Re: attributes based on NAS

2002-02-15 Thread Alan DeKok
Kostas Kalevras <[EMAIL PROTECTED]> wrote: > It's exacltly this way. The only difference is that because the > authorize code is the first one to run you can't set Autz-Type > before calling module_authorize. Uh, yeah. I knew that... > So we first run whatever is not included in a autztype {}

Re: attributes based on NAS

2002-02-15 Thread Kostas Kalevras
On Fri, 15 Feb 2002, Alan DeKok wrote: > Kostas Kalevras <[EMAIL PROTECTED]> wrote: > > Try it and tell me how it worked, cause I havent tested the patch heavily. > > Alan, maybe we could just use the files module to make authorize/accounting > > module selection based on checks on the incoming r

Re: attributes based on NAS

2002-02-15 Thread Alan DeKok
Kostas Kalevras <[EMAIL PROTECTED]> wrote: > Try it and tell me how it worked, cause I havent tested the patch heavily. > Alan, maybe we could just use the files module to make authorize/accounting > module selection based on checks on the incoming request instead of extending > radiusd.conf to al

Re: attributes based on NAS

2002-02-15 Thread Kostas Kalevras
On Thu, 14 Feb 2002, Matthew Schumacher wrote: > Chris, > > Thanks for your reply... I don't think this will work with my system > because Some-Attribute is coming from LDAP. Basically I need > ldap.attrmap changes on a per NAS basis. > > The changes that I want are not something that will work

Re: attributes based on NAS

2002-02-14 Thread Matthew Schumacher
Alan, I see the docs you are referring to, but I don't see how that could work in an ldap context... schu Alan DeKok wrote: > Matthew Schumacher <[EMAIL PROTECTED]> wrote: > >>Can you point me to documentation the explains how? >> > > raddb/radiusd.conf, look in the 'detail' section. > >

Re: attributes based on NAS

2002-02-14 Thread Matthew Schumacher
Chris, Thanks for your reply... I don't think this will work with my system because Some-Attribute is coming from LDAP. Basically I need ldap.attrmap changes on a per NAS basis. The changes that I want are not something that will work in a hunt group because I want one NAS to serve a diffren

Re: attributes based on NAS

2002-02-14 Thread Alan DeKok
Matthew Schumacher <[EMAIL PROTECTED]> wrote: > Can you point me to documentation the explains how? raddb/radiusd.conf, look in the 'detail' section. The documention may not be extensive or well organized, but most things *are* described somewhere in the configuration files. Alan DeKok.

Re: attributes based on NAS

2002-02-14 Thread Chris Parker
At 10:14 PM 2/13/2002 -0900, Matthew Schumacher wrote: >Alan, > >Can you point me to documentation the explains how? The users file would be one place. Any attribute that exists in an authentication packet can be used as a Check-Item. IE: DEFAULT Auth-Type := System, NAS-IP-Address == 127.0.0

Re: attributes based on NAS

2002-02-13 Thread Matthew Schumacher
Alan, Can you point me to documentation the explains how? schu Alan DeKok wrote: > Matthew Schumacher <[EMAIL PROTECTED]> wrote" > >>Is it possible to configure freeradius to serve different attributes >>based on which NAS is asking to authenticate? >> > > Yes. > > Alan DeKok. > > -

Re: attributes based on NAS

2002-02-13 Thread Alan DeKok
Matthew Schumacher <[EMAIL PROTECTED]> wrote" > Is it possible to configure freeradius to serve different attributes > based on which NAS is asking to authenticate? Yes. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

attributes based on NAS

2002-02-12 Thread Matthew Schumacher
Hello all, Is it possible to configure freeradius to serve different attributes based on which NAS is asking to authenticate? I want to make DSL and Dialup static addresses not conflict with each other. I am using ldap so I would need the same radius server to return (ldap)dialupaddress as F