AW: differentiate authoriztion/ authentication in separate ldap modules

2013-09-04 Thread Hachmer, Tobias
Hello Alan, Hachmer, Tobias wrote: - Rewrite DN? You can rewrite the DN. That's why it's editable, as the LDAP-UserDn attribute. How can I do this and how magic could I rewrite the DN? The local ldap DIT and the AD DIT are totally different (different OU structure). It is much more

Re: CLASS value in SQL xlat

2013-09-04 Thread Arran Cudbard-Bell
On 4 Sep 2013, at 05:05, Okis Chuang okischu...@outlook.com wrote: Hi all, I’m using FR 2.2.0 with Oracle 11g. Now I’m collecting Accounting records into Oracle DB with sql xlat which call a function in PL/SQL. For example in debug mode it expands like below: “%{sql:select

Re: differentiate authoriztion/ authentication in separate ldap modules

2013-09-04 Thread Arran Cudbard-Bell
On 4 Sep 2013, at 06:54, Hachmer, Tobias tobias.hach...@stadt-frankfurt.de wrote: Hello Alan, Hachmer, Tobias wrote: - Rewrite DN? You can rewrite the DN. That's why it's editable, as the LDAP-UserDn attribute. How can I do this and how magic could I rewrite the DN? The local

Re: CLASS value in SQL xlat

2013-09-04 Thread Okis Chuang
Dear Arran, Much thanks! It works! Okis - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

AW: differentiate authoriztion/ authentication in separate ldap modules

2013-09-04 Thread Hachmer, Tobias
How can I do this and how magic could I rewrite the DN? The local ldap DIT and the AD DIT are totally different (different OU structure). It is much more than rewrite the base DN. When there's no way to determine the DN in AD DIT again I think I can achieve this more easy using ntlm_auth

Re: differentiate authoriztion/ authentication in separate ldap modules

2013-09-04 Thread Arran Cudbard-Bell
On 4 Sep 2013, at 13:10, Hachmer, Tobias tobias.hach...@stadt-frankfurt.de wrote: How can I do this and how magic could I rewrite the DN? The local ldap DIT and the AD DIT are totally different (different OU structure). It is much more than rewrite the base DN. When there's no way to