Configuring LDAP for query ONLY...

Eric Martell workoutexcite at yahoo.com
Wed Dec 12 17:05:39 CET 2007


Hi Phil, Yes I did.. Here is the config.
modules {
        ldap {

               ....
                set_auth_type = no
        }
}



authorize {
	preprocess
	ldap
	pap
}

authenticate {
        #
        #  PAP authentication, when a back-end
database listed
        #  in the 'authorize' section supplies a
password.  The
        #  password can be clear-text, or encrypted.
        Auth-Type PAP {
                pap
        }
}


I commented out everything from the users file as I am
not using Local or System Auth-Type. I think I am
might be missing something in the users file. Please
advice.

I get the following error.



rlm_ldap: user test1 authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
  modcall[authorize]: module "ldap" returns ok for
request 0
rlm_pap: WARNING! No "known good" password found for
the user.  Authentication may fail because of this.
  modcall[authorize]: module "pap" returns noop for
request 0
modcall: leaving group authorize (returns ok) for
request 0
auth: No authenticate method (Auth-Type) configuration
found for the request: Rejecting the user
auth: Failed to validate the user.






--- Phil Mayers <p.mayers at imperial.ac.uk> wrote:

> Eric Martell wrote:
> > Hi Phil,
> >   I installed the latest freeradius-1.1.7. I put
> the
> > line 
> >>>      set_auth_type = no in ldap module
> > to ignore the authentication. But for some reason
> I
> > get the following error in the log. 
> > 
> > rlm_ldap: user test1 authorized to use remote
> access
> > rlm_ldap: ldap_release_conn: Release Id: 0
> >   modcall[authorize]: module "ldap" returns ok for
> > request 0
> > modcall: leaving group authorize (returns ok) for
> > request 0
> > auth: No authenticate method (Auth-Type)
> configuration
> > found for the request: Rejecting the user
> > auth: Failed to validate the user.
> 
> Did you add the "pap" module to the bottom of the
> "authorize" section as 
> per my example?
> 
> 
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
> 



      ____________________________________________________________________________________
Be a better friend, newshound, and 
know-it-all with Yahoo! Mobile.  Try it now.  http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ 




More information about the Freeradius-Users mailing list