<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML xmlns="http://www.w3.org/TR/REC-html40" xmlns:o =
"urn:schemas-microsoft-com:office:office" xmlns:w =
"urn:schemas-microsoft-com:office:word"><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2900.2627" name=GENERATOR>
<STYLE>@page Section1 {size: 595.3pt 841.9pt; margin: 1.0cm 1.0cm 1.0cm 42.55pt; }
P.MsoNormal {
        FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"
}
LI.MsoNormal {
        FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"
}
DIV.MsoNormal {
        FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"
}
A:link {
        COLOR: blue; TEXT-DECORATION: underline
}
SPAN.MsoHyperlink {
        COLOR: blue; TEXT-DECORATION: underline
}
A:visited {
        COLOR: purple; TEXT-DECORATION: underline
}
SPAN.MsoHyperlinkFollowed {
        COLOR: purple; TEXT-DECORATION: underline
}
SPAN.EmailStyle17 {
        COLOR: windowtext; FONT-FAMILY: Arial; mso-style-type: personal
}
SPAN.EmailStyle18 {
        COLOR: navy; FONT-FAMILY: Arial; mso-style-type: personal
}
SPAN.EmailStyle19 {
        COLOR: navy; FONT-FAMILY: Arial; mso-style-type: personal-reply
}
DIV.Section1 {
        page: Section1
}
</STYLE>
</HEAD>
<BODY lang=HR vLink=purple link=blue bgColor=#ffffff>
<DIV>This seems to be a NavisRadius problem. You should ask on a list for
that software. </DIV>
<DIV>However, this:</DIV>
<DIV><plugin.AuthHttpDigest.checkDigest> FAILURE -- No
check.password<BR></DIV>
<DIV>tells you that the radius server cannot find a password that can be used
with the AuthHttpDigest algorithm. How you set it, I don't know for
NavisRadius.</DIV>
<DIV>g-)</DIV>
<DIV> </DIV>
<DIV>---- Original Message ----<BR>From: davor jovanovic<BR>To:
serusers@lists.iptel.org<BR>Sent: Wednesday, May 11, 2005 02:25 PM<BR>Subject:
[Serusers] SER and NavisRadius not working<BR><BR>> Hi all,<BR>> <BR>>
I’m trying to configure SER 0.8.14 to use authentication with<BR>>
NavisRadius 4.5.0. <BR>> On my X-Lite (X-Lite v2.0 Build 1103m) client I’m
getting “Login<BR>> Failed! Contact Network Admin.” <BR>> <BR>> I’m
getting following message from NavisRadius. Why? => Reply-Message<BR>> =
"No check.password" <BR>> <BR>> I would be very grateful if someone could
look at my ser.cfg and<BR>> output from NavisRadius. <BR>> <BR>> Best
regards<BR>> <BR>>
*****************************************************************************<BR>>
This is what I get on RADIUS server (different from SER machine)<BR>>
<BR>> Client:<BR>> Client-Class = "#default"<BR>>
Nas_Port_Normalization = off<BR>> Radius_Remove_Trailing_Nul = TRUE<BR>>
Radius_Append_Trailing_Nul = FALSE<BR>> Auto_Remove_Check_Items =
TRUE<BR>> Check_Authenticators = TRUE<BR>> Session_Time_From_Time_Of_Day =
FALSE<BR>> Radius_Charset = "UTF8"<BR>> Client-Class = "video"<BR>>
Client-Dictionary = "draft_ietf_radext_digest_auth_01"<BR>> **** dictionary
of radiusclient on SER machine is adjusted to<BR>> dictionary of RADIUS, and
RADIUS can recognize attributes - except if<BR>> I MUST run
sterman_aaa_sip_00 on NavisRadius???? I attached<BR>> dictionary in
radiusclient to this message **** <BR>> Client-Secret =
<hidden><BR>> <BR>> Request:<BR>> User-Name =
"djovanov.srce"<BR>> Digest-Username = "djovanov.srce"<BR>> Digest-Realm =
"srce.hr"<BR>> Digest-Nonce =
"427b5aa983df858da94c50d1f8132a69e3e703ad"<BR>> Digest-URI =
"sip:srce.hr"<BR>> Digest-Method = "REGISTER"<BR>> Digest-Response =
"ca6202fe55c51501295a9bc6ab325420"<BR>> Service-Type = IAPP-Register<BR>>
Anonymous = v0-a208-646A6F76616E6F7669632E73726365<BR>> **** RADIUS doesn’t
recognize code 208, which is Sip-Uri-User ****<BR>> ****Am I missing
Digest-Algorithm? Why SER doesn’t send this<BR>> attribute?**** <BR>>
NAS-IP-Address = 161.53.0.131<BR>> NAS-Port = 5060<BR>> <BR>>
Packet:<BR>> Client-Name = "161.53.0.131"<BR>> Packet-Type =
Access-Request<BR>> Packet-Identifier = 213<BR>> Packet-Length =
197<BR>> Packet-Authenticator = 2B25D6D4934B930EB21F8E1B6AEFFE50<BR>>
Source-Address = 161.53.0.131<BR>> Source-Port = 33159<BR>>
Destination-Address = 0.0.0.0<BR>> Destination-Port = 1812<BR>>
Receipt-Time = "2005/05/06 13:44:32"<BR>> Full-User-Name =
"djovanov.srce"<BR>> Base-User-Name = "djovanov.srce"<BR>>
Normalized-Nas-Port = 5060<BR>> <BR>> <BR>> 19
<engine.worker.0> -> checkDigest[AuthHttpDigest]<BR>> 19
<plugin.AuthHttpDigest.checkDigest> FAILURE -- No check.password<BR>>
20 <engine.worker.0> Variable group trace<BR>> <BR>>
Reply:<BR>> Reply-Message = "No check.password"<BR>> **** this is message
is which I get from NavisRadius ****<BR>> <BR>> <BR>>
****************************************************************************************<BR>>
This is my ser.cfg<BR>> <BR>>
fifo_db_url="mysql://ser:heslo@localhost/ser"<BR>> <BR>> #
------------------ module loading ----------------------------------<BR>>
<BR>> loadmodule "/usr/local/lib/ser/modules/mysql.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/sl.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/tm.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/rr.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/maxfwd.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/usrloc.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/registrar.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/textops.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/auth.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/group.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/uri.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/uri_radius.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/group_radius.so"<BR>> loadmodule
"/usr/local/lib/ser/modules/auth_radius.so"<BR>> <BR>> loadmodule
"/usr/local/lib/ser/modules/msilo.so"<BR>> <BR>> <BR>>
modparam("usrloc", "db_url", "mysql://ser:heslo@localhost/ser")<BR>>
modparam("usrloc", "db_mode", 2)<BR>> modparam("usrloc", "timer_interval",
10)<BR>> <BR>> modparam("rr", "enable_full_lr", 1)<BR>> <BR>>
modparam("auth_radius", "radius_config",<BR>>
"/usr/local/etc/radiusclient-ng/radiusclient.conf") <BR>>
modparam("auth_radius", "service_type", 15)<BR>> modparam("group_radius",
"use_domain", 0)<BR>> <BR>> <BR>> if (uri==myself) {<BR>>
<BR>>
if (method=="REGISTER") {<BR>>
<BR>> # Uncomment this if you
want to use digest
authentication<BR>>
if (!radius_www_authorize(""))
{<BR>>
www_challenge("",
"0");<BR>>
break;<BR>>
};<BR>>
<BR>>
save("location");<BR>>
break;<BR>>
};<BR>>
<BR>>
lookup("aliases");<BR>>
if (!uri==myself)
{<BR>>
append_hf("P-hint: outbound
alias\r\n");<BR>>
route(1);<BR>>
break;<BR>>
};<BR>>
<BR>>
# native SIP destinations are handled using our<BR>> USRLOC DB
<BR>>
if (!lookup("location"))
{<BR>>
sl_send_reply("404", "Not
Found");<BR>>
break;<BR>>
};<BR>> };<BR>> <BR>>
<BR>> <BR>> _______________________________________________<BR>>
Serusers mailing list<BR>> serusers@lists.iptel.org<BR>>
http://lists.iptel.org/mailman/listinfo/serusers</DIV></BODY></HTML>