[authorized_macs.authorize] returns noop
a.cudbardb at googlemail.com
Fri Jan 7 00:25:08 CET 2011
On Jan 6, 2011, at 6:17 AM, Phil Mayers wrote:
> On 06/01/11 12:48, Nagaraj Panyam wrote:
>> Dear experts,
>> I setup mac_auth as in the freeradius wiki and its not working, am
>> unable to debug further.
> Hmm. This:
> ...seems like it's a bit... over-engineered? if () unlang statements in the "authenticate" section and calling a module .authorize method in post-auth don't seem necessary?
> Anyone who wrote the page, and why it uses that method?
Because the server does things in the wrong order. The default configuration is very inefficient when processing complex policies for authorisation and multi-round authentication. Although this isn't multi-round authentication it does give an example of how a request *should* pass through the server.
That said it probably is over engineered for novice users- feel free to create an alternate config.
More information about the Freeradius-Users