How I do to User/Machine Certificate + LDAP User/Pass Authentication?

Alan DeKok aland at
Sun Nov 22 14:55:39 CET 2020

On Nov 20, 2020, at 12:31 PM, Jose Ramón Arnau Garví via Freeradius-Users <freeradius-users at> wrote:
> The ide is some similar to 2fa:
>  *   First I authenticate with User/Machine Certificate
>  *   Next I want to Introduce User/Pass to Authenticate with ldap througt Active Directory
> Can Anyone help me
> Notes:
>  *   I can authenticate with User/Machine Certificate
>  *   I can authenticate with User/pass with ldapt througt Active Directory
> I can't authenticate with 2 simultaneously

  I'm not sure what you mean by "simultaneously". 

 Can you do both of those authentications in the same virtual server?  Yes.  Read the debug output to see how they're different, and then key off of those differences.

 Can you make the user do machine certificate *and* password authentication in the same authentication session?  No, because that's up to the client.  And Windows doesn't do that.

  Alan DeKok.

More information about the Freeradius-Users mailing list