> You will need to strip it; what "other" problem did it cause?
The "other" problem it caused was as follows and as another respondent wrote, you can't mess with the User-Name attribute, so that's the wrong path to take it seems. Anyway I found some additional info in the main branch of the thread. FYI the appropriate debug log section is as follows when I rewrite the User-Name attribute: Processing the authenticate section of radiusd.conf modcall: entering group authenticate for request 6 rlm_eap: Identity does not match User-Name, setting from EAP Identity. rlm_eap: Failed in handler modcall[authenticate]: module "eap" returns invalid for request 6 modcall: leaving group authenticate (returns invalid) for request 6 auth: Failed to validate the user. Found Post-Auth-Type Processing the post-auth section of radiusd.conf modcall: entering group REJECT for request 6 - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

