Chapter 5
Pop quiz – user stores
- The value of the
read_groups
directive insql.conf
was probably set tono
by the previous administrator; changing it toyes
will activate reading of the group tables for all users. - The
freeradius-postgresql
package needs to be installed first. This package contains the required set-up files as well as the PostgreSQL-specific FreeRADIUS module. - No, you do not authenticate against an SQL database or text files, but rather use them to store credentials. Password verification is then done by an authentication module using the data stored in the text file or the SQL database. (If he's non-technical just tell him no problem, can be done.)
- Connect to the server through a secure connection and add access control to the directory to restrict access to the
userPassword
attribute. - No, this is not true! You can still use the 'bind as user' method, which limits you to PAP authentication. The
nspmPassword
attribute, which is available when Universal Password...