local ssh authentication via radius possible?

Alan DeKok aland at deployingradius.com
Mon Nov 26 18:17:33 CET 2007


Dan Gahlinger wrote:
> it doesn't like my config, even with "TCP Clear"-
> 
> testing Cleartext-Password := "callme"
>         Service-Type = Login-User,
>         Login-Service = TCP Clear,
>         Login-IP-Host = testing.mydomain.com

  You have to use the names from the dictionaries.  "TCP clear" is two
words, and is not a name from the dictionaries.

  In any case, the PAM RADIUS module doesn't need "TCP Clear".  If
you're using something else to do RADIUS authentication, see it's
documentation for what it needs.

> this is frustrating.
> and i'm not even sure this is correct for SSH?

  Perhaps the SSH documentation says something?

  You've been very careful to not show the output of debugging mode,
either on the server or on the client (if it has one).  You've also been
careful to hide which RADIUS client you're using.

  This makes it difficult to help you.  You're saying "Hi, I'm using
stuff to login, but it doesn't work.  Help me!"  Those kind of questions
are content-free, and actively prevent anyone from helping you.

  Alan DeKok.



More information about the Freeradius-Users mailing list