"Riccardo.Veraldi" <[EMAIL PROTECTED]> wrote: > I would like only users with kerberos credentials to being able to > authenticate
Then delete everything from the "authenticate" section, except for "eap" and "krb5". Also, ensure that nothing in the "authorize" section obtains a clear-text password for the user from a database. That guarantees: a) no password by which to authenticate someone b) therefore they must use kerberos c) they can't use anything other than kerberos Everyone else will have no way to get authenticated, and will be rejected. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

