Google LDAP integration failure
Phil Grace
phil.grace at hssd.k12.ar.us
Sat Feb 23 23:50:45 CET 2019
Its not mentioned in the guide at all, so I didn’t do anything with ms-chap as far as that goes. So I guess the clients by default are trying to use MS-CHAP. Testing client is Mac OS and I just leave it on automatic.
> On Feb 23, 2019, at 4:46 PM, Alan DeKok <aland at deployingradius.com> wrote:
>
> On Feb 23, 2019, at 5:04 PM, Phil Grace <phil.grace at hssd.k12.ar.us> wrote:
>> I’m not sure, I just followed google’s provided setup guide for freeradius to work with their LDAP service.
>
> So they say it will work with MS-CHAP?
>
>> So would I just disable MS-CHAP or do something different with LDAP config to get the “known good”password. Would my issue probably be in the inner-tunnel file or the default file?
>
> You can't really disable MS-CHAP. It's chosen by the users system, and sent to FreeRADIUS.
>
> If you disable MS-CHAP on the server, all that happens is the user gets rejected when they try to use MS-CHAP.
>
> Alan DeKok.
>
>
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
More information about the Freeradius-Users
mailing list