Deprecated features (was: Any objection to deleting support for"clients"?)
Nicolas Baradakis
nbk at sitadelle.com
Wed Jul 27 20:00:46 CEST 2005
Alan DeKok wrote:
> "Thor Spruyt" <thor.spruyt at telenet.be> wrote:
>
> > Regularly the advice of "only change the defaults if needed" is given.
> > Therfore, I wouldn't just delete this configuration parameter or
> > funtionality, but just change the default, so that users don't use it
> > anymore over time!
>
> I'd say change both. I'd like to update the server core to allow
> more configurable calling of sections. So the "post-proxy-authorize"
> can morph into "when receiving a reply from a home server, use section
> foo, and call the modules authorize function for each module listed in
> that section"
In CVS head we have the stanza 'Post-Proxy-Type' which allows to run
different modules groups when receiving a reply from a home server.
Perhaps I didn't understand what you'd like to do, but I'd prefer not
running modules from authorize section a second time. (and moving all
the modules to the section post-proxy)
> That kind of flexibility also allows you to automagically do
> different things based on packet reply code, in a more flexible way
> that the current "post-auth-type REJECT".
It could be easy to have a "Post-Proxy-Type REJECT", too.
--
Nicolas Baradakis
More information about the Freeradius-Devel
mailing list