Re: LDAP->RADIUS Attribute Mapping

This is a discussion on Re: LDAP->RADIUS Attribute Mapping within the FreeRADIUS Users forums, part of the Networking and Network Related category; Owen DeLong wrote: > We have historically used the AuthorizedService attribute in LDAP to > control the level > of ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-08-2006
Alan DeKok
 
Posts: n/a
Default Re: LDAP->RADIUS Attribute Mapping

Owen DeLong wrote:

> We have historically used the AuthorizedService attribute in LDAP to
> control the level
> of access available to the user. We would like to continue to do so.
> However, in order
> for that to work, I need to map AuthorizedService to different RADIUS
> attributes in
> the response depending on the authentication client.


Do it in two steps. Map the AuthorisedService LDAP attribute to a
RADIUS attribute (invent a local one, see the dictionary docs), and then
depending on the NAS, map that to another attribute.

The reason for doing it this way is that the LDAP -> RADIUS attribute
mapping is simple, and should be kept simple.

> Ideally, I'd like to be able to map RADIUS clients into "groups" and
> have a mapping
> of AuthorizedService values for each group. The client groups would,
> ideally,
> be defined by matching the client IP address. An example of what I'd
> like that
> mapping to look like is below:


Use rlm_passwd to map clients to groups (see it's documentation), and
then the "users" file to map AuthorizedService to another RADIUS
attribute, as described above.

> Alan, your flames and RTFM comments are welcome, but, please understand,
> I've done my best to RTFM before posting this.


As I tell my co-workers, "Remember, there are no stupid questions.
There are only stupid people.".

And they still speak to me after that. :)

Alan DeKok.
--
http://deployingradius.com - The web site of the book
http://deployingradius.com/blog/ - The blog
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:50 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0