Re: (RADIUS) Secondary radius authentication server.

Nick Waterman (nick-ls@leonet.co.uk)
Tue, 28 Apr 1998 16:45:15 +0100 (BST)

Netlink Support said:
> Is it possible to make the default radius entry on Linux#2 point to a
> shadow/passwd file that is not used for login, etc. on this box?
> ex:
>
> DEFAULT Password = "/somepath/file" rather than DEFAULT Password = "UNIX"

You could probably run radiusd chrooted, so /etc/passwd was actually
/foo/radd_root/etc/passwd or something?

The normal way to do this, though, is to play with groups. put all
people who SHOULD have dialin access into group "dialin", then in your
check-items, only authenticate where Group = "dialin". You can then
allow / disallow people to log on to the linux box itself by fiddling
their shells or something.

-- 
Nick Waterman.  Network Consultant / Sysadmin - LEOnet
Beating tomorrow's technology into submission.
nick-sig@leonet.co.uk                    Team *AMIGA*!
It said "requires Windows 95 or better", so why won't it work on my Amiga?

- To unsubscribe, email 'majordomo@livingston.com' with 'unsubscribe portmaster-radius' in the body of the message. Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>