Re: ldap { fail=1}

This is a discussion on Re: ldap { fail=1} within the FreeRADIUS Users forums, part of the Networking and Network Related category; --===============1951718473== Content-Type: multipart/alternative; boundary="----=_Part_15748_16001538.1168507065083" ------=_Part_15748_16001538.1168507065083 Content-Type: text/plain; charset=UTF-8 Content-...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-11-2007
jerrrry@voila.fr
 
Posts: n/a
Default Re: ldap { fail=1}

--===============1951718473==
Content-Type: multipart/alternative;
boundary="----=_Part_15748_16001538.1168507065083"

------=_Part_15748_16001538.1168507065083
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable







> Message du 10/01/07 =C3=A0 15h38
> De : "Alan DeKok"=20
> A : jerrrry@voila.fr, "FreeRadius users mailing list"=20
> Copie =C3=A0 :=20
> Objet : Re: ldap { fail=3D1}
>=20
> jerrrry@voila.fr wrote:
> >=20
> > i'm using freeradius 1.0.1 from Red Hat entreprise 4.

>=20
> You SHOULD upgrade:
>=20
> http://freeradius.org/security.html
>=20
> > I want the radius server to authenticate users thanks to the "users"
> > file even if the ldap directory is not reachable and the radius server
> > to start even if the DB is not reachable

>=20
> That's probably the way the server should work. Those issues probably
> weren't though of when the server was written, as the SQL module works
> the same way.
>=20
> > I tried with ldap { fail =3D1} in the authorize section and sql { fail
> > =3D 1 } in the instantiate section without any success.
> >=20
> > "fail" doen't seem to be know.

>=20
> No, it doesn't work in the "instantiate" section. It could, though.
> It's a good idea, and one I hadn't thought of.

so there is no solution to backup my nas client list thanks to freeradius w=
ith somethng like=20
instantiate{
redundant {=20
sql1
sql2
}
}
Thomas

>=20
> An alternative would be to update the LDAP module to NOT bind at
> startup, and do it only when a request came in. That would help, too.
>=20
> Alan DeKok.
> --
> http://deployingradius.com - The web site of the book
> http://deployingradius.com/blog/ - The blog
>=20
>

------=_Part_15748_16001538.1168507065083
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<BR><BR><BR><BR><BR>
<BLOCKQUOTE style=3D"PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #ff0=
000 2px solid">
<P>&gt; Message du 10/01/07 =C3=A0 15h38<BR>&gt; De : "Alan DeKok" <ALAND@D=
EPLOYINGRADIUS.COM><BR>&gt; A : jerrrry@voila.fr, "FreeRadius users mailing=
list" <FREERADIUS-USERS@LISTS.FREERADIUS.ORG><BR>&gt; Copie =C3=A0 : <BR>&=
gt; Objet : Re: ldap { fail=3D1}<BR>&gt; <BR>&gt; jerrrry@voila.fr wrote:<B=
R>&gt; &gt; <BR>&gt; &gt; i'm using freeradius 1.0.1 from Red Hat entrepris=
e 4.<BR>&gt; <BR>&gt; You SHOULD upgrade:<BR>&gt; <BR>&gt; http://freeradiu=
s.org/security.html<BR>&gt; <BR>&gt; &gt; I want the radius server to authe=
nticate users thanks to the "users"<BR>&gt; &gt; file even if the ldap dire=
ctory is not reachable and the radius server<BR>&gt; &gt; to start even if =
the DB is not reachable<BR>&gt; <BR>&gt; That's probably the way the server=
should work. Those issues probably<BR>&gt; weren't though of when the serv=
er was written, as the SQL module works<BR>&gt; the same way.<BR>&gt; <BR>&=
gt; &gt; I tried with ldap { fail =3D1} in the authorize section and sql { =
fail<BR>&gt; &gt; =3D 1 } in the instantiate section without any success.<B=
R>&gt; &gt; <BR>&gt; &gt; "fail" doen't seem to be know.<BR>&gt; <BR>&gt; N=
o, it doesn't work in the "instantiate" section. It could, though.<BR>&gt; =
It's a good idea, and one I hadn't thought of.</P>
<P>so&nbsp;there is no solution to backup my nas client list thanks to free=
radius with somethng like </P>
<P>instantiate{</P>
<P>redundant { </P>
<P>sql1</P>
<P>sql2</P>
<P>}</P>
<P>}</P>
<P>Thomas</P>
<P><BR>&gt; <BR>&gt; An alternative would be to update the LDAP module to N=
OT bind at<BR>&gt; startup, and do it only when a request came in. That wou=
ld help, too.<BR>&gt; <BR>&gt; Alan DeKok.<BR>&gt; --<BR>&gt; http://deploy=
ingradius.com - The web site of the book<BR>&gt; http://deployingradius.com=
/blog/ - The blog<BR>&gt; <BR>&gt; </P></BLOCKQUOTE>
------=_Part_15748_16001538.1168507065083--



--===============1951718473==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
--===============1951718473==--


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:17 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0