Hugh Irvine wrote:
> Yes this is fairly simple to do with multiple AuthBy clauses - in this
> case with a trailing AuthBy FILE to set the required reply attributes.

My plan is to avoid the entire AuthBy FILE, if I can, so whoever is
provisioning these users won't have to also edit a file, adding the users
to the groups in LDAP should be sufficient. And if we need to make new
levels of user access / giving special attributes to some, we'll add a new
group and do a small change in radiusd.cfg

I'll add the attributes with AddToReply, in the specific AuthBy block, and
won't need to use an AuthBy FILE then?

Eivind Olsen

