[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freeradius-users
Subject:    Re: Fallback method of authentication
From:       Alan DeKok <aland () deployingradius ! com>
Date:       2015-05-29 11:32:52
Message-ID: 2BEC03CF-85F5-498B-9E69-DABC498303AC () deployingradius ! com
[Download RAW message or body]

On May 29, 2015, at 7:07 AM, Rafael Domingues Quitério <rdquiterio.si@cenfim.pt> \
wrote:
> I have installed FreeRADIUS Version 3.0.7 from source and it's doing machine \
> authentication on a Windows domain. 

  That makes it more difficult.

> The radius server is a samba member. The place doesn't have a DC, so, the radius \
> authentication is done to a remote DC. If the WAN link to the DC site fails, \
> machine authentication on the Freradius server will fail. 
> Because of that , I'm considering having a fallback method for authentication \
> (files) when the link goes down.  
> Is that possible to implement via the configuration files? Could somebody give me \
> hints to achieve that.

  There is no real way to do fallback authentication.  Because EAP / machine \
authentication is designed to make that impossible.

  Put a backup DC in the local site.  That's really the best way to solve the \
problem.

  Alan DeKok.


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic