Multi-valued LDAP attribute configuration

Michael Ströder michael at stroeder.com
Tue Sep 12 16:00:27 CEST 2017


Srinivasa R wrote:
> I mean, I am storing 3 different macaddresses (like laptop,
> tab, & phone) in a single LDAP attribute (multiple value). I
> want Freerdaius to check all these 3 values from the LDAP
> before it send "Access-Accept" or "Access-Reject" message.

Instead of comparing client's MAC address with all 3 attribute 
values you could probably simply search the entry with the 
client's MAC address used in the LDAP search filter and reject in 
case there was no LDAP search result.

Also LDAP implements compare requests.

Ciao, Michael.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3829 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20170912/4a9f97e5/attachment-0001.bin>


More information about the Freeradius-Users mailing list