1
General Discussion / Re: How to setup FreeRadius to bind to Windows AD with LDAP
« on: August 05, 2021, 09:08:37 am »
Hello mimugmail
thank you so much for the answer. I read a lot about EAP, PAP and all other methods. I'm not sure if I understand it 100% correctly.
In my opinion, my setup would only work with EAP-TTLS/PAP, which is just secure, if the certificate is validated properly.
If I try to authenticate with EAP-TTLS/PAP, I get an error message on the OPNsense/radius.log (EAP Type "TTLS" configured):
Auth: (11) Login incorrect (No Auth-Type found: rejecting the user via Post-Auth-Type = Reject)
If I try to use the EAP Type "TTLS-GTC", the RADIUS daemon doesn't start:
Error: /usr/local/etc/raddb/mods-enabled/eap[15]: No dictionary definition for default EAP method 'ttls-gtc'.
Is ttls-gtc the same as ttls/pap?
Have a good day.
Olk
thank you so much for the answer. I read a lot about EAP, PAP and all other methods. I'm not sure if I understand it 100% correctly.
In my opinion, my setup would only work with EAP-TTLS/PAP, which is just secure, if the certificate is validated properly.
If I try to authenticate with EAP-TTLS/PAP, I get an error message on the OPNsense/radius.log (EAP Type "TTLS" configured):
Auth: (11) Login incorrect (No Auth-Type found: rejecting the user via Post-Auth-Type = Reject)
If I try to use the EAP Type "TTLS-GTC", the RADIUS daemon doesn't start:
Error: /usr/local/etc/raddb/mods-enabled/eap[15]: No dictionary definition for default EAP method 'ttls-gtc'.
Is ttls-gtc the same as ttls/pap?
Have a good day.
Olk