Could'nt authenticate windows host account with freeradius + ldap backend + samba domain controller

david.barbion at adeoservices.com david.barbion at adeoservices.com
Tue Dec 18 13:43:24 CET 2007



Alan DeKok a écrit :
> david.barbion at adeoservices.com wrote:
>   
>> In the radiusd.conf config file, the %{Stripped-User-Name} is correctly
>> created from %{User-Name}.
>>     
>
>   That's not the issue.  The issue is that something is editing the
> User-Name attribute.  That editing is breaking EAP.
>
>   
Okay, I understand...
>> I have made some tests with and without the %{User-Name} change, but
>> nothing helps
>>     
>
>   Other people have this working.  It *is* possible.
>
>   
Ok, that's great ! I know it is possible, but I still wonder how (I will 
manage to find the right configuration...)
>> I have another question: How does the EAP/MSCHAPV2 authentication work ?
>> which username/password couples does it take ? and with which database
>> does it compare to ?
>>     
>
>   It doesn't compare anything to a database.  Passwords are obtained
> from whatever database you choose, using whatever queries you choose.
>
>   
Thanks a lot for your clue, I understand now how it works and I will be 
able to find the solution.

>   Alan DeKok.
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
>
>   


Ce message et toutes les pièces jointes sont établis à l'attention exclusive de leurs destinataires et sont confidentiels. Si vous recevez ce message par erreur, merci de le détruire et d'en avertir immédiatement l'expéditeur. L'internet ne permettant pas d'assurer l'intégrité de ce message, le contenu de ce message ne représente en aucun cas un engagement de la part de Adeo Services.



More information about the Freeradius-Users mailing list