<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
{font-family:"Matura MT Script Capitals";
panose-1:3 2 8 2 6 6 2 7 2 2;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
{font-family:"OCR A Extended";
panose-1:2 1 5 9 2 1 2 1 3 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
{mso-style-priority:99;
mso-style-link:"Plain Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.5pt;
font-family:Consolas;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-priority:99;
mso-style-link:"Balloon Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:8.0pt;
font-family:"Tahoma","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
span.PlainTextChar
{mso-style-name:"Plain Text Char";
mso-style-priority:99;
mso-style-link:"Plain Text";
font-family:Consolas;}
span.EmailStyle20
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.EmailStyle21
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle22
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.BalloonTextChar
{mso-style-name:"Balloon Text Char";
mso-style-priority:99;
mso-style-link:"Balloon Text";
font-family:"Tahoma","sans-serif";}
span.EmailStyle25
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:58097312;
mso-list-type:hybrid;
mso-list-template-ids:304275110 517270526 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
{mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:.75in;
text-indent:-.25in;}
@list l0:level2
{mso-level-tab-stop:1.0in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level3
{mso-level-tab-stop:1.5in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level4
{mso-level-tab-stop:2.0in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level5
{mso-level-tab-stop:2.5in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level6
{mso-level-tab-stop:3.0in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level7
{mso-level-tab-stop:3.5in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level8
{mso-level-tab-stop:4.0in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level9
{mso-level-tab-stop:4.5in;
mso-level-number-position:left;
text-indent:-.25in;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">> </span><span style="color:#1F497D">Because that is what is installed when you do ‘yum –y install freeradius’ on the CentOS 5.x PBX-in-a-Flash (PiaF) platform.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">That is a fair statement, however I will say the installing FR from source is the easiest source installation I have ever done. And as for staying up to date, a two line script can pull the latest source and
build the new version, and if you’re really crazy a third line can restart the service with your new binary.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Sorry, didn’t mean to hijack your thread.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:28.0pt;font-family:"Matura MT Script Capitals";color:#1F497D">Jake Sallee<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Courier New";color:#1F497D">Godfather of Bandwidth<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Courier New";color:#1F497D">System Engineer<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">University of Mary Hardin-Baylor<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">900 College St.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">Belton, Texas<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">76513<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">Fone: 254-295-4658<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">Phax: 254-295-4221<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> freeradius-users-bounces+jake.sallee=umhb.edu@lists.freeradius.org [mailto:freeradius-users-bounces+jake.sallee=umhb.edu@lists.freeradius.org]
<b>On Behalf Of </b>d.tom.schmitt@L-3com.com<br>
<b>Sent:</b> Monday, August 01, 2011 4:45 PM<br>
<b>To:</b> FreeRadius users mailing list<br>
<b>Subject:</b> RE: Security issues with 1.1.3 flatfile<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Because that is what is installed when you do ‘yum –y install freeradius’ on the CentOS 5.x PBX-in-a-Flash (PiaF) platform.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Otherwise, you have to explain to everyone how to manually install 2.1.7.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Does the problem not exist in 2.1.7?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Also, that was the How-To for MySQL that I was able to find.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Do you have a newer link to a How-To?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">What is the latest release of freeRADIUS that I should try to use and is it already configured to run MySQL?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">Thanks,<o:p></o:p></span></i></b></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D"><o:p> </o:p></span></i></b></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">Tom Schmitt<o:p></o:p></span></i></b></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">Senior IT Staff - R&D</span></i><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">L-3 Communication Systems West<o:p></o:p></span></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">640 North 2200 West<o:p></o:p></span></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">P.O. Box 16850<o:p></o:p></span></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">Salt Lake City, UT 84116<o:p></o:p></span></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">Phone (801)
<i>594-3030</i><o:p></o:p></span></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><span style="font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D">Cell (801) 231-7230<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> freeradius-users-bounces+d.tom.schmitt=l-3com.com@lists.freeradius.org [mailto:freeradius-users-bounces+d.tom.schmitt=l-3com.com@lists.freeradius.org]
<b>On Behalf Of </b>Sallee, Stephen (Jake)<br>
<b>Sent:</b> Monday, August 01, 2011 3:16 PM<br>
<b>To:</b> FreeRadius users mailing list<br>
<b>Subject:</b> RE: Security issues with 1.1.3 flatfile<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoPlainText">> So my questions are:<o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">There REALLY needs to be a good reason that you are running any 1.X version or else your question should be, Why haven’t I upgraded to the latest and most secure FreeRADIUS release.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:28.0pt;font-family:"Matura MT Script Capitals";color:#1F497D">Jake Sallee<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Courier New";color:#1F497D">Godfather of Bandwidth<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Courier New";color:#1F497D">System Engineer<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">University of Mary Hardin-Baylor<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">900 College St.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">Belton, Texas<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">76513<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">Fone: 254-295-4658<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D">Phax: 254-295-4221<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> freeradius-users-bounces+jake.sallee=umhb.edu@lists.freeradius.org [mailto:freeradius-users-bounces+jake.sallee=umhb.edu@lists.freeradius.org]
<b>On Behalf Of </b>d.tom.schmitt@L-3com.com<br>
<b>Sent:</b> Monday, August 01, 2011 4:09 PM<br>
<b>To:</b> freeradius-users@lists.freeradius.org<br>
<b>Subject:</b> Security issues with 1.1.3 flatfile<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoPlainText">Currently running 1.1.3 on CentOS 5.x.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">I am currently using the flat file option and it works just fine as long as the permissions on the file are:<o:p></o:p></p>
<p class="MsoPlainText"> 664 RW-RW-R—<o:p></o:p></p>
<p class="MsoPlainText"> Record in the file looks like:<o:p></o:p></p>
<p class="MsoPlainText"> Tom <tab> Auth-Type := Local, User-Password := “tompass”<o:p></o:p></p>
<p class="MsoPlainText">This allows everyone to read the file – not good security.<o:p></o:p></p>
<p class="MsoPlainText">If I change the permissions to 660 RW-RW---- then freeRADIUS will not restart.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">I started setting up freeRADIUS to use MySQL DB for access but I must have something setup incorrectly.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">I tried to follow the How-To but still must be missing something in the setup.<o:p></o:p></p>
<p class="MsoPlainText">I have inserted a record into DB=radius and TALBE=radcheck where:<o:p></o:p></p>
<p class="MsoPlainText"> Id = selected by the MySQL as the next index number<o:p></o:p></p>
<p class="MsoPlainText"> UserName = tom<o:p></o:p></p>
<p class="MsoPlainText"> Attribute = ‘Cleartext-Password’ <o:p></o:p></p>
<p class="MsoPlainText"> Op = ‘:=’<o:p></o:p></p>
<p class="MsoPlainText"> Value = tompass is the password<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">So my questions are:<o:p></o:p></p>
<p class="MsoPlainText" style="margin-left:.75in;text-indent:-.25in;mso-list:l0 level1 lfo2">
<![if !supportLists]><span style="mso-list:Ignore">1.<span style="font:7.0pt "Times New Roman"">
</span></span><![endif]> Is there a way to just secure the flatfile permissions?<o:p></o:p></p>
<p class="MsoPlainText" style="margin-left:.75in;text-indent:-.25in;mso-list:l0 level1 lfo2">
<![if !supportLists]><span style="mso-list:Ignore">2.<span style="font:7.0pt "Times New Roman"">
</span></span><![endif]> Is there a complete How-To for using MySQL with freeRADIUS?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif"">Thanks,<o:p></o:p></span></i></b></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif""><o:p> </o:p></span></i></b></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif"">Tom Schmitt<o:p></o:p></span></i></b></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif"">Senior IT Staff - R&D</span></i><span style="font-size:8.0pt;font-family:"Arial","sans-serif""><o:p></o:p></span></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><span style="font-size:8.0pt;font-family:"Arial","sans-serif"">L-3 Communication Systems West<o:p></o:p></span></p>
<p class="MsoNormal" style="text-indent:.5in;text-autospace:none"><span style="font-size:8.0pt;font-family:"Arial","sans-serif"">Phone (801)
<i>594-3030</i><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.25in;text-indent:.25in;text-autospace:none">
<b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif""> </span>
</i></b><b><span style="font-size:8.0pt;font-family:"OCR A Extended"">\\\\||////</span></b><b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif""><o:p></o:p></span></i></b></p>
<p class="MsoNormal" style="margin-left:.25in;text-indent:.25in;text-autospace:none">
<b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif"">
</span></i></b><b><span style="font-size:8.0pt;font-family:"OCR A Extended"">\ ~ ~ /
</span></b><b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif""><o:p></o:p></span></i></b></p>
<p class="MsoNormal" style="margin-left:.25in;text-indent:.25in;text-autospace:none">
<b><i><span style="font-size:8.0pt;font-family:"Arial","sans-serif""> </span></i></b><b><span style="font-size:8.0pt;font-family:"OCR A Extended"">| @ @ |<o:p></o:p></span></b></p>
<p class="MsoNormal" style="margin-left:.25in;text-indent:.25in;text-autospace:none">
<b><span style="font-size:8.0pt;font-family:"OCR A Extended"">--oOo---(_)---oOo--<o:p></o:p></span></b></p>
<p class="MsoNormal" style="margin-left:.25in;text-indent:.25in;text-autospace:none">
<b><span style="font-size:8.0pt;font-family:"OCR A Extended"">Have A Nice Day !<o:p></o:p></span></b></p>
</div>
</body>
</html>