Hi everbody,
I have a freeradius+openldap working well, but I'd like to make some changes.
Below are the ldap module configuration:
server = "ldap.mycompany.br"
identity = "cn=Admin,dc=univates,dc=br"
password = xx
basedn = "dc=my
On 02/10/2012 09:09 PM, NdK wrote:
Can't create "users" in AD. Just machine accounts. Maybe it's possible
to use the (or "a dedicated") *machine* account credentials?
rlm_ldap just needs a bind DN. Any ldap DN with permissions to bind to
the directory and execute the searches you need will su
@lists.freeradius.org] on behalf
of Alan DeKok [al...@deployingradius.com]
Sent: Friday, February 10, 2012 3:37 PM
To: FreeRadius users mailing list
Subject: Re: LDAP Binding
NdK wrote:
> Can't create "users" in AD. Just machine accounts.
That's a local policy which c
NdK wrote:
> Can't create "users" in AD. Just machine accounts.
That's a local policy which can be changed.
AD is perfectly capable of creating read-only administrator accounts.
It's what everyone else does.
> Maybe it's possible
> to use the (or "a dedicated") *machine* account credentials
Il 10/02/2012 16:21, Phil Mayers ha scritto:
>> Is it possible to bind to AD's LDAP using the Kerberos ticket obtained
>> at join time?
> This question does not make sense. Joining a domain doesn't "obtain a
> kerberos ticket". It creates a machine account principal, and a shared
> secret (passwor
On 10/02/12 14:38, NdK wrote:
Hello all.
Is it possible to bind to AD's LDAP using the Kerberos ticket obtained
at join time?
This question does not make sense. Joining a domain doesn't "obtain a
kerberos ticket". It creates a machine account principal, and a shared
secret (password) that ca
NdK wrote:
> Is it possible to bind to AD's LDAP using the Kerberos ticket obtained
> at join time?
No. The LDAP API doesn't support that.
> That would allow to search for group membership without spawning more
> processes...
Huh? You can configure AD as an LDAP server, and do group member
Hello all.
Is it possible to bind to AD's LDAP using the Kerberos ticket obtained
at join time?
That would allow to search for group membership without spawning more
processes...
Tks,
Diego.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
8 matches
Mail list logo