FreeRadius2 & Krb

John Dennis jdennis at redhat.com
Fri Jun 8 18:56:07 CEST 2012


On 06/08/2012 12:40 PM, Lisa Besko wrote:
> I've seen that on my radius servers before right before it goes into krb
> and get's my token from our kerberos server.
>
> I'm quite sure I've missed something in the config but I'm not finding
> it and the doc's I've found are lacking in the krb area.
>
> Believe me asking for help here is a last resort.

If you're migrating from 1.x to 2.x you're probably using the wrong 
password attribute, it changed from user-password to cleartext-password. 
It's correct in the new 2.x configurations but if you just copied 1.x 
config over to 2.x you probably copied the old attribute name.

FWIW the recommended procedure when migrating from 1.x to 2.x is to 
start with the 2.x vanilla config, put it under source code control so 
you manage changes in the config, then *incrementally* add your site 
local needs using the *2.x* methodology (i.e. virtual servers, unlang, 
etc.) and test every change. If something breaks along the way, don't 
worry, it's all under source code control so just roll the change back 
to a known working point.

-- 
John Dennis <jdennis at redhat.com>

Looking to carve out IT costs?
www.redhat.com/carveoutcosts/


More information about the Freeradius-Users mailing list