Re: Freeradius + EAP-TLS + LDAP

2011-04-20 Thread Alexandros Gougousoudis
Hi Folks, the question makes sense, I think I wrote it not understandible enough. 1. What I already do is: 1.1. Authenticating via EAP-TLS Computers/Workstations against my Switches 1.2. Users are authenticated with PEAP and Cleartext-Passwords in $RADDB/users 2. What I want to do is: 2.1.

Re: Freeradius + EAP-TLS + LDAP

2011-04-20 Thread Phil Mayers
On 04/20/2011 10:23 AM, Alexandros Gougousoudis wrote: 3.1. Certs on all Computer/Workstations and an entry in $RADDB/users of the Computername wirh Authentification-Type = EAP 3.2. Users in my LDAP with crypted Passwords (MD5/crypt) AND Passwords for Samba (NT-Passwords). Ah, good. If you

Re: Freeradius + EAP-TLS + LDAP

2011-04-20 Thread Alexandros Gougousoudis
Hi Phil, Phil Mayers schrieb: Ah, good. If you have NT-Password, PEAP/MS-CHAP should work. Great! Yes. There are lots of ways to do this, depending on what key you want to use for the lookup (machine account name, mac address, TLS cert subject) Thanks, I'll start to do this. Machine

Re: Freeradius + EAP-TLS + LDAP

2011-04-20 Thread Alan Buxey
Hi, Thanks, I'll start to do this. Machine account name should work for me. Any hints, or how to do this? Is there somewhere an example availlable to start with? I'am new to FR 2.1 and it's hard to make even my old config work on the test-maschine. after altering ntlm_auth command

Re: Freeradius + EAP-TLS + LDAP

2011-04-20 Thread Phil Mayers
On 04/20/2011 11:37 AM, Alexandros Gougousoudis wrote: Hi Phil, Phil Mayers schrieb: Ah, good. If you have NT-Password, PEAP/MS-CHAP should work. Great! Yes. There are lots of ways to do this, depending on what key you want to use for the lookup (machine account name, mac address, TLS cert

Freeradius + EAP-TLS + LDAP

2011-04-19 Thread Alexandros Gougousoudis
Hi, with my FR 1.x installation I'am authenticating via EAP-TLS Computers against my Switches. User are authenticated with PEAP, all are held in the users-textfile in $RADDB/users But with rising number of PCs and Users the edit of the users file is a bit uncomfortable. I want to upgrade

Re: Freeradius + EAP-TLS + LDAP

2011-04-19 Thread Sven Hartge
Alexandros Gougousoudis gougousoudis-l...@servicecenter-khs.de wrote: The users should be checked by uid and the password should be checked, but I have of course no cleartext-password in my LDAP, they are all crypt or MD5 (depends on tree). Is this possible or not? No, impossible. If you

Re: Freeradius + EAP-TLS + LDAP

2011-04-19 Thread Phil Mayers
On 19/04/11 15:24, Sven Hartge wrote: Alexandros Gougousoudisgougousoudis-l...@servicecenter-khs.de wrote: The users should be checked by uid and the password should be checked, but I have of course no cleartext-password in my LDAP, they are all crypt or MD5 (depends on tree). Is this

Re: Freeradius + EAP-TLS + LDAP

2011-04-19 Thread Phil Mayers
On 19/04/11 13:55, Alexandros Gougousoudis wrote: Hi, with my FR 1.x installation I'am authenticating via EAP-TLS Computers against my Switches. User are authenticated with PEAP, all are held in the users-textfile in $RADDB/users EAP-TLS and PEAP are different. Which do you mean? But with

Re: Freeradius + EAP-TLS + LDAP

2011-04-19 Thread Sven Hartge
Phil Mayers p.may...@imperial.ac.uk wrote: On 19/04/11 15:24, Sven Hartge wrote: Alexandros Gougousoudisgougousoudis-l...@servicecenter-khs.de wrote: The users should be checked by uid and the password should be checked, but I have of course no cleartext-password in my LDAP, they are all