Preserve ldap attributes after proxy

Alan DeKok aland at deployingradius.com
Sun Nov 9 14:33:49 CET 2014


Tamás Becz wrote:
> Yes I got that, but the NAS (which is mainly a VPN concentrator) actually
> uses the value for assigning firewall rules to the user's session which is
> precisely what Filter-Id is for if I understand the rfc correctly.

  OK... you didn't say that originally.  Knowing that helps.

> Currently I can't test, but do I understand correctly that rlm_ldap can't
> put things on the control list, but I could use unlang to copy the
> attributes from reply to control in authorize after ldap, then copy them
> back in post-auth?

  Yes.

  Alan DeKok.


More information about the Freeradius-Users mailing list