using external script in virtual server config

Alan DeKok aland at deployingradius.com
Tue Jan 27 01:51:46 CET 2015


On Jan 26, 2015, at 6:40 PM, the2nd at otpme.org wrote:
> that was not my intention. i just wanted to be precise….

  It’s rude.  Repeating something over and over is suggesting that the reader is an idiot who can’t remember anything.

> i tried to follow your instructions but it does not work. this may be my fault but i dont know whats wrong with my configuration.

  There is documentation.  You’ve already shown you’re not reading it...

> you said i should add something like this to my config:
> 
>                        update request {
>                                Tmp-Octets-0 := "%{mschap:Challenge}"
>                                Tmp-Octets-1 := "%{mschap:NT-Response}"
>                        }
> 
> so i've added this to the authenticate section. then the attribute is accessible from within rlm_python but it contains just "0x”.

   Well...

> after re-reading sites-available/default i tried to add mschap to the authorize section. now authData looks like this:

  I don’t care about “authData”.

  You’re asking *me* to figure out what some magical format you invented.  At the same time, you’re refusing to give information in the *standard* FreeRADIUS format.

  That’s annoying and rude.

  The server has a debug output for a reason.  If you refuse to use it, then stop posting questions here.

> so there is some data in Tmp-Octets-0 and Tmp-Octets-1 now. but this values are longer than whats normally in %{mschap:Challenge} and %{mschap:NT-Response}.

  It’s easy to figure out what the problem is.

> the challenge i get from mschap module when called as an ntlm_auth replacement is 16 character long. and the response is 48 chars long.
> 
> thanks a lot for any hint in the right direction….

  I’ve given you hints.  I’ve given you direct instructions.  So far that hasn’t helped much.

  Alan DeKok.



More information about the Freeradius-Users mailing list