Configuring LDAP for query ONLY...

Eric Martell workoutexcite at yahoo.com
Mon Dec 17 16:27:28 CET 2007


Hi Phil,
   Please let me know if you need more info. I am
still
stuck with the problem.

Thanks and Regards,
Eric.

--- Phil Mayers <p.mayers at imperial.ac.uk> wrote:

> > 
> > rlm_ldap: user test1 authorized to use remote
> access
> > rlm_ldap: ldap_release_conn: Release Id: 0
> >   modcall[authorize]: module "ldap" returns ok for
> > request 0
> > rlm_pap: WARNING! No "known good" password found
> for
> > the user.  Authentication may fail because of
> this.
> 
> That's the problem.
> 
> Your LDAP module should be copying the LDAP
> attribute containing the 
> password to the relevant check item.
> 
> Slightly confusing, there are two ways to do this:
> 
>   1. ldap.attrmap
>   2. password_attribute & password_header config
> items of ldap module
> 
> What are those setup to do?
> 
> A full "-X" debug would help at this point.
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
> 



      ____________________________________________________________________________________
Be a better friend, newshound, and 
know-it-all with Yahoo! Mobile.  Try it now.  http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ 




More information about the Freeradius-Users mailing list