Quick question regarding FR auth against MS AD

Matthew Newton mcn at freeradius.org
Fri Apr 23 12:29:46 CEST 2021



On 23/04/2021 11:20, Alan DeKok wrote:
> On Apr 23, 2021, at 2:18 AM, <275972560 at qq.com> <275972560 at qq.com> wrote:
>> I want to say that was my expecting answer, but per talking with my colleague, he said that the mschap challenge auth can be somehow proxy or transfer from supplicant to MS AD by radius, just the like the trick of ldap bind auth itself, this is what I'm curious about, is this even operational?
> 
>    If he knows the answer already, why are you asking me?  Go ask him how he does it.

Sounds like he's probably running a Microsoft RADIUS server in Windows, 
and proxying over to that to do the auth.

Which isn't FreeRADIUS authenticating against AD. It's just proxying to 
another RADIUS server that is.

-- 
Matthew


More information about the Freeradius-Users mailing list