Re: MAC authorisation (but not authentication) via LDAP

This is a discussion on Re: MAC authorisation (but not authentication) via LDAP within the FreeRADIUS Users forums, part of the Networking and Network Related category; Zitat von Martin Whinnery <martin.whinnery@sbc.ac.uk>: > Thanks Markus, > > the problem seems to ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-25-2007
Markus Krause
 
Posts: n/a
Default Re: MAC authorisation (but not authentication) via LDAP

Zitat von Martin Whinnery <martin.whinnery@sbc.ac.uk>:
> Thanks Markus,
>
> the problem seems to be that the authorisation pass returns "notfound",
> whereas I want it to "reject", as if it found an entry in LDAP without
> the appropriate attribute.
>
> Mart


Hi Mart,

ugh, you are of course right, i forgot on important detail, sorry!
(has been quite a time since i set this up and it is getting quite
late in the night now ...)
directly after the ldap entry in authorize a call a small perl script
which checks for "$RAD_REQUEST{'Module-Failure-Message'}", and if it
is set then return with "RLM_MODULE_REJECT", so 'notfound' is replaced
by 'reject'.

i must admit that this actually is a very dirty solution ... i should
really overthink it (altough it works ...)

regards
markus


+-----------------------------------------------------------------+
| Markus Krause, Mogli-Soft |
| Support for Mac OS X, Webmail/Horde, LDAP, RADIUS |
| by order of the |
| Computing Center of the Max-Planck-Institute of Biochemistry |
+--------------------------------+--------------------------------+
| E-Mail: krause@biochem.mpg.de | Tel.: 089 - 89 40 85 99 |
| markus.krause@mac.com | Fax.: 089 - 89 40 85 98 |
| Skype: markus.krause | iChat: markus.krause@mac.com |
+--------------------------------+--------------------------------+



----------------------------------------------------------------------
This message was sent using https://webmail2.biochem.mpg.de
If you encounter any problems please report to rz-linux@biochem.mpg.de



-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:51 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0