Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 14 Jan 2000 17:28:14 +0100 (MET)
From:      Marcin Cieslak <saper@system.pl>
To:        freebsd-net@FreeBSD.org
Subject:   RADIUS support in ppp(8)
Message-ID:  <Pine.GSO.4.20.0001141716100.18372-100000@tricord.system.pl>

next in thread | raw e-mail | index | archive | help

I have just enabled radius support in my plain old
FreeBSD 2.2.8-based dial-in server (I managed to compile
new ppp with libradius, skipping libalias and other
unnecessary things to me). 

I see that I cannot use CHAP for authentication.
I browsed the source code, and it is unclear to me,
is it my fault that I don't supply "Challenge-Response"
(as Ascend radiusd calls it) attribute - or is it
not supported yet? Who is supposed to supply challenge 
(RADIUS server)?

Second thing, is anyone working on accounting support
for RADIUS? Seems to me that some basic attributes
would be faily easy to implement. Then we
would work to add more fancy "Ascend-*" attributes,
which can be easily supported by current ppp
(like Ascend-Input-Packets, Ascend-Output-Packets,
Ascend-Multilink-ID etc.), or dig something out
from a modem chat (like Ascend-Data-Rate).

Right now I need Framed-Address and NAS-Port badly 
and I am going to hack ppp to get it. 

Last, is it possible to limit user sessions authenticad?
Say to allow given user to login only once or given
number of simultaneous connections. I cannot find
a RADIUS attribute for that, but it would be nicely
controlled from there.

-- 
                 << Marcin Cieslak // saper@system.pl >>

-----------------------------------------------------------------
SYSTEM Internet Provider                     http://www.system.pl



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-net" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.GSO.4.20.0001141716100.18372-100000>