Re : Re : Re : Re : Authorization?? pb Authentication against AD

2008-06-27 Thread Reveal MAP
list Envoyé le : Vendredi, 27 Juin 2008, 16h18mn 32s Objet : Re: Re : Re : Re : Authorization?? pb Authentication against AD ># You can also try setting the user name as: ># >#... --username=%{mschap:User-Name} ... ># Did you read what you copied? Repla

Re: Re : Re : Re : Authorization?? pb Authentication against AD

2008-06-27 Thread Ivan Kalik
># You can also try setting the user name as: ># >#... --username=%{mschap:User-Name} ... ># Did you read what you copied? Replace username bit in ntml_auth with that. Your problem is that you are sending DOMAIN\username and not just username. Ivan Kalik Kalik

Re : Re : Re : Authorization?? pb Authentication against AD

2008-06-27 Thread Reveal MAP
I am Sorry, I have a little problem with english, and i know it might be annoying for you! but i am not sure to understand what you are adcing me right now. 1- um.. using "mschap:User-Name" (how can i do that? in radiusd.conf, mschap section? or in ntlm_ath configuration files?) 2-

Re: Re : Re : Authorization?? pb Authentication against AD

2008-06-27 Thread A . L . M . Buxey
Hi, > the result of ntlm_auth in command line: > > -- > aaa:/var/lib/samba #ntlm_auth --username glouglou --domain pluton > password: > NT_STATUS_OK: Success (0x0) > aaa:/var/lib/samba # > > --

Re : Re : Authorization?? pb Authentication against AD

2008-06-27 Thread Reveal MAP
the result of ntlm_auth in command line: -- aaa:/var/lib/samba #ntlm_auth --username glouglou --domain pluton password: NT_STATUS_OK: Success (0x0) aaa:/var/lib/samba # -

Re: Re : Authorization?? pb Authentication against AD

2008-06-27 Thread Ivan Kalik
>i think the point error in the log is (see below), and i wonder (if i >understood well) how to fix that : > > >rlm_mschap: No Cleartext-Password configured. Cannot create > LM-Password. > rlm_mschap: No Cleartext-Password configured. Cannot create > NT-Password. No, ntlm_a

Re: Authorization?? pb Authentication against AD

2008-06-27 Thread Ivan Kalik
>First question: is EAP system mandatory to authenticate against Active >Directory? No. EAP is there to increase security. >2. "Exec-Program output: winbind client not authorized to use >winbindd_pam_auth_crap. Ensure permissions on >/var/lib/samba/winbindd_privileged are set correctly. (0xc00