On Wed, Jan 9, 2019 at 3:01 AM Christian Meutes <[email protected]>
wrote:

> we are using EAP authentication (802.1x) inside of  'AuthBy LDAP2', and
> that surrounded by another 'AuthBy Group'.
>

EAP was meant to say EAP-TLS. The CN of the user's certificate is slightly
modified by RewriteUsername in the 'AuthBy Group' (which seems to mean that
the AuthBy Group is called twice), and then used as lookup attribute again
in the LDAP query.

--
Christian
_______________________________________________
radiator mailing list
[email protected]
https://lists.open.com.au/mailman/listinfo/radiator

Reply via email to