Re: [EXT] Fetching memberOf attribute

Alan DeKok via Freeradius-Users <[email protected]>
Newsgroups gmane.comp.freeradius.user
Message-ID <[email protected]>
On Jun 2, 2025, at 8:34 AM, Matvey Teplov via Freeradius-Users <[email protected]> wrote:
> Picking this outstanding action. I tried "reject" before, and it is a problem. The startup comes with:
> 
> /etc/freeradius/3.0/sites-enabled/default[85]: Failed to find "reject" as a module or policy.
> /etc/freeradius/3.0/sites-enabled/default[85]: Please verify that the configuration exists in /etc/freeradius/3.0/mods-enabled/reject.
> /etc/freeradius/3.0/sites-enabled/default[85]: Failed to parse "reject" entry.

  Because you edited the default configuration and broke it.  Don't do that.

  The "reject" module is defined in mods-available/always.  You've either edited it to remove the "reject" entry, or you've disabled it by removing mods-enabled/always,

> Also, the simple '==' doesn't work either, and that's why the loop is there. It is coming back with during authentication:
> (0)     if (&control:ldap-LDAP-Group[*] == "CN=Radius_ReadOnly_Group,DC=Groups,DC=abc,DC=abc") {
> (0)     ERROR: Failed retrieving values required to evaluate condition

  The LDAP-Group attribute is documented in the Wiki:  https://wiki.freeradius.org/modules/Rlm_ldap

  Follow those examples and it will work.

  Alan DeKok.

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.