Re: Ldap Group Attribute radiusGroupName

This is a discussion on Re: Ldap Group Attribute radiusGroupName within the FreeRADIUS Users forums, part of the Networking and Network Related category; On Thu, 17 Feb 2005, Chan Min Wai wrote: > Kostas Kalevras wrote: >> You 've got multiple instances ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-17-2005
Kostas Kalevras
 
Posts: n/a
Default Re: Ldap Group Attribute radiusGroupName

On Thu, 17 Feb 2005, Chan Min Wai wrote:

> Kostas Kalevras wrote:
>> You 've got multiple instances of the ldap module and you 're using the
>> wrong one to perform group checks. Use:
>>
>> DEFAULT <ldap_instance>-Ldap-Group == disabled, Auth-Type := Reject

>
> Ok Things statring to be more interesting now. I've using the following
> entry in users as below:
>
>
>
> DEFAULT ocesbldap-Ldap-Group ==
> "cn=disabled,ou=profiles,dc=ocesb,dc=com,dc=my,dc= .", Auth-Type := Reject
> Reply-Message = "Sorry, you are not allowed to have dialup access"
>
> =================OR==================
>
> DEFAULT ocesbldap-Ldap-Group == disabled, User-Profile :=
> "cn=disabled,ou=profiles,dc=ocesb,dc=com,dc=my,dc= .", Auth-Type := Reject
> Reply-Message = "Sorry, you are not allowed to have dialup access"
>
> Both of them are working however...
>
> Seem to be they don't care what group the users is in and just by
> default disable everybody.
>
> Anyone have some hints for me...


Run the server in debug mode to see what happens exactly.

>
>
> After working on this Group, I'm thinking what is the real use of Group?


None really, apart from group checks like the above

> Define the default attribute/replyItem for certain services?


That's what Default/REgular/User profiles are for.

>
> Regards,
> Chan Min Wai
>
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
>


--
Kostas Kalevras Network Operations Center
kkalev@noc.ntua.gr National Technical University of Athens, Greece
Work Phone: +30 210 7721861
'Go back to the shadow' Gandalf

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 01:18 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0