Re: Returning attributes based on group membership using NTLM_AUTH

2011-08-09 Thread Alexander Clouter
Moe, John j...@hatch.com.au wrote: 3) How much/what options do I need to configure in the ldap module config? I've configured server, basedn, filter, groupname_attribute, groupmembership_filter and groupmembership_attribute, but all I get is Operations error. If I add identity and

Re: Returning attributes based on group membership using NTLM_AUTH

2011-08-09 Thread Alexander Clouter
Moe, John j...@hatch.com.au wrote: So I've gone back to FR's LDAP module and thought I'd give ldap_debug a try, despite the warning. Surprisingly, it spit out one extra line in my debug: rlm_ldap: performing search in dc=my,dc=domain,dc=name, with filter (sAMAccountName=username)

Re: Returning attributes based on group membership using NTLM_AUTH

2011-08-08 Thread Alexander Clouter
Moe, John j...@hatch.com.au wrote: Oh goodie, I'm getting somewhere. :-) ...except on the top posting front email-nazi/. ;P 1) So, I don't need to uncomment ldap in the authenticate section, as it's not going to do the password validation, right? Sounds right. 2) Do I just configure

RE: Returning attributes based on group membership using NTLM_AUTH

2011-08-08 Thread Moe, John
: Re: Returning attributes based on group membership using NTLM_AUTH Moe, John j...@hatch.com.au wrote: Oh goodie, I'm getting somewhere. :-) ...except on the top posting front email-nazi/. ;P You know, I even thought of that before I sent it, but noticed that the reply to which I

RE: Returning attributes based on group membership using NTLM_AUTH

2011-08-08 Thread Moe, John
-Original Message- [ snip ] # search reference ref: ldap://DomainDnsZones.my.domain.name/DC=DomainDnsZones,DC=my,DC=domain, DC =name # search result search: 5 result: 0 Success # numResponses: 3 # numEntries: 1 # numReferences: 1 So something still isn't right. Damn,

RE: Returning attributes based on group membership using NTLM_AUTH

2011-08-07 Thread Moe, John
-Bell Sent: Wednesday, 3 August 2011 4:15 PM To: FreeRadius users mailing list Subject: Re: Returning attributes based on group membership using NTLM_AUTH Cect ! :) -Arran On 3 Aug 2011, at 06:19, Moe, John wrote: Sorry to reply to my own post, but I think I've found the answer

Re: Returning attributes based on group membership using NTLM_AUTH

2011-08-03 Thread Arran Cudbard-Bell
: Wednesday, 3 August 2011 9:33 AM To: freeradius-users@lists.freeradius.org Subject: Returning attributes based on group membership using NTLM_AUTH I'm trying to set up switch logons for IT staff. Some will get operator (limited, read-only) access, some get manager (full) access. I've got two

Returning attributes based on group membership using NTLM_AUTH

2011-08-02 Thread Moe, John
I'm trying to set up switch logons for IT staff. Some will get operator (limited, read-only) access, some get manager (full) access. I've got two Active Directory groups that control which access they get. I've got the ntlm_auth section working with two different instances, one for each, using

RE: Returning attributes based on group membership using NTLM_AUTH

2011-08-02 Thread Moe, John
attributes based on group membership using NTLM_AUTH I'm trying to set up switch logons for IT staff. Some will get operator (limited, read-only) access, some get manager (full) access. I've got two Active Directory groups that control which access they get. I've got the ntlm_auth