Re: 802.1X - ldap AND users file
Alan DeKok via Freeradius-Users <[email protected]> Wed, 1 Apr 2026 12:20:14 -0400
| Newsgroups | gmane.comp.freeradius.user |
|---|---|
| Message-ID | <[email protected]> |
On Apr 1, 2026, at 11:22 AM, cedric Delaunay <[email protected]> wrote: > I'd like to find how to force "accept" for a special user, based on "mods-config/files/authorize" file > - user is logged-in on device so that is real username is kown only by inner-tunnel > - user isn't known by ldap (that's why I try with "users" file) > - user's password may change so that I don't want to check it This allegedly works. It was posted to the list a while back. I haven't had a chance to test it in detail, or figure out exactly what Windows is doing with it. authorize { ... update { &control:SMB-Account-CTRL-TEXT := '[N]' &reply:MS-CHAP2-Success = 'password-free' } .. That allegedly works for MS-CHAP authentication. I've tried it with PEAP, and got nowhere. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEIUl02elqcIsf1zM0v3SJ0h7dTTMFAmnNRb4ACgkQv3SJ0h7d TTOnCA//bC/aaSU4Hqb22I7W++xarjhET5sC2JoM0ibYeEfy1FN4Z+cRxbeX4EXG ydumxK1lu0CWx/BRFPeqHOMgq1rZaDAjDneK5Yj4B9INz7XZyxlje8C9QnvlIz/k zdnti+PHF/cPQ9r2jILp6UaWtE7q/j+fHV9H3peyYTArRDbnruINIbtGBWe33/Qi Ld2qJAZ2GZck4V4eIWoadFTjMWyhrzQW5sI1Dl4z8bXNjKq5RRI8JFUvHcGIZ+F8 KQELYFyo80jPJlrDkpAYLxwGbVCGpsirXb64/3UWsMLOrcfKtFK/gd0Dt1CauBgv Rqpp2gY5bIn180Vh8lhnSHuOUiDAjZODkULVlBBfza6Mafp4G9Qu29ZbnF2IbCzr lt5I2y/OLE2qgjp+Dz5LatuQFLZJvPsuQWt6b1sgtVwxmqde+5BSWqWS0g89sne5 XAk5pUKJPN4YyPZQPCqZUIhiBhRUMos1AFNM95r3v9J8YeWoAnjVos4HykA/LoCs qD4owwj7mHbLTlMhFkZN0oatU5kH6m/VVmHqmkNAltPFIXZzvGSgGyAUObDRlkhO c8JxAo503BdW+KTGafAsH5i1TG5jQlZ+QwYcD7FrArJg7lIFEWDWOirqp/S9vHRC jaK/9z+xQSAwNvZYjmMDgYZmVyKgg60asBe19koN7wKZ8Tuy+cc= =mglD -----END PGP SIGNATURE-----