MAC authorisation (but not authentication) via LDAP

Phil Mayers p.mayers at
Sun Feb 25 14:32:56 CET 2007

Markus Krause wrote:

> i am not sure if your approach could really fullfill my needs (no  
> redundancy, serving different types of "requests") ... but i would  
> really like to know ;-)


Without more details it's difficult to say, but what you need does not 
sound excessively difficult. At most, Autz-Type should suffice. Why are 
you finding you need to set Auth-Type?

The ldap module can be peculiar in this regard - are you authenticating 
the users by doing simple bind, or are you extracting the passwords from 
ldap and using rlm_pap and such?

More information about the Freeradius-Users mailing list