radclient ignores 'Group' attribute

Bill Schoolfield bill at billmax.com
Thu Dec 15 22:36:21 CET 2005


Alan,

I got a little mixed up. I was thinking the sql query would use the 
group attribute along with the username (as though the group mechanism 
supported users with the same name in different groups). I know better now.

What was actually happening (I should have looked at the sql closer) is 
one of the queries (the one for radreply) was failing because I put no 
user specific attributes there. Do I have to supply a dummy (constant) 
attribute per user? Right now, all attributes to be returned appear in 
the radgroupreply table.

Thanks for your quick response.

Bill

Alan DeKok wrote:
> Bill Schoolfield <bill at billmax.com> wrote:
> 
>>Here's our problem; the proxy works fine but the authentication 
>>(actually the user lookup) is failing when testing via radclient. The 
>>user lookup fails because the 'Group' attribute in the referenced 
>>attribute file (-f file) is being ignored (not sent) by radclient.
>>Why is this? Is there a workaround?
> 
> 
>   The "Group" attribute is specific to the internals of FreeRADIUS.
> It *can't* go on the wire.
> 
>   Perhaps you could say what you're trying to do...
> 
>   Alan DeKok.
> 
> - 
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

-- 
Bill Schoolfield
Vice President, BillMax
bill at billmax.com
877.245.5629 (USA toll free)
817.446.7776 (International)



More information about the Freeradius-Users mailing list