mschap MS isa error
Alan DeKok
aland at deployingradius.com
Fri May 13 07:27:25 CEST 2011
Doty, Seth wrote:
> I have downloaded and installed the git repo version of what will become
> 2.1.11 on May 10 because of a proxy bug that is fixed in this version.
> In our current testing setup freeradius takes all information from the
> realm and passes in to a MS network policy server for authentication
> into AD. The authentication portion appears to work and we get an
> accept, but we are not getting any of the group information passed from
> the freeradius server to the wireless controller. It appears that
> freeradius is receiving it, just not passing it along.
The debug log shows why this is happening.
The group information is being sent in the Access-Challenge from the
home server. That's wrong. It's not supposed to be there. In
addition, the group information is *not* being sent in the
Access-Accept. It *is* supposed to be there.
Sadly, FR is working correctly. Fix your home server to send the
group information in the Access-Accept, and it will work.
Alan DeKok.
More information about the Freeradius-Users
mailing list