Displaying 4 results from an estimated 4 matches for "sbluck".
Did you mean:
bluck
2019 Nov 13
0
FreeRADIUS & SAMBA when Active Directory domain is not a FQDN
...e wrong context e.g. REALM
TLDR; SAMBA is querying AD based on sAMAccountName but is receiving UPN from user so can't find the user.
Cheers
Steve
________________________________
From: Andrew Bartlett <abartlet at samba.org>
Sent: Thursday, 14 November 2019 10:41 AM
To: Steve Bluck <sbluck at hotmail.com>; samba at lists.samba.org <samba at lists.samba.org>
Subject: Re: [Samba] FreeRADIUS & SAMBA when Active Directory domain is not a FQDN
Can you clarify again what the UPN is vs what the users enter via
FreeRADIUS as their 'username'?
I'm a bit lost.
Andre...
2019 Nov 14
1
FreeRADIUS & SAMBA when Active Directory domain is not a FQDN
On Wed, 2019-11-13 at 22:21 +0000, Steve Bluck via samba wrote:
> FreeRAIDUS is checking for a username in the format of
> [user]@[internet domain] for Eduroam (World wide WiFi network, mostly
> used by Education), if it is not a locally defined Internet domain it
> then refers the RADIUS request to a higher level RADIUS server.
> However if it's our defined domain e.g.
2019 Nov 13
3
FreeRADIUS & SAMBA when Active Directory domain is not a FQDN
Hi Rowland,
Apologies for the tardy reply, I mistakenly set the mailing list to digest...
Thanks for the suggestion, I'll ask the AD guys about this but I have a feeling it is an unlikely solution as Office 365 & Skype for Business apparently relies on the UPN. Unfortunately the local domain is a result of following Microsoft's "Best Practice" in the early 2000's which
2019 Nov 12
2
FreeRADIUS & SAMBA when Active Directory domain is not a FQDN
OS is Centos 7; FreeRADIUS Version 3.0.13; Samba version 4.9.1;
I'm building a FreeRADIUS box for Eduroam authentication for both SP & IDP, and have hit a stumbling block I can?t figure or Google my way out of.
The issue is the local AD domain is along the lines of ?example.campus?, but users have a UPN of ?user at example.com? which was added for Skype for Business as prior the UPN