John T. Guthrie wrote: > So are you saying that FreeRADIUS sometimes needs some assistance when > dealing with authentication oracles? That is, it needs to be told when > to use them?
Yes. The oracles are things like Kerberos, Active Directory, or a proxying to another RADIUS server. There is nothing in the RADIUS Access-Request that tells the server to use an oracle. There is nothing in a DB that tells the server how to authenticate the user. So the server has to be explicitly told "use this oracle". > Moreover, is the problem in this case how to tell > FreeRADIUS about that without setting an explicit Auth-Type? From what > you said above, it seems that is not likely. Yes. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The blog - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

