How to authenticate users against a Windoze AD server with krb5?

2005-05-31 Thread Arne Götje (高盛華)
Hi list, I'm trying to authenticate users against a Windows AD server using the krb5 module... but due to missing documentation on how to do this, I'm stuck. When I try to get a Kerberos ticket using kinit on the radius machine, it works. But when I try to use the krb5 module, it always gives

Re: How to authenticate users against a Windoze AD server with krb5?

2005-05-31 Thread Kenneth G. Arnold
I know what you mean about the lack of documentation for using Kerberos authentication with FreeRadius. I pieced together the correct method using the documentation from the distribution, emails in the archives of this mailing list and trial and error. I am authenticating with the SEAM proces

Re: How to authenticate users against a Windoze AD server with krb5?

2005-05-31 Thread Alan DeKok
Arne =?utf-8?q?G=C3=B6tje?= (=?utf-8?q?=E9=AB=98=E7=9B=9B=E8=8F=AF?=)" <[EMAIL PROTECTED]> wrote: > I'm trying to authenticate users against a Windows AD server using the > krb5 module... but due to missing documentation on how to do this, I'm > stuck. The rlm_krb5 module takes a clear-text pas

Re: How to authenticate users against a Windoze AD server with krb5?

2005-06-01 Thread Arne Götje (高盛華)
On Wednesday 01 June 2005 01:08, Alan DeKok wrote: > The rlm_krb5 module takes a clear-text password from a RADIUS > packet, and uses it to authenticate via kerberos. This may work > against AD, but I don't think anyone has tried it. Ouch! I think this answers my question... this method cannot

Re: How to authenticate users against a Windoze AD server with krb5?

2005-06-01 Thread Alan DeKok
"Arne =?utf-8?q?G=C3=B6tje?= (=?utf-8?q?=E9=AB=98=E7=9B=9B=E8=8F=AF?=)" <[EMAIL PROTECTED]> wrote: > Can ntlm_auth handle MD5 hashes as passwords??? Nope. > Any solution to this or am I forced to use a M$ compatible radius server > instead? You're forced to use IAS. Nothing else does the r