chilli + freeradius + opendirectory

2011-07-28 Thread Massimiliano Tommasi
Hi, I'm moving step by step to get my system working... My architecture is: WEB.CLIENT---CHILLI(captive.portal)---FREERADIUS---OPENLDAP My problem now is between chilli and opendirectory THRU freeradius. Chilli supports chap or pap. I'm not able to use chap because, it's not compatible with

Re: chilli + freeradius + opendirectory

2011-07-28 Thread Massimiliano Tommasi
I forgot to say that LDAP is on MAC OSX, so it's Opendirectory, not the standard OPENLDAP... WEB.CLIENT--CHILLI--FREERADIUS--OPENDIRECTORY With radtest it works amazingly but not passing to chilli :( Regards. Hi, I'm moving step by step to get my system working... My architecture

Re: chilli + freeradius + opendirectory

2011-07-28 Thread Alan DeKok
Massimiliano Tommasi wrote: If I'm right, I'm able to convert the password to plain-text after chilli and before radius..., or am I wronging? No. It's impossible. Is there a way, I can authenticate my users from web-interface on opendirectory thru FREERADIUS? Fix Chillispot so that it

Re: chilli + freeradius + opendirectory

2011-07-28 Thread Massimiliano Tommasi
Chilli supports PAP and, if I'm right, the password is in clear-text. CHAP isn't invertible, this is clear. My only question is ... if it's possible to move from pap to opendirectory. The only way I have to authenticate is to pass clear-text to opendirectory but this doesn't happend :( Isn't

Re: chilli + freeradius + opendirectory

2011-07-28 Thread Alan DeKok
Massimiliano Tommasi wrote: My only question is ... if it's possible to move from pap to opendirectory. The only way I have to authenticate is to pass clear-text to opendirectory but this doesn't happend :( Isn't enough PAP, Alan? Yes. Do you have any idea, where it's the mistake? No.