Re: Issues authenticating vs 2003 AD

2005-08-19 Thread Tim P
I have read the docs, maybe I am just missing where there example was, I see the entries commented but not for what I need I guess (or I missed). I have reconfigured radiusd.conf again to see it I can authenticate and am still having trouble Can you look at these configs and tell me where you

Re: Issues authenticating vs 2003 AD

2005-08-19 Thread Alan DeKok
Tim P [EMAIL PROTECTED] wrote: I have reconfigured radiusd.conf again to see it I can authenticate and am still having trouble Can you look at these configs and tell me where you see issues? The client is doing CHAP. You have configured the MSCHAP module to use ntlm_auth. CHAP is not

Re: Issues authenticating vs 2003 AD

2005-08-19 Thread Alan DeKok
Tim P [EMAIL PROTECTED] wrote: I understand you have said that repeatedly what I am asking is where is that chap coming from? As I've also said repeatedly, the client sends the authentication request to the server, and the server does not, and can not control what authenticate type the client

Re: Issues authenticating vs 2003 AD

2005-08-18 Thread Tim P
Ok using these settings it seems to authenticate with radtest Radius.conf ldap { server = domcon.company.org basedn = dc=company,dc=org filter = (sAMAccountName=%{Stripped-User-Name:-%{User-Name}}) password_attribute =

Re: Issues authenticating vs 2003 AD

2005-08-18 Thread Alan DeKok
Tim P [EMAIL PROTECTED] wrote: Ok using these settings it seems to authenticate with radtest ... [EMAIL PROTECTED] ~]# radtest user userpass localhost:1812 1 radiussecret i.e. clear-text password. rlm_ldap: looking for check items in directory... rlm_ldap: looking for reply items in

Re: Issues authenticating vs 2003 AD

2005-08-18 Thread Tim P
Sorry to keep asking but can you post an example (using mschap) to authenticate from freeradius to AD using the ntlm_auth method? On 8/18/05, Alan DeKok [EMAIL PROTECTED] wrote: Tim P [EMAIL PROTECTED] wrote: Ok using these settings it seems to authenticate with radtest ... [EMAIL

Re: Issues authenticating vs 2003 AD

2005-08-18 Thread Alan DeKok
Tim P [EMAIL PROTECTED] wrote: Sorry to keep asking but can you post an example (using mschap) to authenticate from freeradius to AD using the ntlm_auth method? What's wrong with reading radiusd.conf? Alan DeKok. - List info/subscribe/unsubscribe? See

Issues authenticating vs 2003 AD

2005-08-17 Thread Tim P
I am handing off a qurest from pppd to radius and am failing with a valid user in the domain. Here is the output of radiusd -X -A Ready to process requests. rad_recv: Access-Request packet from host 127.0.0.1:32769, id=39, length=72 Service-Type = Framed-User Framed-Protocol =

Re: Issues authenticating vs 2003 AD

2005-08-17 Thread Alan DeKok
Tim P [EMAIL PROTECTED] wrote: I am handing off a qurest from pppd to radius and am failing with a valid user in the domain. No. The server is failing because it doesn't have a clear-text password. rlm_ldap: looking for check items in directory... rlm_ldap: looking for reply items in

Re: Issues authenticating vs 2003 AD

2005-08-17 Thread Tim P
Thought it was configured, I beleive I have tested it positive in the past, I want to use ntlm_auth, I had this in there and had tested it as far as i know: Radius.conf ldap { server = domcon.company.org basedn = dc=company,dc=org filter =