How to proxy password from TTLS



Hi,

I have a working configuration of FreeRADIUS configured for EAP-TLS.

I´m trying to add support for EAP-TTLS and I want to proxy the username and password of the inner TTLS session to another Radius-Server.

Client doing TTLS --> FreeRADIUS --> 3rd-Party Backend-Server with database of Users

Forwarding of the packets is working.
The Access-Request that FreeRADIUS sends to the backend-server uses the username entered at the client, but no password at all.
If i add
	User-Password := "validpassword"
to preproxy_users, where "validpassword" is the valid password for the given username on the Backend-Server, everything works.

What do I have to change, to use the password transmitted in the TTLS-Tunnel? Or do I have fundamental errors in my idea of how to do this?

Any help is very welcome.

Greetings,

Wolfgang Burger <burgerw@immunbio.mpg.de>

Max-Planck-Institut fuer Immunbiologie
Scientific Data Processing Unit
(+00 49) 761 / 5108 461
Stuebeweg 51
D-79108 Freiburg
Germany




This archive was generated by a fusion of Pipermail (Mailman edition) and MHonArc.