Hi Daniel,

I'm afraid I don't understand what you're trying to accomplish.

There's two primary use cases for RADIUS:

 - RADIUS for wireless auth, with IPA doing the underlying authentication
 - RADIUS as a backend for OTP, with IPA passing OTP queries to RADIUS to
   validate

I'm going to guess by your request that you want the former, not the latter.


What you're looking for is probably most easily accomplished via an LDAP
interface for FreeRADIUS. I think the following might help you:

- https://wiki.freeradius.org/modules/Rlm_ldap
- http://lists.freeradius.org/pipermail/freeradius-users/2018-April/091159.html

I'm not sure what group information you'd need in this scenario, though.


If you're trying to use RADIUS to do authenticate on systems, we don't
support pam_radius (and the authenticating system doesn't get group
information in that setup).

Would sssd be a better fit in this case? 


Thanks,

- Alex

----- Original Message -----
> From: "Daniel E. White (GSFC-770.0)[NICS] via FreeIPA-users" 
> <[email protected]>
> To: "FreeIPA users list" <[email protected]>
> Cc: "Daniel E. White (GSFC-770.0)[NICS]" <[email protected]>
> Sent: Wednesday, February 12, 2020 8:54:31 AM
> Subject: [Freeipa-users] FreeIPA and FreeRadius (or any RADIUS)
> 
> Reference:
> https://www.freeipa.org/page/Using_FreeIPA_and_FreeRadius_as_a_RADIUS_based_software_token_OTP_system_with_CentOS/RedHat_7
> 
> What about setting it up so that RADIUS gets credentials and groups from
> FreeIPA without the OTP ?
> 
> ______________________________________________________________________________________________
> 
> Daniel E. White
> [email protected]<mailto:[email protected]>
> NICS Linux Engineer
> NASA Goddard Space Flight Center
> 8800 Greenbelt Road
> Building 14, Room E175
> Greenbelt, MD 20771
> Office: (301) 286-6919
> Mobile: (240) 513-5290
> 
> _______________________________________________
> FreeIPA-users mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedorahosted.org/archives/list/[email protected]
> 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
  • [Freeipa-users] Free... White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users
    • [Freeipa-users]... Alex Scheel via FreeIPA-users

Reply via email to