siteadmin:basic_freeradius_orps_and_idp_configuration
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| siteadmin:basic_freeradius_orps_and_idp_configuration [2022/12/02 14:26] – admin | siteadmin:basic_freeradius_orps_and_idp_configuration [2023/04/05 11:58] (current) – admin | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ======IN PROGRESS====== | ======IN PROGRESS====== | ||
| + | |||
| + | ====Prerequesites==== | ||
| + | |||
| + | The winbind package must be installed and working. | ||
| ===Changed files=== | ===Changed files=== | ||
| Line 7: | Line 11: | ||
| * sites-available/ | * sites-available/ | ||
| * sites-available/ | * sites-available/ | ||
| + | * mods-available/ | ||
| * mods-available/ | * mods-available/ | ||
| Line 49: | Line 54: | ||
| # Realms that don't match any other listed send to the pool of govroam servers | # Realms that don't match any other listed send to the pool of govroam servers | ||
| - | realm " | + | realm "~^[^@\. ]([a-zA-Z0-9-]+\.)+[a-zA-Z]{2, |
| auth_pool = govroam | auth_pool = govroam | ||
| nostrip | nostrip | ||
| Line 94: | Line 99: | ||
| </ | </ | ||
| - | ===sites-available->govroam:=== | + | ===sites-available/govroam:=== |
| < | < | ||
| Line 168: | Line 173: | ||
| </ | </ | ||
| And then create a symlink from sites-enabled/ | And then create a symlink from sites-enabled/ | ||
| + | |||
| + | ===sites-available/ | ||
| < | < | ||
| Line 188: | Line 195: | ||
| | | ||
| authenticate { | authenticate { | ||
| - | | + | |
| files | files | ||
| | | ||
| Line 203: | Line 210: | ||
| | | ||
| | | ||
| - | | ||
| | | ||
| | | ||
| | | ||
| - | | ||
| } | } | ||
| } | } | ||
| Line 214: | Line 219: | ||
| And then create a symlink from sites-enabled/ | And then create a symlink from sites-enabled/ | ||
| + | ===mods-available/ | ||
| + | |||
| + | < | ||
| + | eap { | ||
| + | default_eap_type = mschapv2 | ||
| + | timer_expire | ||
| + | ignore_unknown_eap_types = no | ||
| + | cisco_accounting_username_bug = no | ||
| + | max_sessions = ${max_requests} | ||
| + | |||
| + | md5 { | ||
| + | } | ||
| + | |||
| + | tls-config tls-common { | ||
| + | # Generate and install a server cert and a CA ROOT. | ||
| + | private_key_password = whatever | ||
| + | private_key_file = / | ||
| + | certificate_file = / | ||
| + | ca_file = / | ||
| + | dh_file = ${certdir}/ | ||
| + | ca_path = ${cadir} | ||
| + | cipher_list = " | ||
| + | cipher_server_preference = no | ||
| + | ecdh_curve = " | ||
| + | |||
| + | cache { | ||
| + | enable = no | ||
| + | lifetime = 24 # hours | ||
| + | } | ||
| + | |||
| + | verify { | ||
| + | } | ||
| + | |||
| + | ocsp { | ||
| + | enable = no | ||
| + | override_cert_url = yes | ||
| + | url = " | ||
| + | } | ||
| + | } | ||
| + | |||
| + | tls { | ||
| + | tls = tls-common | ||
| + | |||
| + | } | ||
| + | |||
| + | # This is the config for PEAP/ | ||
| + | peap { | ||
| + | tls = tls-common | ||
| + | default_eap_type = mschapv2 | ||
| + | copy_request_to_tunnel = no | ||
| + | use_tunneled_reply = no | ||
| + | virtual_server = " | ||
| + | } | ||
| + | |||
| + | mschapv2 { | ||
| + | } | ||
| + | |||
| + | } | ||
| + | </ | ||
| + | And then create a symlink from mods-enabled/ | ||
| - | ===mods-available->govroam_logs: | + | ===mods-available/govroam_logs: |
| < | < | ||
siteadmin/basic_freeradius_orps_and_idp_configuration.1669991172.txt.gz · Last modified: by admin
