Google authenticator : Access-Reject

Alan DeKok aland at
Tue Apr 24 16:40:07 CEST 2018

On Apr 24, 2018, at 10:23 AM, <servernemesis at> <servernemesis at> wrote:
> My FR server is domain joined, and his krb5 realm is
> I don't know where I could specify the domain for PAM.

  I didn't tell you to specify the domain for PAM.

> I'm not sure what you mean by "If it doesn't know about the domain, then add a realm for "".  Make it LOCAL (see proxy.conf)." 
> Should I edit the /etc/pam.d/radiusd ? What's proxy.conf ?

  You know you're on the FreeRADIUS mailing list, right?  proxy.conf is for FreeRADIUS, not PAM.

  No, don't edit the /etc/pam.d/radiusd file.  If I had meant to edit that file, I would have told you to edit that file.

  Look in the /etc/raddb (or on debian / Ubuntu) /etc/freeradius directory.  The proxy.conf file is there.  Read it.

  Alan DeKok.

More information about the Freeradius-Users mailing list