cancel
Showing results for 
Search instead for 
Did you mean: 

how to designate the password field used by LDAP AAA/RADIUS

how to designate the password field used by LDAP AAA/RADIUS

Tom10
New Contributor

Is there any way to define which attribute the RADIUS server checks in an external LDAP server? It seems to be hitting the first one that it hits (NT passwd) rather than the userPassword attribute which has caused some odd problems.

13 REPLIES 13

Tom10
New Contributor

That didn't work. It's still returning two passwords

samantha_lynn
Esteemed Contributor III

Thank you for sending that over to me. By default when we set up an LDAP server in HiveManager, the predefined user group attribute is "radiusGroupName". If we changes this to "person", that should included userPassword.

 

Here is the mapping from openLDAP for reference- http://www.zytrax.com/books/ldap/ape/#person

 

To find this in the HiveManager we will want to go to Configure> Open the Network Policy> Open the SSID> Open/Create the Default Radius Server Group> Select Aerohive Radius Server> Switch to LDAP Server.

2f0911feae1d408e92cbbe40145e5475_0690c000006GwRKAA0.png

 

 

 

samantha_lynn
Esteemed Contributor III

I haven't received the tech data yet, would you be able to send that again to communityhelp@aerohive.com?

Tom10
New Contributor
Sent from Mail for Windows 10

samantha_lynn
Esteemed Contributor III

Thank you. Were you able to get that tech data file?

 

To get tech data in HiveManager (formerly NG, cloud.aerohive.com):

Tools> Utilities> Get tech data> Check the box next to the device> Get tech data (blue button at the top of the page this time).

 

This guide reviews how to get tech data from the CLI of the AP in case that is more convenient:

https://thehivecommunity.aerohive.com/s/article/Collecting-Tech-Data-via-CLI

 

GTM-P2G8KFN