RE: Grouping after Kerberos 5 authentication accepted?

2007-04-20 Thread Jason Chan
PROTECTED]; FreeRadius users mailing list Subject: Re: Grouping after Kerberos 5 authentication accepted? Jason Chan wrote: For example, Kerberos successfully authenticate admin/admin (yes I don't use MySQL for authentication), and FreeRadius knows this user has permission to access. Now

Re: Grouping after Kerberos 5 authentication accepted?

2007-04-19 Thread Alan DeKok
Jason Chan wrote: Is it possible for FreeRadius to perform grouping after Kerberos authentication accepted? You can configure things in the post-authentication phase. My company has many switches and servers and we use kerberos 5 for RADIUS authentication. Once the user is authenticated,

RE: Grouping after Kerberos 5 authentication accepted?

2007-04-19 Thread Jason Chan
PROTECTED] Subject: Re: Grouping after Kerberos 5 authentication accepted? Jason Chan wrote: You are correct, the grouping isn't come from Kerberos. I'm going to build a mysql database in the FreeRadius server to handle all the grouping/permissions. What fields do I need for the database? I

Re: Grouping after Kerberos 5 authentication accepted?

2007-04-19 Thread Donny Jekels
I have been following your thread and am interrested to find out how do d you get freeradius to do authentication wiht kerberos? any config examples would be helpfull. On 4/18/07, Jason Chan [EMAIL PROTECTED] wrote: Hello, Is it possible for FreeRadius to perform grouping after Kerberos

RE: Grouping after Kerberos 5 authentication accepted?

2007-04-19 Thread Jason Chan
[mailto:[EMAIL PROTECTED] Sent: Thursday, April 19, 2007 3:20 PM To: [EMAIL PROTECTED]; FreeRadius users mailing list Subject: Re: Grouping after Kerberos 5 authentication accepted? I have been following your thread and am interrested to find out how do d you get freeradius to do authentication wiht

Re: Grouping after Kerberos 5 authentication accepted?

2007-04-19 Thread Alan DeKok
Jason Chan wrote: For example, Kerberos successfully authenticate admin/admin (yes I don't use MySQL for authentication), and FreeRadius knows this user has permission to access. Now, in the postauth part, FreeRadius searches the radreply table in its MySQL database for the proper attributes

Grouping after Kerberos 5 authentication accepted?

2007-04-18 Thread Jason Chan
Hello, Is it possible for FreeRadius to perform grouping after Kerberos authentication accepted? My company has many switches and servers and we use kerberos 5 for RADIUS authentication. Once the user is authenticated, RADIUS will check and decide if this user can access the switches or