You will need to setup two (or more) LDAP directory configs in the modules/ldap config.
AD's LDAP interface isn't able to query inter-domain. So you need to setup a LDAP connection per unique domain. http://wiki.freeradius.org/Rlm_ldap On Mon, Nov 16, 2009 at 9:42 PM, John <elmer_rad...@yahoo.com.cn> wrote: > Hi, > We are using freeRADIUS-1.1.6 talk to active-directory (multiple DOMAINs: > "A.com" and "sub.A.com"). We use rlm_ldap module Global catalog port to > get attributes from ADs. It works fine. > > Now a forest(e.g. "B.com", "sub.B.com" ...) that is trust with domain > "A.com". I can not get attributes from forest "B.com". > How to get attribute from forest "B.com" ? > Any commnet is welcome. > > Thanks. > John > > ------------------------------ > 好玩贺卡等你发,邮箱贺卡全新上线!<http://cn.rd.yahoo.com/mail_cn/tagline/card/*http://card.mail.cn.yahoo.com/> > - > List info/subscribe/unsubscribe? See > http://www.freeradius.org/list/users.html >
- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html