"Riccardo.Veraldi" <[EMAIL PROTECTED]> wrote:
> I would like only users with  kerberos credentials to being able to 
> authenticate

  Then delete everything from the "authenticate" section, except for
"eap" and "krb5".  Also, ensure that nothing in the "authorize"
section obtains a clear-text password for the user from a database.

  That guarantees:

  a) no password by which to authenticate someone
  b) therefore they must use kerberos
  c) they can't use anything other than kerberos

  Everyone else will have no way to get authenticated, and will be
rejected.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to