Re : EAP-TLS OK - EAP-PEAP KO!! why that?



true!
there was a great problem with winbindwhich did'n want to run. I had to rename winbindd_priviledged to make it work.

so now, the previous error:
---------------------------------------------------
rlm_mschap: No Cleartext-Password configured.  Cannot create LM-Password.
  rlm_mschap: No Cleartext-Password configured.  Cannot create NT-Password.
  rlm_mschap: Told to do MS-CHAPv2 for glouglou with NT-Password
        expand: --username=%{mschap:User-Name} -> --username=glouglou
 mschap2: 8e
        expand: --challenge=%{mschap:Challenge:-00} -> --challenge=a41b12342f73ab07
        expand: --nt-response=%{mschap:NT-Response:-00} -> --nt-response=0a26a29835e2bceea879a42b1fcc7993228f9789da5c6087
Exec-Program output: winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/lib/samba/winbindd_privileged are set correctly. (0xc0000022)
Exec-Program-Wait: plaintext: winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/lib/samba/winbindd_privileged are set correctly. (0xc0000022)
Exec-Program: returned: 1
  rlm_mschap: External script failed.
  rlm_mschap: FAILED: MS-CHAP2-Response is incorrect
++[mschap] returns reject
  rlm_eap: Freeing handler
++[eap] returns reject
auth: Failed to validate the user.
----------------------------------------------------------------------------------------------------------------

could you tell me what autorisation winbindd_priviledge directory should have, please.

thank a lot foryour for help.




Envoyé avec Yahoo! Mail.
Une boite mail plus intelligente.

This archive was generated by a fusion of Pipermail (Mailman edition) and MHonArc.