Re: FreeRadius error LDAP Authentication

2013-07-19 Thread Peter Lambrechtsen
You shouldn't have quotes around your username or domain. You should use identity = cn=user,ou=people,dc=domain,dc=it On 19/07/2013 7:05 PM, Marco Aresu marcoar...@gmail.com wrote: Hi All, i am new about FreeRadius. I am moving from Cisco ACS Tacacs to FreeRadius. During LDAP configuration i

Re: Re: Freeradius 3 LDAP Generic Attributes

2013-04-12 Thread Nicholas Lemberger
The ldap.attrmap syntax in FR2 was: checkItem $GENERIC$ radiusCheckItem replyItem $GENERIC$ radiusReplyItem Basically the ldap attributes radiusCheckItem radiusReplyItem contained FR attr/value pairs which were then added to the

Re: Freeradius 3 LDAP Generic Attributes

2013-04-12 Thread Arran Cudbard-Bell
On 12 Apr 2013, at 15:00, Nicholas Lemberger nick.lember...@lkfd.net wrote: The ldap.attrmap syntax in FR2 was: checkItem $GENERIC$ radiusCheckItem replyItem $GENERIC$ radiusReplyItem Basically the ldap attributes radiusCheckItem

Re: Freeradius 3 LDAP Generic Attributes

2013-04-12 Thread Arran Cudbard-Bell
On 12 Apr 2013, at 15:21, Arran Cudbard-Bell a.cudba...@freeradius.org wrote: On 12 Apr 2013, at 15:00, Nicholas Lemberger nick.lember...@lkfd.net wrote: The ldap.attrmap syntax in FR2 was: checkItem $GENERIC$ radiusCheckItem replyItem $GENERIC$

Re: Freeradius 3 LDAP Generic Attributes

2013-04-10 Thread Arran Cudbard-Bell
I've been puttering around with FR3 and haven't been able to figure out how to set up a mapping from LDAP 'radiusReplyItem' 'radiusCheckItem' attributes to FR3 generic attributes. I guess if it was useful we could add it back in, there's no real reason not to. Could you remind me what the

Re: Freeradius with ldap

2012-05-31 Thread Alan DeKok
Marlos Alex wrote: I'm in trouble and I think that freeradius is, can anyone help me, I configured theldap group and created a wireless and want only the users of this group to accessmy wifi network? Examples of LDAP group checking are in the FAQ. Alan DeKok. - List

Re: Freeradius with ldap

2012-05-31 Thread g17jimmy
The FAQ gives a *very* basic and less than complete example of using groups. I found an old maillist entry that might be of help here. - http://lists.freeradius.org/pipermail/freeradius-users/2007-June/019764.html I'm trying to do something similar and I'm having trouble getting radius to be

Re: FreeRADIUS with LDAP Support

2011-12-08 Thread Alan Buxey
Hi, I tried to compile FreeRADIUS with LDAP support however, rlm_ldap has not been compiled. Are libldap-2.4-2 libldap-dev not sufficent? Do I need to install OpenLDAP? if you read the output of ./configure eg ./confogure | grep WARN you will see what LDAP stuff is required - openldap

Re: FreeRADIUS with LDAP Support

2011-12-08 Thread Fajar A. Nugraha
On Thu, Dec 8, 2011 at 9:51 AM, Nick Khamis sym...@gmail.com wrote: Hello Everyone, I tried to compile FreeRADIUS with LDAP support however, rlm_ldap has not been compiled. Are libldap-2.4-2 libldap-dev not sufficent? Do I need to install OpenLDAP? Try libldap2-dev. That's what on

Re: FreeRADIUS with LDAP Support

2011-12-08 Thread Nick Khamis
Hello Everyone, I do have libldap2-dev installed however, it seems like openldap in all it's totality is needed? Thanks in Advnace, Nick. On Thu, Dec 8, 2011 at 5:31 AM, Fajar A. Nugraha l...@fajar.net wrote: On Thu, Dec 8, 2011 at 9:51 AM, Nick Khamis sym...@gmail.com wrote: Hello Everyone,

Re: FreeRADIUS with LDAP Support

2011-12-08 Thread John Dennis
On 12/08/2011 01:11 PM, Nick Khamis wrote: Hello Everyone, I do have libldap2-dev installed however, it seems like openldap in all it's totality is needed? What is needed will be listed in the output of configure. Also listed will be where configure looked for the dependency. You should read

Re: Freeradius and LDAP keepalive

2011-09-08 Thread Angel L. Mateo
Thank you. I have tried those options, but they doesn't work for me. The problem is that they configure freeradius to send TCP Keepalive messages over the connection, but these packets are just TCP packets, they don't content any ldap command, so openldap idle_timeout is still applied. --

Re: Freeradius and LDAP keepalive

2011-09-08 Thread Alan DeKok
Angel L. Mateo wrote: Thank you. I have tried those options, but they doesn't work for me. The problem is that they configure freeradius to send TCP Keepalive messages over the connection, but these packets are just TCP packets, they don't content any ldap command, so openldap idle_timeout

Re: Freeradius and LDAP keepalive

2011-09-07 Thread Alan DeKok
Angel L. Mateo wrote: I have a freeradius 2.1.10 running in a ubuntu (10.04) server. My users are in a ldap directory. The problem I have is that openldap server has an idle timeout (if there is more than this time with an idle connection, openldap closes the connection). So I want

Re: Freeradius and LDAP keepalive

2011-09-07 Thread Angel L. Mateo
El 07/09/11 13:02, Alan DeKok escribió: Angel L. Mateo wrote: I have a freeradius 2.1.10 running in a ubuntu (10.04) server. My users are in a ldap directory. The problem I have is that openldap server has an idle timeout (if there is more than this time with an idle connection,

Re: Freeradius and LDAP keepalive

2011-09-07 Thread Alan DeKok
Angel L. Mateo wrote: I didn't find any 2.1.12 freeradius version (the latest version at freeradius web is 2.1.11). In 2.1.11 (and 2.1.10) the options I have found that could be related are: 2.1.12 will be released soon. * ldap_connections_number: number of active ldap connections

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread nf-vale
Hi, You can add NT / LM pairs to each LDAP user object. You must include the samba.schema into the ldap server schemas. Ex: sambaNTPassword: CAF13D4F321E608B27FD75D2549BA53C sambaLMPassword: 02D093CE93038E2FAAD3B435B51404EE You can create these passwords using smbencrypt tool (deployed with

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Alan DeKok
Daniel Gomes wrote: I know this is a question which has been thoroughly asked and answered, but after spending several days configuring, debugging, searching the internet, rec-configuring, etc, I still can't get my freeradius server to properly authenticate users (for a pptd server). Go

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Daniel Gomes
Hey there, first of all, thanks for all the tips! Commenting them, in the order in which they came: @peter lambrechtsen: I actually had tried PAP before, but I gave up then because pptpd was refusing clients without even consulting the RADIUS server... But I noticed (a couple of minutes

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Alan DeKok
Daniel Gomes wrote: From the logs, and as I wrote on my initial cry for help, I could see that the password wasn't being found, I just couldn't puzzle out why... And yes, the users do have passwords on LDAP (we are using it to authenticate many other applications), and as I wrote down, radtest

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Daniel Gomes
Wrong guess, i'ts OpenLDAP :) Em 09-07-2010 13:04, Alan DeKok escreveu: Daniel Gomes wrote: From the logs, and as I wrote on my initial cry for help, I could see that the password wasn't being found, I just couldn't puzzle out why... And yes, the users do have passwords on LDAP (we are using

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Alan DeKok
Daniel Gomes wrote: Wrong guess, i'ts OpenLDAP :) Then fix it so that it returns a password to FreeRADIUS. It's an LDAP server. If it doesn't return a password when an LDAP client queries it for a password, it's broken. Alan DeKok. - List info/subscribe/unsubscribe? See

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Daniel Gomes
Well, as I mentioned (a couple of times now), the LDAP server was indeed returning a password to FreeRADIUS, since radtest was always working fine. So the problem wasn't in the LDAP server itself, because it does return a password when an LDAP client queries it for a password (as I also

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Alan DeKok
Daniel Gomes wrote: Well, as I mentioned (a couple of times now), the LDAP server was indeed returning a password to FreeRADIUS, since radtest was always working fine. No, it wasn't returning a password to FreeRADIUS. Go *read* the debug output. It will prove this. When using PAP, the

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Daniel Gomes
Em 09-07-2010 13:59, Alan DeKok escreveu: Daniel Gomes wrote: Well, as I mentioned (a couple of times now), the LDAP server was indeed returning a password to FreeRADIUS, since radtest was always working fine. No, it wasn't returning a password to FreeRADIUS. Go *read* the debug

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Alan DeKok
Daniel Gomes wrote: we are currently and successfully using it to authenticate other services).\ Using PAP passwords. Actually these application are probably just binding with the user's credentials, but that's not relevant here. sigh That's what I meant. Well, it doesn't

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-09 Thread Daniel Gomes
Em 09-07-2010 17:12, Alan DeKok escreveu: Daniel Gomes wrote: we are currently and successfully using it to authenticate other services).\ Using PAP passwords. Actually these application are probably just binding with the user's credentials, but that's not

Re: Freeradius with LDAP backend for pptpd (via MS-CHAP)

2010-07-08 Thread Peter Lambrechtsen
Why not setup your NAS to use PAP, instead of MS-CHAP. If you use MS-CHAP you will need to have NT Hash'es in your LDAP directory. It would be far easier to have PAP authentication enabled on your NAS, then it should work fine. On Tue, Jul 6, 2010 at 3:59 AM, Daniel Gomes dgo...@ipfn.ist.utl.pt

Re: FreeRADIUS with LDAP backend (PAP works but CHAP or any other modules does not work), help please

2009-10-04 Thread Peter Lambrechtsen
You're password needs to be readable in cleartext by FR for anything other than PAP to work. That way FR can hash/encrypt the password out of LDAP on the server side and compare against the hash it gets passed from the client. On Sun, Oct 4, 2009 at 6:07 PM, Ryaz Khan rk...@ezesolve.com wrote:

Re: FreeRADIUS with LDAP backend (PAP works but CHAP or any other modules does not work), help please

2009-10-04 Thread Ivan Kalik
I am glad to say that I was able to setup FreeRADIUS ver. 2.1.7 with LDAP (slapd) authentication after a continuous research of a whole week. I can authenticate user via LDAP but it only works for PAP, radtest tool works, NTRadPing works but only when using PAP (un-checking CHAP). If you have

Re: freeradius and ldap

2009-08-02 Thread Ivan Kalik
I installed freeradius-server-2.1.6. It is related with a LDAP server.when run radiusd -X there is this error: /usr/local/etc/raddb/modules/ldap[29]: Failed to link to module 'rlm_ldap': /usr/lib/rlm_ldap.so: undefined symbol: librad_errstr Is it needed to install freeradius-ldap or my

Re: freeradius and ldap

2009-08-02 Thread Eric
Yum install freeradius-ldap sends this needed too. I installed freeradius-server-2.1.6. It is related with a LDAP server.when run radiusd -X there is this error: /usr/local/etc/raddb/modules/ldap[29]: Failed to link to module 'rlm_ldap': /usr/lib/rlm_ldap.so: undefined symbol:

Re: freeradius and ldap

2009-08-02 Thread Alan Buxey
Hi, I installed freeradius-server-2.1.6. It is related with a LDAP server.when run radiusd -X there is this error: /usr/local/etc/raddb/modules/ldap[29]: Failed to link to module 'rlm_ldap': /usr/lib/rlm_ldap.so: undefined symbol: librad_errstr Is it needed to install freeradius-ldap or

Re: freeradius and ldap

2009-08-02 Thread Eric
Yes but yum install version 1.1.3 and I want to use reply-name item that is in version 2.1.6. if you installed freeradius from YUM it looks like it didnt pull in dependencies. for LDAP functionality, you'll need to install openldap and all of its dependencies. if you built from source, you'll

Re: freeradius and ldap

2009-08-02 Thread Ivan Kalik
Yes but yum install version 1.1.3 and I want to use reply-name item that is in version 2.1.6. http://wiki.freeradius.org/Red_Hat_FAQ Ivan Kalik Kalik Informatika ISP - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-25 Thread Alan DeKok
Christopher Sheldon wrote: Does anyone else who subscribes to the list specifically read every email Alan sends just to chuckle at him berating the poor, confused people seeking help? My unhelpful comments are directed at the people who don't read (a) the documentation I already wrote, or

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-25 Thread Alan DeKok
daverum...@boothcreek.com wrote: So funny you say that, I was just talking about that with a co worker. I almost find myself searching for his emails and thinking that poor person who is looking for help. Asking people to read the debug log, as suggested in the FAQ, README, INSTALL, man

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-25 Thread John Dennis
Alan often replies immediately with useful information, often for questions which are constantly repeated. I'm personally impressed with his tireless dedication, not only in being one of the primary help desk roles but also in developing the software, both of which you're getting for *free*. I

RE: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-25 Thread Danner, Mearl
: freeradius 2.1.6 ldap + mschapv2 to authenticate Alan often replies immediately with useful information, often for questions which are constantly repeated. I'm personally impressed with his tireless dedication, not only in being one of the primary help desk roles but also in developing

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-24 Thread Alan DeKok
jpablorp wrote: I replace eap.conf with the Default eap.conf file and this is my debug: Where you have *deleted* the real cause of the error. [peap] Had sent TLV failure. User was rejected earlier in this session. Look EARLIER in the debug log for the failure. It's really not hard.

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-24 Thread jpablorp
Thanks for your help. I'm pretty new on freeradius. I've been read many how's to, but only in this post I've discovered many things. Alan DeKok-2 wrote: jpablorp wrote: I replace eap.conf with the Default eap.conf file and this is my debug: Where you have *deleted* the real cause

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-24 Thread Christopher Sheldon
Does anyone else who subscribes to the list specifically read every email Alan sends just to chuckle at him berating the poor, confused people seeking help? It's like reality TV. ;-) Chris. Alan DeKok wrote: jpablorp wrote: I replace eap.conf with the Default eap.conf file and this

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-24 Thread daverummel
ReplyTo: FreeRadius users mailing list Subject: Re: freeradius 2.1.6 ldap + mschapv2 to authenticate Sent: Jun 24, 2009 5:36 PM Does anyone else who subscribes to the list specifically read every email Alan sends just to chuckle at him berating the poor, confused people seeking help? It's like

RE: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-24 Thread Tim Sylvester
Of daverum...@boothcreek.com Sent: Wednesday, June 24, 2009 7:56 PM To: FreeRadius users mailing list Subject: Re: freeradius 2.1.6 ldap + mschapv2 to authenticate Chris, So funny you say that, I was just talking about that with a co worker. I almost find myself searching for his emails

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-23 Thread Ivan Kalik
I've trying to setup a freeradius 2.1.6 with Ldap and mschapv2 to authenticate. when I send test from my console, this works fine. But when I try to connect. I don't know what I'm missing. here is my radiusd.conf: Why did you find it necessary to butcher default configuration? Use default

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-23 Thread jpablorp
Thanks for your response. Now I'm using the defaults files and configure the access in modules (raddb/modules/ldap). Now seems like the solution is closer, When I test this appear in my server in debug mode: [ldap] No default NMAS login sequence [ldap] looking for check items in directory...

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-23 Thread Ivan Kalik
Thanks for your response. Now I'm using the defaults files and configure the access in modules (raddb/modules/ldap). Now seems like the solution is closer, When I test this appear in my server in debug mode: ... [eap] EAP NAK [eap] NAK asked for unsupported type 25 [eap] No common EAP

Re: freeradius 2.1.6 ldap + mschapv2 to authenticate

2009-06-23 Thread jpablorp
Ivan Kalik wrote: Have you done some strange things to eap.conf or are you using the default one? Default configuration works. I replace eap.conf with the Default eap.conf file and this is my debug: ++[ldap] returns ok Found Auth-Type = EAP +- entering group authenticate {...} [eap]

RE: FreeRadius 2.1 + LDAP Authentication - mschap

2009-06-05 Thread Mackey, Theral
[mschapv2] +- entering group MS-CHAP {...} [mschap] No Cleartext-Password configured. Cannot create LM-Password. [mschap] No Cleartext-Password configured. Cannot create NT-Password. [mschap] Told to do MS-CHAPv2 for sminhas with NT-Password [mschap] FAILED: No NT/LM-Password. Cannot perform

Re: freeRadius 1.1.6 ldap inner and outer identity

2009-05-25 Thread Ivan Kalik
We use freeRadius v 1.1.6 and EAP-TTLS for our WiFi network. FreeRadius uses LDAP for users autentication. It is querying LDAP about inner identities and outer identities (anonymous usually). Is there any way to stop freeRadius from querying LDAP about outer identities? Upgrade. In 2.x inner

Re: freeRadius 1.1.6 ldap inner and outer identity

2009-05-25 Thread Alan DeKok
Daniel Daza Muñoz wrote: We use freeRadius v 1.1.6 and EAP-TTLS for our WiFi network. FreeRadius uses LDAP for users autentication. It is querying LDAP about inner identities and outer identities (anonymous usually). Is there any way to stop freeRadius from querying LDAP about outer

Re: FreeRADIUS and LDAP Groups

2008-12-13 Thread tnt
You don't need Auth-Type Accept (it will let people in even if the password is wrong). Processing of the users file stops with the first match without Fall-Trough. Ivan Kalik Kalik Informatika ISP Dana 12/12/2008, Tim Gustafson t...@soe.ucsc.edu piše: Add: DEFAULT Auth-Type := Reject

Re: FreeRADIUS and LDAP Groups

2008-12-12 Thread Tim Gustafson
Add: DEFAULT Auth-Type := Reject Awesome, that worked. So, if I wanted to enable multiple LDAP groups, would this be the correct syntax: DEFAULT LDAP-Group == foo, Auth-Type := Accept DEFAULT LDAP-Group == bar, Auth-Type := Accept DEFAULT LDAP-Group == baz, Auth-Type := Accept DEFAULT

Re: FreeRADIUS and LDAP Groups

2008-12-11 Thread tnt
In my users I have DEFAULT LDAP-Group == foo However, even with these configuration options set, anyone with a valid login and password can authenticate right now. In my radiusd -X I see: rlm_ldap: performing search in dc=blah, with filter ((cn=foo)(memberUid=test)) rlm_ldap: object not found

Re: Freeradius 2.0.5 %{Ldap-UserDn} not correctly expanded ?

2008-07-02 Thread Alan DeKok
[EMAIL PROTECTED] wrote: Trying to setup group membership filtering against LDAP group membership for user authentication and authorization, seems that %{Ldap-UserDn} is not correctly expanded (shown as blank) in my conf. Does anyone experienced same problems or has any idea about what is

Réf. : Re: Freeradius 2.0.5 %{ Ldap-UserDn} not correctly expanded ?

2008-07-02 Thread Pierre . Strazza-prestataire
Thanks a lot, that was the point. Pierre [EMAIL PROTECTED] wrote: Trying to setup group membership filtering against LDAP group membership for user authentication and authorization, seems that %{Ldap-UserDn} is not correctly expanded (shown as blank) in my conf. Does anyone experienced

Re: FreeRadius and LDAP/AD username/password check

2008-02-18 Thread Alan DeKok
Mats Blomgren B wrote: Today I check the etc/passwd for the usernames and passwords and fetches the users default group from etc/passwd. I'm not so sure... #/usr/local/etc/raddb/users DEFAULT Group == admin-network, Auth-Type = System This checks /etc/groups, via the getgrent() call.

Re: freeradius with ldap

2007-03-26 Thread Martin Gadbois
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 satish patel wrote: I am going to installed freeradius with ldap but my problem is i m confused about ldap and chap i want impement VPDN and users authenticate through ldap so CHAP will work or not how can i configure ldif file for

Re: freeradius 1.1.4 + LDAP + PEAP/mschapv2

2007-02-19 Thread Alan DeKok
Baptiste Delporte wrote: Mon Feb 19 09:30:08 2007 : Error: rlm_mschap: Invalid LM-Password Mon Feb 19 09:30:08 2007 : Error: rlm_mschap: Invalid NT-Password That happens only when an LM-Password and NT-Password are added for the user, AND where they're not the right format. /Authentication

Re: FreeRadius and LDAP

2006-12-03 Thread Alan DeKok
Sundaram Divya-QDIVYA1 wrote: What I need to understand is how to integrate FreeRADIUS with an LDAP Server without exposing the (crypted) password hashes. Any pointers on what I need to do for that? Bind as the LDAP user. PAP will work, nothing else will. Alan DeKok. --

RE : FreeRadius and LDAP

2006-12-01 Thread Thibault Le Meur
-Message d'origine- De : [EMAIL PROTECTED] radius.org [mailto:[EMAIL PROTECTED] sts.freeradius.org] De la part de Sundaram Divya-QDIVYA1 Envoyé : jeudi 30 novembre 2006 23:51 À : freeradius-users@lists.freeradius.org Objet : FreeRadius and LDAP We don't use openldap or

RE: freeradius 802.11x + ldap

2006-04-27 Thread ludovic cailleau
Good morning, I send this email because I don't found my error about freeradius + ldap. I thinhk, I have an error of the userPassword. You can see the output of radiusd -X : Thanks for your help. Faites de Yahoo! votre page d'accueil sur le web pour retrouver directement vos services

Re: Freeradius and LDAP : to be continued

2005-12-16 Thread Christophe Gravier
Phil Mayers wrote: Christophe Gravier wrote: My password are not stored in LDAP in clear text but hashed using SHA algorythm, so this won't work ;-( Ok, let's take a breath. First things first: If your passwords are in SHA (which they are) your Radius server will ONLY be able to

Re: Freeradius and LDAP : to be continued

2005-12-16 Thread Christophe Gravier
Christophe Gravier wrote: Phil Mayers wrote: Christophe Gravier wrote: My password are not stored in LDAP in clear text but hashed using SHA algorythm, so this won't work ;-( Ok, let's take a breath. First things first: If your passwords are in SHA (which they are) your Radius

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Christophe Gravier
Christophe Gravier wrote: Alan DeKok wrote: [EMAIL PROTECTED] wrote: rlm_ldap: Adding userPassword as User-Password, value { op=11 That's better. modcall: group authorize returns ok for request 0 rad_check_password: Found Auth-Type LDAP Yuck. My quick answer is to

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Phil Mayers
Alan DeKok wrote: [EMAIL PROTECTED] wrote: rlm_ldap: Adding userPassword as User-Password, value { op=11 That's better. modcall: group authorize returns ok for request 0 rad_check_password: Found Auth-Type LDAP Yuck. My quick answer is to edit rlm_ldap.c to have it *never* set

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Christophe Gravier
Phil Mayers wrote: Alan DeKok wrote: [EMAIL PROTECTED] wrote: rlm_ldap: Adding userPassword as User-Password, value { op=11 That's better. modcall: group authorize returns ok for request 0 rad_check_password: Found Auth-Type LDAP Yuck. My quick answer is to edit

RE: Freeradius and LDAP : to be continued

2005-12-15 Thread Seferovic Edvin
correct me... Regards, Edvin -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Christophe Gravier Sent: Donnerstag, 15. Dezember 2005 16:05 To: FreeRadius users mailing list Subject: Re: Freeradius and LDAP : to be continued Phil Mayers wrote: Alan DeKok

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Christophe Gravier
To: FreeRadius users mailing list Subject: Re: Freeradius and LDAP : to be continued Phil Mayers wrote: Alan DeKok wrote: [EMAIL PROTECTED] wrote: rlm_ldap: Adding userPassword as User-Password, value { op=11 That's better. modcall: group authorize returns ok

RE: Freeradius and LDAP : to be continued

2005-12-15 Thread Seferovic Edvin
opinion about this on this list ;) Kind regards, Edvin -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Christophe Gravier Sent: Donnerstag, 15. Dezember 2005 16:41 To: FreeRadius users mailing list Subject: Re: Freeradius and LDAP : to be continued Hello

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Damjan
rather confusing. I have to admit, I have never used chillispot, but I've just visited their website and in FAQ I found Why should I use CHAP-Challenge and CHAP-Password? so this makes me think that Chillispot uses CHAP authorization. And when you use CHAP, you do NOT need LDAP as

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Christophe Gravier
;) Kind regards, Edvin -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Christophe Gravier Sent: Donnerstag, 15. Dezember 2005 16:41 To: FreeRadius users mailing list Subject: Re: Freeradius and LDAP : to be continued Hello Edvin, First, I received my

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Frank Bonnet
Hello I have a chillispot that works with OpenLDAP on a Debian box here are the modifications in radiusd.conf I wrote # Lightweight Directory Access Protocol (LDAP) # # This module definition allows you to use LDAP for # authorization and authentication (Auth-Type :=

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Christophe Gravier
Frank Bonnet wrote: Hello I have a chillispot that works with OpenLDAP on a Debian box Strictly the same thing I want to achieve indeed ! ;-) How are your password in your LDAP ? (clear ? hash form ?) Moreover, except this configuration of the ldap remote server, what did you put in

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Phil Mayers
Christophe Gravier wrote: My password are not stored in LDAP in clear text but hashed using SHA algorythm, so this won't work ;-( Ok, let's take a breath. First things first: If your passwords are in SHA (which they are) your Radius server will ONLY be able to answer PAP requests. The

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread christophe.gravier
Christophe Gravier wrote: My password are not stored in LDAP in clear text but hashed using SHA algorythm, so this won't work ;-( Ok, let's take a breath. Yes, I agree, that's why I quit for today ;-) First things first: If your passwords are in SHA (which they are) your Radius server

Re: Freeradius and LDAP : to be continued

2005-12-15 Thread Alan DeKok
Phil Mayers [EMAIL PROTECTED] wrote: Ok, let's take a breath. First things first: ... Could this be a Wiki page? Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius and LDAP : to be continued

2005-12-14 Thread Alan DeKok
Christophe Gravier [EMAIL PROTECTED] wrote: auth: type LDAP Processing the authenticate section of radiusd.conf modcall: entering group Auth-Type for request 0 rlm_ldap: - authenticate rlm_ldap: Attribute User-Password is required for authentication. Cannot use CHAP-Password. You're

Re: Freeradius and LDAP : to be continued

2005-12-14 Thread Christophe Gravier
Alan DeKok wrote: Christophe Gravier [EMAIL PROTECTED] wrote: auth: type LDAP Processing the authenticate section of radiusd.conf modcall: entering group Auth-Type for request 0 rlm_ldap: - authenticate rlm_ldap: Attribute User-Password is required for authentication. Cannot use

Re: Freeradius and LDAP : to be continued

2005-12-14 Thread Alan DeKok
Christophe Gravier [EMAIL PROTECTED]wrote: Removing the ldap entry, radtest no longer works of course. Did you put ldap in the authorize section? That would allow radtest to work, as I said. rlm_ldap: looking for check items in directory... Can you say which LDAP server you're using?

Re: Freeradius and LDAP : to be continued

2005-12-14 Thread christophe.gravier
Christophe Gravier [EMAIL PROTECTED]wrote: Removing the ldap entry, radtest no longer works of course. Did you put ldap in the authorize section? That would allow radtest to work, as I said. Yes, I did like we said: - did put ldap (it was already indeed) in authorize section. - did remove

Re: freeradius 1.0.4 ldap compilation

2005-07-05 Thread Marc-Henri Boisis-delavaud
Le 4 juil. 05 à 17:54, Alan DeKok a écrit : Marc-Henri Boisis-delavaud [EMAIL PROTECTED] wrote: /opt/freeradius/distrib.freeradius-1.0.4/src/modules/rlm_ldap/ rlm_ldap.c:2181: undefined reference to `ldap_unbind_s' Hmm... it looks like your version of OpenLDAP doesn't have the

Re: freeradius 1.0.4 ldap compilation

2005-07-05 Thread Alan DeKok
Marc-Henri Boisis-Delavaud [EMAIL PROTECTED] wrote: And what is the version of openldap recomended by freeradius ? Most versions should work. My guess is that the LDAP libraries are in a non-standard place, where your linker can't find them. Alan DeKok. - List info/subscribe/unsubscribe?

Re: freeradius 1.0.4 ldap compilation

2005-07-04 Thread Alan DeKok
Marc-Henri Boisis-delavaud [EMAIL PROTECTED] wrote: /opt/freeradius/distrib.freeradius-1.0.4/src/modules/rlm_ldap/ rlm_ldap.c:2181: undefined reference to `ldap_unbind_s' Hmm... it looks like your version of OpenLDAP doesn't have the functions needed by FreeRADIUS. Or, the LDAP libraries

Re: freeradius 1.0.4 ldap compilation

2005-07-04 Thread Marc-Henri Boisis-Delavaud
Alan DeKok wrote: Marc-Henri Boisis-delavaud [EMAIL PROTECTED] wrote: /opt/freeradius/distrib.freeradius-1.0.4/src/modules/rlm_ldap/ rlm_ldap.c:2181: undefined reference to `ldap_unbind_s' Hmm... it looks like your version of OpenLDAP doesn't have the functions

Re: freeradius and LDAP-V2

2005-04-21 Thread Vladimir
Frank Bonnet wrote: I am setting up a chillispot server to manage our future WiFi network and I wonder if the schemas given with the lastest freeradius ditribution as it is marqued for LDAP-v3 are OK for LDAP-v2 ? We actually use LDAP v2 ( openldap 2.0.27 ) as centralized auth system and we do

Re: freeradius and LDAP-V2

2005-04-21 Thread Luis Daniel Lucio Quiroz
Le Jeudi 21 Avril 2005 07:53, Frank Bonnet a écrit : Hello I'm new to the list :-) I am setting up a chillispot server to manage our future WiFi network and I wonder if the schemas given with the lastest freeradius ditribution as it is marqued for LDAP-v3 are OK for LDAP-v2 ? We actually

Re: freeradius and LDAP

2005-03-03 Thread Beast
Thomas Simmons wrote: passwords must be encrypted even when sent inside our LAN. I would like to use mschap v2, but it seems that it will not work with LDAP, is this correct? If I cannot use mschap v2, is there another way to encrypt the passwords or use some sort of challenge authentication?

Re: freeradius and LDAP

2005-03-02 Thread Alan DeKok
Thomas Simmons [EMAIL PROTECTED] wrote: When using PAP, the password is sent in clear text. Sent in what protocol? RADIUS does no such thing. The password is sent through the VPN to the firewall, so it's never exposed to the internet but passwords must be encrypted even when sent inside

Re: FreeRadius with LDAP

2005-02-18 Thread Michael Mitchell
dbx is your friend... But check to see that the ldap module actually built... unless you've got things installed in the default places, it can take a little work to get the ldap module to compile on Solaris... José Berenguer wrote: Hello! We are trying to authenticate the last version of

RE: FreeRadius with LDAP

2005-02-18 Thread Sébastien Cantos
PROTECTED] [mailto:[EMAIL PROTECTED] De la part de Michael Mitchell Envoyé : vendredi 18 février 2005 13:30 À : freeradius-users@lists.freeradius.org Objet : Re: FreeRadius with LDAP dbx is your friend... But check to see that the ldap module actually built... unless you've got things

Re: Freeradius and LDAP

2005-02-18 Thread Dustin Doris
On Fri, 18 Feb 2005, E L wrote: I'm new to LDAP and Freeradius. I'm trying to find out if there is a way to configure Freeradius to get information from the LDAP database and assign it to one of the radius atributes(like Framed-IP-Address and Framed-IP-Netmask) for a uids that have any of

Re: Freeradius and LDAP

2005-02-18 Thread Luis Daniel Lucio Quiroz
You may want to read http://www.linuxchange.com/opendocs/howto/authentication/radius/index.es.html however it's on spanish LD - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Freeradius and LDAP

2005-02-18 Thread E L
Thanks Dustin. I'll give a try. Thanks to Luis too, but unfortunately is don't speak Spanish. Cris _ Express yourself instantly with MSN Messenger! Download today it's FREE!

Re: FreeRadius + AD/LDAP + basedn

2004-10-07 Thread Kostas Kalevras
On Thu, 7 Oct 2004, Michael Benton wrote: Hello, FreeRadius 1.0.1 Linux RHES3.1 Does anyone know how to configure the FreeRadius server to to a LDAP query on a Win2003 AD server, and to look at the whole AD tree ? We have for some unknown reason, multiple OU's with users in each, rather

RE: freeradius+poptop+LDAP+Samba

2004-08-27 Thread John H.
Ok Thor, I got a different email address cuz myway stinks. How do I verify my version of ppp, the rpm from poptop's page, has radius plugin? __ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread Thor Spruyt
Because the radiusclient wasn't compiled in. Grrr. -- Regards, Thor Spruyt E: [EMAIL PROTECTED] W: www.thor-spruyt.com M: +32 (0)475 67 22 65 - Original Message - From: John H. To: [EMAIL PROTECTED] Sent: Friday, August 27, 2004 7:45 AM Subject: Re: freeradius+poptop+LDAP+Samba

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread Thor Spruyt
John H. wrote: Ok Thor, I got a different email address cuz myway stinks. Hey nice :) How do I verify my version of ppp, the rpm from poptop's page, has radius plugin? find / -name radiusclient -- Regards, Thor Spruyt E: [EMAIL PROTECTED] W: www.thor-spruyt.com M: +32 (0)475 67 22 65 -

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread John H.
radiusclient dir not found. I don't understand why, though, I used the ppp straight from poptop's website. --- Thor Spruyt [EMAIL PROTECTED] wrote: John H. wrote: Ok Thor, I got a different email address cuz myway stinks. Hey nice :) How do I verify my version of ppp, the rpm from

Re: freeradius+poptop+LDAP+Samba

2004-08-27 Thread John H.
Spruyt E: [EMAIL PROTECTED] W: www.thor-spruyt.com M: +32 (0)475 67 22 65 - Original Message - From: John H. To: [EMAIL PROTECTED] Sent: Friday, August 27, 2004 7:45 AM Subject: Re: freeradius+poptop+LDAP+Samba And can you tell me why I have no radiusclient dir? --- On Fri 08/27

  1   2   >