Re: Radius-based windows authentication

2008-04-29 Thread Mike Perdide
Phil Mayers wrote : > There's no need to CC me. I read the list. Sorry about that ^^*. > There's a better way; use the mschap module expansion function, which > will both strip and suffix for you: > > filter = "(uid=%{mschap:User-Name})" Thank you very much, everything works fine works fine now. T

Re: Radius-based windows authentication

2008-04-29 Thread Phil Mayers
Julien MIOTTE wrote: 1. Using the windows native supplicant and machine account authentication. Basically the process is this: * machine powers on - no-one logged in * machine uses its own domain account to login "host/$machinename" * user presses ctrl+alt+del * machine vali

Re: Radius-based windows authentication

2008-04-25 Thread Phil Mayers
Mike Perdide wrote: Phil Mayers wrote: Is the windows machine a domain member? No it's not. Only the users are. ? When you sit at the login screen, and press ctrl+alt+del, are you logging in with a username and password which is checked against the domain controllers? If so, then the machin

Re: Radius-based windows authentication

2008-04-25 Thread A . L . M . Buxey
Hi, > > Phil Mayers wrote: > >>> Is the windows machine a domain member? > >> No it's not. Only the users are. > > ? > > > When you sit at the login screen, and press ctrl+alt+del, are you > > logging in with a username and password which is checked against the > > domain controllers? > > If so, t

Re: Radius-based windows authentication

2008-04-25 Thread Mike Perdide
> Phil Mayers wrote: >>> Is the windows machine a domain member? >> No it's not. Only the users are. > ? > When you sit at the login screen, and press ctrl+alt+del, are you > logging in with a username and password which is checked against the > domain controllers? > If so, then the machine *is* j

Re: Radius-based windows authentication

2008-04-25 Thread Phil Mayers
Mike Perdide wrote: Phil Mayers wrote: Is the windows machine a domain member? No it's not. Only the users are. ? When you sit at the login screen, and press ctrl+alt+del, are you logging in with a username and password which is checked against the domain controllers? If so, then the mac

Re: Radius-based windows authentication

2008-04-25 Thread Guy Davies
2008/4/25 Phil Mayers <[EMAIL PROTECTED]>: > Mike Perdide wrote: > > > Hello, > > > > I'm working on VLAN assignement with FreeRadius, with windows XP users. > > The FreeRadius server is using openLdap, and works overs EAP-TTLS. > > The goal of my work is for the users to be on different Vlans depe

Re: Radius-based windows authentication

2008-04-25 Thread Mike Perdide
Phil Mayers wrote: > Is the windows machine a domain member? No it's not. Only the users are. > I think you are asking "is it possible for the client to do 802.1x with > the username/password typed into the login box" and the answer is "yes". That's exactly my question, thanks ;). > 1. Using th

Re: Radius-based windows authentication

2008-04-25 Thread Phil Mayers
Mike Perdide wrote: Hello, I'm working on VLAN assignement with FreeRadius, with windows XP users. The FreeRadius server is using openLdap, and works overs EAP-TTLS. The goal of my work is for the users to be on different Vlans depending on their status. The radius part is working fine, sin

Radius-based windows authentication

2008-04-25 Thread Mike Perdide
Hello, I'm working on VLAN assignement with FreeRadius, with windows XP users. The FreeRadius server is using openLdap, and works overs EAP-TTLS. The goal of my work is for the users to be on different Vlans depending on their status. The radius part is working fine, since the switch sets the