notes on AD
authorAlan T. DeKok <aland@freeradius.org>
Tue, 27 Sep 2016 19:12:23 +0000 (15:12 -0400)
committerAlan T. DeKok <aland@freeradius.org>
Tue, 27 Sep 2016 19:12:23 +0000 (15:12 -0400)
raddb/mods-available/ldap

index 0a1cf02..4b7e458 100644 (file)
@@ -154,6 +154,10 @@ ldap {
 
                #  Filter for user objects, should be specific enough
                #  to identify a single user object.
+               #
+               #  For Active Directory, you should use
+               #  "samaccountname=" instead of "uid="
+               #
                filter = "(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
 
                #  SASL parameters to use for user binds