Use Windows AD (Radius module) as an authentication module for LinOTP!!

719 views
Skip to first unread message

HaTiM Chikhi

unread,
Jun 25, 2015, 8:49:05 AM6/25/15
to lin...@googlegroups.com
Hi,


I'm wondering if it is possible to use the Radius module of Windows AD as an authentication module for LinOTP?

Now I'm using freeradius, but I want to try this with Windows AD (Radius module) because it is the real server that we are using.


Thank you!

Mirko Ahnert

unread,
Jun 25, 2015, 10:29:23 AM6/25/15
to lin...@googlegroups.com
Dear HaTiM Chikhi,

correct me, if I misread your setup. You want to substitute FreeRADIUS with a Windows based RADIUS Server which then should contact LinOTP to check the OTPs? If so, you would need to have something like a plugin for the RADIUS server in order to be able to communicate with LinOTP. Unfortunately their is none available at the moment.

If your question is about how to integrate RADIUS in your windows Login procedures (and thereby LinOTP e.g. via FreeRADIUS) - this is possible with Microsoft NPS.

Best regards,

Mirko

-- 
Mirko Ahnert 
LSE Leading Security Experts GmbH, http://www.lsexperts.de 
Postfach 100121, 64201 Darmstadt, Germany 
Zentrale: +49 6151 86086-0 , Fax: -299 
Support Hotline: +49 6151 86086-115 
Unternehmenssitz: Weiterstadt Amtsgericht Darmstadt: HRB8649 
Geschäftsführer: Oliver Michel, Sven Walther 

HaTiM Chikhi

unread,
Jun 26, 2015, 5:28:38 AM6/26/15
to lin...@googlegroups.com
Hi Mirko,

Thanks for you reply.

Yes it is the first scenario that I wanted to setup.

For the second scenario, if I understand well, The Microsoft NPS server will relay authentication requests to the FreeRadius server that will talk to LinOTP. is that right?

Thanks for your help.

Mirko Ahnert

unread,
Jun 26, 2015, 5:30:57 AM6/26/15
to lin...@googlegroups.com
Hi,
 
For the second scenario, if I understand well, The Microsoft NPS server will relay authentication requests to the FreeRadius server that will talk to LinOTP. is that right?

Yes, this is correct.

Regards,

HaTiM Chikhi

unread,
Jun 26, 2015, 6:03:58 AM6/26/15
to lin...@googlegroups.com
OK, this may be a possible solution. Otherwise, it's better to use a seperate FreeRadius server for VPN authentication.

Thank you again for your help.

Best regards,

Hatim
Reply all
Reply to author
Forward
0 new messages