[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freeradius-users
Subject:    Re: Unable to answer requests from an IAS proxy
From:       Guy Fraser <guy () incentre ! net>
Date:       2003-12-29 16:38:45
[Download RAW message or body]

It sounds like a mismatched secret.

Run radiusd with '-x' and send the offending information, for more 
assitance.

PS Send you messages in Text not HTML. :)

Jeff Vail wrote:

> I have a Cisco AS5300 talking to an MS IAS server which proxies 
> certain requests to a FreeRADIUS server.  These requests are rejected 
> by the FreeRADIUS server because of a bad password, but the password 
> was entered correctly by the end user.  The log seems to indicate that 
> the FreeRADIUS server doesn't understand the encryption used to 
> transmit the password, since debugging data shows a gibberish string 
> instead of the actual password, which it shows during successful 
> authentication attempts made directly from the NAS to the FreeRADIUS 
> server.  The FreeRADIUS server is version 0.9.3, the machine is 
> running Solaris 7, patches are reasonably up to date, and as I 
> indicated earlier, authenticating directly to the FreeRADIUS server 
> works correctly.  I am doing pass through authentication to the 
> system.  The client, the NAS and the IAS proxy are all configured for 
> PAP only, no CHAP or EAP or any of that.
>
> Any assistance in getting the proxy to communicate with my FreeRADIUS 
> server would be appreciated.  There appear to be a number of 
> references on the mail list archives to getting a FreeRADIUS proxy to 
> talk to an IAS server, but I couldn't find anything going the other 
> direction.
>
> Thanks,
>
> Jeff Vail
>
>
> This message is a private communication. It may contain information 
> that is confidential and legally protected from disclosure. If you are 
> not an intended recipient, please do not read, copy or use this 
> message or any attachments, and do not disclose them to others.
>
> Please notify the sender of the delivery error by replying to this 
> message, and then delete it and any attachments from your system. 
> Thank you.
>
> Solucient LLC.
>


- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic