[RadiusNT Digest]

radiusnt-digest-request@iea-software.com
Thu, 13 Aug 1998 00:01:16 -0700

Message 1: Re: MD5/Des Hashing
from Greg Johnson Perry-Spencer <gjohnson@psci.net>

Message 2: Re: MD5/Des Hashing
from Greg Johnson Perry-Spencer <gjohnson@psci.net>

Message 3: Local IP
from David Moore <dmoore@CommunityChoice.net>

Message 4: RE: MaxSessionLength in ServerAccess table
from Mark Colasante <mcola@exchange.netexp.net>

Message 5: Password problem
from "Viktors Judins" <storms@parks.lv>

Message 6: RE: MaxSessionLength in ServerAccess table
from Mike Rabaut <rabaut@hcc.cc.fl.us>

Message 7: Call Online view is not getting updated
from Mark Colasante <mcola@exchange.netexp.net>

Message 8: SNMP
from "Greg Lowthian" <greg@isat.com>

Message 9: Re: Call Online view is not getting updated
from "Dale E. Reed Jr." <daler@iea-software.com>

Message 10: Re: Authentication Problem | PLEASE REPLY ASAP!
from "Allen Mallari" <allen@fiax.net>

Message 11: Re: MaxSessionLength in ServerAccess table
from "Dale E. Reed Jr." <daler@iea-software.com>

Message 12: Re: Authentication Problem | PLEASE REPLY ASAP!
from "James B. Hrdy" <jhrdy@greensoft.com>

Message 13: Re: Password problem
from "Dale E. Reed Jr." <daler@iea-software.com>

Message 14: Re: MD5/Des Hashing
from "Dale E. Reed Jr." <daler@iea-software.com>

Message 15: Invalid type on line 173 of dictionary
from ajandris <ajandris@parks.lv>

Message 16: Re: MD5/Des Hashing
from Greg Johnson Perry-Spencer <gjohnson@psci.net>

Message 17: Re: MD5/Des Hashing
from Greg Johnson Perry-Spencer <gjohnson@psci.net>

Message 18: Re: MD5/Des Hashing
from "Dale E. Reed Jr." <daler@iea-software.com>

Message 19: Re: MD5/Des Hashing
from "Dale E. Reed Jr." <daler@iea-software.com>

Message 20: Re: Invalid type on line 173 of dictionary
from "Dale E. Reed Jr." <daler@iea-software.com>

Message 21: Re: MD5/Des Hashing
from Greg Johnson Perry-Spencer <gjohnson@psci.net>

Message 22: Re: Authentication Problem | PLEASE REPLY ASAP!
from "Allen Mallari" <allen@fiax.net>

Message 23: Re: Authentication Problem | PLEASE REPLY ASAP!
from "Allen Mallari" <allen@fiax.net>

Message 24: Re: Authentication Problem | PLEASE REPLY ASAP!
from "Allen Mallari" <allen@fiax.net>

Message 25: Re: Authentication Problem | PLEASE REPLY ASAP!
from "Allen Mallari" <allen@fiax.net>

Message 26: FW: Password Replace not working on NT
from <ssilver@ideasign.com>

Message 27:
from "Syed Mohammad Talha" <smtalha@global.net.pk>

..------ ------ ------ ------ ------ ------ ------ ------ ------ ------.
| Message 1 |
'------ ------ ------ ------ ------ ------ ------ ------ ------ ------'
Subject: Re: MD5/Des Hashing
From: Greg Johnson Perry-Spencer <gjohnson@psci.net>
Date: Wed, 12 Aug 1998 06:59:54 -0500 (EST)

The FreeBSD passwd file is MD5, this is why I find it strange that the two
encrypted strings don't match. Is my assumption correct that all MD5
encryption strings start with $1$? If so, when I run radius in debug mode
and it displays the encrypted passwd it generates to match against the
password in the Unix password file, why does it not start with $1$?

Thanks,
Greg

On Tue, 11 Aug 1998, Dale E. Reed Jr. wrote:

> Greg Johnson Perry-Spencer wrote:
> >
> > I did this and RadiusNT does look in the passwd file and shows the
> > encrypted passwd string (x15 debug mode), but it also shows the encrypted
> > passwd it generates based upon the passwd I enter. It is encrypted, but
> > much smaller and does not start with $1$.
>
> RadiusNT supports MD5 hases in the passwd file, typically found on
> linux, solaris, and unixware. I am not familiar with DES password
> encryption. Do you have information on the DES routines (and are
> they free)?
>
> --
> Dale E. Reed Jr. (daler@iea-software.com)
> _________________________________________________________________
> IEA Software, Inc. | RadiusNT, Emerald, and NT FAQs
> Internet Solutions for Today | http://www.iea-software.com
>

..------ ------ ------ ------ ------ ------ ------ ------ ------ ------.
| Message 2 |
'------ ------ ------ ------ ------ ------ ------ ------ ------ ------'
Subject: Re: MD5/Des Hashing
From: Greg Johnson Perry-Spencer <gjohnson@psci.net>
Date: Wed, 12 Aug 1998 07:37:58 -0500 (EST)

Here is the output from the Radius debug. I replaced the real password
with ????:

radrecv: Request from host 7f000001 code=1, id=6, length=60
NAS-IP-Address = 127.0.0.1
NAS-Port = 0
User-Name = "johndoe"
Password = "\???\????\???\???\???\???\???\???\???\????\???\????"
Checking user record PW_PASSWORD type
authPapPwd
chkPwd->strvalue is UNIX
decrypted pwd is ?????
(UNIX) User Password: ???? File Password:
$1$????????????????????????????????.
ncrypted Password: $1??????????
Sending Reject of id 6 to 7f000001 (127.0.0.1)

Resp Time: 70 Auth: 0/1 -> 1 Acct: 0/0/0 -> 0

On Tue, 11 Aug 1998, Dale E. Reed Jr. wrote:

> Greg Johnson Perry-Spencer wrote:
> >
> > I did this and RadiusNT does look in the passwd file and shows the
> > encrypted passwd string (x15 debug mode), but it also shows the encrypted
> > passwd it generates based upon the passwd I enter. It is encrypted, but
> > much smaller and does not start with $1$.
>
> RadiusNT supports MD5 hases in the passwd file, typically found on
> linux, solaris, and unixware. I am not familiar with DES password
> encryption. Do you have information on the DES routines (and are
> they free)?
>
> --
> Dale E. Reed Jr. (daler@iea-software.com)
> _________________________________________________________________
> IEA Software, Inc. | RadiusNT, Emerald, and NT FAQs
> Internet Solutions for Today | http://www.iea-software.com
>

..------ ------ ------ ------ ------ ------ ------ ------ ------ ------.
| Message 3 |
'------ ------ ------ ------ ------ ------ ------ ------ ------ ------'
Subject: Local IP
From: David Moore <dmoore@CommunityChoice.net>
Date: Wed, 12 Aug 1998 09:43:54 -0400

I can't get Radius NT to work with the 127.0.0.1 as a localhost IP.
Everything works fine when I put in my actual IP address. Will this cause
problems in other parts of RadiusNT? Radius NT does not seem to be loging
the Authentication and Accounting info. In ODBC mode, is there a setting I
need to make to have this info recorded? Right now the logfile entries in
the administrator are blank. My assumption is that those entries are for
text mode. Is that correct?

Thanks

..------ ------ ------ ------ ------ ------ ------ ------ ------ ------.
| Message 4 |
'------ ------ ------ ------ ------ ------ ------ ------ ------ ------'
Subject: RE: MaxSessionLength in ServerAccess table
From: Mark Colasante <mcola@exchange.netexp.net>
Date: Wed, 12 Aug 1998 11:12:00 -0400

Thanks Dale. I didn't have a stored procedure called RadCheckPort in
the database at all. I created it and all works fine now.

Mark Colasante

-----Original Message-----
From: Dale E. Reed Jr. [mailto:daler@iea-software.com]
Sent: Wednesday, August 12, 1998 2:20 AM
To: mcola@exchange.netexp.net
Subject: Re: MaxSessionLength in ServerAccess table

Mark Colasante wrote:
>
> What value should be in the MaxSessionLength column in the
ServerAccess
> table in order to NOT limit the session lengths. I am using Radius
2.5
> and SQL Server database. Currently, I have this field NULL for all
> servers and it does not allow any access at all. I had them set to 0
> also but got the same denied access.

Do you see the "Access allowed for xx Seconds"? If you do, then RadiusNT
sees a MSL as a positive number. The value can be 0 or NULL. What does
radlogin show for the return attributes for the user?

Also, check your RadCheckPort stored procedure. It should look like
this:

CREATE PROCEDURE RadCheckPort @nasid varchar(16), @nasport integer, @at
varchar(15) AS
Select MaxSessionLength, StartTime, StopTime, CurrTime = (DatePart(Hour,
GetDate()) * 60) + DatePart(Minute, GetDate())