[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: LDAP with TLS Enable/Disable not working
- To: "Sunkad, Abhilash" <abhilash.sunkad@commscope.com>, "ldap@umich.edu" <ldap@umich.edu>, "openldap-technical@openldap.org" <openldap-technical@openldap.org>
- Subject: Re: LDAP with TLS Enable/Disable not working
- From: Michael Ströder <michael@stroeder.com>
- Date: Fri, 21 Jun 2019 08:56:45 +0200
- Autocrypt: addr=michael@stroeder.com; prefer-encrypt=mutual; keydata= mQENBFbdnRoBCADj0vYA4aRwKJ6AE4mf8oElLgMT/1eLNKpJ2FYBWcwj9d8dTk5/p9b8DRxy S/qQIUUZqt9xRFZwUCm0vFeQMRDeN9xzAKoRzrJifoDOacOjG1lhZTKYvVZGgUT89Ao3QeHh Q7gPzcAKNoueoR2y3FXStOYuRrbk5PlSjVAITjsotgc7PWE9mmVYpeu8a+byK/DBHKUyolOA 1UXYvDa7MbPhMtdNm8qnwtKs1Vsyk1VkErM+5cIe+zTT6WYQcmZMRjCtWGiFTzk9W6Mdlskk WRTKhKNgokTsgcy1ecaCBUZWxv/SyXgD81+rwRi9b8Px+1reg43ayxi8sV7jrI1feybbABEB AAG0J01pY2hhZWwgU3Ryw7ZkZXIgPG1pY2hhZWxAc3Ryb2VkZXIuY29tPokBNwQTAQgAIQUC Vt2dGgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgAAKCRAH3HrjaovJOFpTCACjO773gcmJ KvzjiNpUFl/gANyaJgIq4VbMQ7VthRb1F9X6YbdJ6Z99ntyESjGFCpjofcSomr2vJDpv6ht+ lY33yo20YwsMpqe2OeId0jPybG+FtabKjgBNoAk7iqnBGUvE4t0dz0n1LQVCQR2jxyTKmcNq OYpsRZ3H+6kWwJMuVgsNZglINVZ8JgV5QuLYN5jhYz+pOuFnU11bV6nWREvzZXzebe7g7Zus 6AsWjtJ0lDvgBNzLlF3/eFrVch6Bejs0SvuFseIdZQk+4YU6Rb8xul/jDFXIfo7eTmijO3dV T5AmC1cUi8czncwpgAJnEH8vYv23RoN/aw2gSMCS2huIuQENBFbdnRoBCAC7L1cTVBVZZuM/ yxSUM5CsgGBlTD1Cr7C2ngZFsHSYXVLq6NUB8GZA2iLK96CrwnFw4/Jjz4llOjc50iVRMQKL RyFWOJAMrpPq2ew5T+Uoo524D//dwVbqkFVVuvM8NPiKIDyPGCjP+acM1D8hXwhOXgQ8Iz8Q 3/GRSYjitn9JrkF0ia2nhariznBKVu0LDffxF/hOCx45+QRR2/rYYlshfZMB7nEJX9P+hVfM CSzltz9Z8CldeUbiJvnyrISReR2XBw9oh8JkIUP0BtpIaify9A7EfzOk+W9BUnWe+YwdSUsB fJxOhSv+umyW5GMqZGFu+4oYnkzbe+1LUs1JarCtABEBAAGJAR8EGAEIAAkFAlbdnRoCGwwA CgkQB9x642qLyTjEUgf+JX6Atatl/QKe37yCj1OZYNPd3B0rPLJRF5mEmrADRXLZC9+uFeDS Wxxln040gnR6rjBHrRcvVmlTDiZY26iuL16+V+0/aZ9uyXNQSzk2cwDSiI/8gvr72Y+FN5fh cGXpeNHxHilYc9onzDhxyE76cwzqTKm4q2ULIH2u9IHQ5O86Fv6nHPYhe2fy1bhQapNwi/Xl 3G3i2WNH/w7m+1zWU1IddZOjmXzoxLT1BATwXGa0Tt5RjVb2mM1Wg3Zj6kqFkF2vvKcvrwj0 q0Ap5uyfN5m0uWzQMCMoaV9HQf7f5MkS1lnwBqDgnojjVAieX5uk7olUiRuPKHMfhvXulYP8 AA==
- Content-language: en-US
- In-reply-to: <BN6PR14MB14608DD49319B1D5CD154CD4EFE40@BN6PR14MB1460.namprd14.prod.outlook.com>
- Openpgp: id=43C8730E84A20E560722806C07DC7AE36A8BC938
- References: <BN6PR14MB14608DD49319B1D5CD154CD4EFE40@BN6PR14MB1460.namprd14.prod.outlook.com>
- User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.7.1
On 6/20/19 7:00 PM, Sunkad, Abhilash wrote:
> I am facing a strange problem. I am using FreeRadius 3.16 version for my
> Proxy authentication.
>
> I have an AD server and I make an authentication request enabling TLS.
> So the TLS connection passes and authentication is successful.
>
> Now I have one more LDAP server where its non TLS. Now if I make a call,
> even though TLS is disabled on this server, Client tries to make a TLS
> connection and fails. I have tried freeing connections but with no luck.
> Please help.
First of all you should not use different security settings. Depending
on your RADIUS config the users' passwords are sent in clear to the LDAP
server when TLS is not used.
I suspect that the policy in section tls {} within the section ldap {}
in FreeRADIUS config is applied to all servers. Which makes sense
because you want all servers in a pool to have the same security level.
This is rather a FreeRADIUS question though and you might better ask on
their mailing list (see https://freeradius.org/community/).
Ciao, Michael.