MS foo (they sound familiar somehow *g*) regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius + OpenLDAP - user password problem

2006-09-22 Thread K. Hoercher
On 9/22/06, K. Hoercher <[EMAIL PROTECTED]> wrote: the usual suspects: oid's in certs on supplicant, reception of ah, for peap, of course you only need a proper root ca cert there. Anyways it doesn't look like that gets even relevant. regards K .Hoercher - List info/subsc

Re: Problem configuration eap-tls

2006-09-22 Thread K. Hoercher
Hi, hm, the _full_ debugging output (-X as has been time and time again been mentioned here, faq, etc.) would show, where exactly freeradius wants to read that file. "No such file or directory" does point pretty strong into the direction of the problem one would think. regards K

Re: EAP-Problem

2006-09-22 Thread K. Hoercher
.conf - debug log of supplicant - some beer (should be further up *g*) regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Windows Vista doing PEAP

2006-10-10 Thread K. Hoercher
rmally does live up to its name, i.e. stripping binaries off what it considers "unneeded symbols". For building a "debugging" package let DEB_BUILD_OPTIONS contain "nostrip". Uh, on a side note the ifeq/endif construct around seems unneeded to me, as dh_strip should ho

Re: Decisionmaking in FreeRADIUS & Check/Reply Items

2006-10-11 Thread K. Hoercher
ot;sql" in post-auth{} and minus "sql" in accounting{}. Make small changes and check how they work by looking at debug output. Then you could contemplate putting the logic in users file to sql tables. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Decisionmaking in FreeRADIUS & Check/Reply Items

2006-10-11 Thread K. Hoercher
On 10/11/06, K. Hoercher <[EMAIL PROTECTED]> wrote: and "files" to authenticate {}, get rid of "files" "512*" etc and to authorize{} of course. Sorry for that. K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: mysql and Auth-Type:=Reject Problem

2006-10-13 Thread K. Hoercher
e of coming from radreply table) won't work. See doc/processing_users_file, doc/aaa.txt, "man users" etc. hth K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: TLS handshaking problem

2006-10-13 Thread K. Hoercher
s further down the line. You should check that. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Multiple instances of the exec module

2006-10-13 Thread K. Hoercher
"actual section" by their name. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Mobile Phones Radius Authentications

2006-10-13 Thread K. Hoercher
INSTALL (provided you even talk about freeradius) etc. and almost daily on this list. Even if someone would know anything more specific than me, I think (s)he would consider it too burdensome to reply to such a broad question. regards K. Hoercher - List info/subscribe/unsubscribe? See http://ww

Re: Multiple instances of the exec module

2006-10-13 Thread K. Hoercher
n the comments looks preferable, at least until you get some working config. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: logs: invalid Message-Authenticator! (Shared secret is incorrect.)

2006-10-13 Thread K. Hoercher
ere, done that *g*). Something to those effects regarding chilli.conf. Some of that might have been ruled out/in already, had you provided the full debug output and pertinent snippets from your config. Sniff the radius traffic, and check validity manually. See src/lib/hmac.c hth K. Hoercher -

Re: WPA authentication works but take very log time

2006-10-14 Thread K. Hoercher
request reveiced by radius server: As I told you in another thread, those first 6 requests are part of the ongoing EAP negotiation. To sort out any timing problems it would be helpful to show the log at least up to the point when the server sends either Access-Accept or Access-Reject. regard

Re: Cisco AP, FreeRADIUS and Fedora Directory Server

2006-10-15 Thread K. Hoercher
; parts of the _full_ debug output. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Cisco AP, FreeRADIUS and Fedora Directory Server

2006-10-16 Thread K. Hoercher
you still chose not to provide here. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-TTLS problem at phase 1

2006-10-21 Thread K. Hoercher
all[authenticate]: module "eap" returns invalid for request 1^M modcall: leaving group authenticate (returns invalid) for request 1^M Thats pretty much non-informative. In case, the above fix does not yet yield the desired results, provide the full debug output. regards K. Hoercher - List i

Re: EAP-TTLS problem at phase 1

2006-10-21 Thread K. Hoercher
equest timed out OR EAP-response to an unknown EAP-request^M That does look strange (and might indicate your real problem), if it still persists with the suggested changes it might be useful to dig further into that. Perhaps you could add another -x to the freeradius invocation to

Re: configuration problem in Freeradius.

2006-11-19 Thread K. Hoercher
e behaviour of the server?) regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: distinction between users on different AP (talking to the same radius server)

2006-11-19 Thread K. Hoercher
n't have a clear understanding of what the meaning of "different subnet mask"s in that context could possibly be, under sort of normal circumstances dhcp would happen after users' machines associate/authenticate on an ap. regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: distinction between users on different AP (talking to the same radius server)

2006-11-19 Thread K. Hoercher
ferent inputs. Any more specific suggestions could only arise from you telling what the aps do (other than putting users on different subnets, which is possible too, but not desireable I think) ; more to the point: what (which attributes) do they send in which situations, and what reaction yo

Re: rlm_eap: SSL error

2007-01-19 Thread K. Hoercher
t; message meaning that no error occured. hth K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: One question about Access-Request packet

2007-01-19 Thread K. Hoercher
eral a question to give an useful answer. Keep in mind that "authenticating" against ldap by binding the user's dn, will not work for EAP(-PEAP) Regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: rlm_eap: Failed to link EAP-Type/peap: rlm_eap_peap.so:

2007-01-19 Thread K. Hoercher
lines 21-28 of said rules file. apt-get install libssl-dev dpkg-buildpackage -us -us -rfakeroot -d dpkg -i Before ./configure set --with-rlm_eap_tls in makefile. i think As you don't call ./configure manually there is no business of that. Anyway you should not mess around in ma

Re: EAP-TLS certificate question

2007-01-19 Thread K. Hoercher
") and while perhaps technically possible, ill advised from the SSL/TLS point of view. Good starting points for further reading would be RFCs 2716 and 2246, maybe documentation of openssl. Regards K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Mac OS X EAP-TLS with wrong usename kills freeradius when check_cert_cn is set

2007-01-19 Thread K. Hoercher
7;t be able to crash the authentication server but it looks curious. Perhaps someone might find that information helpful. regards K. Hoercher radius_debug.log Description: Binary data - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius-mysql and freeradius 1.1.5

2007-03-19 Thread K. Hoercher
rce package). Under normal circumstances you cannot/should not mix interdependent packages from different sources. That leads to conflicting dependencies as you are told by apt-get. Those are there for a reason. hth K. Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: EAP-PEAP and windows supplicant behaviour

2005-12-16 Thread K. Hoercher
Some hint in my notes says HKEY_CURRENT_USER\Software\Microsoft\Eapol\UserEapInfo I'm not sure if you have to delete it, or to put some value 0 into it. But I remember it being quite obvious. HTH Klaus Hoercher - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Changes to get tls working at debian

2006-04-27 Thread K. Hoercher
On 4/27/06, Krämer Armin <[EMAIL PROTECTED]> wrote: > Hi, i downloaded the source of freeradius 1.1.1 and compiled it with default > setting which does not include eap-tls support. What do I have to change to If you dl'ed upstream tarball, the debian/rules defaults to building with eap-tls. If you