Conditional expression ":-" deprecated?

freeradius at corwyn.net freeradius at corwyn.net
Sun Jan 24 19:04:42 CET 2010


At 06:45 AM 1/24/2010, Alan Buxey wrote:
>(&(sAMAccountname=%{%{Stripped-User-Name}:-%{User-Name}})(objectClass=person))

thanks

>there have been a few places where these things have been fixed in the default
>configurations so remove those errors.....though its suprising how many
>people still run their servers with that error message being flagged...surely
>you read it and think 'WARNING? must check that out and fix it' ?

Sure do!, and posted the question :-)  this is from a recent 2.17 
install using the associated docs on the freeradius pages. . .

It's the same reason I keep asking about this error:

[ldap] looking for reply items in directory...
WARNING: No "known good" password was found in LDAP.  Are you sure 
that the user is configured correctly?
[ldap] user rsteeves authorized to use remote access


>..and , in fact, the latest version has that default value fixed. go grab the
>2.1.8 source code and check raddb/modules/ldap file...

Thx, will do. One question about that file. Example:

         #  seconds LDAP server has to process the query (server-side
         #  time limit). default: 20
         #
         #  LDAP_OPT_TIMELIMIT is set to this value.
         timelimit = 3


Why does it say the default is 20, and yet actually have the default 
value set to 3?

Rick









More information about the Freeradius-Users mailing list