Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 6 Mar 1998 16:09:00 +0100 (CET)
From:      Andrzej Bialecki <abial@nask.pl>
To:        William Bulley <web@merit.edu>
Cc:        freebsd-isp@FreeBSD.ORG
Subject:   Re: Merit Radius and password changing
Message-ID:  <Pine.NEB.3.95.980306160333.1697A-100000@korin.warman.org.pl>
In-Reply-To: <199803061448.JAA22002@ohm.merit.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 6 Mar 1998, William Bulley wrote:

> According to Andrzej Bialecki:
> > 
> > I have several questions concerning Merit Radius v. 3.5.6:
> 
> Then send them to aaa-support@merit.edu as is clearly suggested
> on our WWW pages at the following URL:   :-)
> 
>    http://www.merit.edu/aaa/

Okay, you're right :-) Thanks for the information you give below, though!

> > * I also want to allow users to change their passwords (remember, they are
> > not Unix passwords, so this is not going to be passwd(1)). How can I do
> > this without manually editing 'users' file and restarting server?
> 
> This is the $64,000 question that has plagued the RADIUS protocol and
> IETF RADIUS Working Group discussions for years.  I would recommend
> using Kerberos (which has mechanisms for users to remotely change
> their passwords).  The Merit AAA Server supports Kerberos BTW.

And what about the db(3) interface, which allows to dynamically update the
on-disk database, also supporting transactions (which would allow several
clients to one database - I mean, radiusd and some other maintenance/admin
tool)? I can imagine adding support for this - it would be realtively
simple because most of the hooks is already there. 

> The support for DBM/NDBM/etc. and builddbm in the Merit AAA Server is
> weak.  We cache all the of configuration files and therefore we see
> little benefit from the use of builddbm (and don't deal with it) or any
> access to the disk to get user profiles (since it is all in memory).

Ok. But it's possible to turn the caching off (which would be beneficial
in case of using db(3)).

Thanks for reply!


Andrzej Bialecki

---------------------+---------------------------------------------------------
abial@warman.org.pl  | if(halt_per_mth > 0) { fetch("http://www.freebsd.org") }
Research & Academic  | "Be open-minded, but don't let your brains to fall out."
Network in Poland    | All of the above (and more) is just my personal opinion.
---------------------+---------------------------------------------------------


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.NEB.3.95.980306160333.1697A-100000>