Re: [RADIATOR] "IgnoreIfMissing" required?

2019-01-20 Thread Christian Meutes
Hey Hugh, On Sun, Jan 20, 2019 at 2:30 AM Hugh Irvine wrote: > DEFAULT User-Name = /hugh/ > Reply-Message = DEFAULT > > DEFAULT1 User-Name = /christian/ > Reply-Message = DEFAULT1 I'm not able to see how indroducing another 'AuthBy FILE' can help me with my logic, apologies. I

Re: [RADIATOR] "IgnoreIfMissing" required?

2019-01-19 Thread Christian Meutes
Hi Hugh. On Sat, Jan 19, 2019 at 10:52 PM Hugh Irvine wrote: > Well, you can have multiple DEFAULT entries like this: > > > DEFAULT User-Name = /something/ > …… > > DEFAULT User-Name = /whatever/ > ….. > > and so on. > > Does that work for you? the RADMIN 'RADUSERS'-table has an

Re: [RADIATOR] radiator Digest, Vol 116, Issue 12

2019-01-18 Thread Christian Meutes
Hello Alfred, On Fri, Jan 18, 2019 at 5:11 PM Alfred Reibenschuh wrote: > hello you might want oto look at > ContinueUntilAccept thanks for your idea. Unfortunately this would mean (as far as I do understand) that the first 'AuthBy' couldn't reject a user when the check-items fail. Therefore

[RADIATOR] Possibility to rewrite username into unique string (eg. out of request attributes like 'Calling-Station-Id')

2019-01-13 Thread Christian Meutes
Hi, we have some HotSpot (CSCO WLC-based) infrastructure which makes use of a captive portal and uses always the same user in auth- and acct-requests. Is there a way to rewrite the username into some unique string like using request attributes like 'Calling-Station-Id' (client MAC)? Otherwise the

Re: [RADIATOR] Dedicated debug/trace log for specific AuthBys and Handlers

2019-01-12 Thread Christian Meutes
Hi again, On Fri, Jan 11, 2019 at 10:21 PM Hugh Irvine wrote: > >> # define Log clauses for use elsewhere without them being global loggers >> > any idea why RewriteUsername inside Handlers (using dedicated "AuthBy Group" with "Log File" and trace set to 5) isn't logged that way? Thanks! --

Re: [RADIATOR] Dedicated debug/trace log for specific AuthBys and Handlers

2019-01-11 Thread Christian Meutes
Hi Hugh, On Fri, Jan 11, 2019 at 10:21 PM Hugh Irvine wrote: > # define Log clauses for use elsewhere without them being global loggers > > > > > Identifier Something > ….. > > > > Identifier Whatever >

Re: [RADIATOR] connection / protocol failures and policy bevavior (decouple LDAP2 from EAP?)

2019-01-10 Thread Christian Meutes
Hi. On Wed, Jan 9, 2019 at 7:16 PM Alfred Reibenschuh < alfred.reibenschuh_v-tservi...@at.ibm.com> wrote: > The file dependency is from the goodies directory and i have not found a > way to do without. > let's see if the following configuration is the way to go (but looks kind of bloated to me

Re: [RADIATOR] connection / protocol failures and policy bevavior (decouple LDAP2 from EAP?)

2019-01-09 Thread Christian Meutes
Hi, On Wed, Jan 9, 2019 at 1:13 PM Alfred Reibenschuh < alfred.reibenschuh_v-tservi...@at.ibm.com> wrote: > due to the different behaviours of the 802.1x clients we have decupled eap > from ldap like this: > > --- > > AuthByPolicy ContinueWhileAccept > > Filename

Re: [RADIATOR] Radmin behavior

2018-06-18 Thread Christian Meutes
On 18/06/18 13:15, Christian Meutes wrote: I wonder if it's possible to use Radmin also for subsequent checks/replies after EAP-TLS authentication. I created a new AuthSelect statement which differs from the DEFAULT statement only by leaving out the PASS_WORD field. Then I tried

[RADIATOR] Radmin behavior

2018-06-18 Thread Christian Meutes
the SQL statement results in making no checks at all anymore. Any idea about that? Thanks Chris -- Christian Meutes - Duesseldorf, Germany JESK-RIPE - jesk@IRCnet - tel:+49.176.32370305 ___ radiator mailing list radiator@lists.open.com.au http

Re: [RADIATOR] eap-tls with ldap check

2018-06-18 Thread Christian Meutes
Hello Heikki, On 14/06/18 14:12, Heikki Vatiainen wrote: On 13/06/2018 17.46, Christian Meutes wrote: Start with goodies/eap_tls.cfg. This configuration sample uses AuthBy FILE which you need to change to AuthBy LDAP2. You can get started by first enabling NoCheckId in this configuration file

[RADIATOR] eap-tls with ldap check

2018-06-13 Thread Christian Meutes
Thank you very much! Best regards Christian -- Christian Meutes - Wiesbaden, Germany JESK-RIPE - jesk@IRCnet - tel:+49.176.32370305 ___ radiator mailing list radiator@lists.open.com.au http://lists.open.com.au/mailman/listinfo/radiator