multiple radiusVSA in ldap.attrmap

François Mehault Francois.Mehault at
Fri Jun 12 16:41:47 CEST 2009

Thanks Alan Dekok and Ivan Kalik, I will try the two way you sent me in my labo.

-----Message d'origine-----
De : at [ at] De la part de Alan DeKok
Envoyé : vendredi 12 juin 2009 13:28
À : FreeRadius users mailing list
Objet : Re: multiple radiusVSA in ldap.attrmap

François Mehault wrote:
>  + in ldap.attrmap I add
> replyItem       Cisco-AVPair
> radiusVSA
> replyItem       Foundry-Privilege-Level                   radiusVSA
> replyItem       Foundry-INM-Privilege                    radiusVSA

  You can't do that.  You are mapping the "radiusVSA" item to 3
different RADIUS attributes.  This will NOT work.

> I don’t succeed to give good value for each attribute with OpenLDAP,
> ldapattrmap, radiusVSA … In addition, I can’t to have two radiusVSA
> attributes with the same value in OpenLDAP.

  Yes, you can.  Read the comments at the top of ldap.attrmap.  Use the
"+=" operator.

  Alan DeKok.
List info/subscribe/unsubscribe? See

More information about the Freeradius-Users mailing list