How to store clients.conf in LDAP?

Alan DeKok aland at deployingradius.com
Wed Feb 2 10:03:28 CET 2011


c0re wrote:
> Is it possible to store device secrets in openldap? If yes, please,
> point me to right direction.

  Not really.

  And I think your configuration doesn't really do what you think it
does.  At the minimum, you should be using Packet-Src-IP-Address instead
of NAS-IP-Address.

  See raddb/sites-available/dynamic-clients for examples of how to
dynamically add clients.  They can likely be read from LDAP with some
customized configuration.

  Alan DeKok.



More information about the Freeradius-Users mailing list