<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=utf-8">
<META content="MSHTML 6.00.2900.3395" name=GENERATOR></HEAD>
<BODY style="MARGIN: 4px 4px 1px; FONT: 10pt Tahoma">
<DIV>Great - thanks,</DIV>
<DIV>Absolutely outstanding help thanks! :)</DIV>
<DIV>I hashed from ldap.attrmap as below</DIV>
<DIV>#checkItem LM-Password sambaLmPassword<BR>#checkItem NT-Password sambaNtPassword<BR>And it all worked! :)</DIV>
<DIV>Thanks very much! </DIV>
<DIV>Simon<BR><BR>>>> <tnt@kalik.net> 12/11/2008 13:46 >>><BR>>[ldap] Added the eDirectory password password in check items as<BR>>Cleartext-Password<BR><BR>OK. Here is the clear text password.<BR><BR>>[ldap] No default NMAS login sequence<BR>>[ldap] looking for check items in directory...<BR>>rlm_ldap: acctFlags -> SMB-Account-CTRL-TEXT == "[UX ]"<BR>>rlm_ldap: sambaNtPassword -> NT-Password ==<BR>>0x4145394341303636374133413937333342303139423034323645363933373332<BR>>rlm_ldap: sambaLmPassword -> LM-Password ==<BR>>0x3635423939303044343142344533363831394631304139333344343836384443<BR><BR>So, you don't need these. Remove them and mschap will work. That hash<BR>looks decimal not hex to me. I don't think that they are correct.<BR><BR>Ivan Kalik<BR>Kalik informatika ISP<BR><BR>-<BR>List info/subscribe/unsubscribe? See <A href="http://www.freeradius.org/list/users.html">http://www.freeradius.org/list/users.html</A><BR></DIV><BR>
</BODY></HTML>