Freeradius 3.0.4 authentication to FreeIPA 4.1.2

Charles Jennings jennings.charles.e at
Tue Feb 10 20:22:24 CET 2015

FreeIPA is just a packaged-up GUI'ed-up frontend to MIT Kerberos, 389 Directory Server, Dogtag CA/RA, and SSSD.  The internals are there - I just can't seem to get it to work....

-----Original Message-----
From: Freeradius-Users [ at] On Behalf Of Brendan Kearney
Sent: Tuesday, February 10, 2015 1:16 PM
To: FreeRadius users mailing list
Subject: Re: Freeradius 3.0.4 authentication to FreeIPA 4.1.2

On Tue, 2015-02-10 at 12:24 -0600, Charles Jennings wrote:
> Environment:
> 	Fedora release 21 (Twenty One) {Linux
> 3.18.5-201.fc21.x86_64 #1 SMP Mon Feb 2 21:00:58 UTC 2015 x86_64 
> x86_64
> x86_64 GNU/Linux}
> 	radiusd: FreeRADIUS Version 3.0.4, for host x86_64-redhat-linux-gnu, 
> built on Jan 19 2015 at 19:42:17
> 	ipa: VERSION: 4.1.2, API_VERSION: 2.109
> I am a freeradius noob.  I figure if I can get to the point where I 
> can do a test with radtest locally, I can get from there.  I cannot 
> find any documentation on the internet that is coherent for me to give 
> me a step-by-step configuration for authenticating radius against 
> FreeIPA.  I would prefer (I think) to use the Kerberos portion of 
> FreeIPA as opposed to the OpenLDAP portion - however, I can go either 
> way.  I just need a nudge in the configuration of freeradius to 
> freeipa.  Any help would be very much appreciated.
> As a side note, I am authenticating successfully against my IPA 
> infrastructure - I just can't seem to find the information I need to 
> tie freeradius to freeipa.
> Thanks.
> -
> List info/subscribe/unsubscribe? See 

its not for FreeIPA, but it does work against Fedora 20, OpenLDAP and MIT Kerberos...
List info/subscribe/unsubscribe? See

More information about the Freeradius-Users mailing list