Re: freeRADIUS with Active-derectory

2007-10-30 Thread Alan DeKok
Hangjun He wrote:
I have configured ntlm_auth in freeRADIUS talk to AD(user store). And
 It works well.
 Now I want to use ldap to get attribute from AD, It failed.
  
It seems ldapsearch will search user's *display name*. And ntlm_auth
 will search user's *user logon name.*
  
  If I set display name same with user logon name, It can work. Is
 there a way let ldapsearch to search user logon name too??

  The LDAP search strings are editable in radiusd.conf.

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


freeRADIUS with Active-derectory

2007-10-29 Thread Hangjun He
Hi,
 I have configured ntlm_auth in freeRADIUS talk to AD(user store). And It 
works well.
  Now I want to use ldap to get attribute from AD, It failed.
   
 It seems ldapsearch will search user's display name. And ntlm_auth will 
search user's user logon name.
   
   If I set display name same with user logon name, It can work. Is there a 
way let ldapsearch to search user logon name too??
   
   
  relate configure in radiusd.conf:
  authorize {   
  
mschap nbsp;   
 suffix 

 eap
 files  

 ldap   

} nbsp;
 
  
nbsp;
authenticate {  
   
Auth-Type MS-CHAP {   
mschap
} 
eap   
ldap  
}   

   
-
雅虎邮箱,终生伙伴! -
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html