multiple ldap instances, which instance is used for searching?

Arran Cudbard-Bell a.cudbardb at freeradius.org
Wed Jul 3 18:57:16 CEST 2013


On 3 Jul 2013, at 17:47, Phil Mayers <p.mayers at imperial.ac.uk> wrote:

> On 03/07/13 17:34, Martin Kraus wrote:
> 
>> Now my setup stopped working because suddenly ldap-eduroam was checking for
>> groups when matching Ldap-Group. I was under the impression that when not
>> specificed with ldap-eduroam-Ldap-Group the default ldap entry would be used.
> 
> No. Most recently instantiated, which can be essentially random.
> 
> Basically, don't do this; if you have >1 ldap instance, don't use "Ldap-Group", always use "instance-Ldap-Group"

Yeah, that's awful behaviour. I've fixed it for 3.0.0, I guess if people are using it, probably not a good idea to change it for 2.x.x.

Arran Cudbard-Bell <a.cudbardb at freeradius.org>
FreeRADIUS Development Team



More information about the Freeradius-Users mailing list