Reply-Items in Ldap-Group

Giovanni Lovato giovanni.lovato at aldu.net
Sun Mar 2 00:44:56 CET 2008


Ivan Kalik wrote:
> Yes.
> 
> DEFAULT   Ldap-Group == whatever
>                  reply,
>                  reply

Thanks, but I meant if I could store that reply-items directly in LDAP
attributes. It works for users, for example:

dn: uid=testuser,dc=example,dc=org
uid: testuser
...
objectClass: radiusProfile
radiusFramedIPAddress: 192.0.2.1

When 'testuser' authenticates, FreeRADIUS correctly replies with
Framed-IP-Address to the NAS. I wish to store some reply-items on a group:

dn: cn=testgroup,dc=example,dc=org
cn: testgroup
member: testuser1
member: testuser2
member: testuser3
...
radiusReplyItem: Mikrotik-Rate-Limit := "128k"

so that all members of 'testgroup' gets that reply-item!
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3436 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20080302/3952d8ef/attachment.bin>


More information about the Freeradius-Users mailing list