Authorization via getpwent (users coming via SSSD)

Matthew Newton mcn at freeradius.org
Thu Aug 15 18:40:44 CEST 2019


On Thu, 2019-08-15 at 09:27 -0700, Mike Ely wrote:
> On 8/14/19 12:46 PM, Alan DeKok wrote:
> Thanks for that. Unfortunately it appears that this only works
> against the primary group.
...

> After switching the Group check to "Domain Users"
> (0)       if (Group == "Domain Users") {
> (0)       if (Group == "Domain Users")  -> TRUE
> 
> Is there a known issue surrounding this and if so what if any
> workaround should I be looking for?

It's AD, right?

Just do it properly and use rlm_ldap.

-- 
Matthew




More information about the Freeradius-Users mailing list