Re: not binding but query passwords in LDAP

2003-08-26 Thread Kostas Kalevras
On Wed, 20 Aug 2003, Ron Wahler wrote:

>
> Kostas, group,
>
>
> Question 1:
>
> Is there an example out there that shows how to configure radiusd.conf
> to
> Query an LDAP database for the passwords (not bind) and populate
> NT-Password or LM-Password. I need this to complete MS-CHAP & PAP
> authentication to a backend LDAP Database. I just need a snip it of the
> config file.

Check out raddb/ldap.attrmap and doc/rlm_ldap
Just adding the ldap module in the authorize section (and not in the
authenticate section) should be sufficient to extract the corresponding
passwords.

>
> Question 2:
>
> Is there a way to bind with MS-CHAP passwords to a LDAP or active
> directory database?

The ldap BIND operation requires the user plain text password so probably not.

>
>
> Thanks,
> Ron.
>

--
Kostas Kalevras Network Operations Center
[EMAIL PROTECTED]   National Technical University of Athens, Greece
Work Phone: +30 210 7721861
'Go back to the shadow' Gandalf

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


not binding but query passwords in LDAP

2003-08-20 Thread Ron Wahler

Kostas, group,


Question 1:

Is there an example out there that shows how to configure radiusd.conf
to 
Query an LDAP database for the passwords (not bind) and populate
NT-Password or LM-Password. I need this to complete MS-CHAP & PAP
authentication to a backend LDAP Database. I just need a snip it of the
config file.

Question 2: 

Is there a way to bind with MS-CHAP passwords to a LDAP or active
directory database?


Thanks,
Ron.

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html