Re: [PacketFence-users] Machine authentication with multiple AD domains

2019-08-06 Thread Enrico Pasqualotto via PacketFence-users
Hi Ludovic, thanks for the explanation. I re-check my config and all was correctly configured. Today I found the issue, my second domain is longer that principal and the username for machine authentication exceed the MS limit (host/MY_PC_WITH_LONG_NAME.mysecond_domain.local). By renaming the

Re: [PacketFence-users] Machine authentication with multiple AD domains

2019-08-06 Thread Ludovic Zammit via PacketFence-users
Hello Enrico, Maybe you could try a vlan filter that check the username as the computer name and auto-register it and assign a role. It’s manageable if you have not too many rules for computers authentication. Thanks, Ludovic Zammit > On Aug 5, 2019, at 5:03 PM, Enrico Pasqualotto >

Re: [PacketFence-users] Machine authentication with multiple AD domains

2019-08-02 Thread Ludovic Zammit via PacketFence-users
Hello Enrico, You have to create a realm with your domainName.local and enable “Strip in RADIUS authorization” then on your connection profile you will need an AD source with the “Username Attribute” with sAMAccountName and servicePrincipalName. It will allow you authenticate users and

[PacketFence-users] Machine authentication with multiple AD domains

2019-08-02 Thread Enrico Pasqualotto via PacketFence-users
Hi all, I have two domain: mydomain1.local mydomain2.local configured with their REALM (MYDOMAIN1 & MYDOMAIN2) and all user auth are working well over RADIUS + Active-Directory. Machine_authentication are working well for domain1.local because I have set the domain in the REALM NULL &