rlm_ldap attribute mappings 3.0

2012-12-01 Thread Arran Cudbard-Bell
Hi All, Following from previous threads the old attribute mapping scheme in rlm_ldap has been removed in the 3.0 branch. Existing mapping files should be converted to the new configuration file format. # # Mapping of RADIUS dictionary attributes to LDAP directory attributes. #

Re: Sending authentication-requests to multiple radius-servers

2012-12-01 Thread Stefan Kuegler
Hi Arran. You could also use rlm_replicate to duplicate the packet, but there's currently no way of checking the aliveness of a realm at runtime, so you'd end up sending duplicate requests to whatever the primary OTP server was. and that wouldn't help if you were actually wanting to

About Radius security

2012-12-01 Thread Emmanuel BILLOT ACAD
Hi, Apologizes if this question is to newbie, but i recently thought about Radius security when using proxy. Considering we are using an EAP-TTLS method, based on LDAP authentication inside inner-tunnel (finally with PAP auth a the end). When a client tries an auth, encryption is done by the

Re: About Radius security

2012-12-01 Thread Alan Buxey
Hi, But when using this method through a proxy way, wher eis data encryption ? the TLS tunnel is set up with the remote server - the traffic being passed through all the interim proxies. so the client only trusts the remote server (ie the server they authenticate against) - all the traffic is

Re: About Radius security

2012-12-01 Thread Emmanuel BILLOT ACAD
Le 01/12/2012 23:10, Alan Buxey a écrit : Hi, But when using this method through a proxy way, wher eis data encryption ? the TLS tunnel is set up with the remote server - the traffic being passed through all the interim proxies. so the client only trusts the remote server (ie the server they