On 09/12/2016 01:10, Albert K wrote: > I still cannot get that to work. The radiusd seems to not be able to > evaluate the statement. I can't test it right now, but briefly looking at the source I think LDAP-UserDN is put on the control list, not the request list. Try: &control:LDAP-UserDN