Re: Fwd: Request for directions: WinXP + Samba + LDAP + 802.1x

2009-12-15 Thread tnt
> [ldap] looking for check items in directory... > rlm_ldap: userPassword -> User-Password == > "{SMD5}/S4d+fNkBFL3TnpjceYuUiDPd+Q=" > rlm_ldap: sambaNtPassword -> NT-Password == > 0x444338414235383730324637343230453244304232353743453938394634 > rlm_ldap: sambaLmPassword -> LM-Password == > 0x3

Re: Fwd: Request for directions: WinXP + Samba + LDAP + 802.1x

2009-12-15 Thread Fabiano Caixeta Duarte
2009/12/15 Alan Buxey : > hi, > > adjust your matching ocndition in ldap - fix the :- issue You mean a substitute for filter = "(uid=%{Stripped-User-Name:-%{User-Name}})" ??? > adjust your LDAP assignments so that Cleartext-Password is known. I use OpenLDAP with hashed passwords. > does the LDA

Re: Fwd: Request for directions: WinXP + Samba + LDAP + 802.1x

2009-12-15 Thread Alan Buxey
hi, adjust your matching ocndition in ldap - fix the :- issue adjust your LDAP assignments so that Cleartext-Password is known. does the LDAP store the password in a clear format or as some encrypted/hashed method? is this MS AD? we us ntlm_auth to authenticate users against the MS AD - simply

Fwd: Request for directions: WinXP + Samba + LDAP + 802.1x

2009-12-15 Thread Fabiano Caixeta Duarte
> As you can see, it says that it has stripped realm from username but > it passes it along with username to ldap. How can I fix this? Never mind. ldap filter did the job. Sorry about that. Actually it's not working yet. rad_recv: Access-Request packet from host 192.168.205.29 port 49154, id=0,