Hello Robin -

On Tue, 14 Sep 1999, Robin Gruyters wrote:
> >%_Hi,
> 
> Here more info (trace 4)
> 
> dns2# perl radiusd -config_file ldap.cfg
> Tue Sep 14 13:58:41 1999: INFO: Server started
> Tue Sep 14 13:58:47 1999: DEBUG: Packet dump:
> *** Received from 127.0.0.1 port 1181 ....
> Code:       Access-Request
> Identifier: 196
> Authentic:  1234567890123456
> Attributes:
>       User-Name = "andre"
>       Service-Type = Framed-User
>       NAS-IP-Address = 203.63.154.1
>       NAS-Port = 1234
>       NAS-Port-Type = Async
>       User-Password = ****************
> 
> Tue Sep 14 13:58:47 1999: DEBUG: Handling request with Handler 'Realm=DEFAULT'
> Tue Sep 14 13:58:47 1999: DEBUG: Deleting session for andre, 203.63.154.1, 1234
> Tue Sep 14 13:58:47 1999: DEBUG: Handling with Radius::AuthLDAP
> Tue Sep 14 13:58:47 1999: DEBUG: Connecting to *********, port 389
> 
> ep 14 13:58:47 1999: DEBUG: LDAP got result for cn=Andre Oppermann, o=Wish, c=NL
> Tue Sep 14 13:58:47 1999: DEBUG: LDAP got userpassword: {MD5}*****************
> Tue Sep 14 13:58:47 1999: DEBUG: Radius::AuthLDAP looks for match with andre
> Tue Sep 14 13:58:47 1999: DEBUG: Radius::AuthLDAP REJECT: Bad Password
> Tue Sep 14 13:58:47 1999: DEBUG: Connecting to **********, port 389
> Tue Sep 14 13:58:47 1999: DEBUG: No entries for DEFAULT found in LDAP database
> Tue Sep 14 13:58:47 1999: INFO: Access rejected for andre: Bad Password

The debug output above shows a password string of {MD5}*************** - this
will not work. To indicate an MD5 encrypted string, use a prefix of "$1$"
(dollar one dollar). Note that the documentation has a slight error in Section
13.1.1 on this topic which has now been fixed.

hth

Hugh


--
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald,
Platypus, Freeside, TACACS+, PAM, external, etc etc on Unix, Win95/8,
NT, Rhapsody

===
Archive at http://www.thesite.com.au/~radiator/
To unsubscribe, email '[EMAIL PROTECTED]' with
'unsubscribe radiator' in the body of the message.

Reply via email to