Hi All,

After a bit of investigation and playing, I've made some changes to the
rlm_mschap module that seems to have fixed my problem. It now no longer
"trims" the machine authentication domain name, and so based on the
ntlm_auth line from Alan DeKok's How-To on deployingradius.org will handle
both machine and user authentication from any Windows supplicant doing PEAP
from any domain or child domain on my network. In theory, this should be
applicable to all other MS Windows AD environments, regardless of their
internal naming structure. Obviously, although with makes theoretical sense
and works for my environment, it needs more testing...

I've attached a patch based on the diff of my two source files.

Many thanks to Alan Buxey and John Dennis for your help.

Rupert

Attachment: rlm_mschap.patch
Description: Binary data

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to