Trouble with group checking against Samba4

Alan DeKok aland at deployingradius.com
Wed Oct 23 01:56:46 CEST 2013


Arthur Ramsey wrote:
>  I'm having trouble getting group membership to work against Samba4
> (Active Directory).  It doesn't appear to be running the search
> (&(objectClass=group)(member=%{control:Ldap-UserDn})).

  Because you told it to ignore the "users" file.

> I've googled and found others with the same issue, but I don't see the
> same configuration mistakes that they had made.
> 
> modules/ldap <http://pastebin.com/Bw5AUn89>
> users <http://pastebin.com/H44gW7uT>

  Which says to do LDAP group checks.

> debug output <http://pastebin.com/YTFDTCy6>

  Which says it's not using the "files" module.

  i.e. it has been removed from raddb/sites-enabled/default.

  Why?

  Alan DeKok.


More information about the Freeradius-Users mailing list