Add LDAP groups as extra attributes

Robin Helgelin lobbin at gmail.com
Thu Mar 14 18:39:01 CET 2013


On 14 mar 2013, at 11:06, Phil Mayers <p.mayers at imperial.ac.uk> wrote:

> On 03/13/2013 07:45 PM, Robin Helgelin wrote:
> 
>> First problem is that I need to rewrite the output from ldap to
>> something the radius-client finds useful. But there are radius modules
>> for rewriting things right?
> 
> Yes, though TBH manipulating LDAP DNs in unlang/attr_rewrite is going to be a pain. You might have to fall back on one of the scripting language modules, as Arran says.

Yes, I ended up writing a small python script, works very nicely :)

The only thing missing is if it's possible for the ldap module to set an attribute with the users full dn to be available for the python module. 

Regards,
Robin


More information about the Freeradius-Users mailing list