Matt Bernstein wrote:
> By this point we've correctly walked from default -> dcs -> dcs-inner.
> But.. as dcs-inner invokes rlm_ldap, it's using the wrong ldap instance:
...
> rlm_ldap: Entering ldap_groupcmp()
> [dcs-inner-files] expand: dc=maths,dc=qmul,dc=ac,dc=uk ->
> dc=maths,dc=qmul,dc=ac
At 14:19 +0200 Alan DeKok wrote:
I have run into another bug: if I instantiate rlm_ldap in my servers
"dcs-inner" and "maths-inner", it seems to use the base DN for
"maths-inner" (instantiated second) for queries from "dcs-inner".
As always, debug mode.
By this point we've correctly walked
At 14:19 +0200 Alan DeKok wrote:
Matt Bernstein wrote:
We will have multiple server certificates; our departments are rather
independent here.
Ugh. There's not really any good reason for this. If the
departmental certs are signed by a university CA, then you can still get
away with one ser
Matt Bernstein wrote:
> We will have multiple server certificates; our departments are rather
> independent here.
Ugh. There's not really any good reason for this. If the
departmental certs are signed by a university CA, then you can still get
away with one server instance.
>> update
On Oct 15 Alan DeKok wrote:
Matt Bernstein wrote:
So saith FreeRADIUS 2.1.1, but I wasn't trying to do multiple levels of
TLS nesting. I'm trying to use virtual servers so that a single radiusd
can terminate TTLS/PEAP for multiple subrealms, _and_ use the
inner-tunnel trick, keeping the configs
Matt Bernstein wrote:
> So saith FreeRADIUS 2.1.1, but I wasn't trying to do multiple levels of
> TLS nesting. I'm trying to use virtual servers so that a single radiusd
> can terminate TTLS/PEAP for multiple subrealms, _and_ use the
> inner-tunnel trick, keeping the configs completely independent
hi,
hmmm, something about that process and flow doesnt sound
right at all.
alan
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
So saith FreeRADIUS 2.1.1, but I wasn't trying to do multiple levels of
TLS nesting. I'm trying to use virtual servers so that a single radiusd
can terminate TTLS/PEAP for multiple subrealms, _and_ use the inner-tunnel
trick, keeping the configs completely independent for each subrealm. This
al
8 matches
Mail list logo