Google authenticator : Access-Reject

Alan DeKok aland at deployingradius.com
Tue Apr 24 16:40:07 CEST 2018


On Apr 24, 2018, at 10:23 AM, <servernemesis at tutanota.com> <servernemesis at tutanota.com> wrote:
> 
> My FR server is domain joined, and his krb5 realm is mydomain.com
> I don't know where I could specify the domain for PAM.

  I didn't tell you to specify the domain for PAM.

> I'm not sure what you mean by "If it doesn't know about the domain, then add a realm for "mydomain.com".  Make it LOCAL (see proxy.conf)." 
> Should I edit the /etc/pam.d/radiusd ? What's proxy.conf ?

  You know you're on the FreeRADIUS mailing list, right?  proxy.conf is for FreeRADIUS, not PAM.

  No, don't edit the /etc/pam.d/radiusd file.  If I had meant to edit that file, I would have told you to edit that file.

  Look in the /etc/raddb (or on debian / Ubuntu) /etc/freeradius directory.  The proxy.conf file is there.  Read it.

  Alan DeKok.




More information about the Freeradius-Users mailing list