Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-06 Thread Heikki Vatiainen
On 04/06/2013 03:58 PM, Garry Shtern wrote: > That's an excellent idea! Good to hear it's solved. > In my case the SQLite DB doesn't even need > to be writable by the radiator user. I put my users and clients into > that database, and created custom SQL queries and everything works > perfectly.

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-06 Thread Garry Shtern
iator-boun...@open.com.au [mailto:radiator-boun...@open.com.au] On Behalf Of Heikki Vatiainen Sent: Friday, April 05, 2013 4:53 PM To: radiator@open.com.au Subject: Re: [RADIATOR] Ideas on group and reply attribs parsing On 04/05/2013 11:17 PM, Garry Shtern wrote: > I am not quite clear on how th

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-06 Thread Garry Shtern
c: 'Heikki Vatiainen'; radiator@open.com.au Subject: Re: [RADIATOR] Ideas on group and reply attribs parsing Hello Garry - Actually, Fall-Through continues after an ACCEPT. For example, this users file: DEFAULT User-Name = hugh, Password = hugh Fall-Through = yes DEFAULT

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-05 Thread Hugh Irvine
not what I want. > I am looking to augment AuthBy FILE to match against the groups that we > retrieved in AuthBy LDAP2. I want to return as soon as the first Group= is > matched and reject if none are matched... > > Thanks, > > -Original Message- > From: Hugh Irv

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-05 Thread Heikki Vatiainen
On 04/05/2013 11:17 PM, Garry Shtern wrote: > I am not quite clear on how this would help me. Fall-Through > controls whether we will continue looking even after a REJECT. That's > not what I want. I am looking to augment AuthBy FILE to match > against the groups that we retrieved in AuthBy LDAP

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-05 Thread Garry Shtern
half Of Heikki Vatiainen > Sent: Thursday, April 04, 2013 4:47 PM > To: radiator@open.com.au > Subject: Re: [RADIATOR] Ideas on group and reply attribs parsing > > On 04/04/2013 11:24 PM, Garry Shtern wrote: > >> Thanks for the pointer. What I want to accomplish (forgetting about

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-05 Thread Hugh Irvine
t; Sent: Thursday, April 04, 2013 4:47 PM > To: radiator@open.com.au > Subject: Re: [RADIATOR] Ideas on group and reply attribs parsing > > On 04/04/2013 11:24 PM, Garry Shtern wrote: > >> Thanks for the pointer. What I want to accomplish (forgetting about >> the ac

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-04 Thread Garry Shtern
at do you think? -Original Message- From: radiator-boun...@open.com.au [mailto:radiator-boun...@open.com.au] On Behalf Of Heikki Vatiainen Sent: Thursday, April 04, 2013 4:47 PM To: radiator@open.com.au Subject: Re: [RADIATOR] Ideas on group and reply attribs parsing On 04/04/2013 11:24 PM, Gar

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-04 Thread Heikki Vatiainen
On 04/04/2013 11:24 PM, Garry Shtern wrote: > Thanks for the pointer. What I want to accomplish (forgetting about > the actual code), it define all of my users in a single file. And in > the same file to be able to distinguish which reply attributes are > returned based on the RADIUS client. It

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-04 Thread Garry Shtern
hrough all of the groups in User-Groups Thanks! -Original Message- From: radiator-boun...@open.com.au [mailto:radiator-boun...@open.com.au] On Behalf Of Heikki Vatiainen Sent: Thursday, April 04, 2013 3:53 PM To: radiator@open.com.au Subject: Re: [RADIATOR] Ideas on group and reply at

Re: [RADIATOR] Ideas on group and reply attribs parsing

2013-04-04 Thread Heikki Vatiainen
On 04/04/2013 03:40 PM, Garry Shtern wrote: > I am trying to accomplish the following goal and would love ideas on the > best way to accomplish it… Have you considered something like: AuthByPolicy ContinueWhileAccept AuthBy krb-auth AuthBy ldap-auth # If still here, have authenticated a