OPNsense Forum

Archive => 23.1 Legacy Series => Topic started by: henningkessler on February 24, 2023, 03:04:05 pm

Title: FreeRADIUS EAP-GTC Google LDAP
Post by: henningkessler on February 24, 2023, 03:04:05 pm
Hello,

I just did a small test and with only a few edits in eap, default and inner-tunnel config files I could configure the FreeRADIUS plugin to use Google LDAP as authentication source for my Unifi APs. Here are some more details https://www.nasirhafeez.com/freeradius-with-google-g-suite-workspace-secure-ldap-for-wpa2-enterprise-wifi (https://www.nasirhafeez.com/freeradius-with-google-g-suite-workspace-secure-ldap-for-wpa2-enterprise-wifi). After a restart or reload pf the config in the webgui everything is gone of course. Is there a chance that the maintainer for the plugin can make this available in the gui?

Regards

Henning
Title: Re: FreeRADIUS EAP-GTC Google LDAP
Post by: mimizone on March 06, 2023, 08:05:12 pm
Hi,
I am in the process of doing the same.
What's missing in the OPNSense UI for you to make it work the same way?
Is freeradius version 3.0 what's needed to make it work?

On my side,
I have FreeRadius + Unifi working with locally defined users in the OPNSense/FreeRadius service.
Google LDAP works fine with OPNSense System/Access/Server.
But the same LDAP config in FreeRadius doesn't work.
I was blaming my lack of understanding of the User Filter and Group filter that should be used. But maybe it's just the freeradius version?

Title: Re: FreeRADIUS EAP-GTC Google LDAP
Post by: mimizone on March 06, 2023, 08:30:27 pm
Actually I just noticed they are 2 parts for freeradius on my OPNsense.
- Plugin: os-freeradius version: 1.9.21_2
- Package: freeradius3 version 3.2.1_1

Did I install too much or one installed the other?
Should that work with Google?

I am still running OPNSense 22.7.11_1 for the time being until the 23.1 bugs are squished enough :P
Title: Re: FreeRADIUS EAP-GTC Google LDAP
Post by: henningkessler on March 07, 2023, 08:59:51 am
Hi I have the package installed as the Plugin. The modifications that are needed on the configuration files are minor but I can't really say how those could be implemented in the UI...