RE: (PM) RE: Group issues on NT (take 5)

James Courtier-Dutton (dutton@livingston-ent.co.uk)
Fri, 26 Mar 1999 21:20:48 -0000

Hello Josh
maybe is you post an extract of the Radius debug log, it might help.
They is a verbose debug tick box somewhere (Might be called something else)
We can then find out if it is parsing the user entry of not, or whether the
group auth is failing.
I have found that using notepad to edit the users file sometimes causes
problems.
Also, why not post the full radius user entry instead of just the first
line.
Cheers
James

> -----Original Message-----
> From: owner-portmaster-users@livingston.com
> [mailto:owner-portmaster-users@livingston.com]On Behalf Of Josh Moormann
> Sent: Friday, March 26, 1999 04:53
> To: Thomas C Kinnen
> Cc: portmaster-users@livingston.com
> Subject: (PM) RE: Group issues on NT (take 5)
>
>
> > Can you answer the following questions for me? I'm trying to track this
> > down.
> > Is the RADIUS server running on NT Server or WorkStation?
>
> NT Server 4.0 SP3
>
> > Is the RADIUS server a domain member or PDC/BDC?
>
> Domain Member. I can log into this box using my domain account
> without any
> problems.
>
> > Are the groups WS local groups, Domain Local Groups, Domain
> Global groups?
>
> If you are describing what group I am referencing in the first line of my
> users file such that it looks like:
>
> DEFAULT Auth-Type = System, Group = "(groupname)"
>
> Then, when I enter in the "(groupname)" section:
>
> Domain Global Group "RAS" with domain account members - Failed
> Domain Local Group "rastwo" with domain account members - Failed
> WS Local group "dialup" with domain account members - Failed
> WS Local group "dialuptwo" with local account member - Failed
>
> > Are the Accounts Local accounts or domain accounts
>
> Domain accounts - no problem authenticating here via Radius.
> However, once
> "group" command is placed in users file, ALL authentication fails. If
> "Group" command is removed from users file then ALL domain
> members accounts
> as well as local accounts can authenticate successfully.
>
> Any ideas?
>
> JM
>
> -
> To unsubscribe, email 'majordomo@livingston.com' with
> 'unsubscribe portmaster-users' in the body of the message.
> Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>
>
>

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.
Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>