richard lucassen <[EMAIL PROTECTED]> wrote:
> >   I don't know what you mean by "credentials".
> 
> Passwords. When I query the FR server with a wrong server password,

  The server doesn't have a password.  I think you mean "shared
secret", but I don't know why you'd go out of your way to use
different terms for it.

>  the FR returns "Access DENIED. (code = 3)", that's ok of course,
> but the FR is still querying the LDAP server. Although this is not
> necessary. Or am I missing something?

  If the shared secret is wrong, then in some cases, the server won't
notice until it tries to decrypt the users password.  This is a flaw
in the RADIUS protocol.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to