rlm_ldap problem

2006-02-11 Thread Norbert Wegener
For an 802.1x authentication radius first asks an ad server to get information about a specific machine account. If this account belongs to a certain group, the users file is consulted to check, which vlan the account gets assigned. In radiusd.conf I set the groupname_attribute in the the

Re: rlm_ldap problem

2006-02-11 Thread Alan DeKok
Norbert Wegener [EMAIL PROTECTED] wrote: Is there any way to honor the operator = in the users file in this case without modifying the source code? No. This really requires rlm_policy. There you can do something like: ... if (%{ldap:query...} = 500) { ... } ... Assuming