Re: Radius Authentication




Hi Todor,

Thanks, Ive read before that there has to be a user on the local server with
the same name as the windows domain and i have used the man pages for the
configuration, i think the problem lies with the autentication against the
Radius server, or the Radius server itself.

I shall venture forth and try to combat this plague!!! :-P

thanks for the speedy reply btw!

=)

Todor Genov-2 wrote:

Hi Matt,


The three important steps here are as follows:

1.) Confirm that authentication against the RADIUS server succeeds using
any command line RADIUS util.

2.) configure /etc/radius.conf as per "man pam_radius" and man
"radius.conf"

3.) Add a user on the FreeBSD machine whose name corresponds with the
Windows domain account (if the name contains spaces then refer to the
pre-Windows2000 compatible username in AD). This is mandatory as
pam_radius is only used for authentication. UID, GID, home dir and all
*nix relevant account parameters are still retrieved from the local user
database.

An alternative to step 3 would be to use the template_user option in
radius.conf, but this means that all your Windows users will appear to
the system with same UID/GID as the template_user.


MattAD wrote:
I would just like to know if anyone on earth has been able to get the
pam_radius module working on FreeBSD, using a windows domain username
through ssh... ??? This has become a mystery to me. My /etc/pam.d/sshd
config looks like so:

#
# $FreeBSD: src/etc/pam.d/sshd,v 1.16 2007/06/10 18:57:20 yar Exp $
#
# PAM configuration for the "sshd" service
#

# auth
auth required pam_nologin.so no_warn
auth sufficient pam_opie.so no_warn
no_fake_prompts
auth requisite pam_opieaccess.so no_warn
allow_local
auth sufficient pam_radius.so no_warn
try_first_pass
#auth sufficient pam_krb5.so no_warn
try_first_pass
#auth sufficient pam_ssh.so no_warn
try_first_pass
auth sufficient pam_unix.so no_warn
try_first_pass

# account
account required pam_nologin.so
#account required pam_krb5.so
account required pam_login_access.so
account required pam_unix.so

# session
#session optional pam_ssh.so
session required pam_permit.so

# password
#password sufficient pam_krb5.so no_warn
try_first_pass
password required pam_unix.so no_warn
try_first_pass


:confused:

--
Regards,

Todor Genov
Systems Operations

Verizon Business South Africa (Pty) Ltd

todor.genov@xxxxxxxxxxxxxxxxxxxxxx
Tel: +27 11 235 6500
Fax: 086 692 0543
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to
"freebsd-questions-unsubscribe@xxxxxxxxxxx"



--
View this message in context: http://www.nabble.com/Radius-Authentication-tp20013780p20027802.html
Sent from the freebsd-questions mailing list archive at Nabble.com.

_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • [UNIX] DoS Attack Against FreeRADIUS (Other RADIUS Servers Affected)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... to create a high-performance and highly configurable GPL'd RADIUS server. ... program with failed requests causing a denial of service attack. ... Access-Request to the RADIUS server, ...
    (Securiteam)
  • Re: VPN access using Radius to trusted domain Windows 2003
    ... If you are using Windows Server 2003 IAS as your RADIUS server, ... need to do to enable it to proxy connection requests to other RADIUS ...
    (microsoft.public.internet.radius)
  • Re: Windows 2008 NPS Authentication Error
    ... I got over this issue by enabling EAP authentication. ... My issue now is that using Wireshark (on RADIUS server), ... Foundation Network Companion Guide: Deploying Server Certificates ... 1130AG wireless access point and Windows 2008 RADIUS Server. ...
    (microsoft.public.internet.radius)
  • Re: Wireless AP wants Radius Server, advice?
    ... >> EAP-PEAP, EAP-TLS, EAP-TTLS all provide secure authentication between the ... >> client and server. ... >>>> configuring IAS as a Radius Server for Wireless clients. ... >>>>> Radius server but that would require me to add users to the AP, ...
    (microsoft.public.windows.server.sbs)
  • Re: Sanity check - Exchagne DB limits
    ... All *standard Windows Domain tools* do allow you to select all options - the *SBS Wiards* may well not - these are designed to simplify configuration for admins with little experience. ... e.g. if you have difficulty adding a user without a wizard then adding a second server to a domain isn't something you would be doing in the first place. ... in that when you are creating a user, you do not get an option as to what Exchange server, or mailbox store to put the user's mailbox in. ...
    (microsoft.public.windows.server.sbs)