Re: [PacketFence-users] Manage AD password expiration

2019-07-12 Thread Fabrice Durand via PacketFence-users

Hello Enrico,

under mac osx you can have a 'system' wireless profile which is a kind 
of machine authentication.


https://gist.github.com/bruienne/fa2360146d8cb046ffde

Regards

Fabrice


Le 19-07-09 à 13 h 08, Enrico Pasqualotto via PacketFence-users a écrit :


Hello, I'm searching a solution to manage the password expiration of 
Mac OSX users that connect with Active-Directory account on WPA2 
Enterprise WIFI.


For Windows users I've created a new ROLE/VLAN that match machine-auth 
so on login screen the device is in a VLAN that talk only with domain 
server.


How can I simulate that for Apple users?

I'm thinking about:

  * recognize the expired password using RADIUS and assign a special
ROLE/VLAN for it. Possible?
  * make a rule that check if device is/was in register state (so I
know that device was previously connected) and if credential fail
put in the custom VLAN where can contact domain server

NOTE: I'm trying with advanced filter on profile but cannot found any 
docs with syntax or supported fields.


Anyone have managed this situation?

Thanks

Enrico

--
Enrico Pasqualotto





___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


--
Fabrice Durand
fdur...@inverse.ca ::  +1.514.447.4918 (x135) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org)

___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


[PacketFence-users] Manage AD password expiration

2019-07-09 Thread Enrico Pasqualotto via PacketFence-users
Hello, I'm searching a solution to manage the password expiration of Mac OSX 
users that connect with Active-Directory account on WPA2 Enterprise WIFI.

For Windows users I've created a new ROLE/VLAN that match machine-auth so on 
login screen the device is in a VLAN that talk only with domain server.

How can I simulate that for Apple users?

I'm thinking about:

  *   recognize the expired password using RADIUS and assign a special 
ROLE/VLAN for it. Possible?
  *   make a rule that check if device is/was in register state (so I know that 
device was previously connected) and if credential fail put in the custom VLAN 
where can contact domain server

NOTE: I'm trying with advanced filter on profile but cannot found any docs with 
syntax or supported fields.

Anyone have managed this situation?

Thanks

Enrico

--
Enrico Pasqualotto

[https://www.backloop.biz/backloop_loghi/LOGO_BackLoop_small.png]

___
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users