[RADIATOR] AuthAttrDef for multi-value Radius attribute check

Alexander Hartmaier alexander.hartmaier at t-systems.at
Mon Sep 16 07:59:58 CDT 2013


I just tried to implement a check for group membership:

AuthAttrDef memberOf,OSC-Group-Identifier-LDAP,check

OSC-Group-Identifier-LDAP is a multi-value attribute derived from
OSC-Group-Identifier with a PreAuthHook, basically just to transform the
support groups of a device into the corresponding LDAP CNs.
According to the trace 4 log the check runs twice but both times using
the first OSC-Group-Identifier-LDAP value.
Is this a bug?
--
Best regards, Alexander Hartmaier

T-Systems Austria GesmbH
TSS Security Services
Network Security & Monitoring Engineer

phone: +43(0)57057-4320
fax: +43(0)57057-954320



*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*
T-Systems Austria GesmbH Rennweg 97-99, 1030 Wien
Handelsgericht Wien, FN 79340b
*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*
Notice: This e-mail contains information that is confidential and may be privileged.
If you are not the intended recipient, please notify the sender and then
delete this e-mail immediately.
*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*"*


More information about the radiator mailing list