Proxy Forwarding on User-Name attribute

2005-10-30 Thread Christian Meutes
Hello, i have the demand to forward some auth-requests to some further radius servers, but only in the case when a specific User-Name is for authorization requested. The User-Name attributes look like this [EMAIL PROTECTED] and the userpart is always changing but the realm is always the

freeradius and machine account authentication

2005-10-30 Thread Norbert Wegener
To restrict access to a lan the network shall be equipped with switches, that are capable of 802.1x authentication on a per port basis. Only client machines with a valid machine account in a central active directory shall get access. As I have never had to do with active directory, I am unsure,

Re: v 1.05 and %{Cisco-AVPair[ ]}

2005-10-30 Thread Ilia Chipitsine
alternatively You can decode VSA's into regular attributes and use them. look for vsa_hack at radiusd.conf Good day. What must i do to use %{Cisco-AVPair[ ]} with FreeRadius v 1.05 Thanks. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html - List

Re: Proxy Forwarding on User-Name attribute

2005-10-30 Thread Alan DeKok
Christian Meutes [EMAIL PROTECTED] wrote: i have the demand to forward some auth-requests to some further radius servers, but only in the case when a specific User-Name is for authorization requested. The User-Name attributes look like this [EMAIL PROTECTED] and the userpart is always

Re: freeradius and machine account authentication

2005-10-30 Thread Alan DeKok
Norbert Wegener [EMAIL PROTECTED] wrote: FreeRADIUS at this time cannot perform machine account authentications, but it supports proxying them off to another RADIUS server (for example, IAS, or FUNK) After recent changes to both FreeRADIUS and Samba, this is now supported. See the list

Re: Proxy Forwarding on User-Name attribute

2005-10-30 Thread Joe Maimon
Christian Meutes wrote: Hello, i have the demand to forward some auth-requests to some further radius servers, but only in the case when a specific User-Name is for authorization requested. The User-Name attributes look like this [EMAIL PROTECTED] and the userpart is always changing but

Re: Proxy Forwarding on User-Name attribute

2005-10-30 Thread Christian Meutes
iam not forwarding on realm because the realm is always the same! --On Sunday, October 30, 2005 11:52:04 -0500 Joe Maimon [EMAIL PROTECTED] wrote: Christian Meutes wrote: Hello, i have the demand to forward some auth-requests to some further radius servers, but only in the case when a

Re: freeradius and machine account authentication

2005-10-30 Thread Norbert Wegener
Alan DeKok wrote: Norbert Wegener [EMAIL PROTECTED] wrote: FreeRADIUS at this time cannot perform machine account authentications, but it supports proxying them off to another RADIUS server (for example, IAS, or FUNK) After recent changes to both FreeRADIUS and Samba, this is now