Freeradius with EAP/MSChap and Windows 2012

Carsten Czerner carsten.czerner at leuphana.de
Wed Jan 22 06:36:25 CET 2014


Hi,

thank you so much for your help! :)

System Debian7

nano /etc/group

winbindd_priv:x:106:freerad

just added the freerad user to the winbindd-priv group. Thats it!

Regards
Carsten



Am 21.01.2014 19:44, schrieb Mathieu Simon (Lists):
> Hi
> Am 21.01.2014 19:11, schrieb David Aldwinckle:
>> The radiusd process can¹t read the response from winbind.
>>
>> http://wiki.freeradius.org/guide/FreeRADIUS-Active-Directory-Integration-HO
>> WTO
>>
>> [...]
>>
>> setfacl -m u:radiusd:rx winbindd_privileged
>>
>> Or something similar. See
>> http://www.suse.de/~agruen/acl/linux-acls/online/ or man setfacl for more
>> information on POSIX ACLs!"
> I remember being in that situation on my first setup with FreeRADIUS.
> Actually is there something wrong (on Debian and alikes) to simply add
> the user freerad to the winbindd_privileged group or is there a security
> risk I don't realize in contrast to setfacl?
>
> -- Mat
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html



-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5180 bytes
Desc: S/MIME Kryptografische Unterschrift
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20140122/f5200362/attachment.bin>


More information about the Freeradius-Users mailing list